1 /*
2    +----------------------------------------------------------------------+
3    | Zend OPcache                                                         |
4    +----------------------------------------------------------------------+
5    | Copyright (c) The PHP Group                                          |
6    +----------------------------------------------------------------------+
7    | This source file is subject to version 3.01 of the PHP license,      |
8    | that is bundled with this package in the file LICENSE, and is        |
9    | available through the world-wide-web at the following url:           |
10    | http://www.php.net/license/3_01.txt                                  |
11    | If you did not receive a copy of the PHP license and are unable to   |
12    | obtain it through the world-wide-web, please send a note to          |
13    | license@php.net so we can mail you a copy immediately.               |
14    +----------------------------------------------------------------------+
15    | Authors: Dmitry Stogov <dmitry@php.net>                              |
16    |          Xinchen Hui <laruence@php.net>                              |
17    +----------------------------------------------------------------------+
18 */
19 
20 /* pass 4
21  * - optimize INIT_FCALL_BY_NAME to DO_FCALL
22  */
23 
24 #include "php.h"
25 #include "Optimizer/zend_optimizer.h"
26 #include "Optimizer/zend_optimizer_internal.h"
27 #include "zend_API.h"
28 #include "zend_constants.h"
29 #include "zend_execute.h"
30 #include "zend_vm.h"
31 
32 #define ZEND_OP1_IS_CONST_STRING(opline) \
33 	(opline->op1_type == IS_CONST && \
34 	Z_TYPE(op_array->literals[(opline)->op1.constant]) == IS_STRING)
35 #define ZEND_OP2_IS_CONST_STRING(opline) \
36 	(opline->op2_type == IS_CONST && \
37 	Z_TYPE(op_array->literals[(opline)->op2.constant]) == IS_STRING)
38 
39 typedef struct _optimizer_call_info {
40 	zend_function *func;
41 	zend_op       *opline;
42 	zend_bool      try_inline;
43 	uint32_t       func_arg_num;
44 } optimizer_call_info;
45 
zend_delete_call_instructions(zend_op * opline)46 static void zend_delete_call_instructions(zend_op *opline)
47 {
48 	int call = 0;
49 
50 	while (1) {
51 		switch (opline->opcode) {
52 			case ZEND_INIT_FCALL_BY_NAME:
53 			case ZEND_INIT_NS_FCALL_BY_NAME:
54 			case ZEND_INIT_STATIC_METHOD_CALL:
55 			case ZEND_INIT_METHOD_CALL:
56 			case ZEND_INIT_FCALL:
57 				if (call == 0) {
58 					MAKE_NOP(opline);
59 					return;
60 				}
61 				/* break missing intentionally */
62 			case ZEND_NEW:
63 			case ZEND_INIT_DYNAMIC_CALL:
64 			case ZEND_INIT_USER_CALL:
65 				call--;
66 				break;
67 			case ZEND_DO_FCALL:
68 			case ZEND_DO_ICALL:
69 			case ZEND_DO_UCALL:
70 			case ZEND_DO_FCALL_BY_NAME:
71 				call++;
72 				break;
73 			case ZEND_SEND_VAL:
74 			case ZEND_SEND_VAR:
75 				if (call == 0) {
76 					if (opline->op1_type == IS_CONST) {
77 						MAKE_NOP(opline);
78 					} else if (opline->op1_type == IS_CV) {
79 						opline->opcode = ZEND_CHECK_VAR;
80 						opline->extended_value = 0;
81 						opline->result.var = 0;
82 					} else {
83 						opline->opcode = ZEND_FREE;
84 						opline->extended_value = 0;
85 						opline->result.var = 0;
86 					}
87 				}
88 				break;
89 		}
90 		opline--;
91 	}
92 }
93 
zend_try_inline_call(zend_op_array * op_array,zend_op * fcall,zend_op * opline,zend_function * func)94 static void zend_try_inline_call(zend_op_array *op_array, zend_op *fcall, zend_op *opline, zend_function *func)
95 {
96 	if (func->type == ZEND_USER_FUNCTION
97 	 && !(func->op_array.fn_flags & (ZEND_ACC_ABSTRACT|ZEND_ACC_HAS_TYPE_HINTS))
98 		/* TODO: function copied from trait may be inconsistent ??? */
99 	 && !(func->op_array.fn_flags & (ZEND_ACC_TRAIT_CLONE))
100 	 && fcall->extended_value >= func->op_array.required_num_args
101 	 && func->op_array.opcodes[func->op_array.num_args].opcode == ZEND_RETURN) {
102 
103 		zend_op *ret_opline = func->op_array.opcodes + func->op_array.num_args;
104 
105 		if (ret_opline->op1_type == IS_CONST) {
106 			uint32_t i, num_args = func->op_array.num_args;
107 			num_args += (func->op_array.fn_flags & ZEND_ACC_VARIADIC) != 0;
108 
109 			if (fcall->opcode == ZEND_INIT_STATIC_METHOD_CALL
110 					&& !(func->op_array.fn_flags & ZEND_ACC_STATIC)) {
111 				/* Don't inline static call to instance method. */
112 				return;
113 			}
114 
115 			if (fcall->opcode == ZEND_INIT_METHOD_CALL && fcall->op1_type == IS_UNUSED) {
116 				/* TODO: we can't inlne methods, because $this may be used
117 				 *       not in object context ???
118 				 */
119 				return;
120 			}
121 
122 			for (i = 0; i < num_args; i++) {
123 				/* Don't inline functions with by-reference arguments. This would require
124 				 * correct handling of INDIRECT arguments. */
125 				if (func->op_array.arg_info[i].pass_by_reference) {
126 					return;
127 				}
128 			}
129 
130 			if (fcall->extended_value < func->op_array.num_args) {
131 				/* don't inline functions with named constants in default arguments */
132 				i = fcall->extended_value;
133 
134 				do {
135 					if (Z_TYPE_P(RT_CONSTANT(&func->op_array.opcodes[i], func->op_array.opcodes[i].op2)) == IS_CONSTANT_AST) {
136 						return;
137 					}
138 					i++;
139 				} while (i < func->op_array.num_args);
140 			}
141 
142 			if (RETURN_VALUE_USED(opline)) {
143 				zval zv;
144 
145 				ZVAL_COPY(&zv, RT_CONSTANT(ret_opline, ret_opline->op1));
146 				opline->opcode = ZEND_QM_ASSIGN;
147 				opline->op1_type = IS_CONST;
148 				opline->op1.constant = zend_optimizer_add_literal(op_array, &zv);
149 				SET_UNUSED(opline->op2);
150 			} else {
151 				MAKE_NOP(opline);
152 			}
153 
154 			zend_delete_call_instructions(opline-1);
155 		}
156 	}
157 }
158 
zend_optimize_func_calls(zend_op_array * op_array,zend_optimizer_ctx * ctx)159 void zend_optimize_func_calls(zend_op_array *op_array, zend_optimizer_ctx *ctx)
160 {
161 	zend_op *opline = op_array->opcodes;
162 	zend_op *end = opline + op_array->last;
163 	int call = 0;
164 	void *checkpoint;
165 	optimizer_call_info *call_stack;
166 
167 	if (op_array->last < 2) {
168 		return;
169 	}
170 
171 	checkpoint = zend_arena_checkpoint(ctx->arena);
172 	call_stack = zend_arena_calloc(&ctx->arena, op_array->last / 2, sizeof(optimizer_call_info));
173 	while (opline < end) {
174 		switch (opline->opcode) {
175 			case ZEND_INIT_FCALL_BY_NAME:
176 			case ZEND_INIT_NS_FCALL_BY_NAME:
177 			case ZEND_INIT_STATIC_METHOD_CALL:
178 			case ZEND_INIT_METHOD_CALL:
179 			case ZEND_INIT_FCALL:
180 			case ZEND_NEW:
181 				call_stack[call].func = zend_optimizer_get_called_func(
182 					ctx->script, op_array, opline, 0);
183 				call_stack[call].try_inline = opline->opcode != ZEND_NEW;
184 				/* break missing intentionally */
185 			case ZEND_INIT_DYNAMIC_CALL:
186 			case ZEND_INIT_USER_CALL:
187 				call_stack[call].opline = opline;
188 				call_stack[call].func_arg_num = (uint32_t)-1;
189 				call++;
190 				break;
191 			case ZEND_DO_FCALL:
192 			case ZEND_DO_ICALL:
193 			case ZEND_DO_UCALL:
194 			case ZEND_DO_FCALL_BY_NAME:
195 				call--;
196 				if (call_stack[call].func && call_stack[call].opline) {
197 					zend_op *fcall = call_stack[call].opline;
198 
199 					if (fcall->opcode == ZEND_INIT_FCALL) {
200 						/* nothing to do */
201 					} else if (fcall->opcode == ZEND_INIT_FCALL_BY_NAME) {
202 						fcall->opcode = ZEND_INIT_FCALL;
203 						fcall->op1.num = zend_vm_calc_used_stack(fcall->extended_value, call_stack[call].func);
204 						literal_dtor(&ZEND_OP2_LITERAL(fcall));
205 						fcall->op2.constant = fcall->op2.constant + 1;
206 						opline->opcode = zend_get_call_op(fcall, call_stack[call].func);
207 					} else if (fcall->opcode == ZEND_INIT_NS_FCALL_BY_NAME) {
208 						fcall->opcode = ZEND_INIT_FCALL;
209 						fcall->op1.num = zend_vm_calc_used_stack(fcall->extended_value, call_stack[call].func);
210 						literal_dtor(&op_array->literals[fcall->op2.constant]);
211 						literal_dtor(&op_array->literals[fcall->op2.constant + 2]);
212 						fcall->op2.constant = fcall->op2.constant + 1;
213 						opline->opcode = zend_get_call_op(fcall, call_stack[call].func);
214 					} else if (fcall->opcode == ZEND_INIT_STATIC_METHOD_CALL
215 							|| fcall->opcode == ZEND_INIT_METHOD_CALL
216 							|| fcall->opcode == ZEND_NEW) {
217 						/* We don't have specialized opcodes for this, do nothing */
218 					} else {
219 						ZEND_ASSERT(0);
220 					}
221 
222 					if ((ZEND_OPTIMIZER_PASS_16 & ctx->optimization_level)
223 					 && call_stack[call].try_inline) {
224 						zend_try_inline_call(op_array, fcall, opline, call_stack[call].func);
225 					}
226 				}
227 				call_stack[call].func = NULL;
228 				call_stack[call].opline = NULL;
229 				call_stack[call].try_inline = 0;
230 				call_stack[call].func_arg_num = (uint32_t)-1;
231 				break;
232 			case ZEND_FETCH_FUNC_ARG:
233 			case ZEND_FETCH_STATIC_PROP_FUNC_ARG:
234 			case ZEND_FETCH_OBJ_FUNC_ARG:
235 			case ZEND_FETCH_DIM_FUNC_ARG:
236 				if (call_stack[call - 1].func) {
237 					ZEND_ASSERT(call_stack[call - 1].func_arg_num != (uint32_t)-1);
238 					if (ARG_SHOULD_BE_SENT_BY_REF(call_stack[call - 1].func, call_stack[call - 1].func_arg_num)) {
239 						if (opline->opcode != ZEND_FETCH_STATIC_PROP_FUNC_ARG) {
240 							opline->opcode -= 9;
241 						} else {
242 							opline->opcode = ZEND_FETCH_STATIC_PROP_W;
243 						}
244 					} else {
245 						if (opline->opcode == ZEND_FETCH_DIM_FUNC_ARG
246 								&& opline->op2_type == IS_UNUSED) {
247 							/* FETCH_DIM_FUNC_ARG supports UNUSED op2, while FETCH_DIM_R does not.
248 							 * Performing the replacement would create an invalid opcode. */
249 							call_stack[call - 1].try_inline = 0;
250 							break;
251 						}
252 
253 						if (opline->opcode != ZEND_FETCH_STATIC_PROP_FUNC_ARG) {
254 							opline->opcode -= 12;
255 						} else {
256 							opline->opcode = ZEND_FETCH_STATIC_PROP_R;
257 						}
258 					}
259 				}
260 				break;
261 			case ZEND_SEND_VAL_EX:
262 				if (call_stack[call - 1].func) {
263 					if (ARG_MUST_BE_SENT_BY_REF(call_stack[call - 1].func, opline->op2.num)) {
264 						/* We won't convert it into_DO_FCALL to emit error at run-time */
265 						call_stack[call - 1].opline = NULL;
266 					} else {
267 						opline->opcode = ZEND_SEND_VAL;
268 					}
269 				}
270 				break;
271 			case ZEND_CHECK_FUNC_ARG:
272 				if (call_stack[call - 1].func) {
273 					call_stack[call - 1].func_arg_num = opline->op2.num;
274 					MAKE_NOP(opline);
275 				}
276 				break;
277 			case ZEND_SEND_VAR_EX:
278 			case ZEND_SEND_FUNC_ARG:
279 				if (call_stack[call - 1].func) {
280 					call_stack[call - 1].func_arg_num = (uint32_t)-1;
281 					if (ARG_SHOULD_BE_SENT_BY_REF(call_stack[call - 1].func, opline->op2.num)) {
282 						opline->opcode = ZEND_SEND_REF;
283 					} else {
284 						opline->opcode = ZEND_SEND_VAR;
285 					}
286 				}
287 				break;
288 			case ZEND_SEND_VAR_NO_REF_EX:
289 				if (call_stack[call - 1].func) {
290 					if (ARG_MUST_BE_SENT_BY_REF(call_stack[call - 1].func, opline->op2.num)) {
291 						opline->opcode = ZEND_SEND_VAR_NO_REF;
292 					} else if (ARG_MAY_BE_SENT_BY_REF(call_stack[call - 1].func, opline->op2.num)) {
293 						opline->opcode = ZEND_SEND_VAL;
294 					} else {
295 						opline->opcode = ZEND_SEND_VAR;
296 					}
297 				}
298 				break;
299 			case ZEND_SEND_UNPACK:
300 			case ZEND_SEND_USER:
301 			case ZEND_SEND_ARRAY:
302 				call_stack[call - 1].try_inline = 0;
303 				break;
304 			default:
305 				break;
306 		}
307 		opline++;
308 	}
309 
310 	zend_arena_release(&ctx->arena, checkpoint);
311 }
312