[php-src] Issue #12672: Wrong offset key is reported in E_WARNING message with function JIT
| From: | pfustc | Date: | Wed, 15 Nov 2023 08:25:35 +0000 |
| Subject: | [php-src] Issue #12672: Wrong offset key is reported in E_WARNING message with function JIT | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-245803@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/12672
Author: pfustc
### Description
Hi @dstogov, below bug is found with CALL VM, function JIT and release build on my Mac (M1,
AArch64). So far, I haven't reproduced it on Linux AArch64.
The following code:
```php
<?php
function test() {
$a[6] = 0;
echo $a[5];
}
test();
?>
```
with php.ini:
```ini
opcache.enable_cli=1
opcache.jit=function
opcache.jit_buffer_size=16M
opcache.jit_hot_func=1
opcache.jit_hot_loop=1
opcache.jit_hot_return=1
opcache.jit_hot_side_exit=1
zend.assertions=1
```
Resulted in this output:
```
Warning: Undefined array key 6097925520 in /Users/penli01/work/www/index.php on line 4
```
But I expected this output instead:
```
Warning: Undefined array key 5 in /Users/penli01/work/www/index.php on line 4
```
Wrong offset key is reported in the warning message when using function JIT. Tracing JIT is OK based
on my test.
IR dump at codegen
```c
JIT$test: ; codegen
{
uintptr_t c_1 = 0;
bool c_2 = 0;
bool c_3 = 1;
int64_t c_4 = 5;
uintptr_t c_5 = 0x10677c828;
uintptr_t c_6 = 0x50;
uintptr_t c_7 = 0x10;
uintptr_t c_8 = 0x10677c820;
uintptr_t c_9 = 0x8;
uintptr_t c_10 = 0x58;
uintptr_t c_11 = func_addr(0x10dea4820, 2);
uintptr_t c_12 = 0x50;
uintptr_t c_13 = 0x58;
uintptr_t c_14 = 0x105590c58;
uintptr_t c_15 = 0x10dea4230;
uintptr_t c_16 = 0x20;
uintptr_t c_17 = func_addr(0x10491fc58, 2);
uint32_t c_18 = 1;
uintptr_t c_19 = 0x105590ae0;
uintptr_t c_20 = 0x30;
uintptr_t c_21 = 0x28;
uint32_t c_22 = 144572416;
uintptr_t c_23 = 0x10dea4400;
uintptr_t c_24 = 0x105590ac0;
uintptr_t c_25 = 0x105590c58;
uintptr_t c_26 = 0x10dea4610;
int32_t c_27 = 2;
#BB1:
l_1 = START(l_68); # RULE(NOP:SKIPPED)
uintptr_t d_2 {R1} {%x0} = PARAM(l_1, "execute_data", 1); # RULE(PARAM)
l_3 = RSTORE(l_1, d_2 {R1} {%x0}, 27); # RULE(RSTORE)
uint32_t d_4 {R2} {%w0}, l_4 = LOAD(l_3, c_5); # RULE(LOAD_INT)
int64_t d_5 {R3} {%x0} = ZEXT(d_4 {R2} {%w0}); # RULE(ZEXT)
bool d_6 = UGT(d_5 {R3} {%x0}, c_4); # RULE(CMP_INT:FUSED)
l_7 = IF(l_4, d_6); # RULE(CMP_AND_BRANCH_INT)
# IF_TRUE BB2, IF_FALSE BB7
#BB2:
l_10 = IF_TRUE(l_7); # RULE(NOP:SKIPPED)
uintptr_t d_11 {R4} {%x0}, l_11 = LOAD(l_10, c_8); # RULE(LOAD_INT)
uintptr_t d_12 = ADD(d_11 {R4} {%x0}, c_10); # RULE(ADD:FUSED:SIMPLE)
uint8_t d_13 {R5} {%w1}, l_13 = LOAD(l_11, d_12); # RULE(LOAD_INT)
l_14 = IF(l_13, d_13 {R5} {%w1}); # RULE(IF_INT)
# IF_TRUE BB3, IF_FALSE BB9
#BB3:
l_17 = IF_TRUE(l_14); # RULE(NOP:SKIPPED)
uintptr_t d_18 = ADD(d_11 {R4} {%x0}, c_6); # RULE(ADD:FUSED:SIMPLE)
uintptr_t d_19 {R6} {%x1}, l_19 = LOAD(l_17, d_18); # RULE(LOAD_INT)
uintptr_t d_20, l_20 = RLOAD(l_19, 27); # RULE(RLOAD:SKIPPED)
uintptr_t d_21 = ADD(d_20 {%x27}, c_12); # RULE(ADD:FUSED:SIMPLE)
l_22 = STORE(l_20, d_21, d_19 {R6} {%x1}); # RULE(STORE_INT)
uint32_t d_23 {R7} {%w0}, l_23 = LOAD(l_22, d_12); # RULE(LOAD_INT)
uintptr_t d_24 = ADD(d_20 {%x27}, c_13); # RULE(ADD:FUSED:SIMPLE)
l_25 = STORE(l_23, d_24, d_23 {R7} {%w0}); # RULE(STORE_INT)
l_26 = END(l_25); # RULE(END)
#BB4:
l_30 = MERGE(l_29, l_26); # RULE(NOP:SKIPPED)
uintptr_t d_31 {R8} {%x0}, l_31 = LOAD(l_30, c_14); # RULE(LOAD_INT)
l_32 = GUARD_NOT(l_31, d_31 {R8} {%x0}, c_15); # RULE(GUARD_NOT)
uintptr_t d_33, l_33 = RLOAD(l_32, 27); # RULE(RLOAD:SKIPPED)
uintptr_t d_34 {R9} {%x0}, l_34 = LOAD(l_33, d_33 {%x27}); # RULE(LOAD_INT)
uintptr_t d_35 {R10} {%x0} = ADD(d_34 {R9} {%x0}, c_16); # RULE(BINOP_INT)
l_36 = STORE(l_34, d_33 {%x27}, d_35 {R10} {%x0}); # RULE(STORE_INT)
l_37 = CALL/1(l_36, c_17, d_33 {%x27}); # RULE(CALL)
uintptr_t d_38 {R11} {%x0}, l_38 = LOAD(l_37, c_14); # RULE(LOAD_INT)
l_39 = GUARD_NOT(l_38, d_38 {R11} {%x0}, c_15); # RULE(GUARD_NOT)
uintptr_t d_40, l_40 = RLOAD(l_39, 27); # RULE(RLOAD:SKIPPED)
uintptr_t d_41 = ADD(d_40 {%x27}, c_7); # RULE(ADD:FUSED:SIMPLE)
uintptr_t d_42 {R12} {%x0}, l_42 = LOAD(l_40, d_41); # RULE(LOAD_INT)
l_43 = IF(l_42, d_42 {R12} {%x0}); # RULE(IF_INT)
# IF_TRUE BB5, IF_FALSE BB10
#BB5:
l_46 = IF_TRUE(l_43); # RULE(NOP:SKIPPED)
uintptr_t d_47 = ADD(d_42 {R12} {%x0}, c_9); # RULE(ADD:FUSED:SIMPLE)
l_48 = STORE(l_46, d_47, c_18 {%w1}); # RULE(STORE_INT)
l_49 = END(l_48); # RULE(END)
#BB6:
l_50 = MERGE(l_45, l_49); # RULE(NOP:SKIPPED)
uintptr_t d_51, l_51 = RLOAD(l_50, 27); # RULE(RLOAD:SKIPPED)
uintptr_t d_52 = ADD(d_51 {%x27}, c_20); # RULE(ADD:FUSED:SIMPLE)
uintptr_t d_53 {R13} {%x0}, l_53 = LOAD(l_51, d_52); # RULE(LOAD_INT)
l_54 = STORE(l_53, c_19 {%x1}, d_53 {R13} {%x0}); # RULE(STORE_INT)
uintptr_t d_55 = ADD(d_51 {%x27}, c_21); # RULE(ADD:FUSED:SIMPLE)
uint32_t d_56 {R14} {%w0}, l_56 = LOAD(l_54, d_55); # RULE(LOAD_INT)
uint32_t d_57 {R15} {%w0} = AND(d_56 {R14} {%w0}, c_22 {%w1}); # RULE(BINOP_INT)
l_58 = GUARD_NOT(l_56, d_57 {R15} {%w0}, c_23); # RULE(GUARD_NOT)
l_59 = STORE(l_58, c_24 {%x0}, d_51 {%x27}); # RULE(STORE_INT)
uintptr_t d_60 {R16} {%x0}, l_60 = LOAD(l_59, d_52); # RULE(LOAD_INT)
l_61 = RSTORE(l_60, d_60 {R16} {%x0}, 27); # RULE(RSTORE)
uintptr_t d_62 {R17} {%x0}, l_62 = LOAD(l_61, c_25); # RULE(LOAD_INT)
l_63 = GUARD_NOT(l_62, d_62 {R17} {%x0}, c_26); # RULE(GUARD_NOT)
uintptr_t d_64, l_64 = RLOAD(l_63, 27); # RULE(RLOAD:SKIPPED)
uintptr_t d_65 {R18} {%x0}, l_65 = LOAD(l_64, d_64 {%x27}); # RULE(LOAD_INT)
uintptr_t d_66 {R19} {%x0} = ADD(d_65 {R18} {%x0}, c_16); # RULE(BINOP_INT)
l_67 = STORE(l_65, d_64 {%x27}, d_66 {R19} {%x0}); # RULE(STORE_INT)
l_68 = RETURN(l_67, c_27); # RULE(RETURN_INT)
#BB7:
l_8 = IF_FALSE(l_7); # RULE(NOP:SKIPPED)
l_9 = END(l_8); # RULE(END)
#BB8:
l_27 = MERGE(l_9, l_16); # RULE(NOP:SKIPPED)
l_28 = CALL(l_27, c_11); # RULE(CALL)
l_29 = END(l_28); # RULE(END)
# GOTO BB4
#BB9:
l_15 = IF_FALSE(l_14); # RULE(NOP:SKIPPED)
l_16 = END(l_15); # RULE(END)
# GOTO BB8
#BB10:
l_44 = IF_FALSE(l_43, 1); # RULE(NOP:SKIPPED)
l_45 = END(l_44); # RULE(END)
# GOTO BB6
}
```
### PHP Version
master @ https://github.com/php/php-src/commit/2ca142ecd8e3af5a2ac09938546b57123d01297d
### Operating System
MacOS 14.1.1