1 /*
2    +----------------------------------------------------------------------+
3    | Zend OPcache                                                         |
4    +----------------------------------------------------------------------+
5    | Copyright (c) 1998-2015 The PHP Group                                |
6    +----------------------------------------------------------------------+
7    | This source file is subject to version 3.01 of the PHP license,      |
8    | that is bundled with this package in the file LICENSE, and is        |
9    | available through the world-wide-web at the following url:           |
10    | http://www.php.net/license/3_01.txt                                  |
11    | If you did not receive a copy of the PHP license and are unable to   |
12    | obtain it through the world-wide-web, please send a note to          |
13    | license@php.net so we can mail you a copy immediately.               |
14    +----------------------------------------------------------------------+
15    | Authors: Andi Gutmans <andi@zend.com>                                |
16    |          Zeev Suraski <zeev@zend.com>                                |
17    |          Stanislav Malyshev <stas@zend.com>                          |
18    |          Dmitry Stogov <dmitry@zend.com>                             |
19    +----------------------------------------------------------------------+
20 */
21 
22 #include "php.h"
23 #include "Optimizer/zend_optimizer.h"
24 #include "Optimizer/zend_optimizer_internal.h"
25 #include "zend_API.h"
26 #include "zend_constants.h"
27 #include "zend_execute.h"
28 
29 #define OPTIMIZATION_LEVEL \
30 	ZCG(accel_directives).optimization_level
31 
32 #if ZEND_EXTENSION_API_NO >= PHP_5_5_X_API_NO
zend_optimizer_lookup_cv(zend_op_array * op_array,char * name,int name_len)33 static int zend_optimizer_lookup_cv(zend_op_array *op_array, char* name, int name_len)
34 {
35 	int i = 0;
36 	ulong hash_value = zend_inline_hash_func(name, name_len+1);
37 
38 	while (i < op_array->last_var) {
39 		if (op_array->vars[i].name == name ||
40 		    (op_array->vars[i].hash_value == hash_value &&
41 		     op_array->vars[i].name_len == name_len &&
42 		     memcmp(op_array->vars[i].name, name, name_len) == 0)) {
43 			return i;
44 		}
45 		i++;
46 	}
47 	i = op_array->last_var;
48 	op_array->last_var++;
49 	op_array->vars = erealloc(op_array->vars, op_array->last_var * sizeof(zend_compiled_variable));
50 	if (IS_INTERNED(name)) {
51 		op_array->vars[i].name = name;
52 	} else {
53 		op_array->vars[i].name = estrndup(name, name_len);
54 	}
55 	op_array->vars[i].name_len = name_len;
56 	op_array->vars[i].hash_value = hash_value;
57 	return i;
58 }
59 #endif
60 
61 #if ZEND_EXTENSION_API_NO > PHP_5_3_X_API_NO
zend_optimizer_add_literal(zend_op_array * op_array,const zval * zv TSRMLS_DC)62 int zend_optimizer_add_literal(zend_op_array *op_array, const zval *zv TSRMLS_DC)
63 {
64 	int i = op_array->last_literal;
65 	op_array->last_literal++;
66 	if (i >= CG(context).literals_size) {
67 		CG(context).literals_size += 16; /* FIXME */
68 		op_array->literals = (zend_literal*)erealloc(op_array->literals, CG(context).literals_size * sizeof(zend_literal));
69 	}
70 	op_array->literals[i].constant = *zv;
71 	op_array->literals[i].hash_value = 0;
72 	op_array->literals[i].cache_slot = -1;
73 	Z_SET_REFCOUNT(op_array->literals[i].constant, 2);
74 	Z_SET_ISREF(op_array->literals[i].constant);
75 	return i;
76 }
77 
78 # define LITERAL_LONG(op, val) do { \
79 		zval _c; \
80 		ZVAL_LONG(&_c, val); \
81 		op.constant = zend_optimizer_add_literal(op_array, &_c TSRMLS_CC); \
82 	} while (0)
83 
84 # define LITERAL_BOOL(op, val) do { \
85 		zval _c; \
86 		ZVAL_BOOL(&_c, val); \
87 		op.constant = zend_optimizer_add_literal(op_array, &_c TSRMLS_CC); \
88 	} while (0)
89 
90 # define literal_dtor(zv) do { \
91 		zval_dtor(zv); \
92 		Z_TYPE_P(zv) = IS_NULL; \
93 	} while (0)
94 
95 #define COPY_NODE(target, src) do { \
96 		target ## _type = src ## _type; \
97 		target = src; \
98 	} while (0)
99 
100 #else
101 
102 # define LITERAL_LONG(op, val) ZVAL_LONG(&op.u.constant, val)
103 
104 # define LITERAL_BOOL(op, val) ZVAL_BOOL(&op.u.constant, val)
105 
106 # define literal_dtor(zv) zval_dtor(zv)
107 
108 #define COPY_NODE(target, src) do { \
109 		target = src; \
110 	} while (0)
111 
112 #endif
113 
update_op1_const(zend_op_array * op_array,zend_op * opline,zval * val TSRMLS_DC)114 static void update_op1_const(zend_op_array *op_array,
115                              zend_op       *opline,
116                              zval          *val TSRMLS_DC)
117 {
118 	if (opline->opcode == ZEND_FREE) {
119 		MAKE_NOP(opline);
120 		zval_dtor(val);
121 	} else {
122 		ZEND_OP1_TYPE(opline) = IS_CONST;
123 #if ZEND_EXTENSION_API_NO > PHP_5_3_X_API_NO
124 		if (Z_TYPE_P(val) == IS_STRING) {
125 			switch (opline->opcode) {
126 				case ZEND_INIT_STATIC_METHOD_CALL:
127 				case ZEND_CATCH:
128 				case ZEND_FETCH_CONSTANT:
129 					opline->op1.constant = zend_optimizer_add_literal(op_array, val TSRMLS_CC);
130 					Z_HASH_P(&ZEND_OP1_LITERAL(opline)) = zend_hash_func(Z_STRVAL(ZEND_OP1_LITERAL(opline)), Z_STRLEN(ZEND_OP1_LITERAL(opline)) + 1);
131 					op_array->literals[opline->op1.constant].cache_slot = op_array->last_cache_slot++;
132 					zend_str_tolower(Z_STRVAL_P(val), Z_STRLEN_P(val));
133 					zend_optimizer_add_literal(op_array, val TSRMLS_CC);
134 					op_array->literals[opline->op1.constant+1].hash_value = zend_hash_func(Z_STRVAL(op_array->literals[opline->op1.constant+1].constant), Z_STRLEN(op_array->literals[opline->op1.constant+1].constant) + 1);
135 					break;
136 				case ZEND_DO_FCALL:
137 					zend_str_tolower(Z_STRVAL_P(val), Z_STRLEN_P(val));
138 					opline->op1.constant = zend_optimizer_add_literal(op_array, val TSRMLS_CC);
139 					Z_HASH_P(&ZEND_OP1_LITERAL(opline)) = zend_hash_func(Z_STRVAL(ZEND_OP1_LITERAL(opline)), Z_STRLEN(ZEND_OP1_LITERAL(opline)) + 1);
140 					op_array->literals[opline->op1.constant].cache_slot = op_array->last_cache_slot++;
141 					break;
142 				default:
143 					opline->op1.constant = zend_optimizer_add_literal(op_array, val TSRMLS_CC);
144 					Z_HASH_P(&ZEND_OP1_LITERAL(opline)) = zend_hash_func(Z_STRVAL(ZEND_OP1_LITERAL(opline)), Z_STRLEN(ZEND_OP1_LITERAL(opline)) + 1);
145 					break;
146 			}
147 		} else {
148 			opline->op1.constant = zend_optimizer_add_literal(op_array, val TSRMLS_CC);
149 		}
150 #else
151 		ZEND_OP1_LITERAL(opline) = *val;
152 #endif
153 	}
154 }
155 
update_op2_const(zend_op_array * op_array,zend_op * opline,zval * val TSRMLS_DC)156 static void update_op2_const(zend_op_array *op_array,
157                              zend_op       *opline,
158                              zval          *val TSRMLS_DC)
159 {
160 	ZEND_OP2_TYPE(opline) = IS_CONST;
161 #if ZEND_EXTENSION_API_NO > PHP_5_3_X_API_NO
162 	opline->op2.constant = zend_optimizer_add_literal(op_array, val TSRMLS_CC);
163 	if (Z_TYPE_P(val) == IS_STRING) {
164 		Z_HASH_P(&ZEND_OP2_LITERAL(opline)) = zend_hash_func(Z_STRVAL(ZEND_OP2_LITERAL(opline)), Z_STRLEN(ZEND_OP2_LITERAL(opline)) + 1);
165 		switch (opline->opcode) {
166 			case ZEND_FETCH_R:
167 			case ZEND_FETCH_W:
168 			case ZEND_FETCH_RW:
169 			case ZEND_FETCH_IS:
170 			case ZEND_FETCH_UNSET:
171 			case ZEND_FETCH_FUNC_ARG:
172 			case ZEND_FETCH_CLASS:
173 			case ZEND_INIT_FCALL_BY_NAME:
174 			/*case ZEND_INIT_NS_FCALL_BY_NAME:*/
175 			case ZEND_UNSET_VAR:
176 			case ZEND_ISSET_ISEMPTY_VAR:
177 			case ZEND_ADD_INTERFACE:
178 			case ZEND_ADD_TRAIT:
179 				op_array->literals[opline->op2.constant].cache_slot = op_array->last_cache_slot++;
180 				zend_str_tolower(Z_STRVAL_P(val), Z_STRLEN_P(val));
181 				zend_optimizer_add_literal(op_array, val TSRMLS_CC);
182 				op_array->literals[opline->op2.constant+1].hash_value = zend_hash_func(Z_STRVAL(op_array->literals[opline->op2.constant+1].constant), Z_STRLEN(op_array->literals[opline->op2.constant+1].constant) + 1);
183 				break;
184 			case ZEND_INIT_METHOD_CALL:
185 			case ZEND_INIT_STATIC_METHOD_CALL:
186 				zend_str_tolower(Z_STRVAL_P(val), Z_STRLEN_P(val));
187 				zend_optimizer_add_literal(op_array, val TSRMLS_CC);
188 				op_array->literals[opline->op2.constant+1].hash_value = zend_hash_func(Z_STRVAL(op_array->literals[opline->op2.constant+1].constant), Z_STRLEN(op_array->literals[opline->op2.constant+1].constant) + 1);
189 				/* break missing intentionally */
190 			/*case ZEND_FETCH_CONSTANT:*/
191 			case ZEND_ASSIGN_OBJ:
192 			case ZEND_FETCH_OBJ_R:
193 			case ZEND_FETCH_OBJ_W:
194 			case ZEND_FETCH_OBJ_RW:
195 			case ZEND_FETCH_OBJ_IS:
196 			case ZEND_FETCH_OBJ_UNSET:
197 			case ZEND_FETCH_OBJ_FUNC_ARG:
198 			case ZEND_UNSET_OBJ:
199 			case ZEND_PRE_INC_OBJ:
200 			case ZEND_PRE_DEC_OBJ:
201 			case ZEND_POST_INC_OBJ:
202 			case ZEND_POST_DEC_OBJ:
203 			case ZEND_ISSET_ISEMPTY_PROP_OBJ:
204 				op_array->literals[opline->op2.constant].cache_slot = op_array->last_cache_slot;
205 				op_array->last_cache_slot += 2;
206 				break;
207 			case ZEND_ASSIGN_ADD:
208 			case ZEND_ASSIGN_SUB:
209 			case ZEND_ASSIGN_MUL:
210 			case ZEND_ASSIGN_DIV:
211 			case ZEND_ASSIGN_MOD:
212 			case ZEND_ASSIGN_SL:
213 			case ZEND_ASSIGN_SR:
214 			case ZEND_ASSIGN_CONCAT:
215 			case ZEND_ASSIGN_BW_OR:
216 			case ZEND_ASSIGN_BW_AND:
217 			case ZEND_ASSIGN_BW_XOR:
218 				if (opline->extended_value == ZEND_ASSIGN_OBJ) {
219 					op_array->literals[opline->op2.constant].cache_slot = op_array->last_cache_slot;
220 					op_array->last_cache_slot += 2;
221 				}
222 				break;
223 #if ZEND_EXTENSION_API_NO >= PHP_5_4_X_API_NO
224 			case ZEND_OP_DATA:
225 				if ((opline-1)->opcode == ZEND_ASSIGN_DIM ||
226 				    ((opline-1)->extended_value == ZEND_ASSIGN_DIM &&
227 				     ((opline-1)->opcode == ZEND_ASSIGN_ADD ||
228 				     (opline-1)->opcode == ZEND_ASSIGN_SUB ||
229 				     (opline-1)->opcode == ZEND_ASSIGN_MUL ||
230 				     (opline-1)->opcode == ZEND_ASSIGN_DIV ||
231 				     (opline-1)->opcode == ZEND_ASSIGN_MOD ||
232 				     (opline-1)->opcode == ZEND_ASSIGN_SL ||
233 				     (opline-1)->opcode == ZEND_ASSIGN_SR ||
234 				     (opline-1)->opcode == ZEND_ASSIGN_CONCAT ||
235 				     (opline-1)->opcode == ZEND_ASSIGN_BW_OR ||
236 				     (opline-1)->opcode == ZEND_ASSIGN_BW_AND ||
237 				     (opline-1)->opcode == ZEND_ASSIGN_BW_XOR))) {
238 					goto check_numeric;
239 				}
240 				break;
241 			case ZEND_ISSET_ISEMPTY_DIM_OBJ:
242 			case ZEND_ADD_ARRAY_ELEMENT:
243 			case ZEND_INIT_ARRAY:
244 			case ZEND_ASSIGN_DIM:
245 			case ZEND_UNSET_DIM:
246 			case ZEND_FETCH_DIM_R:
247 			case ZEND_FETCH_DIM_W:
248 			case ZEND_FETCH_DIM_RW:
249 			case ZEND_FETCH_DIM_IS:
250 			case ZEND_FETCH_DIM_FUNC_ARG:
251 			case ZEND_FETCH_DIM_UNSET:
252 			case ZEND_FETCH_DIM_TMP_VAR:
253 check_numeric:
254 				{
255 					ulong index;
256 					int numeric = 0;
257 
258 					ZEND_HANDLE_NUMERIC_EX(Z_STRVAL_P(val), Z_STRLEN_P(val)+1, index, numeric = 1);
259 					if (numeric) {
260 						zval_dtor(val);
261 						ZVAL_LONG(val, index);
262 						op_array->literals[opline->op2.constant].constant = *val;
263 		        	}
264 				}
265 				break;
266 #endif
267 			default:
268 				break;
269 		}
270 	}
271 #else
272 	ZEND_OP2_LITERAL(opline) = *val;
273 #endif
274 }
275 
replace_tmp_by_const(zend_op_array * op_array,zend_op * opline,zend_uint var,zval * val TSRMLS_DC)276 static void replace_tmp_by_const(zend_op_array *op_array,
277                                  zend_op       *opline,
278                                  zend_uint      var,
279                                  zval          *val
280                                  TSRMLS_DC)
281 {
282 	zend_op *end = op_array->opcodes + op_array->last;
283 
284 	while (opline < end) {
285 		if (ZEND_OP1_TYPE(opline) == IS_TMP_VAR &&
286 			ZEND_OP1(opline).var == var) {
287 
288 			/* In most cases IS_TMP_VAR operand may be used only once.
289 			 * The operands are usually destroyed by the opcode handler.
290 			 * ZEND_CASE is an exception, that keeps operand unchanged,
291 			 * and allows its reuse. The number of ZEND_CASE instructions
292 			 * usually terminated by ZEND_FREE that finally kills the value.
293 			 */
294 			if (opline->opcode == ZEND_CASE || opline->opcode == ZEND_FREE) {
295 				zend_op *m, *n;
296 				int brk = op_array->last_brk_cont;
297 				zend_bool in_switch = 0;
298 				while (brk--) {
299 					if (op_array->brk_cont_array[brk].start <= (opline - op_array->opcodes) &&
300 							op_array->brk_cont_array[brk].brk > (opline - op_array->opcodes)) {
301 						in_switch = 1;
302 						break;
303 					}
304 				}
305 
306 				if (!in_switch) {
307 					MAKE_NOP(opline);
308 					zval_dtor(val);
309 					break;
310 				}
311 
312 				m = opline;
313 				n = op_array->opcodes + op_array->brk_cont_array[brk].brk + 1;
314 				while (m < n) {
315 					if (ZEND_OP1_TYPE(m) == IS_TMP_VAR &&
316 							ZEND_OP1(m).var == var) {
317 						if (m->opcode == ZEND_CASE) {
318 							zval old_val;
319 							old_val = *val;
320 							zval_copy_ctor(val);
321 							update_op1_const(op_array, m, val TSRMLS_CC);
322 							*val = old_val;
323 						} else if (m->opcode == ZEND_FREE) {
324 							MAKE_NOP(m);
325 						} else {
326 							ZEND_ASSERT(0);
327 						}
328 					}
329 					m++;
330 				}
331 				zval_dtor(val);
332 				break;
333 			} else {
334 				update_op1_const(op_array, opline, val TSRMLS_CC);
335 				break;
336 			}
337 		}
338 
339 		if (ZEND_OP2_TYPE(opline) == IS_TMP_VAR &&
340 			ZEND_OP2(opline).var == var) {
341 
342 			update_op2_const(op_array, opline, val TSRMLS_CC);
343 			/* TMP_VAR may be used only once */
344 			break;
345 		}
346 		opline++;
347 	}
348 }
349 
350 #include "Optimizer/nop_removal.c"
351 #include "Optimizer/block_pass.c"
352 #include "Optimizer/optimize_temp_vars_5.c"
353 
zend_optimizer(zend_op_array * op_array TSRMLS_DC)354 void zend_optimizer(zend_op_array *op_array TSRMLS_DC)
355 {
356 	if (op_array->type == ZEND_EVAL_CODE ||
357 	    (op_array->fn_flags & ZEND_ACC_INTERACTIVE)) {
358 		return;
359 	}
360 
361 	/* pass 1
362 	 * - substitute persistent constants (true, false, null, etc)
363 	 * - perform compile-time evaluation of constant binary and unary operations
364 	 * - optimize series of ADD_STRING and/or ADD_CHAR
365 	 * - convert CAST(IS_BOOL,x) into BOOL(x)
366 	 * - convert INTI_FCALL_BY_NAME + DO_FCALL_BY_NAME into DO_FCALL
367 	 */
368 #include "Optimizer/pass1_5.c"
369 
370 	/* pass 2:
371 	 * - convert non-numeric constants to numeric constants in numeric operators
372 	 * - optimize constant conditional JMPs
373 	 * - optimize static BRKs and CONTs
374 	 */
375 #include "Optimizer/pass2.c"
376 
377 	/* pass 3:
378 	 * - optimize $i = $i+expr to $i+=expr
379 	 * - optimize series of JMPs
380 	 * - change $i++ to ++$i where possible
381 	 */
382 #include "Optimizer/pass3.c"
383 
384 	/* pass 5:
385 	 * - CFG optimization
386 	 */
387 #include "Optimizer/pass5.c"
388 
389 	 /* pass 9:
390 	 * - Optimize temp variables usage
391 	 */
392 #include "Optimizer/pass9.c"
393 
394 	/* pass 10:
395 	 * - remove NOPs
396 	 */
397 #include "Optimizer/pass10.c"
398 }
399