1/*
2   +----------------------------------------------------------------------+
3   | Zend Engine                                                          |
4   +----------------------------------------------------------------------+
5   | Copyright (c) 1998-2014 Zend Technologies Ltd. (http://www.zend.com) |
6   +----------------------------------------------------------------------+
7   | This source file is subject to version 2.00 of the Zend license,     |
8   | that is bundled with this package in the file LICENSE, and is        |
9   | available through the world-wide-web at the following url:           |
10   | http://www.zend.com/license/2_00.txt.                                |
11   | If you did not receive a copy of the Zend license and are unable to  |
12   | obtain it through the world-wide-web, please send a note to          |
13   | license@zend.com so we can mail you a copy immediately.              |
14   +----------------------------------------------------------------------+
15   | Authors: Andi Gutmans <andi@zend.com>                                |
16   |          Zeev Suraski <zeev@zend.com>                                |
17   |          Dmitry Stogov <dmitry@zend.com>                             |
18   +----------------------------------------------------------------------+
19*/
20
21/* $Id$ */
22
23/* If you change this file, please regenerate the zend_vm_execute.h and
24 * zend_vm_opcodes.h files by running:
25 * php zend_vm_gen.php
26 */
27
28ZEND_VM_HANDLER(1, ZEND_ADD, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
29{
30    USE_OPLINE
31    zend_free_op free_op1, free_op2;
32
33    SAVE_OPLINE();
34    fast_add_function(EX_VAR(opline->result.var),
35        GET_OP1_ZVAL_PTR(BP_VAR_R),
36        GET_OP2_ZVAL_PTR(BP_VAR_R) TSRMLS_CC);
37    FREE_OP1();
38    FREE_OP2();
39    CHECK_EXCEPTION();
40    ZEND_VM_NEXT_OPCODE();
41}
42
43ZEND_VM_HANDLER(2, ZEND_SUB, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
44{
45    USE_OPLINE
46    zend_free_op free_op1, free_op2;
47
48    SAVE_OPLINE();
49    fast_sub_function(EX_VAR(opline->result.var),
50        GET_OP1_ZVAL_PTR(BP_VAR_R),
51        GET_OP2_ZVAL_PTR(BP_VAR_R) TSRMLS_CC);
52    FREE_OP1();
53    FREE_OP2();
54    CHECK_EXCEPTION();
55    ZEND_VM_NEXT_OPCODE();
56}
57
58ZEND_VM_HANDLER(3, ZEND_MUL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
59{
60    USE_OPLINE
61    zend_free_op free_op1, free_op2;
62
63    SAVE_OPLINE();
64    fast_mul_function(EX_VAR(opline->result.var),
65        GET_OP1_ZVAL_PTR(BP_VAR_R),
66        GET_OP2_ZVAL_PTR(BP_VAR_R) TSRMLS_CC);
67    FREE_OP1();
68    FREE_OP2();
69    CHECK_EXCEPTION();
70    ZEND_VM_NEXT_OPCODE();
71}
72
73ZEND_VM_HANDLER(4, ZEND_DIV, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
74{
75    USE_OPLINE
76    zend_free_op free_op1, free_op2;
77
78    SAVE_OPLINE();
79    fast_div_function(EX_VAR(opline->result.var),
80        GET_OP1_ZVAL_PTR(BP_VAR_R),
81        GET_OP2_ZVAL_PTR(BP_VAR_R) TSRMLS_CC);
82    FREE_OP1();
83    FREE_OP2();
84    CHECK_EXCEPTION();
85    ZEND_VM_NEXT_OPCODE();
86}
87
88ZEND_VM_HANDLER(5, ZEND_MOD, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
89{
90    USE_OPLINE
91    zend_free_op free_op1, free_op2;
92
93    SAVE_OPLINE();
94    fast_mod_function(EX_VAR(opline->result.var),
95        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
96        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
97    FREE_OP1();
98    FREE_OP2();
99    CHECK_EXCEPTION();
100    ZEND_VM_NEXT_OPCODE();
101}
102
103ZEND_VM_HANDLER(6, ZEND_SL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
104{
105    USE_OPLINE
106    zend_free_op free_op1, free_op2;
107
108    SAVE_OPLINE();
109    shift_left_function(EX_VAR(opline->result.var),
110        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
111        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
112    FREE_OP1();
113    FREE_OP2();
114    CHECK_EXCEPTION();
115    ZEND_VM_NEXT_OPCODE();
116}
117
118ZEND_VM_HANDLER(7, ZEND_SR, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
119{
120    USE_OPLINE
121    zend_free_op free_op1, free_op2;
122
123    SAVE_OPLINE();
124    shift_right_function(EX_VAR(opline->result.var),
125        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
126        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
127    FREE_OP1();
128    FREE_OP2();
129    CHECK_EXCEPTION();
130    ZEND_VM_NEXT_OPCODE();
131}
132
133ZEND_VM_HANDLER(8, ZEND_CONCAT, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
134{
135    USE_OPLINE
136    zend_free_op free_op1, free_op2;
137
138    SAVE_OPLINE();
139    concat_function(EX_VAR(opline->result.var),
140        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
141        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
142    FREE_OP1();
143    FREE_OP2();
144    CHECK_EXCEPTION();
145    ZEND_VM_NEXT_OPCODE();
146}
147
148ZEND_VM_HANDLER(15, ZEND_IS_IDENTICAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
149{
150    USE_OPLINE
151    zend_free_op free_op1, free_op2;
152
153    SAVE_OPLINE();
154    fast_is_identical_function(EX_VAR(opline->result.var),
155        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
156        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
157    FREE_OP1();
158    FREE_OP2();
159    CHECK_EXCEPTION();
160    ZEND_VM_NEXT_OPCODE();
161}
162
163ZEND_VM_HANDLER(16, ZEND_IS_NOT_IDENTICAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
164{
165    USE_OPLINE
166    zend_free_op free_op1, free_op2;
167    zval *result = EX_VAR(opline->result.var);
168
169    SAVE_OPLINE();
170    fast_is_not_identical_function(result,
171        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
172        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
173    FREE_OP1();
174    FREE_OP2();
175    CHECK_EXCEPTION();
176    ZEND_VM_NEXT_OPCODE();
177}
178
179ZEND_VM_HANDLER(17, ZEND_IS_EQUAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
180{
181    USE_OPLINE
182    zend_free_op free_op1, free_op2;
183    zval *result = EX_VAR(opline->result.var);
184
185    SAVE_OPLINE();
186    fast_equal_function(result,
187        GET_OP1_ZVAL_PTR(BP_VAR_R),
188        GET_OP2_ZVAL_PTR(BP_VAR_R) TSRMLS_CC);
189    FREE_OP1();
190    FREE_OP2();
191    CHECK_EXCEPTION();
192    ZEND_VM_NEXT_OPCODE();
193}
194
195ZEND_VM_HANDLER(18, ZEND_IS_NOT_EQUAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
196{
197    USE_OPLINE
198    zend_free_op free_op1, free_op2;
199    zval *result = EX_VAR(opline->result.var);
200
201    SAVE_OPLINE();
202    fast_not_equal_function(result,
203        GET_OP1_ZVAL_PTR(BP_VAR_R),
204        GET_OP2_ZVAL_PTR(BP_VAR_R) TSRMLS_CC);
205    FREE_OP1();
206    FREE_OP2();
207    CHECK_EXCEPTION();
208    ZEND_VM_NEXT_OPCODE();
209}
210
211ZEND_VM_HANDLER(19, ZEND_IS_SMALLER, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
212{
213    USE_OPLINE
214    zend_free_op free_op1, free_op2;
215    zval *result = EX_VAR(opline->result.var);
216
217    SAVE_OPLINE();
218    fast_is_smaller_function(result,
219        GET_OP1_ZVAL_PTR(BP_VAR_R),
220        GET_OP2_ZVAL_PTR(BP_VAR_R) TSRMLS_CC);
221    FREE_OP1();
222    FREE_OP2();
223    CHECK_EXCEPTION();
224    ZEND_VM_NEXT_OPCODE();
225}
226
227ZEND_VM_HANDLER(20, ZEND_IS_SMALLER_OR_EQUAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
228{
229    USE_OPLINE
230    zend_free_op free_op1, free_op2;
231    zval *result = EX_VAR(opline->result.var);
232
233    SAVE_OPLINE();
234    fast_is_smaller_or_equal_function(result,
235        GET_OP1_ZVAL_PTR(BP_VAR_R),
236        GET_OP2_ZVAL_PTR(BP_VAR_R) TSRMLS_CC);
237    FREE_OP1();
238    FREE_OP2();
239    CHECK_EXCEPTION();
240    ZEND_VM_NEXT_OPCODE();
241}
242
243ZEND_VM_HANDLER(9, ZEND_BW_OR, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
244{
245    USE_OPLINE
246    zend_free_op free_op1, free_op2;
247
248    SAVE_OPLINE();
249    bitwise_or_function(EX_VAR(opline->result.var),
250        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
251        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
252    FREE_OP1();
253    FREE_OP2();
254    CHECK_EXCEPTION();
255    ZEND_VM_NEXT_OPCODE();
256}
257
258ZEND_VM_HANDLER(10, ZEND_BW_AND, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
259{
260    USE_OPLINE
261    zend_free_op free_op1, free_op2;
262
263    SAVE_OPLINE();
264    bitwise_and_function(EX_VAR(opline->result.var),
265        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
266        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
267    FREE_OP1();
268    FREE_OP2();
269    CHECK_EXCEPTION();
270    ZEND_VM_NEXT_OPCODE();
271}
272
273ZEND_VM_HANDLER(11, ZEND_BW_XOR, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
274{
275    USE_OPLINE
276    zend_free_op free_op1, free_op2;
277
278    SAVE_OPLINE();
279    bitwise_xor_function(EX_VAR(opline->result.var),
280        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
281        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
282    FREE_OP1();
283    FREE_OP2();
284    CHECK_EXCEPTION();
285    ZEND_VM_NEXT_OPCODE();
286}
287
288ZEND_VM_HANDLER(14, ZEND_BOOL_XOR, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
289{
290    USE_OPLINE
291    zend_free_op free_op1, free_op2;
292
293    SAVE_OPLINE();
294    boolean_xor_function(EX_VAR(opline->result.var),
295        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
296        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
297    FREE_OP1();
298    FREE_OP2();
299    CHECK_EXCEPTION();
300    ZEND_VM_NEXT_OPCODE();
301}
302
303ZEND_VM_HANDLER(12, ZEND_BW_NOT, CONST|TMP|VAR|CV, ANY)
304{
305    USE_OPLINE
306    zend_free_op free_op1;
307
308    SAVE_OPLINE();
309    bitwise_not_function(EX_VAR(opline->result.var),
310        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
311    FREE_OP1();
312    CHECK_EXCEPTION();
313    ZEND_VM_NEXT_OPCODE();
314}
315
316ZEND_VM_HANDLER(13, ZEND_BOOL_NOT, CONST|TMP|VAR|CV, ANY)
317{
318    USE_OPLINE
319    zend_free_op free_op1;
320
321    SAVE_OPLINE();
322    boolean_not_function(EX_VAR(opline->result.var),
323        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
324    FREE_OP1();
325    CHECK_EXCEPTION();
326    ZEND_VM_NEXT_OPCODE();
327}
328
329ZEND_VM_HELPER_EX(zend_binary_assign_op_obj_helper, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV, int (*binary_op)(zval *result, zval *op1, zval *op2 TSRMLS_DC))
330{
331    USE_OPLINE
332    zend_free_op free_op1, free_op2, free_op_data1;
333    zval *object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
334    zval *property = GET_OP2_ZVAL_PTR(BP_VAR_R);
335    zval *value;
336    int have_get_ptr = 0;
337
338    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
339        zend_error_noreturn(E_ERROR, "Cannot use string offset as an object");
340    }
341
342    object = make_real_object(object TSRMLS_CC);
343
344    value = get_zval_ptr((opline+1)->op1_type, &(opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
345
346    if (UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
347        zend_error(E_WARNING, "Attempt to assign property of non-object");
348        FREE_OP2();
349        FREE_OP(free_op_data1);
350
351        if (RETURN_VALUE_USED(opline)) {
352            ZVAL_NULL(EX_VAR(opline->result.var));
353        }
354    } else {
355        /* here we are sure we are dealing with an object */
356        if (opline->extended_value == ZEND_ASSIGN_OBJ
357            && Z_OBJ_HT_P(object)->get_property_ptr_ptr) {
358            zval *zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL) TSRMLS_CC);
359            if (zptr != NULL) {             /* NULL means no success in getting PTR */
360                SEPARATE_ZVAL_IF_NOT_REF(zptr);
361
362                have_get_ptr = 1;
363                binary_op(zptr, zptr, value TSRMLS_CC);
364                if (RETURN_VALUE_USED(opline)) {
365                    ZVAL_COPY(EX_VAR(opline->result.var), zptr);
366                }
367            }
368        }
369
370        if (!have_get_ptr) {
371            zval *z = NULL;
372            zval rv;
373
374            if (opline->extended_value == ZEND_ASSIGN_OBJ) {
375                if (Z_OBJ_HT_P(object)->read_property) {
376                    z = Z_OBJ_HT_P(object)->read_property(object, property, BP_VAR_R, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL), &rv TSRMLS_CC);
377                }
378            } else /* if (opline->extended_value == ZEND_ASSIGN_DIM) */ {
379                if (Z_OBJ_HT_P(object)->read_dimension) {
380                    z = Z_OBJ_HT_P(object)->read_dimension(object, property, BP_VAR_R, &rv TSRMLS_CC);
381                }
382            }
383            if (z) {
384                if (Z_TYPE_P(z) == IS_OBJECT && Z_OBJ_HT_P(z)->get) {
385                    zval rv;
386                    zval *value = Z_OBJ_HT_P(z)->get(z, &rv TSRMLS_CC);
387
388                    if (Z_REFCOUNT_P(z) == 0) {
389                        zval_dtor(z);
390                    }
391                    ZVAL_COPY_VALUE(z, value);
392                }
393//???               if (Z_REFCOUNTED_P(z)) Z_ADDREF_P(z);
394                SEPARATE_ZVAL_IF_NOT_REF(z);
395                binary_op(z, z, value TSRMLS_CC);
396                if (opline->extended_value == ZEND_ASSIGN_OBJ) {
397                    Z_OBJ_HT_P(object)->write_property(object, property, z, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL) TSRMLS_CC);
398                } else /* if (opline->extended_value == ZEND_ASSIGN_DIM) */ {
399                    Z_OBJ_HT_P(object)->write_dimension(object, property, z TSRMLS_CC);
400                }
401                if (RETURN_VALUE_USED(opline)) {
402                    ZVAL_COPY(EX_VAR(opline->result.var), z);
403                }
404                zval_ptr_dtor(z);
405            } else {
406                zend_error(E_WARNING, "Attempt to assign property of non-object");
407                if (RETURN_VALUE_USED(opline)) {
408                    ZVAL_NULL(EX_VAR(opline->result.var));
409                }
410            }
411        }
412
413        FREE_OP2();
414        FREE_OP(free_op_data1);
415    }
416
417    FREE_OP1_VAR_PTR();
418    /* assign_obj has two opcodes! */
419    CHECK_EXCEPTION();
420    ZEND_VM_INC_OPCODE();
421    ZEND_VM_NEXT_OPCODE();
422}
423
424ZEND_VM_HELPER_EX(zend_binary_assign_op_dim_helper, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV, int (*binary_op)(zval *result, zval *op1, zval *op2 TSRMLS_DC))
425{
426    USE_OPLINE
427    zend_free_op free_op1, free_op2, free_op_data2, free_op_data1;
428    zval *var_ptr;
429    zval *value, *container;
430
431    SAVE_OPLINE();
432    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
433    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
434        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
435    } else if (UNEXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
436        if (OP1_TYPE == IS_VAR && !OP1_FREE) {
437            Z_ADDREF_P(container);  /* undo the effect of get_obj_zval_ptr_ptr() */
438        }
439        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, binary_op);
440    } else {
441        zval *dim = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
442
443        zend_fetch_dimension_address_RW(EX_VAR((opline+1)->op2.var), container, dim, OP2_TYPE TSRMLS_CC);
444        value = get_zval_ptr((opline+1)->op1_type, &(opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
445        var_ptr = _get_zval_ptr_ptr_var((opline+1)->op2.var, execute_data, &free_op_data2 TSRMLS_CC);
446    }
447
448    if (UNEXPECTED(var_ptr == NULL)) {
449        zend_error_noreturn(E_ERROR, "Cannot use assign-op operators with overloaded objects nor string offsets");
450    }
451
452    if (UNEXPECTED(var_ptr == &EG(error_zval))) {
453        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
454            ZVAL_NULL(EX_VAR(opline->result.var));
455        }
456        ZEND_VM_C_GOTO(assign_op_dim_exit);
457    }
458
459    ZVAL_DEREF(var_ptr);
460    SEPARATE_ZVAL_NOREF(var_ptr);
461
462    if (UNEXPECTED(Z_TYPE_P(var_ptr) == IS_OBJECT) &&
463        UNEXPECTED(Z_OBJ_HANDLER_P(var_ptr, get) && Z_OBJ_HANDLER_P(var_ptr, set))) {
464        /* proxy object */
465        zval rv;
466        zval *objval = Z_OBJ_HANDLER_P(var_ptr, get)(var_ptr, &rv TSRMLS_CC);
467        Z_ADDREF_P(objval);
468        binary_op(objval, objval, value TSRMLS_CC);
469        Z_OBJ_HANDLER_P(var_ptr, set)(var_ptr, objval TSRMLS_CC);
470        zval_ptr_dtor(objval);
471    } else {
472        binary_op(var_ptr, var_ptr, value TSRMLS_CC);
473    }
474
475    if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
476        ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
477    }
478
479ZEND_VM_C_LABEL(assign_op_dim_exit):
480    FREE_OP2();
481    FREE_OP(free_op_data1);
482    FREE_OP_VAR_PTR(free_op_data2);
483    FREE_OP1_VAR_PTR();
484    CHECK_EXCEPTION();
485    ZEND_VM_INC_OPCODE();
486    ZEND_VM_NEXT_OPCODE();
487}
488
489ZEND_VM_HELPER_EX(zend_binary_assign_op_helper, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV, int (*binary_op)(zval *result, zval *op1, zval *op2 TSRMLS_DC))
490{
491    USE_OPLINE
492    zend_free_op free_op1, free_op2;
493    zval *var_ptr;
494    zval *value;
495
496    SAVE_OPLINE();
497    value = GET_OP2_ZVAL_PTR(BP_VAR_R);
498    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
499
500    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
501        zend_error_noreturn(E_ERROR, "Cannot use assign-op operators with overloaded objects nor string offsets");
502    }
503
504    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
505        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
506            ZVAL_NULL(EX_VAR(opline->result.var));
507        }
508        ZEND_VM_C_GOTO(assign_op_exit);
509    }
510
511    ZVAL_DEREF(var_ptr);
512    SEPARATE_ZVAL_NOREF(var_ptr);
513
514    if (UNEXPECTED(Z_TYPE_P(var_ptr) == IS_OBJECT) &&
515        UNEXPECTED(Z_OBJ_HANDLER_P(var_ptr, get) && Z_OBJ_HANDLER_P(var_ptr, set))) {
516        /* proxy object */
517        zval rv;
518        zval *objval = Z_OBJ_HANDLER_P(var_ptr, get)(var_ptr, &rv TSRMLS_CC);
519        Z_ADDREF_P(objval);
520        binary_op(objval, objval, value TSRMLS_CC);
521        Z_OBJ_HANDLER_P(var_ptr, set)(var_ptr, objval TSRMLS_CC);
522        zval_ptr_dtor(objval);
523    } else {
524        binary_op(var_ptr, var_ptr, value TSRMLS_CC);
525    }
526
527    if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
528        ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
529    }
530
531ZEND_VM_C_LABEL(assign_op_exit):
532    FREE_OP2();
533    FREE_OP1_VAR_PTR();
534    CHECK_EXCEPTION();
535    ZEND_VM_NEXT_OPCODE();
536}
537
538ZEND_VM_HANDLER(23, ZEND_ASSIGN_ADD, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
539{
540    USE_OPLINE
541
542    if (EXPECTED(opline->extended_value == 0)) {
543        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, add_function);
544    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
545        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, add_function);
546    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
547        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, add_function);
548    }
549}
550
551ZEND_VM_HANDLER(24, ZEND_ASSIGN_SUB, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
552{
553    USE_OPLINE
554
555    if (EXPECTED(opline->extended_value == 0)) {
556        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, sub_function);
557    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
558        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, sub_function);
559    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
560        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, sub_function);
561    }
562}
563
564ZEND_VM_HANDLER(25, ZEND_ASSIGN_MUL, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
565{
566    USE_OPLINE
567
568    if (EXPECTED(opline->extended_value == 0)) {
569        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, mul_function);
570    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
571        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, mul_function);
572    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
573        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, mul_function);
574    }
575}
576
577ZEND_VM_HANDLER(26, ZEND_ASSIGN_DIV, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
578{
579    USE_OPLINE
580
581    if (EXPECTED(opline->extended_value == 0)) {
582        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, div_function);
583    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
584        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, div_function);
585    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
586        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, div_function);
587    }
588}
589
590ZEND_VM_HANDLER(27, ZEND_ASSIGN_MOD, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
591{
592    USE_OPLINE
593
594    if (EXPECTED(opline->extended_value == 0)) {
595        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, mod_function);
596    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
597        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, mod_function);
598    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
599        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, mod_function);
600    }
601}
602
603ZEND_VM_HANDLER(28, ZEND_ASSIGN_SL, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
604{
605    USE_OPLINE
606
607    if (EXPECTED(opline->extended_value == 0)) {
608        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, shift_left_function);
609    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
610        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, shift_left_function);
611    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
612        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, shift_left_function);
613    }
614}
615
616ZEND_VM_HANDLER(29, ZEND_ASSIGN_SR, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
617{
618    USE_OPLINE
619
620    if (EXPECTED(opline->extended_value == 0)) {
621        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, shift_right_function);
622    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
623        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, shift_right_function);
624    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
625        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, shift_right_function);
626    }
627}
628
629ZEND_VM_HANDLER(30, ZEND_ASSIGN_CONCAT, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
630{
631    USE_OPLINE
632
633    if (EXPECTED(opline->extended_value == 0)) {
634        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, concat_function);
635    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
636        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, concat_function);
637    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
638        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, concat_function);
639    }
640}
641
642ZEND_VM_HANDLER(31, ZEND_ASSIGN_BW_OR, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
643{
644    USE_OPLINE
645
646    if (EXPECTED(opline->extended_value == 0)) {
647        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, bitwise_or_function);
648    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
649        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_or_function);
650    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
651        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, bitwise_or_function);
652    }
653}
654
655ZEND_VM_HANDLER(32, ZEND_ASSIGN_BW_AND, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
656{
657    USE_OPLINE
658
659    if (EXPECTED(opline->extended_value == 0)) {
660        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, bitwise_and_function);
661    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
662        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_and_function);
663    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
664        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, bitwise_and_function);
665    }
666}
667
668ZEND_VM_HANDLER(33, ZEND_ASSIGN_BW_XOR, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
669{
670    USE_OPLINE
671
672    if (EXPECTED(opline->extended_value == 0)) {
673        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, bitwise_xor_function);
674    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
675        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_xor_function);
676    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
677        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, bitwise_xor_function);
678    }
679}
680
681ZEND_VM_HELPER_EX(zend_pre_incdec_property_helper, VAR|UNUSED|CV, CONST|TMP|VAR|CV, incdec_t incdec_op)
682{
683    USE_OPLINE
684    zend_free_op free_op1, free_op2;
685    zval *object;
686    zval *property;
687    zval *retval;
688    int have_get_ptr = 0;
689
690    SAVE_OPLINE();
691    object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
692    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
693    retval = EX_VAR(opline->result.var);
694
695    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
696        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
697    }
698
699    object = make_real_object(object TSRMLS_CC); /* this should modify object only if it's empty */
700
701    if (UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
702        zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
703        FREE_OP2();
704        if (RETURN_VALUE_USED(opline)) {
705            ZVAL_NULL(retval);
706        }
707        FREE_OP1_VAR_PTR();
708        CHECK_EXCEPTION();
709        ZEND_VM_NEXT_OPCODE();
710    }
711
712    /* here we are sure we are dealing with an object */
713
714    if (Z_OBJ_HT_P(object)->get_property_ptr_ptr) {
715        zval *zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL) TSRMLS_CC);
716        if (zptr != NULL) {             /* NULL means no success in getting PTR */
717            SEPARATE_ZVAL_IF_NOT_REF(zptr);
718
719            have_get_ptr = 1;
720            incdec_op(zptr);
721            if (RETURN_VALUE_USED(opline)) {
722                ZVAL_COPY(retval, zptr);
723            }
724        }
725    }
726
727    if (!have_get_ptr) {
728        zval rv;
729
730        if (Z_OBJ_HT_P(object)->read_property && Z_OBJ_HT_P(object)->write_property) {
731            zval *z = Z_OBJ_HT_P(object)->read_property(object, property, BP_VAR_R, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL), &rv TSRMLS_CC);
732
733            if (UNEXPECTED(Z_TYPE_P(z) == IS_OBJECT) && Z_OBJ_HT_P(z)->get) {
734                zval rv;
735                zval *value = Z_OBJ_HT_P(z)->get(z, &rv TSRMLS_CC);
736
737                if (Z_REFCOUNT_P(z) == 0) {
738                    zval_dtor(z);
739                }
740                ZVAL_COPY_VALUE(z, value);
741            }
742            if (Z_REFCOUNTED_P(z)) Z_ADDREF_P(z);
743            SEPARATE_ZVAL_IF_NOT_REF(z);
744            incdec_op(z);
745            ZVAL_COPY_VALUE(retval, z);
746            Z_OBJ_HT_P(object)->write_property(object, property, z, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL) TSRMLS_CC);
747            SELECTIVE_PZVAL_LOCK(retval, opline);
748            zval_ptr_dtor(z);
749        } else {
750            zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
751            if (RETURN_VALUE_USED(opline)) {
752                ZVAL_NULL(retval);
753            }
754        }
755    }
756
757    FREE_OP2();
758    FREE_OP1_VAR_PTR();
759    CHECK_EXCEPTION();
760    ZEND_VM_NEXT_OPCODE();
761}
762
763ZEND_VM_HANDLER(132, ZEND_PRE_INC_OBJ, VAR|UNUSED|CV, CONST|TMP|VAR|CV)
764{
765    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_pre_incdec_property_helper, incdec_op, increment_function);
766}
767
768ZEND_VM_HANDLER(133, ZEND_PRE_DEC_OBJ, VAR|UNUSED|CV, CONST|TMP|VAR|CV)
769{
770    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_pre_incdec_property_helper, incdec_op, decrement_function);
771}
772
773ZEND_VM_HELPER_EX(zend_post_incdec_property_helper, VAR|UNUSED|CV, CONST|TMP|VAR|CV, incdec_t incdec_op)
774{
775    USE_OPLINE
776    zend_free_op free_op1, free_op2;
777    zval *object;
778    zval *property;
779    zval *retval;
780    int have_get_ptr = 0;
781
782    SAVE_OPLINE();
783    object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
784    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
785    retval = EX_VAR(opline->result.var);
786
787    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
788        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
789    }
790
791    object = make_real_object(object TSRMLS_CC); /* this should modify object only if it's empty */
792
793    if (UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
794        zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
795        FREE_OP2();
796        ZVAL_NULL(retval);
797        FREE_OP1_VAR_PTR();
798        CHECK_EXCEPTION();
799        ZEND_VM_NEXT_OPCODE();
800    }
801
802    /* here we are sure we are dealing with an object */
803
804    if (Z_OBJ_HT_P(object)->get_property_ptr_ptr) {
805        zval *zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL) TSRMLS_CC);
806        if (zptr != NULL) {             /* NULL means no success in getting PTR */
807            have_get_ptr = 1;
808            SEPARATE_ZVAL_IF_NOT_REF(zptr);
809
810            ZVAL_DUP(retval, zptr);
811
812            incdec_op(zptr);
813
814        }
815    }
816
817    if (!have_get_ptr) {
818        if (Z_OBJ_HT_P(object)->read_property && Z_OBJ_HT_P(object)->write_property) {
819            zval rv;
820            zval *z = Z_OBJ_HT_P(object)->read_property(object, property, BP_VAR_R, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL), &rv TSRMLS_CC);
821            zval z_copy;
822
823            if (UNEXPECTED(Z_TYPE_P(z) == IS_OBJECT) && Z_OBJ_HT_P(z)->get) {
824                zval rv;
825                zval *value = Z_OBJ_HT_P(z)->get(z, &rv TSRMLS_CC);
826
827                if (Z_REFCOUNT_P(z) == 0) {
828                    zval_dtor(z);
829                }
830                ZVAL_COPY_VALUE(z, value);
831            }
832            ZVAL_DUP(retval, z);
833            ZVAL_DUP(&z_copy, z);
834            incdec_op(&z_copy);
835            if (Z_REFCOUNTED_P(z)) Z_ADDREF_P(z);
836            Z_OBJ_HT_P(object)->write_property(object, property, &z_copy, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL) TSRMLS_CC);
837            zval_ptr_dtor(&z_copy);
838            zval_ptr_dtor(z);
839        } else {
840            zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
841            ZVAL_NULL(retval);
842        }
843    }
844
845    FREE_OP2();
846    FREE_OP1_VAR_PTR();
847    CHECK_EXCEPTION();
848    ZEND_VM_NEXT_OPCODE();
849}
850
851ZEND_VM_HANDLER(134, ZEND_POST_INC_OBJ, VAR|UNUSED|CV, CONST|TMP|VAR|CV)
852{
853    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_post_incdec_property_helper, incdec_op, increment_function);
854}
855
856ZEND_VM_HANDLER(135, ZEND_POST_DEC_OBJ, VAR|UNUSED|CV, CONST|TMP|VAR|CV)
857{
858    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_post_incdec_property_helper, incdec_op, decrement_function);
859}
860
861ZEND_VM_HANDLER(34, ZEND_PRE_INC, VAR|CV, ANY)
862{
863    USE_OPLINE
864    zend_free_op free_op1;
865    zval *var_ptr;
866
867    SAVE_OPLINE();
868    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
869
870    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
871        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
872    }
873
874    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
875        fast_increment_function(var_ptr);
876        if (RETURN_VALUE_USED(opline)) {
877            ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
878        }
879        ZEND_VM_NEXT_OPCODE();
880    }
881
882    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
883        if (RETURN_VALUE_USED(opline)) {
884            ZVAL_NULL(EX_VAR(opline->result.var));
885        }
886        FREE_OP1_VAR_PTR();
887        CHECK_EXCEPTION();
888        ZEND_VM_NEXT_OPCODE();
889    }
890
891    ZVAL_DEREF(var_ptr);
892    SEPARATE_ZVAL_NOREF(var_ptr);
893
894    if (UNEXPECTED(Z_TYPE_P(var_ptr) == IS_OBJECT)
895       && Z_OBJ_HANDLER_P(var_ptr, get)
896       && Z_OBJ_HANDLER_P(var_ptr, set)) {
897        /* proxy object */
898        zval rv;
899        zval *val = Z_OBJ_HANDLER_P(var_ptr, get)(var_ptr, &rv TSRMLS_CC);
900        Z_ADDREF_P(val);
901        fast_increment_function(val);
902        Z_OBJ_HANDLER_P(var_ptr, set)(var_ptr, val TSRMLS_CC);
903        zval_ptr_dtor(val);
904    } else {
905        increment_function(var_ptr);
906    }
907
908    if (RETURN_VALUE_USED(opline)) {
909        ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
910    }
911
912    FREE_OP1_VAR_PTR();
913    CHECK_EXCEPTION();
914    ZEND_VM_NEXT_OPCODE();
915}
916
917ZEND_VM_HANDLER(35, ZEND_PRE_DEC, VAR|CV, ANY)
918{
919    USE_OPLINE
920    zend_free_op free_op1;
921    zval *var_ptr;
922
923    SAVE_OPLINE();
924    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
925
926    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
927        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
928    }
929
930    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
931        fast_decrement_function(var_ptr);
932        if (RETURN_VALUE_USED(opline)) {
933            ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
934        }
935        ZEND_VM_NEXT_OPCODE();
936    }
937
938    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
939        if (RETURN_VALUE_USED(opline)) {
940            ZVAL_NULL(EX_VAR(opline->result.var));
941        }
942        FREE_OP1_VAR_PTR();
943        CHECK_EXCEPTION();
944        ZEND_VM_NEXT_OPCODE();
945    }
946
947    ZVAL_DEREF(var_ptr);
948    SEPARATE_ZVAL_NOREF(var_ptr);
949
950    if (UNEXPECTED(Z_TYPE_P(var_ptr) == IS_OBJECT)
951       && Z_OBJ_HANDLER_P(var_ptr, get)
952       && Z_OBJ_HANDLER_P(var_ptr, set)) {
953        /* proxy object */
954        zval rv;
955        zval *val = Z_OBJ_HANDLER_P(var_ptr, get)(var_ptr, &rv TSRMLS_CC);
956        Z_ADDREF_P(val);
957        fast_decrement_function(val);
958        Z_OBJ_HANDLER_P(var_ptr, set)(var_ptr, val TSRMLS_CC);
959        zval_ptr_dtor(val);
960    } else {
961        decrement_function(var_ptr);
962    }
963
964    if (RETURN_VALUE_USED(opline)) {
965        ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
966    }
967
968    FREE_OP1_VAR_PTR();
969    CHECK_EXCEPTION();
970    ZEND_VM_NEXT_OPCODE();
971}
972
973ZEND_VM_HANDLER(36, ZEND_POST_INC, VAR|CV, ANY)
974{
975    USE_OPLINE
976    zend_free_op free_op1;
977    zval *var_ptr, *retval;
978
979    SAVE_OPLINE();
980    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
981
982    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
983        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
984    }
985
986    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
987        ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
988        fast_increment_function(var_ptr);
989        ZEND_VM_NEXT_OPCODE();
990    }
991
992    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
993        ZVAL_NULL(EX_VAR(opline->result.var));
994        FREE_OP1_VAR_PTR();
995        CHECK_EXCEPTION();
996        ZEND_VM_NEXT_OPCODE();
997    }
998
999    retval = EX_VAR(opline->result.var);
1000
1001    if (UNEXPECTED(Z_ISREF_P(var_ptr))) {
1002        var_ptr = Z_REFVAL_P(var_ptr);
1003        ZVAL_DUP(retval, var_ptr);
1004    } else {
1005        ZVAL_DUP(retval, var_ptr);
1006        SEPARATE_ZVAL_NOREF(var_ptr);
1007    }
1008
1009    if (UNEXPECTED(Z_TYPE_P(var_ptr) == IS_OBJECT)
1010       && Z_OBJ_HANDLER_P(var_ptr, get)
1011       && Z_OBJ_HANDLER_P(var_ptr, set)) {
1012        /* proxy object */
1013        zval rv;
1014        zval *val = Z_OBJ_HANDLER_P(var_ptr, get)(var_ptr, &rv TSRMLS_CC);
1015        Z_ADDREF_P(val);
1016        fast_increment_function(val);
1017        Z_OBJ_HANDLER_P(var_ptr, set)(var_ptr, val TSRMLS_CC);
1018        zval_ptr_dtor(val);
1019    } else {
1020        increment_function(var_ptr);
1021    }
1022
1023    FREE_OP1_VAR_PTR();
1024    CHECK_EXCEPTION();
1025    ZEND_VM_NEXT_OPCODE();
1026}
1027
1028ZEND_VM_HANDLER(37, ZEND_POST_DEC, VAR|CV, ANY)
1029{
1030    USE_OPLINE
1031    zend_free_op free_op1;
1032    zval *var_ptr, *retval;
1033
1034    SAVE_OPLINE();
1035    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
1036
1037    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
1038        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
1039    }
1040
1041    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1042        ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1043        fast_decrement_function(var_ptr);
1044        ZEND_VM_NEXT_OPCODE();
1045    }
1046
1047    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
1048        ZVAL_NULL(EX_VAR(opline->result.var));
1049        FREE_OP1_VAR_PTR();
1050        CHECK_EXCEPTION();
1051        ZEND_VM_NEXT_OPCODE();
1052    }
1053
1054    retval = EX_VAR(opline->result.var);
1055
1056    if (UNEXPECTED(Z_ISREF_P(var_ptr))) {
1057        var_ptr = Z_REFVAL_P(var_ptr);
1058        ZVAL_DUP(retval, var_ptr);
1059    } else {
1060        ZVAL_DUP(retval, var_ptr);
1061        SEPARATE_ZVAL_NOREF(var_ptr);
1062    }
1063
1064    if (UNEXPECTED(Z_TYPE_P(var_ptr) == IS_OBJECT)
1065       && Z_OBJ_HANDLER_P(var_ptr, get)
1066       && Z_OBJ_HANDLER_P(var_ptr, set)) {
1067        /* proxy object */
1068        zval rv;
1069        zval *val = Z_OBJ_HANDLER_P(var_ptr, get)(var_ptr, &rv TSRMLS_CC);
1070        Z_ADDREF_P(val);
1071        fast_decrement_function(val);
1072        Z_OBJ_HANDLER_P(var_ptr, set)(var_ptr, val TSRMLS_CC);
1073        zval_ptr_dtor(val);
1074    } else {
1075        decrement_function(var_ptr);
1076    }
1077
1078    FREE_OP1_VAR_PTR();
1079    CHECK_EXCEPTION();
1080    ZEND_VM_NEXT_OPCODE();
1081}
1082
1083ZEND_VM_HANDLER(40, ZEND_ECHO, CONST|TMP|VAR|CV, ANY)
1084{
1085    USE_OPLINE
1086    zend_free_op free_op1;
1087    zval *z;
1088
1089    SAVE_OPLINE();
1090    z = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
1091
1092    zend_print_variable(z TSRMLS_CC);
1093
1094    FREE_OP1();
1095    CHECK_EXCEPTION();
1096    ZEND_VM_NEXT_OPCODE();
1097}
1098
1099ZEND_VM_HANDLER(41, ZEND_PRINT, CONST|TMP|VAR|CV, ANY)
1100{
1101    USE_OPLINE
1102
1103    ZVAL_LONG(EX_VAR(opline->result.var), 1);
1104    ZEND_VM_DISPATCH_TO_HANDLER(ZEND_ECHO);
1105}
1106
1107ZEND_VM_HELPER_EX(zend_fetch_var_address_helper, CONST|TMP|VAR|CV, UNUSED|CONST|VAR, int type)
1108{
1109    USE_OPLINE
1110    zend_free_op free_op1;
1111    zval *varname;
1112    zval *retval;
1113    zend_string *name;
1114    HashTable *target_symbol_table;
1115
1116    SAVE_OPLINE();
1117    varname = GET_OP1_ZVAL_PTR(BP_VAR_R);
1118
1119    if (OP1_TYPE == IS_CONST) {
1120        name = Z_STR_P(varname);
1121    } else if (EXPECTED(Z_TYPE_P(varname) == IS_STRING)) {
1122        name = Z_STR_P(varname);
1123        zend_string_addref(name);
1124    } else {
1125        name = zval_get_string(varname);
1126    }
1127
1128    if (OP2_TYPE != IS_UNUSED) {
1129        zend_class_entry *ce;
1130
1131        if (OP2_TYPE == IS_CONST) {
1132            if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv))) {
1133                ce = CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv));
1134            } else {
1135                ce = zend_fetch_class_by_name(Z_STR_P(opline->op2.zv), opline->op2.zv + 1, 0 TSRMLS_CC);
1136                if (UNEXPECTED(ce == NULL)) {
1137                    if (OP1_TYPE != IS_CONST) {
1138                        zend_string_release(name);
1139                    }
1140                    FREE_OP1();
1141                    CHECK_EXCEPTION();
1142                    ZEND_VM_NEXT_OPCODE();
1143                }
1144                CACHE_PTR(Z_CACHE_SLOT_P(opline->op2.zv), ce);
1145            }
1146        } else {
1147            ce = Z_CE_P(EX_VAR(opline->op2.var));
1148        }
1149        retval = zend_std_get_static_property(ce, name, 0, ((OP1_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(varname)) : NULL) TSRMLS_CC);
1150        FREE_OP1();
1151    } else {
1152        target_symbol_table = zend_get_target_symbol_table(execute_data, opline->extended_value & ZEND_FETCH_TYPE_MASK TSRMLS_CC);
1153        retval = zend_hash_find(target_symbol_table, name);
1154        if (retval == NULL) {
1155            switch (type) {
1156                case BP_VAR_R:
1157                case BP_VAR_UNSET:
1158                    zend_error(E_NOTICE,"Undefined variable: %s", name->val);
1159                    /* break missing intentionally */
1160                case BP_VAR_IS:
1161                    retval = &EG(uninitialized_zval);
1162                    break;
1163                case BP_VAR_RW:
1164                    zend_error(E_NOTICE,"Undefined variable: %s", name->val);
1165                    /* break missing intentionally */
1166                case BP_VAR_W:
1167                    retval = zend_hash_add_new(target_symbol_table, name, &EG(uninitialized_zval));
1168                    break;
1169                EMPTY_SWITCH_DEFAULT_CASE()
1170            }
1171        /* GLOBAL or $$name variable may be an INDIRECT pointer to CV */
1172        } else if (Z_TYPE_P(retval) == IS_INDIRECT) {
1173            retval = Z_INDIRECT_P(retval);
1174            if (Z_TYPE_P(retval) == IS_UNDEF) {
1175                switch (type) {
1176                    case BP_VAR_R:
1177                    case BP_VAR_UNSET:
1178                        zend_error(E_NOTICE,"Undefined variable: %s", name->val);
1179                        /* break missing intentionally */
1180                    case BP_VAR_IS:
1181                        retval = &EG(uninitialized_zval);
1182                        break;
1183                    case BP_VAR_RW:
1184                        zend_error(E_NOTICE,"Undefined variable: %s", name->val);
1185                        /* break missing intentionally */
1186                    case BP_VAR_W:
1187                        ZVAL_NULL(retval);
1188                        break;
1189                    EMPTY_SWITCH_DEFAULT_CASE()
1190                }
1191            }
1192        }
1193        if ((opline->extended_value & ZEND_FETCH_TYPE_MASK) == ZEND_FETCH_STATIC) {
1194            if (Z_CONSTANT_P(retval)) {
1195                zval_update_constant(retval, 1 TSRMLS_CC);
1196            }
1197        } else if ((opline->extended_value & ZEND_FETCH_TYPE_MASK) != ZEND_FETCH_GLOBAL_LOCK) {
1198            FREE_OP1();
1199        }
1200    }
1201
1202    if (OP1_TYPE != IS_CONST) {
1203        zend_string_release(name);
1204    }
1205
1206    ZEND_ASSERT(retval != NULL);
1207    if (type == BP_VAR_R || type == BP_VAR_IS) {
1208        if (/*type == BP_VAR_R &&*/ Z_ISREF_P(retval) && Z_REFCOUNT_P(retval) == 1) {
1209            ZVAL_UNREF(retval);
1210        }
1211        ZVAL_COPY(EX_VAR(opline->result.var), retval);
1212    } else {
1213        if (/*type == BP_VAR_W &&*/ (opline->extended_value & ZEND_FETCH_MAKE_REF)) {
1214            ZVAL_MAKE_REF(retval);
1215        }
1216        ZVAL_INDIRECT(EX_VAR(opline->result.var), retval);
1217    }
1218    CHECK_EXCEPTION();
1219    ZEND_VM_NEXT_OPCODE();
1220}
1221
1222ZEND_VM_HANDLER(80, ZEND_FETCH_R, CONST|TMP|VAR|CV, UNUSED|CONST|VAR)
1223{
1224    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_R);
1225}
1226
1227ZEND_VM_HANDLER(83, ZEND_FETCH_W, CONST|TMP|VAR|CV, UNUSED|CONST|VAR)
1228{
1229    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_W);
1230}
1231
1232ZEND_VM_HANDLER(86, ZEND_FETCH_RW, CONST|TMP|VAR|CV, UNUSED|CONST|VAR)
1233{
1234    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_RW);
1235}
1236
1237ZEND_VM_HANDLER(92, ZEND_FETCH_FUNC_ARG, CONST|TMP|VAR|CV, UNUSED|CONST|VAR)
1238{
1239    USE_OPLINE
1240
1241    if (zend_is_by_ref_func_arg_fetch(opline, EX(call) TSRMLS_CC)) {
1242        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_W);
1243    } else {
1244        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_R);
1245    }
1246}
1247
1248ZEND_VM_HANDLER(95, ZEND_FETCH_UNSET, CONST|TMP|VAR|CV, UNUSED|CONST|VAR)
1249{
1250    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_UNSET);
1251}
1252
1253ZEND_VM_HANDLER(89, ZEND_FETCH_IS, CONST|TMP|VAR|CV, UNUSED|CONST|VAR)
1254{
1255    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_IS);
1256}
1257
1258ZEND_VM_HANDLER(81, ZEND_FETCH_DIM_R, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
1259{
1260    USE_OPLINE
1261    zend_free_op free_op1, free_op2;
1262    zval *container;
1263
1264    SAVE_OPLINE();
1265    container = GET_OP1_ZVAL_PTR(BP_VAR_R);
1266    zend_fetch_dimension_address_read_R(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R), OP2_TYPE TSRMLS_CC);
1267    FREE_OP2();
1268    if (OP1_TYPE != IS_VAR || !(opline->extended_value & ZEND_FETCH_ADD_LOCK)) {
1269        FREE_OP1();
1270    }
1271    CHECK_EXCEPTION();
1272    ZEND_VM_NEXT_OPCODE();
1273}
1274
1275ZEND_VM_HANDLER(84, ZEND_FETCH_DIM_W, VAR|CV, CONST|TMP|VAR|UNUSED|CV)
1276{
1277    USE_OPLINE
1278    zend_free_op free_op1, free_op2;
1279    zval *container;
1280
1281    SAVE_OPLINE();
1282    container = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
1283
1284    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1285        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1286    }
1287    if (EXPECTED(opline->extended_value == 0)) {
1288        zend_fetch_dimension_address_W(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R), OP2_TYPE TSRMLS_CC);
1289    } else {
1290        zend_fetch_dimension_address_W_ref(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R), OP2_TYPE TSRMLS_CC);
1291    }
1292    FREE_OP2();
1293    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1.var)) {
1294        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1295    }
1296    FREE_OP1_VAR_PTR();
1297    CHECK_EXCEPTION();
1298    ZEND_VM_NEXT_OPCODE();
1299}
1300
1301ZEND_VM_HANDLER(87, ZEND_FETCH_DIM_RW, VAR|CV, CONST|TMP|VAR|UNUSED|CV)
1302{
1303    USE_OPLINE
1304    zend_free_op free_op1, free_op2;
1305    zval *container;
1306
1307    SAVE_OPLINE();
1308    container = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
1309
1310    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1311        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1312    }
1313    zend_fetch_dimension_address_RW(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R), OP2_TYPE TSRMLS_CC);
1314    FREE_OP2();
1315    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1.var)) {
1316        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1317    }
1318    FREE_OP1_VAR_PTR();
1319    CHECK_EXCEPTION();
1320    ZEND_VM_NEXT_OPCODE();
1321}
1322
1323ZEND_VM_HANDLER(90, ZEND_FETCH_DIM_IS, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
1324{
1325    USE_OPLINE
1326    zend_free_op free_op1, free_op2;
1327    zval *container;
1328
1329    SAVE_OPLINE();
1330    container = GET_OP1_ZVAL_PTR(BP_VAR_IS);
1331    zend_fetch_dimension_address_read_IS(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R), OP2_TYPE TSRMLS_CC);
1332    FREE_OP2();
1333    FREE_OP1();
1334    CHECK_EXCEPTION();
1335    ZEND_VM_NEXT_OPCODE();
1336}
1337
1338ZEND_VM_HANDLER(93, ZEND_FETCH_DIM_FUNC_ARG, CONST|TMP|VAR|CV, CONST|TMP|VAR|UNUSED|CV)
1339{
1340    USE_OPLINE
1341    zval *container;
1342    zend_free_op free_op1, free_op2;
1343
1344    SAVE_OPLINE();
1345
1346    if (zend_is_by_ref_func_arg_fetch(opline, EX(call) TSRMLS_CC)) {
1347        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
1348            zend_error_noreturn(E_ERROR, "Cannot use temporary expression in write context");
1349        }
1350        container = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
1351        if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1352            zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1353        }
1354        zend_fetch_dimension_address_W(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R), OP2_TYPE TSRMLS_CC);
1355        if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1.var)) {
1356            EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1357        }
1358        FREE_OP2();
1359        FREE_OP1_VAR_PTR();
1360    } else {
1361        if (OP2_TYPE == IS_UNUSED) {
1362            zend_error_noreturn(E_ERROR, "Cannot use [] for reading");
1363        }
1364        container = GET_OP1_ZVAL_PTR(BP_VAR_R);
1365        zend_fetch_dimension_address_read_R(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R), OP2_TYPE TSRMLS_CC);
1366        FREE_OP2();
1367        FREE_OP1();
1368    }
1369    CHECK_EXCEPTION();
1370    ZEND_VM_NEXT_OPCODE();
1371}
1372
1373ZEND_VM_HANDLER(96, ZEND_FETCH_DIM_UNSET, VAR|CV, CONST|TMP|VAR|CV)
1374{
1375    USE_OPLINE
1376    zend_free_op free_op1, free_op2;
1377    zval *container;
1378
1379    SAVE_OPLINE();
1380    container = GET_OP1_ZVAL_PTR_PTR(BP_VAR_UNSET);
1381
1382    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1383        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1384    }
1385    zend_fetch_dimension_address_UNSET(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R), OP2_TYPE TSRMLS_CC);
1386    FREE_OP2();
1387    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1.var)) {
1388        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1389    }
1390    FREE_OP1_VAR_PTR();
1391    CHECK_EXCEPTION();
1392    ZEND_VM_NEXT_OPCODE();
1393}
1394
1395ZEND_VM_HELPER(zend_fetch_property_address_read_helper, CONST|TMP|VAR|UNUSED|CV, CONST|TMP|VAR|CV)
1396{
1397    USE_OPLINE
1398    zend_free_op free_op1;
1399    zval *container;
1400    zend_free_op free_op2;
1401    zval *offset;
1402
1403    SAVE_OPLINE();
1404    container = GET_OP1_OBJ_ZVAL_PTR_DEREF(BP_VAR_R);
1405    offset  = GET_OP2_ZVAL_PTR(BP_VAR_R);
1406
1407    if (UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT) ||
1408        UNEXPECTED(Z_OBJ_HT_P(container)->read_property == NULL)) {
1409        zend_error(E_NOTICE, "Trying to get property of non-object");
1410        ZVAL_NULL(EX_VAR(opline->result.var));
1411    } else {
1412        zval *retval;
1413
1414        /* here we are sure we are dealing with an object */
1415        retval = Z_OBJ_HT_P(container)->read_property(container, offset, BP_VAR_R, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(offset)) : NULL), EX_VAR(opline->result.var) TSRMLS_CC);
1416
1417        if (retval != EX_VAR(opline->result.var)) {
1418            ZVAL_COPY(EX_VAR(opline->result.var), retval);
1419        }
1420    }
1421
1422    FREE_OP2();
1423    FREE_OP1();
1424    CHECK_EXCEPTION();
1425    ZEND_VM_NEXT_OPCODE();
1426}
1427
1428ZEND_VM_HANDLER(82, ZEND_FETCH_OBJ_R, CONST|TMP|VAR|UNUSED|CV, CONST|TMP|VAR|CV)
1429{
1430    ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_property_address_read_helper);
1431}
1432
1433ZEND_VM_HANDLER(85, ZEND_FETCH_OBJ_W, VAR|UNUSED|CV, CONST|TMP|VAR|CV)
1434{
1435    USE_OPLINE
1436    zend_free_op free_op1, free_op2;
1437    zval *property;
1438    zval *container;
1439
1440    SAVE_OPLINE();
1441    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1442
1443    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_W);
1444    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1445        zend_error_noreturn(E_ERROR, "Cannot use string offset as an object");
1446    }
1447
1448    zend_fetch_property_address(EX_VAR(opline->result.var), container, property, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_W, (opline->extended_value & ZEND_FETCH_MAKE_REF) != 0 TSRMLS_CC);
1449    FREE_OP2();
1450    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1.var)) {
1451        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1452    }
1453    FREE_OP1_VAR_PTR();
1454    CHECK_EXCEPTION();
1455    ZEND_VM_NEXT_OPCODE();
1456}
1457
1458ZEND_VM_HANDLER(88, ZEND_FETCH_OBJ_RW, VAR|UNUSED|CV, CONST|TMP|VAR|CV)
1459{
1460    USE_OPLINE
1461    zend_free_op free_op1, free_op2;
1462    zval *property;
1463    zval *container;
1464
1465    SAVE_OPLINE();
1466    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1467    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
1468
1469    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1470        zend_error_noreturn(E_ERROR, "Cannot use string offset as an object");
1471    }
1472    zend_fetch_property_address(EX_VAR(opline->result.var), container, property, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_RW, 0 TSRMLS_CC);
1473    FREE_OP2();
1474    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1.var)) {
1475        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1476    }
1477    FREE_OP1_VAR_PTR();
1478    CHECK_EXCEPTION();
1479    ZEND_VM_NEXT_OPCODE();
1480}
1481
1482ZEND_VM_HANDLER(91, ZEND_FETCH_OBJ_IS, CONST|TMP|VAR|UNUSED|CV, CONST|TMP|VAR|CV)
1483{
1484    USE_OPLINE
1485    zend_free_op free_op1;
1486    zval *container;
1487    zend_free_op free_op2;
1488    zval *offset;
1489
1490    SAVE_OPLINE();
1491    container = GET_OP1_OBJ_ZVAL_PTR_DEREF(BP_VAR_IS);
1492    offset  = GET_OP2_ZVAL_PTR(BP_VAR_R);
1493
1494    if (UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT) ||
1495        UNEXPECTED(Z_OBJ_HT_P(container)->read_property == NULL)) {
1496        ZVAL_NULL(EX_VAR(opline->result.var));
1497    } else {
1498        zval *retval;
1499
1500        /* here we are sure we are dealing with an object */
1501        retval = Z_OBJ_HT_P(container)->read_property(container, offset, BP_VAR_IS, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(offset)) : NULL), EX_VAR(opline->result.var) TSRMLS_CC);
1502
1503        if (retval != EX_VAR(opline->result.var)) {
1504            ZVAL_COPY(EX_VAR(opline->result.var), retval);
1505        }
1506    }
1507
1508    FREE_OP2();
1509    FREE_OP1();
1510    CHECK_EXCEPTION();
1511    ZEND_VM_NEXT_OPCODE();
1512}
1513
1514ZEND_VM_HANDLER(94, ZEND_FETCH_OBJ_FUNC_ARG, CONST|TMP|VAR|UNUSED|CV, CONST|TMP|VAR|CV)
1515{
1516    USE_OPLINE
1517    zval *container;
1518
1519    if (zend_is_by_ref_func_arg_fetch(opline, EX(call) TSRMLS_CC)) {
1520        /* Behave like FETCH_OBJ_W */
1521        zend_free_op free_op1, free_op2;
1522        zval *property;
1523
1524        SAVE_OPLINE();
1525        property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1526        container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_W);
1527
1528        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
1529            zend_error_noreturn(E_ERROR, "Cannot use temporary expression in write context");
1530        }
1531        if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1532            zend_error_noreturn(E_ERROR, "Cannot use string offset as an object");
1533        }
1534        zend_fetch_property_address(EX_VAR(opline->result.var), container, property, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_W, 0 TSRMLS_CC);
1535        FREE_OP2();
1536        if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1.var)) {
1537            EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1538        }
1539        FREE_OP1_VAR_PTR();
1540        CHECK_EXCEPTION();
1541        ZEND_VM_NEXT_OPCODE();
1542    } else {
1543        ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_property_address_read_helper);
1544    }
1545}
1546
1547ZEND_VM_HANDLER(97, ZEND_FETCH_OBJ_UNSET, VAR|UNUSED|CV, CONST|TMP|VAR|CV)
1548{
1549    USE_OPLINE
1550    zend_free_op free_op1, free_op2;
1551    zval *container, *property;
1552
1553    SAVE_OPLINE();
1554    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_UNSET);
1555    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1556
1557    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1558        zend_error_noreturn(E_ERROR, "Cannot use string offset as an object");
1559    }
1560    zend_fetch_property_address(EX_VAR(opline->result.var), container, property, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_UNSET, 0 TSRMLS_CC);
1561    FREE_OP2();
1562    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1.var)) {
1563        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1564    }
1565    FREE_OP1_VAR_PTR();
1566    CHECK_EXCEPTION();
1567    ZEND_VM_NEXT_OPCODE();
1568}
1569
1570ZEND_VM_HANDLER(98, ZEND_FETCH_DIM_TMP_VAR, CONST|TMP, CONST)
1571{
1572    USE_OPLINE
1573    zend_free_op free_op1;
1574    zval *container;
1575
1576    SAVE_OPLINE();
1577    container = GET_OP1_ZVAL_PTR(BP_VAR_R);
1578
1579    if (UNEXPECTED(Z_TYPE_P(container) != IS_ARRAY)) {
1580        ZVAL_NULL(EX_VAR(opline->result.var));
1581    } else {
1582        zend_free_op free_op2;
1583        zval *value = zend_fetch_dimension_address_inner(Z_ARRVAL_P(container), GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R), OP2_TYPE, BP_VAR_R TSRMLS_CC);
1584
1585        ZVAL_COPY(EX_VAR(opline->result.var), value);
1586        FREE_OP2();
1587    }
1588    CHECK_EXCEPTION();
1589    ZEND_VM_NEXT_OPCODE();
1590}
1591
1592ZEND_VM_HANDLER(136, ZEND_ASSIGN_OBJ, VAR|UNUSED|CV, CONST|TMP|VAR|CV)
1593{
1594    USE_OPLINE
1595    zend_free_op free_op1, free_op2;
1596    zval *object;
1597    zval *property_name;
1598
1599    SAVE_OPLINE();
1600    object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_W);
1601    property_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
1602
1603    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
1604        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1605    }
1606    zend_assign_to_object(RETURN_VALUE_USED(opline)?EX_VAR(opline->result.var):NULL, object, property_name, (opline+1)->op1_type, &(opline+1)->op1, execute_data, ZEND_ASSIGN_OBJ, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property_name)) : NULL) TSRMLS_CC);
1607    FREE_OP2();
1608    FREE_OP1_VAR_PTR();
1609    /* assign_obj has two opcodes! */
1610    CHECK_EXCEPTION();
1611    ZEND_VM_INC_OPCODE();
1612    ZEND_VM_NEXT_OPCODE();
1613}
1614
1615ZEND_VM_HANDLER(147, ZEND_ASSIGN_DIM, VAR|CV, CONST|TMP|VAR|UNUSED|CV)
1616{
1617    USE_OPLINE
1618    zend_free_op free_op1;
1619    zval *object_ptr;
1620
1621    SAVE_OPLINE();
1622    object_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
1623
1624    if (OP1_TYPE == IS_VAR && UNEXPECTED(object_ptr == NULL)) {
1625        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1626    }
1627    if (UNEXPECTED(Z_ISREF_P(object_ptr)) && Z_TYPE_P(Z_REFVAL_P(object_ptr)) == IS_OBJECT) {
1628        object_ptr = Z_REFVAL_P(object_ptr);
1629    }
1630    if (Z_TYPE_P(object_ptr) == IS_OBJECT) {
1631        zend_free_op free_op2;
1632        zval *property_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
1633
1634        zend_assign_to_object(RETURN_VALUE_USED(opline)?EX_VAR(opline->result.var):NULL, object_ptr, property_name, (opline+1)->op1_type, &(opline+1)->op1, execute_data, ZEND_ASSIGN_DIM, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property_name)) : NULL) TSRMLS_CC);
1635        FREE_OP2();
1636    } else {
1637        zend_free_op free_op2, free_op_data1, free_op_data2;
1638        zval *value;
1639        zval *dim = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
1640        zval *variable_ptr;
1641
1642        variable_ptr = zend_fetch_dimension_address_W_str(EX_VAR((opline+1)->op2.var), object_ptr, dim, OP2_TYPE TSRMLS_CC);
1643        FREE_OP2();
1644        value = get_zval_ptr_deref((opline+1)->op1_type, &(opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
1645        if (UNEXPECTED(variable_ptr != NULL)) {
1646            zend_assign_to_string_offset(variable_ptr, Z_LVAL_P(EX_VAR((opline+1)->op2.var)), value, (opline+1)->op1_type, (RETURN_VALUE_USED(opline) ? EX_VAR(opline->result.var) : NULL) TSRMLS_CC);
1647        } else {
1648            variable_ptr = _get_zval_ptr_ptr_var((opline+1)->op2.var, execute_data, &free_op_data2 TSRMLS_CC);
1649            if (UNEXPECTED(variable_ptr == &EG(error_zval))) {
1650                if (IS_TMP_FREE(free_op_data1)) {
1651                    zval_dtor(value);
1652                }
1653                if (RETURN_VALUE_USED(opline)) {
1654                    ZVAL_NULL(EX_VAR(opline->result.var));
1655                }
1656                FREE_OP_VAR_PTR(free_op_data2);
1657            } else {
1658                value = zend_assign_to_variable(variable_ptr, value, (opline+1)->op1_type TSRMLS_CC);
1659                if (RETURN_VALUE_USED(opline)) {
1660                    ZVAL_COPY(EX_VAR(opline->result.var), value);
1661                }
1662                FREE_OP_VAR_PTR(free_op_data2);
1663            }
1664        }
1665        FREE_OP_IF_VAR(free_op_data1);
1666    }
1667    FREE_OP1_VAR_PTR();
1668    /* assign_dim has two opcodes! */
1669    CHECK_EXCEPTION();
1670    ZEND_VM_INC_OPCODE();
1671    ZEND_VM_NEXT_OPCODE();
1672}
1673
1674ZEND_VM_HANDLER(38, ZEND_ASSIGN, VAR|CV, CONST|TMP|VAR|CV)
1675{
1676    USE_OPLINE
1677    zend_free_op free_op1, free_op2;
1678    zval *value;
1679    zval *variable_ptr;
1680
1681    SAVE_OPLINE();
1682    value = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
1683    variable_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1684
1685    if (OP1_TYPE == IS_VAR && UNEXPECTED(variable_ptr == &EG(error_zval))) {
1686        if (IS_OP2_TMP_FREE()) {
1687            zval_dtor(value);
1688        }
1689        if (RETURN_VALUE_USED(opline)) {
1690            ZVAL_NULL(EX_VAR(opline->result.var));
1691        }
1692    } else {
1693        value = zend_assign_to_variable(variable_ptr, value, OP2_TYPE TSRMLS_CC);
1694        if (RETURN_VALUE_USED(opline)) {
1695            ZVAL_COPY(EX_VAR(opline->result.var), value);
1696        }
1697        FREE_OP1_VAR_PTR();
1698    }
1699
1700    /* zend_assign_to_variable() always takes care of op2, never free it! */
1701    FREE_OP2_IF_VAR();
1702
1703    CHECK_EXCEPTION();
1704    ZEND_VM_NEXT_OPCODE();
1705}
1706
1707ZEND_VM_HANDLER(39, ZEND_ASSIGN_REF, VAR|CV, VAR|CV)
1708{
1709    USE_OPLINE
1710    zend_free_op free_op1, free_op2;
1711    zval *variable_ptr;
1712    zval *value_ptr;
1713
1714    SAVE_OPLINE();
1715    value_ptr = GET_OP2_ZVAL_PTR_PTR(BP_VAR_W);
1716
1717    if (OP2_TYPE == IS_VAR &&
1718        opline->extended_value == ZEND_RETURNS_FUNCTION &&
1719        !(Z_VAR_FLAGS_P(value_ptr) & IS_VAR_RET_REF) &&
1720        !Z_ISREF_P(value_ptr)) {
1721        if (!OP2_FREE) {
1722            PZVAL_LOCK(value_ptr); /* undo the effect of get_zval_ptr_ptr() */
1723        }
1724        zend_error(E_STRICT, "Only variables should be assigned by reference");
1725        if (UNEXPECTED(EG(exception) != NULL)) {
1726            FREE_OP2_VAR_PTR();
1727            HANDLE_EXCEPTION();
1728        }
1729        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_ASSIGN);
1730    } else if (OP2_TYPE == IS_VAR && opline->extended_value == ZEND_RETURNS_NEW) {
1731        if (!OP2_FREE) {
1732            PZVAL_LOCK(value_ptr);
1733        }
1734    }
1735
1736    variable_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1737    if (OP1_TYPE == IS_VAR &&
1738        UNEXPECTED(Z_TYPE_P(EX_VAR(opline->op1.var)) != IS_INDIRECT) &&
1739        UNEXPECTED(!Z_ISREF_P(variable_ptr))) {
1740        zend_error_noreturn(E_ERROR, "Cannot assign by reference to overloaded object");
1741    }
1742    if ((OP2_TYPE == IS_VAR && UNEXPECTED(value_ptr == NULL)) ||
1743        (OP1_TYPE == IS_VAR && UNEXPECTED(variable_ptr == NULL))) {
1744        zend_error_noreturn(E_ERROR, "Cannot create references to/from string offsets nor overloaded objects");
1745    }
1746    if ((OP1_TYPE == IS_VAR && UNEXPECTED(variable_ptr == &EG(error_zval))) ||
1747        (OP2_TYPE == IS_VAR && UNEXPECTED(value_ptr == &EG(error_zval)))) {
1748        variable_ptr = &EG(uninitialized_zval);
1749    } else {
1750        zend_assign_to_variable_reference(variable_ptr, value_ptr TSRMLS_CC);
1751    }
1752
1753    if (OP2_TYPE == IS_VAR && opline->extended_value == ZEND_RETURNS_NEW) {
1754        if (!OP2_FREE) {
1755            Z_DELREF_P(variable_ptr);
1756        }
1757    }
1758
1759    if (RETURN_VALUE_USED(opline)) {
1760        ZVAL_COPY(EX_VAR(opline->result.var), variable_ptr);
1761    }
1762
1763    FREE_OP1_VAR_PTR();
1764    FREE_OP2_VAR_PTR();
1765
1766    CHECK_EXCEPTION();
1767    ZEND_VM_NEXT_OPCODE();
1768}
1769
1770ZEND_VM_HELPER(zend_leave_helper, ANY, ANY)
1771{
1772    vm_frame_kind frame_kind = EX(frame_kind);
1773
1774    if (frame_kind == VM_FRAME_NESTED_FUNCTION) {
1775        i_free_compiled_variables(execute_data TSRMLS_CC);
1776        if (UNEXPECTED(EX(symbol_table) != NULL)) {
1777            zend_clean_and_cache_symbol_table(EX(symbol_table) TSRMLS_CC);
1778        }
1779        zend_vm_stack_free_extra_args(execute_data TSRMLS_CC);
1780        EG(current_execute_data) = EX(prev_execute_data);
1781        if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_CLOSURE) != 0) && EX(func)->op_array.prototype) {
1782            OBJ_RELEASE((zend_object*)EX(func)->op_array.prototype);
1783        }
1784        zend_vm_stack_free_call_frame(execute_data TSRMLS_CC);
1785
1786        execute_data = EG(current_execute_data);
1787
1788        if (Z_OBJ(EG(This))) {
1789            if (UNEXPECTED(EG(exception) != NULL) && (EX(opline)->op1.num & ZEND_CALL_CTOR)) {
1790                if (!(EX(opline)->op1.num & ZEND_CALL_CTOR_RESULT_UNUSED)) {
1791                    Z_DELREF(EG(This));
1792                }
1793                if (Z_REFCOUNT(EG(This)) == 1) {
1794                    zend_object_store_ctor_failed(Z_OBJ(EG(This)) TSRMLS_CC);
1795                }
1796            }
1797            if (!Z_DELREF(EG(This))) {
1798                _zval_dtor_func_for_ptr(Z_COUNTED(EG(This)) ZEND_FILE_LINE_CC);
1799            } else if (UNEXPECTED(!Z_GC_INFO(EG(This)))) {
1800                gc_possible_root(Z_COUNTED(EG(This)) TSRMLS_CC);
1801            }
1802        }
1803        Z_OBJ(EG(This)) = EX(object);
1804        EG(scope) = EX(scope);
1805
1806        if (UNEXPECTED(EG(exception) != NULL)) {
1807            const zend_op *opline = EX(opline);
1808            zend_throw_exception_internal(NULL TSRMLS_CC);
1809            if (RETURN_VALUE_USED(opline)) {
1810                zval_ptr_dtor(EX_VAR(opline->result.var));
1811            }
1812            HANDLE_EXCEPTION_LEAVE();
1813        }
1814
1815        LOAD_OPLINE();
1816        ZEND_VM_INC_OPCODE();
1817        ZEND_VM_LEAVE();
1818    } else if (frame_kind == VM_FRAME_NESTED_CODE) {
1819        zend_detach_symbol_table(execute_data);
1820        destroy_op_array(&EX(func)->op_array TSRMLS_CC);
1821        efree_size(EX(func), sizeof(zend_op_array));
1822        EG(current_execute_data) = EX(prev_execute_data);
1823        zend_vm_stack_free_call_frame(execute_data TSRMLS_CC);
1824
1825        execute_data = EG(current_execute_data);
1826        zend_attach_symbol_table(execute_data);
1827        if (UNEXPECTED(EG(exception) != NULL)) {
1828            zend_throw_exception_internal(NULL TSRMLS_CC);
1829            HANDLE_EXCEPTION_LEAVE();
1830        }
1831
1832        LOAD_OPLINE();
1833        ZEND_VM_INC_OPCODE();
1834        ZEND_VM_LEAVE();
1835    } else {
1836        if (frame_kind == VM_FRAME_TOP_FUNCTION) {
1837            i_free_compiled_variables(execute_data TSRMLS_CC);
1838            if (UNEXPECTED(EX(symbol_table) != NULL)) {
1839                zend_clean_and_cache_symbol_table(EX(symbol_table) TSRMLS_CC);
1840            }
1841            zend_vm_stack_free_extra_args(execute_data TSRMLS_CC);
1842            EG(current_execute_data) = EX(prev_execute_data);
1843            if ((EX(func)->op_array.fn_flags & ZEND_ACC_CLOSURE) && EX(func)->op_array.prototype) {
1844                OBJ_RELEASE((zend_object*)EX(func)->op_array.prototype);
1845            }
1846        } else /* if (frame_kind == VM_FRAME_TOP_CODE) */ {
1847            zend_array *symbol_table = EX(symbol_table);
1848            zend_execute_data *old_execute_data;
1849
1850            zend_detach_symbol_table(execute_data);
1851            old_execute_data = EX(prev_execute_data);
1852            while (old_execute_data) {
1853                if (old_execute_data->func && ZEND_USER_CODE(old_execute_data->func->op_array.type)) {
1854                    if (old_execute_data->symbol_table == symbol_table) {
1855                        zend_attach_symbol_table(old_execute_data);
1856                    }
1857                    break;
1858                }
1859                old_execute_data = old_execute_data->prev_execute_data;
1860            }
1861            EG(current_execute_data) = EX(prev_execute_data);
1862        }
1863        zend_vm_stack_free_call_frame(execute_data TSRMLS_CC);
1864
1865        ZEND_VM_RETURN();
1866    }
1867}
1868
1869ZEND_VM_HANDLER(42, ZEND_JMP, ANY, ANY)
1870{
1871    USE_OPLINE
1872
1873    ZEND_VM_SET_OPCODE(opline->op1.jmp_addr);
1874    ZEND_VM_CONTINUE();
1875}
1876
1877ZEND_VM_HANDLER(43, ZEND_JMPZ, CONST|TMP|VAR|CV, ANY)
1878{
1879    USE_OPLINE
1880    zend_free_op free_op1;
1881    zval *val;
1882
1883    SAVE_OPLINE();
1884    val = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
1885
1886    if (OP1_TYPE == IS_TMP_VAR) {
1887        if (Z_TYPE_P(val) == IS_TRUE) {
1888            ZEND_VM_SET_OPCODE(opline + 1);
1889            ZEND_VM_CONTINUE();
1890        } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
1891            ZEND_VM_SET_OPCODE(opline->op2.jmp_addr);
1892            ZEND_VM_CONTINUE();
1893        }
1894    }
1895
1896    if (i_zend_is_true(val TSRMLS_CC)) {
1897        opline++;
1898    } else {
1899        opline = opline->op2.jmp_addr;
1900    }
1901    FREE_OP1();
1902    if (UNEXPECTED(EG(exception) != NULL)) {
1903        HANDLE_EXCEPTION();
1904    }
1905    ZEND_VM_JMP(opline);
1906}
1907
1908ZEND_VM_HANDLER(44, ZEND_JMPNZ, CONST|TMP|VAR|CV, ANY)
1909{
1910    USE_OPLINE
1911    zend_free_op free_op1;
1912    zval *val;
1913
1914    SAVE_OPLINE();
1915    val = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
1916
1917    if (OP1_TYPE == IS_TMP_VAR) {
1918        if (Z_TYPE_P(val) == IS_TRUE) {
1919            ZEND_VM_SET_OPCODE(opline->op2.jmp_addr);
1920            ZEND_VM_CONTINUE();
1921        } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
1922            ZEND_VM_SET_OPCODE(opline + 1);
1923            ZEND_VM_CONTINUE();
1924        }
1925    }
1926
1927    if (i_zend_is_true(val TSRMLS_CC)) {
1928        opline = opline->op2.jmp_addr;
1929    } else {
1930        opline++;
1931    }
1932    FREE_OP1();
1933    if (UNEXPECTED(EG(exception) != NULL)) {
1934        HANDLE_EXCEPTION();
1935    }
1936    ZEND_VM_JMP(opline);
1937}
1938
1939ZEND_VM_HANDLER(45, ZEND_JMPZNZ, CONST|TMP|VAR|CV, ANY)
1940{
1941    USE_OPLINE
1942    zend_free_op free_op1;
1943    zval *val;
1944
1945    SAVE_OPLINE();
1946    val = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
1947
1948    if (OP1_TYPE == IS_TMP_VAR) {
1949        if (EXPECTED(Z_TYPE_P(val) == IS_TRUE)) {
1950            ZEND_VM_SET_RELATIVE_OPCODE(opline, opline->extended_value);
1951            ZEND_VM_CONTINUE();
1952        } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
1953            ZEND_VM_SET_OPCODE(opline->op2.jmp_addr);
1954            ZEND_VM_CONTINUE();
1955        }
1956    }
1957
1958    if (i_zend_is_true(val TSRMLS_CC)) {
1959        opline = (zend_op*)(((char*)opline) + opline->extended_value);
1960    } else {
1961        opline = opline->op2.jmp_addr;
1962    }
1963    FREE_OP1();
1964    if (UNEXPECTED(EG(exception) != NULL)) {
1965        HANDLE_EXCEPTION();
1966    }
1967    ZEND_VM_JMP(opline);
1968}
1969
1970ZEND_VM_HANDLER(46, ZEND_JMPZ_EX, CONST|TMP|VAR|CV, ANY)
1971{
1972    USE_OPLINE
1973    zend_free_op free_op1;
1974    zval *val;
1975
1976    SAVE_OPLINE();
1977    val = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
1978
1979    if (OP1_TYPE == IS_TMP_VAR) {
1980        if (Z_TYPE_P(val) == IS_TRUE) {
1981            ZVAL_TRUE(EX_VAR(opline->result.var));
1982            ZEND_VM_SET_OPCODE(opline + 1);
1983            ZEND_VM_CONTINUE();
1984        } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
1985            ZVAL_FALSE(EX_VAR(opline->result.var));
1986            ZEND_VM_SET_OPCODE(opline->op2.jmp_addr);
1987            ZEND_VM_CONTINUE();
1988        }
1989    }
1990
1991    if (i_zend_is_true(val TSRMLS_CC)) {
1992        ZVAL_TRUE(EX_VAR(opline->result.var));
1993        opline++;
1994    } else {
1995        ZVAL_FALSE(EX_VAR(opline->result.var));
1996        opline = opline->op2.jmp_addr;
1997    }
1998    FREE_OP1();
1999    if (UNEXPECTED(EG(exception) != NULL)) {
2000        HANDLE_EXCEPTION();
2001    }
2002    ZEND_VM_JMP(opline);
2003}
2004
2005ZEND_VM_HANDLER(47, ZEND_JMPNZ_EX, CONST|TMP|VAR|CV, ANY)
2006{
2007    USE_OPLINE
2008    zend_free_op free_op1;
2009    zval *val;
2010
2011    SAVE_OPLINE();
2012    val = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
2013
2014    if (OP1_TYPE == IS_TMP_VAR) {
2015        if (Z_TYPE_P(val) == IS_TRUE) {
2016            ZVAL_TRUE(EX_VAR(opline->result.var));
2017            ZEND_VM_SET_OPCODE(opline->op2.jmp_addr);
2018            ZEND_VM_CONTINUE();
2019        } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
2020            ZVAL_FALSE(EX_VAR(opline->result.var));
2021            ZEND_VM_SET_OPCODE(opline + 1);
2022            ZEND_VM_CONTINUE();
2023        }
2024    }
2025    if (i_zend_is_true(val TSRMLS_CC)) {
2026        ZVAL_TRUE(EX_VAR(opline->result.var));
2027        opline = opline->op2.jmp_addr;
2028    } else {
2029        ZVAL_FALSE(EX_VAR(opline->result.var));
2030        opline++;
2031    }
2032    FREE_OP1();
2033    if (UNEXPECTED(EG(exception) != NULL)) {
2034        HANDLE_EXCEPTION();
2035    }
2036    ZEND_VM_JMP(opline);
2037}
2038
2039ZEND_VM_HANDLER(70, ZEND_FREE, TMP|VAR, ANY)
2040{
2041    USE_OPLINE
2042
2043    SAVE_OPLINE();
2044    if (OP1_TYPE == IS_TMP_VAR) {
2045        zval_dtor(EX_VAR(opline->op1.var));
2046    } else {
2047        zval_ptr_dtor(EX_VAR(opline->op1.var));
2048    }
2049    CHECK_EXCEPTION();
2050    ZEND_VM_NEXT_OPCODE();
2051}
2052
2053ZEND_VM_HANDLER(53, ZEND_INIT_STRING, ANY, ANY)
2054{
2055    USE_OPLINE
2056    zval *tmp = EX_VAR(opline->result.var);
2057
2058    SAVE_OPLINE();
2059    ZVAL_EMPTY_STRING(tmp);
2060    /*CHECK_EXCEPTION();*/
2061    ZEND_VM_NEXT_OPCODE();
2062}
2063
2064ZEND_VM_HANDLER(54, ZEND_ADD_CHAR, TMP|UNUSED, CONST)
2065{
2066    USE_OPLINE
2067    zval *str = EX_VAR(opline->result.var);
2068
2069    SAVE_OPLINE();
2070
2071    if (OP1_TYPE == IS_UNUSED) {
2072        /* Initialize for erealloc in add_char_to_string */
2073        ZVAL_EMPTY_STRING(str);
2074    }
2075
2076    add_char_to_string(str, str, opline->op2.zv);
2077
2078    /* FREE_OP is missing intentionally here - we're always working on the same temporary variable */
2079    /*CHECK_EXCEPTION();*/
2080    ZEND_VM_NEXT_OPCODE();
2081}
2082
2083ZEND_VM_HANDLER(55, ZEND_ADD_STRING, TMP|UNUSED, CONST)
2084{
2085    USE_OPLINE
2086    zval *str = EX_VAR(opline->result.var);
2087
2088    SAVE_OPLINE();
2089
2090    if (OP1_TYPE == IS_UNUSED) {
2091        /* Initialize for erealloc in add_string_to_string */
2092        ZVAL_EMPTY_STRING(str);
2093    }
2094
2095    add_string_to_string(str, str, opline->op2.zv);
2096
2097    /* FREE_OP is missing intentionally here - we're always working on the same temporary variable */
2098    /*CHECK_EXCEPTION();*/
2099    ZEND_VM_NEXT_OPCODE();
2100}
2101
2102ZEND_VM_HANDLER(56, ZEND_ADD_VAR, TMP|UNUSED, TMP|VAR|CV)
2103{
2104    USE_OPLINE
2105    zend_free_op free_op2;
2106    zval *str = EX_VAR(opline->result.var);
2107    zval *var;
2108    zval var_copy;
2109    int use_copy = 0;
2110
2111    SAVE_OPLINE();
2112    var = GET_OP2_ZVAL_PTR(BP_VAR_R);
2113
2114    if (OP1_TYPE == IS_UNUSED) {
2115        /* Initialize for erealloc in add_string_to_string */
2116        ZVAL_EMPTY_STRING(str);
2117    }
2118
2119    if (Z_TYPE_P(var) != IS_STRING) {
2120        ZVAL_DEREF(var);
2121        if (Z_TYPE_P(var) != IS_STRING) {
2122            use_copy = zend_make_printable_zval(var, &var_copy TSRMLS_CC);
2123
2124            if (use_copy) {
2125                var = &var_copy;
2126            }
2127        }
2128    }
2129    add_string_to_string(str, str, var);
2130
2131    if (use_copy) {
2132        zval_dtor(var);
2133    }
2134    /* original comment, possibly problematic:
2135     * FREE_OP is missing intentionally here - we're always working on the same temporary variable
2136     * (Zeev):  I don't think it's problematic, we only use variables
2137     * which aren't affected by FREE_OP(Ts, )'s anyway, unless they're
2138     * string offsets or overloaded objects
2139     */
2140    FREE_OP2();
2141
2142    CHECK_EXCEPTION();
2143    ZEND_VM_NEXT_OPCODE();
2144}
2145
2146ZEND_VM_HANDLER(109, ZEND_FETCH_CLASS, ANY, CONST|TMP|VAR|UNUSED|CV)
2147{
2148    USE_OPLINE
2149
2150    SAVE_OPLINE();
2151    if (EG(exception)) {
2152        zend_exception_save(TSRMLS_C);
2153    }
2154    if (OP2_TYPE == IS_UNUSED) {
2155        Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class(NULL, opline->extended_value TSRMLS_CC);
2156        CHECK_EXCEPTION();
2157        ZEND_VM_NEXT_OPCODE();
2158    } else {
2159        zend_free_op free_op2;
2160        zval *class_name = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
2161
2162        if (OP2_TYPE == IS_CONST) {
2163            if (CACHED_PTR(Z_CACHE_SLOT_P(class_name))) {
2164                Z_CE_P(EX_VAR(opline->result.var)) = CACHED_PTR(Z_CACHE_SLOT_P(class_name));
2165            } else {
2166                Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class_by_name(Z_STR_P(class_name), opline->op2.zv + 1, opline->extended_value TSRMLS_CC);
2167                CACHE_PTR(Z_CACHE_SLOT_P(class_name), Z_CE_P(EX_VAR(opline->result.var)));
2168            }
2169        } else if (Z_TYPE_P(class_name) == IS_OBJECT) {
2170            Z_CE_P(EX_VAR(opline->result.var)) = Z_OBJCE_P(class_name);
2171        } else if (Z_TYPE_P(class_name) == IS_STRING) {
2172            Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class(Z_STR_P(class_name), opline->extended_value TSRMLS_CC);
2173        } else {
2174            if (UNEXPECTED(EG(exception) != NULL)) {
2175                HANDLE_EXCEPTION();
2176            }
2177            zend_error_noreturn(E_ERROR, "Class name must be a valid object or a string");
2178        }
2179
2180        FREE_OP2();
2181        CHECK_EXCEPTION();
2182        ZEND_VM_NEXT_OPCODE();
2183    }
2184}
2185
2186ZEND_VM_HANDLER(112, ZEND_INIT_METHOD_CALL, TMP|VAR|UNUSED|CV, CONST|TMP|VAR|CV)
2187{
2188    USE_OPLINE
2189    zval *function_name;
2190    zend_free_op free_op1, free_op2;
2191    zval *object;
2192    zend_function *fbc;
2193    zend_class_entry *called_scope;
2194    zend_object *obj;
2195
2196    SAVE_OPLINE();
2197
2198    function_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2199
2200    if (OP2_TYPE != IS_CONST &&
2201        UNEXPECTED(Z_TYPE_P(function_name) != IS_STRING)) {
2202        if (UNEXPECTED(EG(exception) != NULL)) {
2203            HANDLE_EXCEPTION();
2204        }
2205        zend_error_noreturn(E_ERROR, "Method name must be a string");
2206    }
2207
2208    object = GET_OP1_OBJ_ZVAL_PTR_DEREF(BP_VAR_R);
2209
2210    if (UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
2211        if (UNEXPECTED(EG(exception) != NULL)) {
2212            FREE_OP2();
2213            HANDLE_EXCEPTION();
2214        }
2215        zend_error_noreturn(E_ERROR, "Call to a member function %s() on %s", Z_STRVAL_P(function_name), zend_get_type_by_const(Z_TYPE_P(object)));
2216    }
2217
2218    obj = Z_OBJ_P(object);
2219    called_scope = zend_get_class_entry(obj TSRMLS_CC);
2220
2221    if (OP2_TYPE != IS_CONST ||
2222        (fbc = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), called_scope)) == NULL) {
2223        zend_object *orig_obj = obj;
2224
2225        if (UNEXPECTED(obj->handlers->get_method == NULL)) {
2226            zend_error_noreturn(E_ERROR, "Object does not support method calls");
2227        }
2228
2229        /* First, locate the function. */
2230        fbc = obj->handlers->get_method(&obj, Z_STR_P(function_name), ((OP2_TYPE == IS_CONST) ? (opline->op2.zv + 1) : NULL) TSRMLS_CC);
2231        if (UNEXPECTED(fbc == NULL)) {
2232            zend_error_noreturn(E_ERROR, "Call to undefined method %s::%s()", Z_OBJ_CLASS_NAME_P(obj), Z_STRVAL_P(function_name));
2233        }
2234        if (OP2_TYPE == IS_CONST &&
2235            EXPECTED(fbc->type <= ZEND_USER_FUNCTION) &&
2236            EXPECTED((fbc->common.fn_flags & (ZEND_ACC_CALL_VIA_HANDLER|ZEND_ACC_NEVER_CACHE)) == 0) &&
2237            EXPECTED(obj == orig_obj)) {
2238            CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), called_scope, fbc);
2239        }
2240    }
2241
2242    if ((fbc->common.fn_flags & ZEND_ACC_STATIC) != 0) {
2243        obj = NULL;
2244    } else {
2245        GC_REFCOUNT(obj)++; /* For $this pointer */
2246    }
2247
2248    EX(call) = zend_vm_stack_push_call_frame(
2249        fbc, opline->extended_value, 0, called_scope, obj, EX(call) TSRMLS_CC);
2250
2251    FREE_OP2();
2252    FREE_OP1_IF_VAR();
2253
2254    CHECK_EXCEPTION();
2255    ZEND_VM_NEXT_OPCODE();
2256}
2257
2258ZEND_VM_HANDLER(113, ZEND_INIT_STATIC_METHOD_CALL, CONST|VAR, CONST|TMP|VAR|UNUSED|CV)
2259{
2260    USE_OPLINE
2261    zval *function_name;
2262    zend_class_entry *ce;
2263    zend_object *object;
2264    zend_function *fbc;
2265
2266    SAVE_OPLINE();
2267
2268    if (OP1_TYPE == IS_CONST) {
2269        /* no function found. try a static method in class */
2270        if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op1.zv))) {
2271            ce = CACHED_PTR(Z_CACHE_SLOT_P(opline->op1.zv));
2272        } else {
2273            ce = zend_fetch_class_by_name(Z_STR_P(opline->op1.zv), opline->op1.zv + 1, ZEND_FETCH_CLASS_DEFAULT TSRMLS_CC);
2274            if (UNEXPECTED(EG(exception) != NULL)) {
2275                HANDLE_EXCEPTION();
2276            }
2277            if (UNEXPECTED(ce == NULL)) {
2278                zend_error_noreturn(E_ERROR, "Class '%s' not found", Z_STRVAL_P(opline->op1.zv));
2279            }
2280            CACHE_PTR(Z_CACHE_SLOT_P(opline->op1.zv), ce);
2281        }
2282    } else {
2283        ce = Z_CE_P(EX_VAR(opline->op1.var));
2284    }
2285
2286    if (OP1_TYPE == IS_CONST &&
2287        OP2_TYPE == IS_CONST &&
2288        CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv))) {
2289        fbc = CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv));
2290    } else if (OP1_TYPE != IS_CONST &&
2291               OP2_TYPE == IS_CONST &&
2292               (fbc = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(opline->op2.zv), ce))) {
2293        /* do nothing */
2294    } else if (OP2_TYPE != IS_UNUSED) {
2295        zend_free_op free_op2;
2296
2297        function_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2298        if (OP2_TYPE != IS_CONST) {
2299            if (UNEXPECTED(Z_TYPE_P(function_name) != IS_STRING)) {
2300                if (UNEXPECTED(EG(exception) != NULL)) {
2301                    HANDLE_EXCEPTION();
2302                }
2303                zend_error_noreturn(E_ERROR, "Function name must be a string");
2304            }
2305        }
2306
2307        if (ce->get_static_method) {
2308            fbc = ce->get_static_method(ce, Z_STR_P(function_name) TSRMLS_CC);
2309        } else {
2310            fbc = zend_std_get_static_method(ce, Z_STR_P(function_name), ((OP2_TYPE == IS_CONST) ? (opline->op2.zv + 1) : NULL) TSRMLS_CC);
2311        }
2312        if (UNEXPECTED(fbc == NULL)) {
2313            zend_error_noreturn(E_ERROR, "Call to undefined method %s::%s()", ce->name->val, Z_STRVAL_P(function_name));
2314        }
2315        if (OP2_TYPE == IS_CONST &&
2316            EXPECTED(fbc->type <= ZEND_USER_FUNCTION) &&
2317            EXPECTED((fbc->common.fn_flags & (ZEND_ACC_CALL_VIA_HANDLER|ZEND_ACC_NEVER_CACHE)) == 0)) {
2318            if (OP1_TYPE == IS_CONST) {
2319                CACHE_PTR(Z_CACHE_SLOT_P(function_name), fbc);
2320            } else {
2321                CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), ce, fbc);
2322            }
2323        }
2324        if (OP2_TYPE != IS_CONST) {
2325            FREE_OP2();
2326        }
2327    } else {
2328        if (UNEXPECTED(ce->constructor == NULL)) {
2329            zend_error_noreturn(E_ERROR, "Cannot call constructor");
2330        }
2331        if (EX(object) && zend_get_class_entry(EX(object) TSRMLS_CC) != ce->constructor->common.scope && (ce->constructor->common.fn_flags & ZEND_ACC_PRIVATE)) {
2332            zend_error_noreturn(E_ERROR, "Cannot call private %s::__construct()", ce->name->val);
2333        }
2334        fbc = ce->constructor;
2335    }
2336
2337    object = NULL;
2338    if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
2339        if (EX(object)) {
2340            object = EX(object);
2341            GC_REFCOUNT(object)++;
2342            if (object->handlers->get_class_entry &&
2343                !instanceof_function(zend_get_class_entry(object TSRMLS_CC), ce TSRMLS_CC)) {
2344                /* We are calling method of the other (incompatible) class,
2345                   but passing $this. This is done for compatibility with php-4. */
2346                if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
2347                    zend_error(E_DEPRECATED, "Non-static method %s::%s() should not be called statically, assuming $this from incompatible context", fbc->common.scope->name->val, fbc->common.function_name->val);
2348                } else {
2349                    /* An internal function assumes $this is present and won't check that. So PHP would crash by allowing the call. */
2350                    zend_error_noreturn(E_ERROR, "Non-static method %s::%s() cannot be called statically, assuming $this from incompatible context", fbc->common.scope->name->val, fbc->common.function_name->val);
2351                }
2352            }
2353        }
2354    }
2355
2356    if (OP1_TYPE != IS_CONST) {
2357        /* previous opcode is ZEND_FETCH_CLASS */
2358        if ((opline-1)->extended_value == ZEND_FETCH_CLASS_PARENT || (opline-1)->extended_value == ZEND_FETCH_CLASS_SELF) {
2359            ce = EX(called_scope);
2360        }
2361    }
2362
2363    EX(call) = zend_vm_stack_push_call_frame(
2364        fbc, opline->extended_value, 0, ce, object, EX(call) TSRMLS_CC);
2365
2366    if (OP2_TYPE == IS_UNUSED) {
2367        EX(call)->return_value = NULL;
2368    }
2369
2370    CHECK_EXCEPTION();
2371    ZEND_VM_NEXT_OPCODE();
2372}
2373
2374ZEND_VM_HANDLER(59, ZEND_INIT_FCALL_BY_NAME, ANY, CONST|TMP|VAR|CV)
2375{
2376    USE_OPLINE
2377    zend_function *fbc;
2378    zval *function_name, *func;
2379
2380    if (OP2_TYPE == IS_CONST && Z_TYPE_P(opline->op2.zv) == IS_STRING) {
2381        function_name = (zval*)(opline->op2.zv+1);
2382        if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv))) {
2383            fbc = CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv));
2384        } else if (UNEXPECTED((func = zend_hash_find(EG(function_table), Z_STR_P(function_name))) == NULL)) {
2385            SAVE_OPLINE();
2386            zend_error_noreturn(E_ERROR, "Call to undefined function %s()", Z_STRVAL_P(opline->op2.zv));
2387        } else {
2388            fbc = Z_FUNC_P(func);
2389            CACHE_PTR(Z_CACHE_SLOT_P(opline->op2.zv), fbc);
2390        }
2391
2392        EX(call) = zend_vm_stack_push_call_frame(
2393            fbc, opline->extended_value, 0, NULL, NULL, EX(call) TSRMLS_CC);
2394
2395        /*CHECK_EXCEPTION();*/
2396        ZEND_VM_NEXT_OPCODE();
2397    } else {
2398        zend_string *lcname;
2399        zend_free_op free_op2;
2400        zend_class_entry *called_scope;
2401        zend_object *object;
2402        zval *function_name_ptr;
2403
2404        SAVE_OPLINE();
2405        function_name_ptr = function_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2406
2407        ZVAL_DEREF(function_name);
2408        if (EXPECTED(Z_TYPE_P(function_name) == IS_STRING)) {
2409            if (Z_STRVAL_P(function_name)[0] == '\\') {
2410                lcname = zend_string_alloc(Z_STRLEN_P(function_name) - 1, 0);
2411                zend_str_tolower_copy(lcname->val, Z_STRVAL_P(function_name) + 1, Z_STRLEN_P(function_name) - 1);
2412            } else {
2413                lcname = zend_string_alloc(Z_STRLEN_P(function_name), 0);
2414                zend_str_tolower_copy(lcname->val, Z_STRVAL_P(function_name), Z_STRLEN_P(function_name));
2415            }
2416            if (UNEXPECTED((func = zend_hash_find(EG(function_table), lcname)) == NULL)) {
2417                zend_error_noreturn(E_ERROR, "Call to undefined function %s()", Z_STRVAL_P(function_name));
2418            }
2419            zend_string_free(lcname);
2420            FREE_OP2();
2421
2422            fbc = Z_FUNC_P(func);
2423            called_scope = NULL;
2424            object = NULL;
2425        } else if (OP2_TYPE != IS_CONST &&
2426            EXPECTED(Z_TYPE_P(function_name) == IS_OBJECT) &&
2427            Z_OBJ_HANDLER_P(function_name, get_closure) &&
2428            Z_OBJ_HANDLER_P(function_name, get_closure)(function_name, &called_scope, &fbc, &object TSRMLS_CC) == SUCCESS) {
2429            if (object) {
2430                GC_REFCOUNT(object)++;
2431            }
2432            if (OP2_TYPE == IS_VAR && OP2_FREE && Z_REFCOUNT_P(function_name) == 1 &&
2433                fbc->common.fn_flags & ZEND_ACC_CLOSURE) {
2434                /* Delay closure destruction until its invocation */
2435                fbc->common.prototype = (zend_function*)Z_OBJ_P(function_name_ptr);
2436            } else if (OP2_TYPE == IS_CV) {
2437                FREE_OP2();
2438            }
2439        } else if (EXPECTED(Z_TYPE_P(function_name) == IS_ARRAY) &&
2440                zend_hash_num_elements(Z_ARRVAL_P(function_name)) == 2) {
2441            zval *obj;
2442            zval *method;
2443
2444            obj = zend_hash_index_find(Z_ARRVAL_P(function_name), 0);
2445            method = zend_hash_index_find(Z_ARRVAL_P(function_name), 1);
2446
2447            if (!obj || !method) {
2448                zend_error_noreturn(E_ERROR, "Array callback has to contain indices 0 and 1");
2449            }
2450
2451            ZVAL_DEREF(obj);
2452            if (Z_TYPE_P(obj) != IS_STRING && Z_TYPE_P(obj) != IS_OBJECT) {
2453                zend_error_noreturn(E_ERROR, "First array member is not a valid class name or object");
2454            }
2455
2456            ZVAL_DEREF(method);
2457            if (Z_TYPE_P(method) != IS_STRING) {
2458                zend_error_noreturn(E_ERROR, "Second array member is not a valid method");
2459            }
2460
2461            if (Z_TYPE_P(obj) == IS_STRING) {
2462                object = NULL;
2463                called_scope = zend_fetch_class_by_name(Z_STR_P(obj), NULL, 0 TSRMLS_CC);
2464                if (UNEXPECTED(called_scope == NULL)) {
2465                    CHECK_EXCEPTION();
2466                    ZEND_VM_NEXT_OPCODE();
2467                }
2468
2469                if (called_scope->get_static_method) {
2470                    fbc = called_scope->get_static_method(called_scope, Z_STR_P(method) TSRMLS_CC);
2471                } else {
2472                    fbc = zend_std_get_static_method(called_scope, Z_STR_P(method), NULL TSRMLS_CC);
2473                }
2474                if (UNEXPECTED(fbc == NULL)) {
2475                    zend_error_noreturn(E_ERROR, "Call to undefined method %s::%s()", called_scope->name->val, Z_STRVAL_P(method));
2476                }
2477            } else {
2478                called_scope = Z_OBJCE_P(obj);
2479                object = Z_OBJ_P(obj);
2480
2481                fbc = Z_OBJ_HT_P(obj)->get_method(&object, Z_STR_P(method), NULL TSRMLS_CC);
2482                if (UNEXPECTED(fbc == NULL)) {
2483                    zend_error_noreturn(E_ERROR, "Call to undefined method %s::%s()", Z_OBJ_CLASS_NAME_P(object), Z_STRVAL_P(method));
2484                }
2485
2486                if ((fbc->common.fn_flags & ZEND_ACC_STATIC) != 0) {
2487                    object = NULL;
2488                } else {
2489                    GC_REFCOUNT(object)++; /* For $this pointer */
2490                }
2491            }
2492            FREE_OP2();
2493        } else {
2494            if (UNEXPECTED(EG(exception) != NULL)) {
2495                HANDLE_EXCEPTION();
2496            }
2497            zend_error_noreturn(E_ERROR, "Function name must be a string");
2498            ZEND_VM_CONTINUE(); /* Never reached */
2499        }
2500        EX(call) = zend_vm_stack_push_call_frame(
2501            fbc, opline->extended_value, 0, called_scope, object, EX(call) TSRMLS_CC);
2502
2503        CHECK_EXCEPTION();
2504        ZEND_VM_NEXT_OPCODE();
2505    }
2506}
2507
2508ZEND_VM_HANDLER(118, ZEND_INIT_USER_CALL, CONST, CONST|TMP|VAR|CV)
2509{
2510    USE_OPLINE
2511    zend_free_op free_op2;
2512    zval *function_name = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
2513    zend_fcall_info_cache fcc;
2514    char *error = NULL;
2515    zend_function *func;
2516    zend_class_entry *called_scope;
2517    zend_object *object;
2518
2519    if (zend_is_callable_ex(function_name, NULL, 0, NULL, &fcc, &error TSRMLS_CC)) {
2520        if (error) {
2521            efree(error);
2522        }
2523        func = fcc.function_handler;
2524        if (func->common.fn_flags & ZEND_ACC_CLOSURE) {
2525            /* Delay closure destruction until its invocation */
2526            func->common.prototype = (zend_function*)Z_OBJ_P(function_name);
2527            Z_ADDREF_P(function_name);
2528        }
2529        called_scope = fcc.called_scope;
2530        object = fcc.object;
2531        if (object) {
2532            GC_REFCOUNT(object)++; /* For $this pointer */
2533        }
2534    } else {
2535        zend_error(E_WARNING, "%s() expects parameter 1 to be a valid callback, %s", Z_STRVAL_P(opline->op1.zv), error);
2536        efree(error);
2537        func = (zend_function*)&zend_pass_function;
2538        called_scope = NULL;
2539        object = NULL;
2540    }
2541
2542    EX(call) = zend_vm_stack_push_call_frame(
2543        func, opline->extended_value, 0, called_scope, object, EX(call) TSRMLS_CC);
2544
2545    FREE_OP2();
2546    CHECK_EXCEPTION();
2547    ZEND_VM_NEXT_OPCODE();
2548}
2549
2550ZEND_VM_HANDLER(69, ZEND_INIT_NS_FCALL_BY_NAME, ANY, CONST)
2551{
2552    USE_OPLINE
2553    zval *func_name;
2554    zval *func;
2555    zend_function *fbc;
2556
2557    func_name = opline->op2.zv + 1;
2558    if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv))) {
2559        fbc = CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv));
2560    } else if ((func = zend_hash_find(EG(function_table), Z_STR_P(func_name))) == NULL) {
2561        func_name++;
2562        if (UNEXPECTED((func = zend_hash_find(EG(function_table), Z_STR_P(func_name))) == NULL)) {
2563            SAVE_OPLINE();
2564            zend_error_noreturn(E_ERROR, "Call to undefined function %s()", Z_STRVAL_P(opline->op2.zv));
2565        } else {
2566            fbc = Z_FUNC_P(func);
2567            CACHE_PTR(Z_CACHE_SLOT_P(opline->op2.zv), fbc);
2568        }
2569    } else {
2570        fbc = Z_FUNC_P(func);
2571        CACHE_PTR(Z_CACHE_SLOT_P(opline->op2.zv), fbc);
2572    }
2573
2574    EX(call) = zend_vm_stack_push_call_frame(
2575        fbc, opline->extended_value, 0, NULL, NULL, EX(call) TSRMLS_CC);
2576
2577    ZEND_VM_NEXT_OPCODE();
2578}
2579
2580ZEND_VM_HANDLER(61, ZEND_INIT_FCALL, ANY, CONST)
2581{
2582    USE_OPLINE
2583    zend_free_op free_op2;
2584    zval *fname = GET_OP2_ZVAL_PTR(BP_VAR_R);
2585    zval *func;
2586    zend_function *fbc;
2587
2588    if (CACHED_PTR(Z_CACHE_SLOT_P(fname))) {
2589        fbc = CACHED_PTR(Z_CACHE_SLOT_P(fname));
2590    } else if (UNEXPECTED((func = zend_hash_find(EG(function_table), Z_STR_P(fname))) == NULL)) {
2591        SAVE_OPLINE();
2592        zend_error_noreturn(E_ERROR, "Call to undefined function %s()", Z_STRVAL_P(fname));
2593    } else {
2594        fbc = Z_FUNC_P(func);
2595        CACHE_PTR(Z_CACHE_SLOT_P(fname), fbc);
2596    }
2597
2598    EX(call) = zend_vm_stack_push_call_frame(
2599        fbc, opline->extended_value, 0, NULL, NULL, EX(call) TSRMLS_CC);
2600
2601    FREE_OP2();
2602
2603    ZEND_VM_NEXT_OPCODE();
2604}
2605
2606ZEND_VM_HANDLER(60, ZEND_DO_FCALL, ANY, ANY)
2607{
2608    USE_OPLINE
2609    zend_execute_data *call = EX(call);
2610    zend_function *fbc = call->func;
2611
2612    SAVE_OPLINE();
2613    EX(call) = call->prev_nested_call;
2614    if (UNEXPECTED((fbc->common.fn_flags & (ZEND_ACC_ABSTRACT|ZEND_ACC_DEPRECATED)) != 0)) {
2615        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_ABSTRACT) != 0)) {
2616            zend_error_noreturn(E_ERROR, "Cannot call abstract method %s::%s()", fbc->common.scope->name->val, fbc->common.function_name->val);
2617        }
2618        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_DEPRECATED) != 0)) {
2619            zend_error(E_DEPRECATED, "Function %s%s%s() is deprecated",
2620                fbc->common.scope ? fbc->common.scope->name->val : "",
2621                fbc->common.scope ? "::" : "",
2622                fbc->common.function_name->val);
2623            if (UNEXPECTED(EG(exception) != NULL)) {
2624                HANDLE_EXCEPTION();
2625            }
2626        }
2627    }
2628    if (fbc->common.scope &&
2629        !(fbc->common.fn_flags & ZEND_ACC_STATIC) &&
2630        !call->object) {
2631
2632        if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
2633            /* FIXME: output identifiers properly */
2634            zend_error(E_STRICT, "Non-static method %s::%s() should not be called statically", fbc->common.scope->name->val, fbc->common.function_name->val);
2635            if (UNEXPECTED(EG(exception) != NULL)) {
2636                HANDLE_EXCEPTION();
2637            }
2638        } else {
2639            /* FIXME: output identifiers properly */
2640            /* An internal function assumes $this is present and won't check that. So PHP would crash by allowing the call. */
2641            zend_error_noreturn(E_ERROR, "Non-static method %s::%s() cannot be called statically", fbc->common.scope->name->val, fbc->common.function_name->val);
2642        }
2643    }
2644
2645    LOAD_OPLINE();
2646
2647    if (UNEXPECTED(fbc->type == ZEND_INTERNAL_FUNCTION)) {
2648        int should_change_scope = 0;
2649        zval *ret;
2650
2651        if (fbc->common.scope) {
2652            should_change_scope = 1;
2653            Z_OBJ(EG(This)) = call->object;
2654            /* TODO: we don't set scope if we call an object method ??? */
2655            /* See: ext/pdo_sqlite/tests/pdo_fetch_func_001.phpt */
2656#if 1
2657            EG(scope) = (call->object) ? NULL : fbc->common.scope;
2658#else
2659            EG(scope) = fbc->common.scope;
2660#endif
2661        } else {
2662            call->called_scope = EX(called_scope);
2663        }
2664
2665        call->prev_execute_data = execute_data;
2666        EG(current_execute_data) = call;
2667
2668        if (fbc->common.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) {
2669            uint32_t i;
2670            zval *p = ZEND_CALL_ARG(call, 1);
2671
2672            for (i = 0; i < call->num_args; ++i) {
2673                zend_verify_arg_type(fbc, i + 1, p, 0 TSRMLS_CC);
2674                p++;
2675            }
2676            if (UNEXPECTED(EG(exception) != NULL)) {
2677                EG(current_execute_data) = call->prev_execute_data;
2678                zend_vm_stack_free_args(call TSRMLS_CC);
2679                zend_vm_stack_free_call_frame(call TSRMLS_CC);
2680                if (RETURN_VALUE_USED(opline)) {
2681                    ZVAL_UNDEF(EX_VAR(opline->result.var));
2682                }
2683                if (UNEXPECTED(should_change_scope)) {
2684                    ZEND_VM_C_GOTO(fcall_end_change_scope);
2685                } else {
2686                    ZEND_VM_C_GOTO(fcall_end);
2687                }
2688            }
2689        }
2690
2691        ret = EX_VAR(opline->result.var);
2692        ZVAL_NULL(ret);
2693        Z_VAR_FLAGS_P(ret) = (fbc->common.fn_flags & ZEND_ACC_RETURN_REFERENCE) != 0 ? IS_VAR_RET_REF : 0;
2694
2695        if (!zend_execute_internal) {
2696            /* saves one function call if zend_execute_internal is not used */
2697            fbc->internal_function.handler(call->num_args, ret TSRMLS_CC);
2698        } else {
2699            zend_execute_internal(call, ret TSRMLS_CC);
2700        }
2701        EG(current_execute_data) = call->prev_execute_data;
2702        zend_vm_stack_free_args(call TSRMLS_CC);
2703        zend_vm_stack_free_call_frame(call TSRMLS_CC);
2704
2705        if (!RETURN_VALUE_USED(opline)) {
2706            zval_ptr_dtor(ret);
2707        }
2708
2709        if (UNEXPECTED(should_change_scope)) {
2710            ZEND_VM_C_GOTO(fcall_end_change_scope);
2711        } else {
2712            ZEND_VM_C_GOTO(fcall_end);
2713        }
2714    } else if (EXPECTED(fbc->type == ZEND_USER_FUNCTION)) {
2715        zval *return_value = NULL;
2716
2717        Z_OBJ(EG(This)) = call->object;
2718        EG(scope) = fbc->common.scope;
2719        call->symbol_table = NULL;
2720        if (RETURN_VALUE_USED(opline)) {
2721            return_value = EX_VAR(opline->result.var);
2722
2723            ZVAL_NULL(return_value);
2724            Z_VAR_FLAGS_P(return_value) = (fbc->common.fn_flags & ZEND_ACC_RETURN_REFERENCE) != 0 ? IS_VAR_RET_REF : 0;
2725        }
2726
2727        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_GENERATOR) != 0)) {
2728            if (RETURN_VALUE_USED(opline)) {
2729                zend_generator_create_zval(call, &fbc->op_array, EX_VAR(opline->result.var) TSRMLS_CC);
2730            } else {
2731                zend_vm_stack_free_args(call TSRMLS_CC);
2732            }
2733
2734            zend_vm_stack_free_call_frame(call TSRMLS_CC);
2735        } else {
2736            call->prev_execute_data = execute_data;
2737            i_init_func_execute_data(call, &fbc->op_array, return_value, EXPECTED(zend_execute_ex == execute_ex) ? VM_FRAME_NESTED_FUNCTION : VM_FRAME_TOP_FUNCTION TSRMLS_CC);
2738
2739            if (EXPECTED(zend_execute_ex == execute_ex)) {
2740                ZEND_VM_ENTER();
2741            } else {
2742                zend_execute_ex(call TSRMLS_CC);
2743            }
2744        }
2745    } else { /* ZEND_OVERLOADED_FUNCTION */
2746        Z_OBJ(EG(This)) = call->object;
2747        EG(scope) = fbc->common.scope;
2748
2749        ZVAL_NULL(EX_VAR(opline->result.var));
2750
2751        /* Not sure what should be done here if it's a static method */
2752        if (EXPECTED(call->object != NULL)) {
2753            call->prev_execute_data = execute_data;
2754            EG(current_execute_data) = call;
2755            call->object->handlers->call_method(fbc->common.function_name, call->object, call->num_args, EX_VAR(opline->result.var) TSRMLS_CC);
2756            EG(current_execute_data) = call->prev_execute_data;
2757        } else {
2758            zend_error_noreturn(E_ERROR, "Cannot call overloaded function for non-object");
2759        }
2760
2761        zend_vm_stack_free_args(call TSRMLS_CC);
2762
2763        zend_vm_stack_free_call_frame(call TSRMLS_CC);
2764
2765        if (fbc->type == ZEND_OVERLOADED_FUNCTION_TEMPORARY) {
2766            zend_string_release(fbc->common.function_name);
2767        }
2768        efree(fbc);
2769
2770        if (!RETURN_VALUE_USED(opline)) {
2771            zval_ptr_dtor(EX_VAR(opline->result.var));
2772        } else {
2773//???           Z_UNSET_ISREF_P(EX_T(opline->result.var).var.ptr);
2774//???           Z_SET_REFCOUNT_P(EX_T(opline->result.var).var.ptr, 1);
2775            Z_VAR_FLAGS_P(EX_VAR(opline->result.var)) = 0;
2776        }
2777    }
2778
2779ZEND_VM_C_LABEL(fcall_end_change_scope):
2780    if (Z_OBJ(EG(This))) {
2781        if (UNEXPECTED(EG(exception) != NULL) && (opline->op1.num & ZEND_CALL_CTOR)) {
2782            if (!(opline->op1.num & ZEND_CALL_CTOR_RESULT_UNUSED)) {
2783                Z_DELREF(EG(This));
2784            }
2785            if (Z_REFCOUNT(EG(This)) == 1) {
2786                zend_object_store_ctor_failed(Z_OBJ(EG(This)) TSRMLS_CC);
2787            }
2788        }
2789        if (!Z_DELREF(EG(This))) {
2790            _zval_dtor_func_for_ptr(Z_COUNTED(EG(This)) ZEND_FILE_LINE_CC);
2791        } else if (UNEXPECTED(!Z_GC_INFO(EG(This)))) {
2792            gc_possible_root(Z_COUNTED(EG(This)) TSRMLS_CC);
2793        }
2794    }
2795    Z_OBJ(EG(This)) = EX(object);
2796    EG(scope) = EX(scope);
2797
2798ZEND_VM_C_LABEL(fcall_end):
2799    if (UNEXPECTED(EG(exception) != NULL)) {
2800        zend_throw_exception_internal(NULL TSRMLS_CC);
2801        if (RETURN_VALUE_USED(opline)) {
2802            zval_ptr_dtor(EX_VAR(opline->result.var));
2803        }
2804        HANDLE_EXCEPTION();
2805    }
2806
2807    ZEND_VM_NEXT_OPCODE();
2808}
2809
2810ZEND_VM_HANDLER(62, ZEND_RETURN, CONST|TMP|VAR|CV, ANY)
2811{
2812    USE_OPLINE
2813    zval *retval_ptr;
2814    zend_free_op free_op1;
2815
2816    SAVE_OPLINE();
2817    retval_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
2818
2819    if (!EX(return_value)) {
2820        FREE_OP1();
2821    } else {
2822        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
2823            ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
2824            if (OP1_TYPE == IS_CONST) {
2825                if (UNEXPECTED(Z_OPT_COPYABLE_P(EX(return_value)))) {
2826                    zval_copy_ctor_func(EX(return_value));
2827                }
2828            }
2829        } else if (Z_ISREF_P(retval_ptr)) {
2830            ZVAL_COPY(EX(return_value), Z_REFVAL_P(retval_ptr));
2831            FREE_OP1_IF_VAR();
2832        } else {
2833            ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
2834            if (OP1_TYPE == IS_CV) {
2835                if (Z_OPT_REFCOUNTED_P(retval_ptr)) Z_ADDREF_P(retval_ptr);
2836            }
2837        }
2838    }
2839    ZEND_VM_DISPATCH_TO_HELPER(zend_leave_helper);
2840}
2841
2842ZEND_VM_HANDLER(111, ZEND_RETURN_BY_REF, CONST|TMP|VAR|CV, ANY)
2843{
2844    USE_OPLINE
2845    zval *retval_ptr;
2846    zend_free_op free_op1;
2847
2848    SAVE_OPLINE();
2849
2850    do {
2851        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR ||
2852            (OP1_TYPE == IS_VAR && opline->extended_value == ZEND_RETURNS_VALUE)) {
2853            /* Not supposed to happen, but we'll allow it */
2854            zend_error(E_NOTICE, "Only variable references should be returned by reference");
2855
2856            retval_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
2857            if (!EX(return_value)) {
2858                if (OP1_TYPE == IS_TMP_VAR) {
2859                    FREE_OP1();
2860                }
2861            } else {
2862                ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
2863                if (OP1_TYPE != IS_TMP_VAR) {
2864                    zval_opt_copy_ctor_no_imm(EX(return_value));
2865                }
2866            }
2867            break;
2868        }
2869
2870        retval_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
2871
2872        if (OP1_TYPE == IS_VAR && UNEXPECTED(retval_ptr == NULL)) {
2873            zend_error_noreturn(E_ERROR, "Cannot return string offsets by reference");
2874        }
2875
2876        if (OP1_TYPE == IS_VAR && !Z_ISREF_P(retval_ptr)) {
2877            if (opline->extended_value == ZEND_RETURNS_FUNCTION &&
2878                (Z_VAR_FLAGS_P(retval_ptr) & IS_VAR_RET_REF)) {
2879            } else {
2880                zend_error(E_NOTICE, "Only variable references should be returned by reference");
2881                if (EX(return_value)) {
2882                    zval tmp;
2883                    ZVAL_DUP(&tmp, retval_ptr);
2884                    ZVAL_NEW_REF(EX(return_value), &tmp);
2885                }
2886                break;
2887            }
2888        }
2889
2890        if (EX(return_value)) {
2891            ZVAL_MAKE_REF(retval_ptr);
2892            Z_ADDREF_P(retval_ptr);
2893            ZVAL_REF(EX(return_value), Z_REF_P(retval_ptr));
2894        }
2895    } while (0);
2896
2897    FREE_OP1_VAR_PTR();
2898    ZEND_VM_DISPATCH_TO_HELPER(zend_leave_helper);
2899}
2900
2901ZEND_VM_HANDLER(161, ZEND_GENERATOR_RETURN, ANY, ANY)
2902{
2903    /* The generator object is stored in EX(return_value) */
2904    zend_generator *generator = (zend_generator *) EX(return_value);
2905
2906    /* Close the generator to free up resources */
2907    zend_generator_close(generator, 1 TSRMLS_CC);
2908
2909    /* Pass execution back to handling code */
2910    ZEND_VM_RETURN();
2911}
2912
2913ZEND_VM_HANDLER(108, ZEND_THROW, CONST|TMP|VAR|CV, ANY)
2914{
2915    USE_OPLINE
2916    zval *value;
2917    zend_free_op free_op1;
2918
2919    SAVE_OPLINE();
2920    value = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
2921
2922    if (OP1_TYPE == IS_CONST || UNEXPECTED(Z_TYPE_P(value) != IS_OBJECT)) {
2923        if (UNEXPECTED(EG(exception) != NULL)) {
2924            HANDLE_EXCEPTION();
2925        }
2926        zend_error_noreturn(E_ERROR, "Can only throw objects");
2927    }
2928
2929    zend_exception_save(TSRMLS_C);
2930    if (OP1_TYPE != IS_TMP_VAR) {
2931        if (Z_REFCOUNTED_P(value)) Z_ADDREF_P(value);
2932    }
2933
2934    zend_throw_exception_object(value TSRMLS_CC);
2935    zend_exception_restore(TSRMLS_C);
2936    FREE_OP1_IF_VAR();
2937    HANDLE_EXCEPTION();
2938}
2939
2940ZEND_VM_HANDLER(107, ZEND_CATCH, CONST, CV)
2941{
2942    USE_OPLINE
2943    zend_class_entry *ce, *catch_ce;
2944    zend_object *exception;
2945
2946    SAVE_OPLINE();
2947    /* Check whether an exception has been thrown, if not, jump over code */
2948    zend_exception_restore(TSRMLS_C);
2949    if (EG(exception) == NULL) {
2950        ZEND_VM_SET_OPCODE(&EX(func)->op_array.opcodes[opline->extended_value]);
2951        ZEND_VM_CONTINUE(); /* CHECK_ME */
2952    }
2953    if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op1.zv))) {
2954        catch_ce = CACHED_PTR(Z_CACHE_SLOT_P(opline->op1.zv));
2955    } else {
2956        catch_ce = zend_fetch_class_by_name(Z_STR_P(opline->op1.zv), opline->op1.zv + 1, ZEND_FETCH_CLASS_NO_AUTOLOAD TSRMLS_CC);
2957
2958        CACHE_PTR(Z_CACHE_SLOT_P(opline->op1.zv), catch_ce);
2959    }
2960    ce = zend_get_class_entry(EG(exception) TSRMLS_CC);
2961
2962#ifdef HAVE_DTRACE
2963    if (DTRACE_EXCEPTION_CAUGHT_ENABLED()) {
2964        DTRACE_EXCEPTION_CAUGHT((char *)ce->name);
2965    }
2966#endif /* HAVE_DTRACE */
2967
2968    if (ce != catch_ce) {
2969        if (!instanceof_function(ce, catch_ce TSRMLS_CC)) {
2970            if (opline->result.num) {
2971                zend_throw_exception_internal(NULL TSRMLS_CC);
2972                HANDLE_EXCEPTION();
2973            }
2974            ZEND_VM_SET_OPCODE(&EX(func)->op_array.opcodes[opline->extended_value]);
2975            ZEND_VM_CONTINUE(); /* CHECK_ME */
2976        }
2977    }
2978
2979    exception = EG(exception);
2980    if (Z_REFCOUNTED_P(EX_VAR(opline->op2.var))) {
2981        zval_ptr_dtor(EX_VAR(opline->op2.var));
2982    }
2983    ZVAL_OBJ(EX_VAR(opline->op2.var), EG(exception));
2984    if (UNEXPECTED(EG(exception) != exception)) {
2985        GC_REFCOUNT(EG(exception))++;
2986        HANDLE_EXCEPTION();
2987    } else {
2988        EG(exception) = NULL;
2989        ZEND_VM_NEXT_OPCODE();
2990    }
2991}
2992
2993ZEND_VM_HANDLER(65, ZEND_SEND_VAL, CONST|TMP, ANY)
2994{
2995    USE_OPLINE
2996    zval *value, *arg;
2997    zend_free_op free_op1;
2998
2999    SAVE_OPLINE();
3000    value = GET_OP1_ZVAL_PTR(BP_VAR_R);
3001    arg = ZEND_CALL_ARG(EX(call), opline->op2.num);
3002    EX(call)->num_args = opline->op2.num;
3003    ZVAL_COPY_VALUE(arg, value);
3004    if (OP1_TYPE == IS_CONST) {
3005        if (UNEXPECTED(Z_OPT_COPYABLE_P(arg))) {
3006            zval_copy_ctor_func(arg);
3007        }
3008    }
3009    ZEND_VM_NEXT_OPCODE();
3010}
3011
3012ZEND_VM_HANDLER(116, ZEND_SEND_VAL_EX, CONST|TMP, ANY)
3013{
3014    USE_OPLINE
3015    zval *value, *arg;
3016    zend_free_op free_op1;
3017
3018    SAVE_OPLINE();
3019    if (ARG_MUST_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3020        zend_error_noreturn(E_ERROR, "Cannot pass parameter %d by reference", opline->op2.num);
3021    }
3022    value = GET_OP1_ZVAL_PTR(BP_VAR_R);
3023    arg = ZEND_CALL_ARG(EX(call), opline->op2.num);
3024    EX(call)->num_args = opline->op2.num;
3025    ZVAL_COPY_VALUE(arg, value);
3026    if (OP1_TYPE == IS_CONST) {
3027        if (UNEXPECTED(Z_OPT_COPYABLE_P(arg))) {
3028            zval_copy_ctor_func(arg);
3029        }
3030    }
3031    ZEND_VM_NEXT_OPCODE();
3032}
3033
3034ZEND_VM_HANDLER(117, ZEND_SEND_VAR, VAR|CV, ANY)
3035{
3036    USE_OPLINE
3037    zval *varptr, *arg;
3038    zend_free_op free_op1;
3039
3040    varptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
3041    arg = ZEND_CALL_ARG(EX(call), opline->op2.num);
3042    EX(call)->num_args = opline->op2.num;
3043    if (Z_ISREF_P(varptr)) {
3044        ZVAL_COPY(arg, Z_REFVAL_P(varptr));
3045        FREE_OP1();
3046    } else {
3047        ZVAL_COPY_VALUE(arg, varptr);
3048        if (OP1_TYPE == IS_CV) {
3049            if (Z_OPT_REFCOUNTED_P(arg)) Z_ADDREF_P(arg);
3050        }
3051    }
3052    ZEND_VM_NEXT_OPCODE();
3053}
3054
3055ZEND_VM_HANDLER(106, ZEND_SEND_VAR_NO_REF, VAR|CV, ANY)
3056{
3057    USE_OPLINE
3058    zend_free_op free_op1;
3059    zval *varptr, *arg;
3060
3061    SAVE_OPLINE();
3062    if (opline->extended_value & ZEND_ARG_COMPILE_TIME_BOUND) { /* Had function_ptr at compile_time */
3063        if (!(opline->extended_value & ZEND_ARG_SEND_BY_REF)) {
3064            ZEND_VM_DISPATCH_TO_HANDLER(ZEND_SEND_VAR);
3065        }
3066    } else {
3067        if (!ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3068            ZEND_VM_DISPATCH_TO_HANDLER(ZEND_SEND_VAR);
3069        }
3070    }
3071
3072    varptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
3073    if ((!(opline->extended_value & ZEND_ARG_SEND_FUNCTION) ||
3074         (Z_VAR_FLAGS_P(varptr) & IS_VAR_RET_REF)) &&
3075        (Z_ISREF_P(varptr) || Z_TYPE_P(varptr) == IS_OBJECT)) {
3076
3077        ZVAL_MAKE_REF(varptr);
3078        if (OP1_TYPE == IS_CV) {
3079            Z_ADDREF_P(varptr);
3080        }
3081        arg = ZEND_CALL_ARG(EX(call), opline->op2.num);
3082        EX(call)->num_args = opline->op2.num;
3083        ZVAL_COPY_VALUE(arg, varptr);
3084    } else {
3085        if ((opline->extended_value & ZEND_ARG_COMPILE_TIME_BOUND) ?
3086            !(opline->extended_value & ZEND_ARG_SEND_SILENT) :
3087            !ARG_MAY_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3088            zend_error(E_STRICT, "Only variables should be passed by reference");
3089        }
3090        arg = ZEND_CALL_ARG(EX(call), opline->op2.num);
3091        EX(call)->num_args = opline->op2.num;
3092        ZVAL_COPY(arg, varptr);
3093        FREE_OP1_IF_VAR();
3094    }
3095    CHECK_EXCEPTION();
3096    ZEND_VM_NEXT_OPCODE();
3097}
3098
3099ZEND_VM_HANDLER(67, ZEND_SEND_REF, VAR|CV, ANY)
3100{
3101    USE_OPLINE
3102    zend_free_op free_op1;
3103    zval *varptr, *arg;
3104
3105    SAVE_OPLINE();
3106    varptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
3107
3108    if (OP1_TYPE == IS_VAR && UNEXPECTED(varptr == NULL)) {
3109        zend_error_noreturn(E_ERROR, "Only variables can be passed by reference");
3110    }
3111
3112    arg = ZEND_CALL_ARG(EX(call), opline->op2.num);
3113    EX(call)->num_args = opline->op2.num;
3114    if (OP1_TYPE == IS_VAR && UNEXPECTED(varptr == &EG(error_zval))) {
3115        ZVAL_NEW_REF(arg, &EG(uninitialized_zval));
3116        ZEND_VM_NEXT_OPCODE();
3117    }
3118
3119    if (Z_ISREF_P(varptr)) {
3120        Z_ADDREF_P(varptr);
3121        ZVAL_COPY_VALUE(arg, varptr);
3122    } else if (OP1_TYPE == IS_VAR &&
3123        UNEXPECTED(Z_TYPE_P(EX_VAR(opline->op1.var)) != IS_INDIRECT)) {
3124        ZVAL_COPY_VALUE(arg, varptr);
3125        ZVAL_MAKE_REF(arg);
3126    } else {
3127        ZVAL_MAKE_REF(varptr);
3128        Z_ADDREF_P(varptr);
3129        ZVAL_REF(arg, Z_REF_P(varptr));
3130    }
3131
3132    FREE_OP1_VAR_PTR();
3133    ZEND_VM_NEXT_OPCODE();
3134}
3135
3136ZEND_VM_HANDLER(66, ZEND_SEND_VAR_EX, VAR|CV, ANY)
3137{
3138    USE_OPLINE
3139    zval *varptr, *arg;
3140    zend_free_op free_op1;
3141
3142    if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3143        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_SEND_REF);
3144    }
3145    varptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
3146    arg = ZEND_CALL_ARG(EX(call), opline->op2.num);
3147    EX(call)->num_args = opline->op2.num;
3148    if (Z_ISREF_P(varptr)) {
3149        ZVAL_COPY(arg, Z_REFVAL_P(varptr));
3150        FREE_OP1();
3151    } else {
3152        ZVAL_COPY_VALUE(arg, varptr);
3153        if (OP1_TYPE == IS_CV) {
3154            if (Z_OPT_REFCOUNTED_P(arg)) Z_ADDREF_P(arg);
3155        }
3156    }
3157    ZEND_VM_NEXT_OPCODE();
3158}
3159
3160ZEND_VM_HANDLER(165, ZEND_SEND_UNPACK, ANY, ANY)
3161{
3162    USE_OPLINE
3163    zend_free_op free_op1;
3164    zval *args;
3165    int arg_num;
3166    SAVE_OPLINE();
3167
3168    args = GET_OP1_ZVAL_PTR(BP_VAR_R);
3169    arg_num = EX(call)->num_args + 1;
3170
3171ZEND_VM_C_LABEL(send_again):
3172    switch (Z_TYPE_P(args)) {
3173        case IS_ARRAY: {
3174            HashTable *ht = Z_ARRVAL_P(args);
3175            zval *arg, *top;
3176            zend_string *name;
3177
3178            zend_vm_stack_extend_call_frame(&EX(call), arg_num - 1, zend_hash_num_elements(ht) TSRMLS_CC);
3179
3180            if (OP1_TYPE != IS_CONST && OP1_TYPE != IS_TMP_VAR && Z_IMMUTABLE_P(args)) {
3181                uint32_t i;
3182                int separate = 0;
3183
3184                /* check if any of arguments are going to be passed by reference */
3185                for (i = 0; i < zend_hash_num_elements(ht); i++) {
3186                    if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num + i)) {
3187                        separate = 1;
3188                        break;
3189                    }
3190                }
3191                if (separate) {
3192                    zval_copy_ctor(args);
3193                    ht = Z_ARRVAL_P(args);
3194                }
3195            }
3196
3197            ZEND_HASH_FOREACH_STR_KEY_VAL(ht, name, arg) {
3198                if (name) {
3199                    zend_error(E_RECOVERABLE_ERROR, "Cannot unpack array with string keys");
3200                    FREE_OP1();
3201                    CHECK_EXCEPTION();
3202                    ZEND_VM_NEXT_OPCODE();
3203                }
3204
3205                top = ZEND_CALL_ARG(EX(call), arg_num);
3206                if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
3207                    if (!Z_IMMUTABLE_P(args)) {
3208                        ZVAL_MAKE_REF(arg);
3209                        Z_ADDREF_P(arg);
3210                        ZVAL_REF(top, Z_REF_P(arg));
3211                    } else {
3212                        ZVAL_DUP(top, arg);
3213                    }
3214                } else if (Z_ISREF_P(arg)) {
3215                    ZVAL_COPY(top, Z_REFVAL_P(arg));
3216                } else {
3217                    ZVAL_COPY(top, arg);
3218                }
3219
3220                EX(call)->num_args++;
3221                arg_num++;
3222            } ZEND_HASH_FOREACH_END();
3223
3224            break;
3225        }
3226        case IS_OBJECT: {
3227            zend_class_entry *ce = Z_OBJCE_P(args);
3228            zend_object_iterator *iter;
3229
3230            if (!ce || !ce->get_iterator) {
3231                zend_error(E_WARNING, "Only arrays and Traversables can be unpacked");
3232                break;
3233            }
3234
3235            iter = ce->get_iterator(ce, args, 0 TSRMLS_CC);
3236            if (UNEXPECTED(!iter)) {
3237                FREE_OP1();
3238                if (!EG(exception)) {
3239                    zend_throw_exception_ex(
3240                        NULL, 0 TSRMLS_CC, "Object of type %s did not create an Iterator", ce->name->val
3241                    );
3242                }
3243                HANDLE_EXCEPTION();
3244            }
3245
3246            if (iter->funcs->rewind) {
3247                iter->funcs->rewind(iter TSRMLS_CC);
3248                if (UNEXPECTED(EG(exception) != NULL)) {
3249                    ZEND_VM_C_GOTO(unpack_iter_dtor);
3250                }
3251            }
3252
3253            for (; iter->funcs->valid(iter TSRMLS_CC) == SUCCESS; ++arg_num) {
3254                zval *arg, *top;
3255
3256                if (UNEXPECTED(EG(exception) != NULL)) {
3257                    ZEND_VM_C_GOTO(unpack_iter_dtor);
3258                }
3259
3260                arg = iter->funcs->get_current_data(iter TSRMLS_CC);
3261                if (UNEXPECTED(EG(exception) != NULL)) {
3262                    ZEND_VM_C_GOTO(unpack_iter_dtor);
3263                }
3264
3265                if (iter->funcs->get_current_key) {
3266                    zval key;
3267                    iter->funcs->get_current_key(iter, &key TSRMLS_CC);
3268                    if (UNEXPECTED(EG(exception) != NULL)) {
3269                        ZEND_VM_C_GOTO(unpack_iter_dtor);
3270                    }
3271
3272                    if (Z_TYPE(key) == IS_STRING) {
3273                        zend_error(E_RECOVERABLE_ERROR,
3274                            "Cannot unpack Traversable with string keys");
3275                        zval_dtor(&key);
3276                        ZEND_VM_C_GOTO(unpack_iter_dtor);
3277                    }
3278
3279                    zval_dtor(&key);
3280                }
3281
3282                if (ARG_MUST_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
3283                    zend_error(
3284                        E_WARNING, "Cannot pass by-reference argument %d of %s%s%s()"
3285                        " by unpacking a Traversable, passing by-value instead", arg_num,
3286                        EX(call)->func->common.scope ? EX(call)->func->common.scope->name->val : "",
3287                        EX(call)->func->common.scope ? "::" : "",
3288                        EX(call)->func->common.function_name->val
3289                    );
3290                }
3291
3292                if (Z_ISREF_P(arg)) {
3293                    ZVAL_DUP(arg, Z_REFVAL_P(arg));
3294                } else {
3295                    if (Z_REFCOUNTED_P(arg)) Z_ADDREF_P(arg);
3296                }
3297
3298                zend_vm_stack_extend_call_frame(&EX(call), arg_num - 1, 1 TSRMLS_CC);
3299                top = ZEND_CALL_ARG(EX(call), arg_num);
3300                ZVAL_COPY_VALUE(top, arg);
3301                EX(call)->num_args++;
3302
3303                iter->funcs->move_forward(iter TSRMLS_CC);
3304                if (UNEXPECTED(EG(exception) != NULL)) {
3305                    ZEND_VM_C_GOTO(unpack_iter_dtor);
3306                }
3307            }
3308
3309ZEND_VM_C_LABEL(unpack_iter_dtor):
3310            zend_iterator_dtor(iter TSRMLS_CC);
3311            break;
3312        }
3313        case IS_REFERENCE:
3314            args = Z_REFVAL_P(args);
3315            ZEND_VM_C_GOTO(send_again);
3316            break;
3317        default:
3318            zend_error(E_WARNING, "Only arrays and Traversables can be unpacked");
3319    }
3320
3321    FREE_OP1();
3322    CHECK_EXCEPTION();
3323    ZEND_VM_NEXT_OPCODE();
3324}
3325
3326ZEND_VM_HANDLER(119, ZEND_SEND_ARRAY, ANY, ANY)
3327{
3328    USE_OPLINE
3329    zend_free_op free_op1;
3330    zval *args;
3331    SAVE_OPLINE();
3332
3333    args = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
3334
3335    if (Z_TYPE_P(args) != IS_ARRAY) {
3336        zend_error(E_WARNING, "call_user_func_array() expects parameter 2 to be array, %s given", zend_get_type_by_const(Z_TYPE_P(args)));
3337        if (EX(call)->func->common.fn_flags & ZEND_ACC_CLOSURE) {
3338            OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
3339        }
3340        if (EX(call)->object) {
3341            OBJ_RELEASE(EX(call)->object);
3342        }
3343        EX(call)->func = (zend_function*)&zend_pass_function;
3344        EX(call)->called_scope = NULL;
3345        EX(call)->object = NULL;
3346    } else {
3347        uint32_t arg_num = 1;
3348
3349        HashTable *ht = Z_ARRVAL_P(args);
3350        zval *arg, *param, tmp;
3351
3352        zend_vm_stack_extend_call_frame(&EX(call), 0, zend_hash_num_elements(ht) TSRMLS_CC);
3353
3354        if (OP1_TYPE != IS_CONST && OP1_TYPE != IS_TMP_VAR && Z_IMMUTABLE_P(args)) {
3355            uint32_t i;
3356            int separate = 0;
3357
3358            /* check if any of arguments are going to be passed by reference */
3359            for (i = 0; i < zend_hash_num_elements(ht); i++) {
3360                if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num + i)) {
3361                    separate = 1;
3362                    break;
3363                }
3364            }
3365            if (separate) {
3366                zval_copy_ctor(args);
3367                ht = Z_ARRVAL_P(args);
3368            }
3369        }
3370
3371        param = ZEND_CALL_ARG(EX(call), arg_num);
3372        ZEND_HASH_FOREACH_VAL(ht, arg) {
3373            if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
3374                // TODO: Scalar values don't have reference counters anymore.
3375                // They are assumed to be 1, and they may be easily passed by
3376                // reference now. However, previously scalars with refcount==1
3377                // might be passed and with refcount>1 might not. We can support
3378                // only single behavior ???
3379#if 0
3380                if (Z_REFCOUNTED_P(arg) &&
3381                    // This solution breaks the following test (omit warning message) ???
3382                    // Zend/tests/bug61273.phpt
3383                    // ext/reflection/tests/bug42976.phpt
3384                    // ext/standard/tests/general_functions/call_user_func_array_variation_001.phpt
3385#else
3386                if (!Z_REFCOUNTED_P(arg) ||
3387                    // This solution breaks the following test (emit warning message) ???
3388                    // ext/pdo_sqlite/tests/pdo_005.phpt
3389#endif
3390                    (!Z_ISREF_P(arg) && Z_REFCOUNT_P(arg) > 1)) {
3391
3392                    if (!ARG_MAY_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
3393
3394                        zend_error(E_WARNING, "Parameter %d to %s%s%s() expected to be a reference, value given",
3395                            arg_num,
3396                            EX(call)->func->common.scope ? EX(call)->func->common.scope->name->val : "",
3397                            EX(call)->func->common.scope ? "::" : "",
3398                            EX(call)->func->common.function_name->val);
3399
3400                        if (EX(call)->func->common.fn_flags & ZEND_ACC_CLOSURE) {
3401                            OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
3402                        }
3403                        if (EX(call)->object) {
3404                            OBJ_RELEASE(EX(call)->object);
3405                        }
3406                        EX(call)->func = (zend_function*)&zend_pass_function;
3407                        EX(call)->called_scope = NULL;
3408                        EX(call)->object = NULL;
3409
3410                        break;
3411                    }
3412
3413                    if (Z_REFCOUNTED_P(arg)) {
3414                        Z_DELREF_P(arg);
3415                    }
3416                    ZVAL_DUP(&tmp, arg);
3417                    ZVAL_NEW_REF(arg, &tmp);
3418                    Z_ADDREF_P(arg);
3419                } else if (!Z_ISREF_P(arg)) {
3420                    ZVAL_NEW_REF(arg, arg);
3421                    Z_ADDREF_P(arg);
3422                } else if (Z_REFCOUNTED_P(arg)) {
3423                    Z_ADDREF_P(arg);
3424                }
3425                ZVAL_COPY_VALUE(param, arg);
3426            } else if (Z_ISREF_P(arg) &&
3427                   /* don't separate references for __call */
3428                   (EX(call)->func->common.fn_flags & ZEND_ACC_CALL_VIA_HANDLER) == 0) {
3429                ZVAL_DUP(param, Z_REFVAL_P(arg));
3430            } else {
3431                ZVAL_COPY(param, arg);
3432            }
3433            EX(call)->num_args++;
3434            arg_num++;
3435            param++;
3436        } ZEND_HASH_FOREACH_END();
3437    }
3438    FREE_OP1();
3439    CHECK_EXCEPTION();
3440    ZEND_VM_NEXT_OPCODE();
3441}
3442
3443ZEND_VM_HANDLER(120, ZEND_SEND_USER, VAR|CV, ANY)
3444{
3445    USE_OPLINE
3446    zval *arg, *param, tmp;
3447    zend_free_op free_op1;
3448
3449    arg = GET_OP1_ZVAL_PTR(BP_VAR_R);
3450    param = ZEND_CALL_ARG(EX(call), opline->op2.num);
3451
3452    if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3453        // TODO: Scalar values don't have reference counters anymore.
3454        // They are assumed to be 1, and they may be easily passed by
3455        // reference now. However, previously scalars with refcount==1
3456        // might be passed and with refcount>1 might not. We can support
3457        // only single behavior ???
3458#if 0
3459        if (Z_REFCOUNTED_P(arg) &&
3460            // This solution breaks the following test (omit warning message) ???
3461            // Zend/tests/bug61273.phpt
3462            // ext/reflection/tests/bug42976.phpt
3463            // ext/standard/tests/general_functions/call_user_func_array_variation_001.phpt
3464#else
3465        if (!Z_REFCOUNTED_P(arg) ||
3466            // This solution breaks the following test (emit warning message) ???
3467            // ext/pdo_sqlite/tests/pdo_005.phpt
3468#endif
3469            (!Z_ISREF_P(arg) /*&& Z_REFCOUNT_P(arg) > 1???*/)) {
3470
3471            if (!ARG_MAY_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3472
3473                zend_error(E_WARNING, "Parameter %d to %s%s%s() expected to be a reference, value given",
3474                    opline->op2.num,
3475                    EX(call)->func->common.scope ? EX(call)->func->common.scope->name->val : "",
3476                    EX(call)->func->common.scope ? "::" : "",
3477                    EX(call)->func->common.function_name->val);
3478
3479                if (EX(call)->func->common.fn_flags & ZEND_ACC_CLOSURE) {
3480                    OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
3481                }
3482                if (EX(call)->object) {
3483                    OBJ_RELEASE(EX(call)->object);
3484                }
3485                EX(call)->func = (zend_function*)&zend_pass_function;
3486                EX(call)->called_scope = NULL;
3487                EX(call)->object = NULL;
3488
3489                FREE_OP1();
3490                CHECK_EXCEPTION();
3491                ZEND_VM_NEXT_OPCODE();
3492            }
3493
3494            if (Z_REFCOUNTED_P(arg)) {
3495                Z_DELREF_P(arg);
3496            }
3497            ZVAL_DUP(&tmp, arg);
3498            ZVAL_NEW_REF(arg, &tmp);
3499            Z_ADDREF_P(arg);
3500        } else if (!Z_ISREF_P(arg)) {
3501            ZVAL_NEW_REF(arg, arg);
3502            Z_ADDREF_P(arg);
3503        } else if (Z_REFCOUNTED_P(arg)) {
3504            Z_ADDREF_P(arg);
3505        }
3506        ZVAL_COPY_VALUE(param, arg);
3507    } else if (Z_ISREF_P(arg) &&
3508               /* don't separate references for __call */
3509               (EX(call)->func->common.fn_flags & ZEND_ACC_CALL_VIA_HANDLER) == 0) {
3510        ZVAL_DUP(param, Z_REFVAL_P(arg));
3511    } else {
3512        ZVAL_COPY(param, arg);
3513    }
3514
3515    EX(call)->num_args = opline->op2.num;
3516
3517    FREE_OP1();
3518    CHECK_EXCEPTION();
3519    ZEND_VM_NEXT_OPCODE();
3520}
3521
3522ZEND_VM_HANDLER(63, ZEND_RECV, ANY, ANY)
3523{
3524    USE_OPLINE
3525    uint32_t arg_num = opline->op1.num;
3526
3527    SAVE_OPLINE();
3528    if (UNEXPECTED(arg_num > EX(num_args))) {
3529        zend_verify_missing_arg(execute_data, arg_num TSRMLS_CC);
3530        CHECK_EXCEPTION();
3531    } else if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
3532        zval *param = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var TSRMLS_CC);
3533
3534        zend_verify_arg_type(EX(func), arg_num, param, opline->extended_value TSRMLS_CC);
3535        CHECK_EXCEPTION();
3536    }
3537
3538    ZEND_VM_NEXT_OPCODE();
3539}
3540
3541ZEND_VM_HANDLER(64, ZEND_RECV_INIT, ANY, CONST)
3542{
3543    USE_OPLINE
3544    uint32_t arg_num = opline->op1.num;
3545    zval *param;
3546
3547    SAVE_OPLINE();
3548    param = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var TSRMLS_CC);
3549    if (arg_num > EX(num_args)) {
3550        ZVAL_COPY_VALUE(param, opline->op2.zv);
3551        if (Z_OPT_CONSTANT_P(param)) {
3552            zval_update_constant(param, 0 TSRMLS_CC);
3553        } else {
3554            /* IS_CONST can't be IS_OBJECT, IS_RESOURCE or IS_REFERENCE */
3555            if (UNEXPECTED(Z_OPT_COPYABLE_P(param))) {
3556                zval_copy_ctor_func(param);
3557            }
3558        }
3559    }
3560
3561    if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
3562        zend_verify_arg_type(EX(func), arg_num, param, opline->extended_value TSRMLS_CC);
3563    }
3564
3565    CHECK_EXCEPTION();
3566    ZEND_VM_NEXT_OPCODE();
3567}
3568
3569ZEND_VM_HANDLER(164, ZEND_RECV_VARIADIC, ANY, ANY)
3570{
3571    USE_OPLINE
3572    uint32_t arg_num = opline->op1.num;
3573    uint32_t arg_count = EX(num_args);
3574    zval *params;
3575
3576    SAVE_OPLINE();
3577
3578    params = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var TSRMLS_CC);
3579
3580    if (arg_num <= arg_count) {
3581        zval *param;
3582
3583        array_init_size(params, arg_count - arg_num + 1);
3584        param = EX_VAR_NUM(EX(func)->op_array.last_var + EX(func)->op_array.T);
3585        if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
3586            do {
3587                zend_verify_arg_type(EX(func), arg_num, param, opline->extended_value TSRMLS_CC);
3588                zend_hash_next_index_insert_new(Z_ARRVAL_P(params), param);
3589                if (Z_REFCOUNTED_P(param)) Z_ADDREF_P(param);
3590                param++;
3591            } while (++arg_num <= arg_count);
3592        } else {
3593            do {
3594                zend_hash_next_index_insert_new(Z_ARRVAL_P(params), param);
3595                if (Z_REFCOUNTED_P(param)) Z_ADDREF_P(param);
3596                param++;
3597            } while (++arg_num <= arg_count);
3598        }
3599    } else {
3600        array_init(params);
3601    }
3602
3603    CHECK_EXCEPTION();
3604    ZEND_VM_NEXT_OPCODE();
3605}
3606
3607ZEND_VM_HANDLER(52, ZEND_BOOL, CONST|TMP|VAR|CV, ANY)
3608{
3609    USE_OPLINE
3610    zend_free_op free_op1;
3611    zval *retval = EX_VAR(opline->result.var);
3612
3613    SAVE_OPLINE();
3614    /* PHP 3.0 returned "" for false and 1 for true, here we use 0 and 1 for now */
3615    ZVAL_BOOL(retval, i_zend_is_true(GET_OP1_ZVAL_PTR(BP_VAR_R) TSRMLS_CC));
3616    FREE_OP1();
3617
3618    CHECK_EXCEPTION();
3619    ZEND_VM_NEXT_OPCODE();
3620}
3621
3622ZEND_VM_HANDLER(50, ZEND_BRK, ANY, CONST)
3623{
3624    USE_OPLINE
3625    zend_brk_cont_element *el;
3626
3627    SAVE_OPLINE();
3628    el = zend_brk_cont(Z_LVAL_P(opline->op2.zv), opline->op1.opline_num,
3629                       &EX(func)->op_array, execute_data TSRMLS_CC);
3630    ZEND_VM_JMP(EX(func)->op_array.opcodes + el->brk);
3631}
3632
3633ZEND_VM_HANDLER(51, ZEND_CONT, ANY, CONST)
3634{
3635    USE_OPLINE
3636    zend_brk_cont_element *el;
3637
3638    SAVE_OPLINE();
3639    el = zend_brk_cont(Z_LVAL_P(opline->op2.zv), opline->op1.opline_num,
3640                       &EX(func)->op_array, execute_data TSRMLS_CC);
3641    ZEND_VM_JMP(EX(func)->op_array.opcodes + el->cont);
3642}
3643
3644ZEND_VM_HANDLER(100, ZEND_GOTO, ANY, CONST)
3645{
3646    zend_op *brk_opline;
3647    USE_OPLINE
3648    zend_brk_cont_element *el;
3649
3650    SAVE_OPLINE();
3651    el = zend_brk_cont(Z_LVAL_P(opline->op2.zv), opline->extended_value,
3652                       &EX(func)->op_array, execute_data TSRMLS_CC);
3653
3654    brk_opline = EX(func)->op_array.opcodes + el->brk;
3655
3656    if (brk_opline->opcode == ZEND_SWITCH_FREE) {
3657        if (!(brk_opline->extended_value & EXT_TYPE_FREE_ON_RETURN)) {
3658            zval_ptr_dtor(EX_VAR(brk_opline->op1.var));
3659        }
3660    } else if (brk_opline->opcode == ZEND_FREE) {
3661        if (!(brk_opline->extended_value & EXT_TYPE_FREE_ON_RETURN)) {
3662            zval_dtor(EX_VAR(brk_opline->op1.var));
3663        }
3664    }
3665    ZEND_VM_JMP(opline->op1.jmp_addr);
3666}
3667
3668ZEND_VM_HANDLER(48, ZEND_CASE, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
3669{
3670    USE_OPLINE
3671    zend_free_op free_op1, free_op2;
3672    zval *result = EX_VAR(opline->result.var);
3673
3674    SAVE_OPLINE();
3675    fast_equal_function(result,
3676         GET_OP1_ZVAL_PTR(BP_VAR_R),
3677         GET_OP2_ZVAL_PTR(BP_VAR_R) TSRMLS_CC);
3678
3679    FREE_OP2();
3680    CHECK_EXCEPTION();
3681    ZEND_VM_NEXT_OPCODE();
3682}
3683
3684ZEND_VM_HANDLER(49, ZEND_SWITCH_FREE, VAR, ANY)
3685{
3686    USE_OPLINE
3687
3688    SAVE_OPLINE();
3689    zval_ptr_dtor(EX_VAR(opline->op1.var));
3690    CHECK_EXCEPTION();
3691    ZEND_VM_NEXT_OPCODE();
3692}
3693
3694ZEND_VM_HANDLER(68, ZEND_NEW, ANY, ANY)
3695{
3696    USE_OPLINE
3697    zval object_zval;
3698    zend_function *constructor;
3699
3700    SAVE_OPLINE();
3701    if (UNEXPECTED((Z_CE_P(EX_VAR(opline->op1.var))->ce_flags & (ZEND_ACC_INTERFACE|ZEND_ACC_IMPLICIT_ABSTRACT_CLASS|ZEND_ACC_EXPLICIT_ABSTRACT_CLASS)) != 0)) {
3702        if (Z_CE_P(EX_VAR(opline->op1.var))->ce_flags & ZEND_ACC_INTERFACE) {
3703            zend_error_noreturn(E_ERROR, "Cannot instantiate interface %s", Z_CE_P(EX_VAR(opline->op1.var))->name->val);
3704        } else if ((Z_CE_P(EX_VAR(opline->op1.var))->ce_flags & ZEND_ACC_TRAIT) == ZEND_ACC_TRAIT) {
3705            zend_error_noreturn(E_ERROR, "Cannot instantiate trait %s", Z_CE_P(EX_VAR(opline->op1.var))->name->val);
3706        } else {
3707            zend_error_noreturn(E_ERROR, "Cannot instantiate abstract class %s", Z_CE_P(EX_VAR(opline->op1.var))->name->val);
3708        }
3709    }
3710    object_init_ex(&object_zval, Z_CE_P(EX_VAR(opline->op1.var)));
3711    constructor = Z_OBJ_HT(object_zval)->get_constructor(Z_OBJ(object_zval) TSRMLS_CC);
3712
3713    if (constructor == NULL) {
3714        if (RETURN_VALUE_USED(opline)) {
3715            ZVAL_COPY_VALUE(EX_VAR(opline->result.var), &object_zval);
3716        } else {
3717            zval_ptr_dtor(&object_zval);
3718        }
3719        ZEND_VM_JMP(opline->op2.jmp_addr);
3720    } else {
3721        /* We are not handling overloaded classes right now */
3722        EX(call) = zend_vm_stack_push_call_frame(
3723            constructor, opline->extended_value,
3724            RETURN_VALUE_USED(opline) ?
3725                ZEND_CALL_CTOR : (ZEND_CALL_CTOR | ZEND_CALL_CTOR_RESULT_UNUSED),
3726            Z_CE_P(EX_VAR(opline->op1.var)),
3727            Z_OBJ(object_zval),
3728            EX(call) TSRMLS_CC);
3729
3730        if (RETURN_VALUE_USED(opline)) {
3731            ZVAL_COPY(EX_VAR(opline->result.var), &object_zval);
3732            EX(call)->return_value = EX_VAR(opline->result.var);
3733        } else {
3734            EX(call)->return_value = NULL;
3735        }
3736
3737        CHECK_EXCEPTION();
3738        ZEND_VM_NEXT_OPCODE();
3739    }
3740}
3741
3742ZEND_VM_HANDLER(110, ZEND_CLONE, CONST|TMP|VAR|UNUSED|CV, ANY)
3743{
3744    USE_OPLINE
3745    zend_free_op free_op1;
3746    zval *obj;
3747    zend_class_entry *ce;
3748    zend_function *clone;
3749    zend_object_clone_obj_t clone_call;
3750
3751    SAVE_OPLINE();
3752    obj = GET_OP1_OBJ_ZVAL_PTR_DEREF(BP_VAR_R);
3753
3754    if (OP1_TYPE == IS_CONST ||
3755        UNEXPECTED(Z_TYPE_P(obj) != IS_OBJECT)) {
3756        if (UNEXPECTED(EG(exception) != NULL)) {
3757            HANDLE_EXCEPTION();
3758        }
3759        zend_error_noreturn(E_ERROR, "__clone method called on non-object");
3760    }
3761
3762    ce = Z_OBJCE_P(obj);
3763    clone = ce ? ce->clone : NULL;
3764    clone_call =  Z_OBJ_HT_P(obj)->clone_obj;
3765    if (UNEXPECTED(clone_call == NULL)) {
3766        if (ce) {
3767            zend_error_noreturn(E_ERROR, "Trying to clone an uncloneable object of class %s", ce->name->val);
3768        } else {
3769            zend_error_noreturn(E_ERROR, "Trying to clone an uncloneable object");
3770        }
3771    }
3772
3773    if (ce && clone) {
3774        if (clone->op_array.fn_flags & ZEND_ACC_PRIVATE) {
3775            /* Ensure that if we're calling a private function, we're allowed to do so.
3776             */
3777            if (UNEXPECTED(ce != EX(scope))) {
3778                zend_error_noreturn(E_ERROR, "Call to private %s::__clone() from context '%s'", ce->name->val, EX(scope) ? EX(scope)->name->val : "");
3779            }
3780        } else if ((clone->common.fn_flags & ZEND_ACC_PROTECTED)) {
3781            /* Ensure that if we're calling a protected function, we're allowed to do so.
3782             */
3783            if (UNEXPECTED(!zend_check_protected(zend_get_function_root_class(clone), EX(scope)))) {
3784                zend_error_noreturn(E_ERROR, "Call to protected %s::__clone() from context '%s'", ce->name->val, EX(scope) ? EX(scope)->name->val : "");
3785            }
3786        }
3787    }
3788
3789    if (EXPECTED(EG(exception) == NULL)) {
3790        ZVAL_OBJ(EX_VAR(opline->result.var), clone_call(obj TSRMLS_CC));
3791        if (!RETURN_VALUE_USED(opline) || UNEXPECTED(EG(exception) != NULL)) {
3792            zval_ptr_dtor(EX_VAR(opline->result.var));
3793        }
3794    }
3795    FREE_OP1_IF_VAR();
3796    CHECK_EXCEPTION();
3797    ZEND_VM_NEXT_OPCODE();
3798}
3799
3800ZEND_VM_HANDLER(99, ZEND_FETCH_CONSTANT, VAR|CONST|UNUSED, CONST)
3801{
3802    USE_OPLINE
3803
3804    SAVE_OPLINE();
3805    if (OP1_TYPE == IS_UNUSED) {
3806        zend_constant *c;
3807        zval *retval;
3808
3809        if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv))) {
3810            c = CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv));
3811        } else if ((c = zend_quick_get_constant(opline->op2.zv + 1, opline->extended_value TSRMLS_CC)) == NULL) {
3812            if ((opline->extended_value & IS_CONSTANT_UNQUALIFIED) != 0) {
3813                char *actual = (char *)zend_memrchr(Z_STRVAL_P(opline->op2.zv), '\\', Z_STRLEN_P(opline->op2.zv));
3814                if(!actual) {
3815                    actual = Z_STRVAL_P(opline->op2.zv);
3816                } else {
3817                    actual++;
3818                }
3819                /* non-qualified constant - allow text substitution */
3820                zend_error(E_NOTICE, "Use of undefined constant %s - assumed '%s'", actual, actual);
3821                ZVAL_STRINGL(EX_VAR(opline->result.var), actual, Z_STRLEN_P(opline->op2.zv)-(actual - Z_STRVAL_P(opline->op2.zv)));
3822                CHECK_EXCEPTION();
3823                ZEND_VM_NEXT_OPCODE();
3824            } else {
3825                zend_error_noreturn(E_ERROR, "Undefined constant '%s'", Z_STRVAL_P(opline->op2.zv));
3826            }
3827        } else {
3828            CACHE_PTR(Z_CACHE_SLOT_P(opline->op2.zv), c);
3829        }
3830        retval = EX_VAR(opline->result.var);
3831        ZVAL_COPY_VALUE(retval, &c->value);
3832        if (Z_OPT_COPYABLE_P(retval) || Z_OPT_REFCOUNTED_P(retval)) {
3833            if (Z_OPT_COPYABLE_P(retval)) {
3834                zval_copy_ctor_func(retval);
3835            } else {
3836                Z_ADDREF_P(retval);
3837            }
3838        }
3839    } else {
3840        /* class constant */
3841        zend_class_entry *ce;
3842        zval *value;
3843
3844        if (OP1_TYPE == IS_CONST) {
3845            if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv))) {
3846                value = CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv));
3847                ZVAL_DEREF(value);
3848                ZVAL_DUP(EX_VAR(opline->result.var), value);
3849                ZEND_VM_C_GOTO(constant_fetch_end);
3850            } else if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op1.zv))) {
3851                ce = CACHED_PTR(Z_CACHE_SLOT_P(opline->op1.zv));
3852            } else {
3853                ce = zend_fetch_class_by_name(Z_STR_P(opline->op1.zv), opline->op1.zv + 1, opline->extended_value TSRMLS_CC);
3854                if (UNEXPECTED(EG(exception) != NULL)) {
3855                    HANDLE_EXCEPTION();
3856                }
3857                if (UNEXPECTED(ce == NULL)) {
3858                    zend_error_noreturn(E_ERROR, "Class '%s' not found", Z_STRVAL_P(opline->op1.zv));
3859                }
3860                CACHE_PTR(Z_CACHE_SLOT_P(opline->op1.zv), ce);
3861            }
3862        } else {
3863            ce = Z_CE_P(EX_VAR(opline->op1.var));
3864            if ((value = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(opline->op2.zv), ce)) != NULL) {
3865                ZVAL_DEREF(value);
3866                ZVAL_DUP(EX_VAR(opline->result.var), value);
3867                ZEND_VM_C_GOTO(constant_fetch_end);
3868            }
3869        }
3870
3871        if (EXPECTED((value = zend_hash_find(&ce->constants_table, Z_STR_P(opline->op2.zv))) != NULL)) {
3872            ZVAL_DEREF(value);
3873            if (Z_CONSTANT_P(value)) {
3874                EG(scope) = ce;
3875                zval_update_constant(value, 1 TSRMLS_CC);
3876                EG(scope) = EX(scope);
3877            }
3878            if (OP1_TYPE == IS_CONST) {
3879                CACHE_PTR(Z_CACHE_SLOT_P(opline->op2.zv), value);
3880            } else {
3881                CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(opline->op2.zv), ce, value);
3882            }
3883            ZVAL_DUP(EX_VAR(opline->result.var), value);
3884        } else if (Z_STRLEN_P(opline->op2.zv) == sizeof("class")-1 && memcmp(Z_STRVAL_P(opline->op2.zv), "class", sizeof("class") - 1) == 0) {
3885            /* "class" is assigned as a case-sensitive keyword from zend_do_resolve_class_name */
3886            ZVAL_STR_COPY(EX_VAR(opline->result.var), ce->name);
3887        } else {
3888            zend_error_noreturn(E_ERROR, "Undefined class constant '%s'", Z_STRVAL_P(opline->op2.zv));
3889        }
3890    }
3891ZEND_VM_C_LABEL(constant_fetch_end):
3892    CHECK_EXCEPTION();
3893    ZEND_VM_NEXT_OPCODE();
3894}
3895
3896ZEND_VM_HANDLER(72, ZEND_ADD_ARRAY_ELEMENT, CONST|TMP|VAR|CV, CONST|TMP|VAR|UNUSED|CV)
3897{
3898    USE_OPLINE
3899    zend_free_op free_op1;
3900    zval *expr_ptr, new_expr;
3901
3902    SAVE_OPLINE();
3903    if ((OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) &&
3904        (opline->extended_value & ZEND_ARRAY_ELEMENT_REF)) {
3905        expr_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
3906        if (OP1_TYPE == IS_VAR && UNEXPECTED(expr_ptr == NULL)) {
3907            zend_error_noreturn(E_ERROR, "Cannot create references to/from string offsets");
3908        }
3909        ZVAL_MAKE_REF(expr_ptr);
3910        Z_ADDREF_P(expr_ptr);
3911        FREE_OP1_VAR_PTR();
3912    } else {
3913        expr_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
3914        if (IS_OP1_TMP_FREE()) { /* temporary variable */
3915            ZVAL_COPY_VALUE(&new_expr, expr_ptr);
3916            expr_ptr = &new_expr;
3917        } else if (OP1_TYPE == IS_CONST) {
3918            if (!Z_IMMUTABLE_P(expr_ptr)) {
3919                ZVAL_DUP(&new_expr, expr_ptr);
3920                expr_ptr = &new_expr;
3921            }
3922        } else if (Z_ISREF_P(expr_ptr)) {
3923            ZVAL_DUP(&new_expr, Z_REFVAL_P(expr_ptr));
3924            expr_ptr = &new_expr;
3925            FREE_OP1_IF_VAR();
3926        } else if (OP1_TYPE == IS_CV && Z_REFCOUNTED_P(expr_ptr)) {
3927            Z_ADDREF_P(expr_ptr);
3928        }
3929    }
3930
3931    if (OP2_TYPE != IS_UNUSED) {
3932        zend_free_op free_op2;
3933        zval *offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
3934        zend_string *str;
3935        zend_ulong hval;
3936
3937ZEND_VM_C_LABEL(add_again):
3938        switch (Z_TYPE_P(offset)) {
3939            case IS_DOUBLE:
3940                hval = zend_dval_to_lval(Z_DVAL_P(offset));
3941                ZEND_VM_C_GOTO(num_index);
3942            case IS_LONG:
3943                hval = Z_LVAL_P(offset);
3944ZEND_VM_C_LABEL(num_index):
3945                zend_hash_index_update(Z_ARRVAL_P(EX_VAR(opline->result.var)), hval, expr_ptr);
3946                break;
3947            case IS_STRING:
3948                str = Z_STR_P(offset);
3949                if (OP2_TYPE != IS_CONST) {
3950                    if (ZEND_HANDLE_NUMERIC(str, hval)) {
3951                        ZEND_VM_C_GOTO(num_index);
3952                    }
3953                }
3954ZEND_VM_C_LABEL(str_index):
3955                zend_hash_update(Z_ARRVAL_P(EX_VAR(opline->result.var)), str, expr_ptr);
3956                break;
3957            case IS_NULL:
3958                str = STR_EMPTY_ALLOC();
3959                ZEND_VM_C_GOTO(str_index);
3960            case IS_FALSE:
3961                hval = 0;
3962                ZEND_VM_C_GOTO(num_index);
3963            case IS_TRUE:
3964                hval = 1;
3965                ZEND_VM_C_GOTO(num_index);
3966            case IS_REFERENCE:
3967                offset = Z_REFVAL_P(offset);
3968                ZEND_VM_C_GOTO(add_again);
3969                break;
3970            default:
3971                zend_error(E_WARNING, "Illegal offset type");
3972                zval_ptr_dtor(expr_ptr);
3973                /* do nothing */
3974                break;
3975        }
3976        FREE_OP2();
3977    } else {
3978        zend_hash_next_index_insert(Z_ARRVAL_P(EX_VAR(opline->result.var)), expr_ptr);
3979    }
3980    CHECK_EXCEPTION();
3981    ZEND_VM_NEXT_OPCODE();
3982}
3983
3984ZEND_VM_HANDLER(71, ZEND_INIT_ARRAY, CONST|TMP|VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
3985{
3986    zval *array;
3987    uint32_t size;
3988    USE_OPLINE
3989
3990    array = EX_VAR(opline->result.var);
3991    if (OP1_TYPE != IS_UNUSED) {
3992        size = opline->extended_value >> ZEND_ARRAY_SIZE_SHIFT;
3993    } else {
3994        size = 0;
3995    }
3996    ZVAL_NEW_ARR(array);
3997    zend_hash_init(Z_ARRVAL_P(array), size, NULL, ZVAL_PTR_DTOR, 0);
3998
3999    if (OP1_TYPE != IS_UNUSED) {
4000        /* Explicitly initialize array as not-packed if flag is set */
4001        if (opline->extended_value & ZEND_ARRAY_NOT_PACKED) {
4002            zend_hash_real_init(Z_ARRVAL_P(array), 0);
4003        }
4004    }
4005
4006    if (OP1_TYPE == IS_UNUSED) {
4007        ZEND_VM_NEXT_OPCODE();
4008#if !defined(ZEND_VM_SPEC) || OP1_TYPE != IS_UNUSED
4009    } else {
4010        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_ADD_ARRAY_ELEMENT);
4011#endif
4012    }
4013}
4014
4015ZEND_VM_HANDLER(21, ZEND_CAST, CONST|TMP|VAR|CV, ANY)
4016{
4017    USE_OPLINE
4018    zend_free_op free_op1;
4019    zval *expr;
4020    zval *result = EX_VAR(opline->result.var);
4021
4022    SAVE_OPLINE();
4023    expr = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
4024
4025    switch (opline->extended_value) {
4026        case IS_NULL:
4027            /* This code is taken from convert_to_null. However, it does not seems very useful,
4028             * because a conversion to null always results in the same value. This could only
4029             * be relevant if a cast_object handler for IS_NULL has some kind of side-effect. */
4030#if 0
4031            if (OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) {
4032                ZVAL_DEREF(expr);
4033            }
4034            if (Z_TYPE_P(expr) == IS_OBJECT && Z_OBJ_HT_P(expr)->cast_object) {
4035                if (Z_OBJ_HT_P(expr)->cast_object(expr, result, IS_NULL TSRMLS_CC) == SUCCESS) {
4036                    break;
4037                }
4038            }
4039#endif
4040
4041            ZVAL_NULL(result);
4042            break;
4043        case _IS_BOOL:
4044            ZVAL_BOOL(result, zend_is_true(expr TSRMLS_CC));
4045            break;
4046        case IS_LONG:
4047            ZVAL_LONG(result, zval_get_long(expr));
4048            break;
4049        case IS_DOUBLE:
4050            ZVAL_DOUBLE(result, zval_get_double(expr));
4051            break;
4052        case IS_STRING:
4053            ZVAL_STR(result, zval_get_string(expr));
4054            break;
4055        default:
4056            /* If value is already of correct type, return it directly */
4057            if (Z_TYPE_P(expr) == opline->extended_value) {
4058                ZVAL_COPY_VALUE(result, expr);
4059                if (OP1_TYPE == IS_CONST) {
4060                    if (UNEXPECTED(Z_OPT_COPYABLE_P(result))) {
4061                        zval_copy_ctor_func(result);
4062                    }
4063                } else if (OP1_TYPE != IS_TMP_VAR) {
4064                    if (Z_OPT_REFCOUNTED_P(expr)) Z_ADDREF_P(expr);
4065                }
4066
4067                FREE_OP1();
4068                CHECK_EXCEPTION();
4069                ZEND_VM_NEXT_OPCODE();
4070            }
4071
4072            if (opline->extended_value == IS_ARRAY) {
4073                if (Z_TYPE_P(expr) != IS_OBJECT) {
4074                    ZVAL_NEW_ARR(result);
4075                    zend_hash_init(Z_ARRVAL_P(result), 8, NULL, ZVAL_PTR_DTOR, 0);
4076                    if (Z_TYPE_P(expr) != IS_NULL) {
4077                        expr = zend_hash_index_add_new(Z_ARRVAL_P(result), 0, expr);
4078                        if (OP1_TYPE == IS_CONST) {
4079                            if (UNEXPECTED(Z_OPT_COPYABLE_P(expr))) {
4080                                zval_copy_ctor_func(expr);
4081                            }
4082                        } else if (OP1_TYPE != IS_TMP_VAR) {
4083                            if (Z_OPT_REFCOUNTED_P(expr)) Z_ADDREF_P(expr);
4084                        }
4085                    }
4086                } else {
4087                    ZVAL_COPY_VALUE(result, expr);
4088                    if (!IS_OP1_TMP_FREE()) {
4089                        zval_opt_copy_ctor(result);
4090                    }
4091                    convert_to_array(result);
4092                }
4093            } else {
4094                if (Z_TYPE_P(expr) != IS_ARRAY) {
4095                    object_init(result);
4096                    if (Z_TYPE_P(expr) != IS_NULL) {
4097                        expr = zend_hash_str_add_new(Z_OBJPROP_P(result), "scalar", sizeof("scalar")-1, expr);
4098                        if (OP1_TYPE == IS_CONST) {
4099                            if (UNEXPECTED(Z_OPT_COPYABLE_P(expr))) {
4100                                zval_copy_ctor_func(expr);
4101                            }
4102                        } else if (OP1_TYPE != IS_TMP_VAR) {
4103                            if (Z_OPT_REFCOUNTED_P(expr)) Z_ADDREF_P(expr);
4104                        }
4105                    }
4106                } else {
4107                    ZVAL_COPY_VALUE(result, expr);
4108                    if (!IS_OP1_TMP_FREE()) {
4109                        zval_opt_copy_ctor(result);
4110                    }
4111                    convert_to_object(result);
4112                }
4113            }
4114
4115            FREE_OP1_IF_VAR();
4116            CHECK_EXCEPTION();
4117            ZEND_VM_NEXT_OPCODE();
4118    }
4119    FREE_OP1();
4120    CHECK_EXCEPTION();
4121    ZEND_VM_NEXT_OPCODE();
4122}
4123
4124ZEND_VM_HANDLER(73, ZEND_INCLUDE_OR_EVAL, CONST|TMP|VAR|CV, ANY)
4125{
4126    USE_OPLINE
4127    zend_op_array *new_op_array=NULL;
4128    zend_free_op free_op1;
4129    zval *inc_filename;
4130    zval tmp_inc_filename;
4131    zend_bool failure_retval=0;
4132
4133    SAVE_OPLINE();
4134    inc_filename = GET_OP1_ZVAL_PTR(BP_VAR_R);
4135
4136    ZVAL_UNDEF(&tmp_inc_filename);
4137    if (Z_TYPE_P(inc_filename) != IS_STRING) {
4138        ZVAL_DUP(&tmp_inc_filename, inc_filename);
4139        convert_to_string(&tmp_inc_filename);
4140        inc_filename = &tmp_inc_filename;
4141    }
4142
4143    if (opline->extended_value != ZEND_EVAL && strlen(Z_STRVAL_P(inc_filename)) != Z_STRLEN_P(inc_filename)) {
4144        if (opline->extended_value == ZEND_INCLUDE_ONCE || opline->extended_value == ZEND_INCLUDE) {
4145            zend_message_dispatcher(ZMSG_FAILED_INCLUDE_FOPEN, Z_STRVAL_P(inc_filename) TSRMLS_CC);
4146        } else {
4147            zend_message_dispatcher(ZMSG_FAILED_REQUIRE_FOPEN, Z_STRVAL_P(inc_filename) TSRMLS_CC);
4148        }
4149    } else {
4150        switch (opline->extended_value) {
4151            case ZEND_INCLUDE_ONCE:
4152            case ZEND_REQUIRE_ONCE: {
4153                    zend_file_handle file_handle;
4154                    char *resolved_path;
4155
4156                    resolved_path = zend_resolve_path(Z_STRVAL_P(inc_filename), (int)Z_STRLEN_P(inc_filename) TSRMLS_CC);
4157                    if (resolved_path) {
4158                        failure_retval = zend_hash_str_exists(&EG(included_files), resolved_path, (int)strlen(resolved_path));
4159                    } else {
4160                        resolved_path = Z_STRVAL_P(inc_filename);
4161                    }
4162
4163                    if (failure_retval) {
4164                        /* do nothing, file already included */
4165                    } else if (SUCCESS == zend_stream_open(resolved_path, &file_handle TSRMLS_CC)) {
4166
4167                        if (!file_handle.opened_path) {
4168                            file_handle.opened_path = estrdup(resolved_path);
4169                        }
4170
4171                        if (zend_hash_str_add_empty_element(&EG(included_files), file_handle.opened_path, (int)strlen(file_handle.opened_path))) {
4172                            new_op_array = zend_compile_file(&file_handle, (opline->extended_value==ZEND_INCLUDE_ONCE?ZEND_INCLUDE:ZEND_REQUIRE) TSRMLS_CC);
4173                            zend_destroy_file_handle(&file_handle TSRMLS_CC);
4174                        } else {
4175                            zend_file_handle_dtor(&file_handle TSRMLS_CC);
4176                            failure_retval=1;
4177                        }
4178                    } else {
4179                        if (opline->extended_value == ZEND_INCLUDE_ONCE) {
4180                            zend_message_dispatcher(ZMSG_FAILED_INCLUDE_FOPEN, Z_STRVAL_P(inc_filename) TSRMLS_CC);
4181                        } else {
4182                            zend_message_dispatcher(ZMSG_FAILED_REQUIRE_FOPEN, Z_STRVAL_P(inc_filename) TSRMLS_CC);
4183                        }
4184                    }
4185                    if (resolved_path != Z_STRVAL_P(inc_filename)) {
4186                        efree(resolved_path);
4187                    }
4188                }
4189                break;
4190            case ZEND_INCLUDE:
4191            case ZEND_REQUIRE:
4192                new_op_array = compile_filename(opline->extended_value, inc_filename TSRMLS_CC);
4193                break;
4194            case ZEND_EVAL: {
4195                    char *eval_desc = zend_make_compiled_string_description("eval()'d code" TSRMLS_CC);
4196
4197                    new_op_array = zend_compile_string(inc_filename, eval_desc TSRMLS_CC);
4198                    efree(eval_desc);
4199                }
4200                break;
4201            EMPTY_SWITCH_DEFAULT_CASE()
4202        }
4203    }
4204    if (Z_TYPE(tmp_inc_filename) != IS_UNDEF) {
4205        zval_ptr_dtor(&tmp_inc_filename);
4206    }
4207    FREE_OP1();
4208    if (UNEXPECTED(EG(exception) != NULL)) {
4209        HANDLE_EXCEPTION();
4210    } else if (EXPECTED(new_op_array != NULL)) {
4211        zval *return_value = NULL;
4212        zend_execute_data *call;
4213
4214        if (RETURN_VALUE_USED(opline)) {
4215            return_value = EX_VAR(opline->result.var);
4216        }
4217
4218        call = zend_vm_stack_push_call_frame(
4219            (zend_function*)new_op_array, 0, 0, EX(called_scope), EX(object), NULL TSRMLS_CC);
4220
4221        if (EX(symbol_table)) {
4222            call->symbol_table = EX(symbol_table);
4223        } else {
4224            call->symbol_table = zend_rebuild_symbol_table(TSRMLS_C);
4225        }
4226
4227        call->prev_execute_data = execute_data;
4228        i_init_code_execute_data(call, new_op_array, return_value, EXPECTED(zend_execute_ex == execute_ex) ? VM_FRAME_NESTED_CODE : VM_FRAME_TOP_CODE TSRMLS_CC);
4229        if (EXPECTED(zend_execute_ex == execute_ex)) {
4230            ZEND_VM_ENTER();
4231        } else {
4232            zend_execute_ex(call TSRMLS_CC);
4233        }
4234
4235        destroy_op_array(new_op_array TSRMLS_CC);
4236        efree_size(new_op_array, sizeof(zend_op_array));
4237        if (UNEXPECTED(EG(exception) != NULL)) {
4238            zend_throw_exception_internal(NULL TSRMLS_CC);
4239            HANDLE_EXCEPTION();
4240        }
4241
4242    } else if (RETURN_VALUE_USED(opline)) {
4243        ZVAL_BOOL(EX_VAR(opline->result.var), failure_retval);
4244    }
4245    ZEND_VM_NEXT_OPCODE();
4246}
4247
4248ZEND_VM_HANDLER(74, ZEND_UNSET_VAR, CONST|TMP|VAR|CV, UNUSED|CONST|VAR)
4249{
4250    USE_OPLINE
4251    zval tmp, *varname;
4252    HashTable *target_symbol_table;
4253    zend_free_op free_op1;
4254    zend_bool tmp_is_dup = 0;
4255
4256    SAVE_OPLINE();
4257    if (OP1_TYPE == IS_CV &&
4258        OP2_TYPE == IS_UNUSED &&
4259        (opline->extended_value & ZEND_QUICK_SET)) {
4260        ZVAL_COPY_VALUE(&tmp, EX_VAR(opline->op1.var));
4261        ZVAL_UNDEF(EX_VAR(opline->op1.var));
4262        zval_ptr_dtor(&tmp);
4263        CHECK_EXCEPTION();
4264        ZEND_VM_NEXT_OPCODE();
4265    }
4266
4267    varname = GET_OP1_ZVAL_PTR(BP_VAR_R);
4268
4269    if (OP1_TYPE != IS_CONST && Z_TYPE_P(varname) != IS_STRING) {
4270        ZVAL_DUP(&tmp, varname);
4271        convert_to_string(&tmp);
4272        varname = &tmp;
4273        tmp_is_dup = 1;
4274    } else if (OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) {
4275        ZVAL_COPY(&tmp, varname);
4276        varname = &tmp;
4277    }
4278
4279    if (OP2_TYPE != IS_UNUSED) {
4280        zend_class_entry *ce;
4281
4282        if (OP2_TYPE == IS_CONST) {
4283            if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv))) {
4284                ce = CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv));
4285            } else {
4286                ce = zend_fetch_class_by_name(Z_STR_P(opline->op2.zv), opline->op2.zv + 1, 0 TSRMLS_CC);
4287                if (UNEXPECTED(EG(exception) != NULL)) {
4288                    if (OP1_TYPE != IS_CONST && tmp_is_dup) {
4289                        zval_dtor(&tmp);
4290                    } else if (OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) {
4291                        zval_ptr_dtor(&tmp);
4292                    }
4293                    FREE_OP1();
4294                    HANDLE_EXCEPTION();
4295                }
4296                if (UNEXPECTED(ce == NULL)) {
4297                    zend_error_noreturn(E_ERROR, "Class '%s' not found", Z_STRVAL_P(opline->op2.zv));
4298                }
4299                CACHE_PTR(Z_CACHE_SLOT_P(opline->op2.zv), ce);
4300            }
4301        } else {
4302            ce = Z_CE_P(EX_VAR(opline->op2.var));
4303        }
4304        zend_std_unset_static_property(ce, Z_STR_P(varname), ((OP1_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(varname)) : NULL) TSRMLS_CC);
4305    } else {
4306        target_symbol_table = zend_get_target_symbol_table(execute_data, opline->extended_value & ZEND_FETCH_TYPE_MASK TSRMLS_CC);
4307        zend_hash_del_ind(target_symbol_table, Z_STR_P(varname));
4308    }
4309
4310    if (OP1_TYPE != IS_CONST && tmp_is_dup) {
4311        zval_dtor(&tmp);
4312    } else if (OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) {
4313        zval_ptr_dtor(&tmp);
4314    }
4315    FREE_OP1();
4316    CHECK_EXCEPTION();
4317    ZEND_VM_NEXT_OPCODE();
4318}
4319
4320ZEND_VM_HANDLER(75, ZEND_UNSET_DIM, VAR|UNUSED|CV, CONST|TMP|VAR|CV)
4321{
4322    USE_OPLINE
4323    zend_free_op free_op1, free_op2;
4324    zval *container;
4325    zval *offset;
4326    zend_ulong hval;
4327
4328    SAVE_OPLINE();
4329    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_UNSET);
4330    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
4331        zend_error_noreturn(E_ERROR, "Cannot unset string offsets");
4332    }
4333    if (OP1_TYPE != IS_UNUSED) {
4334        ZVAL_DEREF(container);
4335        SEPARATE_ZVAL_NOREF(container);
4336    }
4337    offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
4338
4339    switch (Z_TYPE_P(container)) {
4340        case IS_ARRAY: {
4341            HashTable *ht = Z_ARRVAL_P(container);
4342ZEND_VM_C_LABEL(offset_again):
4343            switch (Z_TYPE_P(offset)) {
4344                case IS_DOUBLE:
4345                    hval = zend_dval_to_lval(Z_DVAL_P(offset));
4346                    zend_hash_index_del(ht, hval);
4347                    break;
4348                case IS_LONG:
4349                    hval = Z_LVAL_P(offset);
4350ZEND_VM_C_LABEL(num_index_dim):
4351                    zend_hash_index_del(ht, hval);
4352                    break;
4353                case IS_STRING:
4354                    if (OP2_TYPE == IS_CV || OP2_TYPE == IS_VAR) {
4355                        if (Z_REFCOUNTED_P(offset)) Z_ADDREF_P(offset);
4356                    }
4357                    if (OP2_TYPE != IS_CONST) {
4358                        if (ZEND_HANDLE_NUMERIC(Z_STR_P(offset), hval)) {
4359                            ZEND_VM_C_GOTO(numeric_index_dim);
4360                        }
4361                    }
4362                    if (ht == &EG(symbol_table).ht) {
4363                        zend_delete_global_variable(Z_STR_P(offset) TSRMLS_CC);
4364                    } else {
4365                        zend_hash_del(ht, Z_STR_P(offset));
4366                    }
4367                    if (OP2_TYPE == IS_CV || OP2_TYPE == IS_VAR) {
4368                        zval_ptr_dtor(offset);
4369                    }
4370                    break;
4371ZEND_VM_C_LABEL(numeric_index_dim):
4372                    zend_hash_index_del(ht, hval);
4373                    if (OP2_TYPE == IS_CV || OP2_TYPE == IS_VAR) {
4374                        zval_ptr_dtor(offset);
4375                    }
4376                    break;
4377                case IS_NULL:
4378                    zend_hash_del(ht, STR_EMPTY_ALLOC());
4379                    break;
4380                case IS_FALSE:
4381                    hval = 0;
4382                    ZEND_VM_C_GOTO(num_index_dim);
4383                case IS_TRUE:
4384                    hval = 1;
4385                    ZEND_VM_C_GOTO(num_index_dim);
4386                case IS_RESOURCE:
4387                    hval = Z_RES_HANDLE_P(offset);
4388                    ZEND_VM_C_GOTO(num_index_dim);
4389                case IS_REFERENCE:
4390                    offset = Z_REFVAL_P(offset);
4391                    ZEND_VM_C_GOTO(offset_again);
4392                    break;
4393                default:
4394                    zend_error(E_WARNING, "Illegal offset type in unset");
4395                    break;
4396            }
4397            FREE_OP2();
4398            break;
4399        }
4400        case IS_OBJECT:
4401            if (UNEXPECTED(Z_OBJ_HT_P(container)->unset_dimension == NULL)) {
4402                zend_error_noreturn(E_ERROR, "Cannot use object as array");
4403            }
4404//???           if (OP2_TYPE == IS_CONST) {
4405//???               zval_copy_ctor(offset);
4406//???           }
4407            Z_OBJ_HT_P(container)->unset_dimension(container, offset TSRMLS_CC);
4408            FREE_OP2();
4409            break;
4410        case IS_STRING:
4411            zend_error_noreturn(E_ERROR, "Cannot unset string offsets");
4412            ZEND_VM_CONTINUE(); /* bailed out before */
4413        default:
4414            FREE_OP2();
4415            break;
4416    }
4417    FREE_OP1_VAR_PTR();
4418    CHECK_EXCEPTION();
4419    ZEND_VM_NEXT_OPCODE();
4420}
4421
4422ZEND_VM_HANDLER(76, ZEND_UNSET_OBJ, VAR|UNUSED|CV, CONST|TMP|VAR|CV)
4423{
4424    USE_OPLINE
4425    zend_free_op free_op1, free_op2;
4426    zval *container;
4427    zval *offset;
4428
4429    SAVE_OPLINE();
4430    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_UNSET);
4431    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
4432        zend_error_noreturn(E_ERROR, "Cannot unset string offsets");
4433    }
4434    offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
4435
4436    ZVAL_DEREF(container);
4437    if (Z_TYPE_P(container) == IS_OBJECT) {
4438        if (Z_OBJ_HT_P(container)->unset_property) {
4439            Z_OBJ_HT_P(container)->unset_property(container, offset, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(offset)) : NULL) TSRMLS_CC);
4440        } else {
4441            zend_error(E_NOTICE, "Trying to unset property of non-object");
4442        }
4443    }
4444    FREE_OP2();
4445    FREE_OP1_VAR_PTR();
4446    CHECK_EXCEPTION();
4447    ZEND_VM_NEXT_OPCODE();
4448}
4449
4450ZEND_VM_HANDLER(77, ZEND_FE_RESET, CONST|TMP|VAR|CV, ANY)
4451{
4452    USE_OPLINE
4453    zend_free_op free_op1;
4454    zval *array_ptr, *array_ref, iterator, tmp;
4455    HashTable *fe_ht;
4456    zend_object_iterator *iter = NULL;
4457    zend_class_entry *ce = NULL;
4458    zend_bool is_empty = 0;
4459
4460    SAVE_OPLINE();
4461
4462    if ((OP1_TYPE == IS_CV || OP1_TYPE == IS_VAR) &&
4463        (opline->extended_value & ZEND_FE_FETCH_BYREF)) {
4464        array_ptr = array_ref = GET_OP1_ZVAL_PTR_PTR(BP_VAR_R);
4465        ZVAL_DEREF(array_ptr);
4466        if (Z_TYPE_P(array_ptr) == IS_ARRAY) {
4467            SEPARATE_ARRAY(array_ptr);
4468            if (!Z_ISREF_P(array_ref)) {
4469                ZVAL_NEW_REF(array_ref, array_ref);
4470                array_ptr = Z_REFVAL_P(array_ref);
4471            }
4472            if (Z_REFCOUNTED_P(array_ref)) Z_ADDREF_P(array_ref);
4473        } else if (Z_TYPE_P(array_ptr) == IS_OBJECT) {
4474            if(Z_OBJ_HT_P(array_ptr)->get_class_entry == NULL) {
4475                zend_error(E_WARNING, "foreach() cannot iterate over objects without PHP class");
4476                ZEND_VM_JMP(opline->op2.jmp_addr);
4477            }
4478
4479            ce = Z_OBJCE_P(array_ptr);
4480            if (!ce || ce->get_iterator == NULL) {
4481                Z_ADDREF_P(array_ptr);
4482            }
4483            array_ref = array_ptr;
4484        } else {
4485            if (Z_REFCOUNTED_P(array_ref)) Z_ADDREF_P(array_ref);
4486        }
4487    } else {
4488        array_ptr = array_ref = GET_OP1_ZVAL_PTR(BP_VAR_R);
4489        ZVAL_DEREF(array_ptr);
4490        if (IS_OP1_TMP_FREE()) { /* IS_TMP_VAR */
4491            ZVAL_COPY_VALUE(&tmp, array_ptr);
4492            array_ptr = &tmp;
4493            if (Z_TYPE_P(array_ptr) == IS_OBJECT) {
4494                ce = Z_OBJCE_P(array_ptr);
4495                if (ce && ce->get_iterator) {
4496                    Z_DELREF_P(array_ref);
4497                }
4498            }
4499        } else if (Z_TYPE_P(array_ptr) == IS_OBJECT) {
4500            ce = Z_OBJCE_P(array_ptr);
4501            if (!ce || !ce->get_iterator) {
4502                if (OP1_TYPE == IS_CV) {
4503                    Z_ADDREF_P(array_ref);
4504                }
4505            }
4506        } else if (Z_IMMUTABLE_P(array_ref)) {
4507            if (OP1_TYPE == IS_CV) {
4508                zval_copy_ctor(array_ref);
4509                Z_ADDREF_P(array_ref);
4510            } else {
4511                ZVAL_DUP(&tmp, array_ref);
4512                array_ptr = array_ref = &tmp;
4513            }
4514        } else if (Z_REFCOUNTED_P(array_ref)) {
4515            if (OP1_TYPE == IS_CONST ||
4516                       (OP1_TYPE == IS_CV &&
4517                        !Z_ISREF_P(array_ref) &&
4518                        Z_REFCOUNT_P(array_ref) > 1) ||
4519                       (OP1_TYPE == IS_VAR &&
4520                        !Z_ISREF_P(array_ref) &&
4521                        Z_REFCOUNT_P(array_ref) > 2)) {
4522                if (OP1_TYPE == IS_VAR) {
4523                    Z_DELREF_P(array_ref);
4524                }
4525                ZVAL_DUP(&tmp, array_ref);
4526                array_ptr = array_ref = &tmp;
4527            } else if (OP1_TYPE == IS_CV || OP1_TYPE == IS_VAR) {
4528                if (Z_ISREF_P(array_ref) && Z_REFCOUNT_P(array_ref) == 1) {
4529                    ZVAL_UNREF(array_ref);
4530                    array_ptr = array_ref;
4531                }
4532                if (Z_IMMUTABLE_P(array_ptr) ||
4533                    (Z_ISREF_P(array_ref) &&
4534                     Z_REFCOUNTED_P(array_ptr) &&
4535                     Z_REFCOUNT_P(array_ptr) > 1)) {
4536                    if (!Z_IMMUTABLE_P(array_ptr)) {
4537                        Z_DELREF_P(array_ptr);
4538                    }
4539                    zval_copy_ctor(array_ptr);
4540                }
4541                if (OP1_TYPE == IS_CV) {
4542                    Z_ADDREF_P(array_ref);
4543                }
4544            }
4545        }
4546    }
4547
4548    if (ce && ce->get_iterator) {
4549        iter = ce->get_iterator(ce, array_ptr, opline->extended_value & ZEND_FE_FETCH_BYREF TSRMLS_CC);
4550
4551        if (OP1_TYPE == IS_VAR && !(opline->extended_value & ZEND_FE_FETCH_BYREF)) {
4552            FREE_OP1_IF_VAR();
4553        }
4554        if (iter && EXPECTED(EG(exception) == NULL)) {
4555            ZVAL_OBJ(&iterator, &iter->std);
4556            array_ptr = array_ref = &iterator;
4557        } else {
4558            if (OP1_TYPE == IS_VAR && opline->extended_value & ZEND_FE_FETCH_BYREF) {
4559                FREE_OP1_VAR_PTR();
4560            }
4561            if (!EG(exception)) {
4562                zend_throw_exception_ex(NULL, 0 TSRMLS_CC, "Object of type %s did not create an Iterator", ce->name->val);
4563            }
4564            zend_throw_exception_internal(NULL TSRMLS_CC);
4565            HANDLE_EXCEPTION();
4566        }
4567    }
4568
4569    ZVAL_COPY_VALUE(EX_VAR(opline->result.var), array_ref);
4570
4571    if (iter) {
4572        iter->index = 0;
4573        if (iter->funcs->rewind) {
4574            iter->funcs->rewind(iter TSRMLS_CC);
4575            if (UNEXPECTED(EG(exception) != NULL)) {
4576                zval_ptr_dtor(array_ref);
4577                if (OP1_TYPE == IS_VAR && opline->extended_value & ZEND_FE_FETCH_BYREF) {
4578                    FREE_OP1_VAR_PTR();
4579                }
4580                HANDLE_EXCEPTION();
4581            }
4582        }
4583        is_empty = iter->funcs->valid(iter TSRMLS_CC) != SUCCESS;
4584        if (UNEXPECTED(EG(exception) != NULL)) {
4585            zval_ptr_dtor(array_ref);
4586            if (OP1_TYPE == IS_VAR && opline->extended_value & ZEND_FE_FETCH_BYREF) {
4587                FREE_OP1_VAR_PTR();
4588            }
4589            HANDLE_EXCEPTION();
4590        }
4591        iter->index = -1; /* will be set to 0 before using next handler */
4592    } else if ((fe_ht = HASH_OF(array_ptr)) != NULL) {
4593        HashPointer *ptr = (HashPointer*)EX_VAR((opline+2)->op1.var);
4594        HashPosition pos = 0;
4595        Bucket *p;
4596
4597        while (1) {
4598            if (pos >= fe_ht->nNumUsed) {
4599                is_empty = 1;
4600                if (OP1_TYPE == IS_VAR && opline->extended_value & ZEND_FE_FETCH_BYREF) {
4601                    FREE_OP1_VAR_PTR();
4602                }
4603                ZEND_VM_JMP(opline->op2.jmp_addr);
4604            }
4605            p = fe_ht->arData + pos;
4606            if (Z_TYPE(p->val) == IS_UNDEF ||
4607                (Z_TYPE(p->val) == IS_INDIRECT &&
4608                 Z_TYPE_P(Z_INDIRECT(p->val)) == IS_UNDEF)) {
4609                pos++;
4610                continue;
4611            }
4612            if (!ce ||
4613                !p->key ||
4614                zend_check_property_access(Z_OBJ_P(array_ptr), p->key TSRMLS_CC) == SUCCESS) {
4615                break;
4616            }
4617            pos++;
4618        }
4619        fe_ht->nInternalPointer = pos;
4620        ptr->pos = pos;
4621        ptr->ht = fe_ht;
4622        ptr->h = fe_ht->arData[pos].h;
4623        is_empty = 0;
4624    } else {
4625        zend_error(E_WARNING, "Invalid argument supplied for foreach()");
4626        is_empty = 1;
4627    }
4628
4629    if (OP1_TYPE == IS_VAR && opline->extended_value & ZEND_FE_FETCH_BYREF) {
4630        FREE_OP1_VAR_PTR();
4631    }
4632    if (is_empty) {
4633        ZEND_VM_JMP(opline->op2.jmp_addr);
4634    } else {
4635        CHECK_EXCEPTION();
4636        ZEND_VM_NEXT_OPCODE();
4637    }
4638}
4639
4640ZEND_VM_HANDLER(78, ZEND_FE_FETCH, VAR, ANY)
4641{
4642    USE_OPLINE
4643    zend_free_op free_op1;
4644    zval *array, *array_ref;
4645    zval *value;
4646    HashTable *fe_ht;
4647    HashPointer *ptr;
4648    HashPosition pos;
4649    Bucket *p;
4650
4651    array = array_ref = EX_VAR(opline->op1.var);
4652    if (Z_ISREF_P(array)) {
4653        array = Z_REFVAL_P(array);
4654        // TODO: referenced value might be changed to different array ???
4655        if (Z_IMMUTABLE_P(array)) {
4656            zval_copy_ctor(array);
4657        }
4658    }
4659
4660    SAVE_OPLINE();
4661
4662    if (EXPECTED(Z_TYPE_P(array) == IS_ARRAY)) {
4663        fe_ht = Z_ARRVAL_P(array);
4664        ptr = (HashPointer*)EX_VAR((opline+1)->op1.var);
4665        pos = ptr->pos;
4666        if (UNEXPECTED(pos == INVALID_IDX)) {
4667            /* reached end of iteration */
4668            ZEND_VM_JMP(opline->op2.jmp_addr);
4669        } else if (UNEXPECTED(ptr->ht != fe_ht)) {
4670            ptr->ht = fe_ht;
4671            pos = 0;
4672        } else if (UNEXPECTED(fe_ht->nInternalPointer != ptr->pos)) {
4673            if (fe_ht->u.flags & HASH_FLAG_PACKED) {
4674                pos = ptr->h;
4675            } else {
4676                pos = fe_ht->arHash[ptr->h & fe_ht->nTableMask];
4677                while (pos != INVALID_IDX) {
4678                    if (fe_ht->arData[pos].h == ptr->h && pos == ptr->pos) {
4679                        break;
4680                    }
4681                    pos = Z_NEXT(fe_ht->arData[pos].val);
4682                }
4683            }
4684        }
4685        while (1) {
4686            if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
4687                /* reached end of iteration */
4688                ZEND_VM_JMP(opline->op2.jmp_addr);
4689            }
4690            p = fe_ht->arData + pos;
4691            value = &p->val;
4692            if (UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
4693                pos++;
4694                continue;
4695            } else if (UNEXPECTED(Z_TYPE_P(value) == IS_INDIRECT)) {
4696                value = Z_INDIRECT_P(value);
4697                if (UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
4698                    pos++;
4699                    continue;
4700                }
4701            }
4702            if (opline->extended_value & ZEND_FE_FETCH_BYREF) {
4703                ZVAL_MAKE_REF(value);
4704                Z_ADDREF_P(value);
4705                ZVAL_REF(EX_VAR(opline->result.var), Z_REF_P(value));
4706            } else {
4707                ZVAL_COPY(EX_VAR(opline->result.var), value);
4708            }
4709            if (opline->extended_value & ZEND_FE_FETCH_WITH_KEY) {
4710                if (!p->key) {
4711                    ZVAL_LONG(EX_VAR((opline+1)->result.var), p->h);
4712                } else {
4713                    ZVAL_STR_COPY(EX_VAR((opline+1)->result.var), p->key);
4714                }
4715            }
4716            break;
4717        }
4718        do {
4719            pos++;
4720            if (pos >= fe_ht->nNumUsed) {
4721                fe_ht->nInternalPointer = ptr->pos = INVALID_IDX;
4722                ZEND_VM_INC_OPCODE();
4723                ZEND_VM_NEXT_OPCODE();
4724            }
4725            p = fe_ht->arData + pos;
4726        } while (Z_TYPE(p->val) == IS_UNDEF ||
4727                 (Z_TYPE(p->val) == IS_INDIRECT &&
4728                  Z_TYPE_P(Z_INDIRECT(p->val)) == IS_UNDEF));
4729        fe_ht->nInternalPointer = ptr->pos = pos;
4730        ptr->h = fe_ht->arData[pos].h;
4731        ZEND_VM_INC_OPCODE();
4732        ZEND_VM_NEXT_OPCODE();
4733    } else if (EXPECTED(Z_TYPE_P(array) == IS_OBJECT)) {
4734        zend_object_iterator *iter;
4735
4736        if ((iter = zend_iterator_unwrap(array TSRMLS_CC)) == NULL) {
4737            /* plain object */
4738            zend_object *zobj = Z_OBJ_P(array);
4739
4740            fe_ht = Z_OBJPROP_P(array);
4741            ptr = (HashPointer*)EX_VAR((opline+1)->op1.var);
4742            pos = ptr->pos;
4743            if (pos == INVALID_IDX) {
4744                /* reached end of iteration */
4745                ZEND_VM_JMP(opline->op2.jmp_addr);
4746            } else if (UNEXPECTED(ptr->ht != fe_ht)) {
4747                ptr->ht = fe_ht;
4748                pos = 0;
4749            } else if (UNEXPECTED(fe_ht->nInternalPointer != ptr->pos)) {
4750                if (fe_ht->u.flags & HASH_FLAG_PACKED) {
4751                    pos = ptr->h;
4752                } else {
4753                    pos = fe_ht->arHash[ptr->h & fe_ht->nTableMask];
4754                    while (pos != INVALID_IDX) {
4755                        if (fe_ht->arData[pos].h == ptr->h && pos == ptr->pos) {
4756                            break;
4757                        }
4758                        pos = Z_NEXT(fe_ht->arData[pos].val);
4759                    }
4760                }
4761            }
4762            while (1) {
4763                if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
4764                    /* reached end of iteration */
4765                    ZEND_VM_JMP(opline->op2.jmp_addr);
4766                }
4767
4768                p = fe_ht->arData + pos;
4769                value = &p->val;
4770                if (UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
4771                    pos++;
4772                    continue;
4773                } else if (UNEXPECTED(Z_TYPE_P(value) == IS_INDIRECT)) {
4774                    value = Z_INDIRECT_P(value);
4775                    if (UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
4776                        pos++;
4777                        continue;
4778                    }
4779                }
4780
4781                if (UNEXPECTED(!p->key)) {
4782                    if (opline->extended_value & ZEND_FE_FETCH_WITH_KEY) {
4783                        ZVAL_LONG(EX_VAR((opline+1)->result.var), p->h);
4784                    }
4785                    break;
4786                } else if (zend_check_property_access(zobj, p->key TSRMLS_CC) == SUCCESS) {
4787                    if (opline->extended_value & ZEND_FE_FETCH_WITH_KEY) {
4788                        if (p->key->val[0]) {
4789                            ZVAL_STR_COPY(EX_VAR((opline+1)->result.var), p->key);
4790                        } else {
4791                            const char *class_name, *prop_name;
4792                            size_t prop_name_len;
4793                            zend_unmangle_property_name_ex(
4794                                p->key, &class_name, &prop_name, &prop_name_len);
4795                            ZVAL_STRINGL(EX_VAR((opline+1)->result.var), prop_name, prop_name_len);
4796                        }
4797                    }
4798                    break;
4799                }
4800                pos++;
4801            }
4802            if (opline->extended_value & ZEND_FE_FETCH_BYREF) {
4803                ZVAL_MAKE_REF(value);
4804                Z_ADDREF_P(value);
4805                ZVAL_REF(EX_VAR(opline->result.var), Z_REF_P(value));
4806            } else {
4807                ZVAL_COPY(EX_VAR(opline->result.var), value);
4808            }
4809            do {
4810                pos++;
4811                if (pos >= fe_ht->nNumUsed) {
4812                    fe_ht->nInternalPointer = ptr->pos = INVALID_IDX;
4813                    ZEND_VM_INC_OPCODE();
4814                    ZEND_VM_NEXT_OPCODE();
4815                }
4816                p = fe_ht->arData + pos;
4817            } while (Z_TYPE(p->val) == IS_UNDEF ||
4818                     (Z_TYPE(p->val) == IS_INDIRECT &&
4819                      Z_TYPE_P(Z_INDIRECT(p->val)) == IS_UNDEF) ||
4820                     (EXPECTED(p->key != NULL) &&
4821                      zend_check_property_access(zobj, p->key TSRMLS_CC) == FAILURE));
4822            fe_ht->nInternalPointer = ptr->pos = pos;
4823            ptr->h = fe_ht->arData[pos].h;
4824            ZEND_VM_INC_OPCODE();
4825            ZEND_VM_NEXT_OPCODE();
4826        } else {
4827            /* !iter happens from exception */
4828            if (iter && ++iter->index > 0) {
4829                /* This could cause an endless loop if index becomes zero again.
4830                 * In case that ever happens we need an additional flag. */
4831                iter->funcs->move_forward(iter TSRMLS_CC);
4832                if (UNEXPECTED(EG(exception) != NULL)) {
4833                    zval_ptr_dtor(array_ref);
4834                    HANDLE_EXCEPTION();
4835                }
4836            }
4837            /* If index is zero we come from FE_RESET and checked valid() already. */
4838            if (!iter || (iter->index > 0 && iter->funcs->valid(iter TSRMLS_CC) == FAILURE)) {
4839                /* reached end of iteration */
4840                if (UNEXPECTED(EG(exception) != NULL)) {
4841                    zval_ptr_dtor(array_ref);
4842                    HANDLE_EXCEPTION();
4843                }
4844                ZEND_VM_JMP(opline->op2.jmp_addr);
4845            }
4846            value = iter->funcs->get_current_data(iter TSRMLS_CC);
4847            if (UNEXPECTED(EG(exception) != NULL)) {
4848                zval_ptr_dtor(array_ref);
4849                HANDLE_EXCEPTION();
4850            }
4851            if (!value) {
4852                /* failure in get_current_data */
4853                ZEND_VM_JMP(opline->op2.jmp_addr);
4854            }
4855            if (opline->extended_value & ZEND_FE_FETCH_BYREF) {
4856                ZVAL_MAKE_REF(value);
4857                Z_ADDREF_P(value);
4858                ZVAL_REF(EX_VAR(opline->result.var), Z_REF_P(value));
4859            } else {
4860                ZVAL_COPY(EX_VAR(opline->result.var), value);
4861            }
4862            if (opline->extended_value & ZEND_FE_FETCH_WITH_KEY) {
4863                if (iter->funcs->get_current_key) {
4864                    iter->funcs->get_current_key(iter, EX_VAR((opline+1)->result.var) TSRMLS_CC);
4865                    if (UNEXPECTED(EG(exception) != NULL)) {
4866                        zval_ptr_dtor(array_ref);
4867                        HANDLE_EXCEPTION();
4868                    }
4869                } else {
4870                    ZVAL_LONG(EX_VAR((opline+1)->result.var), iter->index);
4871                }
4872            }
4873            ZEND_VM_INC_OPCODE();
4874            ZEND_VM_NEXT_OPCODE();
4875        }
4876    } else {
4877        zend_error(E_WARNING, "Invalid argument supplied for foreach()");
4878        ZEND_VM_JMP(opline->op2.jmp_addr);
4879    }
4880}
4881
4882ZEND_VM_HANDLER(114, ZEND_ISSET_ISEMPTY_VAR, CONST|TMP|VAR|CV, UNUSED|CONST|VAR)
4883{
4884    USE_OPLINE
4885    zval *value;
4886    zend_bool isset = 1;
4887
4888    SAVE_OPLINE();
4889    if (OP1_TYPE == IS_CV &&
4890        OP2_TYPE == IS_UNUSED &&
4891        (opline->extended_value & ZEND_QUICK_SET)) {
4892        if (Z_TYPE_P(EX_VAR(opline->op1.var)) != IS_UNDEF) {
4893            value = EX_VAR(opline->op1.var);
4894            ZVAL_DEREF(value);
4895        } else {
4896            isset = 0;
4897        }
4898    } else {
4899        HashTable *target_symbol_table;
4900        zend_free_op free_op1;
4901        zval tmp, *varname = GET_OP1_ZVAL_PTR(BP_VAR_IS);
4902
4903        if (OP1_TYPE != IS_CONST && Z_TYPE_P(varname) != IS_STRING) {
4904            ZVAL_DUP(&tmp, varname);
4905            convert_to_string(&tmp);
4906            varname = &tmp;
4907        }
4908
4909        if (OP2_TYPE != IS_UNUSED) {
4910            zend_class_entry *ce;
4911
4912            if (OP2_TYPE == IS_CONST) {
4913                if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv))) {
4914                    ce = CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv));
4915                } else {
4916                    ce = zend_fetch_class_by_name(Z_STR_P(opline->op2.zv), opline->op2.zv + 1, 0 TSRMLS_CC);
4917                    if (UNEXPECTED(ce == NULL)) {
4918                        CHECK_EXCEPTION();
4919                        ZEND_VM_NEXT_OPCODE();
4920                    }
4921                    CACHE_PTR(Z_CACHE_SLOT_P(opline->op2.zv), ce);
4922                }
4923            } else {
4924                ce = Z_CE_P(EX_VAR(opline->op2.var));
4925            }
4926            value = zend_std_get_static_property(ce, Z_STR_P(varname), 1, ((OP1_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(varname)) : NULL) TSRMLS_CC);
4927            if (!value) {
4928                isset = 0;
4929            }
4930        } else {
4931            target_symbol_table = zend_get_target_symbol_table(execute_data, opline->extended_value & ZEND_FETCH_TYPE_MASK TSRMLS_CC);
4932            if ((value = zend_hash_find(target_symbol_table, Z_STR_P(varname))) == NULL) {
4933                isset = 0;
4934            }
4935        }
4936
4937        if (OP1_TYPE != IS_CONST && varname == &tmp) {
4938            zval_dtor(&tmp);
4939        }
4940        FREE_OP1();
4941    }
4942
4943    if (opline->extended_value & ZEND_ISSET) {
4944        if (isset && Z_TYPE_P(value) != IS_NULL &&
4945            (!Z_ISREF_P(value) || Z_TYPE_P(Z_REFVAL_P(value)) != IS_NULL)) {
4946            ZVAL_BOOL(EX_VAR(opline->result.var), 1);
4947        } else {
4948            ZVAL_BOOL(EX_VAR(opline->result.var), 0);
4949        }
4950    } else /* if (opline->extended_value & ZEND_ISEMPTY) */ {
4951        if (!isset || !i_zend_is_true(value TSRMLS_CC)) {
4952            ZVAL_BOOL(EX_VAR(opline->result.var), 1);
4953        } else {
4954            ZVAL_BOOL(EX_VAR(opline->result.var), 0);
4955        }
4956    }
4957
4958    CHECK_EXCEPTION();
4959    ZEND_VM_NEXT_OPCODE();
4960}
4961
4962ZEND_VM_HANDLER(115, ZEND_ISSET_ISEMPTY_DIM_OBJ, CONST|TMP|VAR|UNUSED|CV, CONST|TMP|VAR|CV)
4963{
4964    USE_OPLINE
4965    zend_free_op free_op1, free_op2;
4966    zval *container;
4967    int result;
4968    zend_ulong hval;
4969    zval *offset;
4970
4971    SAVE_OPLINE();
4972    container = GET_OP1_OBJ_ZVAL_PTR_DEREF(BP_VAR_IS);
4973    offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
4974
4975    if (Z_TYPE_P(container) == IS_ARRAY) {
4976        HashTable *ht = Z_ARRVAL_P(container);
4977        zval *value;
4978        zend_string *str;
4979
4980ZEND_VM_C_LABEL(isset_again):
4981        if (EXPECTED(Z_TYPE_P(offset) == IS_STRING)) {
4982            str = Z_STR_P(offset);
4983            if (OP2_TYPE != IS_CONST) {
4984                if (ZEND_HANDLE_NUMERIC(str, hval)) {
4985                    ZEND_VM_C_GOTO(num_index_prop);
4986                }
4987            }
4988ZEND_VM_C_LABEL(str_index_prop):
4989            value = zend_hash_find_ind(ht, str);
4990        } else if (EXPECTED(Z_TYPE_P(offset) == IS_LONG)) {
4991            hval = Z_LVAL_P(offset);
4992ZEND_VM_C_LABEL(num_index_prop):
4993            value = zend_hash_index_find(ht, hval);
4994        } else {
4995            switch (Z_TYPE_P(offset)) {
4996                case IS_DOUBLE:
4997                    hval = zend_dval_to_lval(Z_DVAL_P(offset));
4998                    ZEND_VM_C_GOTO(num_index_prop);
4999                case IS_NULL:
5000                    str = STR_EMPTY_ALLOC();
5001                    ZEND_VM_C_GOTO(str_index_prop);
5002                case IS_FALSE:
5003                    hval = 0;
5004                    ZEND_VM_C_GOTO(num_index_prop);
5005                case IS_TRUE:
5006                    hval = 1;
5007                    ZEND_VM_C_GOTO(num_index_prop);
5008                case IS_RESOURCE:
5009                    hval = Z_RES_HANDLE_P(offset);
5010                    ZEND_VM_C_GOTO(num_index_prop);
5011                case IS_REFERENCE:
5012                    offset = Z_REFVAL_P(offset);
5013                    ZEND_VM_C_GOTO(isset_again);
5014                default:
5015                    zend_error(E_WARNING, "Illegal offset type in isset or empty");
5016                    value = NULL;
5017                    break;
5018            }
5019        }
5020
5021        if (opline->extended_value & ZEND_ISSET) {
5022            /* > IS_NULL means not IS_UNDEF and not IS_NULL */
5023            result = value != NULL && Z_TYPE_P(value) > IS_NULL &&
5024                (!Z_ISREF_P(value) || Z_TYPE_P(Z_REFVAL_P(value)) != IS_NULL);
5025        } else /* if (opline->extended_value & ZEND_ISEMPTY) */ {
5026            result = (value == NULL || !i_zend_is_true(value TSRMLS_CC));
5027        }
5028    } else if (Z_TYPE_P(container) == IS_OBJECT) {
5029        if (Z_OBJ_HT_P(container)->has_dimension) {
5030            result = Z_OBJ_HT_P(container)->has_dimension(container, offset, (opline->extended_value & ZEND_ISSET) == 0 TSRMLS_CC);
5031        } else {
5032            zend_error(E_NOTICE, "Trying to check element of non-array");
5033            result = 0;
5034        }
5035        if ((opline->extended_value & ZEND_ISSET) == 0) {
5036            result = !result;
5037        }
5038    } else if (Z_TYPE_P(container) == IS_STRING) { /* string offsets */
5039        zval tmp;
5040
5041        result = 0;
5042        if (UNEXPECTED(Z_TYPE_P(offset) != IS_LONG)) {
5043            if (OP1_TYPE == IS_CV || OP1_TYPE == IS_VAR) {
5044                ZVAL_DEREF(offset);
5045            }
5046            if (Z_TYPE_P(offset) < IS_STRING /* simple scalar types */
5047                    || (Z_TYPE_P(offset) == IS_STRING /* or numeric string */
5048                        && IS_LONG == is_numeric_string(Z_STRVAL_P(offset), Z_STRLEN_P(offset), NULL, NULL, 0))) {
5049                ZVAL_DUP(&tmp, offset);
5050                convert_to_long(&tmp);
5051                offset = &tmp;
5052            }
5053        }
5054        if (Z_TYPE_P(offset) == IS_LONG) {
5055            if (offset->value.lval >= 0 && (size_t)offset->value.lval < Z_STRLEN_P(container)) {
5056                if ((opline->extended_value & ZEND_ISSET) ||
5057                    Z_STRVAL_P(container)[offset->value.lval] != '0') {
5058                    result = 1;
5059                }
5060            }
5061        }
5062        if ((opline->extended_value & ZEND_ISSET) == 0) {
5063            result = !result;
5064        }
5065    } else {
5066        result = ((opline->extended_value & ZEND_ISSET) == 0);
5067    }
5068
5069    FREE_OP2();
5070    ZVAL_BOOL(EX_VAR(opline->result.var), result);
5071    FREE_OP1();
5072    CHECK_EXCEPTION();
5073    ZEND_VM_NEXT_OPCODE();
5074}
5075
5076ZEND_VM_HANDLER(148, ZEND_ISSET_ISEMPTY_PROP_OBJ, CONST|TMP|VAR|UNUSED|CV, CONST|TMP|VAR|CV)
5077{
5078    USE_OPLINE
5079    zend_free_op free_op1, free_op2;
5080    zval *container;
5081    int result;
5082    zval *offset;
5083
5084    SAVE_OPLINE();
5085    container = GET_OP1_OBJ_ZVAL_PTR_DEREF(BP_VAR_IS);
5086    offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
5087
5088    if (Z_TYPE_P(container) == IS_OBJECT) {
5089        if (Z_OBJ_HT_P(container)->has_property) {
5090            result = Z_OBJ_HT_P(container)->has_property(container, offset, (opline->extended_value & ZEND_ISSET) == 0, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(offset)) : NULL) TSRMLS_CC);
5091        } else {
5092            zend_error(E_NOTICE, "Trying to check property of non-object");
5093            result = 0;
5094        }
5095        if ((opline->extended_value & ZEND_ISSET) == 0) {
5096            result = !result;
5097        }
5098    } else {
5099        result = ((opline->extended_value & ZEND_ISSET) == 0);
5100    }
5101