Skip to content

Commit c0bb238

Browse files
committed
Fixed reference counting inference
Fixes oss-fuzz #46084
1 parent 9cb512e commit c0bb238

File tree

2 files changed

+34
-0
lines changed

2 files changed

+34
-0
lines changed

ext/opcache/Optimizer/zend_inference.c

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3311,6 +3311,20 @@ static zend_always_inline int _zend_update_type_info(
33113311
if (opline->opcode == ZEND_FETCH_DIM_IS && (t1 & MAY_BE_STRING)) {
33123312
tmp |= MAY_BE_NULL;
33133313
}
3314+
if ((tmp & (MAY_BE_RC1|MAY_BE_RCN)) == MAY_BE_RCN && opline->result_type == IS_TMP_VAR) {
3315+
/* refcount may be indirectly decremented. Make an exception if the result is used in the next instruction */
3316+
if (!ssa_opcodes) {
3317+
if (ssa->vars[ssa_op->result_def].use_chain < 0
3318+
|| opline + 1 != op_array->opcodes + ssa->vars[ssa_op->result_def].use_chain) {
3319+
tmp |= MAY_BE_RC1;
3320+
}
3321+
} else {
3322+
if (ssa->vars[ssa_op->result_def].use_chain < 0
3323+
|| opline + 1 != ssa_opcodes[ssa->vars[ssa_op->result_def].use_chain]) {
3324+
tmp |= MAY_BE_RC1;
3325+
}
3326+
}
3327+
}
33143328
UPDATE_SSA_TYPE(tmp, ssa_op->result_def);
33153329
break;
33163330
case ZEND_FETCH_THIS:
Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
--TEST--
2+
JIT FETCH_DIM_R: 013
3+
--INI--
4+
opcache.enable=1
5+
opcache.enable_cli=1
6+
opcache.file_update_protection=0
7+
opcache.jit_buffer_size=1M
8+
--FILE--
9+
<?php
10+
function foo() {
11+
$y = 0; $tokens = [];
12+
for($cnt = 0; $cnt < 6; $cnt++) {
13+
$tokens[$y] > $tokens[$y][] = $y;
14+
}
15+
}
16+
@foo();
17+
?>
18+
DONE
19+
--EXPECT--
20+
DONE

0 commit comments

Comments
 (0)