Bug #77275 [Opn->Ver]: OPcache optimization problem for ArrayAccess->offsetGet(string)

From: Date: Mon, 10 Dec 2018 11:12:41 +0000
Subject: Bug #77275 [Opn->Ver]: OPcache optimization problem for ArrayAccess->offsetGet(string)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218357@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77275&edit=1 ID: 77275 Updated by: nikic@php.net Reported by: kentaro at ranvis dot com Summary: OPcache optimization problem for ArrayAccess->offsetGet(string) -Status: Open +Status: Verified Type: Bug Package: opcache Operating System: Windows 10 PHP Version: 7.3.0 Block user comment: N Private report: N New Comment: Can reproduce under valgrind: ==23813== Conditional jump or move depends on uninitialised value(s) ==23813== at 0x91B2F8: ZEND_FETCH_DIM_R_SPEC_CV_CONST_HANDLER (zend_vm_execute.h:39179) ==23813== by 0x93A255: execute_ex (zend_vm_execute.h:59027) ==23813== by 0x93B63D: zend_execute (zend_vm_execute.h:60215) ==23813== by 0x84E2D7: zend_execute_scripts (zend.c:1615) ==23813== by 0x789D5C: php_execute_script (main.c:2641) ==23813== by 0x93E6BA: do_cli (php_cli.c:997) ==23813== by 0x93FB05: main (php_cli.c:1389) Previous Comments: ------------------------------------------------------------------------ [2018-12-10 11:06:38] nikic@php.net Can't repro on Ubuntu, though the issue is certainly plausible. At a guess the second literal for the the offset lookup is not being preserved and being overwritten. ------------------------------------------------------------------------ [2018-12-10 05:46:36] kentaro at ranvis dot com Description: ------------ In a certain condition, a call to the class method offsetGet() via $instance['literalString'] is turned into $instance[anotherLiteral] when OPcache is enabled. Steps to reproduce: 1. On Windows x64, extract php-7.3.0-nts-Win32-VC15-x64.zip into the current directory 2. Save test script as test.php 3. Make sure no PHP built-in server is running (as shared memory matters?) 4. Launch PHP built-in server by running a command: php -c php.ini-development -d extension_dir=ext -d zend_extension=php_opcache.dll -S 127.0.0.1:8000 5. Open browser and go to http://127.0.0.1:8000/test.php The output is: string(1) "a" 6. Touch test.php to update the modification time, and wait 3 seconds (opcache.revalidate_freq) 7. Reload the browser and confirm the output Test script: --------------- <?php namespace Foo; class Bar { public function get() {} } class Record implements \ArrayAccess { public function offsetSet($offset, $value) { throw new \Exception; } public function offsetGet($offset) { var_dump($offset); } public function offsetExists($offset) { throw new \Exception; } public function offsetUnset($offset) { throw new \Exception; } } class Baz { public function run() { $a = pow(1, 2); $b = new Bar(); $c = new Bar(); $d = new Bar(); $id = $b->get('a', 'b', 'c'); $rec = new Record(); $id = $rec['a']; } } (new Baz())->run(); Expected result: ---------------- The output is: string(1) "a" Actual result: -------------- The output is: string(1) "b" ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77275&edit=1

« previous php.bugs (#218357) next »