[php-src] Issue #8642: JIT trace not invalidated after re-linking
| From: | arnaud-lb | Date: | Fri, 27 May 2022 11:44:46 +0000 |
| Subject: | [php-src] Issue #8642: JIT trace not invalidated after re-linking | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-241604@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/8642
Author: arnaud-lb
### Description
JIT traces are not invalidated after a class is re-linked. The JIT code may make assumptions that
are not true anymore after re-linking.
For example, in
``` php
<?php
$a=0;
class A implement Iface {
public function hello() {
global $a;
for ($i = 0; $i < 100; $i++) {
$a++;
}
}
}
```
we may still enter in the JITed loop after
A has been re-linked (A can be
re-link due to Iface being recompiled for example). The JITed code may be based on
assumptions that are not true anymore (at least the run_time_cache pointer changes
during linking, but I suspect that other assumptions can be made based on the parent classes or
interfaces, that do not hold true after re-linking).
This is due to op_array.oplines being shared between all linked versions of the same
class. oplines has pointers to JITed code.
### PHP Version
PHP 8.1
### Operating System
_No response_