1/*
2   +----------------------------------------------------------------------+
3   | Zend Engine                                                          |
4   +----------------------------------------------------------------------+
5   | Copyright (c) 1998-2016 Zend Technologies Ltd. (http://www.zend.com) |
6   +----------------------------------------------------------------------+
7   | This source file is subject to version 2.00 of the Zend license,     |
8   | that is bundled with this package in the file LICENSE, and is        |
9   | available through the world-wide-web at the following url:           |
10   | http://www.zend.com/license/2_00.txt.                                |
11   | If you did not receive a copy of the Zend license and are unable to  |
12   | obtain it through the world-wide-web, please send a note to          |
13   | license@zend.com so we can mail you a copy immediately.              |
14   +----------------------------------------------------------------------+
15   | Authors: Andi Gutmans <andi@zend.com>                                |
16   |          Zeev Suraski <zeev@zend.com>                                |
17   |          Dmitry Stogov <dmitry@zend.com>                             |
18   +----------------------------------------------------------------------+
19*/
20
21/* $Id$ */
22
23#define ZEND_INTENSIVE_DEBUGGING 0
24
25#include <stdio.h>
26#include <signal.h>
27
28#include "zend.h"
29#include "zend_compile.h"
30#include "zend_execute.h"
31#include "zend_API.h"
32#include "zend_ptr_stack.h"
33#include "zend_constants.h"
34#include "zend_extensions.h"
35#include "zend_ini.h"
36#include "zend_exceptions.h"
37#include "zend_interfaces.h"
38#include "zend_closures.h"
39#include "zend_generators.h"
40#include "zend_vm.h"
41#include "zend_dtrace.h"
42#include "zend_inheritance.h"
43#include "zend_type_info.h"
44
45/* Virtual current working directory support */
46#include "zend_virtual_cwd.h"
47
48#define _CONST_CODE  0
49#define _TMP_CODE    1
50#define _VAR_CODE    2
51#define _UNUSED_CODE 3
52#define _CV_CODE     4
53
54typedef int (ZEND_FASTCALL *incdec_t)(zval *);
55
56#define get_zval_ptr(op_type, node, ex, should_free, type) _get_zval_ptr(op_type, node, ex, should_free, type)
57#define get_zval_ptr_deref(op_type, node, ex, should_free, type) _get_zval_ptr_deref(op_type, node, ex, should_free, type)
58#define get_zval_ptr_r(op_type, node, ex, should_free) _get_zval_ptr_r(op_type, node, ex, should_free)
59#define get_zval_ptr_r_deref(op_type, node, ex, should_free) _get_zval_ptr_r_deref(op_type, node, ex, should_free)
60#define get_zval_ptr_undef(op_type, node, ex, should_free, type) _get_zval_ptr_undef(op_type, node, ex, should_free, type)
61#define get_zval_ptr_ptr(op_type, node, ex, should_free, type) _get_zval_ptr_ptr(op_type, node, ex, should_free, type)
62#define get_zval_ptr_ptr_undef(op_type, node, ex, should_free, type) _get_zval_ptr_ptr(op_type, node, ex, should_free, type)
63#define get_obj_zval_ptr(op_type, node, ex, should_free, type) _get_obj_zval_ptr(op_type, node, ex, should_free, type)
64#define get_obj_zval_ptr_undef(op_type, node, ex, should_free, type) _get_obj_zval_ptr_undef(op_type, node, ex, should_free, type)
65#define get_obj_zval_ptr_ptr(op_type, node, ex, should_free, type) _get_obj_zval_ptr_ptr(op_type, node, ex, should_free, type)
66
67/* Prototypes */
68static void zend_extension_statement_handler(const zend_extension *extension, zend_execute_data *frame);
69static void zend_extension_fcall_begin_handler(const zend_extension *extension, zend_execute_data *frame);
70static void zend_extension_fcall_end_handler(const zend_extension *extension, zend_execute_data *frame);
71
72#define RETURN_VALUE_USED(opline) ((opline)->result_type != IS_UNUSED)
73
74static ZEND_FUNCTION(pass)
75{
76}
77
78ZEND_API const zend_internal_function zend_pass_function = {
79	ZEND_INTERNAL_FUNCTION, /* type              */
80	{0, 0, 0},              /* arg_flags         */
81	0,                      /* fn_flags          */
82	NULL,                   /* name              */
83	NULL,                   /* scope             */
84	NULL,                   /* prototype         */
85	0,                      /* num_args          */
86	0,                      /* required_num_args */
87	NULL,                   /* arg_info          */
88	ZEND_FN(pass),          /* handler           */
89	NULL,                   /* module            */
90	{NULL,NULL,NULL,NULL}   /* reserved          */
91};
92
93#undef zval_ptr_dtor
94#define zval_ptr_dtor(zv) i_zval_ptr_dtor(zv ZEND_FILE_LINE_CC)
95
96#define READY_TO_DESTROY(zv) \
97	(UNEXPECTED(zv) && Z_REFCOUNTED_P(zv) && Z_REFCOUNT_P(zv) == 1)
98
99#define EXTRACT_ZVAL_PTR(zv) do {		\
100	zval *__zv = (zv);								\
101	if (EXPECTED(Z_TYPE_P(__zv) == IS_INDIRECT)) {	\
102		ZVAL_COPY(__zv, Z_INDIRECT_P(__zv));	    \
103	}												\
104} while (0)
105
106#define FREE_OP(should_free) \
107	if (should_free) { \
108		zval_ptr_dtor_nogc(should_free); \
109	}
110
111#define FREE_UNFETCHED_OP(type, var) \
112	if ((type) & (IS_TMP_VAR|IS_VAR)) { \
113		zval_ptr_dtor_nogc(EX_VAR(var)); \
114	}
115
116#define FREE_OP_VAR_PTR(should_free) \
117	if (should_free) { \
118		zval_ptr_dtor_nogc(should_free); \
119	}
120
121#define CV_DEF_OF(i) (EX(func)->op_array.vars[i])
122
123#define ZEND_VM_MAIN_STACK_PAGE_SLOTS (16 * 1024) /* should be a power of 2 */
124#define ZEND_VM_GENERATOR_STACK_PAGE_SLOTS (256)
125
126#define ZEND_VM_STACK_PAGE_SLOTS(gen) ((gen) ? ZEND_VM_GENERATOR_STACK_PAGE_SLOTS : ZEND_VM_MAIN_STACK_PAGE_SLOTS)
127
128#define ZEND_VM_STACK_PAGE_SIZE(gen)  (ZEND_VM_STACK_PAGE_SLOTS(gen) * sizeof(zval))
129
130#define ZEND_VM_STACK_FREE_PAGE_SIZE(gen) \
131	((ZEND_VM_STACK_PAGE_SLOTS(gen) - ZEND_VM_STACK_HEADER_SLOTS) * sizeof(zval))
132
133#define ZEND_VM_STACK_PAGE_ALIGNED_SIZE(gen, size) \
134	(((size) + (ZEND_VM_STACK_FREE_PAGE_SIZE(gen) - 1)) & ~(ZEND_VM_STACK_PAGE_SIZE(gen) - 1))
135
136static zend_always_inline zend_vm_stack zend_vm_stack_new_page(size_t size, zend_vm_stack prev) {
137	zend_vm_stack page = (zend_vm_stack)emalloc(size);
138
139	page->top = ZEND_VM_STACK_ELEMENTS(page);
140	page->end = (zval*)((char*)page + size);
141	page->prev = prev;
142	return page;
143}
144
145ZEND_API void zend_vm_stack_init(void)
146{
147	EG(vm_stack) = zend_vm_stack_new_page(ZEND_VM_STACK_PAGE_SIZE(0 /* main stack */), NULL);
148	EG(vm_stack)->top++;
149	EG(vm_stack_top) = EG(vm_stack)->top;
150	EG(vm_stack_end) = EG(vm_stack)->end;
151}
152
153ZEND_API void zend_vm_stack_destroy(void)
154{
155	zend_vm_stack stack = EG(vm_stack);
156
157	while (stack != NULL) {
158		zend_vm_stack p = stack->prev;
159		efree(stack);
160		stack = p;
161	}
162}
163
164ZEND_API void* zend_vm_stack_extend(size_t size)
165{
166	zend_vm_stack stack;
167	void *ptr;
168
169	stack = EG(vm_stack);
170	stack->top = EG(vm_stack_top);
171	EG(vm_stack) = stack = zend_vm_stack_new_page(
172		EXPECTED(size < ZEND_VM_STACK_FREE_PAGE_SIZE(0)) ?
173			ZEND_VM_STACK_PAGE_SIZE(0) : ZEND_VM_STACK_PAGE_ALIGNED_SIZE(0, size),
174		stack);
175	ptr = stack->top;
176	EG(vm_stack_top) = (void*)(((char*)ptr) + size);
177	EG(vm_stack_end) = stack->end;
178	return ptr;
179}
180
181ZEND_API zval* zend_get_compiled_variable_value(const zend_execute_data *execute_data, uint32_t var)
182{
183	return EX_VAR(var);
184}
185
186static zend_always_inline zval *_get_zval_ptr_tmp(uint32_t var, const zend_execute_data *execute_data, zend_free_op *should_free)
187{
188	zval *ret = EX_VAR(var);
189	*should_free = ret;
190
191	ZEND_ASSERT(Z_TYPE_P(ret) != IS_REFERENCE);
192
193	return ret;
194}
195
196static zend_always_inline zval *_get_zval_ptr_var(uint32_t var, const zend_execute_data *execute_data, zend_free_op *should_free)
197{
198	zval *ret = EX_VAR(var);
199
200	*should_free = ret;
201	return ret;
202}
203
204static zend_always_inline zval *_get_zval_ptr_var_deref(uint32_t var, const zend_execute_data *execute_data, zend_free_op *should_free)
205{
206	zval *ret = EX_VAR(var);
207
208	*should_free = ret;
209	ZVAL_DEREF(ret);
210	return ret;
211}
212
213static zend_never_inline ZEND_COLD void zval_undefined_cv(uint32_t var, const zend_execute_data *execute_data)
214{
215	zend_string *cv = CV_DEF_OF(EX_VAR_TO_NUM(var));
216
217	zend_error(E_NOTICE, "Undefined variable: %s", ZSTR_VAL(cv));
218}
219
220static zend_never_inline zval *_get_zval_cv_lookup(zval *ptr, uint32_t var, int type, const zend_execute_data *execute_data)
221{
222	switch (type) {
223		case BP_VAR_R:
224		case BP_VAR_UNSET:
225			zval_undefined_cv(var, execute_data);
226			/* break missing intentionally */
227		case BP_VAR_IS:
228			ptr = &EG(uninitialized_zval);
229			break;
230		case BP_VAR_RW:
231			zval_undefined_cv(var, execute_data);
232			/* break missing intentionally */
233		case BP_VAR_W:
234			ZVAL_NULL(ptr);
235			break;
236	}
237	return ptr;
238}
239
240static zend_always_inline zval *_get_zval_cv_lookup_BP_VAR_R(zval *ptr, uint32_t var, const zend_execute_data *execute_data)
241{
242	zval_undefined_cv(var, execute_data);
243	return &EG(uninitialized_zval);
244}
245
246static zend_always_inline zval *_get_zval_cv_lookup_BP_VAR_UNSET(zval *ptr, uint32_t var, const zend_execute_data *execute_data)
247{
248	zval_undefined_cv(var, execute_data);
249	return &EG(uninitialized_zval);
250}
251
252static zend_always_inline zval *_get_zval_cv_lookup_BP_VAR_RW(zval *ptr, uint32_t var, const zend_execute_data *execute_data)
253{
254	ZVAL_NULL(ptr);
255	zval_undefined_cv(var, execute_data);
256	return ptr;
257}
258
259static zend_always_inline zval *_get_zval_cv_lookup_BP_VAR_W(zval *ptr, uint32_t var, const zend_execute_data *execute_data)
260{
261	ZVAL_NULL(ptr);
262	return ptr;
263}
264
265static zend_always_inline zval *_get_zval_ptr_cv(const zend_execute_data *execute_data, uint32_t var, int type)
266{
267	zval *ret = EX_VAR(var);
268
269	if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
270		return _get_zval_cv_lookup(ret, var, type, execute_data);
271	}
272	return ret;
273}
274
275static zend_always_inline zval *_get_zval_ptr_cv_undef(const zend_execute_data *execute_data, uint32_t var)
276{
277	return EX_VAR(var);
278}
279
280static zend_always_inline zval *_get_zval_ptr_cv_deref(const zend_execute_data *execute_data, uint32_t var, int type)
281{
282	zval *ret = EX_VAR(var);
283
284	if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
285		return _get_zval_cv_lookup(ret, var, type, execute_data);
286	}
287	ZVAL_DEREF(ret);
288	return ret;
289}
290
291static zend_always_inline zval *_get_zval_ptr_cv_BP_VAR_R(const zend_execute_data *execute_data, uint32_t var)
292{
293	zval *ret = EX_VAR(var);
294
295	if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
296		return _get_zval_cv_lookup_BP_VAR_R(ret, var, execute_data);
297	}
298	return ret;
299}
300
301static zend_always_inline zval *_get_zval_ptr_cv_deref_BP_VAR_R(const zend_execute_data *execute_data, uint32_t var)
302{
303	zval *ret = EX_VAR(var);
304
305	if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
306		return _get_zval_cv_lookup_BP_VAR_R(ret, var, execute_data);
307	}
308	ZVAL_DEREF(ret);
309	return ret;
310}
311
312static zend_always_inline zval *_get_zval_ptr_cv_BP_VAR_UNSET(const zend_execute_data *execute_data, uint32_t var)
313{
314	zval *ret = EX_VAR(var);
315
316	if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
317		return _get_zval_cv_lookup_BP_VAR_UNSET(ret, var, execute_data);
318	}
319	return ret;
320}
321
322static zend_always_inline zval *_get_zval_ptr_cv_deref_BP_VAR_UNSET(const zend_execute_data *execute_data, uint32_t var)
323{
324	zval *ret = EX_VAR(var);
325
326	if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
327		return _get_zval_cv_lookup_BP_VAR_UNSET(ret, var, execute_data);
328	}
329	ZVAL_DEREF(ret);
330	return ret;
331}
332
333static zend_always_inline zval *_get_zval_ptr_cv_BP_VAR_IS(const zend_execute_data *execute_data, uint32_t var)
334{
335	zval *ret = EX_VAR(var);
336
337	return ret;
338}
339
340static zend_always_inline zval *_get_zval_ptr_cv_deref_BP_VAR_IS(const zend_execute_data *execute_data, uint32_t var)
341{
342	zval *ret = EX_VAR(var);
343
344	ZVAL_DEREF(ret);
345	return ret;
346}
347
348static zend_always_inline zval *_get_zval_ptr_cv_BP_VAR_RW(const zend_execute_data *execute_data, uint32_t var)
349{
350	zval *ret = EX_VAR(var);
351
352	if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
353		return _get_zval_cv_lookup_BP_VAR_RW(ret, var, execute_data);
354	}
355	return ret;
356}
357
358static zend_always_inline zval *_get_zval_ptr_cv_deref_BP_VAR_RW(const zend_execute_data *execute_data, uint32_t var)
359{
360	zval *ret = EX_VAR(var);
361
362	if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
363		return _get_zval_cv_lookup_BP_VAR_RW(ret, var, execute_data);
364	}
365	ZVAL_DEREF(ret);
366	return ret;
367}
368
369static zend_always_inline zval *_get_zval_ptr_cv_BP_VAR_W(const zend_execute_data *execute_data, uint32_t var)
370{
371	zval *ret = EX_VAR(var);
372
373	if (Z_TYPE_P(ret) == IS_UNDEF) {
374		return _get_zval_cv_lookup_BP_VAR_W(ret, var, execute_data);
375	}
376	return ret;
377}
378
379static zend_always_inline zval *_get_zval_ptr_cv_undef_BP_VAR_W(const zend_execute_data *execute_data, uint32_t var)
380{
381	return EX_VAR(var);
382}
383
384static zend_always_inline zval *_get_zval_ptr_cv_undef_BP_VAR_RW(const zend_execute_data *execute_data, uint32_t var)
385{
386	return EX_VAR(var);
387}
388
389static zend_always_inline zval *_get_zval_ptr_cv_undef_BP_VAR_UNSET(const zend_execute_data *execute_data, uint32_t var)
390{
391	return EX_VAR(var);
392}
393
394static zend_always_inline zval *_get_zval_ptr_cv_deref_BP_VAR_W(const zend_execute_data *execute_data, uint32_t var)
395{
396	zval *ret = EX_VAR(var);
397
398	if (Z_TYPE_P(ret) == IS_UNDEF) {
399		return _get_zval_cv_lookup_BP_VAR_W(ret, var, execute_data);
400	}
401	ZVAL_DEREF(ret);
402	return ret;
403}
404
405static zend_always_inline zval *_get_zval_ptr(int op_type, znode_op node, const zend_execute_data *execute_data, zend_free_op *should_free, int type)
406{
407	if (op_type & (IS_TMP_VAR|IS_VAR)) {
408		if (op_type == IS_TMP_VAR) {
409			return _get_zval_ptr_tmp(node.var, execute_data, should_free);
410		} else {
411			ZEND_ASSERT(op_type == IS_VAR);
412			return _get_zval_ptr_var(node.var, execute_data, should_free);
413		}
414	} else {
415		*should_free = NULL;
416		if (op_type == IS_CONST) {
417			return EX_CONSTANT(node);
418		} else if (op_type == IS_CV) {
419			return _get_zval_ptr_cv(execute_data, node.var, type);
420		} else {
421			return NULL;
422		}
423	}
424}
425
426static zend_always_inline zval *_get_zval_ptr_r(int op_type, znode_op node, const zend_execute_data *execute_data, zend_free_op *should_free)
427{
428	if (op_type & (IS_TMP_VAR|IS_VAR)) {
429		if (op_type == IS_TMP_VAR) {
430			return _get_zval_ptr_tmp(node.var, execute_data, should_free);
431		} else {
432			ZEND_ASSERT(op_type == IS_VAR);
433			return _get_zval_ptr_var(node.var, execute_data, should_free);
434		}
435	} else {
436		*should_free = NULL;
437		if (op_type == IS_CONST) {
438			return EX_CONSTANT(node);
439		} else if (op_type == IS_CV) {
440			return _get_zval_ptr_cv_BP_VAR_R(execute_data, node.var);
441		} else {
442			return NULL;
443		}
444	}
445}
446
447static zend_always_inline zval *_get_zval_ptr_deref(int op_type, znode_op node, const zend_execute_data *execute_data, zend_free_op *should_free, int type)
448{
449	if (op_type & (IS_TMP_VAR|IS_VAR)) {
450		if (op_type == IS_TMP_VAR) {
451			return _get_zval_ptr_tmp(node.var, execute_data, should_free);
452		} else {
453			ZEND_ASSERT(op_type == IS_VAR);
454			return _get_zval_ptr_var_deref(node.var, execute_data, should_free);
455		}
456	} else {
457		*should_free = NULL;
458		if (op_type == IS_CONST) {
459			return EX_CONSTANT(node);
460		} else if (op_type == IS_CV) {
461			return _get_zval_ptr_cv_deref(execute_data, node.var, type);
462		} else {
463			return NULL;
464		}
465	}
466}
467
468static zend_always_inline zval *_get_zval_ptr_r_deref(int op_type, znode_op node, const zend_execute_data *execute_data, zend_free_op *should_free)
469{
470	if (op_type & (IS_TMP_VAR|IS_VAR)) {
471		if (op_type == IS_TMP_VAR) {
472			return _get_zval_ptr_tmp(node.var, execute_data, should_free);
473		} else {
474			ZEND_ASSERT(op_type == IS_VAR);
475			return _get_zval_ptr_var_deref(node.var, execute_data, should_free);
476		}
477	} else {
478		*should_free = NULL;
479		if (op_type == IS_CONST) {
480			return EX_CONSTANT(node);
481		} else if (op_type == IS_CV) {
482			return _get_zval_ptr_cv_deref_BP_VAR_R(execute_data, node.var);
483		} else {
484			return NULL;
485		}
486	}
487}
488
489static zend_always_inline zval *_get_zval_ptr_undef(int op_type, znode_op node, const zend_execute_data *execute_data, zend_free_op *should_free, int type)
490{
491	if (op_type & (IS_TMP_VAR|IS_VAR)) {
492		if (op_type == IS_TMP_VAR) {
493			return _get_zval_ptr_tmp(node.var, execute_data, should_free);
494		} else {
495			ZEND_ASSERT(op_type == IS_VAR);
496			return _get_zval_ptr_var(node.var, execute_data, should_free);
497		}
498	} else {
499		*should_free = NULL;
500		if (op_type == IS_CONST) {
501			return EX_CONSTANT(node);
502		} else if (op_type == IS_CV) {
503			return _get_zval_ptr_cv_undef(execute_data, node.var);
504		} else {
505			return NULL;
506		}
507	}
508}
509
510static zend_always_inline zval *_get_zval_ptr_ptr_var(uint32_t var, const zend_execute_data *execute_data, zend_free_op *should_free)
511{
512	zval *ret = EX_VAR(var);
513
514	if (EXPECTED(Z_TYPE_P(ret) == IS_INDIRECT)) {
515		*should_free = NULL;
516		ret = Z_INDIRECT_P(ret);
517	} else {
518		*should_free = ret;
519	}
520	return ret;
521}
522
523static inline zval *_get_zval_ptr_ptr(int op_type, znode_op node, const zend_execute_data *execute_data, zend_free_op *should_free, int type)
524{
525	if (op_type == IS_CV) {
526		*should_free = NULL;
527		return _get_zval_ptr_cv(execute_data, node.var, type);
528	} else /* if (op_type == IS_VAR) */ {
529		ZEND_ASSERT(op_type == IS_VAR);
530		return _get_zval_ptr_ptr_var(node.var, execute_data, should_free);
531	}
532}
533
534static zend_always_inline zval *_get_obj_zval_ptr_unused(zend_execute_data *execute_data)
535{
536	return &EX(This);
537}
538
539static inline zval *_get_obj_zval_ptr(int op_type, znode_op op, zend_execute_data *execute_data, zend_free_op *should_free, int type)
540{
541	if (op_type == IS_UNUSED) {
542		*should_free = NULL;
543		return &EX(This);
544	}
545	return get_zval_ptr(op_type, op, execute_data, should_free, type);
546}
547
548static inline zval *_get_obj_zval_ptr_undef(int op_type, znode_op op, zend_execute_data *execute_data, zend_free_op *should_free, int type)
549{
550	if (op_type == IS_UNUSED) {
551		*should_free = NULL;
552		return &EX(This);
553	}
554	return get_zval_ptr_undef(op_type, op, execute_data, should_free, type);
555}
556
557static inline zval *_get_obj_zval_ptr_ptr(int op_type, znode_op node, zend_execute_data *execute_data, zend_free_op *should_free, int type)
558{
559	if (op_type == IS_UNUSED) {
560		*should_free = NULL;
561		return &EX(This);
562	}
563	return get_zval_ptr_ptr(op_type, node, execute_data, should_free, type);
564}
565
566static inline void zend_assign_to_variable_reference(zval *variable_ptr, zval *value_ptr)
567{
568	zend_reference *ref;
569
570	if (EXPECTED(!Z_ISREF_P(value_ptr))) {
571		ZVAL_NEW_REF(value_ptr, value_ptr);
572	} else if (UNEXPECTED(variable_ptr == value_ptr)) {
573		return;
574	}
575
576	ref = Z_REF_P(value_ptr);
577	GC_REFCOUNT(ref)++;
578	zval_ptr_dtor(variable_ptr);
579	ZVAL_REF(variable_ptr, ref);
580}
581
582/* this should modify object only if it's empty */
583static inline int make_real_object(zval *object)
584{
585	if (UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
586		if (EXPECTED(Z_TYPE_P(object) <= IS_FALSE)) {
587			/* nothing to destroy */
588		} else if (EXPECTED((Z_TYPE_P(object) == IS_STRING && Z_STRLEN_P(object) == 0))) {
589			zval_ptr_dtor_nogc(object);
590		} else {
591			return 0;
592		}
593		object_init(object);
594		zend_error(E_WARNING, "Creating default object from empty value");
595	}
596	return 1;
597}
598
599static char * zend_verify_internal_arg_class_kind(const zend_internal_arg_info *cur_arg_info, char **class_name, zend_class_entry **pce)
600{
601	zend_string *key;
602	ALLOCA_FLAG(use_heap);
603
604	ZSTR_ALLOCA_INIT(key, cur_arg_info->class_name, strlen(cur_arg_info->class_name), use_heap);
605	*pce = zend_fetch_class(key, (ZEND_FETCH_CLASS_AUTO | ZEND_FETCH_CLASS_NO_AUTOLOAD));
606	ZSTR_ALLOCA_FREE(key, use_heap);
607
608	*class_name = (*pce) ? ZSTR_VAL((*pce)->name) : (char*)cur_arg_info->class_name;
609	if (*pce && (*pce)->ce_flags & ZEND_ACC_INTERFACE) {
610		return "implement interface ";
611	} else {
612		return "be an instance of ";
613	}
614}
615
616static zend_always_inline zend_class_entry* zend_verify_arg_class_kind(const zend_arg_info *cur_arg_info)
617{
618	return zend_fetch_class(cur_arg_info->class_name, (ZEND_FETCH_CLASS_AUTO | ZEND_FETCH_CLASS_NO_AUTOLOAD));
619}
620
621static ZEND_COLD void zend_verify_arg_error(const zend_function *zf, uint32_t arg_num, const char *need_msg, const char *need_kind, const char *given_msg, const char *given_kind)
622{
623	zend_execute_data *ptr = EG(current_execute_data)->prev_execute_data;
624	const char *fname = ZSTR_VAL(zf->common.function_name);
625	const char *fsep;
626	const char *fclass;
627
628	if (zf->common.scope) {
629		fsep =  "::";
630		fclass = ZSTR_VAL(zf->common.scope->name);
631	} else {
632		fsep =  "";
633		fclass = "";
634	}
635
636	if (zf->common.type == ZEND_USER_FUNCTION) {
637		if (ptr && ptr->func && ZEND_USER_CODE(ptr->func->common.type)) {
638			zend_type_error("Argument %d passed to %s%s%s() must %s%s, %s%s given, called in %s on line %d",
639					arg_num, fclass, fsep, fname, need_msg, need_kind, given_msg, given_kind,
640					ZSTR_VAL(ptr->func->op_array.filename), ptr->opline->lineno);
641		} else {
642			zend_type_error("Argument %d passed to %s%s%s() must %s%s, %s%s given", arg_num, fclass, fsep, fname, need_msg, need_kind, given_msg, given_kind);
643		}
644	} else {
645		zend_type_error("Argument %d passed to %s%s%s() must %s%s, %s%s given", arg_num, fclass, fsep, fname, need_msg, need_kind, given_msg, given_kind);
646	}
647}
648
649static int is_null_constant(zend_class_entry *scope, zval *default_value)
650{
651	if (Z_CONSTANT_P(default_value)) {
652		zval constant;
653
654		ZVAL_COPY(&constant, default_value);
655		if (UNEXPECTED(zval_update_constant_ex(&constant, scope) != SUCCESS)) {
656			return 0;
657		}
658		if (Z_TYPE(constant) == IS_NULL) {
659			return 1;
660		}
661		zval_ptr_dtor(&constant);
662	}
663	return 0;
664}
665
666static zend_bool zend_verify_weak_scalar_type_hint(zend_uchar type_hint, zval *arg)
667{
668	switch (type_hint) {
669		case _IS_BOOL: {
670			zend_bool dest;
671
672			if (!zend_parse_arg_bool_weak(arg, &dest)) {
673				return 0;
674			}
675			zval_ptr_dtor(arg);
676			ZVAL_BOOL(arg, dest);
677			return 1;
678		}
679		case IS_LONG: {
680			zend_long dest;
681
682			if (!zend_parse_arg_long_weak(arg, &dest)) {
683				return 0;
684			}
685			zval_ptr_dtor(arg);
686			ZVAL_LONG(arg, dest);
687			return 1;
688		}
689		case IS_DOUBLE: {
690			double dest;
691
692			if (!zend_parse_arg_double_weak(arg, &dest)) {
693				return 0;
694			}
695			zval_ptr_dtor(arg);
696			ZVAL_DOUBLE(arg, dest);
697			return 1;
698		}
699		case IS_STRING: {
700			zend_string *dest;
701
702			/* on success "arg" is converted to IS_STRING */
703			if (!zend_parse_arg_str_weak(arg, &dest)) {
704				return 0;
705			}
706			return 1;
707		}
708		default:
709			return 0;
710	}
711}
712
713static zend_bool zend_verify_scalar_type_hint(zend_uchar type_hint, zval *arg, zend_bool strict)
714{
715	if (UNEXPECTED(strict)) {
716		/* SSTH Exception: IS_LONG may be accepted as IS_DOUBLE (converted) */
717		if (type_hint != IS_DOUBLE || Z_TYPE_P(arg) != IS_LONG) {
718			return 0;
719		}
720	} else if (UNEXPECTED(Z_TYPE_P(arg) == IS_NULL)) {
721		/* NULL may be accepted only by nullable hints (this is already checked) */
722		return 0;
723	}
724	return zend_verify_weak_scalar_type_hint(type_hint, arg);
725}
726
727static int zend_verify_internal_arg_type(zend_function *zf, uint32_t arg_num, zval *arg)
728{
729	zend_internal_arg_info *cur_arg_info;
730	char *need_msg, *class_name;
731	zend_class_entry *ce;
732
733	if (EXPECTED(arg_num <= zf->internal_function.num_args)) {
734		cur_arg_info = &zf->internal_function.arg_info[arg_num-1];
735	} else if (zf->internal_function.fn_flags & ZEND_ACC_VARIADIC) {
736		cur_arg_info = &zf->internal_function.arg_info[zf->internal_function.num_args];
737	} else {
738		return 1;
739	}
740
741	if (cur_arg_info->type_hint) {
742		ZVAL_DEREF(arg);
743		if (EXPECTED(cur_arg_info->type_hint == Z_TYPE_P(arg))) {
744			if (cur_arg_info->class_name) {
745				need_msg = zend_verify_internal_arg_class_kind((zend_internal_arg_info*)cur_arg_info, &class_name, &ce);
746				if (!ce || !instanceof_function(Z_OBJCE_P(arg), ce)) {
747					zend_verify_arg_error(zf, arg_num, need_msg, class_name, "instance of ", ZSTR_VAL(Z_OBJCE_P(arg)->name));
748					return 0;
749				}
750			}
751		} else if (Z_TYPE_P(arg) != IS_NULL || !cur_arg_info->allow_null) {
752			if (cur_arg_info->class_name) {
753				need_msg = zend_verify_internal_arg_class_kind((zend_internal_arg_info*)cur_arg_info, &class_name, &ce);
754				zend_verify_arg_error(zf, arg_num, need_msg, class_name, zend_zval_type_name(arg), "");
755				return 0;
756			} else if (cur_arg_info->type_hint == IS_CALLABLE) {
757				if (!zend_is_callable(arg, IS_CALLABLE_CHECK_SILENT, NULL)) {
758					zend_verify_arg_error(zf, arg_num, "be callable", "", zend_zval_type_name(arg), "");
759					return 0;
760				}
761			} else if (cur_arg_info->type_hint == _IS_BOOL &&
762			           EXPECTED(Z_TYPE_P(arg) == IS_FALSE || Z_TYPE_P(arg) == IS_TRUE)) {
763				/* pass */
764			} else if (UNEXPECTED(!zend_verify_scalar_type_hint(cur_arg_info->type_hint, arg, ZEND_CALL_USES_STRICT_TYPES(EG(current_execute_data))))) {
765				zend_verify_arg_error(zf, arg_num, "be of the type ", zend_get_type_by_const(cur_arg_info->type_hint), zend_zval_type_name(arg), "");
766				return 0;
767			}
768		}
769	}
770	return 1;
771}
772
773static zend_never_inline int zend_verify_internal_arg_types(zend_function *fbc, zend_execute_data *call)
774{
775	uint32_t i;
776	uint32_t num_args = ZEND_CALL_NUM_ARGS(call);
777	zval *p = ZEND_CALL_ARG(call, 1);
778
779	for (i = 0; i < num_args; ++i) {
780		if (UNEXPECTED(!zend_verify_internal_arg_type(fbc, i + 1, p))) {
781			EG(current_execute_data) = call->prev_execute_data;
782			zend_vm_stack_free_args(call);
783			return 0;
784		}
785		p++;
786	}
787	return 1;
788}
789
790static zend_always_inline int zend_verify_arg_type(zend_function *zf, uint32_t arg_num, zval *arg, zval *default_value, void **cache_slot)
791{
792	zend_arg_info *cur_arg_info;
793	char *need_msg;
794	zend_class_entry *ce;
795
796	if (EXPECTED(arg_num <= zf->common.num_args)) {
797		cur_arg_info = &zf->common.arg_info[arg_num-1];
798	} else if (UNEXPECTED(zf->common.fn_flags & ZEND_ACC_VARIADIC)) {
799		cur_arg_info = &zf->common.arg_info[zf->common.num_args];
800	} else {
801		return 1;
802	}
803
804	if (cur_arg_info->type_hint) {
805		ZVAL_DEREF(arg);
806		if (EXPECTED(cur_arg_info->type_hint == Z_TYPE_P(arg))) {
807			if (cur_arg_info->class_name) {
808				if (EXPECTED(*cache_slot)) {
809					ce = (zend_class_entry*)*cache_slot;
810				} else {
811					ce = zend_verify_arg_class_kind(cur_arg_info);
812					if (UNEXPECTED(!ce)) {
813						zend_verify_arg_error(zf, arg_num, "be an instance of ", ZSTR_VAL(cur_arg_info->class_name), "instance of ", ZSTR_VAL(Z_OBJCE_P(arg)->name));
814						return 0;
815					}
816					*cache_slot = (void*)ce;
817				}
818				if (UNEXPECTED(!instanceof_function(Z_OBJCE_P(arg), ce))) {
819					need_msg =
820						(ce->ce_flags & ZEND_ACC_INTERFACE) ?
821						"implement interface " : "be an instance of ";
822					zend_verify_arg_error(zf, arg_num, need_msg, ZSTR_VAL(ce->name), "instance of ", ZSTR_VAL(Z_OBJCE_P(arg)->name));
823					return 0;
824				}
825			}
826		} else if (Z_TYPE_P(arg) != IS_NULL || !(cur_arg_info->allow_null || (default_value && is_null_constant(zf->common.scope, default_value)))) {
827			if (cur_arg_info->class_name) {
828				if (EXPECTED(*cache_slot)) {
829					ce = (zend_class_entry*)*cache_slot;
830				} else {
831					ce = zend_verify_arg_class_kind(cur_arg_info);
832					if (UNEXPECTED(!ce)) {
833						if (Z_TYPE_P(arg) == IS_OBJECT) {
834							zend_verify_arg_error(zf, arg_num, "be an instance of ", ZSTR_VAL(cur_arg_info->class_name), "instance of ", ZSTR_VAL(Z_OBJCE_P(arg)->name));
835						} else {
836							zend_verify_arg_error(zf, arg_num, "be an instance of ", ZSTR_VAL(cur_arg_info->class_name), "", zend_zval_type_name(arg));
837						}
838						return 0;
839					}
840					*cache_slot = (void*)ce;
841				}
842				need_msg =
843					(ce->ce_flags & ZEND_ACC_INTERFACE) ?
844					"implement interface " : "be an instance of ";
845				zend_verify_arg_error(zf, arg_num, need_msg, ZSTR_VAL(ce->name), zend_zval_type_name(arg), "");
846				return 0;
847			} else if (cur_arg_info->type_hint == IS_CALLABLE) {
848				if (!zend_is_callable(arg, IS_CALLABLE_CHECK_SILENT, NULL)) {
849					zend_verify_arg_error(zf, arg_num, "be callable", "", zend_zval_type_name(arg), "");
850					return 0;
851				}
852			} else if (cur_arg_info->type_hint == _IS_BOOL &&
853			           EXPECTED(Z_TYPE_P(arg) == IS_FALSE || Z_TYPE_P(arg) == IS_TRUE)) {
854				/* pass */
855			} else if (UNEXPECTED(!zend_verify_scalar_type_hint(cur_arg_info->type_hint, arg, ZEND_ARG_USES_STRICT_TYPES()))) {
856				zend_verify_arg_error(zf, arg_num, "be of the type ", zend_get_type_by_const(cur_arg_info->type_hint), zend_zval_type_name(arg), "");
857				return 0;
858			}
859		}
860	}
861	return 1;
862}
863
864static zend_always_inline int zend_verify_missing_arg_type(zend_function *zf, uint32_t arg_num, void **cache_slot)
865{
866	zend_arg_info *cur_arg_info;
867	char *need_msg;
868	zend_class_entry *ce;
869
870	if (EXPECTED(arg_num <= zf->common.num_args)) {
871		cur_arg_info = &zf->common.arg_info[arg_num-1];
872	} else if (UNEXPECTED(zf->common.fn_flags & ZEND_ACC_VARIADIC)) {
873		cur_arg_info = &zf->common.arg_info[zf->common.num_args];
874	} else {
875		return 1;
876	}
877
878	if (cur_arg_info->type_hint) {
879		if (cur_arg_info->class_name) {
880			if (EXPECTED(*cache_slot)) {
881				ce = (zend_class_entry*)*cache_slot;
882			} else {
883				ce = zend_verify_arg_class_kind(cur_arg_info);
884				if (UNEXPECTED(!ce)) {
885					zend_verify_arg_error(zf, arg_num, "be an instance of ", ZSTR_VAL(cur_arg_info->class_name), "none", "");
886					return 0;
887				}
888				*cache_slot = (void*)ce;
889			}
890			need_msg =
891				(ce->ce_flags & ZEND_ACC_INTERFACE) ?
892				"implement interface " : "be an instance of ";
893			zend_verify_arg_error(zf, arg_num, need_msg, ZSTR_VAL(ce->name), "none", "");
894		} else if (cur_arg_info->type_hint == IS_CALLABLE) {
895			zend_verify_arg_error(zf, arg_num, "be callable", "", "none", "");
896		} else {
897			zend_verify_arg_error(zf, arg_num, "be of the type ", zend_get_type_by_const(cur_arg_info->type_hint), "none", "");
898		}
899		return 0;
900	}
901	return 1;
902}
903
904static ZEND_COLD void zend_verify_missing_arg(zend_execute_data *execute_data, uint32_t arg_num, void **cache_slot)
905{
906	if (EXPECTED(!(EX(func)->common.fn_flags & ZEND_ACC_HAS_TYPE_HINTS)) ||
907	    UNEXPECTED(zend_verify_missing_arg_type(EX(func), arg_num, cache_slot))) {
908		const char *class_name = EX(func)->common.scope ? ZSTR_VAL(EX(func)->common.scope->name) : "";
909		const char *space = EX(func)->common.scope ? "::" : "";
910		const char *func_name = EX(func)->common.function_name ? ZSTR_VAL(EX(func)->common.function_name) : "main";
911		zend_execute_data *ptr = EX(prev_execute_data);
912
913		if (ptr && ptr->func && ZEND_USER_CODE(ptr->func->common.type)) {
914			zend_error(E_WARNING, "Missing argument %u for %s%s%s(), called in %s on line %d and defined", arg_num, class_name, space, func_name, ZSTR_VAL(ptr->func->op_array.filename), ptr->opline->lineno);
915		} else {
916			zend_error(E_WARNING, "Missing argument %u for %s%s%s()", arg_num, class_name, space, func_name);
917		}
918	}
919}
920
921static ZEND_COLD void zend_verify_return_error(const zend_function *zf, const char *need_msg, const char *need_kind, const char *returned_msg, const char *returned_kind)
922{
923	const char *fname = ZSTR_VAL(zf->common.function_name);
924	const char *fsep;
925	const char *fclass;
926
927	if (zf->common.scope) {
928		fsep =  "::";
929		fclass = ZSTR_VAL(zf->common.scope->name);
930	} else {
931		fsep =  "";
932		fclass = "";
933	}
934
935	zend_type_error("Return value of %s%s%s() must %s%s, %s%s returned",
936		fclass, fsep, fname, need_msg, need_kind, returned_msg, returned_kind);
937}
938
939#if ZEND_DEBUG
940static ZEND_COLD void zend_verify_internal_return_error(const zend_function *zf, const char *need_msg, const char *need_kind, const char *returned_msg, const char *returned_kind)
941{
942	const char *fname = ZSTR_VAL(zf->common.function_name);
943	const char *fsep;
944	const char *fclass;
945
946	if (zf->common.scope) {
947		fsep =  "::";
948		fclass = ZSTR_VAL(zf->common.scope->name);
949	} else {
950		fsep =  "";
951		fclass = "";
952	}
953
954	zend_error_noreturn(E_CORE_ERROR, "Return value of %s%s%s() must %s%s, %s%s returned",
955		fclass, fsep, fname, need_msg, need_kind, returned_msg, returned_kind);
956}
957
958static ZEND_COLD void zend_verify_void_return_error(const zend_function *zf, const char *returned_msg, const char *returned_kind)
959{
960	const char *fname = ZSTR_VAL(zf->common.function_name);
961	const char *fsep;
962	const char *fclass;
963
964	if (zf->common.scope) {
965		fsep =  "::";
966		fclass = ZSTR_VAL(zf->common.scope->name);
967	} else {
968		fsep =  "";
969		fclass = "";
970	}
971
972	zend_type_error("%s%s%s() must not return a value, %s%s returned",
973		fclass, fsep, fname, returned_msg, returned_kind);
974}
975
976static int zend_verify_internal_return_type(zend_function *zf, zval *ret)
977{
978	zend_arg_info *ret_info = zf->common.arg_info - 1;
979	char *need_msg, *class_name;
980	zend_class_entry *ce;
981
982
983	if (ret_info->type_hint) {
984		if (EXPECTED(ret_info->type_hint == Z_TYPE_P(ret))) {
985			if (ret_info->class_name) {
986				need_msg = zend_verify_internal_arg_class_kind((zend_internal_arg_info *)ret_info, &class_name, &ce);
987				if (!ce || !instanceof_function(Z_OBJCE_P(ret), ce)) {
988					zend_verify_internal_return_error(zf, need_msg, class_name, "instance of ", ZSTR_VAL(Z_OBJCE_P(ret)->name));
989					return 0;
990				}
991			}
992		} else if (Z_TYPE_P(ret) != IS_NULL || !ret_info->allow_null) {
993			if (ret_info->class_name) {
994				need_msg = zend_verify_internal_arg_class_kind((zend_internal_arg_info *)ret_info, &class_name, &ce);
995				zend_verify_internal_return_error(zf, need_msg, class_name, zend_zval_type_name(ret), "");
996			} else if (ret_info->type_hint == IS_CALLABLE) {
997				if (!zend_is_callable(ret, IS_CALLABLE_CHECK_SILENT, NULL) && (Z_TYPE_P(ret) != IS_NULL || !ret_info->allow_null)) {
998					zend_verify_internal_return_error(zf, "be callable", "", zend_zval_type_name(ret), "");
999					return 0;
1000				}
1001			} else if (ret_info->type_hint == _IS_BOOL &&
1002			           EXPECTED(Z_TYPE_P(ret) == IS_FALSE || Z_TYPE_P(ret) == IS_TRUE)) {
1003				/* pass */
1004			} else if (ret_info->type_hint == IS_VOID) {
1005				zend_verify_void_return_error(zf, zend_zval_type_name(ret), "");
1006			} else {
1007				/* Use strict check to verify return value of internal function */
1008				zend_verify_internal_return_error(zf, "be of the type ", zend_get_type_by_const(ret_info->type_hint), zend_zval_type_name(ret), "");
1009				return 0;
1010			}
1011		}
1012	}
1013	return 1;
1014}
1015#endif
1016
1017static zend_always_inline void zend_verify_return_type(zend_function *zf, zval *ret, void **cache_slot)
1018{
1019	zend_arg_info *ret_info = zf->common.arg_info - 1;
1020	char *need_msg;
1021	zend_class_entry *ce;
1022
1023	if (ret_info->type_hint) {
1024		if (EXPECTED(ret_info->type_hint == Z_TYPE_P(ret))) {
1025			if (ret_info->class_name) {
1026				if (EXPECTED(*cache_slot)) {
1027					ce = (zend_class_entry*)*cache_slot;
1028				} else {
1029					ce = zend_verify_arg_class_kind(ret_info);
1030					if (UNEXPECTED(!ce)) {
1031						zend_verify_return_error(zf, "be an instance of ", ZSTR_VAL(ret_info->class_name), "instance of ", ZSTR_VAL(Z_OBJCE_P(ret)->name));
1032						return;
1033					}
1034					*cache_slot = (void*)ce;
1035				}
1036				if (UNEXPECTED(!instanceof_function(Z_OBJCE_P(ret), ce))) {
1037					need_msg =
1038						(ce->ce_flags & ZEND_ACC_INTERFACE) ?
1039						"implement interface " : "be an instance of ";
1040					zend_verify_return_error(zf, need_msg, ZSTR_VAL(ce->name), "instance of ", ZSTR_VAL(Z_OBJCE_P(ret)->name));
1041				}
1042			}
1043		} else if (Z_TYPE_P(ret) != IS_NULL || !ret_info->allow_null) {
1044			if (ret_info->class_name) {
1045				if (EXPECTED(*cache_slot)) {
1046					ce = (zend_class_entry*)*cache_slot;
1047				} else {
1048					ce = zend_verify_arg_class_kind(ret_info);
1049					if (UNEXPECTED(!ce)) {
1050						zend_verify_return_error(zf, "be an instance of ", ZSTR_VAL(ret_info->class_name), zend_zval_type_name(ret), "");
1051						return;
1052					}
1053					*cache_slot = (void*)ce;
1054				}
1055				need_msg =
1056					(ce->ce_flags & ZEND_ACC_INTERFACE) ?
1057					"implement interface " : "be an instance of ";
1058				zend_verify_return_error(zf, need_msg, ZSTR_VAL(ce->name), zend_zval_type_name(ret), "");
1059			} else if (ret_info->type_hint == IS_CALLABLE) {
1060				if (!zend_is_callable(ret, IS_CALLABLE_CHECK_SILENT, NULL)) {
1061					zend_verify_return_error(zf, "be callable", "", zend_zval_type_name(ret), "");
1062				}
1063			} else if (ret_info->type_hint == _IS_BOOL &&
1064			           EXPECTED(Z_TYPE_P(ret) == IS_FALSE || Z_TYPE_P(ret) == IS_TRUE)) {
1065				/* pass */
1066			/* There would be a check here for the IS_VOID type hint, which
1067			 * would trigger an error because a value had been returned.
1068			 * However, zend_compile.c already does a compile-time check
1069			 * that bans `return ...;` within a void function. Thus we can skip
1070			 * this part of the runtime check for non-internal functions.
1071			 */
1072			} else if (UNEXPECTED(!zend_verify_scalar_type_hint(ret_info->type_hint, ret, ZEND_RET_USES_STRICT_TYPES()))) {
1073				zend_verify_return_error(zf, "be of the type ", zend_get_type_by_const(ret_info->type_hint), zend_zval_type_name(ret), "");
1074			}
1075		}
1076	}
1077}
1078
1079static ZEND_COLD int zend_verify_missing_return_type(zend_function *zf, void **cache_slot)
1080{
1081	zend_arg_info *ret_info = zf->common.arg_info - 1;
1082	char *need_msg;
1083	zend_class_entry *ce;
1084
1085	if (ret_info->type_hint && EXPECTED(ret_info->type_hint != IS_VOID)) {
1086		if (ret_info->class_name) {
1087			if (EXPECTED(*cache_slot)) {
1088				ce = (zend_class_entry*)*cache_slot;
1089			} else {
1090				ce = zend_verify_arg_class_kind(ret_info);
1091				if (UNEXPECTED(!ce)) {
1092					zend_verify_return_error(zf, "be an instance of ", ZSTR_VAL(ret_info->class_name), "none", "");
1093					return 0;
1094				}
1095				*cache_slot = (void*)ce;
1096			}
1097			need_msg =
1098				(ce->ce_flags & ZEND_ACC_INTERFACE) ?
1099				"implement interface " : "be an instance of ";
1100			zend_verify_return_error(zf, need_msg, ZSTR_VAL(ce->name), "none", "");
1101			return 0;
1102		} else if (ret_info->type_hint == IS_CALLABLE) {
1103			zend_verify_return_error(zf, "be callable", "", "none", "");
1104		} else {
1105			zend_verify_return_error(zf, "be of the type ", zend_get_type_by_const(ret_info->type_hint), "none", "");
1106		}
1107		return 0;
1108	}
1109	return 1;
1110}
1111
1112static zend_never_inline void zend_assign_to_object_dim(zval *object, zval *dim, zval *value)
1113{
1114	if (UNEXPECTED(!Z_OBJ_HT_P(object)->write_dimension)) {
1115		zend_throw_error(NULL, "Cannot use object as array");
1116		return;
1117	}
1118
1119	Z_OBJ_HT_P(object)->write_dimension(object, dim, value);
1120}
1121
1122static zend_never_inline void zend_binary_assign_op_obj_dim(zval *object, zval *property, zval *value, zval *retval, binary_op_type binary_op)
1123{
1124	zval *z;
1125	zval rv, res;
1126
1127	if (Z_OBJ_HT_P(object)->read_dimension &&
1128		(z = Z_OBJ_HT_P(object)->read_dimension(object, property, BP_VAR_R, &rv)) != NULL) {
1129
1130		if (Z_TYPE_P(z) == IS_OBJECT && Z_OBJ_HT_P(z)->get) {
1131			zval rv2;
1132			zval *value = Z_OBJ_HT_P(z)->get(z, &rv2);
1133
1134			if (z == &rv) {
1135				zval_ptr_dtor(&rv);
1136			}
1137			ZVAL_COPY_VALUE(z, value);
1138		}
1139		binary_op(&res, Z_ISREF_P(z) ? Z_REFVAL_P(z) : z, value);
1140		Z_OBJ_HT_P(object)->write_dimension(object, property, &res);
1141		if (z == &rv) {
1142			zval_ptr_dtor(&rv);
1143		}
1144		if (retval) {
1145			ZVAL_COPY(retval, &res);
1146		}
1147		zval_ptr_dtor(&res);
1148	} else {
1149		zend_error(E_WARNING, "Attempt to assign property of non-object");
1150		if (retval) {
1151			ZVAL_NULL(retval);
1152		}
1153	}
1154}
1155
1156static zend_never_inline zend_long zend_check_string_offset(zval *dim, int type)
1157{
1158	zend_long offset;
1159
1160try_again:
1161	if (UNEXPECTED(Z_TYPE_P(dim) != IS_LONG)) {
1162		switch(Z_TYPE_P(dim)) {
1163			case IS_STRING:
1164				if (IS_LONG == is_numeric_string(Z_STRVAL_P(dim), Z_STRLEN_P(dim), NULL, NULL, -1)) {
1165					break;
1166				}
1167				if (type != BP_VAR_UNSET) {
1168					zend_error(E_WARNING, "Illegal string offset '%s'", Z_STRVAL_P(dim));
1169				}
1170				break;
1171			case IS_UNDEF:
1172				zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
1173			case IS_DOUBLE:
1174			case IS_NULL:
1175			case IS_FALSE:
1176			case IS_TRUE:
1177				zend_error(E_NOTICE, "String offset cast occurred");
1178				break;
1179			case IS_REFERENCE:
1180				dim = Z_REFVAL_P(dim);
1181				goto try_again;
1182			default:
1183				zend_error(E_WARNING, "Illegal offset type");
1184				break;
1185		}
1186
1187		offset = _zval_get_long_func(dim);
1188	} else {
1189		offset = Z_LVAL_P(dim);
1190	}
1191
1192	return offset;
1193}
1194
1195static zend_never_inline ZEND_COLD void zend_wrong_string_offset(void)
1196{
1197	const char *msg = NULL;
1198	const zend_op *opline = EG(current_execute_data)->opline;
1199	const zend_op *end;
1200	uint32_t var;
1201
1202	switch (opline->opcode) {
1203		case ZEND_ASSIGN_ADD:
1204		case ZEND_ASSIGN_SUB:
1205		case ZEND_ASSIGN_MUL:
1206		case ZEND_ASSIGN_DIV:
1207		case ZEND_ASSIGN_MOD:
1208		case ZEND_ASSIGN_SL:
1209		case ZEND_ASSIGN_SR:
1210		case ZEND_ASSIGN_CONCAT:
1211		case ZEND_ASSIGN_BW_OR:
1212		case ZEND_ASSIGN_BW_AND:
1213		case ZEND_ASSIGN_BW_XOR:
1214		case ZEND_ASSIGN_POW:
1215			msg = "Cannot use assign-op operators with string offsets";
1216			break;
1217		case ZEND_FETCH_DIM_W:
1218		case ZEND_FETCH_DIM_RW:
1219		case ZEND_FETCH_DIM_FUNC_ARG:
1220		case ZEND_FETCH_DIM_UNSET:
1221			/* TODO: Encode the "reason" into opline->extended_value??? */
1222			var = opline->result.var;
1223			opline++;
1224			end = EG(current_execute_data)->func->op_array.opcodes +
1225				EG(current_execute_data)->func->op_array.last;
1226			while (opline < end) {
1227				if (opline->op1_type == IS_VAR && opline->op1.var == var) {
1228					switch (opline->opcode) {
1229						case ZEND_ASSIGN_ADD:
1230						case ZEND_ASSIGN_SUB:
1231						case ZEND_ASSIGN_MUL:
1232						case ZEND_ASSIGN_DIV:
1233						case ZEND_ASSIGN_MOD:
1234						case ZEND_ASSIGN_SL:
1235						case ZEND_ASSIGN_SR:
1236						case ZEND_ASSIGN_CONCAT:
1237						case ZEND_ASSIGN_BW_OR:
1238						case ZEND_ASSIGN_BW_AND:
1239						case ZEND_ASSIGN_BW_XOR:
1240						case ZEND_ASSIGN_POW:
1241							if (opline->extended_value == ZEND_ASSIGN_OBJ) {
1242								msg = "Cannot use string offset as an object";
1243							} else if (opline->extended_value == ZEND_ASSIGN_DIM) {
1244								msg = "Cannot use string offset as an array";
1245							} else {
1246								msg = "Cannot use assign-op operators with string offsets";
1247							}
1248							break;
1249						case ZEND_PRE_INC_OBJ:
1250						case ZEND_PRE_DEC_OBJ:
1251						case ZEND_POST_INC_OBJ:
1252						case ZEND_POST_DEC_OBJ:
1253						case ZEND_PRE_INC:
1254						case ZEND_PRE_DEC:
1255						case ZEND_POST_INC:
1256						case ZEND_POST_DEC:
1257							msg = "Cannot increment/decrement string offsets";
1258							break;
1259						case ZEND_FETCH_DIM_W:
1260						case ZEND_FETCH_DIM_RW:
1261						case ZEND_FETCH_DIM_FUNC_ARG:
1262						case ZEND_FETCH_DIM_UNSET:
1263						case ZEND_ASSIGN_DIM:
1264							msg = "Cannot use string offset as an array";
1265							break;
1266						case ZEND_FETCH_OBJ_W:
1267						case ZEND_FETCH_OBJ_RW:
1268						case ZEND_FETCH_OBJ_FUNC_ARG:
1269						case ZEND_FETCH_OBJ_UNSET:
1270						case ZEND_ASSIGN_OBJ:
1271							msg = "Cannot use string offset as an object";
1272							break;
1273						case ZEND_ASSIGN_REF:
1274						case ZEND_ADD_ARRAY_ELEMENT:
1275						case ZEND_INIT_ARRAY:
1276							msg = "Cannot create references to/from string offsets";
1277							break;
1278						case ZEND_RETURN_BY_REF:
1279							msg = "Cannot return string offsets by reference";
1280							break;
1281						case ZEND_UNSET_DIM:
1282						case ZEND_UNSET_OBJ:
1283							msg = "Cannot unset string offsets";
1284							break;
1285						case ZEND_YIELD:
1286							msg = "Cannot yield string offsets by reference";
1287							break;
1288						case ZEND_SEND_REF:
1289						case ZEND_SEND_VAR_EX:
1290							msg = "Only variables can be passed by reference";
1291							break;
1292						EMPTY_SWITCH_DEFAULT_CASE();
1293					}
1294					break;
1295				}
1296				if (opline->op2_type == IS_VAR && opline->op2.var == var) {
1297					ZEND_ASSERT(opline->opcode == ZEND_ASSIGN_REF);
1298					msg = "Cannot create references to/from string offsets";
1299					break;
1300				}
1301			}
1302			break;
1303		EMPTY_SWITCH_DEFAULT_CASE();
1304	}
1305	ZEND_ASSERT(msg != NULL);
1306	zend_throw_error(NULL, msg);
1307}
1308
1309static zend_never_inline void zend_assign_to_string_offset(zval *str, zval *dim, zval *value, zval *result)
1310{
1311	zend_string *old_str;
1312	zend_uchar c;
1313	size_t string_len;
1314	zend_long offset;
1315
1316	offset = zend_check_string_offset(dim, BP_VAR_W);
1317	if (offset < (zend_long)(-Z_STRLEN_P(str))) {
1318		/* Error on negative offset */
1319		zend_error(E_WARNING, "Illegal string offset:  " ZEND_LONG_FMT, offset);
1320		if (result) {
1321			ZVAL_NULL(result);
1322		}
1323		return;
1324	}
1325
1326	if (Z_TYPE_P(value) != IS_STRING) {
1327		/* Convert to string, just the time to pick the 1st byte */
1328		zend_string *tmp = zval_get_string(value);
1329
1330		string_len = ZSTR_LEN(tmp);
1331		c = (zend_uchar)ZSTR_VAL(tmp)[0];
1332		zend_string_release(tmp);
1333	} else {
1334		string_len = Z_STRLEN_P(value);
1335		c = (zend_uchar)Z_STRVAL_P(value)[0];
1336	}
1337
1338	if (string_len == 0) {
1339		/* Error on empty input string */
1340		zend_error(E_WARNING, "Cannot assign an empty string to a string offset");
1341		if (result) {
1342			ZVAL_NULL(result);
1343		}
1344		return;
1345	}
1346
1347	if (offset < 0) { /* Handle negative offset */
1348		offset += (zend_long)Z_STRLEN_P(str);
1349	}
1350
1351	if ((size_t)offset >= Z_STRLEN_P(str)) {
1352		/* Extend string if needed */
1353		zend_long old_len = Z_STRLEN_P(str);
1354		Z_STR_P(str) = zend_string_extend(Z_STR_P(str), offset + 1, 0);
1355		Z_TYPE_INFO_P(str) = IS_STRING_EX;
1356		memset(Z_STRVAL_P(str) + old_len, ' ', offset - old_len);
1357		Z_STRVAL_P(str)[offset+1] = 0;
1358	} else if (!Z_REFCOUNTED_P(str)) {
1359		old_str = Z_STR_P(str);
1360		Z_STR_P(str) = zend_string_init(Z_STRVAL_P(str), Z_STRLEN_P(str), 0);
1361		Z_TYPE_INFO_P(str) = IS_STRING_EX;
1362		zend_string_release(old_str);
1363	} else {
1364		SEPARATE_STRING(str);
1365	}
1366
1367	Z_STRVAL_P(str)[offset] = c;
1368
1369	if (result) {
1370		/* Return the new character */
1371		if (CG(one_char_string)[c]) {
1372			ZVAL_INTERNED_STR(result, CG(one_char_string)[c]);
1373		} else {
1374			ZVAL_NEW_STR(result, zend_string_init(Z_STRVAL_P(str) + offset, 1, 0));
1375		}
1376	}
1377}
1378
1379static zend_never_inline void zend_post_incdec_overloaded_property(zval *object, zval *property, void **cache_slot, int inc, zval *result)
1380{
1381	if (Z_OBJ_HT_P(object)->read_property && Z_OBJ_HT_P(object)->write_property) {
1382		zval rv, obj;
1383		zval *z;
1384		zval z_copy;
1385
1386		ZVAL_OBJ(&obj, Z_OBJ_P(object));
1387		Z_ADDREF(obj);
1388		z = Z_OBJ_HT(obj)->read_property(&obj, property, BP_VAR_R, cache_slot, &rv);
1389		if (UNEXPECTED(EG(exception))) {
1390			OBJ_RELEASE(Z_OBJ(obj));
1391			return;
1392		}
1393
1394		if (UNEXPECTED(Z_TYPE_P(z) == IS_OBJECT) && Z_OBJ_HT_P(z)->get) {
1395			zval rv2;
1396			zval *value = Z_OBJ_HT_P(z)->get(z, &rv2);
1397			if (z == &rv) {
1398				zval_ptr_dtor(&rv);
1399			}
1400			ZVAL_COPY_VALUE(z, value);
1401		}
1402
1403		if (UNEXPECTED(Z_TYPE_P(z) == IS_REFERENCE)) {
1404			ZVAL_COPY(result, Z_REFVAL_P(z));
1405		} else {
1406			ZVAL_COPY(result, z);
1407		}
1408		ZVAL_DUP(&z_copy, result);
1409		if (inc) {
1410			increment_function(&z_copy);
1411		} else {
1412			decrement_function(&z_copy);
1413		}
1414		Z_OBJ_HT(obj)->write_property(&obj, property, &z_copy, cache_slot);
1415		OBJ_RELEASE(Z_OBJ(obj));
1416		zval_ptr_dtor(&z_copy);
1417		zval_ptr_dtor(z);
1418	} else {
1419		zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
1420		ZVAL_NULL(result);
1421	}
1422}
1423
1424static zend_never_inline void zend_pre_incdec_overloaded_property(zval *object, zval *property, void **cache_slot, int inc, zval *result)
1425{
1426	zval rv;
1427
1428	if (Z_OBJ_HT_P(object)->read_property && Z_OBJ_HT_P(object)->write_property) {
1429		zval *z, obj;
1430
1431		ZVAL_OBJ(&obj, Z_OBJ_P(object));
1432		Z_ADDREF(obj);
1433		z = Z_OBJ_HT(obj)->read_property(&obj, property, BP_VAR_R, cache_slot, &rv);
1434		if (UNEXPECTED(EG(exception))) {
1435			OBJ_RELEASE(Z_OBJ(obj));
1436			return;
1437		}
1438
1439		if (UNEXPECTED(Z_TYPE_P(z) == IS_OBJECT) && Z_OBJ_HT_P(z)->get) {
1440			zval rv2;
1441			zval *value = Z_OBJ_HT_P(z)->get(z, &rv2);
1442
1443			if (z == &rv) {
1444				zval_ptr_dtor(&rv);
1445			}
1446			ZVAL_COPY_VALUE(z, value);
1447		}
1448		ZVAL_DEREF(z);
1449		SEPARATE_ZVAL_NOREF(z);
1450		if (inc) {
1451			increment_function(z);
1452		} else {
1453			decrement_function(z);
1454		}
1455		if (UNEXPECTED(result)) {
1456			ZVAL_COPY(result, z);
1457		}
1458		Z_OBJ_HT(obj)->write_property(&obj, property, z, cache_slot);
1459		OBJ_RELEASE(Z_OBJ(obj));
1460		zval_ptr_dtor(z);
1461	} else {
1462		zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
1463		if (UNEXPECTED(result)) {
1464			ZVAL_NULL(result);
1465		}
1466	}
1467}
1468
1469static zend_never_inline void zend_assign_op_overloaded_property(zval *object, zval *property, void **cache_slot, zval *value, binary_op_type binary_op, zval *result)
1470{
1471	zval *z;
1472	zval rv, obj;
1473	zval *zptr;
1474
1475	ZVAL_OBJ(&obj, Z_OBJ_P(object));
1476	Z_ADDREF(obj);
1477	if (EXPECTED(Z_OBJ_HT(obj)->read_property)) {
1478		z = Z_OBJ_HT(obj)->read_property(&obj, property, BP_VAR_R, cache_slot, &rv);
1479		if (UNEXPECTED(EG(exception))) {
1480			OBJ_RELEASE(Z_OBJ(obj));
1481			return;
1482		}
1483		if (Z_TYPE_P(z) == IS_OBJECT && Z_OBJ_HT_P(z)->get) {
1484			zval rv2;
1485			zval *value = Z_OBJ_HT_P(z)->get(z, &rv2);
1486
1487			if (z == &rv) {
1488				zval_ptr_dtor(&rv);
1489			}
1490			ZVAL_COPY_VALUE(z, value);
1491		}
1492		zptr = z;
1493		ZVAL_DEREF(z);
1494		SEPARATE_ZVAL_NOREF(z);
1495		binary_op(z, z, value);
1496		Z_OBJ_HT(obj)->write_property(&obj, property, z, cache_slot);
1497		if (UNEXPECTED(result)) {
1498			ZVAL_COPY(result, z);
1499		}
1500		zval_ptr_dtor(zptr);
1501	} else {
1502		zend_error(E_WARNING, "Attempt to assign property of non-object");
1503		if (UNEXPECTED(result)) {
1504			ZVAL_NULL(result);
1505		}
1506	}
1507	OBJ_RELEASE(Z_OBJ(obj));
1508}
1509
1510/* Utility Functions for Extensions */
1511static void zend_extension_statement_handler(const zend_extension *extension, zend_execute_data *frame)
1512{
1513	if (extension->statement_handler) {
1514		extension->statement_handler(frame);
1515	}
1516}
1517
1518
1519static void zend_extension_fcall_begin_handler(const zend_extension *extension, zend_execute_data *frame)
1520{
1521	if (extension->fcall_begin_handler) {
1522		extension->fcall_begin_handler(frame);
1523	}
1524}
1525
1526
1527static void zend_extension_fcall_end_handler(const zend_extension *extension, zend_execute_data *frame)
1528{
1529	if (extension->fcall_end_handler) {
1530		extension->fcall_end_handler(frame);
1531	}
1532}
1533
1534
1535static zend_always_inline HashTable *zend_get_target_symbol_table(zend_execute_data *execute_data, int fetch_type)
1536{
1537	HashTable *ht;
1538
1539	if (EXPECTED(fetch_type == ZEND_FETCH_GLOBAL_LOCK) ||
1540	    EXPECTED(fetch_type == ZEND_FETCH_GLOBAL)) {
1541		ht = &EG(symbol_table);
1542	} else {
1543		ZEND_ASSERT(fetch_type == ZEND_FETCH_LOCAL);
1544		if (!(EX_CALL_INFO() & ZEND_CALL_HAS_SYMBOL_TABLE)) {
1545			zend_rebuild_symbol_table();
1546		}
1547		ht = EX(symbol_table);
1548	}
1549	return ht;
1550}
1551
1552static zend_always_inline zval *zend_fetch_dimension_address_inner(HashTable *ht, const zval *dim, int dim_type, int type)
1553{
1554	zval *retval;
1555	zend_string *offset_key;
1556	zend_ulong hval;
1557
1558try_again:
1559	if (EXPECTED(Z_TYPE_P(dim) == IS_LONG)) {
1560		hval = Z_LVAL_P(dim);
1561num_index:
1562		ZEND_HASH_INDEX_FIND(ht, hval, retval, num_undef);
1563		return retval;
1564num_undef:
1565		switch (type) {
1566			case BP_VAR_R:
1567				zend_error(E_NOTICE,"Undefined offset: " ZEND_LONG_FMT, hval);
1568				/* break missing intentionally */
1569			case BP_VAR_UNSET:
1570			case BP_VAR_IS:
1571				retval = &EG(uninitialized_zval);
1572				break;
1573			case BP_VAR_RW:
1574				zend_error(E_NOTICE,"Undefined offset: " ZEND_LONG_FMT, hval);
1575				retval = zend_hash_index_update(ht, hval, &EG(uninitialized_zval));
1576				break;
1577			case BP_VAR_W:
1578				retval = zend_hash_index_add_new(ht, hval, &EG(uninitialized_zval));
1579				break;
1580		}
1581	} else if (EXPECTED(Z_TYPE_P(dim) == IS_STRING)) {
1582		offset_key = Z_STR_P(dim);
1583		if (dim_type != IS_CONST) {
1584			if (ZEND_HANDLE_NUMERIC(offset_key, hval)) {
1585				goto num_index;
1586			}
1587		}
1588str_index:
1589		retval = zend_hash_find(ht, offset_key);
1590		if (retval) {
1591			/* support for $GLOBALS[...] */
1592			if (UNEXPECTED(Z_TYPE_P(retval) == IS_INDIRECT)) {
1593				retval = Z_INDIRECT_P(retval);
1594				if (UNEXPECTED(Z_TYPE_P(retval) == IS_UNDEF)) {
1595					switch (type) {
1596						case BP_VAR_R:
1597							zend_error(E_NOTICE, "Undefined index: %s", ZSTR_VAL(offset_key));
1598							/* break missing intentionally */
1599						case BP_VAR_UNSET:
1600						case BP_VAR_IS:
1601							retval = &EG(uninitialized_zval);
1602							break;
1603						case BP_VAR_RW:
1604							zend_error(E_NOTICE,"Undefined index: %s", ZSTR_VAL(offset_key));
1605							/* break missing intentionally */
1606						case BP_VAR_W:
1607							ZVAL_NULL(retval);
1608							break;
1609					}
1610				}
1611			}
1612		} else {
1613			switch (type) {
1614				case BP_VAR_R:
1615					zend_error(E_NOTICE, "Undefined index: %s", ZSTR_VAL(offset_key));
1616					/* break missing intentionally */
1617				case BP_VAR_UNSET:
1618				case BP_VAR_IS:
1619					retval = &EG(uninitialized_zval);
1620					break;
1621				case BP_VAR_RW:
1622					zend_error(E_NOTICE,"Undefined index: %s", ZSTR_VAL(offset_key));
1623					retval = zend_hash_update(ht, offset_key, &EG(uninitialized_zval));
1624					break;
1625				case BP_VAR_W:
1626					retval = zend_hash_add_new(ht, offset_key, &EG(uninitialized_zval));
1627					break;
1628			}
1629		}
1630	} else {
1631		switch (Z_TYPE_P(dim)) {
1632			case IS_UNDEF:
1633				zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
1634				/* break missing intentionally */
1635			case IS_NULL:
1636				offset_key = ZSTR_EMPTY_ALLOC();
1637				goto str_index;
1638			case IS_DOUBLE:
1639				hval = zend_dval_to_lval(Z_DVAL_P(dim));
1640				goto num_index;
1641			case IS_RESOURCE:
1642				zend_error(E_NOTICE, "Resource ID#%pd used as offset, casting to integer (%pd)", Z_RES_HANDLE_P(dim), Z_RES_HANDLE_P(dim));
1643				hval = Z_RES_HANDLE_P(dim);
1644				goto num_index;
1645			case IS_FALSE:
1646				hval = 0;
1647				goto num_index;
1648			case IS_TRUE:
1649				hval = 1;
1650				goto num_index;
1651			case IS_REFERENCE:
1652				dim = Z_REFVAL_P(dim);
1653				goto try_again;
1654			default:
1655				zend_error(E_WARNING, "Illegal offset type");
1656				retval = (type == BP_VAR_W || type == BP_VAR_RW) ?
1657					NULL : &EG(uninitialized_zval);
1658		}
1659	}
1660	return retval;
1661}
1662
1663static zend_never_inline zval* ZEND_FASTCALL zend_fetch_dimension_address_inner_W(HashTable *ht, const zval *dim)
1664{
1665	return zend_fetch_dimension_address_inner(ht, dim, IS_TMP_VAR, BP_VAR_W);
1666}
1667
1668static zend_never_inline zval* ZEND_FASTCALL zend_fetch_dimension_address_inner_W_CONST(HashTable *ht, const zval *dim)
1669{
1670	return zend_fetch_dimension_address_inner(ht, dim, IS_CONST, BP_VAR_W);
1671}
1672
1673static zend_never_inline zval* ZEND_FASTCALL zend_fetch_dimension_address_inner_RW(HashTable *ht, const zval *dim)
1674{
1675	return zend_fetch_dimension_address_inner(ht, dim, IS_TMP_VAR, BP_VAR_RW);
1676}
1677
1678static zend_never_inline zval* ZEND_FASTCALL zend_fetch_dimension_address_inner_RW_CONST(HashTable *ht, const zval *dim)
1679{
1680	return zend_fetch_dimension_address_inner(ht, dim, IS_CONST, BP_VAR_RW);
1681}
1682
1683static zend_always_inline void zend_fetch_dimension_address(zval *result, zval *container, zval *dim, int dim_type, int type)
1684{
1685    zval *retval;
1686
1687	if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
1688try_array:
1689		SEPARATE_ARRAY(container);
1690fetch_from_array:
1691		if (dim == NULL) {
1692			retval = zend_hash_next_index_insert(Z_ARRVAL_P(container), &EG(uninitialized_zval));
1693			if (UNEXPECTED(retval == NULL)) {
1694				zend_error(E_WARNING, "Cannot add element to the array as the next element is already occupied");
1695				ZVAL_ERROR(result);
1696				return;
1697			}
1698		} else {
1699			retval = zend_fetch_dimension_address_inner(Z_ARRVAL_P(container), dim, dim_type, type);
1700			if (UNEXPECTED(!retval)) {
1701				ZVAL_ERROR(result);
1702				return;
1703			}
1704		}
1705		ZVAL_INDIRECT(result, retval);
1706		return;
1707	} else if (EXPECTED(Z_TYPE_P(container) == IS_REFERENCE)) {
1708		container = Z_REFVAL_P(container);
1709		if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
1710			goto try_array;
1711		}
1712	}
1713	if (EXPECTED(Z_TYPE_P(container) == IS_STRING)) {
1714		if (type != BP_VAR_UNSET && UNEXPECTED(Z_STRLEN_P(container) == 0)) {
1715			zval_ptr_dtor_nogc(container);
1716convert_to_array:
1717			ZVAL_NEW_ARR(container);
1718			zend_hash_init(Z_ARRVAL_P(container), 8, NULL, ZVAL_PTR_DTOR, 0);
1719			goto fetch_from_array;
1720		}
1721
1722		if (dim == NULL) {
1723			zend_throw_error(NULL, "[] operator not supported for strings");
1724		} else {
1725			zend_check_string_offset(dim, type);
1726			zend_wrong_string_offset();
1727		}
1728		ZVAL_ERROR(result);
1729	} else if (EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
1730		if (/*dim_type == IS_CV &&*/ dim && UNEXPECTED(Z_TYPE_P(dim) == IS_UNDEF)) {
1731			zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
1732			dim = &EG(uninitialized_zval);
1733		}
1734		if (!Z_OBJ_HT_P(container)->read_dimension) {
1735			zend_throw_error(NULL, "Cannot use object as array");
1736			ZVAL_ERROR(result);
1737		} else {
1738			retval = Z_OBJ_HT_P(container)->read_dimension(container, dim, type, result);
1739
1740			if (UNEXPECTED(retval == &EG(uninitialized_zval))) {
1741				zend_class_entry *ce = Z_OBJCE_P(container);
1742
1743				ZVAL_NULL(result);
1744				zend_error(E_NOTICE, "Indirect modification of overloaded element of %s has no effect", ZSTR_VAL(ce->name));
1745			} else if (EXPECTED(retval && Z_TYPE_P(retval) != IS_UNDEF)) {
1746				if (!Z_ISREF_P(retval)) {
1747					if (Z_REFCOUNTED_P(retval) &&
1748					    Z_REFCOUNT_P(retval) > 1) {
1749						if (Z_TYPE_P(retval) != IS_OBJECT) {
1750							Z_DELREF_P(retval);
1751							ZVAL_DUP(result, retval);
1752							retval = result;
1753						} else {
1754							ZVAL_COPY_VALUE(result, retval);
1755							retval = result;
1756						}
1757					}
1758					if (Z_TYPE_P(retval) != IS_OBJECT) {
1759						zend_class_entry *ce = Z_OBJCE_P(container);
1760						zend_error(E_NOTICE, "Indirect modification of overloaded element of %s has no effect", ZSTR_VAL(ce->name));
1761					}
1762				} else if (UNEXPECTED(Z_REFCOUNT_P(retval) == 1)) {
1763					ZVAL_UNREF(retval);
1764				}
1765				if (result != retval) {
1766					ZVAL_INDIRECT(result, retval);
1767				}
1768			} else {
1769				ZVAL_ERROR(result);
1770			}
1771		}
1772	} else {
1773		if (type != BP_VAR_W && UNEXPECTED(Z_TYPE_P(container) == IS_UNDEF)) {
1774			zval_undefined_cv(EG(current_execute_data)->opline->op1.var, EG(current_execute_data));
1775		}
1776		if (/*dim_type == IS_CV &&*/ dim && UNEXPECTED(Z_TYPE_P(dim) == IS_UNDEF)) {
1777			zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
1778		}
1779		if (EXPECTED(Z_TYPE_P(container) <= IS_FALSE)) {
1780			if (type != BP_VAR_UNSET) {
1781				goto convert_to_array;
1782			} else {
1783				/* for read-mode only */
1784				ZVAL_NULL(result);
1785			}
1786		} else if (EXPECTED(Z_ISERROR_P(container))) {
1787			ZVAL_ERROR(result);
1788		} else {
1789			if (type == BP_VAR_UNSET) {
1790				zend_error(E_WARNING, "Cannot unset offset in a non-array variable");
1791				ZVAL_NULL(result);
1792			} else {
1793				zend_error(E_WARNING, "Cannot use a scalar value as an array");
1794				ZVAL_ERROR(result);
1795			}
1796		}
1797	}
1798}
1799
1800static zend_never_inline void zend_fetch_dimension_address_W(zval *result, zval *container_ptr, zval *dim, int dim_type)
1801{
1802	zend_fetch_dimension_address(result, container_ptr, dim, dim_type, BP_VAR_W);
1803}
1804
1805static zend_never_inline void zend_fetch_dimension_address_RW(zval *result, zval *container_ptr, zval *dim, int dim_type)
1806{
1807	zend_fetch_dimension_address(result, container_ptr, dim, dim_type, BP_VAR_RW);
1808}
1809
1810static zend_never_inline void zend_fetch_dimension_address_UNSET(zval *result, zval *container_ptr, zval *dim, int dim_type)
1811{
1812	zend_fetch_dimension_address(result, container_ptr, dim, dim_type, BP_VAR_UNSET);
1813}
1814
1815static zend_always_inline void zend_fetch_dimension_address_read(zval *result, zval *container, zval *dim, int dim_type, int type, int support_strings, int slow)
1816{
1817	zval *retval;
1818
1819	if (!slow) {
1820		if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
1821try_array:
1822			retval = zend_fetch_dimension_address_inner(Z_ARRVAL_P(container), dim, dim_type, type);
1823			ZVAL_COPY(result, retval);
1824			return;
1825		} else if (EXPECTED(Z_TYPE_P(container) == IS_REFERENCE)) {
1826			container = Z_REFVAL_P(container);
1827			if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
1828				goto try_array;
1829			}
1830		}
1831	}
1832	if (support_strings && EXPECTED(Z_TYPE_P(container) == IS_STRING)) {
1833		zend_long offset;
1834
1835try_string_offset:
1836		if (UNEXPECTED(Z_TYPE_P(dim) != IS_LONG)) {
1837			switch (Z_TYPE_P(dim)) {
1838				/* case IS_LONG: */
1839				case IS_STRING:
1840					if (IS_LONG == is_numeric_string(Z_STRVAL_P(dim), Z_STRLEN_P(dim), NULL, NULL, -1)) {
1841						break;
1842					}
1843					if (type == BP_VAR_IS) {
1844						ZVAL_NULL(result);
1845						return;
1846					}
1847					zend_error(E_WARNING, "Illegal string offset '%s'", Z_STRVAL_P(dim));
1848					break;
1849				case IS_UNDEF:
1850					zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
1851				case IS_DOUBLE:
1852				case IS_NULL:
1853				case IS_FALSE:
1854				case IS_TRUE:
1855					if (type != BP_VAR_IS) {
1856						zend_error(E_NOTICE, "String offset cast occurred");
1857					}
1858					break;
1859				case IS_REFERENCE:
1860					dim = Z_REFVAL_P(dim);
1861					goto try_string_offset;
1862				default:
1863					zend_error(E_WARNING, "Illegal offset type");
1864					break;
1865			}
1866
1867			offset = _zval_get_long_func(dim);
1868		} else {
1869			offset = Z_LVAL_P(dim);
1870		}
1871
1872		if (UNEXPECTED(Z_STRLEN_P(container) < (size_t)((offset < 0) ? -offset : (offset + 1)))) {
1873			if (type != BP_VAR_IS) {
1874				zend_error(E_NOTICE, "Uninitialized string offset: %pd", offset);
1875				ZVAL_EMPTY_STRING(result);
1876			} else {
1877				ZVAL_NULL(result);
1878			}
1879		} else {
1880			zend_uchar c;
1881			zend_long real_offset;
1882
1883			real_offset = (UNEXPECTED(offset < 0)) /* Handle negative offset */
1884				? (zend_long)Z_STRLEN_P(container) + offset : offset;
1885			c = (zend_uchar)Z_STRVAL_P(container)[real_offset];
1886
1887			if (CG(one_char_string)[c]) {
1888				ZVAL_INTERNED_STR(result, CG(one_char_string)[c]);
1889			} else {
1890				ZVAL_NEW_STR(result, zend_string_init(Z_STRVAL_P(container) + real_offset, 1, 0));
1891			}
1892		}
1893	} else if (EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
1894		if (/*dim_type == IS_CV &&*/ UNEXPECTED(Z_TYPE_P(dim) == IS_UNDEF)) {
1895			zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
1896			dim = &EG(uninitialized_zval);
1897		}
1898		if (!Z_OBJ_HT_P(container)->read_dimension) {
1899			zend_throw_error(NULL, "Cannot use object as array");
1900			ZVAL_NULL(result);
1901		} else {
1902			retval = Z_OBJ_HT_P(container)->read_dimension(container, dim, type, result);
1903
1904			ZEND_ASSERT(result != NULL);
1905			if (retval) {
1906				if (result != retval) {
1907					ZVAL_COPY(result, retval);
1908				}
1909			} else {
1910				ZVAL_NULL(result);
1911			}
1912		}
1913	} else {
1914		if (type != BP_VAR_IS && UNEXPECTED(Z_TYPE_P(container) == IS_UNDEF)) {
1915			zval_undefined_cv(EG(current_execute_data)->opline->op1.var, EG(current_execute_data));
1916		}
1917		if (/*dim_type == IS_CV &&*/ UNEXPECTED(Z_TYPE_P(dim) == IS_UNDEF)) {
1918			zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
1919		}
1920		ZVAL_NULL(result);
1921	}
1922}
1923
1924static zend_never_inline void zend_fetch_dimension_address_read_R(zval *result, zval *container, zval *dim, int dim_type)
1925{
1926	zend_fetch_dimension_address_read(result, container, dim, dim_type, BP_VAR_R, 1, 0);
1927}
1928
1929static zend_never_inline void zend_fetch_dimension_address_read_R_slow(zval *result, zval *container, zval *dim)
1930{
1931	zend_fetch_dimension_address_read(result, container, dim, IS_CV, BP_VAR_R, 1, 1);
1932}
1933
1934static zend_never_inline void zend_fetch_dimension_address_read_IS(zval *result, zval *container, zval *dim, int dim_type)
1935{
1936	zend_fetch_dimension_address_read(result, container, dim, dim_type, BP_VAR_IS, 1, 0);
1937}
1938
1939static zend_never_inline void zend_fetch_dimension_address_read_LIST(zval *result, zval *container, zval *dim)
1940{
1941	zend_fetch_dimension_address_read(result, container, dim, IS_TMP_VAR, BP_VAR_R, 0, 0);
1942}
1943
1944ZEND_API void zend_fetch_dimension_by_zval(zval *result, zval *container, zval *dim)
1945{
1946	zend_fetch_dimension_address_read_R(result, container, dim, IS_TMP_VAR);
1947}
1948
1949ZEND_API void zend_fetch_dimension_by_zval_is(zval *result, zval *container, zval *dim, int dim_type)
1950{
1951	zend_fetch_dimension_address_read(result, container, dim, dim_type, BP_VAR_IS, 1, 0);
1952}
1953
1954
1955static zend_always_inline void zend_fetch_property_address(zval *result, zval *container, uint32_t container_op_type, zval *prop_ptr, uint32_t prop_op_type, void **cache_slot, int type)
1956{
1957    if (container_op_type != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
1958		do {
1959			if (container_op_type == IS_VAR && UNEXPECTED(Z_ISERROR_P(container))) {
1960				ZVAL_ERROR(result);
1961				return;
1962			}
1963
1964			if (Z_ISREF_P(container)) {
1965				container = Z_REFVAL_P(container);
1966				if (EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
1967					break;
1968				}
1969			}
1970
1971			/* this should modify object only if it's empty */
1972			if (type != BP_VAR_UNSET &&
1973			    EXPECTED(Z_TYPE_P(container) <= IS_FALSE ||
1974			      (Z_TYPE_P(container) == IS_STRING && Z_STRLEN_P(container)==0))) {
1975				zval_ptr_dtor_nogc(container);
1976				object_init(container);
1977			} else {
1978				zend_error(E_WARNING, "Attempt to modify property of non-object");
1979				ZVAL_ERROR(result);
1980				return;
1981			}
1982		} while (0);
1983	}
1984	if (prop_op_type == IS_CONST &&
1985	    EXPECTED(Z_OBJCE_P(container) == CACHED_PTR_EX(cache_slot))) {
1986		uint32_t prop_offset = (uint32_t)(intptr_t)CACHED_PTR_EX(cache_slot + 1);
1987		zend_object *zobj = Z_OBJ_P(container);
1988		zval *retval;
1989
1990		if (EXPECTED(prop_offset != (uint32_t)ZEND_DYNAMIC_PROPERTY_OFFSET)) {
1991			retval = OBJ_PROP(zobj, prop_offset);
1992			if (EXPECTED(Z_TYPE_P(retval) != IS_UNDEF)) {
1993				ZVAL_INDIRECT(result, retval);
1994				return;
1995			}
1996		} else if (EXPECTED(zobj->properties != NULL)) {
1997			if (UNEXPECTED(GC_REFCOUNT(zobj->properties) > 1)) {
1998				if (EXPECTED(!(GC_FLAGS(zobj->properties) & IS_ARRAY_IMMUTABLE))) {
1999					GC_REFCOUNT(zobj->properties)--;
2000				}
2001				zobj->properties = zend_array_dup(zobj->properties);
2002			}
2003			retval = zend_hash_find(zobj->properties, Z_STR_P(prop_ptr));
2004			if (EXPECTED(retval)) {
2005				ZVAL_INDIRECT(result, retval);
2006				return;
2007			}
2008		}
2009	}
2010	if (EXPECTED(Z_OBJ_HT_P(container)->get_property_ptr_ptr)) {
2011		zval *ptr = Z_OBJ_HT_P(container)->get_property_ptr_ptr(container, prop_ptr, type, cache_slot);
2012		if (NULL == ptr) {
2013			if (EXPECTED(Z_OBJ_HT_P(container)->read_property)) {
2014				ptr = Z_OBJ_HT_P(container)->read_property(container, prop_ptr, type, cache_slot, result);
2015				if (ptr != result) {
2016					ZVAL_INDIRECT(result, ptr);
2017				} else if (UNEXPECTED(Z_ISREF_P(ptr) && Z_REFCOUNT_P(ptr) == 1)) {
2018					ZVAL_UNREF(ptr);
2019				}
2020			} else {
2021				zend_throw_error(NULL, "Cannot access undefined property for object with overloaded property access");
2022				ZVAL_ERROR(result);
2023			}
2024		} else {
2025			ZVAL_INDIRECT(result, ptr);
2026		}
2027	} else if (EXPECTED(Z_OBJ_HT_P(container)->read_property)) {
2028		zval *ptr = Z_OBJ_HT_P(container)->read_property(container, prop_ptr, type, cache_slot, result);
2029		if (ptr != result) {
2030			ZVAL_INDIRECT(result, ptr);
2031		} else if (UNEXPECTED(Z_ISREF_P(ptr) && Z_REFCOUNT_P(ptr) == 1)) {
2032			ZVAL_UNREF(ptr);
2033		}
2034	} else {
2035		zend_error(E_WARNING, "This object doesn't support property references");
2036		ZVAL_ERROR(result);
2037	}
2038}
2039
2040#if ZEND_INTENSIVE_DEBUGGING
2041
2042#define CHECK_SYMBOL_TABLES()													\
2043	zend_hash_apply(&EG(symbol_table), zend_check_symbol);			\
2044	if (&EG(symbol_table)!=EX(symbol_table)) {							\
2045		zend_hash_apply(EX(symbol_table), zend_check_symbol);	\
2046	}
2047
2048static int zend_check_symbol(zval *pz)
2049{
2050	if (Z_TYPE_P(pz) == IS_INDIRECT) {
2051		pz = Z_INDIRECT_P(pz);
2052	}
2053	if (Z_TYPE_P(pz) > 10) {
2054		fprintf(stderr, "Warning!  %x has invalid type!\n", *pz);
2055/* See http://support.microsoft.com/kb/190351 */
2056#ifdef ZEND_WIN32
2057		fflush(stderr);
2058#endif
2059	} else if (Z_TYPE_P(pz) == IS_ARRAY) {
2060		zend_hash_apply(Z_ARRVAL_P(pz), zend_check_symbol);
2061	} else if (Z_TYPE_P(pz) == IS_OBJECT) {
2062		/* OBJ-TBI - doesn't support new object model! */
2063		zend_hash_apply(Z_OBJPROP_P(pz), zend_check_symbol);
2064	}
2065
2066	return 0;
2067}
2068
2069
2070#else
2071#define CHECK_SYMBOL_TABLES()
2072#endif
2073
2074ZEND_API void execute_internal(zend_execute_data *execute_data, zval *return_value)
2075{
2076	execute_data->func->internal_function.handler(execute_data, return_value);
2077}
2078
2079ZEND_API void zend_clean_and_cache_symbol_table(zend_array *symbol_table) /* {{{ */
2080{
2081	if (EG(symtable_cache_ptr) >= EG(symtable_cache_limit)) {
2082		zend_array_destroy(symbol_table);
2083	} else {
2084		/* clean before putting into the cache, since clean
2085		   could call dtors, which could use cached hash */
2086		zend_symtable_clean(symbol_table);
2087		*(++EG(symtable_cache_ptr)) = symbol_table;
2088	}
2089}
2090/* }}} */
2091
2092static zend_always_inline void i_free_compiled_variables(zend_execute_data *execute_data) /* {{{ */
2093{
2094	zval *cv = EX_VAR_NUM(0);
2095	zval *end = cv + EX(func)->op_array.last_var;
2096	while (EXPECTED(cv != end)) {
2097		if (Z_REFCOUNTED_P(cv)) {
2098			if (!Z_DELREF_P(cv)) {
2099				zend_refcounted *r = Z_COUNTED_P(cv);
2100				ZVAL_NULL(cv);
2101				zval_dtor_func(r);
2102			} else {
2103				GC_ZVAL_CHECK_POSSIBLE_ROOT(cv);
2104			}
2105		}
2106		cv++;
2107 	}
2108}
2109/* }}} */
2110
2111void zend_free_compiled_variables(zend_execute_data *execute_data) /* {{{ */
2112{
2113	i_free_compiled_variables(execute_data);
2114}
2115/* }}} */
2116
2117static zend_never_inline ZEND_COLD ZEND_NORETURN void ZEND_FASTCALL zend_interrupt(void) /* {{{ */
2118{
2119	zend_timeout(0);
2120}
2121/* }}} */
2122
2123#define ZEND_VM_INTERRUPT_CHECK() do { \
2124		if (UNEXPECTED(EG(timed_out))) { \
2125			zend_interrupt(); \
2126		} \
2127	} while (0)
2128
2129/*
2130 * Stack Frame Layout (the whole stack frame is allocated at once)
2131 * ==================
2132 *
2133 *                             +========================================+
2134 * EG(current_execute_data) -> | zend_execute_data                      |
2135 *                             +----------------------------------------+
2136 *     EX_CV_NUM(0) ---------> | VAR[0] = ARG[1]                        |
2137 *                             | ...                                    |
2138 *                             | VAR[op_array->num_args-1] = ARG[N]     |
2139 *                             | ...                                    |
2140 *                             | VAR[op_array->last_var-1]              |
2141 *                             | VAR[op_array->last_var] = TMP[0]       |
2142 *                             | ...                                    |
2143 *                             | VAR[op_array->last_var+op_array->T-1]  |
2144 *                             | ARG[N+1] (extra_args)                  |
2145 *                             | ...                                    |
2146 *                             +----------------------------------------+
2147 */
2148
2149static zend_always_inline void i_init_func_execute_data(zend_execute_data *execute_data, zend_op_array *op_array, zval *return_value, int check_this) /* {{{ */
2150{
2151	uint32_t first_extra_arg, num_args;
2152	ZEND_ASSERT(EX(func) == (zend_function*)op_array);
2153
2154	EX(opline) = op_array->opcodes;
2155	EX(call) = NULL;
2156	EX(return_value) = return_value;
2157
2158	/* Handle arguments */
2159	first_extra_arg = op_array->num_args;
2160	num_args = EX_NUM_ARGS();
2161	if (UNEXPECTED(num_args > first_extra_arg)) {
2162		if (EXPECTED(!(op_array->fn_flags & ZEND_ACC_CALL_VIA_TRAMPOLINE))) {
2163			zval *end, *src, *dst;
2164			uint32_t type_flags = 0;
2165
2166			if (EXPECTED((op_array->fn_flags & ZEND_ACC_HAS_TYPE_HINTS) == 0)) {
2167				/* Skip useless ZEND_RECV and ZEND_RECV_INIT opcodes */
2168				EX(opline) += first_extra_arg;
2169			}
2170
2171			/* move extra args into separate array after all CV and TMP vars */
2172			end = EX_VAR_NUM(first_extra_arg - 1);
2173			src = end + (num_args - first_extra_arg);
2174			dst = src + (op_array->last_var + op_array->T - first_extra_arg);
2175			if (EXPECTED(src != dst)) {
2176				do {
2177					type_flags |= Z_TYPE_INFO_P(src);
2178					ZVAL_COPY_VALUE(dst, src);
2179					ZVAL_UNDEF(src);
2180					src--;
2181					dst--;
2182				} while (src != end);
2183			} else {
2184				do {
2185					type_flags |= Z_TYPE_INFO_P(src);
2186					src--;
2187				} while (src != end);
2188			}
2189			ZEND_ADD_CALL_FLAG(execute_data, ((type_flags >> Z_TYPE_FLAGS_SHIFT) & IS_TYPE_REFCOUNTED));
2190		}
2191	} else if (EXPECTED((op_array->fn_flags & ZEND_ACC_HAS_TYPE_HINTS) == 0)) {
2192		/* Skip useless ZEND_RECV and ZEND_RECV_INIT opcodes */
2193		EX(opline) += num_args;
2194	}
2195
2196	/* Initialize CV variables (skip arguments) */
2197	if (EXPECTED((int)num_args < op_array->last_var)) {
2198		zval *var = EX_VAR_NUM(num_args);
2199		zval *end = EX_VAR_NUM(op_array->last_var);
2200
2201		do {
2202			ZVAL_UNDEF(var);
2203			var++;
2204		} while (var != end);
2205	}
2206
2207	if (check_this && op_array->this_var != (uint32_t)-1 && EXPECTED(Z_TYPE(EX(This)) == IS_OBJECT)) {
2208		ZVAL_OBJ(EX_VAR(op_array->this_var), Z_OBJ(EX(This)));
2209		GC_REFCOUNT(Z_OBJ(EX(This)))++;
2210	}
2211
2212	EX_LOAD_RUN_TIME_CACHE(op_array);
2213	EX_LOAD_LITERALS(op_array);
2214
2215	EG(current_execute_data) = execute_data;
2216}
2217/* }}} */
2218
2219static zend_never_inline void ZEND_FASTCALL init_func_run_time_cache(zend_op_array *op_array) /* {{{ */
2220{
2221	ZEND_ASSERT(op_array->run_time_cache == NULL);
2222	op_array->run_time_cache = zend_arena_alloc(&CG(arena), op_array->cache_size);
2223	memset(op_array->run_time_cache, 0, op_array->cache_size);
2224}
2225/* }}} */
2226
2227static zend_always_inline void i_init_code_execute_data(zend_execute_data *execute_data, zend_op_array *op_array, zval *return_value) /* {{{ */
2228{
2229	ZEND_ASSERT(EX(func) == (zend_function*)op_array);
2230
2231	EX(opline) = op_array->opcodes;
2232	EX(call) = NULL;
2233	EX(return_value) = return_value;
2234
2235	if (UNEXPECTED(op_array->this_var != (uint32_t)-1) && EXPECTED(Z_TYPE(EX(This)) == IS_OBJECT)) {
2236		GC_REFCOUNT(Z_OBJ(EX(This)))++;
2237		if (!zend_hash_add(EX(symbol_table), CG(known_strings)[ZEND_STR_THIS], &EX(This))) {
2238			GC_REFCOUNT(Z_OBJ(EX(This)))--;
2239		}
2240	}
2241
2242	zend_attach_symbol_table(execute_data);
2243
2244	if (!op_array->run_time_cache) {
2245		op_array->run_time_cache = emalloc(op_array->cache_size);
2246		memset(op_array->run_time_cache, 0, op_array->cache_size);
2247	}
2248	EX_LOAD_RUN_TIME_CACHE(op_array);
2249	EX_LOAD_LITERALS(op_array);
2250
2251	EG(current_execute_data) = execute_data;
2252}
2253/* }}} */
2254
2255static zend_always_inline void i_init_execute_data(zend_execute_data *execute_data, zend_op_array *op_array, zval *return_value) /* {{{ */
2256{
2257	ZEND_ASSERT(EX(func) == (zend_function*)op_array);
2258
2259	EX(opline) = op_array->opcodes;
2260	EX(call) = NULL;
2261	EX(return_value) = return_value;
2262
2263	if (EX_CALL_INFO() & ZEND_CALL_HAS_SYMBOL_TABLE) {
2264		if (UNEXPECTED(op_array->this_var != (uint32_t)-1) && EXPECTED(Z_TYPE(EX(This)) == IS_OBJECT)) {
2265			GC_REFCOUNT(Z_OBJ(EX(This)))++;
2266			if (!zend_hash_add(EX(symbol_table), CG(known_strings)[ZEND_STR_THIS], &EX(This))) {
2267				GC_REFCOUNT(Z_OBJ(EX(This)))--;
2268			}
2269		}
2270
2271		zend_attach_symbol_table(execute_data);
2272	} else {
2273		uint32_t first_extra_arg, num_args;
2274
2275		/* Handle arguments */
2276		first_extra_arg = op_array->num_args;
2277		num_args = EX_NUM_ARGS();
2278		if (UNEXPECTED(num_args > first_extra_arg)) {
2279			if (EXPECTED(!(op_array->fn_flags & ZEND_ACC_CALL_VIA_TRAMPOLINE))) {
2280				zval *end, *src, *dst;
2281				uint32_t type_flags = 0;
2282
2283				if (EXPECTED((op_array->fn_flags & ZEND_ACC_HAS_TYPE_HINTS) == 0)) {
2284					/* Skip useless ZEND_RECV and ZEND_RECV_INIT opcodes */
2285					EX(opline) += first_extra_arg;
2286				}
2287
2288				/* move extra args into separate array after all CV and TMP vars */
2289				end = EX_VAR_NUM(first_extra_arg - 1);
2290				src = end + (num_args - first_extra_arg);
2291				dst = src + (op_array->last_var + op_array->T - first_extra_arg);
2292				if (EXPECTED(src != dst)) {
2293					do {
2294						type_flags |= Z_TYPE_INFO_P(src);
2295						ZVAL_COPY_VALUE(dst, src);
2296						ZVAL_UNDEF(src);
2297						src--;
2298						dst--;
2299					} while (src != end);
2300				} else {
2301					do {
2302						type_flags |= Z_TYPE_INFO_P(src);
2303						src--;
2304					} while (src != end);
2305				}
2306				ZEND_ADD_CALL_FLAG(execute_data, ((type_flags >> Z_TYPE_FLAGS_SHIFT) & IS_TYPE_REFCOUNTED));
2307			}
2308		} else if (EXPECTED((op_array->fn_flags & ZEND_ACC_HAS_TYPE_HINTS) == 0)) {
2309			/* Skip useless ZEND_RECV and ZEND_RECV_INIT opcodes */
2310			EX(opline) += num_args;
2311		}
2312
2313		/* Initialize CV variables (skip arguments) */
2314		if (EXPECTED((int)num_args < op_array->last_var)) {
2315			zval *var = EX_VAR_NUM(num_args);
2316			zval *end = EX_VAR_NUM(op_array->last_var);
2317
2318			do {
2319				ZVAL_UNDEF(var);
2320				var++;
2321			} while (var != end);
2322		}
2323
2324		if (op_array->this_var != (uint32_t)-1 && EXPECTED(Z_TYPE(EX(This)) == IS_OBJECT)) {
2325			ZVAL_OBJ(EX_VAR(op_array->this_var), Z_OBJ(EX(This)));
2326			GC_REFCOUNT(Z_OBJ(EX(This)))++;
2327		}
2328	}
2329
2330	if (!op_array->run_time_cache) {
2331		if (op_array->function_name) {
2332			op_array->run_time_cache = zend_arena_alloc(&CG(arena), op_array->cache_size);
2333		} else {
2334			op_array->run_time_cache = emalloc(op_array->cache_size);
2335		}
2336		memset(op_array->run_time_cache, 0, op_array->cache_size);
2337	}
2338	EX_LOAD_RUN_TIME_CACHE(op_array);
2339	EX_LOAD_LITERALS(op_array);
2340
2341	EG(current_execute_data) = execute_data;
2342}
2343/* }}} */
2344
2345ZEND_API void zend_init_execute_data(zend_execute_data *execute_data, zend_op_array *op_array, zval *return_value) /* {{{ */
2346{
2347	EX(prev_execute_data) = EG(current_execute_data);
2348	i_init_execute_data(execute_data, op_array, return_value);
2349}
2350/* }}} */
2351
2352static zend_always_inline zend_bool zend_is_by_ref_func_arg_fetch(const zend_op *opline, zend_execute_data *call) /* {{{ */
2353{
2354	uint32_t arg_num = opline->extended_value & ZEND_FETCH_ARG_MASK;
2355
2356	if (EXPECTED(arg_num <= MAX_ARG_FLAG_NUM)) {
2357		return QUICK_ARG_SHOULD_BE_SENT_BY_REF(call->func, arg_num);
2358	}
2359	return ARG_SHOULD_BE_SENT_BY_REF(call->func, arg_num);
2360}
2361/* }}} */
2362
2363static zend_execute_data *zend_vm_stack_copy_call_frame(zend_execute_data *call, uint32_t passed_args, uint32_t additional_args) /* {{{ */
2364{
2365	zend_execute_data *new_call;
2366	int used_stack = (EG(vm_stack_top) - (zval*)call) + additional_args;
2367
2368	/* copy call frame into new stack segment */
2369	new_call = zend_vm_stack_extend(used_stack * sizeof(zval));
2370	*new_call = *call;
2371	ZEND_ADD_CALL_FLAG(new_call, ZEND_CALL_ALLOCATED);
2372
2373	if (passed_args) {
2374		zval *src = ZEND_CALL_ARG(call, 1);
2375		zval *dst = ZEND_CALL_ARG(new_call, 1);
2376		do {
2377			ZVAL_COPY_VALUE(dst, src);
2378			passed_args--;
2379			src++;
2380			dst++;
2381		} while (passed_args);
2382	}
2383
2384	/* delete old call_frame from previous stack segment */
2385	EG(vm_stack)->prev->top = (zval*)call;
2386
2387	/* delete previous stack segment if it becames empty */
2388	if (UNEXPECTED(EG(vm_stack)->prev->top == ZEND_VM_STACK_ELEMENTS(EG(vm_stack)->prev))) {
2389		zend_vm_stack r = EG(vm_stack)->prev;
2390
2391		EG(vm_stack)->prev = r->prev;
2392		efree(r);
2393	}
2394
2395	return new_call;
2396}
2397/* }}} */
2398
2399static zend_always_inline void zend_vm_stack_extend_call_frame(zend_execute_data **call, uint32_t passed_args, uint32_t additional_args) /* {{{ */
2400{
2401	if (EXPECTED((uint32_t)(EG(vm_stack_end) - EG(vm_stack_top)) > additional_args)) {
2402		EG(vm_stack_top) += additional_args;
2403	} else {
2404		*call = zend_vm_stack_copy_call_frame(*call, passed_args, additional_args);
2405	}
2406}
2407/* }}} */
2408
2409static zend_always_inline zend_generator *zend_get_running_generator(zend_execute_data *execute_data) /* {{{ */
2410{
2411	/* The generator object is stored in EX(return_value) */
2412	zend_generator *generator = (zend_generator *) EX(return_value);
2413	/* However control may currently be delegated to another generator.
2414	 * That's the one we're interested in. */
2415	return generator;
2416}
2417/* }}} */
2418
2419static void cleanup_unfinished_calls(zend_execute_data *execute_data, uint32_t op_num) /* {{{ */
2420{
2421	if (UNEXPECTED(EX(call))) {
2422		zend_execute_data *call = EX(call);
2423		zend_op *opline = EX(func)->op_array.opcodes + op_num;
2424		int level;
2425		int do_exit;
2426
2427		if (UNEXPECTED(opline->opcode == ZEND_INIT_FCALL ||
2428			opline->opcode == ZEND_INIT_FCALL_BY_NAME ||
2429			opline->opcode == ZEND_INIT_DYNAMIC_CALL ||
2430			opline->opcode == ZEND_INIT_METHOD_CALL ||
2431			opline->opcode == ZEND_INIT_STATIC_METHOD_CALL)) {
2432			ZEND_ASSERT(op_num);
2433			opline--;
2434		}
2435
2436		do {
2437			/* If the exception was thrown during a function call there might be
2438			 * arguments pushed to the stack that have to be dtor'ed. */
2439
2440			/* find the number of actually passed arguments */
2441			level = 0;
2442			do_exit = 0;
2443			do {
2444				switch (opline->opcode) {
2445					case ZEND_DO_FCALL:
2446					case ZEND_DO_ICALL:
2447					case ZEND_DO_UCALL:
2448					case ZEND_DO_FCALL_BY_NAME:
2449						level++;
2450						break;
2451					case ZEND_INIT_FCALL:
2452					case ZEND_INIT_FCALL_BY_NAME:
2453					case ZEND_INIT_NS_FCALL_BY_NAME:
2454					case ZEND_INIT_DYNAMIC_CALL:
2455					case ZEND_INIT_USER_CALL:
2456					case ZEND_INIT_METHOD_CALL:
2457					case ZEND_INIT_STATIC_METHOD_CALL:
2458					case ZEND_NEW:
2459						if (level == 0) {
2460							ZEND_CALL_NUM_ARGS(call) = 0;
2461							do_exit = 1;
2462						}
2463						level--;
2464						break;
2465					case ZEND_SEND_VAL:
2466					case ZEND_SEND_VAL_EX:
2467					case ZEND_SEND_VAR:
2468					case ZEND_SEND_VAR_EX:
2469					case ZEND_SEND_REF:
2470					case ZEND_SEND_VAR_NO_REF:
2471					case ZEND_SEND_USER:
2472						if (level == 0) {
2473							ZEND_CALL_NUM_ARGS(call) = opline->op2.num;
2474							do_exit = 1;
2475						}
2476						break;
2477					case ZEND_SEND_ARRAY:
2478					case ZEND_SEND_UNPACK:
2479						if (level == 0) {
2480							do_exit = 1;
2481						}
2482						break;
2483				}
2484				if (!do_exit) {
2485					opline--;
2486				}
2487			} while (!do_exit);
2488			if (call->prev_execute_data) {
2489				/* skip current call region */
2490				level = 0;
2491				do_exit = 0;
2492				do {
2493					switch (opline->opcode) {
2494						case ZEND_DO_FCALL:
2495						case ZEND_DO_ICALL:
2496						case ZEND_DO_UCALL:
2497						case ZEND_DO_FCALL_BY_NAME:
2498							level++;
2499							break;
2500						case ZEND_INIT_FCALL:
2501						case ZEND_INIT_FCALL_BY_NAME:
2502						case ZEND_INIT_NS_FCALL_BY_NAME:
2503						case ZEND_INIT_DYNAMIC_CALL:
2504						case ZEND_INIT_USER_CALL:
2505						case ZEND_INIT_METHOD_CALL:
2506						case ZEND_INIT_STATIC_METHOD_CALL:
2507						case ZEND_NEW:
2508							if (level == 0) {
2509								do_exit = 1;
2510							}
2511							level--;
2512							break;
2513					}
2514					opline--;
2515				} while (!do_exit);
2516			}
2517
2518			zend_vm_stack_free_args(EX(call));
2519
2520			if (ZEND_CALL_INFO(call) & ZEND_CALL_RELEASE_THIS) {
2521				if (ZEND_CALL_INFO(call) & ZEND_CALL_CTOR) {
2522					GC_REFCOUNT(Z_OBJ(call->This))--;
2523					if (GC_REFCOUNT(Z_OBJ(call->This)) == 1) {
2524						zend_object_store_ctor_failed(Z_OBJ(call->This));
2525					}
2526				}
2527				OBJ_RELEASE(Z_OBJ(call->This));
2528			}
2529			if (call->func->common.fn_flags & ZEND_ACC_CLOSURE) {
2530				zend_object_release((zend_object *) call->func->common.prototype);
2531			} else if (call->func->common.fn_flags & ZEND_ACC_CALL_VIA_TRAMPOLINE) {
2532				zend_string_release(call->func->common.function_name);
2533				zend_free_trampoline(call->func);
2534			}
2535
2536			EX(call) = call->prev_execute_data;
2537			zend_vm_stack_free_call_frame(call);
2538			call = EX(call);
2539		} while (call);
2540	}
2541}
2542/* }}} */
2543
2544static void cleanup_live_vars(zend_execute_data *execute_data, uint32_t op_num, uint32_t catch_op_num) /* {{{ */
2545{
2546	int i;
2547
2548	for (i = 0; i < EX(func)->op_array.last_live_range; i++) {
2549		const zend_live_range *range = &EX(func)->op_array.live_range[i];
2550		if (range->start > op_num) {
2551			/* further blocks will not be relevant... */
2552			break;
2553		} else if (op_num < range->end) {
2554			if (!catch_op_num || catch_op_num >= range->end) {
2555				uint32_t kind = range->var & ZEND_LIVE_MASK;
2556				uint32_t var_num = range->var & ~ZEND_LIVE_MASK;
2557				zval *var = EX_VAR(var_num);
2558
2559				if (kind == ZEND_LIVE_TMPVAR) {
2560					zval_ptr_dtor_nogc(var);
2561				} else if (kind == ZEND_LIVE_LOOP) {
2562					if (Z_TYPE_P(var) != IS_ARRAY && Z_FE_ITER_P(var) != (uint32_t)-1) {
2563						zend_hash_iterator_del(Z_FE_ITER_P(var));
2564					}
2565					zval_ptr_dtor_nogc(var);
2566				} else if (kind == ZEND_LIVE_ROPE) {
2567					zend_string **rope = (zend_string **)var;
2568					zend_op *last = EX(func)->op_array.opcodes + op_num;
2569					while ((last->opcode != ZEND_ROPE_ADD && last->opcode != ZEND_ROPE_INIT)
2570							|| last->result.var != var_num) {
2571						ZEND_ASSERT(last >= EX(func)->op_array.opcodes);
2572						last--;
2573					}
2574					if (last->opcode == ZEND_ROPE_INIT) {
2575						zend_string_release(*rope);
2576					} else {
2577						int j = last->extended_value;
2578						do {
2579							zend_string_release(rope[j]);
2580						} while (j--);
2581					}
2582				} else if (kind == ZEND_LIVE_SILENCE) {
2583					/* restore previous error_reporting value */
2584					if (!EG(error_reporting) && Z_LVAL_P(var) != 0) {
2585						EG(error_reporting) = Z_LVAL_P(var);
2586					}
2587				}
2588			}
2589		}
2590	}
2591}
2592/* }}} */
2593
2594void zend_cleanup_unfinished_execution(zend_execute_data *execute_data, uint32_t op_num, uint32_t catch_op_num) {
2595	cleanup_unfinished_calls(execute_data, op_num);
2596	cleanup_live_vars(execute_data, op_num, catch_op_num);
2597}
2598
2599static void zend_swap_operands(zend_op *op) /* {{{ */
2600{
2601	znode_op     tmp;
2602	zend_uchar   tmp_type;
2603
2604	tmp          = op->op1;
2605	tmp_type     = op->op1_type;
2606	op->op1      = op->op2;
2607	op->op1_type = op->op2_type;
2608	op->op2      = tmp;
2609	op->op2_type = tmp_type;
2610}
2611/* }}} */
2612
2613static zend_never_inline zend_execute_data *zend_init_dynamic_call_string(zend_string *function, uint32_t num_args) /* {{{ */
2614{
2615	zend_function *fbc;
2616	zval *func;
2617	zend_class_entry *called_scope;
2618	zend_string *lcname;
2619	const char *colon;
2620
2621	if ((colon = zend_memrchr(ZSTR_VAL(function), ':', ZSTR_LEN(function))) != NULL &&
2622		colon > ZSTR_VAL(function) &&
2623		*(colon-1) == ':'
2624	) {
2625		zend_string *mname;
2626		size_t cname_length = colon - ZSTR_VAL(function) - 1;
2627		size_t mname_length = ZSTR_LEN(function) - cname_length - (sizeof("::") - 1);
2628
2629		lcname = zend_string_init(ZSTR_VAL(function), cname_length, 0);
2630
2631		called_scope = zend_fetch_class_by_name(lcname, NULL, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
2632		if (UNEXPECTED(called_scope == NULL)) {
2633			zend_string_release(lcname);
2634			return NULL;
2635		}
2636
2637		mname = zend_string_init(ZSTR_VAL(function) + (cname_length + sizeof("::") - 1), mname_length, 0);
2638
2639		if (called_scope->get_static_method) {
2640			fbc = called_scope->get_static_method(called_scope, mname);
2641		} else {
2642			fbc = zend_std_get_static_method(called_scope, mname, NULL);
2643		}
2644		if (UNEXPECTED(fbc == NULL)) {
2645			if (EXPECTED(!EG(exception))) {
2646				zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(called_scope->name), ZSTR_VAL(mname));
2647			}
2648			zend_string_release(lcname);
2649			zend_string_release(mname);
2650			return NULL;
2651		}
2652
2653		zend_string_release(lcname);
2654		zend_string_release(mname);
2655
2656		if (UNEXPECTED(!(fbc->common.fn_flags & ZEND_ACC_STATIC))) {
2657			if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
2658				zend_error(E_DEPRECATED,
2659					"Non-static method %s::%s() should not be called statically",
2660					ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
2661				if (UNEXPECTED(EG(exception) != NULL)) {
2662					return NULL;
2663				}
2664			} else {
2665				zend_throw_error(
2666					zend_ce_error,
2667					"Non-static method %s::%s() cannot be called statically",
2668					ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
2669				return NULL;
2670			}
2671		}
2672	} else {
2673		if (ZSTR_VAL(function)[0] == '\\') {
2674			lcname = zend_string_alloc(ZSTR_LEN(function) - 1, 0);
2675			zend_str_tolower_copy(ZSTR_VAL(lcname), ZSTR_VAL(function) + 1, ZSTR_LEN(function) - 1);
2676		} else {
2677			lcname = zend_string_tolower(function);
2678		}
2679		if (UNEXPECTED((func = zend_hash_find(EG(function_table), lcname)) == NULL)) {
2680			zend_throw_error(NULL, "Call to undefined function %s()", ZSTR_VAL(function));
2681			zend_string_release(lcname);
2682			return NULL;
2683		}
2684		zend_string_release(lcname);
2685
2686		fbc = Z_FUNC_P(func);
2687		called_scope = NULL;
2688	}
2689
2690	if (EXPECTED(fbc->type == ZEND_USER_FUNCTION) && UNEXPECTED(!fbc->op_array.run_time_cache)) {
2691		init_func_run_time_cache(&fbc->op_array);
2692	}
2693
2694	return zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION | ZEND_CALL_DYNAMIC,
2695		fbc, num_args, called_scope, NULL);
2696}
2697/* }}} */
2698
2699static zend_never_inline zend_execute_data *zend_init_dynamic_call_object(zval *function, uint32_t num_args) /* {{{ */
2700{
2701	zend_function *fbc;
2702	zend_class_entry *called_scope;
2703	zend_object *object;
2704	uint32_t call_info = ZEND_CALL_NESTED_FUNCTION | ZEND_CALL_DYNAMIC;
2705
2706	if (EXPECTED(Z_OBJ_HANDLER_P(function, get_closure)) &&
2707	    EXPECTED(Z_OBJ_HANDLER_P(function, get_closure)(function, &called_scope, &fbc, &object) == SUCCESS)) {
2708
2709		if (fbc->common.fn_flags & ZEND_ACC_CLOSURE) {
2710			/* Delay closure destruction until its invocation */
2711			ZEND_ASSERT(GC_TYPE((zend_object*)fbc->common.prototype) == IS_OBJECT);
2712			GC_REFCOUNT((zend_object*)fbc->common.prototype)++;
2713			call_info |= ZEND_CALL_CLOSURE;
2714		} else if (object) {
2715			call_info |= ZEND_CALL_RELEASE_THIS;
2716			GC_REFCOUNT(object)++; /* For $this pointer */
2717		}
2718	} else {
2719		zend_throw_error(NULL, "Function name must be a string");
2720		return NULL;
2721	}
2722
2723	if (EXPECTED(fbc->type == ZEND_USER_FUNCTION) && UNEXPECTED(!fbc->op_array.run_time_cache)) {
2724		init_func_run_time_cache(&fbc->op_array);
2725	}
2726
2727	return zend_vm_stack_push_call_frame(call_info,
2728		fbc, num_args, called_scope, object);
2729}
2730/* }}} */
2731
2732static zend_never_inline zend_execute_data *zend_init_dynamic_call_array(zend_array *function, uint32_t num_args) /* {{{ */
2733{
2734	zend_function *fbc;
2735	zend_class_entry *called_scope;
2736	zend_object *object;
2737	uint32_t call_info = ZEND_CALL_NESTED_FUNCTION | ZEND_CALL_DYNAMIC;
2738
2739	if (zend_hash_num_elements(function) == 2) {
2740		zval *obj;
2741		zval *method;
2742		obj = zend_hash_index_find(function, 0);
2743		method = zend_hash_index_find(function, 1);
2744
2745		if (UNEXPECTED(!obj) || UNEXPECTED(!method)) {
2746			zend_throw_error(NULL, "Array callback has to contain indices 0 and 1");
2747			return NULL;
2748		}
2749
2750		ZVAL_DEREF(obj);
2751		if (UNEXPECTED(Z_TYPE_P(obj) != IS_STRING) && UNEXPECTED(Z_TYPE_P(obj) != IS_OBJECT)) {
2752			zend_throw_error(NULL, "First array member is not a valid class name or object");
2753			return NULL;
2754		}
2755
2756		ZVAL_DEREF(method);
2757		if (UNEXPECTED(Z_TYPE_P(method) != IS_STRING)) {
2758			zend_throw_error(NULL, "Second array member is not a valid method");
2759			return NULL;
2760		}
2761
2762		if (Z_TYPE_P(obj) == IS_STRING) {
2763			object = NULL;
2764			called_scope = zend_fetch_class_by_name(Z_STR_P(obj), NULL, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
2765			if (UNEXPECTED(called_scope == NULL)) {
2766				return NULL;
2767			}
2768
2769			if (called_scope->get_static_method) {
2770				fbc = called_scope->get_static_method(called_scope, Z_STR_P(method));
2771			} else {
2772				fbc = zend_std_get_static_method(called_scope, Z_STR_P(method), NULL);
2773			}
2774			if (UNEXPECTED(fbc == NULL)) {
2775				if (EXPECTED(!EG(exception))) {
2776					zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(called_scope->name), Z_STRVAL_P(method));
2777				}
2778				return NULL;
2779			}
2780			if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
2781				if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
2782					zend_error(E_DEPRECATED,
2783						"Non-static method %s::%s() should not be called statically",
2784						ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
2785					if (UNEXPECTED(EG(exception) != NULL)) {
2786						return NULL;
2787					}
2788				} else {
2789					zend_throw_error(
2790						zend_ce_error,
2791						"Non-static method %s::%s() cannot be called statically",
2792						ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
2793					return NULL;
2794				}
2795			}
2796		} else {
2797			called_scope = Z_OBJCE_P(obj);
2798			object = Z_OBJ_P(obj);
2799
2800			fbc = Z_OBJ_HT_P(obj)->get_method(&object, Z_STR_P(method), NULL);
2801			if (UNEXPECTED(fbc == NULL)) {
2802				if (EXPECTED(!EG(exception))) {
2803					zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(object->ce->name), Z_STRVAL_P(method));
2804				}
2805				return NULL;
2806			}
2807
2808			if ((fbc->common.fn_flags & ZEND_ACC_STATIC) != 0) {
2809				object = NULL;
2810			} else {
2811				call_info |= ZEND_CALL_RELEASE_THIS;
2812				GC_REFCOUNT(object)++; /* For $this pointer */
2813			}
2814		}
2815	} else {
2816		zend_throw_error(NULL, "Function name must be a string");
2817		return NULL;
2818	}
2819
2820	if (EXPECTED(fbc->type == ZEND_USER_FUNCTION) && UNEXPECTED(!fbc->op_array.run_time_cache)) {
2821		init_func_run_time_cache(&fbc->op_array);
2822	}
2823
2824	return zend_vm_stack_push_call_frame(call_info,
2825		fbc, num_args, called_scope, object);
2826}
2827/* }}} */
2828
2829#define ZEND_FAKE_OP_ARRAY ((zend_op_array*)(zend_intptr_t)-1)
2830
2831static zend_never_inline zend_op_array* ZEND_FASTCALL zend_include_or_eval(zval *inc_filename, int type) /* {{{ */
2832{
2833	zend_op_array *new_op_array = NULL;
2834	zval tmp_inc_filename;
2835
2836	ZVAL_UNDEF(&tmp_inc_filename);
2837	if (Z_TYPE_P(inc_filename) != IS_STRING) {
2838		ZVAL_STR(&tmp_inc_filename, zval_get_string(inc_filename));
2839		inc_filename = &tmp_inc_filename;
2840	}
2841
2842	if (type != ZEND_EVAL && strlen(Z_STRVAL_P(inc_filename)) != Z_STRLEN_P(inc_filename)) {
2843		if (type == ZEND_INCLUDE_ONCE || type == ZEND_INCLUDE) {
2844			zend_message_dispatcher(ZMSG_FAILED_INCLUDE_FOPEN, Z_STRVAL_P(inc_filename));
2845		} else {
2846			zend_message_dispatcher(ZMSG_FAILED_REQUIRE_FOPEN, Z_STRVAL_P(inc_filename));
2847		}
2848	} else {
2849		switch (type) {
2850			case ZEND_INCLUDE_ONCE:
2851			case ZEND_REQUIRE_ONCE: {
2852					zend_file_handle file_handle;
2853					zend_string *resolved_path;
2854
2855					resolved_path = zend_resolve_path(Z_STRVAL_P(inc_filename), (int)Z_STRLEN_P(inc_filename));
2856					if (resolved_path) {
2857						if (zend_hash_exists(&EG(included_files), resolved_path)) {
2858							goto already_compiled;
2859						}
2860					} else {
2861						resolved_path = zend_string_copy(Z_STR_P(inc_filename));
2862					}
2863
2864					if (SUCCESS == zend_stream_open(ZSTR_VAL(resolved_path), &file_handle)) {
2865
2866						if (!file_handle.opened_path) {
2867							file_handle.opened_path = zend_string_copy(resolved_path);
2868						}
2869
2870						if (zend_hash_add_empty_element(&EG(included_files), file_handle.opened_path)) {
2871							zend_op_array *op_array = zend_compile_file(&file_handle, (type==ZEND_INCLUDE_ONCE?ZEND_INCLUDE:ZEND_REQUIRE));
2872							zend_destroy_file_handle(&file_handle);
2873							zend_string_release(resolved_path);
2874							if (Z_TYPE(tmp_inc_filename) != IS_UNDEF) {
2875								zend_string_release(Z_STR(tmp_inc_filename));
2876							}
2877							return op_array;
2878						} else {
2879							zend_file_handle_dtor(&file_handle);
2880already_compiled:
2881							new_op_array = ZEND_FAKE_OP_ARRAY;
2882						}
2883					} else {
2884						if (type == ZEND_INCLUDE_ONCE) {
2885							zend_message_dispatcher(ZMSG_FAILED_INCLUDE_FOPEN, Z_STRVAL_P(inc_filename));
2886						} else {
2887							zend_message_dispatcher(ZMSG_FAILED_REQUIRE_FOPEN, Z_STRVAL_P(inc_filename));
2888						}
2889					}
2890					zend_string_release(resolved_path);
2891				}
2892				break;
2893			case ZEND_INCLUDE:
2894			case ZEND_REQUIRE:
2895				new_op_array = compile_filename(type, inc_filename);
2896				break;
2897			case ZEND_EVAL: {
2898					char *eval_desc = zend_make_compiled_string_description("eval()'d code");
2899					new_op_array = zend_compile_string(inc_filename, eval_desc);
2900					efree(eval_desc);
2901				}
2902				break;
2903			EMPTY_SWITCH_DEFAULT_CASE()
2904		}
2905	}
2906	if (Z_TYPE(tmp_inc_filename) != IS_UNDEF) {
2907		zend_string_release(Z_STR(tmp_inc_filename));
2908	}
2909	return new_op_array;
2910}
2911/* }}} */
2912
2913static zend_never_inline int zend_do_fcall_overloaded(zend_function *fbc, zend_execute_data *call, zval *ret) /* {{{ */
2914{
2915	zend_object *object;
2916
2917	/* Not sure what should be done here if it's a static method */
2918	if (UNEXPECTED(Z_TYPE(call->This) != IS_OBJECT)) {
2919		zend_vm_stack_free_args(call);
2920		if (fbc->type == ZEND_OVERLOADED_FUNCTION_TEMPORARY) {
2921			zend_string_release(fbc->common.function_name);
2922		}
2923		efree(fbc);
2924		zend_vm_stack_free_call_frame(call);
2925
2926		zend_throw_error(NULL, "Cannot call overloaded function for non-object");
2927		return 0;
2928	}
2929
2930	object = Z_OBJ(call->This);
2931
2932	ZVAL_NULL(ret);
2933
2934	EG(current_execute_data) = call;
2935	object->handlers->call_method(fbc->common.function_name, object, call, ret);
2936	EG(current_execute_data) = call->prev_execute_data;
2937
2938	zend_vm_stack_free_args(call);
2939
2940	if (fbc->type == ZEND_OVERLOADED_FUNCTION_TEMPORARY) {
2941		zend_string_release(fbc->common.function_name);
2942	}
2943	efree(fbc);
2944
2945	return 1;
2946}
2947/* }}} */
2948
2949#ifdef HAVE_GCC_GLOBAL_REGS
2950# if defined(__GNUC__) && ZEND_GCC_VERSION >= 4008 && defined(i386)
2951#  define ZEND_VM_FP_GLOBAL_REG "%esi"
2952#  define ZEND_VM_IP_GLOBAL_REG "%edi"
2953# elif defined(__GNUC__) && ZEND_GCC_VERSION >= 4008 && defined(__x86_64__)
2954#  define ZEND_VM_FP_GLOBAL_REG "%r14"
2955#  define ZEND_VM_IP_GLOBAL_REG "%r15"
2956# elif defined(__GNUC__) && ZEND_GCC_VERSION >= 4008 && defined(__powerpc64__)
2957#  define ZEND_VM_FP_GLOBAL_REG "r28"
2958#  define ZEND_VM_IP_GLOBAL_REG "r29"
2959# elif defined(__IBMC__) && ZEND_GCC_VERSION >= 4002 && defined(__powerpc64__)
2960#  define ZEND_VM_FP_GLOBAL_REG "r28"
2961#  define ZEND_VM_IP_GLOBAL_REG "r29"
2962# endif
2963#endif
2964
2965#define ZEND_VM_NEXT_OPCODE_EX(check_exception, skip) \
2966	CHECK_SYMBOL_TABLES() \
2967	if (check_exception) { \
2968		OPLINE = EX(opline) + (skip); \
2969	} else { \
2970		OPLINE = opline + (skip); \
2971	} \
2972	ZEND_VM_CONTINUE()
2973
2974#define ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION() \
2975	ZEND_VM_NEXT_OPCODE_EX(1, 1)
2976
2977#define ZEND_VM_NEXT_OPCODE() \
2978	ZEND_VM_NEXT_OPCODE_EX(0, 1)
2979
2980#define ZEND_VM_SET_NEXT_OPCODE(new_op) \
2981	CHECK_SYMBOL_TABLES() \
2982	OPLINE = new_op
2983
2984#define ZEND_VM_SET_OPCODE(new_op) \
2985	CHECK_SYMBOL_TABLES() \
2986	OPLINE = new_op; \
2987	ZEND_VM_INTERRUPT_CHECK()
2988
2989#define ZEND_VM_SET_RELATIVE_OPCODE(opline, offset) \
2990	ZEND_VM_SET_OPCODE(ZEND_OFFSET_TO_OPLINE(opline, offset))
2991
2992#define ZEND_VM_JMP(new_op) \
2993	if (EXPECTED(!EG(exception))) { \
2994		ZEND_VM_SET_OPCODE(new_op); \
2995	} else { \
2996		LOAD_OPLINE(); \
2997	} \
2998	ZEND_VM_CONTINUE()
2999
3000#define ZEND_VM_INC_OPCODE() \
3001	OPLINE++
3002
3003
3004#ifndef VM_SMART_OPCODES
3005# define VM_SMART_OPCODES 1
3006#endif
3007
3008#if VM_SMART_OPCODES
3009# define ZEND_VM_REPEATABLE_OPCODE \
3010	do {
3011# define ZEND_VM_REPEAT_OPCODE(_opcode) \
3012	} while (UNEXPECTED((++opline)->opcode == _opcode)); \
3013	OPLINE = opline; \
3014	ZEND_VM_CONTINUE()
3015# define ZEND_VM_SMART_BRANCH(_result, _check) do { \
3016		int __result; \
3017		if (EXPECTED((opline+1)->opcode == ZEND_JMPZ)) { \
3018			__result = (_result); \
3019		} else if (EXPECTED((opline+1)->opcode == ZEND_JMPNZ)) { \
3020			__result = !(_result); \
3021		} else { \
3022			break; \
3023		} \
3024		if ((_check) && UNEXPECTED(EG(exception))) { \
3025			HANDLE_EXCEPTION(); \
3026		} \
3027		if (__result) { \
3028			ZEND_VM_SET_NEXT_OPCODE(opline + 2); \
3029		} else { \
3030			ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline + 1, (opline+1)->op2)); \
3031		} \
3032		ZEND_VM_CONTINUE(); \
3033	} while (0)
3034# define ZEND_VM_SMART_BRANCH_JMPZ(_result, _check) do { \
3035		if ((_check) && UNEXPECTED(EG(exception))) { \
3036			HANDLE_EXCEPTION(); \
3037		} \
3038		if (_result) { \
3039			ZEND_VM_SET_NEXT_OPCODE(opline + 2); \
3040		} else { \
3041			ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline + 1, (opline+1)->op2)); \
3042		} \
3043		ZEND_VM_CONTINUE(); \
3044	} while (0)
3045# define ZEND_VM_SMART_BRANCH_JMPNZ(_result, _check) do { \
3046		if ((_check) && UNEXPECTED(EG(exception))) { \
3047			HANDLE_EXCEPTION(); \
3048		} \
3049		if (!(_result)) { \
3050			ZEND_VM_SET_NEXT_OPCODE(opline + 2); \
3051		} else { \
3052			ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline + 1, (opline+1)->op2)); \
3053		} \
3054		ZEND_VM_CONTINUE(); \
3055	} while (0)
3056#else
3057# define ZEND_VM_REPEATABLE_OPCODE
3058# define ZEND_VM_REPEAT_OPCODE(_opcode)
3059# define ZEND_VM_SMART_BRANCH(_result, _check)
3060# define ZEND_VM_SMART_BRANCH_JMPZ(_result, _check)
3061# define ZEND_VM_SMART_BRANCH_JMPNZ(_result, _check)
3062#endif
3063
3064#ifdef __GNUC__
3065# define ZEND_VM_GUARD(name) __asm__("#" #name)
3066#else
3067# define ZEND_VM_GUARD(name)
3068#endif
3069
3070#define GET_OP1_UNDEF_CV(ptr, type) \
3071	_get_zval_cv_lookup_ ## type(ptr, opline->op1.var, execute_data)
3072#define GET_OP2_UNDEF_CV(ptr, type) \
3073	_get_zval_cv_lookup_ ## type(ptr, opline->op2.var, execute_data)
3074
3075#include "zend_vm_execute.h"
3076
3077ZEND_API int zend_set_user_opcode_handler(zend_uchar opcode, user_opcode_handler_t handler)
3078{
3079	if (opcode != ZEND_USER_OPCODE) {
3080		if (handler == NULL) {
3081			/* restore the original handler */
3082			zend_user_opcodes[opcode] = opcode;
3083		} else {
3084			zend_user_opcodes[opcode] = ZEND_USER_OPCODE;
3085		}
3086		zend_user_opcode_handlers[opcode] = handler;
3087		return SUCCESS;
3088	}
3089	return FAILURE;
3090}
3091
3092ZEND_API user_opcode_handler_t zend_get_user_opcode_handler(zend_uchar opcode)
3093{
3094	return zend_user_opcode_handlers[opcode];
3095}
3096
3097ZEND_API zval *zend_get_zval_ptr(int op_type, const znode_op *node, const zend_execute_data *execute_data, zend_free_op *should_free, int type)
3098{
3099	return get_zval_ptr(op_type, *node, execute_data, should_free, type);
3100}
3101
3102ZEND_API void ZEND_FASTCALL zend_check_internal_arg_type(zend_function *zf, uint32_t arg_num, zval *arg)
3103{
3104	zend_verify_internal_arg_type(zf, arg_num, arg);
3105}
3106
3107ZEND_API int ZEND_FASTCALL zend_check_arg_type(zend_function *zf, uint32_t arg_num, zval *arg, zval *default_value, void **cache_slot)
3108{
3109	return zend_verify_arg_type(zf, arg_num, arg, default_value, cache_slot);
3110}
3111
3112ZEND_API void ZEND_FASTCALL zend_check_missing_arg(zend_execute_data *execute_data, uint32_t arg_num, void **cache_slot)
3113{
3114	zend_verify_missing_arg(execute_data, arg_num, cache_slot);
3115}
3116
3117/*
3118 * Local variables:
3119 * tab-width: 4
3120 * c-basic-offset: 4
3121 * indent-tabs-mode: t
3122 * End:
3123 */
3124