[php-src] Issue #12672: Wrong offset key is reported in E_WARNING message with function JIT

From: Date: Wed, 15 Nov 2023 08:25:35 +0000
Subject: [php-src] Issue #12672: Wrong offset key is reported in E_WARNING message with function JIT
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-245803@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/12672 Author: pfustc ### Description Hi @dstogov, below bug is found with CALL VM, function JIT and release build on my Mac (M1, AArch64). So far, I haven't reproduced it on Linux AArch64. The following code: ```php <?php function test() { $a[6] = 0; echo $a[5]; } test(); ?> ``` with php.ini: ```ini opcache.enable_cli=1 opcache.jit=function opcache.jit_buffer_size=16M opcache.jit_hot_func=1 opcache.jit_hot_loop=1 opcache.jit_hot_return=1 opcache.jit_hot_side_exit=1 zend.assertions=1 ``` Resulted in this output: ``` Warning: Undefined array key 6097925520 in /Users/penli01/work/www/index.php on line 4 ``` But I expected this output instead: ``` Warning: Undefined array key 5 in /Users/penli01/work/www/index.php on line 4 ``` Wrong offset key is reported in the warning message when using function JIT. Tracing JIT is OK based on my test. IR dump at codegen ```c JIT$test: ; codegen { uintptr_t c_1 = 0; bool c_2 = 0; bool c_3 = 1; int64_t c_4 = 5; uintptr_t c_5 = 0x10677c828; uintptr_t c_6 = 0x50; uintptr_t c_7 = 0x10; uintptr_t c_8 = 0x10677c820; uintptr_t c_9 = 0x8; uintptr_t c_10 = 0x58; uintptr_t c_11 = func_addr(0x10dea4820, 2); uintptr_t c_12 = 0x50; uintptr_t c_13 = 0x58; uintptr_t c_14 = 0x105590c58; uintptr_t c_15 = 0x10dea4230; uintptr_t c_16 = 0x20; uintptr_t c_17 = func_addr(0x10491fc58, 2); uint32_t c_18 = 1; uintptr_t c_19 = 0x105590ae0; uintptr_t c_20 = 0x30; uintptr_t c_21 = 0x28; uint32_t c_22 = 144572416; uintptr_t c_23 = 0x10dea4400; uintptr_t c_24 = 0x105590ac0; uintptr_t c_25 = 0x105590c58; uintptr_t c_26 = 0x10dea4610; int32_t c_27 = 2; #BB1: l_1 = START(l_68); # RULE(NOP:SKIPPED) uintptr_t d_2 {R1} {%x0} = PARAM(l_1, "execute_data", 1); # RULE(PARAM) l_3 = RSTORE(l_1, d_2 {R1} {%x0}, 27); # RULE(RSTORE) uint32_t d_4 {R2} {%w0}, l_4 = LOAD(l_3, c_5); # RULE(LOAD_INT) int64_t d_5 {R3} {%x0} = ZEXT(d_4 {R2} {%w0}); # RULE(ZEXT) bool d_6 = UGT(d_5 {R3} {%x0}, c_4); # RULE(CMP_INT:FUSED) l_7 = IF(l_4, d_6); # RULE(CMP_AND_BRANCH_INT) # IF_TRUE BB2, IF_FALSE BB7 #BB2: l_10 = IF_TRUE(l_7); # RULE(NOP:SKIPPED) uintptr_t d_11 {R4} {%x0}, l_11 = LOAD(l_10, c_8); # RULE(LOAD_INT) uintptr_t d_12 = ADD(d_11 {R4} {%x0}, c_10); # RULE(ADD:FUSED:SIMPLE) uint8_t d_13 {R5} {%w1}, l_13 = LOAD(l_11, d_12); # RULE(LOAD_INT) l_14 = IF(l_13, d_13 {R5} {%w1}); # RULE(IF_INT) # IF_TRUE BB3, IF_FALSE BB9 #BB3: l_17 = IF_TRUE(l_14); # RULE(NOP:SKIPPED) uintptr_t d_18 = ADD(d_11 {R4} {%x0}, c_6); # RULE(ADD:FUSED:SIMPLE) uintptr_t d_19 {R6} {%x1}, l_19 = LOAD(l_17, d_18); # RULE(LOAD_INT) uintptr_t d_20, l_20 = RLOAD(l_19, 27); # RULE(RLOAD:SKIPPED) uintptr_t d_21 = ADD(d_20 {%x27}, c_12); # RULE(ADD:FUSED:SIMPLE) l_22 = STORE(l_20, d_21, d_19 {R6} {%x1}); # RULE(STORE_INT) uint32_t d_23 {R7} {%w0}, l_23 = LOAD(l_22, d_12); # RULE(LOAD_INT) uintptr_t d_24 = ADD(d_20 {%x27}, c_13); # RULE(ADD:FUSED:SIMPLE) l_25 = STORE(l_23, d_24, d_23 {R7} {%w0}); # RULE(STORE_INT) l_26 = END(l_25); # RULE(END) #BB4: l_30 = MERGE(l_29, l_26); # RULE(NOP:SKIPPED) uintptr_t d_31 {R8} {%x0}, l_31 = LOAD(l_30, c_14); # RULE(LOAD_INT) l_32 = GUARD_NOT(l_31, d_31 {R8} {%x0}, c_15); # RULE(GUARD_NOT) uintptr_t d_33, l_33 = RLOAD(l_32, 27); # RULE(RLOAD:SKIPPED) uintptr_t d_34 {R9} {%x0}, l_34 = LOAD(l_33, d_33 {%x27}); # RULE(LOAD_INT) uintptr_t d_35 {R10} {%x0} = ADD(d_34 {R9} {%x0}, c_16); # RULE(BINOP_INT) l_36 = STORE(l_34, d_33 {%x27}, d_35 {R10} {%x0}); # RULE(STORE_INT) l_37 = CALL/1(l_36, c_17, d_33 {%x27}); # RULE(CALL) uintptr_t d_38 {R11} {%x0}, l_38 = LOAD(l_37, c_14); # RULE(LOAD_INT) l_39 = GUARD_NOT(l_38, d_38 {R11} {%x0}, c_15); # RULE(GUARD_NOT) uintptr_t d_40, l_40 = RLOAD(l_39, 27); # RULE(RLOAD:SKIPPED) uintptr_t d_41 = ADD(d_40 {%x27}, c_7); # RULE(ADD:FUSED:SIMPLE) uintptr_t d_42 {R12} {%x0}, l_42 = LOAD(l_40, d_41); # RULE(LOAD_INT) l_43 = IF(l_42, d_42 {R12} {%x0}); # RULE(IF_INT) # IF_TRUE BB5, IF_FALSE BB10 #BB5: l_46 = IF_TRUE(l_43); # RULE(NOP:SKIPPED) uintptr_t d_47 = ADD(d_42 {R12} {%x0}, c_9); # RULE(ADD:FUSED:SIMPLE) l_48 = STORE(l_46, d_47, c_18 {%w1}); # RULE(STORE_INT) l_49 = END(l_48); # RULE(END) #BB6: l_50 = MERGE(l_45, l_49); # RULE(NOP:SKIPPED) uintptr_t d_51, l_51 = RLOAD(l_50, 27); # RULE(RLOAD:SKIPPED) uintptr_t d_52 = ADD(d_51 {%x27}, c_20); # RULE(ADD:FUSED:SIMPLE) uintptr_t d_53 {R13} {%x0}, l_53 = LOAD(l_51, d_52); # RULE(LOAD_INT) l_54 = STORE(l_53, c_19 {%x1}, d_53 {R13} {%x0}); # RULE(STORE_INT) uintptr_t d_55 = ADD(d_51 {%x27}, c_21); # RULE(ADD:FUSED:SIMPLE) uint32_t d_56 {R14} {%w0}, l_56 = LOAD(l_54, d_55); # RULE(LOAD_INT) uint32_t d_57 {R15} {%w0} = AND(d_56 {R14} {%w0}, c_22 {%w1}); # RULE(BINOP_INT) l_58 = GUARD_NOT(l_56, d_57 {R15} {%w0}, c_23); # RULE(GUARD_NOT) l_59 = STORE(l_58, c_24 {%x0}, d_51 {%x27}); # RULE(STORE_INT) uintptr_t d_60 {R16} {%x0}, l_60 = LOAD(l_59, d_52); # RULE(LOAD_INT) l_61 = RSTORE(l_60, d_60 {R16} {%x0}, 27); # RULE(RSTORE) uintptr_t d_62 {R17} {%x0}, l_62 = LOAD(l_61, c_25); # RULE(LOAD_INT) l_63 = GUARD_NOT(l_62, d_62 {R17} {%x0}, c_26); # RULE(GUARD_NOT) uintptr_t d_64, l_64 = RLOAD(l_63, 27); # RULE(RLOAD:SKIPPED) uintptr_t d_65 {R18} {%x0}, l_65 = LOAD(l_64, d_64 {%x27}); # RULE(LOAD_INT) uintptr_t d_66 {R19} {%x0} = ADD(d_65 {R18} {%x0}, c_16); # RULE(BINOP_INT) l_67 = STORE(l_65, d_64 {%x27}, d_66 {R19} {%x0}); # RULE(STORE_INT) l_68 = RETURN(l_67, c_27); # RULE(RETURN_INT) #BB7: l_8 = IF_FALSE(l_7); # RULE(NOP:SKIPPED) l_9 = END(l_8); # RULE(END) #BB8: l_27 = MERGE(l_9, l_16); # RULE(NOP:SKIPPED) l_28 = CALL(l_27, c_11); # RULE(CALL) l_29 = END(l_28); # RULE(END) # GOTO BB4 #BB9: l_15 = IF_FALSE(l_14); # RULE(NOP:SKIPPED) l_16 = END(l_15); # RULE(END) # GOTO BB8 #BB10: l_44 = IF_FALSE(l_43, 1); # RULE(NOP:SKIPPED) l_45 = END(l_44); # RULE(END) # GOTO BB6 } ``` ### PHP Version master @ https://github.com/php/php-src/commit/2ca142ecd8e3af5a2ac09938546b57123d01297d ### Operating System MacOS 14.1.1

« previous php.bugs (#245803) next »