1 /*
2    +----------------------------------------------------------------------+
3    | Zend OPcache                                                         |
4    +----------------------------------------------------------------------+
5    | Copyright (c) 1998-2018 The PHP Group                                |
6    +----------------------------------------------------------------------+
7    | This source file is subject to version 3.01 of the PHP license,      |
8    | that is bundled with this package in the file LICENSE, and is        |
9    | available through the world-wide-web at the following url:           |
10    | http://www.php.net/license/3_01.txt                                  |
11    | If you did not receive a copy of the PHP license and are unable to   |
12    | obtain it through the world-wide-web, please send a note to          |
13    | license@php.net so we can mail you a copy immediately.               |
14    +----------------------------------------------------------------------+
15    | Authors: Dmitry Stogov <dmitry@zend.com>                             |
16    |          Xinchen Hui <laruence@php.net>                              |
17    +----------------------------------------------------------------------+
18 */
19 
20 /* pass 4
21  * - optimize INIT_FCALL_BY_NAME to DO_FCALL
22  */
23 
24 #include "php.h"
25 #include "Optimizer/zend_optimizer.h"
26 #include "Optimizer/zend_optimizer_internal.h"
27 #include "zend_API.h"
28 #include "zend_constants.h"
29 #include "zend_execute.h"
30 #include "zend_vm.h"
31 
32 #define ZEND_OP1_IS_CONST_STRING(opline) \
33 	(opline->op1_type == IS_CONST && \
34 	Z_TYPE(op_array->literals[(opline)->op1.constant]) == IS_STRING)
35 #define ZEND_OP2_IS_CONST_STRING(opline) \
36 	(opline->op2_type == IS_CONST && \
37 	Z_TYPE(op_array->literals[(opline)->op2.constant]) == IS_STRING)
38 
39 typedef struct _optimizer_call_info {
40 	zend_function *func;
41 	zend_op       *opline;
42 	zend_bool      try_inline;
43 } optimizer_call_info;
44 
zend_delete_call_instructions(zend_op * opline)45 static void zend_delete_call_instructions(zend_op *opline)
46 {
47 	int call = 0;
48 
49 	while (1) {
50 		switch (opline->opcode) {
51 			case ZEND_INIT_FCALL_BY_NAME:
52 			case ZEND_INIT_NS_FCALL_BY_NAME:
53 			case ZEND_INIT_STATIC_METHOD_CALL:
54 			case ZEND_INIT_METHOD_CALL:
55 			case ZEND_INIT_FCALL:
56 				if (call == 0) {
57 					MAKE_NOP(opline);
58 					return;
59 				}
60 				/* break missing intentionally */
61 			case ZEND_NEW:
62 			case ZEND_INIT_DYNAMIC_CALL:
63 			case ZEND_INIT_USER_CALL:
64 				call--;
65 				break;
66 			case ZEND_DO_FCALL:
67 			case ZEND_DO_ICALL:
68 			case ZEND_DO_UCALL:
69 			case ZEND_DO_FCALL_BY_NAME:
70 				call++;
71 				break;
72 			case ZEND_SEND_VAL:
73 			case ZEND_SEND_VAR:
74 				if (call == 0) {
75 					if (opline->op1_type == IS_CONST) {
76 						MAKE_NOP(opline);
77 					} else if (opline->op1_type == IS_CV) {
78 						opline->opcode = ZEND_CHECK_VAR;
79 						opline->extended_value = 0;
80 						opline->result.var = 0;
81 					} else {
82 						opline->opcode = ZEND_FREE;
83 						opline->extended_value = 0;
84 						opline->result.var = 0;
85 					}
86 				}
87 				break;
88 		}
89 		opline--;
90 	}
91 }
92 
zend_try_inline_call(zend_op_array * op_array,zend_op * fcall,zend_op * opline,zend_function * func)93 static void zend_try_inline_call(zend_op_array *op_array, zend_op *fcall, zend_op *opline, zend_function *func)
94 {
95 	if (func->type == ZEND_USER_FUNCTION
96 	 && !(func->op_array.fn_flags & (ZEND_ACC_ABSTRACT|ZEND_ACC_HAS_TYPE_HINTS))
97 	 && fcall->extended_value >= func->op_array.required_num_args
98 	 && func->op_array.opcodes[func->op_array.num_args].opcode == ZEND_RETURN) {
99 
100 		zend_op *ret_opline = func->op_array.opcodes + func->op_array.num_args;
101 
102 		if (ret_opline->op1_type == IS_CONST) {
103 			uint32_t i, num_args = func->op_array.num_args;
104 			num_args += (func->op_array.fn_flags & ZEND_ACC_VARIADIC) != 0;
105 
106 			if (fcall->opcode == ZEND_INIT_METHOD_CALL && fcall->op1_type == IS_UNUSED) {
107 				/* TODO: we can't inlne methods, because $this may be used
108 				 *       not in object context ???
109 				 */
110 				return;
111 			}
112 
113 			for (i = 0; i < num_args; i++) {
114 				/* Don't inline functions with by-reference arguments. This would require
115 				 * correct handling of INDIRECT arguments. */
116 				if (func->op_array.arg_info[i].pass_by_reference) {
117 					return;
118 				}
119 			}
120 
121 			if (fcall->extended_value < func->op_array.num_args) {
122 				/* don't inline funcions with named constants in default arguments */
123 				i = fcall->extended_value;
124 
125 				do {
126 					if (Z_CONSTANT_P(RT_CONSTANT(&func->op_array, func->op_array.opcodes[i].op2))) {
127 						return;
128 					}
129 					i++;
130 				} while (i < func->op_array.num_args);
131 			}
132 
133 			if (RETURN_VALUE_USED(opline)) {
134 				zval zv;
135 
136 				ZVAL_DUP(&zv, RT_CONSTANT(&func->op_array, ret_opline->op1));
137 				opline->opcode = ZEND_QM_ASSIGN;
138 				opline->op1_type = IS_CONST;
139 				opline->op1.constant = zend_optimizer_add_literal(op_array, &zv);
140 				SET_UNUSED(opline->op2);
141 			} else {
142 				MAKE_NOP(opline);
143 			}
144 
145 			zend_delete_call_instructions(opline-1);
146 		}
147 	}
148 }
149 
zend_optimize_func_calls(zend_op_array * op_array,zend_optimizer_ctx * ctx)150 void zend_optimize_func_calls(zend_op_array *op_array, zend_optimizer_ctx *ctx)
151 {
152 	zend_op *opline = op_array->opcodes;
153 	zend_op *end = opline + op_array->last;
154 	int call = 0;
155 	void *checkpoint;
156 	optimizer_call_info *call_stack;
157 
158 	if (op_array->last < 2) {
159 		return;
160 	}
161 
162 	checkpoint = zend_arena_checkpoint(ctx->arena);
163 	call_stack = zend_arena_calloc(&ctx->arena, op_array->last / 2, sizeof(optimizer_call_info));
164 	while (opline < end) {
165 		switch (opline->opcode) {
166 			case ZEND_INIT_FCALL_BY_NAME:
167 			case ZEND_INIT_NS_FCALL_BY_NAME:
168 			case ZEND_INIT_STATIC_METHOD_CALL:
169 			case ZEND_INIT_METHOD_CALL:
170 			case ZEND_INIT_FCALL:
171 			case ZEND_NEW:
172 				call_stack[call].func = zend_optimizer_get_called_func(
173 					ctx->script, op_array, opline, 0);
174 				call_stack[call].try_inline = opline->opcode != ZEND_NEW;
175 				/* break missing intentionally */
176 			case ZEND_INIT_DYNAMIC_CALL:
177 			case ZEND_INIT_USER_CALL:
178 				call_stack[call].opline = opline;
179 				call++;
180 				break;
181 			case ZEND_DO_FCALL:
182 			case ZEND_DO_ICALL:
183 			case ZEND_DO_UCALL:
184 			case ZEND_DO_FCALL_BY_NAME:
185 				call--;
186 				if (call_stack[call].func && call_stack[call].opline) {
187 					zend_op *fcall = call_stack[call].opline;
188 
189 					if (fcall->opcode == ZEND_INIT_FCALL) {
190 						/* nothing to do */
191 					} else if (fcall->opcode == ZEND_INIT_FCALL_BY_NAME) {
192 						fcall->opcode = ZEND_INIT_FCALL;
193 						fcall->op1.num = zend_vm_calc_used_stack(fcall->extended_value, call_stack[call].func);
194 						Z_CACHE_SLOT(op_array->literals[fcall->op2.constant + 1]) = Z_CACHE_SLOT(op_array->literals[fcall->op2.constant]);
195 						literal_dtor(&ZEND_OP2_LITERAL(fcall));
196 						fcall->op2.constant = fcall->op2.constant + 1;
197 						opline->opcode = zend_get_call_op(fcall, call_stack[call].func);
198 					} else if (fcall->opcode == ZEND_INIT_NS_FCALL_BY_NAME) {
199 						fcall->opcode = ZEND_INIT_FCALL;
200 						fcall->op1.num = zend_vm_calc_used_stack(fcall->extended_value, call_stack[call].func);
201 						Z_CACHE_SLOT(op_array->literals[fcall->op2.constant + 1]) = Z_CACHE_SLOT(op_array->literals[fcall->op2.constant]);
202 						literal_dtor(&op_array->literals[fcall->op2.constant]);
203 						literal_dtor(&op_array->literals[fcall->op2.constant + 2]);
204 						fcall->op2.constant = fcall->op2.constant + 1;
205 						opline->opcode = zend_get_call_op(fcall, call_stack[call].func);
206 					} else if (fcall->opcode == ZEND_INIT_STATIC_METHOD_CALL
207 							|| fcall->opcode == ZEND_INIT_METHOD_CALL
208 							|| fcall->opcode == ZEND_NEW) {
209 						/* We don't have specialized opcodes for this, do nothing */
210 					} else {
211 						ZEND_ASSERT(0);
212 					}
213 
214 					if ((ZEND_OPTIMIZER_PASS_16 & ctx->optimization_level)
215 					 && call_stack[call].try_inline) {
216 						zend_try_inline_call(op_array, fcall, opline, call_stack[call].func);
217 					}
218 				}
219 				call_stack[call].func = NULL;
220 				call_stack[call].opline = NULL;
221 				call_stack[call].try_inline = 0;
222 				break;
223 			case ZEND_FETCH_FUNC_ARG:
224 			case ZEND_FETCH_STATIC_PROP_FUNC_ARG:
225 			case ZEND_FETCH_OBJ_FUNC_ARG:
226 			case ZEND_FETCH_DIM_FUNC_ARG:
227 				if (call_stack[call - 1].func) {
228 					if (ARG_SHOULD_BE_SENT_BY_REF(call_stack[call - 1].func, (opline->extended_value & ZEND_FETCH_ARG_MASK))) {
229 						opline->extended_value &= ZEND_FETCH_TYPE_MASK;
230 						if (opline->opcode != ZEND_FETCH_STATIC_PROP_FUNC_ARG) {
231 							opline->opcode -= 9;
232 						} else {
233 							opline->opcode = ZEND_FETCH_STATIC_PROP_W;
234 						}
235 					} else {
236 						if (opline->opcode == ZEND_FETCH_DIM_FUNC_ARG
237 								&& opline->op2_type == IS_UNUSED) {
238 							/* FETCH_DIM_FUNC_ARG supports UNUSED op2, while FETCH_DIM_R does not.
239 							 * Performing the replacement would create an invalid opcode. */
240 							call_stack[call - 1].try_inline = 0;
241 							break;
242 						}
243 
244 						opline->extended_value &= ZEND_FETCH_TYPE_MASK;
245 						if (opline->opcode != ZEND_FETCH_STATIC_PROP_FUNC_ARG) {
246 							opline->opcode -= 12;
247 						} else {
248 							opline->opcode = ZEND_FETCH_STATIC_PROP_R;
249 						}
250 					}
251 				}
252 				break;
253 			case ZEND_SEND_VAL_EX:
254 				if (call_stack[call - 1].func) {
255 					if (ARG_MUST_BE_SENT_BY_REF(call_stack[call - 1].func, opline->op2.num)) {
256 						/* We won't convert it into_DO_FCALL to emit error at run-time */
257 						call_stack[call - 1].opline = NULL;
258 					} else {
259 						opline->opcode = ZEND_SEND_VAL;
260 					}
261 				}
262 				break;
263 			case ZEND_SEND_VAR_EX:
264 				if (call_stack[call - 1].func) {
265 					if (ARG_SHOULD_BE_SENT_BY_REF(call_stack[call - 1].func, opline->op2.num)) {
266 						opline->opcode = ZEND_SEND_REF;
267 					} else {
268 						opline->opcode = ZEND_SEND_VAR;
269 					}
270 				}
271 				break;
272 			case ZEND_SEND_VAR_NO_REF_EX:
273 				if (call_stack[call - 1].func) {
274 					if (ARG_MUST_BE_SENT_BY_REF(call_stack[call - 1].func, opline->op2.num)) {
275 						opline->opcode = ZEND_SEND_VAR_NO_REF;
276 					} else if (ARG_MAY_BE_SENT_BY_REF(call_stack[call - 1].func, opline->op2.num)) {
277 						opline->opcode = ZEND_SEND_VAL;
278 					} else {
279 						opline->opcode = ZEND_SEND_VAR;
280 					}
281 				}
282 				break;
283 			case ZEND_SEND_UNPACK:
284 			case ZEND_SEND_USER:
285 			case ZEND_SEND_ARRAY:
286 				call_stack[call - 1].try_inline = 0;
287 				break;
288 			default:
289 				break;
290 		}
291 		opline++;
292 	}
293 
294 	zend_arena_release(&ctx->arena, checkpoint);
295 }
296