1/*
2   +----------------------------------------------------------------------+
3   | Zend Engine                                                          |
4   +----------------------------------------------------------------------+
5   | Copyright (c) 1998-2016 Zend Technologies Ltd. (http://www.zend.com) |
6   +----------------------------------------------------------------------+
7   | This source file is subject to version 2.00 of the Zend license,     |
8   | that is bundled with this package in the file LICENSE, and is        |
9   | available through the world-wide-web at the following url:           |
10   | http://www.zend.com/license/2_00.txt.                                |
11   | If you did not receive a copy of the Zend license and are unable to  |
12   | obtain it through the world-wide-web, please send a note to          |
13   | license@zend.com so we can mail you a copy immediately.              |
14   +----------------------------------------------------------------------+
15   | Authors: Andi Gutmans <andi@zend.com>                                |
16   |          Zeev Suraski <zeev@zend.com>                                |
17   |          Dmitry Stogov <dmitry@zend.com>                             |
18   +----------------------------------------------------------------------+
19*/
20
21/* $Id$ */
22
23#define ZEND_INTENSIVE_DEBUGGING 0
24
25#include <stdio.h>
26#include <signal.h>
27
28#include "zend.h"
29#include "zend_compile.h"
30#include "zend_execute.h"
31#include "zend_API.h"
32#include "zend_ptr_stack.h"
33#include "zend_constants.h"
34#include "zend_extensions.h"
35#include "zend_ini.h"
36#include "zend_exceptions.h"
37#include "zend_interfaces.h"
38#include "zend_closures.h"
39#include "zend_generators.h"
40#include "zend_vm.h"
41#include "zend_dtrace.h"
42#include "zend_inheritance.h"
43#include "zend_type_info.h"
44
45/* Virtual current working directory support */
46#include "zend_virtual_cwd.h"
47
48#define _CONST_CODE  0
49#define _TMP_CODE    1
50#define _VAR_CODE    2
51#define _UNUSED_CODE 3
52#define _CV_CODE     4
53
54typedef int (ZEND_FASTCALL *incdec_t)(zval *);
55
56#define get_zval_ptr(op_type, node, ex, should_free, type) _get_zval_ptr(op_type, node, ex, should_free, type)
57#define get_zval_ptr_deref(op_type, node, ex, should_free, type) _get_zval_ptr_deref(op_type, node, ex, should_free, type)
58#define get_zval_ptr_r(op_type, node, ex, should_free) _get_zval_ptr_r(op_type, node, ex, should_free)
59#define get_zval_ptr_r_deref(op_type, node, ex, should_free) _get_zval_ptr_r_deref(op_type, node, ex, should_free)
60#define get_zval_ptr_undef(op_type, node, ex, should_free, type) _get_zval_ptr_undef(op_type, node, ex, should_free, type)
61#define get_zval_ptr_ptr(op_type, node, ex, should_free, type) _get_zval_ptr_ptr(op_type, node, ex, should_free, type)
62#define get_zval_ptr_ptr_undef(op_type, node, ex, should_free, type) _get_zval_ptr_ptr(op_type, node, ex, should_free, type)
63#define get_obj_zval_ptr(op_type, node, ex, should_free, type) _get_obj_zval_ptr(op_type, node, ex, should_free, type)
64#define get_obj_zval_ptr_undef(op_type, node, ex, should_free, type) _get_obj_zval_ptr_undef(op_type, node, ex, should_free, type)
65#define get_obj_zval_ptr_ptr(op_type, node, ex, should_free, type) _get_obj_zval_ptr_ptr(op_type, node, ex, should_free, type)
66
67/* Prototypes */
68static void zend_extension_statement_handler(const zend_extension *extension, zend_execute_data *frame);
69static void zend_extension_fcall_begin_handler(const zend_extension *extension, zend_execute_data *frame);
70static void zend_extension_fcall_end_handler(const zend_extension *extension, zend_execute_data *frame);
71
72#define RETURN_VALUE_USED(opline) ((opline)->result_type != IS_UNUSED)
73
74static ZEND_FUNCTION(pass)
75{
76}
77
78ZEND_API const zend_internal_function zend_pass_function = {
79	ZEND_INTERNAL_FUNCTION, /* type              */
80	{0, 0, 0},              /* arg_flags         */
81	0,                      /* fn_flags          */
82	NULL,                   /* name              */
83	NULL,                   /* scope             */
84	NULL,                   /* prototype         */
85	0,                      /* num_args          */
86	0,                      /* required_num_args */
87	NULL,                   /* arg_info          */
88	ZEND_FN(pass),          /* handler           */
89	NULL,                   /* module            */
90	{NULL,NULL,NULL,NULL}   /* reserved          */
91};
92
93#undef zval_ptr_dtor
94#define zval_ptr_dtor(zv) i_zval_ptr_dtor(zv ZEND_FILE_LINE_CC)
95
96#define READY_TO_DESTROY(zv) \
97	(UNEXPECTED(zv) && Z_REFCOUNTED_P(zv) && Z_REFCOUNT_P(zv) == 1)
98
99#define EXTRACT_ZVAL_PTR(zv) do {		\
100	zval *__zv = (zv);								\
101	if (EXPECTED(Z_TYPE_P(__zv) == IS_INDIRECT)) {	\
102		ZVAL_COPY(__zv, Z_INDIRECT_P(__zv));	    \
103	}												\
104} while (0)
105
106#define FREE_OP(should_free) \
107	if (should_free) { \
108		zval_ptr_dtor_nogc(should_free); \
109	}
110
111#define FREE_UNFETCHED_OP(type, var) \
112	if ((type) & (IS_TMP_VAR|IS_VAR)) { \
113		zval_ptr_dtor_nogc(EX_VAR(var)); \
114	}
115
116#define FREE_OP_VAR_PTR(should_free) \
117	if (should_free) { \
118		zval_ptr_dtor_nogc(should_free); \
119	}
120
121#define CV_DEF_OF(i) (EX(func)->op_array.vars[i])
122
123#define ZEND_VM_MAIN_STACK_PAGE_SLOTS (16 * 1024) /* should be a power of 2 */
124#define ZEND_VM_GENERATOR_STACK_PAGE_SLOTS (256)
125
126#define ZEND_VM_STACK_PAGE_SLOTS(gen) ((gen) ? ZEND_VM_GENERATOR_STACK_PAGE_SLOTS : ZEND_VM_MAIN_STACK_PAGE_SLOTS)
127
128#define ZEND_VM_STACK_PAGE_SIZE(gen)  (ZEND_VM_STACK_PAGE_SLOTS(gen) * sizeof(zval))
129
130#define ZEND_VM_STACK_FREE_PAGE_SIZE(gen) \
131	((ZEND_VM_STACK_PAGE_SLOTS(gen) - ZEND_VM_STACK_HEADER_SLOTS) * sizeof(zval))
132
133#define ZEND_VM_STACK_PAGE_ALIGNED_SIZE(gen, size) \
134	(((size) + (ZEND_VM_STACK_FREE_PAGE_SIZE(gen) - 1)) & ~(ZEND_VM_STACK_PAGE_SIZE(gen) - 1))
135
136static zend_always_inline zend_vm_stack zend_vm_stack_new_page(size_t size, zend_vm_stack prev) {
137	zend_vm_stack page = (zend_vm_stack)emalloc(size);
138
139	page->top = ZEND_VM_STACK_ELEMENTS(page);
140	page->end = (zval*)((char*)page + size);
141	page->prev = prev;
142	return page;
143}
144
145ZEND_API void zend_vm_stack_init(void)
146{
147	EG(vm_stack) = zend_vm_stack_new_page(ZEND_VM_STACK_PAGE_SIZE(0 /* main stack */), NULL);
148	EG(vm_stack)->top++;
149	EG(vm_stack_top) = EG(vm_stack)->top;
150	EG(vm_stack_end) = EG(vm_stack)->end;
151}
152
153ZEND_API void zend_vm_stack_destroy(void)
154{
155	zend_vm_stack stack = EG(vm_stack);
156
157	while (stack != NULL) {
158		zend_vm_stack p = stack->prev;
159		efree(stack);
160		stack = p;
161	}
162}
163
164ZEND_API void* zend_vm_stack_extend(size_t size)
165{
166	zend_vm_stack stack;
167	void *ptr;
168
169	stack = EG(vm_stack);
170	stack->top = EG(vm_stack_top);
171	EG(vm_stack) = stack = zend_vm_stack_new_page(
172		EXPECTED(size < ZEND_VM_STACK_FREE_PAGE_SIZE(0)) ?
173			ZEND_VM_STACK_PAGE_SIZE(0) : ZEND_VM_STACK_PAGE_ALIGNED_SIZE(0, size),
174		stack);
175	ptr = stack->top;
176	EG(vm_stack_top) = (void*)(((char*)ptr) + size);
177	EG(vm_stack_end) = stack->end;
178	return ptr;
179}
180
181ZEND_API zval* zend_get_compiled_variable_value(const zend_execute_data *execute_data, uint32_t var)
182{
183	return EX_VAR(var);
184}
185
186static zend_always_inline zval *_get_zval_ptr_tmp(uint32_t var, const zend_execute_data *execute_data, zend_free_op *should_free)
187{
188	zval *ret = EX_VAR(var);
189	*should_free = ret;
190
191	ZEND_ASSERT(Z_TYPE_P(ret) != IS_REFERENCE);
192
193	return ret;
194}
195
196static zend_always_inline zval *_get_zval_ptr_var(uint32_t var, const zend_execute_data *execute_data, zend_free_op *should_free)
197{
198	zval *ret = EX_VAR(var);
199
200	*should_free = ret;
201	return ret;
202}
203
204static zend_always_inline zval *_get_zval_ptr_var_deref(uint32_t var, const zend_execute_data *execute_data, zend_free_op *should_free)
205{
206	zval *ret = EX_VAR(var);
207
208	*should_free = ret;
209	ZVAL_DEREF(ret);
210	return ret;
211}
212
213static zend_never_inline ZEND_COLD void zval_undefined_cv(uint32_t var, const zend_execute_data *execute_data)
214{
215	zend_string *cv = CV_DEF_OF(EX_VAR_TO_NUM(var));
216
217	zend_error(E_NOTICE, "Undefined variable: %s", ZSTR_VAL(cv));
218}
219
220static zend_never_inline zval *_get_zval_cv_lookup(zval *ptr, uint32_t var, int type, const zend_execute_data *execute_data)
221{
222	switch (type) {
223		case BP_VAR_R:
224		case BP_VAR_UNSET:
225			zval_undefined_cv(var, execute_data);
226			/* break missing intentionally */
227		case BP_VAR_IS:
228			ptr = &EG(uninitialized_zval);
229			break;
230		case BP_VAR_RW:
231			zval_undefined_cv(var, execute_data);
232			/* break missing intentionally */
233		case BP_VAR_W:
234			ZVAL_NULL(ptr);
235			break;
236	}
237	return ptr;
238}
239
240static zend_always_inline zval *_get_zval_cv_lookup_BP_VAR_R(zval *ptr, uint32_t var, const zend_execute_data *execute_data)
241{
242	zval_undefined_cv(var, execute_data);
243	return &EG(uninitialized_zval);
244}
245
246static zend_always_inline zval *_get_zval_cv_lookup_BP_VAR_UNSET(zval *ptr, uint32_t var, const zend_execute_data *execute_data)
247{
248	zval_undefined_cv(var, execute_data);
249	return &EG(uninitialized_zval);
250}
251
252static zend_always_inline zval *_get_zval_cv_lookup_BP_VAR_RW(zval *ptr, uint32_t var, const zend_execute_data *execute_data)
253{
254	ZVAL_NULL(ptr);
255	zval_undefined_cv(var, execute_data);
256	return ptr;
257}
258
259static zend_always_inline zval *_get_zval_cv_lookup_BP_VAR_W(zval *ptr, uint32_t var, const zend_execute_data *execute_data)
260{
261	ZVAL_NULL(ptr);
262	return ptr;
263}
264
265static zend_always_inline zval *_get_zval_ptr_cv(const zend_execute_data *execute_data, uint32_t var, int type)
266{
267	zval *ret = EX_VAR(var);
268
269	if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
270		return _get_zval_cv_lookup(ret, var, type, execute_data);
271	}
272	return ret;
273}
274
275static zend_always_inline zval *_get_zval_ptr_cv_undef(const zend_execute_data *execute_data, uint32_t var)
276{
277	return EX_VAR(var);
278}
279
280static zend_always_inline zval *_get_zval_ptr_cv_deref(const zend_execute_data *execute_data, uint32_t var, int type)
281{
282	zval *ret = EX_VAR(var);
283
284	if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
285		return _get_zval_cv_lookup(ret, var, type, execute_data);
286	}
287	ZVAL_DEREF(ret);
288	return ret;
289}
290
291static zend_always_inline zval *_get_zval_ptr_cv_BP_VAR_R(const zend_execute_data *execute_data, uint32_t var)
292{
293	zval *ret = EX_VAR(var);
294
295	if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
296		return _get_zval_cv_lookup_BP_VAR_R(ret, var, execute_data);
297	}
298	return ret;
299}
300
301static zend_always_inline zval *_get_zval_ptr_cv_deref_BP_VAR_R(const zend_execute_data *execute_data, uint32_t var)
302{
303	zval *ret = EX_VAR(var);
304
305	if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
306		return _get_zval_cv_lookup_BP_VAR_R(ret, var, execute_data);
307	}
308	ZVAL_DEREF(ret);
309	return ret;
310}
311
312static zend_always_inline zval *_get_zval_ptr_cv_BP_VAR_UNSET(const zend_execute_data *execute_data, uint32_t var)
313{
314	zval *ret = EX_VAR(var);
315
316	if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
317		return _get_zval_cv_lookup_BP_VAR_UNSET(ret, var, execute_data);
318	}
319	return ret;
320}
321
322static zend_always_inline zval *_get_zval_ptr_cv_deref_BP_VAR_UNSET(const zend_execute_data *execute_data, uint32_t var)
323{
324	zval *ret = EX_VAR(var);
325
326	if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
327		return _get_zval_cv_lookup_BP_VAR_UNSET(ret, var, execute_data);
328	}
329	ZVAL_DEREF(ret);
330	return ret;
331}
332
333static zend_always_inline zval *_get_zval_ptr_cv_BP_VAR_IS(const zend_execute_data *execute_data, uint32_t var)
334{
335	zval *ret = EX_VAR(var);
336
337	return ret;
338}
339
340static zend_always_inline zval *_get_zval_ptr_cv_deref_BP_VAR_IS(const zend_execute_data *execute_data, uint32_t var)
341{
342	zval *ret = EX_VAR(var);
343
344	ZVAL_DEREF(ret);
345	return ret;
346}
347
348static zend_always_inline zval *_get_zval_ptr_cv_BP_VAR_RW(const zend_execute_data *execute_data, uint32_t var)
349{
350	zval *ret = EX_VAR(var);
351
352	if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
353		return _get_zval_cv_lookup_BP_VAR_RW(ret, var, execute_data);
354	}
355	return ret;
356}
357
358static zend_always_inline zval *_get_zval_ptr_cv_deref_BP_VAR_RW(const zend_execute_data *execute_data, uint32_t var)
359{
360	zval *ret = EX_VAR(var);
361
362	if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
363		return _get_zval_cv_lookup_BP_VAR_RW(ret, var, execute_data);
364	}
365	ZVAL_DEREF(ret);
366	return ret;
367}
368
369static zend_always_inline zval *_get_zval_ptr_cv_BP_VAR_W(const zend_execute_data *execute_data, uint32_t var)
370{
371	zval *ret = EX_VAR(var);
372
373	if (Z_TYPE_P(ret) == IS_UNDEF) {
374		return _get_zval_cv_lookup_BP_VAR_W(ret, var, execute_data);
375	}
376	return ret;
377}
378
379static zend_always_inline zval *_get_zval_ptr_cv_undef_BP_VAR_W(const zend_execute_data *execute_data, uint32_t var)
380{
381	return EX_VAR(var);
382}
383
384static zend_always_inline zval *_get_zval_ptr_cv_undef_BP_VAR_RW(const zend_execute_data *execute_data, uint32_t var)
385{
386	return EX_VAR(var);
387}
388
389static zend_always_inline zval *_get_zval_ptr_cv_undef_BP_VAR_UNSET(const zend_execute_data *execute_data, uint32_t var)
390{
391	return EX_VAR(var);
392}
393
394static zend_always_inline zval *_get_zval_ptr_cv_deref_BP_VAR_W(const zend_execute_data *execute_data, uint32_t var)
395{
396	zval *ret = EX_VAR(var);
397
398	if (Z_TYPE_P(ret) == IS_UNDEF) {
399		return _get_zval_cv_lookup_BP_VAR_W(ret, var, execute_data);
400	}
401	ZVAL_DEREF(ret);
402	return ret;
403}
404
405static zend_always_inline zval *_get_zval_ptr(int op_type, znode_op node, const zend_execute_data *execute_data, zend_free_op *should_free, int type)
406{
407	if (op_type & (IS_TMP_VAR|IS_VAR)) {
408		if (op_type == IS_TMP_VAR) {
409			return _get_zval_ptr_tmp(node.var, execute_data, should_free);
410		} else {
411			ZEND_ASSERT(op_type == IS_VAR);
412			return _get_zval_ptr_var(node.var, execute_data, should_free);
413		}
414	} else {
415		*should_free = NULL;
416		if (op_type == IS_CONST) {
417			return EX_CONSTANT(node);
418		} else if (op_type == IS_CV) {
419			return _get_zval_ptr_cv(execute_data, node.var, type);
420		} else {
421			return NULL;
422		}
423	}
424}
425
426static zend_always_inline zval *_get_zval_ptr_r(int op_type, znode_op node, const zend_execute_data *execute_data, zend_free_op *should_free)
427{
428	if (op_type & (IS_TMP_VAR|IS_VAR)) {
429		if (op_type == IS_TMP_VAR) {
430			return _get_zval_ptr_tmp(node.var, execute_data, should_free);
431		} else {
432			ZEND_ASSERT(op_type == IS_VAR);
433			return _get_zval_ptr_var(node.var, execute_data, should_free);
434		}
435	} else {
436		*should_free = NULL;
437		if (op_type == IS_CONST) {
438			return EX_CONSTANT(node);
439		} else if (op_type == IS_CV) {
440			return _get_zval_ptr_cv_BP_VAR_R(execute_data, node.var);
441		} else {
442			return NULL;
443		}
444	}
445}
446
447static zend_always_inline zval *_get_zval_ptr_deref(int op_type, znode_op node, const zend_execute_data *execute_data, zend_free_op *should_free, int type)
448{
449	if (op_type & (IS_TMP_VAR|IS_VAR)) {
450		if (op_type == IS_TMP_VAR) {
451			return _get_zval_ptr_tmp(node.var, execute_data, should_free);
452		} else {
453			ZEND_ASSERT(op_type == IS_VAR);
454			return _get_zval_ptr_var_deref(node.var, execute_data, should_free);
455		}
456	} else {
457		*should_free = NULL;
458		if (op_type == IS_CONST) {
459			return EX_CONSTANT(node);
460		} else if (op_type == IS_CV) {
461			return _get_zval_ptr_cv_deref(execute_data, node.var, type);
462		} else {
463			return NULL;
464		}
465	}
466}
467
468static zend_always_inline zval *_get_zval_ptr_r_deref(int op_type, znode_op node, const zend_execute_data *execute_data, zend_free_op *should_free)
469{
470	if (op_type & (IS_TMP_VAR|IS_VAR)) {
471		if (op_type == IS_TMP_VAR) {
472			return _get_zval_ptr_tmp(node.var, execute_data, should_free);
473		} else {
474			ZEND_ASSERT(op_type == IS_VAR);
475			return _get_zval_ptr_var_deref(node.var, execute_data, should_free);
476		}
477	} else {
478		*should_free = NULL;
479		if (op_type == IS_CONST) {
480			return EX_CONSTANT(node);
481		} else if (op_type == IS_CV) {
482			return _get_zval_ptr_cv_deref_BP_VAR_R(execute_data, node.var);
483		} else {
484			return NULL;
485		}
486	}
487}
488
489static zend_always_inline zval *_get_zval_ptr_undef(int op_type, znode_op node, const zend_execute_data *execute_data, zend_free_op *should_free, int type)
490{
491	if (op_type & (IS_TMP_VAR|IS_VAR)) {
492		if (op_type == IS_TMP_VAR) {
493			return _get_zval_ptr_tmp(node.var, execute_data, should_free);
494		} else {
495			ZEND_ASSERT(op_type == IS_VAR);
496			return _get_zval_ptr_var(node.var, execute_data, should_free);
497		}
498	} else {
499		*should_free = NULL;
500		if (op_type == IS_CONST) {
501			return EX_CONSTANT(node);
502		} else if (op_type == IS_CV) {
503			return _get_zval_ptr_cv_undef(execute_data, node.var);
504		} else {
505			return NULL;
506		}
507	}
508}
509
510static zend_always_inline zval *_get_zval_ptr_ptr_var(uint32_t var, const zend_execute_data *execute_data, zend_free_op *should_free)
511{
512	zval *ret = EX_VAR(var);
513
514	if (EXPECTED(Z_TYPE_P(ret) == IS_INDIRECT)) {
515		*should_free = NULL;
516		ret = Z_INDIRECT_P(ret);
517	} else {
518		*should_free = ret;
519	}
520	return ret;
521}
522
523static inline zval *_get_zval_ptr_ptr(int op_type, znode_op node, const zend_execute_data *execute_data, zend_free_op *should_free, int type)
524{
525	if (op_type == IS_CV) {
526		*should_free = NULL;
527		return _get_zval_ptr_cv(execute_data, node.var, type);
528	} else /* if (op_type == IS_VAR) */ {
529		ZEND_ASSERT(op_type == IS_VAR);
530		return _get_zval_ptr_ptr_var(node.var, execute_data, should_free);
531	}
532}
533
534static zend_always_inline zval *_get_obj_zval_ptr_unused(zend_execute_data *execute_data)
535{
536	return &EX(This);
537}
538
539static inline zval *_get_obj_zval_ptr(int op_type, znode_op op, zend_execute_data *execute_data, zend_free_op *should_free, int type)
540{
541	if (op_type == IS_UNUSED) {
542		*should_free = NULL;
543		return &EX(This);
544	}
545	return get_zval_ptr(op_type, op, execute_data, should_free, type);
546}
547
548static inline zval *_get_obj_zval_ptr_undef(int op_type, znode_op op, zend_execute_data *execute_data, zend_free_op *should_free, int type)
549{
550	if (op_type == IS_UNUSED) {
551		*should_free = NULL;
552		return &EX(This);
553	}
554	return get_zval_ptr_undef(op_type, op, execute_data, should_free, type);
555}
556
557static inline zval *_get_obj_zval_ptr_ptr(int op_type, znode_op node, zend_execute_data *execute_data, zend_free_op *should_free, int type)
558{
559	if (op_type == IS_UNUSED) {
560		*should_free = NULL;
561		return &EX(This);
562	}
563	return get_zval_ptr_ptr(op_type, node, execute_data, should_free, type);
564}
565
566static inline void zend_assign_to_variable_reference(zval *variable_ptr, zval *value_ptr)
567{
568	zend_reference *ref;
569
570	if (EXPECTED(!Z_ISREF_P(value_ptr))) {
571		ZVAL_NEW_REF(value_ptr, value_ptr);
572	} else if (UNEXPECTED(variable_ptr == value_ptr)) {
573		return;
574	}
575
576	ref = Z_REF_P(value_ptr);
577	GC_REFCOUNT(ref)++;
578	zval_ptr_dtor(variable_ptr);
579	ZVAL_REF(variable_ptr, ref);
580}
581
582/* this should modify object only if it's empty */
583static inline int make_real_object(zval *object)
584{
585	if (UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
586		if (EXPECTED(Z_TYPE_P(object) <= IS_FALSE)) {
587			/* nothing to destroy */
588		} else if (EXPECTED((Z_TYPE_P(object) == IS_STRING && Z_STRLEN_P(object) == 0))) {
589			zval_ptr_dtor_nogc(object);
590		} else {
591			return 0;
592		}
593		object_init(object);
594		zend_error(E_WARNING, "Creating default object from empty value");
595	}
596	return 1;
597}
598
599static char * zend_verify_internal_arg_class_kind(const zend_internal_arg_info *cur_arg_info, char **class_name, zend_class_entry **pce)
600{
601	zend_string *key;
602	ALLOCA_FLAG(use_heap);
603
604	ZSTR_ALLOCA_INIT(key, cur_arg_info->class_name, strlen(cur_arg_info->class_name), use_heap);
605	*pce = zend_fetch_class(key, (ZEND_FETCH_CLASS_AUTO | ZEND_FETCH_CLASS_NO_AUTOLOAD));
606	ZSTR_ALLOCA_FREE(key, use_heap);
607
608	*class_name = (*pce) ? ZSTR_VAL((*pce)->name) : (char*)cur_arg_info->class_name;
609	if (*pce && (*pce)->ce_flags & ZEND_ACC_INTERFACE) {
610		return "implement interface ";
611	} else {
612		return "be an instance of ";
613	}
614}
615
616static zend_always_inline zend_class_entry* zend_verify_arg_class_kind(const zend_arg_info *cur_arg_info)
617{
618	return zend_fetch_class(cur_arg_info->class_name, (ZEND_FETCH_CLASS_AUTO | ZEND_FETCH_CLASS_NO_AUTOLOAD));
619}
620
621static ZEND_COLD void zend_verify_arg_error(const zend_function *zf, uint32_t arg_num, const char *need_msg, const char *need_kind, const char *given_msg, const char *given_kind)
622{
623	zend_execute_data *ptr = EG(current_execute_data)->prev_execute_data;
624	const char *fname = ZSTR_VAL(zf->common.function_name);
625	const char *fsep;
626	const char *fclass;
627
628	if (zf->common.scope) {
629		fsep =  "::";
630		fclass = ZSTR_VAL(zf->common.scope->name);
631	} else {
632		fsep =  "";
633		fclass = "";
634	}
635
636	if (zf->common.type == ZEND_USER_FUNCTION) {
637		if (ptr && ptr->func && ZEND_USER_CODE(ptr->func->common.type)) {
638			zend_type_error("Argument %d passed to %s%s%s() must %s%s, %s%s given, called in %s on line %d",
639					arg_num, fclass, fsep, fname, need_msg, need_kind, given_msg, given_kind,
640					ZSTR_VAL(ptr->func->op_array.filename), ptr->opline->lineno);
641		} else {
642			zend_type_error("Argument %d passed to %s%s%s() must %s%s, %s%s given", arg_num, fclass, fsep, fname, need_msg, need_kind, given_msg, given_kind);
643		}
644	} else {
645		zend_type_error("Argument %d passed to %s%s%s() must %s%s, %s%s given", arg_num, fclass, fsep, fname, need_msg, need_kind, given_msg, given_kind);
646	}
647}
648
649static int is_null_constant(zend_class_entry *scope, zval *default_value)
650{
651	if (Z_CONSTANT_P(default_value)) {
652		zval constant;
653
654		ZVAL_COPY(&constant, default_value);
655		if (UNEXPECTED(zval_update_constant_ex(&constant, scope) != SUCCESS)) {
656			return 0;
657		}
658		if (Z_TYPE(constant) == IS_NULL) {
659			return 1;
660		}
661		zval_ptr_dtor(&constant);
662	}
663	return 0;
664}
665
666static zend_bool zend_verify_weak_scalar_type_hint(zend_uchar type_hint, zval *arg)
667{
668	switch (type_hint) {
669		case _IS_BOOL: {
670			zend_bool dest;
671
672			if (!zend_parse_arg_bool_weak(arg, &dest)) {
673				return 0;
674			}
675			zval_ptr_dtor(arg);
676			ZVAL_BOOL(arg, dest);
677			return 1;
678		}
679		case IS_LONG: {
680			zend_long dest;
681
682			if (!zend_parse_arg_long_weak(arg, &dest)) {
683				return 0;
684			}
685			zval_ptr_dtor(arg);
686			ZVAL_LONG(arg, dest);
687			return 1;
688		}
689		case IS_DOUBLE: {
690			double dest;
691
692			if (!zend_parse_arg_double_weak(arg, &dest)) {
693				return 0;
694			}
695			zval_ptr_dtor(arg);
696			ZVAL_DOUBLE(arg, dest);
697			return 1;
698		}
699		case IS_STRING: {
700			zend_string *dest;
701
702			/* on success "arg" is converted to IS_STRING */
703			if (!zend_parse_arg_str_weak(arg, &dest)) {
704				return 0;
705			}
706			return 1;
707		}
708		default:
709			return 0;
710	}
711}
712
713static zend_bool zend_verify_scalar_type_hint(zend_uchar type_hint, zval *arg, zend_bool strict)
714{
715	if (UNEXPECTED(strict)) {
716		/* SSTH Exception: IS_LONG may be accepted as IS_DOUBLE (converted) */
717		if (type_hint != IS_DOUBLE || Z_TYPE_P(arg) != IS_LONG) {
718			return 0;
719		}
720	} else if (UNEXPECTED(Z_TYPE_P(arg) == IS_NULL)) {
721		/* NULL may be accepted only by nullable hints (this is already checked) */
722		return 0;
723	}
724	return zend_verify_weak_scalar_type_hint(type_hint, arg);
725}
726
727static int zend_verify_internal_arg_type(zend_function *zf, uint32_t arg_num, zval *arg)
728{
729	zend_internal_arg_info *cur_arg_info;
730	char *need_msg, *class_name;
731	zend_class_entry *ce;
732
733	if (EXPECTED(arg_num <= zf->internal_function.num_args)) {
734		cur_arg_info = &zf->internal_function.arg_info[arg_num-1];
735	} else if (zf->internal_function.fn_flags & ZEND_ACC_VARIADIC) {
736		cur_arg_info = &zf->internal_function.arg_info[zf->internal_function.num_args];
737	} else {
738		return 1;
739	}
740
741	if (cur_arg_info->type_hint) {
742		ZVAL_DEREF(arg);
743		if (EXPECTED(cur_arg_info->type_hint == Z_TYPE_P(arg))) {
744			if (cur_arg_info->class_name) {
745				need_msg = zend_verify_internal_arg_class_kind((zend_internal_arg_info*)cur_arg_info, &class_name, &ce);
746				if (!ce || !instanceof_function(Z_OBJCE_P(arg), ce)) {
747					zend_verify_arg_error(zf, arg_num, need_msg, class_name, "instance of ", ZSTR_VAL(Z_OBJCE_P(arg)->name));
748					return 0;
749				}
750			}
751		} else if (Z_TYPE_P(arg) != IS_NULL || !cur_arg_info->allow_null) {
752			if (cur_arg_info->class_name) {
753				need_msg = zend_verify_internal_arg_class_kind((zend_internal_arg_info*)cur_arg_info, &class_name, &ce);
754				zend_verify_arg_error(zf, arg_num, need_msg, class_name, zend_zval_type_name(arg), "");
755				return 0;
756			} else if (cur_arg_info->type_hint == IS_CALLABLE) {
757				if (!zend_is_callable(arg, IS_CALLABLE_CHECK_SILENT, NULL)) {
758					zend_verify_arg_error(zf, arg_num, "be callable", "", zend_zval_type_name(arg), "");
759					return 0;
760				}
761			} else if (cur_arg_info->type_hint == _IS_BOOL &&
762			           EXPECTED(Z_TYPE_P(arg) == IS_FALSE || Z_TYPE_P(arg) == IS_TRUE)) {
763				/* pass */
764			} else if (UNEXPECTED(!zend_verify_scalar_type_hint(cur_arg_info->type_hint, arg, ZEND_CALL_USES_STRICT_TYPES(EG(current_execute_data))))) {
765				zend_verify_arg_error(zf, arg_num, "be of the type ", zend_get_type_by_const(cur_arg_info->type_hint), zend_zval_type_name(arg), "");
766				return 0;
767			}
768		}
769	}
770	return 1;
771}
772
773static zend_never_inline int zend_verify_internal_arg_types(zend_function *fbc, zend_execute_data *call)
774{
775	uint32_t i;
776	uint32_t num_args = ZEND_CALL_NUM_ARGS(call);
777	zval *p = ZEND_CALL_ARG(call, 1);
778
779	for (i = 0; i < num_args; ++i) {
780		if (UNEXPECTED(!zend_verify_internal_arg_type(fbc, i + 1, p))) {
781			EG(current_execute_data) = call->prev_execute_data;
782			zend_vm_stack_free_args(call);
783			return 0;
784		}
785		p++;
786	}
787	return 1;
788}
789
790static zend_always_inline int zend_verify_arg_type(zend_function *zf, uint32_t arg_num, zval *arg, zval *default_value, void **cache_slot)
791{
792	zend_arg_info *cur_arg_info;
793	char *need_msg;
794	zend_class_entry *ce;
795
796	if (EXPECTED(arg_num <= zf->common.num_args)) {
797		cur_arg_info = &zf->common.arg_info[arg_num-1];
798	} else if (UNEXPECTED(zf->common.fn_flags & ZEND_ACC_VARIADIC)) {
799		cur_arg_info = &zf->common.arg_info[zf->common.num_args];
800	} else {
801		return 1;
802	}
803
804	if (cur_arg_info->type_hint) {
805		ZVAL_DEREF(arg);
806		if (EXPECTED(cur_arg_info->type_hint == Z_TYPE_P(arg))) {
807			if (cur_arg_info->class_name) {
808				if (EXPECTED(*cache_slot)) {
809					ce = (zend_class_entry*)*cache_slot;
810				} else {
811					ce = zend_verify_arg_class_kind(cur_arg_info);
812					if (UNEXPECTED(!ce)) {
813						zend_verify_arg_error(zf, arg_num, "be an instance of ", ZSTR_VAL(cur_arg_info->class_name), "instance of ", ZSTR_VAL(Z_OBJCE_P(arg)->name));
814						return 0;
815					}
816					*cache_slot = (void*)ce;
817				}
818				if (UNEXPECTED(!instanceof_function(Z_OBJCE_P(arg), ce))) {
819					need_msg =
820						(ce->ce_flags & ZEND_ACC_INTERFACE) ?
821						"implement interface " : "be an instance of ";
822					zend_verify_arg_error(zf, arg_num, need_msg, ZSTR_VAL(ce->name), "instance of ", ZSTR_VAL(Z_OBJCE_P(arg)->name));
823					return 0;
824				}
825			}
826		} else if (Z_TYPE_P(arg) != IS_NULL || !(cur_arg_info->allow_null || (default_value && is_null_constant(zf->common.scope, default_value)))) {
827			if (cur_arg_info->class_name) {
828				if (EXPECTED(*cache_slot)) {
829					ce = (zend_class_entry*)*cache_slot;
830				} else {
831					ce = zend_verify_arg_class_kind(cur_arg_info);
832					if (UNEXPECTED(!ce)) {
833						if (Z_TYPE_P(arg) == IS_OBJECT) {
834							zend_verify_arg_error(zf, arg_num, "be an instance of ", ZSTR_VAL(cur_arg_info->class_name), "instance of ", ZSTR_VAL(Z_OBJCE_P(arg)->name));
835						} else {
836							zend_verify_arg_error(zf, arg_num, "be an instance of ", ZSTR_VAL(cur_arg_info->class_name), "", zend_zval_type_name(arg));
837						}
838						return 0;
839					}
840					*cache_slot = (void*)ce;
841				}
842				need_msg =
843					(ce->ce_flags & ZEND_ACC_INTERFACE) ?
844					"implement interface " : "be an instance of ";
845				zend_verify_arg_error(zf, arg_num, need_msg, ZSTR_VAL(ce->name), zend_zval_type_name(arg), "");
846				return 0;
847			} else if (cur_arg_info->type_hint == IS_CALLABLE) {
848				if (!zend_is_callable(arg, IS_CALLABLE_CHECK_SILENT, NULL)) {
849					zend_verify_arg_error(zf, arg_num, "be callable", "", zend_zval_type_name(arg), "");
850					return 0;
851				}
852			} else if (cur_arg_info->type_hint == _IS_BOOL &&
853			           EXPECTED(Z_TYPE_P(arg) == IS_FALSE || Z_TYPE_P(arg) == IS_TRUE)) {
854				/* pass */
855			} else if (UNEXPECTED(!zend_verify_scalar_type_hint(cur_arg_info->type_hint, arg, ZEND_ARG_USES_STRICT_TYPES()))) {
856				zend_verify_arg_error(zf, arg_num, "be of the type ", zend_get_type_by_const(cur_arg_info->type_hint), zend_zval_type_name(arg), "");
857				return 0;
858			}
859		}
860	}
861	return 1;
862}
863
864static zend_always_inline int zend_verify_missing_arg_type(zend_function *zf, uint32_t arg_num, void **cache_slot)
865{
866	zend_arg_info *cur_arg_info;
867	char *need_msg;
868	zend_class_entry *ce;
869
870	if (EXPECTED(arg_num <= zf->common.num_args)) {
871		cur_arg_info = &zf->common.arg_info[arg_num-1];
872	} else if (UNEXPECTED(zf->common.fn_flags & ZEND_ACC_VARIADIC)) {
873		cur_arg_info = &zf->common.arg_info[zf->common.num_args];
874	} else {
875		return 1;
876	}
877
878	if (cur_arg_info->type_hint) {
879		if (cur_arg_info->class_name) {
880			if (EXPECTED(*cache_slot)) {
881				ce = (zend_class_entry*)*cache_slot;
882			} else {
883				ce = zend_verify_arg_class_kind(cur_arg_info);
884				if (UNEXPECTED(!ce)) {
885					zend_verify_arg_error(zf, arg_num, "be an instance of ", ZSTR_VAL(cur_arg_info->class_name), "none", "");
886					return 0;
887				}
888				*cache_slot = (void*)ce;
889			}
890			need_msg =
891				(ce->ce_flags & ZEND_ACC_INTERFACE) ?
892				"implement interface " : "be an instance of ";
893			zend_verify_arg_error(zf, arg_num, need_msg, ZSTR_VAL(ce->name), "none", "");
894		} else if (cur_arg_info->type_hint == IS_CALLABLE) {
895			zend_verify_arg_error(zf, arg_num, "be callable", "", "none", "");
896		} else {
897			zend_verify_arg_error(zf, arg_num, "be of the type ", zend_get_type_by_const(cur_arg_info->type_hint), "none", "");
898		}
899		return 0;
900	}
901	return 1;
902}
903
904static ZEND_COLD void zend_verify_missing_arg(zend_execute_data *execute_data, uint32_t arg_num, void **cache_slot)
905{
906	if (EXPECTED(!(EX(func)->common.fn_flags & ZEND_ACC_HAS_TYPE_HINTS)) ||
907	    UNEXPECTED(zend_verify_missing_arg_type(EX(func), arg_num, cache_slot))) {
908		const char *class_name = EX(func)->common.scope ? ZSTR_VAL(EX(func)->common.scope->name) : "";
909		const char *space = EX(func)->common.scope ? "::" : "";
910		const char *func_name = EX(func)->common.function_name ? ZSTR_VAL(EX(func)->common.function_name) : "main";
911		zend_execute_data *ptr = EX(prev_execute_data);
912
913		if (ptr && ptr->func && ZEND_USER_CODE(ptr->func->common.type)) {
914			zend_error(E_WARNING, "Missing argument %u for %s%s%s(), called in %s on line %d and defined", arg_num, class_name, space, func_name, ZSTR_VAL(ptr->func->op_array.filename), ptr->opline->lineno);
915		} else {
916			zend_error(E_WARNING, "Missing argument %u for %s%s%s()", arg_num, class_name, space, func_name);
917		}
918	}
919}
920
921static ZEND_COLD void zend_verify_return_error(const zend_function *zf, const char *need_msg, const char *need_kind, const char *returned_msg, const char *returned_kind)
922{
923	const char *fname = ZSTR_VAL(zf->common.function_name);
924	const char *fsep;
925	const char *fclass;
926
927	if (zf->common.scope) {
928		fsep =  "::";
929		fclass = ZSTR_VAL(zf->common.scope->name);
930	} else {
931		fsep =  "";
932		fclass = "";
933	}
934
935	zend_type_error("Return value of %s%s%s() must %s%s, %s%s returned",
936		fclass, fsep, fname, need_msg, need_kind, returned_msg, returned_kind);
937}
938
939#if ZEND_DEBUG
940static ZEND_COLD void zend_verify_internal_return_error(const zend_function *zf, const char *need_msg, const char *need_kind, const char *returned_msg, const char *returned_kind)
941{
942	const char *fname = ZSTR_VAL(zf->common.function_name);
943	const char *fsep;
944	const char *fclass;
945
946	if (zf->common.scope) {
947		fsep =  "::";
948		fclass = ZSTR_VAL(zf->common.scope->name);
949	} else {
950		fsep =  "";
951		fclass = "";
952	}
953
954	zend_error_noreturn(E_CORE_ERROR, "Return value of %s%s%s() must %s%s, %s%s returned",
955		fclass, fsep, fname, need_msg, need_kind, returned_msg, returned_kind);
956}
957
958static ZEND_COLD void zend_verify_void_return_error(const zend_function *zf, const char *returned_msg, const char *returned_kind)
959{
960	const char *fname = ZSTR_VAL(zf->common.function_name);
961	const char *fsep;
962	const char *fclass;
963
964	if (zf->common.scope) {
965		fsep =  "::";
966		fclass = ZSTR_VAL(zf->common.scope->name);
967	} else {
968		fsep =  "";
969		fclass = "";
970	}
971
972	zend_type_error("%s%s%s() must not return a value, %s%s returned",
973		fclass, fsep, fname, returned_msg, returned_kind);
974}
975
976static int zend_verify_internal_return_type(zend_function *zf, zval *ret)
977{
978	zend_arg_info *ret_info = zf->common.arg_info - 1;
979	char *need_msg, *class_name;
980	zend_class_entry *ce;
981
982
983	if (ret_info->type_hint) {
984		if (EXPECTED(ret_info->type_hint == Z_TYPE_P(ret))) {
985			if (ret_info->class_name) {
986				need_msg = zend_verify_internal_arg_class_kind((zend_internal_arg_info *)ret_info, &class_name, &ce);
987				if (!ce || !instanceof_function(Z_OBJCE_P(ret), ce)) {
988					zend_verify_internal_return_error(zf, need_msg, class_name, "instance of ", ZSTR_VAL(Z_OBJCE_P(ret)->name));
989					return 0;
990				}
991			}
992		} else if (Z_TYPE_P(ret) != IS_NULL || !ret_info->allow_null) {
993			if (ret_info->class_name) {
994				need_msg = zend_verify_internal_arg_class_kind((zend_internal_arg_info *)ret_info, &class_name, &ce);
995				zend_verify_internal_return_error(zf, need_msg, class_name, zend_zval_type_name(ret), "");
996			} else if (ret_info->type_hint == IS_CALLABLE) {
997				if (!zend_is_callable(ret, IS_CALLABLE_CHECK_SILENT, NULL) && (Z_TYPE_P(ret) != IS_NULL || !ret_info->allow_null)) {
998					zend_verify_internal_return_error(zf, "be callable", "", zend_zval_type_name(ret), "");
999					return 0;
1000				}
1001			} else if (ret_info->type_hint == _IS_BOOL &&
1002			           EXPECTED(Z_TYPE_P(ret) == IS_FALSE || Z_TYPE_P(ret) == IS_TRUE)) {
1003				/* pass */
1004			} else if (ret_info->type_hint == IS_VOID) {
1005				zend_verify_void_return_error(zf, zend_zval_type_name(ret), "");
1006			} else {
1007				/* Use strict check to verify return value of internal function */
1008				zend_verify_internal_return_error(zf, "be of the type ", zend_get_type_by_const(ret_info->type_hint), zend_zval_type_name(ret), "");
1009				return 0;
1010			}
1011		}
1012	}
1013	return 1;
1014}
1015#endif
1016
1017static zend_always_inline void zend_verify_return_type(zend_function *zf, zval *ret, void **cache_slot)
1018{
1019	zend_arg_info *ret_info = zf->common.arg_info - 1;
1020	char *need_msg;
1021	zend_class_entry *ce;
1022
1023	if (ret_info->type_hint) {
1024		if (EXPECTED(ret_info->type_hint == Z_TYPE_P(ret))) {
1025			if (ret_info->class_name) {
1026				if (EXPECTED(*cache_slot)) {
1027					ce = (zend_class_entry*)*cache_slot;
1028				} else {
1029					ce = zend_verify_arg_class_kind(ret_info);
1030					if (UNEXPECTED(!ce)) {
1031						zend_verify_return_error(zf, "be an instance of ", ZSTR_VAL(ret_info->class_name), "instance of ", ZSTR_VAL(Z_OBJCE_P(ret)->name));
1032						return;
1033					}
1034					*cache_slot = (void*)ce;
1035				}
1036				if (UNEXPECTED(!instanceof_function(Z_OBJCE_P(ret), ce))) {
1037					need_msg =
1038						(ce->ce_flags & ZEND_ACC_INTERFACE) ?
1039						"implement interface " : "be an instance of ";
1040					zend_verify_return_error(zf, need_msg, ZSTR_VAL(ce->name), "instance of ", ZSTR_VAL(Z_OBJCE_P(ret)->name));
1041				}
1042			}
1043		} else if (Z_TYPE_P(ret) != IS_NULL || !ret_info->allow_null) {
1044			if (ret_info->class_name) {
1045				if (EXPECTED(*cache_slot)) {
1046					ce = (zend_class_entry*)*cache_slot;
1047				} else {
1048					ce = zend_verify_arg_class_kind(ret_info);
1049					if (UNEXPECTED(!ce)) {
1050						zend_verify_return_error(zf, "be an instance of ", ZSTR_VAL(ret_info->class_name), zend_zval_type_name(ret), "");
1051						return;
1052					}
1053					*cache_slot = (void*)ce;
1054				}
1055				need_msg =
1056					(ce->ce_flags & ZEND_ACC_INTERFACE) ?
1057					"implement interface " : "be an instance of ";
1058				zend_verify_return_error(zf, need_msg, ZSTR_VAL(ce->name), zend_zval_type_name(ret), "");
1059			} else if (ret_info->type_hint == IS_CALLABLE) {
1060				if (!zend_is_callable(ret, IS_CALLABLE_CHECK_SILENT, NULL)) {
1061					zend_verify_return_error(zf, "be callable", "", zend_zval_type_name(ret), "");
1062				}
1063			} else if (ret_info->type_hint == _IS_BOOL &&
1064			           EXPECTED(Z_TYPE_P(ret) == IS_FALSE || Z_TYPE_P(ret) == IS_TRUE)) {
1065				/* pass */
1066			/* There would be a check here for the IS_VOID type hint, which
1067			 * would trigger an error because a value had been returned.
1068			 * However, zend_compile.c already does a compile-time check
1069			 * that bans `return ...;` within a void function. Thus we can skip
1070			 * this part of the runtime check for non-internal functions.
1071			 */
1072			} else if (UNEXPECTED(!zend_verify_scalar_type_hint(ret_info->type_hint, ret, ZEND_RET_USES_STRICT_TYPES()))) {
1073				zend_verify_return_error(zf, "be of the type ", zend_get_type_by_const(ret_info->type_hint), zend_zval_type_name(ret), "");
1074			}
1075		}
1076	}
1077}
1078
1079static ZEND_COLD int zend_verify_missing_return_type(zend_function *zf, void **cache_slot)
1080{
1081	zend_arg_info *ret_info = zf->common.arg_info - 1;
1082	char *need_msg;
1083	zend_class_entry *ce;
1084
1085	if (ret_info->type_hint && EXPECTED(ret_info->type_hint != IS_VOID)) {
1086		if (ret_info->class_name) {
1087			if (EXPECTED(*cache_slot)) {
1088				ce = (zend_class_entry*)*cache_slot;
1089			} else {
1090				ce = zend_verify_arg_class_kind(ret_info);
1091				if (UNEXPECTED(!ce)) {
1092					zend_verify_return_error(zf, "be an instance of ", ZSTR_VAL(ret_info->class_name), "none", "");
1093					return 0;
1094				}
1095				*cache_slot = (void*)ce;
1096			}
1097			need_msg =
1098				(ce->ce_flags & ZEND_ACC_INTERFACE) ?
1099				"implement interface " : "be an instance of ";
1100			zend_verify_return_error(zf, need_msg, ZSTR_VAL(ce->name), "none", "");
1101			return 0;
1102		} else if (ret_info->type_hint == IS_CALLABLE) {
1103			zend_verify_return_error(zf, "be callable", "", "none", "");
1104		} else {
1105			zend_verify_return_error(zf, "be of the type ", zend_get_type_by_const(ret_info->type_hint), "none", "");
1106		}
1107		return 0;
1108	}
1109	return 1;
1110}
1111
1112static zend_never_inline void zend_assign_to_object_dim(zval *object, zval *dim, zval *value)
1113{
1114	if (UNEXPECTED(!Z_OBJ_HT_P(object)->write_dimension)) {
1115		zend_throw_error(NULL, "Cannot use object as array");
1116		return;
1117	}
1118
1119	Z_OBJ_HT_P(object)->write_dimension(object, dim, value);
1120}
1121
1122static zend_never_inline void zend_binary_assign_op_obj_dim(zval *object, zval *property, zval *value, zval *retval, binary_op_type binary_op)
1123{
1124	zval *z;
1125	zval rv, res;
1126
1127	if (Z_OBJ_HT_P(object)->read_dimension &&
1128		(z = Z_OBJ_HT_P(object)->read_dimension(object, property, BP_VAR_R, &rv)) != NULL) {
1129
1130		if (Z_TYPE_P(z) == IS_OBJECT && Z_OBJ_HT_P(z)->get) {
1131			zval rv2;
1132			zval *value = Z_OBJ_HT_P(z)->get(z, &rv2);
1133
1134			if (z == &rv) {
1135				zval_ptr_dtor(&rv);
1136			}
1137			ZVAL_COPY_VALUE(z, value);
1138		}
1139		binary_op(&res, Z_ISREF_P(z) ? Z_REFVAL_P(z) : z, value);
1140		Z_OBJ_HT_P(object)->write_dimension(object, property, &res);
1141		if (z == &rv) {
1142			zval_ptr_dtor(&rv);
1143		}
1144		if (retval) {
1145			ZVAL_COPY(retval, &res);
1146		}
1147		zval_ptr_dtor(&res);
1148	} else {
1149		zend_error(E_WARNING, "Attempt to assign property of non-object");
1150		if (retval) {
1151			ZVAL_NULL(retval);
1152		}
1153	}
1154}
1155
1156static zend_never_inline zend_long zend_check_string_offset(zval *dim, int type)
1157{
1158	zend_long offset;
1159
1160try_again:
1161	if (UNEXPECTED(Z_TYPE_P(dim) != IS_LONG)) {
1162		switch(Z_TYPE_P(dim)) {
1163			case IS_STRING:
1164				if (IS_LONG == is_numeric_string(Z_STRVAL_P(dim), Z_STRLEN_P(dim), NULL, NULL, -1)) {
1165					break;
1166				}
1167				if (type != BP_VAR_UNSET) {
1168					zend_error(E_WARNING, "Illegal string offset '%s'", Z_STRVAL_P(dim));
1169				}
1170				break;
1171			case IS_UNDEF:
1172				zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
1173			case IS_DOUBLE:
1174			case IS_NULL:
1175			case IS_FALSE:
1176			case IS_TRUE:
1177				zend_error(E_NOTICE, "String offset cast occurred");
1178				break;
1179			case IS_REFERENCE:
1180				dim = Z_REFVAL_P(dim);
1181				goto try_again;
1182			default:
1183				zend_error(E_WARNING, "Illegal offset type");
1184				break;
1185		}
1186
1187		offset = _zval_get_long_func(dim);
1188	} else {
1189		offset = Z_LVAL_P(dim);
1190	}
1191
1192	return offset;
1193}
1194
1195static zend_never_inline ZEND_COLD void zend_wrong_string_offset(void)
1196{
1197	const char *msg = NULL;
1198	const zend_op *opline = EG(current_execute_data)->opline;
1199	const zend_op *end;
1200	uint32_t var;
1201
1202	switch (opline->opcode) {
1203		case ZEND_ASSIGN_ADD:
1204		case ZEND_ASSIGN_SUB:
1205		case ZEND_ASSIGN_MUL:
1206		case ZEND_ASSIGN_DIV:
1207		case ZEND_ASSIGN_MOD:
1208		case ZEND_ASSIGN_SL:
1209		case ZEND_ASSIGN_SR:
1210		case ZEND_ASSIGN_CONCAT:
1211		case ZEND_ASSIGN_BW_OR:
1212		case ZEND_ASSIGN_BW_AND:
1213		case ZEND_ASSIGN_BW_XOR:
1214		case ZEND_ASSIGN_POW:
1215			msg = "Cannot use assign-op operators with string offsets";
1216			break;
1217		case ZEND_FETCH_DIM_W:
1218		case ZEND_FETCH_DIM_RW:
1219		case ZEND_FETCH_DIM_FUNC_ARG:
1220		case ZEND_FETCH_DIM_UNSET:
1221			/* TODO: Encode the "reason" into opline->extended_value??? */
1222			var = opline->result.var;
1223			opline++;
1224			end = EG(current_execute_data)->func->op_array.opcodes +
1225				EG(current_execute_data)->func->op_array.last;
1226			while (opline < end) {
1227				if (opline->op1_type == IS_VAR && opline->op1.var == var) {
1228					switch (opline->opcode) {
1229						case ZEND_ASSIGN_ADD:
1230						case ZEND_ASSIGN_SUB:
1231						case ZEND_ASSIGN_MUL:
1232						case ZEND_ASSIGN_DIV:
1233						case ZEND_ASSIGN_MOD:
1234						case ZEND_ASSIGN_SL:
1235						case ZEND_ASSIGN_SR:
1236						case ZEND_ASSIGN_CONCAT:
1237						case ZEND_ASSIGN_BW_OR:
1238						case ZEND_ASSIGN_BW_AND:
1239						case ZEND_ASSIGN_BW_XOR:
1240						case ZEND_ASSIGN_POW:
1241							if (opline->extended_value == ZEND_ASSIGN_OBJ) {
1242								msg = "Cannot use string offset as an object";
1243							} else if (opline->extended_value == ZEND_ASSIGN_DIM) {
1244								msg = "Cannot use string offset as an array";
1245							} else {
1246								msg = "Cannot use assign-op operators with string offsets";
1247							}
1248							break;
1249						case ZEND_PRE_INC_OBJ:
1250						case ZEND_PRE_DEC_OBJ:
1251						case ZEND_POST_INC_OBJ:
1252						case ZEND_POST_DEC_OBJ:
1253						case ZEND_PRE_INC:
1254						case ZEND_PRE_DEC:
1255						case ZEND_POST_INC:
1256						case ZEND_POST_DEC:
1257							msg = "Cannot increment/decrement string offsets";
1258							break;
1259						case ZEND_FETCH_DIM_W:
1260						case ZEND_FETCH_DIM_RW:
1261						case ZEND_FETCH_DIM_FUNC_ARG:
1262						case ZEND_FETCH_DIM_UNSET:
1263						case ZEND_ASSIGN_DIM:
1264							msg = "Cannot use string offset as an array";
1265							break;
1266						case ZEND_FETCH_OBJ_W:
1267						case ZEND_FETCH_OBJ_RW:
1268						case ZEND_FETCH_OBJ_FUNC_ARG:
1269						case ZEND_FETCH_OBJ_UNSET:
1270						case ZEND_ASSIGN_OBJ:
1271							msg = "Cannot use string offset as an object";
1272							break;
1273						case ZEND_ASSIGN_REF:
1274						case ZEND_ADD_ARRAY_ELEMENT:
1275						case ZEND_INIT_ARRAY:
1276							msg = "Cannot create references to/from string offsets";
1277							break;
1278						case ZEND_RETURN_BY_REF:
1279							msg = "Cannot return string offsets by reference";
1280							break;
1281						case ZEND_UNSET_DIM:
1282						case ZEND_UNSET_OBJ:
1283							msg = "Cannot unset string offsets";
1284							break;
1285						case ZEND_YIELD:
1286							msg = "Cannot yield string offsets by reference";
1287							break;
1288						case ZEND_SEND_REF:
1289						case ZEND_SEND_VAR_EX:
1290							msg = "Only variables can be passed by reference";
1291							break;
1292						EMPTY_SWITCH_DEFAULT_CASE();
1293					}
1294					break;
1295				}
1296				if (opline->op2_type == IS_VAR && opline->op2.var == var) {
1297					ZEND_ASSERT(opline->opcode == ZEND_ASSIGN_REF);
1298					msg = "Cannot create references to/from string offsets";
1299					break;
1300				}
1301			}
1302			break;
1303		EMPTY_SWITCH_DEFAULT_CASE();
1304	}
1305	ZEND_ASSERT(msg != NULL);
1306	zend_throw_error(NULL, msg);
1307}
1308
1309static zend_never_inline void zend_assign_to_string_offset(zval *str, zval *dim, zval *value, zval *result)
1310{
1311	zend_string *old_str;
1312	zend_uchar c;
1313	size_t string_len;
1314	zend_long offset;
1315
1316	offset = zend_check_string_offset(dim, BP_VAR_W);
1317	if (offset < (zend_long)(-Z_STRLEN_P(str))) {
1318		/* Error on negative offset */
1319		zend_error(E_WARNING, "Illegal string offset:  " ZEND_LONG_FMT, offset);
1320		if (result) {
1321			ZVAL_NULL(result);
1322		}
1323		return;
1324	}
1325
1326	if (Z_TYPE_P(value) != IS_STRING) {
1327		/* Convert to string, just the time to pick the 1st byte */
1328		zend_string *tmp = zval_get_string(value);
1329
1330		string_len = ZSTR_LEN(tmp);
1331		c = (zend_uchar)ZSTR_VAL(tmp)[0];
1332		zend_string_release(tmp);
1333	} else {
1334		string_len = Z_STRLEN_P(value);
1335		c = (zend_uchar)Z_STRVAL_P(value)[0];
1336	}
1337
1338	if (string_len == 0) {
1339		/* Error on empty input string */
1340		zend_error(E_WARNING, "Cannot assign an empty string to a string offset");
1341		if (result) {
1342			ZVAL_NULL(result);
1343		}
1344		return;
1345	}
1346
1347	if (offset < 0) { /* Handle negative offset */
1348		offset += (zend_long)Z_STRLEN_P(str);
1349	}
1350
1351	if ((size_t)offset >= Z_STRLEN_P(str)) {
1352		/* Extend string if needed */
1353		zend_long old_len = Z_STRLEN_P(str);
1354		Z_STR_P(str) = zend_string_extend(Z_STR_P(str), offset + 1, 0);
1355		Z_TYPE_INFO_P(str) = IS_STRING_EX;
1356		memset(Z_STRVAL_P(str) + old_len, ' ', offset - old_len);
1357		Z_STRVAL_P(str)[offset+1] = 0;
1358	} else if (!Z_REFCOUNTED_P(str)) {
1359		old_str = Z_STR_P(str);
1360		Z_STR_P(str) = zend_string_init(Z_STRVAL_P(str), Z_STRLEN_P(str), 0);
1361		Z_TYPE_INFO_P(str) = IS_STRING_EX;
1362		zend_string_release(old_str);
1363	} else {
1364		SEPARATE_STRING(str);
1365	}
1366
1367	Z_STRVAL_P(str)[offset] = c;
1368
1369	if (result) {
1370		/* Return the new character */
1371		if (CG(one_char_string)[c]) {
1372			ZVAL_INTERNED_STR(result, CG(one_char_string)[c]);
1373		} else {
1374			ZVAL_NEW_STR(result, zend_string_init(Z_STRVAL_P(str) + offset, 1, 0));
1375		}
1376	}
1377}
1378
1379static zend_never_inline void zend_post_incdec_overloaded_property(zval *object, zval *property, void **cache_slot, int inc, zval *result)
1380{
1381	if (Z_OBJ_HT_P(object)->read_property && Z_OBJ_HT_P(object)->write_property) {
1382		zval rv, obj;
1383		zval *z;
1384		zval z_copy;
1385
1386		ZVAL_OBJ(&obj, Z_OBJ_P(object));
1387		Z_ADDREF(obj);
1388		z = Z_OBJ_HT(obj)->read_property(&obj, property, BP_VAR_R, cache_slot, &rv);
1389		if (UNEXPECTED(EG(exception))) {
1390			OBJ_RELEASE(Z_OBJ(obj));
1391			return;
1392		}
1393
1394		if (UNEXPECTED(Z_TYPE_P(z) == IS_OBJECT) && Z_OBJ_HT_P(z)->get) {
1395			zval rv2;
1396			zval *value = Z_OBJ_HT_P(z)->get(z, &rv2);
1397			if (z == &rv) {
1398				zval_ptr_dtor(&rv);
1399			}
1400			ZVAL_COPY_VALUE(z, value);
1401		}
1402
1403		if (UNEXPECTED(Z_TYPE_P(z) == IS_REFERENCE)) {
1404			ZVAL_COPY(result, Z_REFVAL_P(z));
1405		} else {
1406			ZVAL_COPY(result, z);
1407		}
1408		ZVAL_DUP(&z_copy, result);
1409		if (inc) {
1410			increment_function(&z_copy);
1411		} else {
1412			decrement_function(&z_copy);
1413		}
1414		Z_OBJ_HT(obj)->write_property(&obj, property, &z_copy, cache_slot);
1415		OBJ_RELEASE(Z_OBJ(obj));
1416		zval_ptr_dtor(&z_copy);
1417		zval_ptr_dtor(z);
1418	} else {
1419		zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
1420		ZVAL_NULL(result);
1421	}
1422}
1423
1424static zend_never_inline void zend_pre_incdec_overloaded_property(zval *object, zval *property, void **cache_slot, int inc, zval *result)
1425{
1426	zval rv;
1427
1428	if (Z_OBJ_HT_P(object)->read_property && Z_OBJ_HT_P(object)->write_property) {
1429		zval *z, obj;
1430
1431		ZVAL_OBJ(&obj, Z_OBJ_P(object));
1432		Z_ADDREF(obj);
1433		z = Z_OBJ_HT(obj)->read_property(&obj, property, BP_VAR_R, cache_slot, &rv);
1434		if (UNEXPECTED(EG(exception))) {
1435			OBJ_RELEASE(Z_OBJ(obj));
1436			return;
1437		}
1438
1439		if (UNEXPECTED(Z_TYPE_P(z) == IS_OBJECT) && Z_OBJ_HT_P(z)->get) {
1440			zval rv2;
1441			zval *value = Z_OBJ_HT_P(z)->get(z, &rv2);
1442
1443			if (z == &rv) {
1444				zval_ptr_dtor(&rv);
1445			}
1446			ZVAL_COPY_VALUE(z, value);
1447		}
1448		ZVAL_DEREF(z);
1449		SEPARATE_ZVAL_NOREF(z);
1450		if (inc) {
1451			increment_function(z);
1452		} else {
1453			decrement_function(z);
1454		}
1455		if (UNEXPECTED(result)) {
1456			ZVAL_COPY(result, z);
1457		}
1458		Z_OBJ_HT(obj)->write_property(&obj, property, z, cache_slot);
1459		OBJ_RELEASE(Z_OBJ(obj));
1460		zval_ptr_dtor(z);
1461	} else {
1462		zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
1463		if (UNEXPECTED(result)) {
1464			ZVAL_NULL(result);
1465		}
1466	}
1467}
1468
1469static zend_never_inline void zend_assign_op_overloaded_property(zval *object, zval *property, void **cache_slot, zval *value, binary_op_type binary_op, zval *result)
1470{
1471	zval *z;
1472	zval rv, obj;
1473	zval *zptr;
1474
1475	ZVAL_OBJ(&obj, Z_OBJ_P(object));
1476	Z_ADDREF(obj);
1477	if (EXPECTED(Z_OBJ_HT(obj)->read_property)) {
1478		z = Z_OBJ_HT(obj)->read_property(&obj, property, BP_VAR_R, cache_slot, &rv);
1479		if (UNEXPECTED(EG(exception))) {
1480			OBJ_RELEASE(Z_OBJ(obj));
1481			return;
1482		}
1483		if (Z_TYPE_P(z) == IS_OBJECT && Z_OBJ_HT_P(z)->get) {
1484			zval rv2;
1485			zval *value = Z_OBJ_HT_P(z)->get(z, &rv2);
1486
1487			if (z == &rv) {
1488				zval_ptr_dtor(&rv);
1489			}
1490			ZVAL_COPY_VALUE(z, value);
1491		}
1492		zptr = z;
1493		ZVAL_DEREF(z);
1494		SEPARATE_ZVAL_NOREF(z);
1495		binary_op(z, z, value);
1496		Z_OBJ_HT(obj)->write_property(&obj, property, z, cache_slot);
1497		if (UNEXPECTED(result)) {
1498			ZVAL_COPY(result, z);
1499		}
1500		zval_ptr_dtor(zptr);
1501	} else {
1502		zend_error(E_WARNING, "Attempt to assign property of non-object");
1503		if (UNEXPECTED(result)) {
1504			ZVAL_NULL(result);
1505		}
1506	}
1507	OBJ_RELEASE(Z_OBJ(obj));
1508}
1509
1510/* Utility Functions for Extensions */
1511static void zend_extension_statement_handler(const zend_extension *extension, zend_execute_data *frame)
1512{
1513	if (extension->statement_handler) {
1514		extension->statement_handler(frame);
1515	}
1516}
1517
1518
1519static void zend_extension_fcall_begin_handler(const zend_extension *extension, zend_execute_data *frame)
1520{
1521	if (extension->fcall_begin_handler) {
1522		extension->fcall_begin_handler(frame);
1523	}
1524}
1525
1526
1527static void zend_extension_fcall_end_handler(const zend_extension *extension, zend_execute_data *frame)
1528{
1529	if (extension->fcall_end_handler) {
1530		extension->fcall_end_handler(frame);
1531	}
1532}
1533
1534
1535static zend_always_inline HashTable *zend_get_target_symbol_table(zend_execute_data *execute_data, int fetch_type)
1536{
1537	HashTable *ht;
1538
1539	if (EXPECTED(fetch_type == ZEND_FETCH_GLOBAL_LOCK) ||
1540	    EXPECTED(fetch_type == ZEND_FETCH_GLOBAL)) {
1541		ht = &EG(symbol_table);
1542	} else {
1543		ZEND_ASSERT(fetch_type == ZEND_FETCH_LOCAL);
1544		if (!(EX_CALL_INFO() & ZEND_CALL_HAS_SYMBOL_TABLE)) {
1545			zend_rebuild_symbol_table();
1546		}
1547		ht = EX(symbol_table);
1548	}
1549	return ht;
1550}
1551
1552static zend_always_inline zval *zend_fetch_dimension_address_inner(HashTable *ht, const zval *dim, int dim_type, int type)
1553{
1554	zval *retval;
1555	zend_string *offset_key;
1556	zend_ulong hval;
1557
1558try_again:
1559	if (EXPECTED(Z_TYPE_P(dim) == IS_LONG)) {
1560		hval = Z_LVAL_P(dim);
1561num_index:
1562		ZEND_HASH_INDEX_FIND(ht, hval, retval, num_undef);
1563		return retval;
1564num_undef:
1565		switch (type) {
1566			case BP_VAR_R:
1567				zend_error(E_NOTICE,"Undefined offset: " ZEND_LONG_FMT, hval);
1568				/* break missing intentionally */
1569			case BP_VAR_UNSET:
1570			case BP_VAR_IS:
1571				retval = &EG(uninitialized_zval);
1572				break;
1573			case BP_VAR_RW:
1574				zend_error(E_NOTICE,"Undefined offset: " ZEND_LONG_FMT, hval);
1575				retval = zend_hash_index_update(ht, hval, &EG(uninitialized_zval));
1576				break;
1577			case BP_VAR_W:
1578				retval = zend_hash_index_add_new(ht, hval, &EG(uninitialized_zval));
1579				break;
1580		}
1581	} else if (EXPECTED(Z_TYPE_P(dim) == IS_STRING)) {
1582		offset_key = Z_STR_P(dim);
1583		if (dim_type != IS_CONST) {
1584			if (ZEND_HANDLE_NUMERIC(offset_key, hval)) {
1585				goto num_index;
1586			}
1587		}
1588str_index:
1589		retval = zend_hash_find(ht, offset_key);
1590		if (retval) {
1591			/* support for $GLOBALS[...] */
1592			if (UNEXPECTED(Z_TYPE_P(retval) == IS_INDIRECT)) {
1593				retval = Z_INDIRECT_P(retval);
1594				if (UNEXPECTED(Z_TYPE_P(retval) == IS_UNDEF)) {
1595					switch (type) {
1596						case BP_VAR_R:
1597							zend_error(E_NOTICE, "Undefined index: %s", ZSTR_VAL(offset_key));
1598							/* break missing intentionally */
1599						case BP_VAR_UNSET:
1600						case BP_VAR_IS:
1601							retval = &EG(uninitialized_zval);
1602							break;
1603						case BP_VAR_RW:
1604							zend_error(E_NOTICE,"Undefined index: %s", ZSTR_VAL(offset_key));
1605							/* break missing intentionally */
1606						case BP_VAR_W:
1607							ZVAL_NULL(retval);
1608							break;
1609					}
1610				}
1611			}
1612		} else {
1613			switch (type) {
1614				case BP_VAR_R:
1615					zend_error(E_NOTICE, "Undefined index: %s", ZSTR_VAL(offset_key));
1616					/* break missing intentionally */
1617				case BP_VAR_UNSET:
1618				case BP_VAR_IS:
1619					retval = &EG(uninitialized_zval);
1620					break;
1621				case BP_VAR_RW:
1622					zend_error(E_NOTICE,"Undefined index: %s", ZSTR_VAL(offset_key));
1623					retval = zend_hash_update(ht, offset_key, &EG(uninitialized_zval));
1624					break;
1625				case BP_VAR_W:
1626					retval = zend_hash_add_new(ht, offset_key, &EG(uninitialized_zval));
1627					break;
1628			}
1629		}
1630	} else {
1631		switch (Z_TYPE_P(dim)) {
1632			case IS_UNDEF:
1633				zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
1634				/* break missing intentionally */
1635			case IS_NULL:
1636				offset_key = ZSTR_EMPTY_ALLOC();
1637				goto str_index;
1638			case IS_DOUBLE:
1639				hval = zend_dval_to_lval(Z_DVAL_P(dim));
1640				goto num_index;
1641			case IS_RESOURCE:
1642				zend_error(E_NOTICE, "Resource ID#%pd used as offset, casting to integer (%pd)", Z_RES_HANDLE_P(dim), Z_RES_HANDLE_P(dim));
1643				hval = Z_RES_HANDLE_P(dim);
1644				goto num_index;
1645			case IS_FALSE:
1646				hval = 0;
1647				goto num_index;
1648			case IS_TRUE:
1649				hval = 1;
1650				goto num_index;
1651			case IS_REFERENCE:
1652				dim = Z_REFVAL_P(dim);
1653				goto try_again;
1654			default:
1655				zend_error(E_WARNING, "Illegal offset type");
1656				retval = (type == BP_VAR_W || type == BP_VAR_RW) ?
1657					NULL : &EG(uninitialized_zval);
1658		}
1659	}
1660	return retval;
1661}
1662
1663static zend_never_inline zval* ZEND_FASTCALL zend_fetch_dimension_address_inner_W(HashTable *ht, const zval *dim)
1664{
1665	return zend_fetch_dimension_address_inner(ht, dim, IS_TMP_VAR, BP_VAR_W);
1666}
1667
1668static zend_never_inline zval* ZEND_FASTCALL zend_fetch_dimension_address_inner_W_CONST(HashTable *ht, const zval *dim)
1669{
1670	return zend_fetch_dimension_address_inner(ht, dim, IS_CONST, BP_VAR_W);
1671}
1672
1673static zend_never_inline zval* ZEND_FASTCALL zend_fetch_dimension_address_inner_RW(HashTable *ht, const zval *dim)
1674{
1675	return zend_fetch_dimension_address_inner(ht, dim, IS_TMP_VAR, BP_VAR_RW);
1676}
1677
1678static zend_never_inline zval* ZEND_FASTCALL zend_fetch_dimension_address_inner_RW_CONST(HashTable *ht, const zval *dim)
1679{
1680	return zend_fetch_dimension_address_inner(ht, dim, IS_CONST, BP_VAR_RW);
1681}
1682
1683static zend_always_inline void zend_fetch_dimension_address(zval *result, zval *container, zval *dim, int dim_type, int type)
1684{
1685    zval *retval;
1686
1687	if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
1688try_array:
1689		SEPARATE_ARRAY(container);
1690fetch_from_array:
1691		if (dim == NULL) {
1692			retval = zend_hash_next_index_insert(Z_ARRVAL_P(container), &EG(uninitialized_zval));
1693			if (UNEXPECTED(retval == NULL)) {
1694				zend_error(E_WARNING, "Cannot add element to the array as the next element is already occupied");
1695				ZVAL_ERROR(result);
1696				return;
1697			}
1698		} else {
1699			retval = zend_fetch_dimension_address_inner(Z_ARRVAL_P(container), dim, dim_type, type);
1700			if (UNEXPECTED(!retval)) {
1701				ZVAL_ERROR(result);
1702				return;
1703			}
1704		}
1705		ZVAL_INDIRECT(result, retval);
1706		return;
1707	} else if (EXPECTED(Z_TYPE_P(container) == IS_REFERENCE)) {
1708		container = Z_REFVAL_P(container);
1709		if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
1710			goto try_array;
1711		}
1712	}
1713	if (EXPECTED(Z_TYPE_P(container) == IS_STRING)) {
1714		if (type != BP_VAR_UNSET && UNEXPECTED(Z_STRLEN_P(container) == 0)) {
1715			zval_ptr_dtor_nogc(container);
1716convert_to_array:
1717			ZVAL_NEW_ARR(container);
1718			zend_hash_init(Z_ARRVAL_P(container), 8, NULL, ZVAL_PTR_DTOR, 0);
1719			goto fetch_from_array;
1720		}
1721
1722		if (dim == NULL) {
1723			zend_throw_error(NULL, "[] operator not supported for strings");
1724		} else {
1725			zend_check_string_offset(dim, type);
1726			zend_wrong_string_offset();
1727		}
1728		ZVAL_ERROR(result);
1729	} else if (EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
1730		if (/*dim_type == IS_CV &&*/ dim && UNEXPECTED(Z_TYPE_P(dim) == IS_UNDEF)) {
1731			zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
1732			dim = &EG(uninitialized_zval);
1733		}
1734		if (!Z_OBJ_HT_P(container)->read_dimension) {
1735			zend_throw_error(NULL, "Cannot use object as array");
1736			ZVAL_ERROR(result);
1737		} else {
1738			retval = Z_OBJ_HT_P(container)->read_dimension(container, dim, type, result);
1739
1740			if (UNEXPECTED(retval == &EG(uninitialized_zval))) {
1741				zend_class_entry *ce = Z_OBJCE_P(container);
1742
1743				ZVAL_NULL(result);
1744				zend_error(E_NOTICE, "Indirect modification of overloaded element of %s has no effect", ZSTR_VAL(ce->name));
1745			} else if (EXPECTED(retval && Z_TYPE_P(retval) != IS_UNDEF)) {
1746				if (!Z_ISREF_P(retval)) {
1747					if (Z_REFCOUNTED_P(retval) &&
1748					    Z_REFCOUNT_P(retval) > 1) {
1749						if (Z_TYPE_P(retval) != IS_OBJECT) {
1750							Z_DELREF_P(retval);
1751							ZVAL_DUP(result, retval);
1752							retval = result;
1753						} else {
1754							ZVAL_COPY_VALUE(result, retval);
1755							retval = result;
1756						}
1757					}
1758					if (Z_TYPE_P(retval) != IS_OBJECT) {
1759						zend_class_entry *ce = Z_OBJCE_P(container);
1760						zend_error(E_NOTICE, "Indirect modification of overloaded element of %s has no effect", ZSTR_VAL(ce->name));
1761					}
1762				} else if (UNEXPECTED(Z_REFCOUNT_P(retval) == 1)) {
1763					ZVAL_UNREF(retval);
1764				}
1765				if (result != retval) {
1766					ZVAL_INDIRECT(result, retval);
1767				}
1768			} else {
1769				ZVAL_ERROR(result);
1770			}
1771		}
1772	} else {
1773		if (type != BP_VAR_W && UNEXPECTED(Z_TYPE_P(container) == IS_UNDEF)) {
1774			zval_undefined_cv(EG(current_execute_data)->opline->op1.var, EG(current_execute_data));
1775		}
1776		if (/*dim_type == IS_CV &&*/ dim && UNEXPECTED(Z_TYPE_P(dim) == IS_UNDEF)) {
1777			zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
1778		}
1779		if (EXPECTED(Z_TYPE_P(container) <= IS_FALSE)) {
1780			if (type != BP_VAR_UNSET) {
1781				goto convert_to_array;
1782			} else {
1783				/* for read-mode only */
1784				ZVAL_NULL(result);
1785			}
1786		} else if (EXPECTED(Z_ISERROR_P(container))) {
1787			ZVAL_ERROR(result);
1788		} else {
1789			if (type == BP_VAR_UNSET) {
1790				zend_error(E_WARNING, "Cannot unset offset in a non-array variable");
1791				ZVAL_NULL(result);
1792			} else {
1793				zend_error(E_WARNING, "Cannot use a scalar value as an array");
1794				ZVAL_ERROR(result);
1795			}
1796		}
1797	}
1798}
1799
1800static zend_never_inline void zend_fetch_dimension_address_W(zval *result, zval *container_ptr, zval *dim, int dim_type)
1801{
1802	zend_fetch_dimension_address(result, container_ptr, dim, dim_type, BP_VAR_W);
1803}
1804
1805static zend_never_inline void zend_fetch_dimension_address_RW(zval *result, zval *container_ptr, zval *dim, int dim_type)
1806{
1807	zend_fetch_dimension_address(result, container_ptr, dim, dim_type, BP_VAR_RW);
1808}
1809
1810static zend_never_inline void zend_fetch_dimension_address_UNSET(zval *result, zval *container_ptr, zval *dim, int dim_type)
1811{
1812	zend_fetch_dimension_address(result, container_ptr, dim, dim_type, BP_VAR_UNSET);
1813}
1814
1815static zend_always_inline void zend_fetch_dimension_address_read(zval *result, zval *container, zval *dim, int dim_type, int type, int support_strings)
1816{
1817	zval *retval;
1818
1819	if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
1820try_array:
1821		retval = zend_fetch_dimension_address_inner(Z_ARRVAL_P(container), dim, dim_type, type);
1822		ZVAL_COPY(result, retval);
1823		return;
1824	} else if (EXPECTED(Z_TYPE_P(container) == IS_REFERENCE)) {
1825		container = Z_REFVAL_P(container);
1826		if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
1827			goto try_array;
1828		}
1829	}
1830	if (support_strings && EXPECTED(Z_TYPE_P(container) == IS_STRING)) {
1831		zend_long offset;
1832
1833try_string_offset:
1834		if (UNEXPECTED(Z_TYPE_P(dim) != IS_LONG)) {
1835			switch (Z_TYPE_P(dim)) {
1836				/* case IS_LONG: */
1837				case IS_STRING:
1838					if (IS_LONG == is_numeric_string(Z_STRVAL_P(dim), Z_STRLEN_P(dim), NULL, NULL, -1)) {
1839						break;
1840					}
1841					if (type == BP_VAR_IS) {
1842						ZVAL_NULL(result);
1843						return;
1844					}
1845					zend_error(E_WARNING, "Illegal string offset '%s'", Z_STRVAL_P(dim));
1846					break;
1847				case IS_UNDEF:
1848					zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
1849				case IS_DOUBLE:
1850				case IS_NULL:
1851				case IS_FALSE:
1852				case IS_TRUE:
1853					if (type != BP_VAR_IS) {
1854						zend_error(E_NOTICE, "String offset cast occurred");
1855					}
1856					break;
1857				case IS_REFERENCE:
1858					dim = Z_REFVAL_P(dim);
1859					goto try_string_offset;
1860				default:
1861					zend_error(E_WARNING, "Illegal offset type");
1862					break;
1863			}
1864
1865			offset = _zval_get_long_func(dim);
1866		} else {
1867			offset = Z_LVAL_P(dim);
1868		}
1869
1870		if (UNEXPECTED(Z_STRLEN_P(container) < (size_t)((offset < 0) ? -offset : (offset + 1)))) {
1871			if (type != BP_VAR_IS) {
1872				zend_error(E_NOTICE, "Uninitialized string offset: %pd", offset);
1873				ZVAL_EMPTY_STRING(result);
1874			} else {
1875				ZVAL_NULL(result);
1876			}
1877		} else {
1878			zend_uchar c;
1879			zend_long real_offset;
1880
1881			real_offset = (UNEXPECTED(offset < 0)) /* Handle negative offset */
1882				? (zend_long)Z_STRLEN_P(container) + offset : offset;
1883			c = (zend_uchar)Z_STRVAL_P(container)[real_offset];
1884
1885			if (CG(one_char_string)[c]) {
1886				ZVAL_INTERNED_STR(result, CG(one_char_string)[c]);
1887			} else {
1888				ZVAL_NEW_STR(result, zend_string_init(Z_STRVAL_P(container) + real_offset, 1, 0));
1889			}
1890		}
1891	} else if (EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
1892		if (/*dim_type == IS_CV &&*/ UNEXPECTED(Z_TYPE_P(dim) == IS_UNDEF)) {
1893			zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
1894			dim = &EG(uninitialized_zval);
1895		}
1896		if (!Z_OBJ_HT_P(container)->read_dimension) {
1897			zend_throw_error(NULL, "Cannot use object as array");
1898			ZVAL_NULL(result);
1899		} else {
1900			retval = Z_OBJ_HT_P(container)->read_dimension(container, dim, type, result);
1901
1902			ZEND_ASSERT(result != NULL);
1903			if (retval) {
1904				if (result != retval) {
1905					ZVAL_COPY(result, retval);
1906				}
1907			} else {
1908				ZVAL_NULL(result);
1909			}
1910		}
1911	} else {
1912		if (type != BP_VAR_IS && UNEXPECTED(Z_TYPE_P(container) == IS_UNDEF)) {
1913			zval_undefined_cv(EG(current_execute_data)->opline->op1.var, EG(current_execute_data));
1914		}
1915		if (/*dim_type == IS_CV &&*/ UNEXPECTED(Z_TYPE_P(dim) == IS_UNDEF)) {
1916			zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
1917		}
1918		ZVAL_NULL(result);
1919	}
1920}
1921
1922static zend_never_inline void zend_fetch_dimension_address_read_R(zval *result, zval *container, zval *dim, int dim_type)
1923{
1924	zend_fetch_dimension_address_read(result, container, dim, dim_type, BP_VAR_R, 1);
1925}
1926
1927static zend_never_inline void zend_fetch_dimension_address_read_IS(zval *result, zval *container, zval *dim, int dim_type)
1928{
1929	zend_fetch_dimension_address_read(result, container, dim, dim_type, BP_VAR_IS, 1);
1930}
1931
1932static zend_never_inline void zend_fetch_dimension_address_read_LIST(zval *result, zval *container, zval *dim)
1933{
1934	zend_fetch_dimension_address_read(result, container, dim, IS_TMP_VAR, BP_VAR_R, 0);
1935}
1936
1937ZEND_API void zend_fetch_dimension_by_zval(zval *result, zval *container, zval *dim)
1938{
1939	zend_fetch_dimension_address_read_R(result, container, dim, IS_TMP_VAR);
1940}
1941
1942ZEND_API void zend_fetch_dimension_by_zval_is(zval *result, zval *container, zval *dim, int dim_type)
1943{
1944	zend_fetch_dimension_address_read(result, container, dim, dim_type, BP_VAR_IS, 1);
1945}
1946
1947
1948static zend_always_inline void zend_fetch_property_address(zval *result, zval *container, uint32_t container_op_type, zval *prop_ptr, uint32_t prop_op_type, void **cache_slot, int type)
1949{
1950    if (container_op_type != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
1951		do {
1952			if (container_op_type == IS_VAR && UNEXPECTED(Z_ISERROR_P(container))) {
1953				ZVAL_ERROR(result);
1954				return;
1955			}
1956
1957			if (Z_ISREF_P(container)) {
1958				container = Z_REFVAL_P(container);
1959				if (EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
1960					break;
1961				}
1962			}
1963
1964			/* this should modify object only if it's empty */
1965			if (type != BP_VAR_UNSET &&
1966			    EXPECTED(Z_TYPE_P(container) <= IS_FALSE ||
1967			      (Z_TYPE_P(container) == IS_STRING && Z_STRLEN_P(container)==0))) {
1968				zval_ptr_dtor_nogc(container);
1969				object_init(container);
1970			} else {
1971				zend_error(E_WARNING, "Attempt to modify property of non-object");
1972				ZVAL_ERROR(result);
1973				return;
1974			}
1975		} while (0);
1976	}
1977	if (prop_op_type == IS_CONST &&
1978	    EXPECTED(Z_OBJCE_P(container) == CACHED_PTR_EX(cache_slot))) {
1979		uint32_t prop_offset = (uint32_t)(intptr_t)CACHED_PTR_EX(cache_slot + 1);
1980		zend_object *zobj = Z_OBJ_P(container);
1981		zval *retval;
1982
1983		if (EXPECTED(prop_offset != (uint32_t)ZEND_DYNAMIC_PROPERTY_OFFSET)) {
1984			retval = OBJ_PROP(zobj, prop_offset);
1985			if (EXPECTED(Z_TYPE_P(retval) != IS_UNDEF)) {
1986				ZVAL_INDIRECT(result, retval);
1987				return;
1988			}
1989		} else if (EXPECTED(zobj->properties != NULL)) {
1990			if (UNEXPECTED(GC_REFCOUNT(zobj->properties) > 1)) {
1991				if (EXPECTED(!(GC_FLAGS(zobj->properties) & IS_ARRAY_IMMUTABLE))) {
1992					GC_REFCOUNT(zobj->properties)--;
1993				}
1994				zobj->properties = zend_array_dup(zobj->properties);
1995			}
1996			retval = zend_hash_find(zobj->properties, Z_STR_P(prop_ptr));
1997			if (EXPECTED(retval)) {
1998				ZVAL_INDIRECT(result, retval);
1999				return;
2000			}
2001		}
2002	}
2003	if (EXPECTED(Z_OBJ_HT_P(container)->get_property_ptr_ptr)) {
2004		zval *ptr = Z_OBJ_HT_P(container)->get_property_ptr_ptr(container, prop_ptr, type, cache_slot);
2005		if (NULL == ptr) {
2006			if (EXPECTED(Z_OBJ_HT_P(container)->read_property)) {
2007				ptr = Z_OBJ_HT_P(container)->read_property(container, prop_ptr, type, cache_slot, result);
2008				if (ptr != result) {
2009					ZVAL_INDIRECT(result, ptr);
2010				} else if (UNEXPECTED(Z_ISREF_P(ptr) && Z_REFCOUNT_P(ptr) == 1)) {
2011					ZVAL_UNREF(ptr);
2012				}
2013			} else {
2014				zend_throw_error(NULL, "Cannot access undefined property for object with overloaded property access");
2015				ZVAL_ERROR(result);
2016			}
2017		} else {
2018			ZVAL_INDIRECT(result, ptr);
2019		}
2020	} else if (EXPECTED(Z_OBJ_HT_P(container)->read_property)) {
2021		zval *ptr = Z_OBJ_HT_P(container)->read_property(container, prop_ptr, type, cache_slot, result);
2022		if (ptr != result) {
2023			ZVAL_INDIRECT(result, ptr);
2024		} else if (UNEXPECTED(Z_ISREF_P(ptr) && Z_REFCOUNT_P(ptr) == 1)) {
2025			ZVAL_UNREF(ptr);
2026		}
2027	} else {
2028		zend_error(E_WARNING, "This object doesn't support property references");
2029		ZVAL_ERROR(result);
2030	}
2031}
2032
2033#if ZEND_INTENSIVE_DEBUGGING
2034
2035#define CHECK_SYMBOL_TABLES()													\
2036	zend_hash_apply(&EG(symbol_table), zend_check_symbol);			\
2037	if (&EG(symbol_table)!=EX(symbol_table)) {							\
2038		zend_hash_apply(EX(symbol_table), zend_check_symbol);	\
2039	}
2040
2041static int zend_check_symbol(zval *pz)
2042{
2043	if (Z_TYPE_P(pz) == IS_INDIRECT) {
2044		pz = Z_INDIRECT_P(pz);
2045	}
2046	if (Z_TYPE_P(pz) > 10) {
2047		fprintf(stderr, "Warning!  %x has invalid type!\n", *pz);
2048/* See http://support.microsoft.com/kb/190351 */
2049#ifdef ZEND_WIN32
2050		fflush(stderr);
2051#endif
2052	} else if (Z_TYPE_P(pz) == IS_ARRAY) {
2053		zend_hash_apply(Z_ARRVAL_P(pz), zend_check_symbol);
2054	} else if (Z_TYPE_P(pz) == IS_OBJECT) {
2055		/* OBJ-TBI - doesn't support new object model! */
2056		zend_hash_apply(Z_OBJPROP_P(pz), zend_check_symbol);
2057	}
2058
2059	return 0;
2060}
2061
2062
2063#else
2064#define CHECK_SYMBOL_TABLES()
2065#endif
2066
2067ZEND_API void execute_internal(zend_execute_data *execute_data, zval *return_value)
2068{
2069	execute_data->func->internal_function.handler(execute_data, return_value);
2070}
2071
2072ZEND_API void zend_clean_and_cache_symbol_table(zend_array *symbol_table) /* {{{ */
2073{
2074	if (EG(symtable_cache_ptr) >= EG(symtable_cache_limit)) {
2075		zend_array_destroy(symbol_table);
2076	} else {
2077		/* clean before putting into the cache, since clean
2078		   could call dtors, which could use cached hash */
2079		zend_symtable_clean(symbol_table);
2080		*(++EG(symtable_cache_ptr)) = symbol_table;
2081	}
2082}
2083/* }}} */
2084
2085static zend_always_inline void i_free_compiled_variables(zend_execute_data *execute_data) /* {{{ */
2086{
2087	zval *cv = EX_VAR_NUM(0);
2088	zval *end = cv + EX(func)->op_array.last_var;
2089	while (EXPECTED(cv != end)) {
2090		if (Z_REFCOUNTED_P(cv)) {
2091			if (!Z_DELREF_P(cv)) {
2092				zend_refcounted *r = Z_COUNTED_P(cv);
2093				ZVAL_NULL(cv);
2094				zval_dtor_func_for_ptr(r);
2095			} else {
2096				GC_ZVAL_CHECK_POSSIBLE_ROOT(cv);
2097			}
2098		}
2099		cv++;
2100 	}
2101}
2102/* }}} */
2103
2104void zend_free_compiled_variables(zend_execute_data *execute_data) /* {{{ */
2105{
2106	i_free_compiled_variables(execute_data);
2107}
2108/* }}} */
2109
2110static zend_never_inline ZEND_COLD ZEND_NORETURN void ZEND_FASTCALL zend_interrupt(void) /* {{{ */
2111{
2112	zend_timeout(0);
2113}
2114/* }}} */
2115
2116#define ZEND_VM_INTERRUPT_CHECK() do { \
2117		if (UNEXPECTED(EG(timed_out))) { \
2118			zend_interrupt(); \
2119		} \
2120	} while (0)
2121
2122/*
2123 * Stack Frame Layout (the whole stack frame is allocated at once)
2124 * ==================
2125 *
2126 *                             +========================================+
2127 * EG(current_execute_data) -> | zend_execute_data                      |
2128 *                             +----------------------------------------+
2129 *     EX_CV_NUM(0) ---------> | VAR[0] = ARG[1]                        |
2130 *                             | ...                                    |
2131 *                             | VAR[op_array->num_args-1] = ARG[N]     |
2132 *                             | ...                                    |
2133 *                             | VAR[op_array->last_var-1]              |
2134 *                             | VAR[op_array->last_var] = TMP[0]       |
2135 *                             | ...                                    |
2136 *                             | VAR[op_array->last_var+op_array->T-1]  |
2137 *                             | ARG[N+1] (extra_args)                  |
2138 *                             | ...                                    |
2139 *                             +----------------------------------------+
2140 */
2141
2142static zend_always_inline void i_init_func_execute_data(zend_execute_data *execute_data, zend_op_array *op_array, zval *return_value, int check_this) /* {{{ */
2143{
2144	uint32_t first_extra_arg, num_args;
2145	ZEND_ASSERT(EX(func) == (zend_function*)op_array);
2146
2147	EX(opline) = op_array->opcodes;
2148	EX(call) = NULL;
2149	EX(return_value) = return_value;
2150
2151	/* Handle arguments */
2152	first_extra_arg = op_array->num_args;
2153	num_args = EX_NUM_ARGS();
2154	if (UNEXPECTED(num_args > first_extra_arg)) {
2155		if (EXPECTED(!(op_array->fn_flags & ZEND_ACC_CALL_VIA_TRAMPOLINE))) {
2156			zval *end, *src, *dst;
2157			uint32_t type_flags = 0;
2158
2159			if (EXPECTED((op_array->fn_flags & ZEND_ACC_HAS_TYPE_HINTS) == 0)) {
2160				/* Skip useless ZEND_RECV and ZEND_RECV_INIT opcodes */
2161				EX(opline) += first_extra_arg;
2162			}
2163
2164			/* move extra args into separate array after all CV and TMP vars */
2165			end = EX_VAR_NUM(first_extra_arg - 1);
2166			src = end + (num_args - first_extra_arg);
2167			dst = src + (op_array->last_var + op_array->T - first_extra_arg);
2168			if (EXPECTED(src != dst)) {
2169				do {
2170					type_flags |= Z_TYPE_INFO_P(src);
2171					ZVAL_COPY_VALUE(dst, src);
2172					ZVAL_UNDEF(src);
2173					src--;
2174					dst--;
2175				} while (src != end);
2176			} else {
2177				do {
2178					type_flags |= Z_TYPE_INFO_P(src);
2179					src--;
2180				} while (src != end);
2181			}
2182			ZEND_ADD_CALL_FLAG(execute_data, ((type_flags >> Z_TYPE_FLAGS_SHIFT) & IS_TYPE_REFCOUNTED));
2183		}
2184	} else if (EXPECTED((op_array->fn_flags & ZEND_ACC_HAS_TYPE_HINTS) == 0)) {
2185		/* Skip useless ZEND_RECV and ZEND_RECV_INIT opcodes */
2186		EX(opline) += num_args;
2187	}
2188
2189	/* Initialize CV variables (skip arguments) */
2190	if (EXPECTED((int)num_args < op_array->last_var)) {
2191		zval *var = EX_VAR_NUM(num_args);
2192		zval *end = EX_VAR_NUM(op_array->last_var);
2193
2194		do {
2195			ZVAL_UNDEF(var);
2196			var++;
2197		} while (var != end);
2198	}
2199
2200	if (check_this && op_array->this_var != (uint32_t)-1 && EXPECTED(Z_TYPE(EX(This)) == IS_OBJECT)) {
2201		ZVAL_OBJ(EX_VAR(op_array->this_var), Z_OBJ(EX(This)));
2202		GC_REFCOUNT(Z_OBJ(EX(This)))++;
2203	}
2204
2205	EX_LOAD_RUN_TIME_CACHE(op_array);
2206	EX_LOAD_LITERALS(op_array);
2207
2208	EG(current_execute_data) = execute_data;
2209}
2210/* }}} */
2211
2212static zend_never_inline void ZEND_FASTCALL init_func_run_time_cache(zend_op_array *op_array) /* {{{ */
2213{
2214	ZEND_ASSERT(op_array->run_time_cache == NULL);
2215	op_array->run_time_cache = zend_arena_alloc(&CG(arena), op_array->cache_size);
2216	memset(op_array->run_time_cache, 0, op_array->cache_size);
2217}
2218/* }}} */
2219
2220static zend_always_inline void i_init_code_execute_data(zend_execute_data *execute_data, zend_op_array *op_array, zval *return_value) /* {{{ */
2221{
2222	ZEND_ASSERT(EX(func) == (zend_function*)op_array);
2223
2224	EX(opline) = op_array->opcodes;
2225	EX(call) = NULL;
2226	EX(return_value) = return_value;
2227
2228	if (UNEXPECTED(op_array->this_var != (uint32_t)-1) && EXPECTED(Z_TYPE(EX(This)) == IS_OBJECT)) {
2229		GC_REFCOUNT(Z_OBJ(EX(This)))++;
2230		if (!zend_hash_str_add(EX(symbol_table), "this", sizeof("this")-1, &EX(This))) {
2231			GC_REFCOUNT(Z_OBJ(EX(This)))--;
2232		}
2233	}
2234
2235	zend_attach_symbol_table(execute_data);
2236
2237	if (!op_array->run_time_cache) {
2238		op_array->run_time_cache = emalloc(op_array->cache_size);
2239		memset(op_array->run_time_cache, 0, op_array->cache_size);
2240	}
2241	EX_LOAD_RUN_TIME_CACHE(op_array);
2242	EX_LOAD_LITERALS(op_array);
2243
2244	EG(current_execute_data) = execute_data;
2245}
2246/* }}} */
2247
2248static zend_always_inline void i_init_execute_data(zend_execute_data *execute_data, zend_op_array *op_array, zval *return_value) /* {{{ */
2249{
2250	ZEND_ASSERT(EX(func) == (zend_function*)op_array);
2251
2252	EX(opline) = op_array->opcodes;
2253	EX(call) = NULL;
2254	EX(return_value) = return_value;
2255
2256	if (EX_CALL_INFO() & ZEND_CALL_HAS_SYMBOL_TABLE) {
2257		if (UNEXPECTED(op_array->this_var != (uint32_t)-1) && EXPECTED(Z_TYPE(EX(This)) == IS_OBJECT)) {
2258			GC_REFCOUNT(Z_OBJ(EX(This)))++;
2259			if (!zend_hash_str_add(EX(symbol_table), "this", sizeof("this")-1, &EX(This))) {
2260				GC_REFCOUNT(Z_OBJ(EX(This)))--;
2261			}
2262		}
2263
2264		zend_attach_symbol_table(execute_data);
2265	} else {
2266		uint32_t first_extra_arg, num_args;
2267
2268		/* Handle arguments */
2269		first_extra_arg = op_array->num_args;
2270		num_args = EX_NUM_ARGS();
2271		if (UNEXPECTED(num_args > first_extra_arg)) {
2272			if (EXPECTED(!(op_array->fn_flags & ZEND_ACC_CALL_VIA_TRAMPOLINE))) {
2273				zval *end, *src, *dst;
2274				uint32_t type_flags = 0;
2275
2276				if (EXPECTED((op_array->fn_flags & ZEND_ACC_HAS_TYPE_HINTS) == 0)) {
2277					/* Skip useless ZEND_RECV and ZEND_RECV_INIT opcodes */
2278					EX(opline) += first_extra_arg;
2279				}
2280
2281				/* move extra args into separate array after all CV and TMP vars */
2282				end = EX_VAR_NUM(first_extra_arg - 1);
2283				src = end + (num_args - first_extra_arg);
2284				dst = src + (op_array->last_var + op_array->T - first_extra_arg);
2285				if (EXPECTED(src != dst)) {
2286					do {
2287						type_flags |= Z_TYPE_INFO_P(src);
2288						ZVAL_COPY_VALUE(dst, src);
2289						ZVAL_UNDEF(src);
2290						src--;
2291						dst--;
2292					} while (src != end);
2293				} else {
2294					do {
2295						type_flags |= Z_TYPE_INFO_P(src);
2296						src--;
2297					} while (src != end);
2298				}
2299				ZEND_ADD_CALL_FLAG(execute_data, ((type_flags >> Z_TYPE_FLAGS_SHIFT) & IS_TYPE_REFCOUNTED));
2300			}
2301		} else if (EXPECTED((op_array->fn_flags & ZEND_ACC_HAS_TYPE_HINTS) == 0)) {
2302			/* Skip useless ZEND_RECV and ZEND_RECV_INIT opcodes */
2303			EX(opline) += num_args;
2304		}
2305
2306		/* Initialize CV variables (skip arguments) */
2307		if (EXPECTED((int)num_args < op_array->last_var)) {
2308			zval *var = EX_VAR_NUM(num_args);
2309			zval *end = EX_VAR_NUM(op_array->last_var);
2310
2311			do {
2312				ZVAL_UNDEF(var);
2313				var++;
2314			} while (var != end);
2315		}
2316
2317		if (op_array->this_var != (uint32_t)-1 && EXPECTED(Z_TYPE(EX(This)) == IS_OBJECT)) {
2318			ZVAL_OBJ(EX_VAR(op_array->this_var), Z_OBJ(EX(This)));
2319			GC_REFCOUNT(Z_OBJ(EX(This)))++;
2320		}
2321	}
2322
2323	if (!op_array->run_time_cache) {
2324		if (op_array->function_name) {
2325			op_array->run_time_cache = zend_arena_alloc(&CG(arena), op_array->cache_size);
2326		} else {
2327			op_array->run_time_cache = emalloc(op_array->cache_size);
2328		}
2329		memset(op_array->run_time_cache, 0, op_array->cache_size);
2330	}
2331	EX_LOAD_RUN_TIME_CACHE(op_array);
2332	EX_LOAD_LITERALS(op_array);
2333
2334	EG(current_execute_data) = execute_data;
2335}
2336/* }}} */
2337
2338ZEND_API zend_execute_data *zend_create_generator_execute_data(zend_execute_data *call, zend_op_array *op_array, zval *return_value) /* {{{ */
2339{
2340	/*
2341	 * Normally the execute_data is allocated on the VM stack (because it does
2342	 * not actually do any allocation and thus is faster). For generators
2343	 * though this behavior would be suboptimal, because the (rather large)
2344	 * structure would have to be copied back and forth every time execution is
2345	 * suspended or resumed. That's why for generators the execution context
2346	 * is allocated using a separate VM stack, thus allowing to save and
2347	 * restore it simply by replacing a pointer.
2348	 */
2349	zend_execute_data *execute_data;
2350	uint32_t num_args = ZEND_CALL_NUM_ARGS(call);
2351	size_t stack_size = (ZEND_CALL_FRAME_SLOT + MAX(op_array->last_var + op_array->T, num_args)) * sizeof(zval);
2352	uint32_t call_info;
2353
2354	EG(vm_stack) = zend_vm_stack_new_page(
2355		EXPECTED(stack_size < ZEND_VM_STACK_FREE_PAGE_SIZE(1)) ?
2356			ZEND_VM_STACK_PAGE_SIZE(1) :
2357			ZEND_VM_STACK_PAGE_ALIGNED_SIZE(1, stack_size),
2358		NULL);
2359	EG(vm_stack_top) = EG(vm_stack)->top;
2360	EG(vm_stack_end) = EG(vm_stack)->end;
2361
2362	call_info = ZEND_CALL_TOP_FUNCTION | ZEND_CALL_ALLOCATED | (ZEND_CALL_INFO(call) & (ZEND_CALL_CLOSURE|ZEND_CALL_RELEASE_THIS));
2363	execute_data = zend_vm_stack_push_call_frame(
2364		call_info,
2365		(zend_function*)op_array,
2366		num_args,
2367		Z_TYPE(call->This) != IS_OBJECT ? Z_CE(call->This) : NULL,
2368		Z_TYPE(call->This) == IS_OBJECT ? Z_OBJ(call->This) : NULL);
2369	EX(prev_execute_data) = NULL;
2370	EX_NUM_ARGS() = num_args;
2371
2372	/* copy arguments */
2373	if (num_args > 0) {
2374		zval *arg_src = ZEND_CALL_ARG(call, 1);
2375		zval *arg_dst = ZEND_CALL_ARG(execute_data, 1);
2376		zval *end = arg_src + num_args;
2377
2378		do {
2379			ZVAL_COPY_VALUE(arg_dst, arg_src);
2380			arg_src++;
2381			arg_dst++;
2382		} while (arg_src != end);
2383	}
2384
2385	if (UNEXPECTED(!op_array->run_time_cache)) {
2386		init_func_run_time_cache(op_array);
2387	}
2388
2389	i_init_func_execute_data(execute_data, op_array, return_value, 1);
2390
2391	return execute_data;
2392}
2393/* }}} */
2394
2395ZEND_API void zend_init_execute_data(zend_execute_data *execute_data, zend_op_array *op_array, zval *return_value) /* {{{ */
2396{
2397	EX(prev_execute_data) = EG(current_execute_data);
2398	i_init_execute_data(execute_data, op_array, return_value);
2399}
2400/* }}} */
2401
2402static zend_always_inline zend_bool zend_is_by_ref_func_arg_fetch(const zend_op *opline, zend_execute_data *call) /* {{{ */
2403{
2404	uint32_t arg_num = opline->extended_value & ZEND_FETCH_ARG_MASK;
2405
2406	if (EXPECTED(arg_num <= MAX_ARG_FLAG_NUM)) {
2407		return QUICK_ARG_SHOULD_BE_SENT_BY_REF(call->func, arg_num);
2408	}
2409	return ARG_SHOULD_BE_SENT_BY_REF(call->func, arg_num);
2410}
2411/* }}} */
2412
2413static zend_execute_data *zend_vm_stack_copy_call_frame(zend_execute_data *call, uint32_t passed_args, uint32_t additional_args) /* {{{ */
2414{
2415	zend_execute_data *new_call;
2416	int used_stack = (EG(vm_stack_top) - (zval*)call) + additional_args;
2417
2418	/* copy call frame into new stack segment */
2419	new_call = zend_vm_stack_extend(used_stack * sizeof(zval));
2420	*new_call = *call;
2421	ZEND_ADD_CALL_FLAG(new_call, ZEND_CALL_ALLOCATED);
2422
2423	if (passed_args) {
2424		zval *src = ZEND_CALL_ARG(call, 1);
2425		zval *dst = ZEND_CALL_ARG(new_call, 1);
2426		do {
2427			ZVAL_COPY_VALUE(dst, src);
2428			passed_args--;
2429			src++;
2430			dst++;
2431		} while (passed_args);
2432	}
2433
2434	/* delete old call_frame from previous stack segment */
2435	EG(vm_stack)->prev->top = (zval*)call;
2436
2437	/* delete previous stack segment if it becames empty */
2438	if (UNEXPECTED(EG(vm_stack)->prev->top == ZEND_VM_STACK_ELEMENTS(EG(vm_stack)->prev))) {
2439		zend_vm_stack r = EG(vm_stack)->prev;
2440
2441		EG(vm_stack)->prev = r->prev;
2442		efree(r);
2443	}
2444
2445	return new_call;
2446}
2447/* }}} */
2448
2449static zend_always_inline void zend_vm_stack_extend_call_frame(zend_execute_data **call, uint32_t passed_args, uint32_t additional_args) /* {{{ */
2450{
2451	if (EXPECTED((uint32_t)(EG(vm_stack_end) - EG(vm_stack_top)) > additional_args)) {
2452		EG(vm_stack_top) += additional_args;
2453	} else {
2454		*call = zend_vm_stack_copy_call_frame(*call, passed_args, additional_args);
2455	}
2456}
2457/* }}} */
2458
2459static zend_always_inline zend_generator *zend_get_running_generator(zend_execute_data *execute_data) /* {{{ */
2460{
2461	/* The generator object is stored in EX(return_value) */
2462	zend_generator *generator = (zend_generator *) EX(return_value);
2463	/* However control may currently be delegated to another generator.
2464	 * That's the one we're interested in. */
2465	return generator;
2466}
2467/* }}} */
2468
2469static void cleanup_unfinished_calls(zend_execute_data *execute_data, uint32_t op_num) /* {{{ */
2470{
2471	if (UNEXPECTED(EX(call))) {
2472		zend_execute_data *call = EX(call);
2473		zend_op *opline = EX(func)->op_array.opcodes + op_num;
2474		int level;
2475		int do_exit;
2476
2477		if (UNEXPECTED(opline->opcode == ZEND_INIT_FCALL ||
2478			opline->opcode == ZEND_INIT_FCALL_BY_NAME ||
2479			opline->opcode == ZEND_INIT_DYNAMIC_CALL ||
2480			opline->opcode == ZEND_INIT_METHOD_CALL ||
2481			opline->opcode == ZEND_INIT_STATIC_METHOD_CALL)) {
2482			ZEND_ASSERT(op_num);
2483			opline--;
2484		}
2485
2486		do {
2487			/* If the exception was thrown during a function call there might be
2488			 * arguments pushed to the stack that have to be dtor'ed. */
2489
2490			/* find the number of actually passed arguments */
2491			level = 0;
2492			do_exit = 0;
2493			do {
2494				switch (opline->opcode) {
2495					case ZEND_DO_FCALL:
2496					case ZEND_DO_ICALL:
2497					case ZEND_DO_UCALL:
2498					case ZEND_DO_FCALL_BY_NAME:
2499						level++;
2500						break;
2501					case ZEND_INIT_FCALL:
2502					case ZEND_INIT_FCALL_BY_NAME:
2503					case ZEND_INIT_NS_FCALL_BY_NAME:
2504					case ZEND_INIT_DYNAMIC_CALL:
2505					case ZEND_INIT_USER_CALL:
2506					case ZEND_INIT_METHOD_CALL:
2507					case ZEND_INIT_STATIC_METHOD_CALL:
2508					case ZEND_NEW:
2509						if (level == 0) {
2510							ZEND_CALL_NUM_ARGS(call) = 0;
2511							do_exit = 1;
2512						}
2513						level--;
2514						break;
2515					case ZEND_SEND_VAL:
2516					case ZEND_SEND_VAL_EX:
2517					case ZEND_SEND_VAR:
2518					case ZEND_SEND_VAR_EX:
2519					case ZEND_SEND_REF:
2520					case ZEND_SEND_VAR_NO_REF:
2521					case ZEND_SEND_USER:
2522						if (level == 0) {
2523							ZEND_CALL_NUM_ARGS(call) = opline->op2.num;
2524							do_exit = 1;
2525						}
2526						break;
2527					case ZEND_SEND_ARRAY:
2528					case ZEND_SEND_UNPACK:
2529						if (level == 0) {
2530							do_exit = 1;
2531						}
2532						break;
2533				}
2534				if (!do_exit) {
2535					opline--;
2536				}
2537			} while (!do_exit);
2538			if (call->prev_execute_data) {
2539				/* skip current call region */
2540				level = 0;
2541				do_exit = 0;
2542				do {
2543					switch (opline->opcode) {
2544						case ZEND_DO_FCALL:
2545						case ZEND_DO_ICALL:
2546						case ZEND_DO_UCALL:
2547						case ZEND_DO_FCALL_BY_NAME:
2548							level++;
2549							break;
2550						case ZEND_INIT_FCALL:
2551						case ZEND_INIT_FCALL_BY_NAME:
2552						case ZEND_INIT_NS_FCALL_BY_NAME:
2553						case ZEND_INIT_DYNAMIC_CALL:
2554						case ZEND_INIT_USER_CALL:
2555						case ZEND_INIT_METHOD_CALL:
2556						case ZEND_INIT_STATIC_METHOD_CALL:
2557						case ZEND_NEW:
2558							if (level == 0) {
2559								do_exit = 1;
2560							}
2561							level--;
2562							break;
2563					}
2564					opline--;
2565				} while (!do_exit);
2566			}
2567
2568			zend_vm_stack_free_args(EX(call));
2569
2570			if (ZEND_CALL_INFO(call) & ZEND_CALL_RELEASE_THIS) {
2571				if (ZEND_CALL_INFO(call) & ZEND_CALL_CTOR) {
2572					GC_REFCOUNT(Z_OBJ(call->This))--;
2573					if (GC_REFCOUNT(Z_OBJ(call->This)) == 1) {
2574						zend_object_store_ctor_failed(Z_OBJ(call->This));
2575					}
2576				}
2577				OBJ_RELEASE(Z_OBJ(call->This));
2578			}
2579			if (call->func->common.fn_flags & ZEND_ACC_CLOSURE) {
2580				zend_object_release((zend_object *) call->func->common.prototype);
2581			} else if (call->func->common.fn_flags & ZEND_ACC_CALL_VIA_TRAMPOLINE) {
2582				zend_string_release(call->func->common.function_name);
2583				zend_free_trampoline(call->func);
2584			}
2585
2586			EX(call) = call->prev_execute_data;
2587			zend_vm_stack_free_call_frame(call);
2588			call = EX(call);
2589		} while (call);
2590	}
2591}
2592/* }}} */
2593
2594static void cleanup_live_vars(zend_execute_data *execute_data, uint32_t op_num, uint32_t catch_op_num) /* {{{ */
2595{
2596	int i;
2597
2598	for (i = 0; i < EX(func)->op_array.last_live_range; i++) {
2599		const zend_live_range *range = &EX(func)->op_array.live_range[i];
2600		if (range->start > op_num) {
2601			/* further blocks will not be relevant... */
2602			break;
2603		} else if (op_num < range->end) {
2604			if (!catch_op_num || catch_op_num >= range->end) {
2605				uint32_t kind = range->var & ZEND_LIVE_MASK;
2606				uint32_t var_num = range->var & ~ZEND_LIVE_MASK;
2607				zval *var = EX_VAR(var_num);
2608
2609				if (kind == ZEND_LIVE_TMPVAR) {
2610					zval_ptr_dtor_nogc(var);
2611				} else if (kind == ZEND_LIVE_LOOP) {
2612					if (Z_TYPE_P(var) != IS_ARRAY && Z_FE_ITER_P(var) != (uint32_t)-1) {
2613						zend_hash_iterator_del(Z_FE_ITER_P(var));
2614					}
2615					zval_ptr_dtor_nogc(var);
2616				} else if (kind == ZEND_LIVE_ROPE) {
2617					zend_string **rope = (zend_string **)var;
2618					zend_op *last = EX(func)->op_array.opcodes + op_num;
2619					while ((last->opcode != ZEND_ROPE_ADD && last->opcode != ZEND_ROPE_INIT)
2620							|| last->result.var != var_num) {
2621						ZEND_ASSERT(last >= EX(func)->op_array.opcodes);
2622						last--;
2623					}
2624					if (last->opcode == ZEND_ROPE_INIT) {
2625						zend_string_release(*rope);
2626					} else {
2627						int j = last->extended_value;
2628						do {
2629							zend_string_release(rope[j]);
2630						} while (j--);
2631					}
2632				} else if (kind == ZEND_LIVE_SILENCE) {
2633					/* restore previous error_reporting value */
2634					if (!EG(error_reporting) && Z_LVAL_P(var) != 0) {
2635						EG(error_reporting) = Z_LVAL_P(var);
2636					}
2637				}
2638			}
2639		}
2640	}
2641}
2642/* }}} */
2643
2644void zend_cleanup_unfinished_execution(zend_execute_data *execute_data, uint32_t op_num, uint32_t catch_op_num) {
2645	cleanup_unfinished_calls(execute_data, op_num);
2646	cleanup_live_vars(execute_data, op_num, catch_op_num);
2647}
2648
2649static void zend_swap_operands(zend_op *op) /* {{{ */
2650{
2651	znode_op     tmp;
2652	zend_uchar   tmp_type;
2653
2654	tmp          = op->op1;
2655	tmp_type     = op->op1_type;
2656	op->op1      = op->op2;
2657	op->op1_type = op->op2_type;
2658	op->op2      = tmp;
2659	op->op2_type = tmp_type;
2660}
2661/* }}} */
2662
2663static zend_never_inline zend_execute_data *zend_init_dynamic_call_string(zend_string *function, uint32_t num_args) /* {{{ */
2664{
2665	zend_function *fbc;
2666	zval *func;
2667	zend_class_entry *called_scope;
2668	zend_string *lcname;
2669	const char *colon;
2670
2671	if ((colon = zend_memrchr(ZSTR_VAL(function), ':', ZSTR_LEN(function))) != NULL &&
2672		colon > ZSTR_VAL(function) &&
2673		*(colon-1) == ':'
2674	) {
2675		zend_string *mname;
2676		size_t cname_length = colon - ZSTR_VAL(function) - 1;
2677		size_t mname_length = ZSTR_LEN(function) - cname_length - (sizeof("::") - 1);
2678
2679		lcname = zend_string_init(ZSTR_VAL(function), cname_length, 0);
2680
2681		called_scope = zend_fetch_class_by_name(lcname, NULL, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
2682		if (UNEXPECTED(called_scope == NULL)) {
2683			zend_string_release(lcname);
2684			return NULL;
2685		}
2686
2687		mname = zend_string_init(ZSTR_VAL(function) + (cname_length + sizeof("::") - 1), mname_length, 0);
2688
2689		if (called_scope->get_static_method) {
2690			fbc = called_scope->get_static_method(called_scope, mname);
2691		} else {
2692			fbc = zend_std_get_static_method(called_scope, mname, NULL);
2693		}
2694		if (UNEXPECTED(fbc == NULL)) {
2695			if (EXPECTED(!EG(exception))) {
2696				zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(called_scope->name), ZSTR_VAL(mname));
2697			}
2698			zend_string_release(lcname);
2699			zend_string_release(mname);
2700			return NULL;
2701		}
2702
2703		zend_string_release(lcname);
2704		zend_string_release(mname);
2705
2706		if (UNEXPECTED(!(fbc->common.fn_flags & ZEND_ACC_STATIC))) {
2707			if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
2708				zend_error(E_DEPRECATED,
2709					"Non-static method %s::%s() should not be called statically",
2710					ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
2711				if (UNEXPECTED(EG(exception) != NULL)) {
2712					return NULL;
2713				}
2714			} else {
2715				zend_throw_error(
2716					zend_ce_error,
2717					"Non-static method %s::%s() cannot be called statically",
2718					ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
2719				return NULL;
2720			}
2721		}
2722	} else {
2723		if (ZSTR_VAL(function)[0] == '\\') {
2724			lcname = zend_string_alloc(ZSTR_LEN(function) - 1, 0);
2725			zend_str_tolower_copy(ZSTR_VAL(lcname), ZSTR_VAL(function) + 1, ZSTR_LEN(function) - 1);
2726		} else {
2727			lcname = zend_string_tolower(function);
2728		}
2729		if (UNEXPECTED((func = zend_hash_find(EG(function_table), lcname)) == NULL)) {
2730			zend_throw_error(NULL, "Call to undefined function %s()", ZSTR_VAL(function));
2731			zend_string_release(lcname);
2732			return NULL;
2733		}
2734		zend_string_release(lcname);
2735
2736		fbc = Z_FUNC_P(func);
2737		called_scope = NULL;
2738	}
2739
2740	if (EXPECTED(fbc->type == ZEND_USER_FUNCTION) && UNEXPECTED(!fbc->op_array.run_time_cache)) {
2741		init_func_run_time_cache(&fbc->op_array);
2742	}
2743
2744	return zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
2745		fbc, num_args, called_scope, NULL);
2746}
2747/* }}} */
2748
2749static zend_never_inline zend_execute_data *zend_init_dynamic_call_object(zval *function, uint32_t num_args) /* {{{ */
2750{
2751	zend_function *fbc;
2752	zend_class_entry *called_scope;
2753	zend_object *object;
2754	uint32_t call_info = ZEND_CALL_NESTED_FUNCTION;
2755
2756	if (EXPECTED(Z_OBJ_HANDLER_P(function, get_closure)) &&
2757	    EXPECTED(Z_OBJ_HANDLER_P(function, get_closure)(function, &called_scope, &fbc, &object) == SUCCESS)) {
2758
2759		if (fbc->common.fn_flags & ZEND_ACC_CLOSURE) {
2760			/* Delay closure destruction until its invocation */
2761			ZEND_ASSERT(GC_TYPE((zend_object*)fbc->common.prototype) == IS_OBJECT);
2762			GC_REFCOUNT((zend_object*)fbc->common.prototype)++;
2763			call_info |= ZEND_CALL_CLOSURE;
2764		} else if (object) {
2765			call_info |= ZEND_CALL_RELEASE_THIS;
2766			GC_REFCOUNT(object)++; /* For $this pointer */
2767		}
2768	} else {
2769		zend_throw_error(NULL, "Function name must be a string");
2770		return NULL;
2771	}
2772
2773	if (EXPECTED(fbc->type == ZEND_USER_FUNCTION) && UNEXPECTED(!fbc->op_array.run_time_cache)) {
2774		init_func_run_time_cache(&fbc->op_array);
2775	}
2776
2777	return zend_vm_stack_push_call_frame(call_info,
2778		fbc, num_args, called_scope, object);
2779}
2780/* }}} */
2781
2782static zend_never_inline zend_execute_data *zend_init_dynamic_call_array(zend_array *function, uint32_t num_args) /* {{{ */
2783{
2784	zend_function *fbc;
2785	zend_class_entry *called_scope;
2786	zend_object *object;
2787	uint32_t call_info = ZEND_CALL_NESTED_FUNCTION;
2788
2789	if (zend_hash_num_elements(function) == 2) {
2790		zval *obj;
2791		zval *method;
2792		obj = zend_hash_index_find(function, 0);
2793		method = zend_hash_index_find(function, 1);
2794
2795		if (UNEXPECTED(!obj) || UNEXPECTED(!method)) {
2796			zend_throw_error(NULL, "Array callback has to contain indices 0 and 1");
2797			return NULL;
2798		}
2799
2800		ZVAL_DEREF(obj);
2801		if (UNEXPECTED(Z_TYPE_P(obj) != IS_STRING) && UNEXPECTED(Z_TYPE_P(obj) != IS_OBJECT)) {
2802			zend_throw_error(NULL, "First array member is not a valid class name or object");
2803			return NULL;
2804		}
2805
2806		ZVAL_DEREF(method);
2807		if (UNEXPECTED(Z_TYPE_P(method) != IS_STRING)) {
2808			zend_throw_error(NULL, "Second array member is not a valid method");
2809			return NULL;
2810		}
2811
2812		if (Z_TYPE_P(obj) == IS_STRING) {
2813			object = NULL;
2814			called_scope = zend_fetch_class_by_name(Z_STR_P(obj), NULL, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
2815			if (UNEXPECTED(called_scope == NULL)) {
2816				return NULL;
2817			}
2818
2819			if (called_scope->get_static_method) {
2820				fbc = called_scope->get_static_method(called_scope, Z_STR_P(method));
2821			} else {
2822				fbc = zend_std_get_static_method(called_scope, Z_STR_P(method), NULL);
2823			}
2824			if (UNEXPECTED(fbc == NULL)) {
2825				if (EXPECTED(!EG(exception))) {
2826					zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(called_scope->name), Z_STRVAL_P(method));
2827				}
2828				return NULL;
2829			}
2830			if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
2831				if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
2832					zend_error(E_DEPRECATED,
2833						"Non-static method %s::%s() should not be called statically",
2834						ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
2835					if (UNEXPECTED(EG(exception) != NULL)) {
2836						return NULL;
2837					}
2838				} else {
2839					zend_throw_error(
2840						zend_ce_error,
2841						"Non-static method %s::%s() cannot be called statically",
2842						ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
2843					return NULL;
2844				}
2845			}
2846		} else {
2847			called_scope = Z_OBJCE_P(obj);
2848			object = Z_OBJ_P(obj);
2849
2850			fbc = Z_OBJ_HT_P(obj)->get_method(&object, Z_STR_P(method), NULL);
2851			if (UNEXPECTED(fbc == NULL)) {
2852				if (EXPECTED(!EG(exception))) {
2853					zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(object->ce->name), Z_STRVAL_P(method));
2854				}
2855				return NULL;
2856			}
2857
2858			if ((fbc->common.fn_flags & ZEND_ACC_STATIC) != 0) {
2859				object = NULL;
2860			} else {
2861				call_info |= ZEND_CALL_RELEASE_THIS;
2862				GC_REFCOUNT(object)++; /* For $this pointer */
2863			}
2864		}
2865	} else {
2866		zend_throw_error(NULL, "Function name must be a string");
2867		return NULL;
2868	}
2869
2870	if (EXPECTED(fbc->type == ZEND_USER_FUNCTION) && UNEXPECTED(!fbc->op_array.run_time_cache)) {
2871		init_func_run_time_cache(&fbc->op_array);
2872	}
2873
2874	return zend_vm_stack_push_call_frame(call_info,
2875		fbc, num_args, called_scope, object);
2876}
2877/* }}} */
2878
2879#define ZEND_FAKE_OP_ARRAY ((zend_op_array*)(zend_intptr_t)-1)
2880
2881static zend_never_inline zend_op_array* ZEND_FASTCALL zend_include_or_eval(zval *inc_filename, int type) /* {{{ */
2882{
2883	zend_op_array *new_op_array = NULL;
2884	zval tmp_inc_filename;
2885
2886	ZVAL_UNDEF(&tmp_inc_filename);
2887	if (Z_TYPE_P(inc_filename) != IS_STRING) {
2888		ZVAL_STR(&tmp_inc_filename, zval_get_string(inc_filename));
2889		inc_filename = &tmp_inc_filename;
2890	}
2891
2892	if (type != ZEND_EVAL && strlen(Z_STRVAL_P(inc_filename)) != Z_STRLEN_P(inc_filename)) {
2893		if (type == ZEND_INCLUDE_ONCE || type == ZEND_INCLUDE) {
2894			zend_message_dispatcher(ZMSG_FAILED_INCLUDE_FOPEN, Z_STRVAL_P(inc_filename));
2895		} else {
2896			zend_message_dispatcher(ZMSG_FAILED_REQUIRE_FOPEN, Z_STRVAL_P(inc_filename));
2897		}
2898	} else {
2899		switch (type) {
2900			case ZEND_INCLUDE_ONCE:
2901			case ZEND_REQUIRE_ONCE: {
2902					zend_file_handle file_handle;
2903					zend_string *resolved_path;
2904
2905					resolved_path = zend_resolve_path(Z_STRVAL_P(inc_filename), (int)Z_STRLEN_P(inc_filename));
2906					if (resolved_path) {
2907						if (zend_hash_exists(&EG(included_files), resolved_path)) {
2908							goto already_compiled;
2909						}
2910					} else {
2911						resolved_path = zend_string_copy(Z_STR_P(inc_filename));
2912					}
2913
2914					if (SUCCESS == zend_stream_open(ZSTR_VAL(resolved_path), &file_handle)) {
2915
2916						if (!file_handle.opened_path) {
2917							file_handle.opened_path = zend_string_copy(resolved_path);
2918						}
2919
2920						if (zend_hash_add_empty_element(&EG(included_files), file_handle.opened_path)) {
2921							zend_op_array *op_array = zend_compile_file(&file_handle, (type==ZEND_INCLUDE_ONCE?ZEND_INCLUDE:ZEND_REQUIRE));
2922							zend_destroy_file_handle(&file_handle);
2923							zend_string_release(resolved_path);
2924							if (Z_TYPE(tmp_inc_filename) != IS_UNDEF) {
2925								zend_string_release(Z_STR(tmp_inc_filename));
2926							}
2927							return op_array;
2928						} else {
2929							zend_file_handle_dtor(&file_handle);
2930already_compiled:
2931							new_op_array = ZEND_FAKE_OP_ARRAY;
2932						}
2933					} else {
2934						if (type == ZEND_INCLUDE_ONCE) {
2935							zend_message_dispatcher(ZMSG_FAILED_INCLUDE_FOPEN, Z_STRVAL_P(inc_filename));
2936						} else {
2937							zend_message_dispatcher(ZMSG_FAILED_REQUIRE_FOPEN, Z_STRVAL_P(inc_filename));
2938						}
2939					}
2940					zend_string_release(resolved_path);
2941				}
2942				break;
2943			case ZEND_INCLUDE:
2944			case ZEND_REQUIRE:
2945				new_op_array = compile_filename(type, inc_filename);
2946				break;
2947			case ZEND_EVAL: {
2948					char *eval_desc = zend_make_compiled_string_description("eval()'d code");
2949					new_op_array = zend_compile_string(inc_filename, eval_desc);
2950					efree(eval_desc);
2951				}
2952				break;
2953			EMPTY_SWITCH_DEFAULT_CASE()
2954		}
2955	}
2956	if (Z_TYPE(tmp_inc_filename) != IS_UNDEF) {
2957		zend_string_release(Z_STR(tmp_inc_filename));
2958	}
2959	return new_op_array;
2960}
2961/* }}} */
2962
2963static zend_never_inline int zend_do_fcall_overloaded(zend_function *fbc, zend_execute_data *call, zval *ret) /* {{{ */
2964{
2965	zend_object *object;
2966
2967	/* Not sure what should be done here if it's a static method */
2968	if (UNEXPECTED(Z_TYPE(call->This) != IS_OBJECT)) {
2969		zend_vm_stack_free_args(call);
2970		if (fbc->type == ZEND_OVERLOADED_FUNCTION_TEMPORARY) {
2971			zend_string_release(fbc->common.function_name);
2972		}
2973		efree(fbc);
2974		zend_vm_stack_free_call_frame(call);
2975
2976		zend_throw_error(NULL, "Cannot call overloaded function for non-object");
2977		return 0;
2978	}
2979
2980	object = Z_OBJ(call->This);
2981
2982	ZVAL_NULL(ret);
2983
2984	EG(current_execute_data) = call;
2985	object->handlers->call_method(fbc->common.function_name, object, call, ret);
2986	EG(current_execute_data) = call->prev_execute_data;
2987
2988	zend_vm_stack_free_args(call);
2989
2990	if (fbc->type == ZEND_OVERLOADED_FUNCTION_TEMPORARY) {
2991		zend_string_release(fbc->common.function_name);
2992	}
2993	efree(fbc);
2994
2995	return 1;
2996}
2997/* }}} */
2998
2999#ifdef HAVE_GCC_GLOBAL_REGS
3000# if defined(__GNUC__) && ZEND_GCC_VERSION >= 4008 && defined(i386)
3001#  define ZEND_VM_FP_GLOBAL_REG "%esi"
3002#  define ZEND_VM_IP_GLOBAL_REG "%edi"
3003# elif defined(__GNUC__) && ZEND_GCC_VERSION >= 4008 && defined(__x86_64__)
3004#  define ZEND_VM_FP_GLOBAL_REG "%r14"
3005#  define ZEND_VM_IP_GLOBAL_REG "%r15"
3006# elif defined(__GNUC__) && ZEND_GCC_VERSION >= 4008 && defined(__powerpc64__)
3007#  define ZEND_VM_FP_GLOBAL_REG "r28"
3008#  define ZEND_VM_IP_GLOBAL_REG "r29"
3009# elif defined(__IBMC__) && ZEND_GCC_VERSION >= 4002 && defined(__powerpc64__)
3010#  define ZEND_VM_FP_GLOBAL_REG "r28"
3011#  define ZEND_VM_IP_GLOBAL_REG "r29"
3012# endif
3013#endif
3014
3015#define ZEND_VM_NEXT_OPCODE_EX(check_exception, skip) \
3016	CHECK_SYMBOL_TABLES() \
3017	if (check_exception) { \
3018		OPLINE = EX(opline) + (skip); \
3019	} else { \
3020		OPLINE = opline + (skip); \
3021	} \
3022	ZEND_VM_CONTINUE()
3023
3024#define ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION() \
3025	ZEND_VM_NEXT_OPCODE_EX(1, 1)
3026
3027#define ZEND_VM_NEXT_OPCODE() \
3028	ZEND_VM_NEXT_OPCODE_EX(0, 1)
3029
3030#define ZEND_VM_SET_NEXT_OPCODE(new_op) \
3031	CHECK_SYMBOL_TABLES() \
3032	OPLINE = new_op
3033
3034#define ZEND_VM_SET_OPCODE(new_op) \
3035	CHECK_SYMBOL_TABLES() \
3036	OPLINE = new_op; \
3037	ZEND_VM_INTERRUPT_CHECK()
3038
3039#define ZEND_VM_SET_RELATIVE_OPCODE(opline, offset) \
3040	ZEND_VM_SET_OPCODE(ZEND_OFFSET_TO_OPLINE(opline, offset))
3041
3042#define ZEND_VM_JMP(new_op) \
3043	if (EXPECTED(!EG(exception))) { \
3044		ZEND_VM_SET_OPCODE(new_op); \
3045	} else { \
3046		LOAD_OPLINE(); \
3047	} \
3048	ZEND_VM_CONTINUE()
3049
3050#define ZEND_VM_INC_OPCODE() \
3051	OPLINE++
3052
3053
3054#ifndef VM_SMART_OPCODES
3055# define VM_SMART_OPCODES 1
3056#endif
3057
3058#if VM_SMART_OPCODES
3059# define ZEND_VM_REPEATABLE_OPCODE \
3060	do {
3061# define ZEND_VM_REPEAT_OPCODE(_opcode) \
3062	} while (UNEXPECTED((++opline)->opcode == _opcode)); \
3063	OPLINE = opline; \
3064	ZEND_VM_CONTINUE()
3065# define ZEND_VM_SMART_BRANCH(_result, _check) do { \
3066		int __result; \
3067		if (EXPECTED((opline+1)->opcode == ZEND_JMPZ)) { \
3068			__result = (_result); \
3069		} else if (EXPECTED((opline+1)->opcode == ZEND_JMPNZ)) { \
3070			__result = !(_result); \
3071		} else { \
3072			break; \
3073		} \
3074		if ((_check) && UNEXPECTED(EG(exception))) { \
3075			HANDLE_EXCEPTION(); \
3076		} \
3077		if (__result) { \
3078			ZEND_VM_SET_NEXT_OPCODE(opline + 2); \
3079		} else { \
3080			ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline + 1, (opline+1)->op2)); \
3081		} \
3082		ZEND_VM_CONTINUE(); \
3083	} while (0)
3084# define ZEND_VM_SMART_BRANCH_JMPZ(_result, _check) do { \
3085		if ((_check) && UNEXPECTED(EG(exception))) { \
3086			HANDLE_EXCEPTION(); \
3087		} \
3088		if (_result) { \
3089			ZEND_VM_SET_NEXT_OPCODE(opline + 2); \
3090		} else { \
3091			ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline + 1, (opline+1)->op2)); \
3092		} \
3093		ZEND_VM_CONTINUE(); \
3094	} while (0)
3095# define ZEND_VM_SMART_BRANCH_JMPNZ(_result, _check) do { \
3096		if ((_check) && UNEXPECTED(EG(exception))) { \
3097			HANDLE_EXCEPTION(); \
3098		} \
3099		if (!(_result)) { \
3100			ZEND_VM_SET_NEXT_OPCODE(opline + 2); \
3101		} else { \
3102			ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline + 1, (opline+1)->op2)); \
3103		} \
3104		ZEND_VM_CONTINUE(); \
3105	} while (0)
3106#else
3107# define ZEND_VM_REPEATABLE_OPCODE
3108# define ZEND_VM_REPEAT_OPCODE(_opcode)
3109# define ZEND_VM_SMART_BRANCH(_result, _check)
3110# define ZEND_VM_SMART_BRANCH_JMPZ(_result, _check)
3111# define ZEND_VM_SMART_BRANCH_JMPNZ(_result, _check)
3112#endif
3113
3114#ifdef __GNUC__
3115# define ZEND_VM_GUARD(name) __asm__("#" #name)
3116#else
3117# define ZEND_VM_GUARD(name)
3118#endif
3119
3120#define GET_OP1_UNDEF_CV(ptr, type) \
3121	_get_zval_cv_lookup_ ## type(ptr, opline->op1.var, execute_data)
3122#define GET_OP2_UNDEF_CV(ptr, type) \
3123	_get_zval_cv_lookup_ ## type(ptr, opline->op2.var, execute_data)
3124
3125#include "zend_vm_execute.h"
3126
3127ZEND_API int zend_set_user_opcode_handler(zend_uchar opcode, user_opcode_handler_t handler)
3128{
3129	if (opcode != ZEND_USER_OPCODE) {
3130		if (handler == NULL) {
3131			/* restore the original handler */
3132			zend_user_opcodes[opcode] = opcode;
3133		} else {
3134			zend_user_opcodes[opcode] = ZEND_USER_OPCODE;
3135		}
3136		zend_user_opcode_handlers[opcode] = handler;
3137		return SUCCESS;
3138	}
3139	return FAILURE;
3140}
3141
3142ZEND_API user_opcode_handler_t zend_get_user_opcode_handler(zend_uchar opcode)
3143{
3144	return zend_user_opcode_handlers[opcode];
3145}
3146
3147ZEND_API zval *zend_get_zval_ptr(int op_type, const znode_op *node, const zend_execute_data *execute_data, zend_free_op *should_free, int type)
3148{
3149	return get_zval_ptr(op_type, *node, execute_data, should_free, type);
3150}
3151
3152ZEND_API void ZEND_FASTCALL zend_check_internal_arg_type(zend_function *zf, uint32_t arg_num, zval *arg)
3153{
3154	zend_verify_internal_arg_type(zf, arg_num, arg);
3155}
3156
3157ZEND_API int ZEND_FASTCALL zend_check_arg_type(zend_function *zf, uint32_t arg_num, zval *arg, zval *default_value, void **cache_slot)
3158{
3159	return zend_verify_arg_type(zf, arg_num, arg, default_value, cache_slot);
3160}
3161
3162ZEND_API void ZEND_FASTCALL zend_check_missing_arg(zend_execute_data *execute_data, uint32_t arg_num, void **cache_slot)
3163{
3164	zend_verify_missing_arg(execute_data, arg_num, cache_slot);
3165}
3166
3167/*
3168 * Local variables:
3169 * tab-width: 4
3170 * c-basic-offset: 4
3171 * indent-tabs-mode: t
3172 * End:
3173 */
3174