1/*
2   +----------------------------------------------------------------------+
3   | Zend Engine                                                          |
4   +----------------------------------------------------------------------+
5   | Copyright (c) 1998-2015 Zend Technologies Ltd. (http://www.zend.com) |
6   +----------------------------------------------------------------------+
7   | This source file is subject to version 2.00 of the Zend license,     |
8   | that is bundled with this package in the file LICENSE, and is        |
9   | available through the world-wide-web at the following url:           |
10   | http://www.zend.com/license/2_00.txt.                                |
11   | If you did not receive a copy of the Zend license and are unable to  |
12   | obtain it through the world-wide-web, please send a note to          |
13   | license@zend.com so we can mail you a copy immediately.              |
14   +----------------------------------------------------------------------+
15   | Authors: Andi Gutmans <andi@zend.com>                                |
16   |          Zeev Suraski <zeev@zend.com>                                |
17   |          Dmitry Stogov <dmitry@zend.com>                             |
18   +----------------------------------------------------------------------+
19*/
20
21/* $Id$ */
22
23/* If you change this file, please regenerate the zend_vm_execute.h and
24 * zend_vm_opcodes.h files by running:
25 * php zend_vm_gen.php
26 */
27
28ZEND_VM_HANDLER(1, ZEND_ADD, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
29{
30    USE_OPLINE
31    zend_free_op free_op1, free_op2;
32    zval *op1, *op2, *result;
33
34    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
35    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
36    if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
37        if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
38            result = EX_VAR(opline->result.var);
39            fast_long_add_function(result, op1, op2);
40            ZEND_VM_NEXT_OPCODE();
41        } else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
42            result = EX_VAR(opline->result.var);
43            ZVAL_DOUBLE(result, ((double)Z_LVAL_P(op1)) + Z_DVAL_P(op2));
44            ZEND_VM_NEXT_OPCODE();
45        }
46    } else if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_DOUBLE)) {
47        if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
48            result = EX_VAR(opline->result.var);
49            ZVAL_DOUBLE(result, Z_DVAL_P(op1) + Z_DVAL_P(op2));
50            ZEND_VM_NEXT_OPCODE();
51        } else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
52            result = EX_VAR(opline->result.var);
53            ZVAL_DOUBLE(result, Z_DVAL_P(op1) + ((double)Z_LVAL_P(op2)));
54            ZEND_VM_NEXT_OPCODE();
55        }
56    }
57
58    SAVE_OPLINE();
59    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
60        op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
61    }
62    if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
63        op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
64    }
65    add_function(EX_VAR(opline->result.var), op1, op2);
66    FREE_OP1();
67    FREE_OP2();
68    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
69}
70
71ZEND_VM_HANDLER(2, ZEND_SUB, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
72{
73    USE_OPLINE
74    zend_free_op free_op1, free_op2;
75    zval *op1, *op2, *result;
76
77    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
78    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
79    if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
80        if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
81            result = EX_VAR(opline->result.var);
82            fast_long_sub_function(result, op1, op2);
83            ZEND_VM_NEXT_OPCODE();
84        } else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
85            result = EX_VAR(opline->result.var);
86            ZVAL_DOUBLE(result, ((double)Z_LVAL_P(op1)) - Z_DVAL_P(op2));
87            ZEND_VM_NEXT_OPCODE();
88        }
89    } else if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_DOUBLE)) {
90        if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
91            result = EX_VAR(opline->result.var);
92            ZVAL_DOUBLE(result, Z_DVAL_P(op1) - Z_DVAL_P(op2));
93            ZEND_VM_NEXT_OPCODE();
94        } else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
95            result = EX_VAR(opline->result.var);
96            ZVAL_DOUBLE(result, Z_DVAL_P(op1) - ((double)Z_LVAL_P(op2)));
97            ZEND_VM_NEXT_OPCODE();
98        }
99    }
100
101    SAVE_OPLINE();
102    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
103        op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
104    }
105    if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
106        op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
107    }
108    sub_function(EX_VAR(opline->result.var), op1, op2);
109    FREE_OP1();
110    FREE_OP2();
111    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
112}
113
114ZEND_VM_HANDLER(3, ZEND_MUL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
115{
116    USE_OPLINE
117    zend_free_op free_op1, free_op2;
118    zval *op1, *op2, *result;
119
120    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
121    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
122    if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
123        if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
124            zend_long overflow;
125
126            result = EX_VAR(opline->result.var);
127            ZEND_SIGNED_MULTIPLY_LONG(Z_LVAL_P(op1), Z_LVAL_P(op2), Z_LVAL_P(result), Z_DVAL_P(result), overflow);
128            Z_TYPE_INFO_P(result) = overflow ? IS_DOUBLE : IS_LONG;
129            ZEND_VM_NEXT_OPCODE();
130        } else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
131            result = EX_VAR(opline->result.var);
132            ZVAL_DOUBLE(result, ((double)Z_LVAL_P(op1)) * Z_DVAL_P(op2));
133            ZEND_VM_NEXT_OPCODE();
134        }
135    } else if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_DOUBLE)) {
136        if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
137            result = EX_VAR(opline->result.var);
138            ZVAL_DOUBLE(result, Z_DVAL_P(op1) * Z_DVAL_P(op2));
139            ZEND_VM_NEXT_OPCODE();
140        } else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
141            result = EX_VAR(opline->result.var);
142            ZVAL_DOUBLE(result, Z_DVAL_P(op1) * ((double)Z_LVAL_P(op2)));
143            ZEND_VM_NEXT_OPCODE();
144        }
145    }
146
147    SAVE_OPLINE();
148    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
149        op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
150    }
151    if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
152        op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
153    }
154    mul_function(EX_VAR(opline->result.var), op1, op2);
155    FREE_OP1();
156    FREE_OP2();
157    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
158}
159
160ZEND_VM_HANDLER(4, ZEND_DIV, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
161{
162    USE_OPLINE
163    zend_free_op free_op1, free_op2;
164    zval *op1, *op2;
165
166    SAVE_OPLINE();
167    op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
168    op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
169    fast_div_function(EX_VAR(opline->result.var), op1, op2);
170    FREE_OP1();
171    FREE_OP2();
172    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
173}
174
175ZEND_VM_HANDLER(5, ZEND_MOD, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
176{
177    USE_OPLINE
178    zend_free_op free_op1, free_op2;
179    zval *op1, *op2, *result;
180
181    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
182    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
183    if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
184        if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
185            result = EX_VAR(opline->result.var);
186            if (UNEXPECTED(Z_LVAL_P(op2) == 0)) {
187                SAVE_OPLINE();
188                zend_throw_exception_ex(zend_ce_division_by_zero_error, 0, "Modulo by zero");
189                HANDLE_EXCEPTION();
190            } else if (UNEXPECTED(Z_LVAL_P(op2) == -1)) {
191                /* Prevent overflow error/crash if op1==ZEND_LONG_MIN */
192                ZVAL_LONG(result, 0);
193            } else {
194                ZVAL_LONG(result, Z_LVAL_P(op1) % Z_LVAL_P(op2));
195            }
196            ZEND_VM_NEXT_OPCODE();
197        }
198    }
199
200    SAVE_OPLINE();
201    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
202        op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
203    }
204    if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
205        op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
206    }
207    mod_function(EX_VAR(opline->result.var), op1, op2);
208    FREE_OP1();
209    FREE_OP2();
210    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
211}
212
213ZEND_VM_HANDLER(6, ZEND_SL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
214{
215    USE_OPLINE
216    zend_free_op free_op1, free_op2;
217    zval *op1, *op2;
218
219    SAVE_OPLINE();
220    op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
221    op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
222    shift_left_function(EX_VAR(opline->result.var), op1, op2);
223    FREE_OP1();
224    FREE_OP2();
225    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
226}
227
228ZEND_VM_HANDLER(7, ZEND_SR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
229{
230    USE_OPLINE
231    zend_free_op free_op1, free_op2;
232    zval *op1, *op2;
233
234    SAVE_OPLINE();
235    op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
236    op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
237    shift_right_function(EX_VAR(opline->result.var), op1, op2);
238    FREE_OP1();
239    FREE_OP2();
240    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
241}
242
243ZEND_VM_HANDLER(8, ZEND_CONCAT, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
244{
245    USE_OPLINE
246    zend_free_op free_op1, free_op2;
247    zval *op1, *op2;
248
249    SAVE_OPLINE();
250    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
251    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
252
253    do {
254        if ((OP1_TYPE == IS_CONST || EXPECTED(Z_TYPE_P(op1) == IS_STRING)) &&
255            (OP2_TYPE == IS_CONST || EXPECTED(Z_TYPE_P(op2) == IS_STRING))) {
256            zend_string *op1_str = Z_STR_P(op1);
257            zend_string *op2_str = Z_STR_P(op2);
258            zend_string *str;
259
260            if (OP1_TYPE != IS_CONST) {
261                if (UNEXPECTED(ZSTR_LEN(op1_str) == 0)) {
262                    ZVAL_STR_COPY(EX_VAR(opline->result.var), op2_str);
263                    FREE_OP1();
264                    break;
265                }
266            }
267            if (OP2_TYPE != IS_CONST) {
268                if (UNEXPECTED(ZSTR_LEN(op2_str) == 0)) {
269                    ZVAL_STR_COPY(EX_VAR(opline->result.var), op1_str);
270                    FREE_OP1();
271                    break;
272                }
273            }
274            if (OP1_TYPE != IS_CONST && OP1_TYPE != IS_CV &&
275                !ZSTR_IS_INTERNED(op1_str) && GC_REFCOUNT(op1_str) == 1) {
276                size_t len = ZSTR_LEN(op1_str);
277
278                str = zend_string_realloc(op1_str, len + ZSTR_LEN(op2_str), 0);
279                memcpy(ZSTR_VAL(str) + len, ZSTR_VAL(op2_str), ZSTR_LEN(op2_str)+1);
280                ZVAL_NEW_STR(EX_VAR(opline->result.var), str);
281                break;
282            } else {
283                str = zend_string_alloc(ZSTR_LEN(op1_str) + ZSTR_LEN(op2_str), 0);
284                memcpy(ZSTR_VAL(str), ZSTR_VAL(op1_str), ZSTR_LEN(op1_str));
285                memcpy(ZSTR_VAL(str) + ZSTR_LEN(op1_str), ZSTR_VAL(op2_str), ZSTR_LEN(op2_str)+1);
286                ZVAL_NEW_STR(EX_VAR(opline->result.var), str);
287            }
288        } else {
289            if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op1) == IS_UNDEF)) {
290                op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
291            }
292            if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op2) == IS_UNDEF)) {
293                op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
294            }
295            concat_function(EX_VAR(opline->result.var), op1, op2);
296        }
297        FREE_OP1();
298    } while (0);
299    FREE_OP2();
300    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
301}
302
303ZEND_VM_HANDLER(15, ZEND_IS_IDENTICAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
304{
305    USE_OPLINE
306    zend_free_op free_op1, free_op2;
307    zval *op1, *op2;
308    int result;
309
310    SAVE_OPLINE();
311    op1 = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
312    op2 = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
313    result = fast_is_identical_function(op1, op2);
314    FREE_OP1();
315    FREE_OP2();
316    ZEND_VM_SMART_BRANCH(result, (OP1_TYPE|OP2_TYPE) & (IS_VAR|IS_TMP_VAR));
317    ZVAL_BOOL(EX_VAR(opline->result.var), result);
318    if ((OP1_TYPE|OP2_TYPE) & (IS_VAR|IS_TMP_VAR)) {
319        ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
320    }
321    ZEND_VM_NEXT_OPCODE();
322}
323
324ZEND_VM_HANDLER(16, ZEND_IS_NOT_IDENTICAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
325{
326    USE_OPLINE
327    zend_free_op free_op1, free_op2;
328    zval *op1, *op2;
329    int result;
330
331    SAVE_OPLINE();
332    op1 = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
333    op2 = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
334    result = fast_is_not_identical_function(op1, op2);
335    FREE_OP1();
336    FREE_OP2();
337    ZEND_VM_SMART_BRANCH(result, (OP1_TYPE|OP2_TYPE) & (IS_VAR|IS_TMP_VAR));
338    ZVAL_BOOL(EX_VAR(opline->result.var), result);
339    if ((OP1_TYPE|OP2_TYPE) & (IS_VAR|IS_TMP_VAR)) {
340        ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
341    }
342    ZEND_VM_NEXT_OPCODE();
343}
344
345ZEND_VM_HANDLER(17, ZEND_IS_EQUAL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
346{
347    USE_OPLINE
348    zend_free_op free_op1, free_op2;
349    zval *op1, *op2, *result;
350
351    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
352    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
353    do {
354        int result;
355
356        if (EXPECTED(Z_TYPE_P(op1) == IS_LONG)) {
357            if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
358                result = (Z_LVAL_P(op1) == Z_LVAL_P(op2));
359            } else if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
360                result = ((double)Z_LVAL_P(op1) == Z_DVAL_P(op2));
361            } else {
362                break;
363            }
364        } else if (EXPECTED(Z_TYPE_P(op1) == IS_DOUBLE)) {
365            if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
366                result = (Z_DVAL_P(op1) == Z_DVAL_P(op2));
367            } else if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
368                result = (Z_DVAL_P(op1) == ((double)Z_LVAL_P(op2)));
369            } else {
370                break;
371            }
372        } else if (EXPECTED(Z_TYPE_P(op1) == IS_STRING)) {
373            if (EXPECTED(Z_TYPE_P(op2) == IS_STRING)) {
374                if (Z_STR_P(op1) == Z_STR_P(op2)) {
375                    result = 1;
376                } else if (Z_STRVAL_P(op1)[0] > '9' || Z_STRVAL_P(op2)[0] > '9') {
377                    if (Z_STRLEN_P(op1) != Z_STRLEN_P(op2)) {
378                        result = 0;
379                    } else {
380                        result = (memcmp(Z_STRVAL_P(op1), Z_STRVAL_P(op2), Z_STRLEN_P(op1)) == 0);
381                    }
382                } else {
383                    result = (zendi_smart_strcmp(op1, op2) == 0);
384                }
385                FREE_OP1();
386                FREE_OP2();
387            } else {
388                break;
389            }
390        } else {
391            break;
392        }
393        ZEND_VM_SMART_BRANCH(result, 0);
394        ZVAL_BOOL(EX_VAR(opline->result.var), result);
395        ZEND_VM_NEXT_OPCODE();
396    } while (0);
397
398    SAVE_OPLINE();
399    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op1) == IS_UNDEF)) {
400        op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
401    }
402    if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op2) == IS_UNDEF)) {
403        op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
404    }
405    result = EX_VAR(opline->result.var);
406    compare_function(result, op1, op2);
407    ZVAL_BOOL(result, Z_LVAL_P(result) == 0);
408    FREE_OP1();
409    FREE_OP2();
410    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
411}
412
413ZEND_VM_HANDLER(18, ZEND_IS_NOT_EQUAL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
414{
415    USE_OPLINE
416    zend_free_op free_op1, free_op2;
417    zval *op1, *op2, *result;
418
419    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
420    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
421    do {
422        int result;
423
424        if (EXPECTED(Z_TYPE_P(op1) == IS_LONG)) {
425            if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
426                result = (Z_LVAL_P(op1) != Z_LVAL_P(op2));
427            } else if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
428                result = ((double)Z_LVAL_P(op1) != Z_DVAL_P(op2));
429            } else {
430                break;
431            }
432        } else if (EXPECTED(Z_TYPE_P(op1) == IS_DOUBLE)) {
433            if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
434                result = (Z_DVAL_P(op1) != Z_DVAL_P(op2));
435            } else if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
436                result = (Z_DVAL_P(op1) != ((double)Z_LVAL_P(op2)));
437            } else {
438                break;
439            }
440        } else if (EXPECTED(Z_TYPE_P(op1) == IS_STRING)) {
441            if (EXPECTED(Z_TYPE_P(op2) == IS_STRING)) {
442                if (Z_STR_P(op1) == Z_STR_P(op2)) {
443                    result = 0;
444                } else if (Z_STRVAL_P(op1)[0] > '9' || Z_STRVAL_P(op2)[0] > '9') {
445                    if (Z_STRLEN_P(op1) != Z_STRLEN_P(op2)) {
446                        result = 1;
447                    } else {
448                        result = (memcmp(Z_STRVAL_P(op1), Z_STRVAL_P(op2), Z_STRLEN_P(op1)) != 0);
449                    }
450                } else {
451                    result = (zendi_smart_strcmp(op1, op2) != 0);
452                }
453                FREE_OP1();
454                FREE_OP2();
455            } else {
456                break;
457            }
458        } else {
459            break;
460        }
461        ZEND_VM_SMART_BRANCH(result, 0);
462        ZVAL_BOOL(EX_VAR(opline->result.var), result);
463        ZEND_VM_NEXT_OPCODE();
464    } while (0);
465
466    SAVE_OPLINE();
467    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op1) == IS_UNDEF)) {
468        op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
469    }
470    if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op2) == IS_UNDEF)) {
471        op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
472    }
473    result = EX_VAR(opline->result.var);
474    compare_function(result, op1, op2);
475    ZVAL_BOOL(result, Z_LVAL_P(result) != 0);
476    FREE_OP1();
477    FREE_OP2();
478    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
479}
480
481ZEND_VM_HANDLER(19, ZEND_IS_SMALLER, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
482{
483    USE_OPLINE
484    zend_free_op free_op1, free_op2;
485    zval *op1, *op2, *result;
486
487    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
488    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
489    do {
490        int result;
491
492        if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
493            if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
494                result = (Z_LVAL_P(op1) < Z_LVAL_P(op2));
495            } else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
496                result = ((double)Z_LVAL_P(op1) < Z_DVAL_P(op2));
497            } else {
498                break;
499            }
500        } else if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_DOUBLE)) {
501            if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
502                result = (Z_DVAL_P(op1) < Z_DVAL_P(op2));
503            } else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
504                result = (Z_DVAL_P(op1) < ((double)Z_LVAL_P(op2)));
505            } else {
506                break;
507            }
508        } else {
509            break;
510        }
511        ZEND_VM_SMART_BRANCH(result, 0);
512        ZVAL_BOOL(EX_VAR(opline->result.var), result);
513        ZEND_VM_NEXT_OPCODE();
514    } while (0);
515
516    SAVE_OPLINE();
517    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
518        op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
519    }
520    if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
521        op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
522    }
523    result = EX_VAR(opline->result.var);
524    compare_function(result, op1, op2);
525    ZVAL_BOOL(result, Z_LVAL_P(result) < 0);
526    FREE_OP1();
527    FREE_OP2();
528    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
529}
530
531ZEND_VM_HANDLER(20, ZEND_IS_SMALLER_OR_EQUAL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
532{
533    USE_OPLINE
534    zend_free_op free_op1, free_op2;
535    zval *op1, *op2, *result;
536
537    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
538    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
539    do {
540        int result;
541
542        if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
543            if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
544                result = (Z_LVAL_P(op1) <= Z_LVAL_P(op2));
545            } else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
546                result = ((double)Z_LVAL_P(op1) <= Z_DVAL_P(op2));
547            } else {
548                break;
549            }
550        } else if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_DOUBLE)) {
551            if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
552                result = (Z_DVAL_P(op1) <= Z_DVAL_P(op2));
553            } else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
554                result = (Z_DVAL_P(op1) <= ((double)Z_LVAL_P(op2)));
555            } else {
556                break;
557            }
558        } else {
559            break;
560        }
561        ZEND_VM_SMART_BRANCH(result, 0);
562        ZVAL_BOOL(EX_VAR(opline->result.var), result);
563        ZEND_VM_NEXT_OPCODE();
564    } while (0);
565
566    SAVE_OPLINE();
567    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
568        op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
569    }
570    if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
571        op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
572    }
573    result = EX_VAR(opline->result.var);
574    compare_function(result, op1, op2);
575    ZVAL_BOOL(result, Z_LVAL_P(result) <= 0);
576    FREE_OP1();
577    FREE_OP2();
578    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
579}
580
581ZEND_VM_HANDLER(170, ZEND_SPACESHIP, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
582{
583    USE_OPLINE
584    zend_free_op free_op1, free_op2;
585    zval *op1, *op2;
586
587    SAVE_OPLINE();
588    op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
589    op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
590    compare_function(EX_VAR(opline->result.var), op1, op2);
591    FREE_OP1();
592    FREE_OP2();
593    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
594}
595
596ZEND_VM_HANDLER(9, ZEND_BW_OR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
597{
598    USE_OPLINE
599    zend_free_op free_op1, free_op2;
600    zval *op1, *op2;
601
602    SAVE_OPLINE();
603    op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
604    op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
605    bitwise_or_function(EX_VAR(opline->result.var), op1, op2);
606    FREE_OP1();
607    FREE_OP2();
608    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
609}
610
611ZEND_VM_HANDLER(10, ZEND_BW_AND, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
612{
613    USE_OPLINE
614    zend_free_op free_op1, free_op2;
615    zval *op1, *op2;
616
617    SAVE_OPLINE();
618    op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
619    op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
620    bitwise_and_function(EX_VAR(opline->result.var), op1, op2);
621    FREE_OP1();
622    FREE_OP2();
623    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
624}
625
626ZEND_VM_HANDLER(11, ZEND_BW_XOR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
627{
628    USE_OPLINE
629    zend_free_op free_op1, free_op2;
630    zval *op1, *op2;
631
632    SAVE_OPLINE();
633    op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
634    op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
635    bitwise_xor_function(EX_VAR(opline->result.var), op1, op2);
636    FREE_OP1();
637    FREE_OP2();
638    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
639}
640
641ZEND_VM_HANDLER(14, ZEND_BOOL_XOR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
642{
643    USE_OPLINE
644    zend_free_op free_op1, free_op2;
645    zval *op1, *op2;
646
647    SAVE_OPLINE();
648    op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
649    op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
650    boolean_xor_function(EX_VAR(opline->result.var), op1, op2);
651    FREE_OP1();
652    FREE_OP2();
653    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
654}
655
656ZEND_VM_HANDLER(12, ZEND_BW_NOT, CONST|TMPVAR|CV, ANY)
657{
658    USE_OPLINE
659    zend_free_op free_op1;
660
661    SAVE_OPLINE();
662    bitwise_not_function(EX_VAR(opline->result.var),
663        GET_OP1_ZVAL_PTR(BP_VAR_R));
664    FREE_OP1();
665    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
666}
667
668ZEND_VM_HANDLER(13, ZEND_BOOL_NOT, CONST|TMPVAR|CV, ANY)
669{
670    USE_OPLINE
671    zval *val;
672    zend_free_op free_op1;
673
674    val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
675    if (Z_TYPE_INFO_P(val) == IS_TRUE) {
676        ZVAL_FALSE(EX_VAR(opline->result.var));
677    } else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
678        ZVAL_TRUE(EX_VAR(opline->result.var));
679        if (UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
680            SAVE_OPLINE();
681            GET_OP1_UNDEF_CV(val, BP_VAR_R);
682            ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
683        }
684    } else {
685        SAVE_OPLINE();
686        ZVAL_BOOL(EX_VAR(opline->result.var), !i_zend_is_true(val));
687        FREE_OP1();
688        ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
689    }
690    ZEND_VM_NEXT_OPCODE();
691}
692
693ZEND_VM_HELPER_EX(zend_binary_assign_op_obj_helper, VAR|UNUSED|CV, CONST|TMPVAR|CV, binary_op_type binary_op)
694{
695    USE_OPLINE
696    zend_free_op free_op1, free_op2, free_op_data1;
697    zval *object;
698    zval *property;
699    zval *value;
700    zval *zptr;
701
702    SAVE_OPLINE();
703    object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
704
705    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(object) == NULL)) {
706        zend_throw_error(NULL, "Using $this when not in object context");
707        FREE_UNFETCHED_OP((opline+1)->op1_type, (opline+1)->op1.var);
708        FREE_UNFETCHED_OP2();
709        HANDLE_EXCEPTION();
710    }
711
712    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
713
714    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
715        zend_throw_error(NULL, "Cannot use string offset as an object");
716        FREE_UNFETCHED_OP((opline+1)->op1_type, (opline+1)->op1.var);
717        FREE_OP2();
718        HANDLE_EXCEPTION();
719    }
720
721    do {
722        value = get_zval_ptr((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
723
724        if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
725            ZVAL_DEREF(object);
726            if (UNEXPECTED(!make_real_object(object))) {
727                zend_error(E_WARNING, "Attempt to assign property of non-object");
728                if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
729                    ZVAL_NULL(EX_VAR(opline->result.var));
730                }
731                break;
732            }
733        }
734
735        /* here we are sure we are dealing with an object */
736        if (EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
737            && EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL))) != NULL)) {
738
739            ZVAL_DEREF(zptr);
740            SEPARATE_ZVAL_NOREF(zptr);
741
742            binary_op(zptr, zptr, value);
743            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
744                ZVAL_COPY(EX_VAR(opline->result.var), zptr);
745            }
746        } else {
747            zend_assign_op_overloaded_property(object, property, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), value, binary_op, (UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL));
748        }
749    } while (0);
750
751    FREE_OP(free_op_data1);
752    FREE_OP2();
753    FREE_OP1_VAR_PTR();
754    /* assign_obj has two opcodes! */
755    ZEND_VM_NEXT_OPCODE_EX(1, 2);
756}
757
758ZEND_VM_HELPER_EX(zend_binary_assign_op_dim_helper, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV, binary_op_type binary_op)
759{
760    USE_OPLINE
761    zend_free_op free_op1, free_op2, free_op_data1;
762    zval *var_ptr, rv;
763    zval *value, *container, *dim;
764
765    SAVE_OPLINE();
766    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
767    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
768        zend_throw_error(NULL, "Using $this when not in object context");
769        FREE_UNFETCHED_OP((opline+1)->op1_type, (opline+1)->op1.var);
770        FREE_UNFETCHED_OP2();
771        HANDLE_EXCEPTION();
772    }
773    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
774        zend_throw_error(NULL, "Cannot use string offset as an array");
775        FREE_UNFETCHED_OP((opline+1)->op1_type, (opline+1)->op1.var);
776        FREE_UNFETCHED_OP2();
777        HANDLE_EXCEPTION();
778    }
779
780    dim = GET_OP2_ZVAL_PTR(BP_VAR_R);
781
782    do {
783        if (OP1_TYPE == IS_UNUSED || UNEXPECTED(Z_TYPE_P(container) != IS_ARRAY)) {
784            if (OP1_TYPE != IS_UNUSED) {
785                ZVAL_DEREF(container);
786            }
787            if (OP1_TYPE == IS_UNUSED || EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
788                value = get_zval_ptr((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
789                zend_binary_assign_op_obj_dim(container, dim, value, UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL, binary_op);
790                break;
791            }
792        }
793
794        zend_fetch_dimension_address_RW(&rv, container, dim, OP2_TYPE);
795        value = get_zval_ptr((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
796        ZEND_ASSERT(Z_TYPE(rv) == IS_INDIRECT);
797        var_ptr = Z_INDIRECT(rv);
798
799        if (UNEXPECTED(var_ptr == NULL)) {
800            zend_throw_error(NULL, "Cannot use assign-op operators with overloaded objects nor string offsets");
801            FREE_OP2();
802            FREE_OP(free_op_data1);
803            FREE_OP1_VAR_PTR();
804            HANDLE_EXCEPTION();
805        }
806
807        if (UNEXPECTED(var_ptr == &EG(error_zval))) {
808            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
809                ZVAL_NULL(EX_VAR(opline->result.var));
810            }
811        } else {
812            ZVAL_DEREF(var_ptr);
813            SEPARATE_ZVAL_NOREF(var_ptr);
814
815            binary_op(var_ptr, var_ptr, value);
816
817            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
818                ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
819            }
820        }
821    } while (0);
822
823    FREE_OP2();
824    FREE_OP(free_op_data1);
825    FREE_OP1_VAR_PTR();
826    ZEND_VM_NEXT_OPCODE_EX(1, 2);
827}
828
829ZEND_VM_HELPER_EX(zend_binary_assign_op_helper, VAR|CV, CONST|TMPVAR|CV, binary_op_type binary_op)
830{
831    USE_OPLINE
832    zend_free_op free_op1, free_op2;
833    zval *var_ptr;
834    zval *value;
835
836    SAVE_OPLINE();
837    value = GET_OP2_ZVAL_PTR(BP_VAR_R);
838    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
839
840    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
841        zend_throw_error(NULL, "Cannot use assign-op operators with overloaded objects nor string offsets");
842        FREE_OP2();
843        HANDLE_EXCEPTION();
844    }
845
846    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
847        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
848            ZVAL_NULL(EX_VAR(opline->result.var));
849        }
850    } else {
851        ZVAL_DEREF(var_ptr);
852        SEPARATE_ZVAL_NOREF(var_ptr);
853
854        binary_op(var_ptr, var_ptr, value);
855
856        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
857            ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
858        }
859    }
860
861    FREE_OP2();
862    FREE_OP1_VAR_PTR();
863    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
864}
865
866ZEND_VM_HANDLER(23, ZEND_ASSIGN_ADD, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
867{
868#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
869    USE_OPLINE
870
871# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
872    if (EXPECTED(opline->extended_value == 0)) {
873        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, add_function);
874    }
875# endif
876    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
877        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, add_function);
878    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
879        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, add_function);
880    }
881#else
882    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, add_function);
883#endif
884}
885
886ZEND_VM_HANDLER(24, ZEND_ASSIGN_SUB, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
887{
888#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
889    USE_OPLINE
890
891# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
892    if (EXPECTED(opline->extended_value == 0)) {
893        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, sub_function);
894    }
895# endif
896    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
897        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, sub_function);
898    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
899        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, sub_function);
900    }
901#else
902    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, sub_function);
903#endif
904}
905
906ZEND_VM_HANDLER(25, ZEND_ASSIGN_MUL, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
907{
908#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
909    USE_OPLINE
910
911# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
912    if (EXPECTED(opline->extended_value == 0)) {
913        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, mul_function);
914    }
915# endif
916    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
917        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, mul_function);
918    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
919        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, mul_function);
920    }
921#else
922    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, mul_function);
923#endif
924}
925
926ZEND_VM_HANDLER(26, ZEND_ASSIGN_DIV, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
927{
928#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
929    USE_OPLINE
930
931# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
932    if (EXPECTED(opline->extended_value == 0)) {
933        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, div_function);
934    }
935# endif
936    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
937        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, div_function);
938    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
939        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, div_function);
940    }
941#else
942    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, div_function);
943#endif
944}
945
946ZEND_VM_HANDLER(27, ZEND_ASSIGN_MOD, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
947{
948#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
949    USE_OPLINE
950
951# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
952    if (EXPECTED(opline->extended_value == 0)) {
953        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, mod_function);
954    }
955# endif
956    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
957        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, mod_function);
958    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
959        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, mod_function);
960    }
961#else
962    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, mod_function);
963#endif
964}
965
966ZEND_VM_HANDLER(28, ZEND_ASSIGN_SL, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
967{
968#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
969    USE_OPLINE
970
971# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
972    if (EXPECTED(opline->extended_value == 0)) {
973        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, shift_left_function);
974    }
975# endif
976    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
977        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, shift_left_function);
978    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
979        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, shift_left_function);
980    }
981#else
982    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, shift_left_function);
983#endif
984}
985
986ZEND_VM_HANDLER(29, ZEND_ASSIGN_SR, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
987{
988#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
989    USE_OPLINE
990
991# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
992    if (EXPECTED(opline->extended_value == 0)) {
993        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, shift_right_function);
994    }
995# endif
996    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
997        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, shift_right_function);
998    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
999        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, shift_right_function);
1000    }
1001#else
1002    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, shift_right_function);
1003#endif
1004}
1005
1006ZEND_VM_HANDLER(30, ZEND_ASSIGN_CONCAT, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
1007{
1008#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
1009    USE_OPLINE
1010
1011# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
1012    if (EXPECTED(opline->extended_value == 0)) {
1013        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, concat_function);
1014    }
1015# endif
1016    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
1017        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, concat_function);
1018    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
1019        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, concat_function);
1020    }
1021#else
1022    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, concat_function);
1023#endif
1024}
1025
1026ZEND_VM_HANDLER(31, ZEND_ASSIGN_BW_OR, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
1027{
1028#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
1029    USE_OPLINE
1030
1031# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
1032    if (EXPECTED(opline->extended_value == 0)) {
1033        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, bitwise_or_function);
1034    }
1035# endif
1036    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
1037        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_or_function);
1038    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
1039        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, bitwise_or_function);
1040    }
1041#else
1042    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_or_function);
1043#endif
1044}
1045
1046ZEND_VM_HANDLER(32, ZEND_ASSIGN_BW_AND, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
1047{
1048#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
1049    USE_OPLINE
1050
1051# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
1052    if (EXPECTED(opline->extended_value == 0)) {
1053        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, bitwise_and_function);
1054    }
1055# endif
1056    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
1057        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_and_function);
1058    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
1059        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, bitwise_and_function);
1060    }
1061#else
1062    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_and_function);
1063#endif
1064}
1065
1066ZEND_VM_HANDLER(33, ZEND_ASSIGN_BW_XOR, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
1067{
1068#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
1069    USE_OPLINE
1070
1071# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
1072    if (EXPECTED(opline->extended_value == 0)) {
1073        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, bitwise_xor_function);
1074    }
1075# endif
1076    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
1077        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_xor_function);
1078    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
1079        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, bitwise_xor_function);
1080    }
1081#else
1082    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_xor_function);
1083#endif
1084}
1085
1086ZEND_VM_HELPER_EX(zend_pre_incdec_property_helper, VAR|UNUSED|CV, CONST|TMPVAR|CV, int inc)
1087{
1088    USE_OPLINE
1089    zend_free_op free_op1, free_op2;
1090    zval *object;
1091    zval *property;
1092    zval *zptr;
1093
1094    SAVE_OPLINE();
1095    object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
1096
1097    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(object) == NULL)) {
1098        zend_throw_error(NULL, "Using $this when not in object context");
1099        FREE_UNFETCHED_OP2();
1100        HANDLE_EXCEPTION();
1101    }
1102
1103    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1104
1105    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
1106        zend_throw_error(NULL, "Cannot increment/decrement overloaded objects nor string offsets");
1107        FREE_OP2();
1108        HANDLE_EXCEPTION();
1109    }
1110
1111    do {
1112        if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
1113            ZVAL_DEREF(object);
1114            if (UNEXPECTED(!make_real_object(object))) {
1115                zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
1116                if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1117                    ZVAL_NULL(EX_VAR(opline->result.var));
1118                }
1119                break;
1120            }
1121        }
1122
1123        /* here we are sure we are dealing with an object */
1124
1125        if (EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
1126            && EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL))) != NULL)) {
1127
1128            if (EXPECTED(Z_TYPE_P(zptr) == IS_LONG)) {
1129                if (inc) {
1130                    fast_long_increment_function(zptr);
1131                } else {
1132                    fast_long_decrement_function(zptr);
1133                }
1134            } else {
1135                ZVAL_DEREF(zptr);
1136                SEPARATE_ZVAL_NOREF(zptr);
1137
1138                if (inc) {
1139                    increment_function(zptr);
1140                } else {
1141                    decrement_function(zptr);
1142                }
1143            }
1144            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1145                ZVAL_COPY(EX_VAR(opline->result.var), zptr);
1146            }
1147        } else {
1148            zend_pre_incdec_overloaded_property(object, property, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), inc, (UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL));
1149        }
1150    } while (0);
1151
1152    FREE_OP2();
1153    FREE_OP1_VAR_PTR();
1154    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1155}
1156
1157ZEND_VM_HANDLER(132, ZEND_PRE_INC_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
1158{
1159    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_pre_incdec_property_helper, inc, 1);
1160}
1161
1162ZEND_VM_HANDLER(133, ZEND_PRE_DEC_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
1163{
1164    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_pre_incdec_property_helper, inc, 0);
1165}
1166
1167ZEND_VM_HELPER_EX(zend_post_incdec_property_helper, VAR|UNUSED|CV, CONST|TMPVAR|CV, int inc)
1168{
1169    USE_OPLINE
1170    zend_free_op free_op1, free_op2;
1171    zval *object;
1172    zval *property;
1173    zval *zptr;
1174
1175    SAVE_OPLINE();
1176    object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
1177
1178    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(object) == NULL)) {
1179        zend_throw_error(NULL, "Using $this when not in object context");
1180        FREE_UNFETCHED_OP2();
1181        HANDLE_EXCEPTION();
1182    }
1183
1184    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1185
1186    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
1187        zend_throw_error(NULL, "Cannot increment/decrement overloaded objects nor string offsets");
1188        FREE_OP2();
1189        HANDLE_EXCEPTION();
1190    }
1191
1192    do {
1193        if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
1194            ZVAL_DEREF(object);
1195            if (UNEXPECTED(!make_real_object(object))) {
1196                zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
1197                ZVAL_NULL(EX_VAR(opline->result.var));
1198                break;
1199            }
1200        }
1201
1202        /* here we are sure we are dealing with an object */
1203
1204        if (EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
1205            && EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL))) != NULL)) {
1206
1207            if (EXPECTED(Z_TYPE_P(zptr) == IS_LONG)) {
1208                ZVAL_COPY_VALUE(EX_VAR(opline->result.var), zptr);
1209                if (inc) {
1210                    fast_long_increment_function(zptr);
1211                } else {
1212                    fast_long_decrement_function(zptr);
1213                }
1214            } else {
1215                ZVAL_DEREF(zptr);
1216                ZVAL_COPY_VALUE(EX_VAR(opline->result.var), zptr);
1217                zval_opt_copy_ctor(zptr);
1218                if (inc) {
1219                    increment_function(zptr);
1220                } else {
1221                    decrement_function(zptr);
1222                }
1223            }
1224        } else {
1225            zend_post_incdec_overloaded_property(object, property, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), inc, EX_VAR(opline->result.var));
1226        }
1227    } while (0);
1228
1229    FREE_OP2();
1230    FREE_OP1_VAR_PTR();
1231    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1232}
1233
1234ZEND_VM_HANDLER(134, ZEND_POST_INC_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
1235{
1236    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_post_incdec_property_helper, inc, 1);
1237}
1238
1239ZEND_VM_HANDLER(135, ZEND_POST_DEC_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
1240{
1241    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_post_incdec_property_helper, inc, 0);
1242}
1243
1244ZEND_VM_HANDLER(34, ZEND_PRE_INC, VAR|CV, ANY)
1245{
1246    USE_OPLINE
1247    zend_free_op free_op1;
1248    zval *var_ptr;
1249
1250    var_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_RW);
1251
1252    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
1253        SAVE_OPLINE();
1254        zend_throw_error(NULL, "Cannot increment/decrement overloaded objects nor string offsets");
1255        HANDLE_EXCEPTION();
1256    }
1257
1258    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1259        fast_long_increment_function(var_ptr);
1260        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1261            ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1262        }
1263        ZEND_VM_NEXT_OPCODE();
1264    }
1265
1266    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
1267        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1268            ZVAL_NULL(EX_VAR(opline->result.var));
1269        }
1270        ZEND_VM_NEXT_OPCODE();
1271    }
1272
1273    SAVE_OPLINE();
1274    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var_ptr) == IS_UNDEF)) {
1275        var_ptr = GET_OP1_UNDEF_CV(var_ptr, BP_VAR_RW);
1276    }
1277    ZVAL_DEREF(var_ptr);
1278    SEPARATE_ZVAL_NOREF(var_ptr);
1279
1280    increment_function(var_ptr);
1281
1282    if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1283        ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
1284    }
1285
1286    FREE_OP1_VAR_PTR();
1287    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1288}
1289
1290ZEND_VM_HANDLER(35, ZEND_PRE_DEC, VAR|CV, ANY)
1291{
1292    USE_OPLINE
1293    zend_free_op free_op1;
1294    zval *var_ptr;
1295
1296    var_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_RW);
1297
1298    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
1299        SAVE_OPLINE();
1300        zend_throw_error(NULL, "Cannot increment/decrement overloaded objects nor string offsets");
1301        HANDLE_EXCEPTION();
1302    }
1303
1304    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1305        fast_long_decrement_function(var_ptr);
1306        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1307            ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1308        }
1309        ZEND_VM_NEXT_OPCODE();
1310    }
1311
1312    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
1313        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1314            ZVAL_NULL(EX_VAR(opline->result.var));
1315        }
1316        ZEND_VM_NEXT_OPCODE();
1317    }
1318
1319    SAVE_OPLINE();
1320    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var_ptr) == IS_UNDEF)) {
1321        var_ptr = GET_OP1_UNDEF_CV(var_ptr, BP_VAR_RW);
1322    }
1323    ZVAL_DEREF(var_ptr);
1324    SEPARATE_ZVAL_NOREF(var_ptr);
1325
1326    decrement_function(var_ptr);
1327
1328    if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1329        ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
1330    }
1331
1332    FREE_OP1_VAR_PTR();
1333    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1334}
1335
1336ZEND_VM_HANDLER(36, ZEND_POST_INC, VAR|CV, ANY)
1337{
1338    USE_OPLINE
1339    zend_free_op free_op1;
1340    zval *var_ptr;
1341
1342    var_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_RW);
1343
1344    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
1345        SAVE_OPLINE();
1346        zend_throw_error(NULL, "Cannot increment/decrement overloaded objects nor string offsets");
1347        HANDLE_EXCEPTION();
1348    }
1349
1350    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1351        ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1352        fast_long_increment_function(var_ptr);
1353        ZEND_VM_NEXT_OPCODE();
1354    }
1355
1356    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
1357        ZVAL_NULL(EX_VAR(opline->result.var));
1358        ZEND_VM_NEXT_OPCODE();
1359    }
1360
1361    SAVE_OPLINE();
1362    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var_ptr) == IS_UNDEF)) {
1363        var_ptr = GET_OP1_UNDEF_CV(var_ptr, BP_VAR_RW);
1364    }
1365    ZVAL_DEREF(var_ptr);
1366    ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1367    zval_opt_copy_ctor(var_ptr);
1368
1369    increment_function(var_ptr);
1370
1371    FREE_OP1_VAR_PTR();
1372    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1373}
1374
1375ZEND_VM_HANDLER(37, ZEND_POST_DEC, VAR|CV, ANY)
1376{
1377    USE_OPLINE
1378    zend_free_op free_op1;
1379    zval *var_ptr;
1380
1381    var_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_RW);
1382
1383    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
1384        SAVE_OPLINE();
1385        zend_throw_error(NULL, "Cannot increment/decrement overloaded objects nor string offsets");
1386        HANDLE_EXCEPTION();
1387    }
1388
1389    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1390        ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1391        fast_long_decrement_function(var_ptr);
1392        ZEND_VM_NEXT_OPCODE();
1393    }
1394
1395    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
1396        ZVAL_NULL(EX_VAR(opline->result.var));
1397        ZEND_VM_NEXT_OPCODE();
1398    }
1399
1400    SAVE_OPLINE();
1401    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var_ptr) == IS_UNDEF)) {
1402        var_ptr = GET_OP1_UNDEF_CV(var_ptr, BP_VAR_RW);
1403    }
1404    ZVAL_DEREF(var_ptr);
1405    ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1406    zval_opt_copy_ctor(var_ptr);
1407
1408    decrement_function(var_ptr);
1409
1410    FREE_OP1_VAR_PTR();
1411    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1412}
1413
1414ZEND_VM_HANDLER(40, ZEND_ECHO, CONST|TMPVAR|CV, ANY)
1415{
1416    USE_OPLINE
1417    zend_free_op free_op1;
1418    zval *z;
1419
1420    SAVE_OPLINE();
1421    z = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
1422
1423    if (Z_TYPE_P(z) == IS_STRING) {
1424        zend_string *str = Z_STR_P(z);
1425
1426        if (ZSTR_LEN(str) != 0) {
1427            zend_write(ZSTR_VAL(str), ZSTR_LEN(str));
1428        }
1429    } else {
1430        zend_string *str = _zval_get_string_func(z);
1431
1432        if (ZSTR_LEN(str) != 0) {
1433            zend_write(ZSTR_VAL(str), ZSTR_LEN(str));
1434        } else if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(z) == IS_UNDEF)) {
1435            GET_OP1_UNDEF_CV(z, BP_VAR_R);
1436        }
1437        zend_string_release(str);
1438    }
1439
1440    FREE_OP1();
1441    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1442}
1443
1444ZEND_VM_HELPER_EX(zend_fetch_var_address_helper, CONST|TMPVAR|CV, UNUSED|CONST|VAR, int type)
1445{
1446    USE_OPLINE
1447    zend_free_op free_op1;
1448    zval *varname;
1449    zval *retval;
1450    zend_string *name;
1451    HashTable *target_symbol_table;
1452
1453    SAVE_OPLINE();
1454    varname = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
1455
1456    if (OP1_TYPE == IS_CONST) {
1457        name = Z_STR_P(varname);
1458    } else if (EXPECTED(Z_TYPE_P(varname) == IS_STRING)) {
1459        name = Z_STR_P(varname);
1460        zend_string_addref(name);
1461    } else {
1462        if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(varname) == IS_UNDEF)) {
1463            GET_OP1_UNDEF_CV(varname, BP_VAR_R);
1464        }
1465        name = zval_get_string(varname);
1466    }
1467
1468    if (OP2_TYPE != IS_UNUSED) {
1469        zend_class_entry *ce;
1470
1471        if (OP2_TYPE == IS_CONST) {
1472            if (OP1_TYPE == IS_CONST && EXPECTED((ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)))) != NULL)) {
1473                retval = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)) + sizeof(void*));
1474
1475                /* check if static properties were destoyed */
1476                if (UNEXPECTED(CE_STATIC_MEMBERS(ce) == NULL)) {
1477                    zend_throw_error(NULL, "Access to undeclared static property: %s::$%s", ZSTR_VAL(ce->name), ZSTR_VAL(name));
1478                    FREE_OP1();
1479                    HANDLE_EXCEPTION();
1480                }
1481
1482                ZEND_VM_C_GOTO(fetch_var_return);
1483            } else if (UNEXPECTED((ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) == NULL)) {
1484                ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op2)), EX_CONSTANT(opline->op2) + 1, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
1485                if (UNEXPECTED(ce == NULL)) {
1486                    if (OP1_TYPE != IS_CONST) {
1487                        zend_string_release(name);
1488                    }
1489                    FREE_OP1();
1490                    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1491                }
1492                CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce);
1493            }
1494        } else {
1495            ce = Z_CE_P(EX_VAR(opline->op2.var));
1496            if (OP1_TYPE == IS_CONST &&
1497                (retval = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce)) != NULL) {
1498
1499                /* check if static properties were destoyed */
1500                if (UNEXPECTED(CE_STATIC_MEMBERS(ce) == NULL)) {
1501                    zend_throw_error(NULL, "Access to undeclared static property: %s::$%s", ZSTR_VAL(ce->name), ZSTR_VAL(name));
1502                    FREE_OP1();
1503                    HANDLE_EXCEPTION();
1504                }
1505
1506                ZEND_VM_C_GOTO(fetch_var_return);
1507            }
1508        }
1509        retval = zend_std_get_static_property(ce, name, 0);
1510        if (UNEXPECTED(EG(exception))) {
1511            FREE_OP1();
1512            HANDLE_EXCEPTION();
1513        }
1514        if (OP1_TYPE == IS_CONST && retval) {
1515            CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce, retval);
1516        }
1517
1518        FREE_OP1();
1519    } else {
1520        target_symbol_table = zend_get_target_symbol_table(execute_data, opline->extended_value & ZEND_FETCH_TYPE_MASK);
1521        retval = zend_hash_find(target_symbol_table, name);
1522        if (retval == NULL) {
1523            switch (type) {
1524                case BP_VAR_R:
1525                case BP_VAR_UNSET:
1526                    zend_error(E_NOTICE,"Undefined variable: %s", ZSTR_VAL(name));
1527                    /* break missing intentionally */
1528                case BP_VAR_IS:
1529                    retval = &EG(uninitialized_zval);
1530                    break;
1531                case BP_VAR_RW:
1532                    zend_error(E_NOTICE,"Undefined variable: %s", ZSTR_VAL(name));
1533                    /* break missing intentionally */
1534                case BP_VAR_W:
1535                    retval = zend_hash_add_new(target_symbol_table, name, &EG(uninitialized_zval));
1536                    break;
1537                EMPTY_SWITCH_DEFAULT_CASE()
1538            }
1539        /* GLOBAL or $$name variable may be an INDIRECT pointer to CV */
1540        } else if (Z_TYPE_P(retval) == IS_INDIRECT) {
1541            retval = Z_INDIRECT_P(retval);
1542            if (Z_TYPE_P(retval) == IS_UNDEF) {
1543                switch (type) {
1544                    case BP_VAR_R:
1545                    case BP_VAR_UNSET:
1546                        zend_error(E_NOTICE,"Undefined variable: %s", ZSTR_VAL(name));
1547                        /* break missing intentionally */
1548                    case BP_VAR_IS:
1549                        retval = &EG(uninitialized_zval);
1550                        break;
1551                    case BP_VAR_RW:
1552                        zend_error(E_NOTICE,"Undefined variable: %s", ZSTR_VAL(name));
1553                        /* break missing intentionally */
1554                    case BP_VAR_W:
1555                        ZVAL_NULL(retval);
1556                        break;
1557                    EMPTY_SWITCH_DEFAULT_CASE()
1558                }
1559            }
1560        }
1561        if ((opline->extended_value & ZEND_FETCH_TYPE_MASK) == ZEND_FETCH_STATIC) {
1562            if (Z_CONSTANT_P(retval)) {
1563                if (UNEXPECTED(zval_update_constant_ex(retval, 1, NULL) != SUCCESS)) {
1564                    FREE_OP1();
1565                    HANDLE_EXCEPTION();
1566                }
1567            }
1568        } else if ((opline->extended_value & ZEND_FETCH_TYPE_MASK) != ZEND_FETCH_GLOBAL_LOCK) {
1569            FREE_OP1();
1570        }
1571    }
1572
1573    if (OP1_TYPE != IS_CONST) {
1574        zend_string_release(name);
1575    }
1576
1577ZEND_VM_C_LABEL(fetch_var_return):
1578    ZEND_ASSERT(retval != NULL);
1579    if (type == BP_VAR_R || type == BP_VAR_IS) {
1580        if (/*type == BP_VAR_R &&*/ Z_ISREF_P(retval) && Z_REFCOUNT_P(retval) == 1) {
1581            ZVAL_UNREF(retval);
1582        }
1583        ZVAL_COPY(EX_VAR(opline->result.var), retval);
1584    } else {
1585        ZVAL_INDIRECT(EX_VAR(opline->result.var), retval);
1586    }
1587    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1588}
1589
1590ZEND_VM_HANDLER(80, ZEND_FETCH_R, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1591{
1592    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_R);
1593}
1594
1595ZEND_VM_HANDLER(83, ZEND_FETCH_W, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1596{
1597    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_W);
1598}
1599
1600ZEND_VM_HANDLER(86, ZEND_FETCH_RW, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1601{
1602    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_RW);
1603}
1604
1605ZEND_VM_HANDLER(92, ZEND_FETCH_FUNC_ARG, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1606{
1607    USE_OPLINE
1608
1609    if (zend_is_by_ref_func_arg_fetch(opline, EX(call))) {
1610        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_W);
1611    } else {
1612        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_R);
1613    }
1614}
1615
1616ZEND_VM_HANDLER(95, ZEND_FETCH_UNSET, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1617{
1618    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_UNSET);
1619}
1620
1621ZEND_VM_HANDLER(89, ZEND_FETCH_IS, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1622{
1623    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_IS);
1624}
1625
1626ZEND_VM_HANDLER(81, ZEND_FETCH_DIM_R, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
1627{
1628    USE_OPLINE
1629    zend_free_op free_op1, free_op2;
1630    zval *container;
1631
1632    SAVE_OPLINE();
1633    container = GET_OP1_ZVAL_PTR(BP_VAR_R);
1634    zend_fetch_dimension_address_read_R(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1635    FREE_OP2();
1636    FREE_OP1();
1637    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1638}
1639
1640ZEND_VM_HANDLER(84, ZEND_FETCH_DIM_W, VAR|CV, CONST|TMPVAR|UNUSED|CV)
1641{
1642    USE_OPLINE
1643    zend_free_op free_op1, free_op2;
1644    zval *container;
1645
1646    SAVE_OPLINE();
1647    container = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1648
1649    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1650        zend_throw_error(NULL, "Cannot use string offset as an array");
1651        HANDLE_EXCEPTION();
1652    }
1653    zend_fetch_dimension_address_W(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1654    FREE_OP2();
1655    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1656        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var), 1);
1657    }
1658    FREE_OP1_VAR_PTR();
1659    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1660}
1661
1662ZEND_VM_HANDLER(87, ZEND_FETCH_DIM_RW, VAR|CV, CONST|TMPVAR|UNUSED|CV)
1663{
1664    USE_OPLINE
1665    zend_free_op free_op1, free_op2;
1666    zval *container;
1667
1668    SAVE_OPLINE();
1669    container = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
1670
1671    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1672        zend_throw_error(NULL, "Cannot use string offset as an array");
1673        HANDLE_EXCEPTION();
1674    }
1675    zend_fetch_dimension_address_RW(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1676    FREE_OP2();
1677    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1678        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var), 1);
1679    }
1680    FREE_OP1_VAR_PTR();
1681    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1682}
1683
1684ZEND_VM_HANDLER(90, ZEND_FETCH_DIM_IS, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
1685{
1686    USE_OPLINE
1687    zend_free_op free_op1, free_op2;
1688    zval *container;
1689
1690    SAVE_OPLINE();
1691    container = GET_OP1_ZVAL_PTR(BP_VAR_IS);
1692    zend_fetch_dimension_address_read_IS(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1693    FREE_OP2();
1694    FREE_OP1();
1695    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1696}
1697
1698ZEND_VM_HANDLER(93, ZEND_FETCH_DIM_FUNC_ARG, CONST|TMP|VAR|CV, CONST|TMPVAR|UNUSED|CV)
1699{
1700    USE_OPLINE
1701    zval *container;
1702    zend_free_op free_op1, free_op2;
1703
1704    SAVE_OPLINE();
1705
1706    if (zend_is_by_ref_func_arg_fetch(opline, EX(call))) {
1707        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
1708            zend_throw_error(NULL, "Cannot use temporary expression in write context");
1709            FREE_UNFETCHED_OP2();
1710            FREE_UNFETCHED_OP1();
1711            HANDLE_EXCEPTION();
1712        }
1713        container = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1714        if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1715            zend_throw_error(NULL, "Cannot use string offset as an array");
1716            FREE_UNFETCHED_OP2();
1717            HANDLE_EXCEPTION();
1718        }
1719        zend_fetch_dimension_address_W(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1720        if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1721            EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var), 1);
1722        }
1723        FREE_OP2();
1724        FREE_OP1_VAR_PTR();
1725    } else {
1726        if (OP2_TYPE == IS_UNUSED) {
1727            zend_throw_error(NULL, "Cannot use [] for reading");
1728            FREE_UNFETCHED_OP2();
1729            FREE_UNFETCHED_OP1();
1730            HANDLE_EXCEPTION();
1731        }
1732        container = GET_OP1_ZVAL_PTR(BP_VAR_R);
1733        zend_fetch_dimension_address_read_R(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1734        FREE_OP2();
1735        FREE_OP1();
1736    }
1737    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1738}
1739
1740ZEND_VM_HANDLER(96, ZEND_FETCH_DIM_UNSET, VAR|CV, CONST|TMPVAR|CV)
1741{
1742    USE_OPLINE
1743    zend_free_op free_op1, free_op2;
1744    zval *container;
1745
1746    SAVE_OPLINE();
1747    container = GET_OP1_ZVAL_PTR_PTR(BP_VAR_UNSET);
1748
1749    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1750        zend_throw_error(NULL, "Cannot use string offset as an array");
1751        FREE_UNFETCHED_OP2();
1752        HANDLE_EXCEPTION();
1753    }
1754    zend_fetch_dimension_address_UNSET(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1755    FREE_OP2();
1756    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1757        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var), 1);
1758    }
1759    FREE_OP1_VAR_PTR();
1760    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1761}
1762
1763ZEND_VM_HANDLER(82, ZEND_FETCH_OBJ_R, CONST|TMP|VAR|UNUSED|CV, CONST|TMPVAR|CV)
1764{
1765    USE_OPLINE
1766    zend_free_op free_op1;
1767    zval *container;
1768    zend_free_op free_op2;
1769    zval *offset;
1770
1771    SAVE_OPLINE();
1772    container = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_R);
1773
1774    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
1775        zend_throw_error(NULL, "Using $this when not in object context");
1776        FREE_UNFETCHED_OP2();
1777        HANDLE_EXCEPTION();
1778    }
1779
1780    offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
1781
1782    if (OP1_TYPE == IS_CONST ||
1783        (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT))) {
1784        if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(container)) {
1785            container = Z_REFVAL_P(container);
1786            if (UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
1787                ZEND_VM_C_GOTO(fetch_obj_r_no_object);
1788            }
1789        } else {
1790            ZEND_VM_C_GOTO(fetch_obj_r_no_object);
1791        }
1792    }
1793
1794    /* here we are sure we are dealing with an object */
1795    do {
1796        zend_object *zobj = Z_OBJ_P(container);
1797        zval *retval;
1798
1799        if (OP2_TYPE == IS_CONST &&
1800            EXPECTED(zobj->ce == CACHED_PTR(Z_CACHE_SLOT_P(offset)))) {
1801            uint32_t prop_offset = (uint32_t)(intptr_t)CACHED_PTR(Z_CACHE_SLOT_P(offset) + sizeof(void*));
1802
1803            if (EXPECTED(prop_offset != (uint32_t)ZEND_DYNAMIC_PROPERTY_OFFSET)) {
1804                retval = OBJ_PROP(zobj, prop_offset);
1805                if (EXPECTED(Z_TYPE_P(retval) != IS_UNDEF)) {
1806                    ZVAL_COPY(EX_VAR(opline->result.var), retval);
1807                    break;
1808                }
1809            } else if (EXPECTED(zobj->properties != NULL)) {
1810                retval = zend_hash_find(zobj->properties, Z_STR_P(offset));
1811                if (EXPECTED(retval)) {
1812                    ZVAL_COPY(EX_VAR(opline->result.var), retval);
1813                    break;
1814                }
1815            }
1816        }
1817
1818        if (UNEXPECTED(zobj->handlers->read_property == NULL)) {
1819ZEND_VM_C_LABEL(fetch_obj_r_no_object):
1820            zend_error(E_NOTICE, "Trying to get property of non-object");
1821            ZVAL_NULL(EX_VAR(opline->result.var));
1822        } else {
1823            retval = zobj->handlers->read_property(container, offset, BP_VAR_R, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(offset)) : NULL), EX_VAR(opline->result.var));
1824
1825            if (retval != EX_VAR(opline->result.var)) {
1826                ZVAL_COPY(EX_VAR(opline->result.var), retval);
1827            }
1828        }
1829    } while (0);
1830
1831    FREE_OP2();
1832    FREE_OP1();
1833    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1834}
1835
1836ZEND_VM_HANDLER(85, ZEND_FETCH_OBJ_W, VAR|UNUSED|CV, CONST|TMPVAR|CV)
1837{
1838    USE_OPLINE
1839    zend_free_op free_op1, free_op2;
1840    zval *property;
1841    zval *container;
1842
1843    SAVE_OPLINE();
1844    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1845
1846    container = GET_OP1_OBJ_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1847    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
1848        zend_throw_error(NULL, "Using $this when not in object context");
1849        FREE_OP2();
1850        HANDLE_EXCEPTION();
1851    }
1852    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1853        zend_throw_error(NULL, "Cannot use string offset as an object");
1854        FREE_OP2();
1855        HANDLE_EXCEPTION();
1856    }
1857
1858    zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_W);
1859    FREE_OP2();
1860    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1861        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var), 0);
1862    }
1863    FREE_OP1_VAR_PTR();
1864    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1865}
1866
1867ZEND_VM_HANDLER(88, ZEND_FETCH_OBJ_RW, VAR|UNUSED|CV, CONST|TMPVAR|CV)
1868{
1869    USE_OPLINE
1870    zend_free_op free_op1, free_op2;
1871    zval *property;
1872    zval *container;
1873
1874    SAVE_OPLINE();
1875    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1876    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
1877
1878    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
1879        zend_throw_error(NULL, "Using $this when not in object context");
1880        FREE_OP2();
1881        HANDLE_EXCEPTION();
1882    }
1883    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1884        zend_throw_error(NULL, "Cannot use string offset as an object");
1885        FREE_OP2();
1886        HANDLE_EXCEPTION();
1887    }
1888    zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_RW);
1889    FREE_OP2();
1890    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1891        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var), 0);
1892    }
1893    FREE_OP1_VAR_PTR();
1894    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1895}
1896
1897ZEND_VM_HANDLER(91, ZEND_FETCH_OBJ_IS, CONST|TMPVAR|UNUSED|CV, CONST|TMPVAR|CV)
1898{
1899    USE_OPLINE
1900    zend_free_op free_op1;
1901    zval *container;
1902    zend_free_op free_op2;
1903    zval *offset;
1904
1905    SAVE_OPLINE();
1906    container = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_IS);
1907
1908    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
1909        zend_throw_error(NULL, "Using $this when not in object context");
1910        FREE_UNFETCHED_OP2();
1911        HANDLE_EXCEPTION();
1912    }
1913
1914    offset  = GET_OP2_ZVAL_PTR(BP_VAR_R);
1915
1916    if (OP1_TYPE == IS_CONST ||
1917        (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT))) {
1918        if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(container)) {
1919            container = Z_REFVAL_P(container);
1920            if (UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
1921                ZEND_VM_C_GOTO(fetch_obj_is_no_object);
1922            }
1923        } else {
1924            ZEND_VM_C_GOTO(fetch_obj_is_no_object);
1925        }
1926    }
1927
1928    /* here we are sure we are dealing with an object */
1929    do {
1930        zend_object *zobj = Z_OBJ_P(container);
1931        zval *retval;
1932
1933        if (OP2_TYPE == IS_CONST &&
1934            EXPECTED(zobj->ce == CACHED_PTR(Z_CACHE_SLOT_P(offset)))) {
1935            uint32_t prop_offset = (uint32_t)(intptr_t)CACHED_PTR(Z_CACHE_SLOT_P(offset) + sizeof(void*));
1936
1937            if (EXPECTED(prop_offset != (uint32_t)ZEND_DYNAMIC_PROPERTY_OFFSET)) {
1938                retval = OBJ_PROP(zobj, prop_offset);
1939                if (EXPECTED(Z_TYPE_P(retval) != IS_UNDEF)) {
1940                    ZVAL_COPY(EX_VAR(opline->result.var), retval);
1941                    break;
1942                }
1943            } else if (EXPECTED(zobj->properties != NULL)) {
1944                retval = zend_hash_find(zobj->properties, Z_STR_P(offset));
1945                if (EXPECTED(retval)) {
1946                    ZVAL_COPY(EX_VAR(opline->result.var), retval);
1947                    break;
1948                }
1949            }
1950        }
1951
1952        if (UNEXPECTED(zobj->handlers->read_property == NULL)) {
1953ZEND_VM_C_LABEL(fetch_obj_is_no_object):
1954            ZVAL_NULL(EX_VAR(opline->result.var));
1955        } else {
1956
1957            retval = zobj->handlers->read_property(container, offset, BP_VAR_IS, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(offset)) : NULL), EX_VAR(opline->result.var));
1958
1959            if (retval != EX_VAR(opline->result.var)) {
1960                ZVAL_COPY(EX_VAR(opline->result.var), retval);
1961            }
1962        }
1963    } while (0);
1964
1965    FREE_OP2();
1966    FREE_OP1();
1967    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1968}
1969
1970ZEND_VM_HANDLER(94, ZEND_FETCH_OBJ_FUNC_ARG, CONST|TMP|VAR|UNUSED|CV, CONST|TMPVAR|CV)
1971{
1972    USE_OPLINE
1973    zval *container;
1974
1975    if (zend_is_by_ref_func_arg_fetch(opline, EX(call))) {
1976        /* Behave like FETCH_OBJ_W */
1977        zend_free_op free_op1, free_op2;
1978        zval *property;
1979
1980        SAVE_OPLINE();
1981        property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1982        container = GET_OP1_OBJ_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1983
1984        if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
1985            zend_throw_error(NULL, "Using $this when not in object context");
1986            FREE_OP2();
1987            HANDLE_EXCEPTION();
1988        }
1989        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
1990            zend_throw_error(NULL, "Cannot use temporary expression in write context");
1991            FREE_OP2();
1992            FREE_OP1_VAR_PTR();
1993            HANDLE_EXCEPTION();
1994        }
1995        if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1996            zend_throw_error(NULL, "Cannot use string offset as an object");
1997            FREE_OP2();
1998            HANDLE_EXCEPTION();
1999        }
2000        zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_W);
2001        FREE_OP2();
2002        if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
2003            EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var), 0);
2004        }
2005        FREE_OP1_VAR_PTR();
2006        ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2007    } else {
2008        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_FETCH_OBJ_R);
2009    }
2010}
2011
2012ZEND_VM_HANDLER(97, ZEND_FETCH_OBJ_UNSET, VAR|UNUSED|CV, CONST|TMPVAR|CV)
2013{
2014    USE_OPLINE
2015    zend_free_op free_op1, free_op2;
2016    zval *container, *property;
2017
2018    SAVE_OPLINE();
2019    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_UNSET);
2020
2021    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
2022        zend_throw_error(NULL, "Using $this when not in object context");
2023        FREE_UNFETCHED_OP2();
2024        HANDLE_EXCEPTION();
2025    }
2026
2027    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
2028
2029    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
2030        zend_throw_error(NULL, "Cannot use string offset as an object");
2031        FREE_OP2();
2032        HANDLE_EXCEPTION();
2033    }
2034    zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_UNSET);
2035    FREE_OP2();
2036    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
2037        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var), 0);
2038    }
2039    FREE_OP1_VAR_PTR();
2040    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2041}
2042
2043ZEND_VM_HANDLER(98, ZEND_FETCH_LIST, CONST|TMPVAR|CV, CONST)
2044{
2045    USE_OPLINE
2046    zend_free_op free_op1;
2047    zval *container;
2048
2049    SAVE_OPLINE();
2050    container = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2051
2052ZEND_VM_C_LABEL(try_fetch_list):
2053    if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
2054        zval *value = zend_hash_index_find(Z_ARRVAL_P(container), Z_LVAL_P(EX_CONSTANT(opline->op2)));
2055
2056        if (UNEXPECTED(value == NULL)) {
2057            zend_error(E_NOTICE,"Undefined offset: " ZEND_ULONG_FMT, Z_LVAL_P(EX_CONSTANT(opline->op2)));
2058            ZVAL_NULL(EX_VAR(opline->result.var));
2059        } else {
2060            ZVAL_COPY(EX_VAR(opline->result.var), value);
2061        }
2062    } else if (OP1_TYPE != IS_CONST &&
2063               UNEXPECTED(Z_TYPE_P(container) == IS_OBJECT) &&
2064               EXPECTED(Z_OBJ_HT_P(container)->read_dimension)) {
2065        zval *result = EX_VAR(opline->result.var);
2066        zval *retval = Z_OBJ_HT_P(container)->read_dimension(container, EX_CONSTANT(opline->op2), BP_VAR_R, result);
2067
2068        if (retval) {
2069            if (result != retval) {
2070                ZVAL_COPY(result, retval);
2071            }
2072        } else {
2073            ZVAL_NULL(result);
2074        }
2075    } else if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_TYPE_P(container) == IS_REFERENCE) {
2076        container = Z_REFVAL_P(container);
2077        ZEND_VM_C_GOTO(try_fetch_list);
2078    } else {
2079        if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(container) == IS_UNDEF)) {
2080            GET_OP1_UNDEF_CV(container, BP_VAR_R);
2081        }
2082        ZVAL_NULL(EX_VAR(opline->result.var));
2083    }
2084    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2085}
2086
2087ZEND_VM_HANDLER(136, ZEND_ASSIGN_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
2088{
2089    USE_OPLINE
2090    zend_free_op free_op1, free_op2;
2091    zval *object;
2092    zval *property_name;
2093
2094    SAVE_OPLINE();
2095    object = GET_OP1_OBJ_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
2096
2097    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(object) == NULL)) {
2098        zend_throw_error(NULL, "Using $this when not in object context");
2099        FREE_UNFETCHED_OP2();
2100        HANDLE_EXCEPTION();
2101    }
2102
2103    property_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2104
2105    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
2106        zend_throw_error(NULL, "Cannot use string offset as an array");
2107        FREE_OP2();
2108        HANDLE_EXCEPTION();
2109    }
2110    zend_assign_to_object(UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL, object, OP1_TYPE, property_name, OP2_TYPE, (opline+1)->op1_type, (opline+1)->op1, execute_data, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property_name)) : NULL));
2111    FREE_OP2();
2112    FREE_OP1_VAR_PTR();
2113    /* assign_obj has two opcodes! */
2114    ZEND_VM_NEXT_OPCODE_EX(1, 2);
2115}
2116
2117ZEND_VM_HANDLER(147, ZEND_ASSIGN_DIM, VAR|CV, CONST|TMPVAR|UNUSED|CV)
2118{
2119    USE_OPLINE
2120    zend_free_op free_op1;
2121    zval *object_ptr;
2122    zend_free_op free_op2, free_op_data1;
2123    zval *value;
2124    zval *variable_ptr;
2125    zval *dim;
2126
2127    SAVE_OPLINE();
2128    object_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
2129
2130    if (OP1_TYPE == IS_VAR && UNEXPECTED(object_ptr == NULL)) {
2131        zend_throw_error(NULL, "Cannot use string offset as an array");
2132        FREE_UNFETCHED_OP((opline+1)->op1_type, (opline+1)->op1.var);
2133        FREE_UNFETCHED_OP2();
2134        HANDLE_EXCEPTION();
2135    }
2136
2137    if (EXPECTED(Z_TYPE_P(object_ptr) == IS_ARRAY)) {
2138ZEND_VM_C_LABEL(try_assign_dim_array):
2139        if (OP2_TYPE == IS_UNUSED) {
2140            SEPARATE_ARRAY(object_ptr);
2141            variable_ptr = zend_hash_next_index_insert(Z_ARRVAL_P(object_ptr), &EG(uninitialized_zval));
2142            if (UNEXPECTED(variable_ptr == NULL)) {
2143                zend_error(E_WARNING, "Cannot add element to the array as the next element is already occupied");
2144                variable_ptr = &EG(error_zval);
2145            }
2146        } else {
2147            dim = GET_OP2_ZVAL_PTR(BP_VAR_R);
2148            SEPARATE_ARRAY(object_ptr);
2149            variable_ptr = zend_fetch_dimension_address_inner(Z_ARRVAL_P(object_ptr), dim, OP2_TYPE, BP_VAR_W);
2150            FREE_OP2();
2151        }
2152        value = get_zval_ptr((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
2153        if (UNEXPECTED(variable_ptr == &EG(error_zval))) {
2154            FREE_OP(free_op_data1);
2155            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2156                ZVAL_NULL(EX_VAR(opline->result.var));
2157            }
2158        } else {
2159            value = zend_assign_to_variable(variable_ptr, value, (opline+1)->op1_type);
2160            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2161                ZVAL_COPY(EX_VAR(opline->result.var), value);
2162            }
2163        }
2164    } else {
2165        if (EXPECTED(Z_ISREF_P(object_ptr))) {
2166            object_ptr = Z_REFVAL_P(object_ptr);
2167            if (EXPECTED(Z_TYPE_P(object_ptr) == IS_ARRAY)) {
2168                ZEND_VM_C_GOTO(try_assign_dim_array);
2169            }
2170        }
2171        if (EXPECTED(Z_TYPE_P(object_ptr) == IS_OBJECT)) {
2172            zend_free_op free_op2;
2173            zval *property_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2174
2175            zend_assign_to_object_dim(UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL, object_ptr, property_name, (opline+1)->op1_type, (opline+1)->op1, execute_data);
2176            FREE_OP2();
2177        } else if (EXPECTED(Z_TYPE_P(object_ptr) == IS_STRING)) {
2178            if (EXPECTED(Z_STRLEN_P(object_ptr) != 0)) {
2179                if (OP2_TYPE == IS_UNUSED) {
2180                    zend_throw_error(NULL, "[] operator not supported for strings");
2181                    FREE_UNFETCHED_OP((opline+1)->op1_type, (opline+1)->op1.var);
2182                    FREE_OP1_VAR_PTR();
2183                    HANDLE_EXCEPTION();
2184                } else {
2185                    zend_long offset;
2186
2187                    dim = GET_OP2_ZVAL_PTR(BP_VAR_R);
2188                    offset = zend_fetch_string_offset(object_ptr, dim, BP_VAR_W);
2189                    FREE_OP2();
2190                    value = get_zval_ptr_deref((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
2191                    zend_assign_to_string_offset(object_ptr, offset, value, (UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL));
2192                    FREE_OP(free_op_data1);
2193                }
2194            } else {
2195                zval_ptr_dtor_nogc(object_ptr);
2196ZEND_VM_C_LABEL(assign_dim_convert_to_array):
2197                ZVAL_NEW_ARR(object_ptr);
2198                zend_hash_init(Z_ARRVAL_P(object_ptr), 8, NULL, ZVAL_PTR_DTOR, 0);
2199                ZEND_VM_C_GOTO(try_assign_dim_array);
2200            }
2201        } else if (EXPECTED(Z_TYPE_P(object_ptr) <= IS_FALSE)) {
2202            if (OP1_TYPE == IS_VAR && UNEXPECTED(object_ptr == &EG(error_zval))) {
2203                ZEND_VM_C_GOTO(assign_dim_clean);
2204            }
2205            ZEND_VM_C_GOTO(assign_dim_convert_to_array);
2206        } else {
2207            zend_error(E_WARNING, "Cannot use a scalar value as an array");
2208ZEND_VM_C_LABEL(assign_dim_clean):
2209            dim = GET_OP2_ZVAL_PTR(BP_VAR_R);
2210            FREE_OP2();
2211            value = get_zval_ptr((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
2212            FREE_OP(free_op_data1);
2213            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2214                ZVAL_NULL(EX_VAR(opline->result.var));
2215            }
2216        }
2217    }
2218    FREE_OP1_VAR_PTR();
2219    /* assign_dim has two opcodes! */
2220    ZEND_VM_NEXT_OPCODE_EX(1, 2);
2221}
2222
2223ZEND_VM_HANDLER(38, ZEND_ASSIGN, VAR|CV, CONST|TMP|VAR|CV)
2224{
2225    USE_OPLINE
2226    zend_free_op free_op1, free_op2;
2227    zval *value;
2228    zval *variable_ptr;
2229
2230    SAVE_OPLINE();
2231    value = GET_OP2_ZVAL_PTR(BP_VAR_R);
2232    variable_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
2233
2234    if (OP1_TYPE == IS_VAR && UNEXPECTED(variable_ptr == &EG(error_zval))) {
2235        FREE_OP2();
2236        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2237            ZVAL_NULL(EX_VAR(opline->result.var));
2238        }
2239    } else {
2240        value = zend_assign_to_variable(variable_ptr, value, OP2_TYPE);
2241        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2242            ZVAL_COPY(EX_VAR(opline->result.var), value);
2243        }
2244        FREE_OP1_VAR_PTR();
2245        /* zend_assign_to_variable() always takes care of op2, never free it! */
2246    }
2247
2248    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2249}
2250
2251ZEND_VM_HANDLER(39, ZEND_ASSIGN_REF, VAR|CV, VAR|CV)
2252{
2253    USE_OPLINE
2254    zend_free_op free_op1, free_op2;
2255    zval *variable_ptr;
2256    zval *value_ptr;
2257
2258    SAVE_OPLINE();
2259    value_ptr = GET_OP2_ZVAL_PTR_PTR(BP_VAR_W);
2260
2261    if (OP2_TYPE == IS_VAR && UNEXPECTED(value_ptr == NULL)) {
2262        zend_throw_error(NULL, "Cannot create references to/from string offsets nor overloaded objects");
2263        FREE_UNFETCHED_OP1();
2264        HANDLE_EXCEPTION();
2265    }
2266    if (OP1_TYPE == IS_VAR &&
2267        UNEXPECTED(Z_TYPE_P(EX_VAR(opline->op1.var)) != IS_INDIRECT) &&
2268        UNEXPECTED(!Z_ISREF_P(EX_VAR(opline->op1.var)))) {
2269        zend_throw_error(NULL, "Cannot assign by reference to overloaded object");
2270        FREE_OP2_VAR_PTR();
2271        HANDLE_EXCEPTION();
2272    }
2273    if (OP2_TYPE == IS_VAR &&
2274        (value_ptr == &EG(uninitialized_zval) ||
2275         (opline->extended_value == ZEND_RETURNS_FUNCTION &&
2276          !(Z_VAR_FLAGS_P(value_ptr) & IS_VAR_RET_REF)))) {
2277        if (!OP2_FREE && UNEXPECTED(Z_TYPE_P(EX_VAR(opline->op2.var)) != IS_INDIRECT)) { /* undo the effect of get_zval_ptr_ptr() */
2278            Z_TRY_ADDREF_P(value_ptr);
2279        }
2280        zend_error(E_NOTICE, "Only variables should be assigned by reference");
2281        if (UNEXPECTED(EG(exception) != NULL)) {
2282            FREE_OP2_VAR_PTR();
2283            HANDLE_EXCEPTION();
2284        }
2285        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_ASSIGN);
2286    }
2287
2288    variable_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
2289    if (OP1_TYPE == IS_VAR && UNEXPECTED(variable_ptr == NULL)) {
2290        zend_throw_error(NULL, "Cannot create references to/from string offsets nor overloaded objects");
2291        FREE_OP2_VAR_PTR();
2292        HANDLE_EXCEPTION();
2293    }
2294    if ((OP1_TYPE == IS_VAR && UNEXPECTED(variable_ptr == &EG(error_zval))) ||
2295        (OP2_TYPE == IS_VAR && UNEXPECTED(value_ptr == &EG(error_zval)))) {
2296        variable_ptr = &EG(uninitialized_zval);
2297    } else {
2298        zend_assign_to_variable_reference(variable_ptr, value_ptr);
2299    }
2300
2301    if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2302        ZVAL_COPY(EX_VAR(opline->result.var), variable_ptr);
2303    }
2304
2305    FREE_OP1_VAR_PTR();
2306    FREE_OP2_VAR_PTR();
2307
2308    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2309}
2310
2311ZEND_VM_HELPER(zend_leave_helper, ANY, ANY)
2312{
2313    zend_execute_data *old_execute_data;
2314    uint32_t call_info = EX_CALL_INFO();
2315
2316    if (ZEND_CALL_KIND_EX(call_info) == ZEND_CALL_NESTED_FUNCTION) {
2317        zend_object *object;
2318
2319        i_free_compiled_variables(execute_data);
2320        if (UNEXPECTED(EX(symbol_table) != NULL)) {
2321            zend_clean_and_cache_symbol_table(EX(symbol_table));
2322        }
2323        zend_vm_stack_free_extra_args_ex(call_info, execute_data);
2324        old_execute_data = execute_data;
2325        execute_data = EG(current_execute_data) = EX(prev_execute_data);
2326        if (UNEXPECTED(call_info & ZEND_CALL_CLOSURE)) {
2327            OBJ_RELEASE((zend_object*)old_execute_data->func->op_array.prototype);
2328        }
2329        if (UNEXPECTED(call_info & ZEND_CALL_RELEASE_THIS)) {
2330            object = Z_OBJ(old_execute_data->This);
2331#if 0
2332            if (UNEXPECTED(EG(exception) != NULL) && (EX(opline)->op1.num & ZEND_CALL_CTOR)) {
2333                if (!(EX(opline)->op1.num & ZEND_CALL_CTOR_RESULT_UNUSED)) {
2334#else
2335            if (UNEXPECTED(EG(exception) != NULL) && (call_info & ZEND_CALL_CTOR)) {
2336                if (!(call_info & ZEND_CALL_CTOR_RESULT_UNUSED)) {
2337#endif
2338                    GC_REFCOUNT(object)--;
2339                }
2340                if (GC_REFCOUNT(object) == 1) {
2341                    zend_object_store_ctor_failed(object);
2342                }
2343            }
2344            OBJ_RELEASE(object);
2345        }
2346        EG(scope) = EX(func)->op_array.scope;
2347
2348        zend_vm_stack_free_call_frame_ex(call_info, old_execute_data);
2349
2350        if (UNEXPECTED(EG(exception) != NULL)) {
2351            const zend_op *old_opline = EX(opline);
2352            zend_throw_exception_internal(NULL);
2353            if (RETURN_VALUE_USED(old_opline)) {
2354                zval_ptr_dtor(EX_VAR(old_opline->result.var));
2355            }
2356            HANDLE_EXCEPTION_LEAVE();
2357        }
2358
2359        LOAD_NEXT_OPLINE();
2360        ZEND_VM_LEAVE();
2361    } else if (ZEND_CALL_KIND_EX(call_info) == ZEND_CALL_NESTED_CODE) {
2362        zend_detach_symbol_table(execute_data);
2363        destroy_op_array(&EX(func)->op_array);
2364        efree_size(EX(func), sizeof(zend_op_array));
2365        old_execute_data = execute_data;
2366        execute_data = EG(current_execute_data) = EX(prev_execute_data);
2367        zend_vm_stack_free_call_frame_ex(call_info, old_execute_data);
2368
2369        zend_attach_symbol_table(execute_data);
2370        if (UNEXPECTED(EG(exception) != NULL)) {
2371            zend_throw_exception_internal(NULL);
2372            HANDLE_EXCEPTION_LEAVE();
2373        }
2374
2375        LOAD_NEXT_OPLINE();
2376        ZEND_VM_LEAVE();
2377    } else {
2378        if (ZEND_CALL_KIND_EX(call_info) == ZEND_CALL_TOP_FUNCTION) {
2379            i_free_compiled_variables(execute_data);
2380            if (UNEXPECTED(EX(symbol_table) != NULL)) {
2381                zend_clean_and_cache_symbol_table(EX(symbol_table));
2382            }
2383            zend_vm_stack_free_extra_args_ex(call_info, execute_data);
2384            EG(current_execute_data) = EX(prev_execute_data);
2385            if (UNEXPECTED(call_info & ZEND_CALL_CLOSURE)) {
2386                OBJ_RELEASE((zend_object*)EX(func)->op_array.prototype);
2387            }
2388        } else /* if (call_kind == ZEND_CALL_TOP_CODE) */ {
2389            zend_array *symbol_table = EX(symbol_table);
2390
2391            zend_detach_symbol_table(execute_data);
2392            old_execute_data = EX(prev_execute_data);
2393            while (old_execute_data) {
2394                if (old_execute_data->func && ZEND_USER_CODE(old_execute_data->func->op_array.type)) {
2395                    if (old_execute_data->symbol_table == symbol_table) {
2396                        zend_attach_symbol_table(old_execute_data);
2397                    }
2398                    break;
2399                }
2400                old_execute_data = old_execute_data->prev_execute_data;
2401            }
2402            EG(current_execute_data) = EX(prev_execute_data);
2403        }
2404
2405        ZEND_VM_RETURN();
2406    }
2407}
2408
2409ZEND_VM_HANDLER(42, ZEND_JMP, ANY, ANY)
2410{
2411    USE_OPLINE
2412
2413    ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op1));
2414    ZEND_VM_CONTINUE();
2415}
2416
2417ZEND_VM_HANDLER(43, ZEND_JMPZ, CONST|TMPVAR|CV, ANY)
2418{
2419    USE_OPLINE
2420    zend_free_op free_op1;
2421    zval *val;
2422
2423    val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2424
2425    if (Z_TYPE_INFO_P(val) == IS_TRUE) {
2426        ZEND_VM_SET_NEXT_OPCODE(opline + 1);
2427        ZEND_VM_CONTINUE();
2428    } else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
2429        if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
2430            SAVE_OPLINE();
2431            GET_OP1_UNDEF_CV(val, BP_VAR_R);
2432            ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
2433        } else {
2434            ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2435            ZEND_VM_CONTINUE();
2436        }
2437    }
2438
2439    SAVE_OPLINE();
2440    if (i_zend_is_true(val)) {
2441        opline++;
2442    } else {
2443        opline = OP_JMP_ADDR(opline, opline->op2);
2444    }
2445    FREE_OP1();
2446    if (UNEXPECTED(EG(exception) != NULL)) {
2447        HANDLE_EXCEPTION();
2448    }
2449    ZEND_VM_JMP(opline);
2450}
2451
2452ZEND_VM_HANDLER(44, ZEND_JMPNZ, CONST|TMPVAR|CV, ANY)
2453{
2454    USE_OPLINE
2455    zend_free_op free_op1;
2456    zval *val;
2457
2458    val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2459
2460    if (Z_TYPE_INFO_P(val) == IS_TRUE) {
2461        ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2462        ZEND_VM_CONTINUE();
2463    } else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
2464        if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
2465            SAVE_OPLINE();
2466            GET_OP1_UNDEF_CV(val, BP_VAR_R);
2467            ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2468        } else {
2469            ZEND_VM_NEXT_OPCODE();
2470        }
2471    }
2472
2473    SAVE_OPLINE();
2474    if (i_zend_is_true(val)) {
2475        opline = OP_JMP_ADDR(opline, opline->op2);
2476    } else {
2477        opline++;
2478    }
2479    FREE_OP1();
2480    if (UNEXPECTED(EG(exception) != NULL)) {
2481        HANDLE_EXCEPTION();
2482    }
2483    ZEND_VM_JMP(opline);
2484}
2485
2486ZEND_VM_HANDLER(45, ZEND_JMPZNZ, CONST|TMPVAR|CV, ANY)
2487{
2488    USE_OPLINE
2489    zend_free_op free_op1;
2490    zval *val;
2491
2492    val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2493
2494    if (EXPECTED(Z_TYPE_INFO_P(val) == IS_TRUE)) {
2495        ZEND_VM_SET_RELATIVE_OPCODE(opline, opline->extended_value);
2496        ZEND_VM_CONTINUE();
2497    } else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
2498        if (OP1_TYPE == IS_CV) {
2499            if (UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
2500                SAVE_OPLINE();
2501                GET_OP1_UNDEF_CV(val, BP_VAR_R);
2502            }
2503            ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
2504        } else {
2505            ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2506            ZEND_VM_CONTINUE();
2507        }
2508    }
2509
2510    SAVE_OPLINE();
2511    if (i_zend_is_true(val)) {
2512        opline = ZEND_OFFSET_TO_OPLINE(opline, opline->extended_value);
2513    } else {
2514        opline = OP_JMP_ADDR(opline, opline->op2);
2515    }
2516    FREE_OP1();
2517    if (UNEXPECTED(EG(exception) != NULL)) {
2518        HANDLE_EXCEPTION();
2519    }
2520    ZEND_VM_JMP(opline);
2521}
2522
2523ZEND_VM_HANDLER(46, ZEND_JMPZ_EX, CONST|TMPVAR|CV, ANY)
2524{
2525    USE_OPLINE
2526    zend_free_op free_op1;
2527    zval *val;
2528    int ret;
2529
2530    val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2531
2532    if (Z_TYPE_INFO_P(val) == IS_TRUE) {
2533        ZVAL_TRUE(EX_VAR(opline->result.var));
2534        ZEND_VM_SET_NEXT_OPCODE(opline + 1);
2535        ZEND_VM_CONTINUE();
2536    } else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
2537        ZVAL_FALSE(EX_VAR(opline->result.var));
2538        if (OP1_TYPE == IS_CV) {
2539            if (UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
2540                SAVE_OPLINE();
2541                GET_OP1_UNDEF_CV(val, BP_VAR_R);
2542            }
2543            ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
2544        } else {
2545            ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2546            ZEND_VM_CONTINUE();
2547        }
2548    }
2549
2550    SAVE_OPLINE();
2551    ret = i_zend_is_true(val);
2552    FREE_OP1();
2553    if (ret) {
2554        ZVAL_TRUE(EX_VAR(opline->result.var));
2555        opline++;
2556    } else {
2557        ZVAL_FALSE(EX_VAR(opline->result.var));
2558        opline = OP_JMP_ADDR(opline, opline->op2);
2559    }
2560    if (UNEXPECTED(EG(exception) != NULL)) {
2561        HANDLE_EXCEPTION();
2562    }
2563    ZEND_VM_JMP(opline);
2564}
2565
2566ZEND_VM_HANDLER(47, ZEND_JMPNZ_EX, CONST|TMPVAR|CV, ANY)
2567{
2568    USE_OPLINE
2569    zend_free_op free_op1;
2570    zval *val;
2571    int ret;
2572
2573    val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2574
2575    if (Z_TYPE_INFO_P(val) == IS_TRUE) {
2576        ZVAL_TRUE(EX_VAR(opline->result.var));
2577        ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2578        ZEND_VM_CONTINUE();
2579    } else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
2580        ZVAL_FALSE(EX_VAR(opline->result.var));
2581        if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
2582            SAVE_OPLINE();
2583            GET_OP1_UNDEF_CV(val, BP_VAR_R);
2584            ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2585        } else {
2586            ZEND_VM_NEXT_OPCODE();
2587        }
2588    }
2589
2590    SAVE_OPLINE();
2591    ret = i_zend_is_true(val);
2592    FREE_OP1();
2593    if (ret) {
2594        ZVAL_TRUE(EX_VAR(opline->result.var));
2595        opline = OP_JMP_ADDR(opline, opline->op2);
2596    } else {
2597        ZVAL_FALSE(EX_VAR(opline->result.var));
2598        opline++;
2599    }
2600    if (UNEXPECTED(EG(exception) != NULL)) {
2601        HANDLE_EXCEPTION();
2602    }
2603    ZEND_VM_JMP(opline);
2604}
2605
2606ZEND_VM_HANDLER(70, ZEND_FREE, TMPVAR, ANY)
2607{
2608    USE_OPLINE
2609
2610    SAVE_OPLINE();
2611    zval_ptr_dtor_nogc(EX_VAR(opline->op1.var));
2612    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2613}
2614
2615ZEND_VM_HANDLER(127, ZEND_FE_FREE, TMPVAR, ANY)
2616{
2617    zval *var;
2618    USE_OPLINE
2619
2620    SAVE_OPLINE();
2621    var = EX_VAR(opline->op1.var);
2622    if (Z_TYPE_P(var) != IS_ARRAY && Z_FE_ITER_P(var) != (uint32_t)-1) {
2623        zend_hash_iterator_del(Z_FE_ITER_P(var));
2624    }
2625    zval_ptr_dtor_nogc(var);
2626    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2627}
2628
2629ZEND_VM_HANDLER(53, ZEND_FAST_CONCAT, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
2630{
2631    USE_OPLINE
2632    zend_free_op free_op1, free_op2;
2633    zval *op1, *op2;
2634    zend_string *op1_str, *op2_str, *str;
2635
2636    SAVE_OPLINE();
2637    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2638    if (OP1_TYPE == IS_CONST) {
2639        op1_str = Z_STR_P(op1);
2640    } else if (EXPECTED(Z_TYPE_P(op1) == IS_STRING)) {
2641        op1_str = zend_string_copy(Z_STR_P(op1));
2642    } else {
2643        if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op1) == IS_UNDEF)) {
2644            GET_OP1_UNDEF_CV(op1, BP_VAR_R);
2645        }
2646        op1_str = _zval_get_string_func(op1);
2647    }
2648    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2649    if (OP2_TYPE == IS_CONST) {
2650        op2_str = Z_STR_P(op2);
2651    } else if (EXPECTED(Z_TYPE_P(op2) == IS_STRING)) {
2652        op2_str = zend_string_copy(Z_STR_P(op2));
2653    } else {
2654        if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op2) == IS_UNDEF)) {
2655            GET_OP2_UNDEF_CV(op2, BP_VAR_R);
2656        }
2657        op2_str = _zval_get_string_func(op2);
2658    }
2659    do {
2660        if (OP1_TYPE != IS_CONST) {
2661            if (UNEXPECTED(ZSTR_LEN(op1_str) == 0)) {
2662                if (OP2_TYPE == IS_CONST) {
2663                    zend_string_addref(op2_str);
2664                }
2665                ZVAL_STR(EX_VAR(opline->result.var), op2_str);
2666                zend_string_release(op1_str);
2667                break;
2668            }
2669        }
2670        if (OP2_TYPE != IS_CONST) {
2671            if (UNEXPECTED(ZSTR_LEN(op2_str) == 0)) {
2672                if (OP1_TYPE == IS_CONST) {
2673                    zend_string_addref(op1_str);
2674                }
2675                ZVAL_STR(EX_VAR(opline->result.var), op1_str);
2676                zend_string_release(op2_str);
2677                break;
2678            }
2679        }
2680        str = zend_string_alloc(ZSTR_LEN(op1_str) + ZSTR_LEN(op2_str), 0);
2681        memcpy(ZSTR_VAL(str), ZSTR_VAL(op1_str), ZSTR_LEN(op1_str));
2682        memcpy(ZSTR_VAL(str) + ZSTR_LEN(op1_str), ZSTR_VAL(op2_str), ZSTR_LEN(op2_str)+1);
2683        ZVAL_NEW_STR(EX_VAR(opline->result.var), str);
2684        if (OP1_TYPE != IS_CONST) {
2685            zend_string_release(op1_str);
2686        }
2687        if (OP2_TYPE != IS_CONST) {
2688            zend_string_release(op2_str);
2689        }
2690    } while (0);
2691    FREE_OP1();
2692    FREE_OP2();
2693    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2694}
2695
2696ZEND_VM_HANDLER(54, ZEND_ROPE_INIT, UNUSED, CONST|TMPVAR|CV)
2697{
2698    USE_OPLINE
2699    zend_free_op free_op2;
2700    zend_string **rope;
2701    zval *var;
2702
2703    /* Compiler allocates the necessary number of zval slots to keep the rope */
2704    rope = (zend_string**)EX_VAR(opline->result.var);
2705    if (OP2_TYPE == IS_CONST) {
2706        var = GET_OP2_ZVAL_PTR(BP_VAR_R);
2707        rope[0] = zend_string_copy(Z_STR_P(var));
2708    } else {
2709        var = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2710        if (EXPECTED(Z_TYPE_P(var) == IS_STRING)) {
2711            if (OP2_TYPE == IS_CV) {
2712                rope[0] = zend_string_copy(Z_STR_P(var));
2713            } else {
2714                rope[0] = Z_STR_P(var);
2715            }
2716        } else {
2717            SAVE_OPLINE();
2718            if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var) == IS_UNDEF)) {
2719                GET_OP2_UNDEF_CV(var, BP_VAR_R);
2720            }
2721            rope[0] = _zval_get_string_func(var);
2722            FREE_OP2();
2723            ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2724        }
2725    }
2726    ZEND_VM_NEXT_OPCODE();
2727}
2728
2729ZEND_VM_HANDLER(55, ZEND_ROPE_ADD, TMP, CONST|TMPVAR|CV)
2730{
2731    USE_OPLINE
2732    zend_free_op free_op2;
2733    zend_string **rope;
2734    zval *var;
2735
2736    /* op1 and result are the same */
2737    rope = (zend_string**)EX_VAR(opline->op1.var);
2738    if (OP2_TYPE == IS_CONST) {
2739        var = GET_OP2_ZVAL_PTR(BP_VAR_R);
2740        rope[opline->extended_value] = zend_string_copy(Z_STR_P(var));
2741    } else {
2742        var = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2743        if (EXPECTED(Z_TYPE_P(var) == IS_STRING)) {
2744            if (OP2_TYPE == IS_CV) {
2745                rope[opline->extended_value] = zend_string_copy(Z_STR_P(var));
2746            } else {
2747                rope[opline->extended_value] = Z_STR_P(var);
2748            }
2749        } else {
2750            SAVE_OPLINE();
2751            if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var) == IS_UNDEF)) {
2752                GET_OP2_UNDEF_CV(var, BP_VAR_R);
2753            }
2754            rope[opline->extended_value] = _zval_get_string_func(var);
2755            FREE_OP2();
2756            ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2757        }
2758    }
2759    ZEND_VM_NEXT_OPCODE();
2760}
2761
2762ZEND_VM_HANDLER(56, ZEND_ROPE_END, TMP, CONST|TMPVAR|CV)
2763{
2764    USE_OPLINE
2765    zend_free_op free_op2;
2766    zend_string **rope;
2767    zval *var, *ret;
2768    uint32_t i;
2769    size_t len = 0;
2770    char *target;
2771
2772    rope = (zend_string**)EX_VAR(opline->op1.var);
2773    if (OP2_TYPE == IS_CONST) {
2774        var = GET_OP2_ZVAL_PTR(BP_VAR_R);
2775        rope[opline->extended_value] = zend_string_copy(Z_STR_P(var));
2776    } else {
2777        var = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2778        if (EXPECTED(Z_TYPE_P(var) == IS_STRING)) {
2779            if (OP2_TYPE == IS_CV) {
2780                rope[opline->extended_value] = zend_string_copy(Z_STR_P(var));
2781            } else {
2782                rope[opline->extended_value] = Z_STR_P(var);
2783            }
2784        } else {
2785            SAVE_OPLINE();
2786            if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var) == IS_UNDEF)) {
2787                GET_OP2_UNDEF_CV(var, BP_VAR_R);
2788            }
2789            rope[opline->extended_value] = _zval_get_string_func(var);
2790            FREE_OP2();
2791            if (UNEXPECTED(EG(exception))) {
2792                for (i = 0; i <= opline->extended_value; i++) {
2793                    zend_string_release(rope[i]);
2794                }
2795                HANDLE_EXCEPTION();
2796            }
2797        }
2798    }
2799    for (i = 0; i <= opline->extended_value; i++) {
2800        len += ZSTR_LEN(rope[i]);
2801    }
2802    ret = EX_VAR(opline->result.var);
2803    ZVAL_STR(ret, zend_string_alloc(len, 0));
2804    target = Z_STRVAL_P(ret);
2805    for (i = 0; i <= opline->extended_value; i++) {
2806        memcpy(target, ZSTR_VAL(rope[i]), ZSTR_LEN(rope[i]));
2807        target += ZSTR_LEN(rope[i]);
2808        zend_string_release(rope[i]);
2809    }
2810    *target = '\0';
2811
2812    ZEND_VM_NEXT_OPCODE();
2813}
2814
2815ZEND_VM_HANDLER(109, ZEND_FETCH_CLASS, ANY, CONST|TMPVAR|UNUSED|CV)
2816{
2817    USE_OPLINE
2818
2819    SAVE_OPLINE();
2820    if (OP2_TYPE == IS_UNUSED) {
2821        Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class(NULL, opline->extended_value);
2822        ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2823    } else {
2824        zend_free_op free_op2;
2825        zval *class_name = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2826
2827ZEND_VM_C_LABEL(try_class_name):
2828        if (OP2_TYPE == IS_CONST) {
2829            zend_class_entry *ce = CACHED_PTR(Z_CACHE_SLOT_P(class_name));
2830
2831            if (UNEXPECTED(ce == NULL)) {
2832                ce = zend_fetch_class_by_name(Z_STR_P(class_name), EX_CONSTANT(opline->op2) + 1, opline->extended_value);
2833                CACHE_PTR(Z_CACHE_SLOT_P(class_name), ce);
2834            }
2835            Z_CE_P(EX_VAR(opline->result.var)) = ce;
2836        } else if (Z_TYPE_P(class_name) == IS_OBJECT) {
2837            Z_CE_P(EX_VAR(opline->result.var)) = Z_OBJCE_P(class_name);
2838        } else if (Z_TYPE_P(class_name) == IS_STRING) {
2839            Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class(Z_STR_P(class_name), opline->extended_value);
2840        } else if ((OP2_TYPE & (IS_VAR|IS_CV)) && Z_TYPE_P(class_name) == IS_REFERENCE) {
2841            class_name = Z_REFVAL_P(class_name);
2842            ZEND_VM_C_GOTO(try_class_name);
2843        } else {
2844            if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(class_name) == IS_UNDEF)) {
2845                GET_OP2_UNDEF_CV(class_name, BP_VAR_R);
2846            }
2847            if (UNEXPECTED(EG(exception) != NULL)) {
2848                HANDLE_EXCEPTION();
2849            }
2850            zend_throw_error(NULL, "Class name must be a valid object or a string");
2851        }
2852
2853        FREE_OP2();
2854        ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2855    }
2856}
2857
2858ZEND_VM_HANDLER(112, ZEND_INIT_METHOD_CALL, CONST|TMPVAR|UNUSED|CV, CONST|TMPVAR|CV)
2859{
2860    USE_OPLINE
2861    zval *function_name;
2862    zend_free_op free_op1, free_op2;
2863    zval *object;
2864    zend_function *fbc;
2865    zend_class_entry *called_scope;
2866    zend_object *obj;
2867    zend_execute_data *call;
2868    uint32_t call_info;
2869
2870    SAVE_OPLINE();
2871
2872    function_name = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2873
2874    if (OP2_TYPE != IS_CONST &&
2875        UNEXPECTED(Z_TYPE_P(function_name) != IS_STRING)) {
2876        do {
2877            if ((OP2_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(function_name)) {
2878                function_name = Z_REFVAL_P(function_name);
2879                if (EXPECTED(Z_TYPE_P(function_name) == IS_STRING)) {
2880                    break;
2881                }
2882            }
2883            if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(function_name) == IS_UNDEF)) {
2884                GET_OP2_UNDEF_CV(function_name, BP_VAR_R);
2885            }
2886            if (UNEXPECTED(EG(exception) != NULL)) {
2887                HANDLE_EXCEPTION();
2888            }
2889            zend_throw_error(NULL, "Method name must be a string");
2890            FREE_OP2();
2891            FREE_UNFETCHED_OP1();
2892            HANDLE_EXCEPTION();
2893        } while (0);
2894    }
2895
2896    object = GET_OP1_OBJ_ZVAL_PTR_UNDEF(BP_VAR_R);
2897
2898    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(object) == NULL)) {
2899        zend_throw_error(NULL, "Using $this when not in object context");
2900        FREE_OP2();
2901        HANDLE_EXCEPTION();
2902    }
2903
2904    if (OP1_TYPE != IS_UNUSED) {
2905        do {
2906            if (OP1_TYPE == IS_CONST || UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
2907                if ((OP1_TYPE & (IS_VAR|IS_CV)) && EXPECTED(Z_ISREF_P(object))) {
2908                    object = Z_REFVAL_P(object);
2909                    if (EXPECTED(Z_TYPE_P(object) == IS_OBJECT)) {
2910                        break;
2911                    }
2912                }
2913                if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(object) == IS_UNDEF)) {
2914                    GET_OP1_UNDEF_CV(object, BP_VAR_R);
2915                }
2916                if (UNEXPECTED(EG(exception) != NULL)) {
2917                    HANDLE_EXCEPTION();
2918                }
2919                zend_throw_error(NULL, "Call to a member function %s() on %s", Z_STRVAL_P(function_name), zend_get_type_by_const(Z_TYPE_P(object)));
2920                FREE_OP2();
2921                FREE_OP1();
2922                HANDLE_EXCEPTION();
2923            }
2924        } while (0);
2925    }
2926
2927    obj = Z_OBJ_P(object);
2928    called_scope = obj->ce;
2929
2930    if (OP2_TYPE != IS_CONST ||
2931        UNEXPECTED((fbc = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), called_scope)) == NULL)) {
2932        zend_object *orig_obj = obj;
2933
2934        if (UNEXPECTED(obj->handlers->get_method == NULL)) {
2935            zend_throw_error(NULL, "Object does not support method calls");
2936            FREE_OP2();
2937            FREE_OP1();
2938            HANDLE_EXCEPTION();
2939        }
2940
2941        /* First, locate the function. */
2942        fbc = obj->handlers->get_method(&obj, Z_STR_P(function_name), ((OP2_TYPE == IS_CONST) ? (EX_CONSTANT(opline->op2) + 1) : NULL));
2943        if (UNEXPECTED(fbc == NULL)) {
2944            if (EXPECTED(!EG(exception))) {
2945                zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(obj->ce->name), Z_STRVAL_P(function_name));
2946            }
2947            FREE_OP2();
2948            FREE_OP1();
2949            HANDLE_EXCEPTION();
2950        }
2951        if (OP2_TYPE == IS_CONST &&
2952            EXPECTED(fbc->type <= ZEND_USER_FUNCTION) &&
2953            EXPECTED(!(fbc->common.fn_flags & (ZEND_ACC_CALL_VIA_TRAMPOLINE|ZEND_ACC_NEVER_CACHE))) &&
2954            EXPECTED(obj == orig_obj)) {
2955            CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), called_scope, fbc);
2956        }
2957    }
2958
2959    call_info = ZEND_CALL_NESTED_FUNCTION;
2960    if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_STATIC) != 0)) {
2961        obj = NULL;
2962    } else if (OP1_TYPE & (IS_VAR|IS_TMP_VAR|IS_CV)) {
2963        /* CV may be changed indirectly (e.g. when it's a reference) */
2964        call_info = ZEND_CALL_NESTED_FUNCTION | ZEND_CALL_RELEASE_THIS;
2965        GC_REFCOUNT(obj)++; /* For $this pointer */
2966    }
2967
2968    call = zend_vm_stack_push_call_frame(call_info,
2969        fbc, opline->extended_value, called_scope, obj);
2970    call->prev_execute_data = EX(call);
2971    EX(call) = call;
2972
2973    FREE_OP2();
2974    FREE_OP1();
2975
2976    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2977}
2978
2979ZEND_VM_HANDLER(113, ZEND_INIT_STATIC_METHOD_CALL, CONST|VAR, CONST|TMPVAR|UNUSED|CV)
2980{
2981    USE_OPLINE
2982    zval *function_name;
2983    zend_class_entry *ce;
2984    zend_object *object;
2985    zend_function *fbc;
2986    zend_execute_data *call;
2987
2988    SAVE_OPLINE();
2989
2990    if (OP1_TYPE == IS_CONST) {
2991        /* no function found. try a static method in class */
2992        ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
2993        if (UNEXPECTED(ce == NULL)) {
2994            ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, ZEND_FETCH_CLASS_DEFAULT |  ZEND_FETCH_CLASS_EXCEPTION);
2995            if (UNEXPECTED(EG(exception) != NULL)) {
2996                HANDLE_EXCEPTION();
2997            }
2998            if (UNEXPECTED(ce == NULL)) {
2999                zend_throw_error(NULL, "Class '%s' not found", Z_STRVAL_P(EX_CONSTANT(opline->op1)));
3000                HANDLE_EXCEPTION();
3001            }
3002            CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce);
3003        }
3004    } else {
3005        ce = Z_CE_P(EX_VAR(opline->op1.var));
3006    }
3007
3008    if (OP1_TYPE == IS_CONST &&
3009        OP2_TYPE == IS_CONST &&
3010        EXPECTED((fbc = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) != NULL)) {
3011        /* nothing to do */
3012    } else if (OP1_TYPE != IS_CONST &&
3013               OP2_TYPE == IS_CONST &&
3014               (fbc = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce))) {
3015        /* do nothing */
3016    } else if (OP2_TYPE != IS_UNUSED) {
3017        zend_free_op free_op2;
3018
3019        function_name = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
3020        if (OP2_TYPE != IS_CONST) {
3021            if (UNEXPECTED(Z_TYPE_P(function_name) != IS_STRING)) {
3022                if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(function_name) == IS_UNDEF)) {
3023                    GET_OP2_UNDEF_CV(function_name, BP_VAR_R);
3024                }
3025                if (UNEXPECTED(EG(exception) != NULL)) {
3026                    HANDLE_EXCEPTION();
3027                }
3028                zend_throw_error(NULL, "Function name must be a string");
3029                FREE_OP2();
3030                HANDLE_EXCEPTION();
3031            }
3032        }
3033
3034        if (ce->get_static_method) {
3035            fbc = ce->get_static_method(ce, Z_STR_P(function_name));
3036        } else {
3037            fbc = zend_std_get_static_method(ce, Z_STR_P(function_name), ((OP2_TYPE == IS_CONST) ? (EX_CONSTANT(opline->op2) + 1) : NULL));
3038        }
3039        if (UNEXPECTED(fbc == NULL)) {
3040            if (EXPECTED(!EG(exception))) {
3041                zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(ce->name), Z_STRVAL_P(function_name));
3042            }
3043            FREE_OP2();
3044            HANDLE_EXCEPTION();
3045        }
3046        if (OP2_TYPE == IS_CONST &&
3047            EXPECTED(fbc->type <= ZEND_USER_FUNCTION) &&
3048            EXPECTED(!(fbc->common.fn_flags & (ZEND_ACC_CALL_VIA_TRAMPOLINE|ZEND_ACC_NEVER_CACHE)))) {
3049            if (OP1_TYPE == IS_CONST) {
3050                CACHE_PTR(Z_CACHE_SLOT_P(function_name), fbc);
3051            } else {
3052                CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), ce, fbc);
3053            }
3054        }
3055        if (OP2_TYPE != IS_CONST) {
3056            FREE_OP2();
3057        }
3058    } else {
3059        if (UNEXPECTED(ce->constructor == NULL)) {
3060            zend_throw_error(NULL, "Cannot call constructor");
3061            HANDLE_EXCEPTION();
3062        }
3063        if (Z_OBJ(EX(This)) && Z_OBJ(EX(This))->ce != ce->constructor->common.scope && (ce->constructor->common.fn_flags & ZEND_ACC_PRIVATE)) {
3064            zend_throw_error(NULL, "Cannot call private %s::__construct()", ZSTR_VAL(ce->name));
3065            HANDLE_EXCEPTION();
3066        }
3067        fbc = ce->constructor;
3068    }
3069
3070    object = NULL;
3071    if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
3072        if (Z_OBJ(EX(This)) && instanceof_function(Z_OBJCE(EX(This)), ce)) {
3073            object = Z_OBJ(EX(This));
3074        }
3075        if (!object) {
3076            if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
3077                /* Allowed for PHP 4 compatibility. */
3078                zend_error(
3079                    E_DEPRECATED,
3080                    "Non-static method %s::%s() should not be called statically",
3081                    ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3082                if (UNEXPECTED(EG(exception) != NULL)) {
3083                    HANDLE_EXCEPTION();
3084                }
3085            } else {
3086                /* An internal function assumes $this is present and won't check that.
3087                 * So PHP would crash by allowing the call. */
3088                zend_throw_error(
3089                    zend_ce_error,
3090                    "Non-static method %s::%s() cannot be called statically",
3091                    ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3092                HANDLE_EXCEPTION();
3093            }
3094        }
3095    }
3096
3097    if (OP1_TYPE != IS_CONST) {
3098        /* previous opcode is ZEND_FETCH_CLASS */
3099        if (((opline-1)->extended_value & ZEND_FETCH_CLASS_MASK) == ZEND_FETCH_CLASS_PARENT ||
3100            ((opline-1)->extended_value & ZEND_FETCH_CLASS_MASK) == ZEND_FETCH_CLASS_SELF) {
3101            ce = EX(called_scope);
3102        }
3103    }
3104
3105    call = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
3106        fbc, opline->extended_value, ce, object);
3107    call->prev_execute_data = EX(call);
3108    EX(call) = call;
3109
3110    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
3111}
3112
3113ZEND_VM_HANDLER(59, ZEND_INIT_FCALL_BY_NAME, ANY, CONST)
3114{
3115    USE_OPLINE
3116    zend_function *fbc;
3117    zval *function_name, *func;
3118    zend_execute_data *call;
3119
3120    fbc = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
3121    if (UNEXPECTED(fbc == NULL)) {
3122        function_name = (zval*)(EX_CONSTANT(opline->op2)+1);
3123        func = zend_hash_find(EG(function_table), Z_STR_P(function_name));
3124        if (UNEXPECTED(func == NULL)) {
3125            SAVE_OPLINE();
3126            zend_throw_error(NULL, "Call to undefined function %s()", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
3127            HANDLE_EXCEPTION();
3128        }
3129        fbc = Z_FUNC_P(func);
3130        CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), fbc);
3131    }
3132    call = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
3133        fbc, opline->extended_value, NULL, NULL);
3134    call->prev_execute_data = EX(call);
3135    EX(call) = call;
3136
3137    ZEND_VM_NEXT_OPCODE();
3138}
3139
3140ZEND_VM_HANDLER(128, ZEND_INIT_DYNAMIC_CALL, ANY, CONST|TMPVAR|CV)
3141{
3142    USE_OPLINE
3143    zend_function *fbc;
3144    zval *function_name, *func;
3145    zend_string *lcname;
3146    zend_free_op free_op2;
3147    zend_class_entry *called_scope;
3148    zend_object *object;
3149    zend_execute_data *call;
3150    uint32_t call_info = ZEND_CALL_NESTED_FUNCTION;
3151
3152    SAVE_OPLINE();
3153    function_name = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
3154
3155ZEND_VM_C_LABEL(try_function_name):
3156    if (OP2_TYPE != IS_CONST && EXPECTED(Z_TYPE_P(function_name) == IS_STRING)) {
3157        const char *colon;
3158
3159        if ((colon = zend_memrchr(Z_STRVAL_P(function_name), ':', Z_STRLEN_P(function_name))) != NULL &&
3160            colon > Z_STRVAL_P(function_name) &&
3161            *(colon-1) == ':'
3162        ) {
3163            zend_string *mname;
3164            size_t cname_length = colon - Z_STRVAL_P(function_name) - 1;
3165            size_t mname_length = Z_STRLEN_P(function_name) - cname_length - (sizeof("::") - 1);
3166
3167            lcname = zend_string_init(Z_STRVAL_P(function_name), cname_length, 0);
3168
3169            object = NULL;
3170            called_scope = zend_fetch_class_by_name(lcname, NULL, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
3171            if (UNEXPECTED(called_scope == NULL)) {
3172                zend_string_release(lcname);
3173                ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
3174            }
3175
3176            mname = zend_string_init(Z_STRVAL_P(function_name) + (cname_length + sizeof("::") - 1), mname_length, 0);
3177
3178            if (called_scope->get_static_method) {
3179                fbc = called_scope->get_static_method(called_scope, mname);
3180            } else {
3181                fbc = zend_std_get_static_method(called_scope, mname, NULL);
3182            }
3183            if (UNEXPECTED(fbc == NULL)) {
3184                if (EXPECTED(!EG(exception))) {
3185                    zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(called_scope->name), ZSTR_VAL(mname));
3186                }
3187                zend_string_release(lcname);
3188                zend_string_release(mname);
3189                FREE_OP2();
3190                HANDLE_EXCEPTION();
3191            }
3192
3193            zend_string_release(lcname);
3194            zend_string_release(mname);
3195
3196            if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
3197                if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
3198                    zend_error(E_DEPRECATED,
3199                        "Non-static method %s::%s() should not be called statically",
3200                        ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3201                    if (UNEXPECTED(EG(exception) != NULL)) {
3202                        HANDLE_EXCEPTION();
3203                    }
3204                } else {
3205                    zend_throw_error(
3206                        zend_ce_error,
3207                        "Non-static method %s::%s() cannot be called statically",
3208                        ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3209                    FREE_OP2();
3210                    HANDLE_EXCEPTION();
3211                }
3212            }
3213        } else {
3214            if (Z_STRVAL_P(function_name)[0] == '\\') {
3215                lcname = zend_string_alloc(Z_STRLEN_P(function_name) - 1, 0);
3216                zend_str_tolower_copy(ZSTR_VAL(lcname), Z_STRVAL_P(function_name) + 1, Z_STRLEN_P(function_name) - 1);
3217            } else {
3218                lcname = zend_string_tolower(Z_STR_P(function_name));
3219            }
3220            if (UNEXPECTED((func = zend_hash_find(EG(function_table), lcname)) == NULL)) {
3221                zend_throw_error(NULL, "Call to undefined function %s()", Z_STRVAL_P(function_name));
3222                zend_string_release(lcname);
3223                FREE_OP2();
3224                HANDLE_EXCEPTION();
3225            }
3226            zend_string_release(lcname);
3227
3228            fbc = Z_FUNC_P(func);
3229            called_scope = NULL;
3230            object = NULL;
3231        }
3232        FREE_OP2();
3233    } else if (OP2_TYPE != IS_CONST &&
3234        EXPECTED(Z_TYPE_P(function_name) == IS_OBJECT) &&
3235        Z_OBJ_HANDLER_P(function_name, get_closure) &&
3236        Z_OBJ_HANDLER_P(function_name, get_closure)(function_name, &called_scope, &fbc, &object) == SUCCESS) {
3237        if (fbc->common.fn_flags & ZEND_ACC_CLOSURE) {
3238            /* Delay closure destruction until its invocation */
3239            ZEND_ASSERT(GC_TYPE((zend_object*)fbc->common.prototype) == IS_OBJECT);
3240            GC_REFCOUNT((zend_object*)fbc->common.prototype)++;
3241            call_info |= ZEND_CALL_CLOSURE;
3242        } else if (object) {
3243            call_info |= ZEND_CALL_RELEASE_THIS;
3244            GC_REFCOUNT(object)++; /* For $this pointer */
3245        }
3246        FREE_OP2();
3247    } else if (EXPECTED(Z_TYPE_P(function_name) == IS_ARRAY) &&
3248            zend_hash_num_elements(Z_ARRVAL_P(function_name)) == 2) {
3249        zval *obj;
3250        zval *method;
3251        obj = zend_hash_index_find(Z_ARRVAL_P(function_name), 0);
3252        method = zend_hash_index_find(Z_ARRVAL_P(function_name), 1);
3253
3254        if (!obj || !method) {
3255            zend_throw_error(NULL, "Array callback has to contain indices 0 and 1");
3256            FREE_OP2();
3257            HANDLE_EXCEPTION();
3258        }
3259
3260        ZVAL_DEREF(obj);
3261        if (Z_TYPE_P(obj) != IS_STRING && Z_TYPE_P(obj) != IS_OBJECT) {
3262            zend_throw_error(NULL, "First array member is not a valid class name or object");
3263            FREE_OP2();
3264            HANDLE_EXCEPTION();
3265        }
3266
3267        ZVAL_DEREF(method);
3268        if (Z_TYPE_P(method) != IS_STRING) {
3269            zend_throw_error(NULL, "Second array member is not a valid method");
3270            FREE_OP2();
3271            HANDLE_EXCEPTION();
3272        }
3273
3274        if (Z_TYPE_P(obj) == IS_STRING) {
3275            object = NULL;
3276            called_scope = zend_fetch_class_by_name(Z_STR_P(obj), NULL, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
3277            if (UNEXPECTED(called_scope == NULL)) {
3278                ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
3279            }
3280
3281            if (called_scope->get_static_method) {
3282                fbc = called_scope->get_static_method(called_scope, Z_STR_P(method));
3283            } else {
3284                fbc = zend_std_get_static_method(called_scope, Z_STR_P(method), NULL);
3285            }
3286            if (UNEXPECTED(fbc == NULL)) {
3287                if (EXPECTED(!EG(exception))) {
3288                    zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(called_scope->name), Z_STRVAL_P(method));
3289                }
3290                FREE_OP2();
3291                HANDLE_EXCEPTION();
3292            }
3293            if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
3294                if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
3295                    zend_error(E_DEPRECATED,
3296                        "Non-static method %s::%s() should not be called statically",
3297                        ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3298                    if (UNEXPECTED(EG(exception) != NULL)) {
3299                        HANDLE_EXCEPTION();
3300                    }
3301                } else {
3302                    zend_throw_error(
3303                        zend_ce_error,
3304                        "Non-static method %s::%s() cannot be called statically",
3305                        ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3306                    FREE_OP2();
3307                    HANDLE_EXCEPTION();
3308                }
3309            }
3310        } else {
3311            called_scope = Z_OBJCE_P(obj);
3312            object = Z_OBJ_P(obj);
3313
3314            fbc = Z_OBJ_HT_P(obj)->get_method(&object, Z_STR_P(method), NULL);
3315            if (UNEXPECTED(fbc == NULL)) {
3316                if (EXPECTED(!EG(exception))) {
3317                    zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(object->ce->name), Z_STRVAL_P(method));
3318                }
3319                FREE_OP2();
3320                HANDLE_EXCEPTION();
3321            }
3322
3323            if ((fbc->common.fn_flags & ZEND_ACC_STATIC) != 0) {
3324                object = NULL;
3325            } else {
3326                call_info |= ZEND_CALL_RELEASE_THIS;
3327                GC_REFCOUNT(object)++; /* For $this pointer */
3328            }
3329        }
3330        FREE_OP2();
3331    } else if ((OP2_TYPE & (IS_VAR|IS_CV)) && Z_TYPE_P(function_name) == IS_REFERENCE) {
3332        function_name = Z_REFVAL_P(function_name);
3333        ZEND_VM_C_GOTO(try_function_name);
3334    } else {
3335        if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(function_name) == IS_UNDEF)) {
3336            GET_OP2_UNDEF_CV(function_name, BP_VAR_R);
3337        }
3338        if (UNEXPECTED(EG(exception) != NULL)) {
3339            HANDLE_EXCEPTION();
3340        }
3341        zend_throw_error(NULL, "Function name must be a string");
3342        FREE_OP2();
3343        HANDLE_EXCEPTION();
3344    }
3345    call = zend_vm_stack_push_call_frame(call_info,
3346        fbc, opline->extended_value, called_scope, object);
3347    call->prev_execute_data = EX(call);
3348    EX(call) = call;
3349
3350    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
3351}
3352
3353ZEND_VM_HANDLER(118, ZEND_INIT_USER_CALL, CONST, CONST|TMPVAR|CV)
3354{
3355    USE_OPLINE
3356    zend_free_op free_op2;
3357    zval *function_name;
3358    zend_fcall_info_cache fcc;
3359    char *error = NULL;
3360    zend_function *func;
3361    zend_class_entry *called_scope;
3362    zend_object *object;
3363    zend_execute_data *call;
3364    uint32_t call_info = ZEND_CALL_NESTED_FUNCTION;
3365
3366    SAVE_OPLINE();
3367    function_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
3368    if (zend_is_callable_ex(function_name, NULL, 0, NULL, &fcc, &error)) {
3369        func = fcc.function_handler;
3370        if (func->common.fn_flags & ZEND_ACC_CLOSURE) {
3371            /* Delay closure destruction until its invocation */
3372            if (OP2_TYPE & (IS_VAR|IS_CV)) {
3373                ZVAL_DEREF(function_name);
3374            }
3375            ZEND_ASSERT(GC_TYPE((zend_object*)func->common.prototype) == IS_OBJECT);
3376            GC_REFCOUNT((zend_object*)func->common.prototype)++;
3377            call_info |= ZEND_CALL_CLOSURE;
3378        }
3379        called_scope = fcc.called_scope;
3380        object = fcc.object;
3381        if (object) {
3382            call_info |= ZEND_CALL_RELEASE_THIS;
3383            GC_REFCOUNT(object)++; /* For $this pointer */
3384        }
3385        if (error) {
3386            efree(error);
3387            /* This is the only soft error is_callable() can generate */
3388            zend_error(E_DEPRECATED,
3389                "Non-static method %s::%s() should not be called statically",
3390                ZSTR_VAL(func->common.scope->name), ZSTR_VAL(func->common.function_name));
3391            if (UNEXPECTED(EG(exception) != NULL)) {
3392                HANDLE_EXCEPTION();
3393            }
3394        }
3395    } else {
3396        zend_internal_type_error(EX_USES_STRICT_TYPES(), "%s() expects parameter 1 to be a valid callback, %s", Z_STRVAL_P(EX_CONSTANT(opline->op1)), error);
3397        efree(error);
3398        func = (zend_function*)&zend_pass_function;
3399        called_scope = NULL;
3400        object = NULL;
3401    }
3402
3403    call = zend_vm_stack_push_call_frame(call_info,
3404        func, opline->extended_value, called_scope, object);
3405    call->prev_execute_data = EX(call);
3406    EX(call) = call;
3407
3408    FREE_OP2();
3409    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
3410}
3411
3412ZEND_VM_HANDLER(69, ZEND_INIT_NS_FCALL_BY_NAME, ANY, CONST)
3413{
3414    USE_OPLINE
3415    zval *func_name;
3416    zval *func;
3417    zend_function *fbc;
3418    zend_execute_data *call;
3419
3420    func_name = EX_CONSTANT(opline->op2) + 1;
3421    fbc = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
3422    if (UNEXPECTED(fbc == NULL)) {
3423        func = zend_hash_find(EG(function_table), Z_STR_P(func_name));
3424        if (func == NULL) {
3425            func_name++;
3426            func = zend_hash_find(EG(function_table), Z_STR_P(func_name));
3427            if (UNEXPECTED(func == NULL)) {
3428                SAVE_OPLINE();
3429                zend_throw_error(NULL, "Call to undefined function %s()", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
3430                HANDLE_EXCEPTION();
3431            }
3432        }
3433        fbc = Z_FUNC_P(func);
3434        CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), fbc);
3435    }
3436
3437    call = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
3438        fbc, opline->extended_value, NULL, NULL);
3439    call->prev_execute_data = EX(call);
3440    EX(call) = call;
3441
3442    ZEND_VM_NEXT_OPCODE();
3443}
3444
3445ZEND_VM_HANDLER(61, ZEND_INIT_FCALL, ANY, CONST)
3446{
3447    USE_OPLINE
3448    zend_free_op free_op2;
3449    zval *fname = GET_OP2_ZVAL_PTR(BP_VAR_R);
3450    zval *func;
3451    zend_function *fbc;
3452    zend_execute_data *call;
3453
3454    fbc = CACHED_PTR(Z_CACHE_SLOT_P(fname));
3455    if (UNEXPECTED(fbc == NULL)) {
3456        func = zend_hash_find(EG(function_table), Z_STR_P(fname));
3457        if (UNEXPECTED(func == NULL)) {
3458            SAVE_OPLINE();
3459            zend_throw_error(NULL, "Call to undefined function %s()", Z_STRVAL_P(fname));
3460            HANDLE_EXCEPTION();
3461        }
3462        fbc = Z_FUNC_P(func);
3463        CACHE_PTR(Z_CACHE_SLOT_P(fname), fbc);
3464    }
3465
3466    call = zend_vm_stack_push_call_frame_ex(
3467        opline->op1.num, ZEND_CALL_NESTED_FUNCTION,
3468        fbc, opline->extended_value, NULL, NULL);
3469    call->prev_execute_data = EX(call);
3470    EX(call) = call;
3471
3472    ZEND_VM_NEXT_OPCODE();
3473}
3474
3475ZEND_VM_HANDLER(129, ZEND_DO_ICALL, ANY, ANY)
3476{
3477    USE_OPLINE
3478    zend_execute_data *call = EX(call);
3479    zend_function *fbc = call->func;
3480    zval *ret;
3481
3482    SAVE_OPLINE();
3483    EX(call) = call->prev_execute_data;
3484
3485    call->prev_execute_data = execute_data;
3486    EG(current_execute_data) = call;
3487
3488    ret = EX_VAR(opline->result.var);
3489    ZVAL_NULL(ret);
3490    Z_VAR_FLAGS_P(ret) = 0;
3491
3492    fbc->internal_function.handler(call, ret);
3493
3494#if ZEND_DEBUG
3495    ZEND_ASSERT(
3496        !call->func ||
3497        !(call->func->common.fn_flags & ZEND_ACC_HAS_RETURN_TYPE) ||
3498        zend_verify_internal_return_type(call->func, EX_VAR(opline->result.var)));
3499#endif
3500
3501    EG(current_execute_data) = call->prev_execute_data;
3502    zend_vm_stack_free_args(call);
3503    zend_vm_stack_free_call_frame(call);
3504
3505    if (!RETURN_VALUE_USED(opline)) {
3506        zval_ptr_dtor(EX_VAR(opline->result.var));
3507    }
3508
3509    if (UNEXPECTED(EG(exception) != NULL)) {
3510        zend_throw_exception_internal(NULL);
3511        if (RETURN_VALUE_USED(opline)) {
3512            zval_ptr_dtor(EX_VAR(opline->result.var));
3513        }
3514        HANDLE_EXCEPTION();
3515    }
3516
3517    ZEND_VM_INTERRUPT_CHECK();
3518    ZEND_VM_NEXT_OPCODE();
3519}
3520
3521ZEND_VM_HANDLER(130, ZEND_DO_UCALL, ANY, ANY)
3522{
3523    USE_OPLINE
3524    zend_execute_data *call = EX(call);
3525    zend_function *fbc = call->func;
3526    zval *ret;
3527
3528    SAVE_OPLINE();
3529    EX(call) = call->prev_execute_data;
3530
3531    EG(scope) = NULL;
3532    ret = NULL;
3533    call->symbol_table = NULL;
3534    if (RETURN_VALUE_USED(opline)) {
3535        ret = EX_VAR(opline->result.var);
3536        ZVAL_NULL(ret);
3537        Z_VAR_FLAGS_P(ret) = 0;
3538    }
3539
3540    call->prev_execute_data = execute_data;
3541    i_init_func_execute_data(call, &fbc->op_array, ret, 0);
3542
3543    ZEND_VM_ENTER();
3544}
3545
3546ZEND_VM_HANDLER(131, ZEND_DO_FCALL_BY_NAME, ANY, ANY)
3547{
3548    USE_OPLINE
3549    zend_execute_data *call = EX(call);
3550    zend_function *fbc = call->func;
3551    zval *ret;
3552
3553    SAVE_OPLINE();
3554    EX(call) = call->prev_execute_data;
3555
3556    if (EXPECTED(fbc->type == ZEND_USER_FUNCTION)) {
3557        EG(scope) = NULL;
3558        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_GENERATOR) != 0)) {
3559            if (EXPECTED(RETURN_VALUE_USED(opline))) {
3560                ret = EX_VAR(opline->result.var);
3561                zend_generator_create_zval(call, &fbc->op_array, ret);
3562                Z_VAR_FLAGS_P(ret) = 0;
3563            } else {
3564                zend_vm_stack_free_args(call);
3565            }
3566
3567            zend_vm_stack_free_call_frame(call);
3568        } else {
3569            ret = NULL;
3570            call->symbol_table = NULL;
3571            if (RETURN_VALUE_USED(opline)) {
3572                ret = EX_VAR(opline->result.var);
3573                ZVAL_NULL(ret);
3574                Z_VAR_FLAGS_P(ret) = 0;
3575            }
3576
3577            call->prev_execute_data = execute_data;
3578            i_init_func_execute_data(call, &fbc->op_array, ret, 0);
3579
3580            ZEND_VM_ENTER();
3581        }
3582        EG(scope) = EX(func)->op_array.scope;
3583    } else {
3584        ZEND_ASSERT(fbc->type == ZEND_INTERNAL_FUNCTION);
3585
3586        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_DEPRECATED) != 0)) {
3587            zend_error(E_DEPRECATED, "Function %s%s%s() is deprecated",
3588                fbc->common.scope ? ZSTR_VAL(fbc->common.scope->name) : "",
3589                fbc->common.scope ? "::" : "",
3590                ZSTR_VAL(fbc->common.function_name));
3591            if (UNEXPECTED(EG(exception) != NULL)) {
3592                HANDLE_EXCEPTION();
3593            }
3594        }
3595
3596        call->prev_execute_data = execute_data;
3597        EG(current_execute_data) = call;
3598
3599        if (fbc->common.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) {
3600            uint32_t i;
3601            uint32_t num_args = ZEND_CALL_NUM_ARGS(call);
3602            zval *p = ZEND_CALL_ARG(call, 1);
3603
3604            for (i = 0; i < num_args; ++i) {
3605                zend_verify_internal_arg_type(fbc, i + 1, p);
3606                p++;
3607            }
3608            if (UNEXPECTED(EG(exception) != NULL)) {
3609                EG(current_execute_data) = call->prev_execute_data;
3610                zend_vm_stack_free_args(call);
3611                zend_vm_stack_free_call_frame(call);
3612                zend_throw_exception_internal(NULL);
3613                HANDLE_EXCEPTION();
3614            }
3615        }
3616
3617        ret = EX_VAR(opline->result.var);
3618        ZVAL_NULL(ret);
3619        Z_VAR_FLAGS_P(ret) = (fbc->common.fn_flags & ZEND_ACC_RETURN_REFERENCE) != 0 ? IS_VAR_RET_REF : 0;
3620
3621        fbc->internal_function.handler(call, ret);
3622
3623#if ZEND_DEBUG
3624        ZEND_ASSERT(
3625            !call->func ||
3626            !(call->func->common.fn_flags & ZEND_ACC_HAS_RETURN_TYPE) ||
3627            zend_verify_internal_return_type(call->func, EX_VAR(opline->result.var)));
3628#endif
3629
3630        EG(current_execute_data) = call->prev_execute_data;
3631        zend_vm_stack_free_args(call);
3632        zend_vm_stack_free_call_frame(call);
3633
3634        if (!RETURN_VALUE_USED(opline)) {
3635            zval_ptr_dtor(EX_VAR(opline->result.var));
3636        }
3637    }
3638
3639    if (UNEXPECTED(EG(exception) != NULL)) {
3640        zend_throw_exception_internal(NULL);
3641        if (RETURN_VALUE_USED(opline)) {
3642            zval_ptr_dtor(EX_VAR(opline->result.var));
3643        }
3644        HANDLE_EXCEPTION();
3645    }
3646    ZEND_VM_INTERRUPT_CHECK();
3647    ZEND_VM_NEXT_OPCODE();
3648}
3649
3650ZEND_VM_HANDLER(60, ZEND_DO_FCALL, ANY, ANY)
3651{
3652    USE_OPLINE
3653    zend_execute_data *call = EX(call);
3654    zend_function *fbc = call->func;
3655    zend_object *object;
3656    zval *ret;
3657
3658    SAVE_OPLINE();
3659    EX(call) = call->prev_execute_data;
3660    if (UNEXPECTED((fbc->common.fn_flags & (ZEND_ACC_ABSTRACT|ZEND_ACC_DEPRECATED)) != 0)) {
3661        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_ABSTRACT) != 0)) {
3662            zend_throw_error(NULL, "Cannot call abstract method %s::%s()", ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3663            HANDLE_EXCEPTION();
3664        }
3665        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_DEPRECATED) != 0)) {
3666            zend_error(E_DEPRECATED, "Function %s%s%s() is deprecated",
3667                fbc->common.scope ? ZSTR_VAL(fbc->common.scope->name) : "",
3668                fbc->common.scope ? "::" : "",
3669                ZSTR_VAL(fbc->common.function_name));
3670            if (UNEXPECTED(EG(exception) != NULL)) {
3671                HANDLE_EXCEPTION();
3672            }
3673        }
3674    }
3675
3676    LOAD_OPLINE();
3677
3678    if (EXPECTED(fbc->type == ZEND_USER_FUNCTION)) {
3679        EG(scope) = fbc->common.scope;
3680        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_GENERATOR) != 0)) {
3681            if (EXPECTED(RETURN_VALUE_USED(opline))) {
3682                ret = EX_VAR(opline->result.var);
3683                zend_generator_create_zval(call, &fbc->op_array, ret);
3684                Z_VAR_FLAGS_P(ret) = 0;
3685            } else {
3686                if (UNEXPECTED(ZEND_CALL_INFO(call) & ZEND_CALL_CLOSURE)) {
3687                    OBJ_RELEASE((zend_object*)fbc->op_array.prototype);
3688                }
3689                zend_vm_stack_free_args(call);
3690            }
3691        } else {
3692            ret = NULL;
3693            call->symbol_table = NULL;
3694            if (RETURN_VALUE_USED(opline)) {
3695                ret = EX_VAR(opline->result.var);
3696                ZVAL_NULL(ret);
3697                Z_VAR_FLAGS_P(ret) = 0;
3698            }
3699
3700            call->prev_execute_data = execute_data;
3701            i_init_func_execute_data(call, &fbc->op_array, ret, 1);
3702
3703            if (EXPECTED(zend_execute_ex == execute_ex)) {
3704                ZEND_VM_ENTER();
3705            } else {
3706                ZEND_ADD_CALL_FLAG(call, ZEND_CALL_TOP);
3707                zend_execute_ex(call);
3708            }
3709        }
3710    } else if (EXPECTED(fbc->type < ZEND_USER_FUNCTION)) {
3711        int should_change_scope = 0;
3712
3713        if (fbc->common.scope) {
3714            should_change_scope = 1;
3715            EG(scope) = fbc->common.scope;
3716        }
3717
3718        call->prev_execute_data = execute_data;
3719        EG(current_execute_data) = call;
3720
3721        if (fbc->common.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) {
3722            uint32_t i;
3723            uint32_t num_args = ZEND_CALL_NUM_ARGS(call);
3724            zval *p = ZEND_CALL_ARG(call, 1);
3725
3726            for (i = 0; i < num_args; ++i) {
3727                zend_verify_internal_arg_type(fbc, i + 1, p);
3728                if (UNEXPECTED(EG(exception) != NULL)) {
3729                    EG(current_execute_data) = call->prev_execute_data;
3730                    zend_vm_stack_free_args(call);
3731                    if (RETURN_VALUE_USED(opline)) {
3732                        ZVAL_UNDEF(EX_VAR(opline->result.var));
3733                    }
3734                    if (UNEXPECTED(should_change_scope)) {
3735                        ZEND_VM_C_GOTO(fcall_end_change_scope);
3736                    } else {
3737                        ZEND_VM_C_GOTO(fcall_end);
3738                    }
3739                }
3740                p++;
3741            }
3742        }
3743
3744        ret = EX_VAR(opline->result.var);
3745        ZVAL_NULL(ret);
3746        Z_VAR_FLAGS_P(ret) = (fbc->common.fn_flags & ZEND_ACC_RETURN_REFERENCE) != 0 ? IS_VAR_RET_REF : 0;
3747
3748        if (!zend_execute_internal) {
3749            /* saves one function call if zend_execute_internal is not used */
3750            fbc->internal_function.handler(call, ret);
3751        } else {
3752            zend_execute_internal(call, ret);
3753        }
3754
3755#if ZEND_DEBUG
3756        ZEND_ASSERT(
3757            !call->func ||
3758            !(call->func->common.fn_flags & ZEND_ACC_HAS_RETURN_TYPE) ||
3759            zend_verify_internal_return_type(call->func, EX_VAR(opline->result.var)));
3760#endif
3761
3762        EG(current_execute_data) = call->prev_execute_data;
3763        zend_vm_stack_free_args(call);
3764
3765        if (!RETURN_VALUE_USED(opline)) {
3766            zval_ptr_dtor(EX_VAR(opline->result.var));
3767        }
3768
3769        if (UNEXPECTED(should_change_scope)) {
3770            ZEND_VM_C_GOTO(fcall_end_change_scope);
3771        } else {
3772            ZEND_VM_C_GOTO(fcall_end);
3773        }
3774    } else { /* ZEND_OVERLOADED_FUNCTION */
3775        EG(scope) = fbc->common.scope;
3776
3777        ZVAL_NULL(EX_VAR(opline->result.var));
3778
3779        /* Not sure what should be done here if it's a static method */
3780        object = Z_OBJ(call->This);
3781        if (EXPECTED(object != NULL)) {
3782            call->prev_execute_data = execute_data;
3783            EG(current_execute_data) = call;
3784            object->handlers->call_method(fbc->common.function_name, object, call, EX_VAR(opline->result.var));
3785            EG(current_execute_data) = call->prev_execute_data;
3786        } else {
3787            zend_throw_error(NULL, "Cannot call overloaded function for non-object");
3788#if 0
3789            //TODO: implement clean exit ???
3790            zend_vm_stack_free_args(call);
3791
3792            zend_vm_stack_free_call_frame(call);
3793
3794            if (fbc->type == ZEND_OVERLOADED_FUNCTION_TEMPORARY) {
3795                zend_string_release(fbc->common.function_name);
3796            }
3797            efree(fbc);
3798#endif
3799            HANDLE_EXCEPTION();
3800        }
3801
3802        zend_vm_stack_free_args(call);
3803
3804        if (fbc->type == ZEND_OVERLOADED_FUNCTION_TEMPORARY) {
3805            zend_string_release(fbc->common.function_name);
3806        }
3807        efree(fbc);
3808
3809        if (!RETURN_VALUE_USED(opline)) {
3810            zval_ptr_dtor(EX_VAR(opline->result.var));
3811        } else {
3812            Z_VAR_FLAGS_P(EX_VAR(opline->result.var)) = 0;
3813        }
3814    }
3815
3816ZEND_VM_C_LABEL(fcall_end_change_scope):
3817    if (UNEXPECTED(ZEND_CALL_INFO(call) & ZEND_CALL_RELEASE_THIS)) {
3818        object = Z_OBJ(call->This);
3819#if 0
3820        if (UNEXPECTED(EG(exception) != NULL) && (opline->op1.num & ZEND_CALL_CTOR)) {
3821            if (!(opline->op1.num & ZEND_CALL_CTOR_RESULT_UNUSED)) {
3822#else
3823        if (UNEXPECTED(EG(exception) != NULL) && (ZEND_CALL_INFO(call) & ZEND_CALL_CTOR)) {
3824            if (!(ZEND_CALL_INFO(call) & ZEND_CALL_CTOR_RESULT_UNUSED)) {
3825#endif
3826                GC_REFCOUNT(object)--;
3827            }
3828            if (GC_REFCOUNT(object) == 1) {
3829                zend_object_store_ctor_failed(object);
3830            }
3831        }
3832        OBJ_RELEASE(object);
3833    }
3834    EG(scope) = EX(func)->op_array.scope;
3835
3836ZEND_VM_C_LABEL(fcall_end):
3837    zend_vm_stack_free_call_frame(call);
3838    if (UNEXPECTED(EG(exception) != NULL)) {
3839        zend_throw_exception_internal(NULL);
3840        if (RETURN_VALUE_USED(opline)) {
3841            zval_ptr_dtor(EX_VAR(opline->result.var));
3842        }
3843        HANDLE_EXCEPTION();
3844    }
3845
3846    ZEND_VM_INTERRUPT_CHECK();
3847    ZEND_VM_NEXT_OPCODE();
3848}
3849
3850ZEND_VM_HANDLER(124, ZEND_VERIFY_RETURN_TYPE, CONST|TMP|VAR|UNUSED|CV, UNUSED)
3851{
3852    USE_OPLINE
3853
3854    SAVE_OPLINE();
3855    if (OP1_TYPE == IS_UNUSED) {
3856        zend_verify_missing_return_type(EX(func), CACHE_ADDR(opline->op2.num));
3857    } else {
3858/* prevents "undefined variable opline" errors */
3859#if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
3860        zval *retval_ref, *retval_ptr;
3861        zend_free_op free_op1;
3862        zend_arg_info *ret_info = EX(func)->common.arg_info - 1;
3863
3864        retval_ref = retval_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
3865
3866        if (OP1_TYPE == IS_CONST) {
3867            ZVAL_COPY(EX_VAR(opline->result.var), retval_ptr);
3868            retval_ref = retval_ptr = EX_VAR(opline->result.var);
3869        } else if (OP1_TYPE == IS_VAR) {
3870            if (UNEXPECTED(Z_TYPE_P(retval_ptr) == IS_INDIRECT)) {
3871                retval_ptr = Z_INDIRECT_P(retval_ptr);
3872            }
3873            ZVAL_DEREF(retval_ptr);
3874        } else if (OP1_TYPE == IS_CV) {
3875            ZVAL_DEREF(retval_ptr);
3876        }
3877
3878        if (UNEXPECTED(!ret_info->class_name
3879            && ret_info->type_hint != IS_CALLABLE
3880            && !ZEND_SAME_FAKE_TYPE(ret_info->type_hint, Z_TYPE_P(retval_ptr))
3881            && !(EX(func)->op_array.fn_flags & ZEND_ACC_RETURN_REFERENCE)
3882            && retval_ref != retval_ptr)
3883        ) {
3884            /* A cast might happen - unwrap the reference if this is a by-value return */
3885            if (Z_REFCOUNT_P(retval_ref) == 1) {
3886                ZVAL_UNREF(retval_ref);
3887            } else {
3888                Z_DELREF_P(retval_ref);
3889                ZVAL_COPY(retval_ref, retval_ptr);
3890            }
3891            retval_ptr = retval_ref;
3892        }
3893        zend_verify_return_type(EX(func), retval_ptr, CACHE_ADDR(opline->op2.num));
3894
3895        if (UNEXPECTED(EG(exception) != NULL)) {
3896            FREE_OP1();
3897        }
3898#endif
3899    }
3900    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
3901}
3902
3903ZEND_VM_HANDLER(62, ZEND_RETURN, CONST|TMP|VAR|CV, ANY)
3904{
3905    USE_OPLINE
3906    zval *retval_ptr;
3907    zend_free_op free_op1;
3908
3909    retval_ptr = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
3910    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(retval_ptr) == IS_UNDEF)) {
3911        SAVE_OPLINE();
3912        retval_ptr = GET_OP1_UNDEF_CV(retval_ptr, BP_VAR_R);
3913        if (EX(return_value)) {
3914            ZVAL_NULL(EX(return_value));
3915        }
3916    } else if (!EX(return_value)) {
3917        if (OP1_TYPE == IS_VAR || OP1_TYPE == IS_TMP_VAR ) {
3918            if (Z_REFCOUNTED_P(free_op1) && !Z_DELREF_P(free_op1)) {
3919                SAVE_OPLINE();
3920                zval_dtor_func_for_ptr(Z_COUNTED_P(free_op1));
3921            }
3922        }
3923    } else {
3924        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
3925            ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
3926            if (OP1_TYPE == IS_CONST) {
3927                if (UNEXPECTED(Z_OPT_COPYABLE_P(EX(return_value)))) {
3928                    zval_copy_ctor_func(EX(return_value));
3929                }
3930            }
3931        } else if (OP1_TYPE == IS_CV) {
3932            ZVAL_DEREF(retval_ptr);
3933            ZVAL_COPY(EX(return_value), retval_ptr);
3934        } else /* if (OP1_TYPE == IS_VAR) */ {
3935            if (UNEXPECTED(Z_ISREF_P(retval_ptr))) {
3936                zend_refcounted *ref = Z_COUNTED_P(retval_ptr);
3937
3938                retval_ptr = Z_REFVAL_P(retval_ptr);
3939                ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
3940                if (UNEXPECTED(--GC_REFCOUNT(ref) == 0)) {
3941                    efree_size(ref, sizeof(zend_reference));
3942                } else if (Z_OPT_REFCOUNTED_P(retval_ptr)) {
3943                    Z_ADDREF_P(retval_ptr);
3944                }
3945            } else {
3946                ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
3947            }
3948        }
3949    }
3950    ZEND_VM_DISPATCH_TO_HELPER(zend_leave_helper);
3951}
3952
3953ZEND_VM_HANDLER(111, ZEND_RETURN_BY_REF, CONST|TMP|VAR|CV, ANY)
3954{
3955    USE_OPLINE
3956    zval *retval_ptr;
3957    zend_free_op free_op1;
3958
3959    SAVE_OPLINE();
3960
3961    do {
3962        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR ||
3963            (OP1_TYPE == IS_VAR && opline->extended_value == ZEND_RETURNS_VALUE)) {
3964            /* Not supposed to happen, but we'll allow it */
3965            zend_error(E_NOTICE, "Only variable references should be returned by reference");
3966
3967            retval_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
3968            if (!EX(return_value)) {
3969                if (OP1_TYPE == IS_TMP_VAR) {
3970                    FREE_OP1();
3971                }
3972            } else {
3973                ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
3974                Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
3975                if (OP1_TYPE != IS_TMP_VAR) {
3976                    zval_opt_copy_ctor_no_imm(EX(return_value));
3977                }
3978            }
3979            break;
3980        }
3981
3982        retval_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
3983
3984        if (OP1_TYPE == IS_VAR && UNEXPECTED(retval_ptr == NULL)) {
3985            zend_throw_error(NULL, "Cannot return string offsets by reference");
3986            HANDLE_EXCEPTION();
3987        }
3988
3989        if (OP1_TYPE == IS_VAR) {
3990            if (retval_ptr == &EG(uninitialized_zval) ||
3991                (opline->extended_value == ZEND_RETURNS_FUNCTION &&
3992                 !(Z_VAR_FLAGS_P(retval_ptr) & IS_VAR_RET_REF))) {
3993                zend_error(E_NOTICE, "Only variable references should be returned by reference");
3994                if (EX(return_value)) {
3995                    ZVAL_NEW_REF(EX(return_value), retval_ptr);
3996                    Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
3997                    if (Z_REFCOUNTED_P(retval_ptr)) Z_ADDREF_P(retval_ptr);
3998                }
3999                break;
4000            }
4001        }
4002
4003        if (EX(return_value)) {
4004            ZVAL_MAKE_REF(retval_ptr);
4005            Z_ADDREF_P(retval_ptr);
4006            ZVAL_REF(EX(return_value), Z_REF_P(retval_ptr));
4007            Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
4008        }
4009    } while (0);
4010
4011    FREE_OP1_VAR_PTR();
4012    ZEND_VM_DISPATCH_TO_HELPER(zend_leave_helper);
4013}
4014
4015ZEND_VM_HANDLER(161, ZEND_GENERATOR_RETURN, CONST|TMP|VAR|CV, ANY)
4016{
4017    USE_OPLINE
4018    zval *retval;
4019    zend_free_op free_op1;
4020
4021    zend_generator *generator = zend_get_running_generator(execute_data);
4022
4023    SAVE_OPLINE();
4024    retval = GET_OP1_ZVAL_PTR(BP_VAR_R);
4025
4026    /* Copy return value into generator->retval */
4027    if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
4028        ZVAL_COPY_VALUE(&generator->retval, retval);
4029        if (OP1_TYPE == IS_CONST) {
4030            if (UNEXPECTED(Z_OPT_COPYABLE(generator->retval))) {
4031                zval_copy_ctor_func(&generator->retval);
4032            }
4033        }
4034    } else if (OP1_TYPE == IS_CV) {
4035        ZVAL_DEREF(retval);
4036        ZVAL_COPY(&generator->retval, retval);
4037    } else /* if (OP1_TYPE == IS_VAR) */ {
4038        if (UNEXPECTED(Z_ISREF_P(retval))) {
4039            zend_refcounted *ref = Z_COUNTED_P(retval);
4040
4041            retval = Z_REFVAL_P(retval);
4042            ZVAL_COPY_VALUE(&generator->retval, retval);
4043            if (UNEXPECTED(--GC_REFCOUNT(ref) == 0)) {
4044                efree_size(ref, sizeof(zend_reference));
4045            } else if (Z_OPT_REFCOUNTED_P(retval)) {
4046                Z_ADDREF_P(retval);
4047            }
4048        } else {
4049            ZVAL_COPY_VALUE(&generator->retval, retval);
4050        }
4051    }
4052
4053    /* Close the generator to free up resources */
4054    zend_generator_close(generator, 1);
4055
4056    /* Pass execution back to handling code */
4057    ZEND_VM_RETURN();
4058}
4059
4060ZEND_VM_HANDLER(108, ZEND_THROW, CONST|TMP|VAR|CV, ANY)
4061{
4062    USE_OPLINE
4063    zval *value;
4064    zend_free_op free_op1;
4065
4066    SAVE_OPLINE();
4067    value = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4068
4069    do {
4070        if (OP1_TYPE == IS_CONST || UNEXPECTED(Z_TYPE_P(value) != IS_OBJECT)) {
4071            if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(value)) {
4072                value = Z_REFVAL_P(value);
4073                if (EXPECTED(Z_TYPE_P(value) == IS_OBJECT)) {
4074                    break;
4075                }
4076            }
4077            if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
4078                GET_OP1_UNDEF_CV(value, BP_VAR_R);
4079            }
4080            if (UNEXPECTED(EG(exception) != NULL)) {
4081                HANDLE_EXCEPTION();
4082            }
4083            zend_throw_error(NULL, "Can only throw objects");
4084            FREE_OP1();
4085            HANDLE_EXCEPTION();
4086        }
4087    } while (0);
4088
4089    zend_exception_save();
4090    if (OP1_TYPE != IS_TMP_VAR) {
4091        if (Z_REFCOUNTED_P(value)) Z_ADDREF_P(value);
4092    }
4093
4094    zend_throw_exception_object(value);
4095    zend_exception_restore();
4096    FREE_OP1_IF_VAR();
4097    HANDLE_EXCEPTION();
4098}
4099
4100ZEND_VM_HANDLER(107, ZEND_CATCH, CONST, CV)
4101{
4102    USE_OPLINE
4103    zend_class_entry *ce, *catch_ce;
4104    zend_object *exception;
4105
4106    SAVE_OPLINE();
4107    /* Check whether an exception has been thrown, if not, jump over code */
4108    zend_exception_restore();
4109    if (EG(exception) == NULL) {
4110        ZEND_VM_SET_OPCODE(&EX(func)->op_array.opcodes[opline->extended_value]);
4111        ZEND_VM_CONTINUE(); /* CHECK_ME */
4112    }
4113    catch_ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
4114    if (UNEXPECTED(catch_ce == NULL)) {
4115        catch_ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, ZEND_FETCH_CLASS_NO_AUTOLOAD);
4116
4117        CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), catch_ce);
4118    }
4119    ce = EG(exception)->ce;
4120
4121#ifdef HAVE_DTRACE
4122    if (DTRACE_EXCEPTION_CAUGHT_ENABLED()) {
4123        DTRACE_EXCEPTION_CAUGHT((char *)ce->name);
4124    }
4125#endif /* HAVE_DTRACE */
4126
4127    if (ce != catch_ce) {
4128        if (!catch_ce || !instanceof_function(ce, catch_ce)) {
4129            if (opline->result.num) {
4130                zend_throw_exception_internal(NULL);
4131                HANDLE_EXCEPTION();
4132            }
4133            ZEND_VM_SET_OPCODE(&EX(func)->op_array.opcodes[opline->extended_value]);
4134            ZEND_VM_CONTINUE(); /* CHECK_ME */
4135        }
4136    }
4137
4138    exception = EG(exception);
4139    zval_ptr_dtor(EX_VAR(opline->op2.var));
4140    ZVAL_OBJ(EX_VAR(opline->op2.var), EG(exception));
4141    if (UNEXPECTED(EG(exception) != exception)) {
4142        GC_REFCOUNT(EG(exception))++;
4143        HANDLE_EXCEPTION();
4144    } else {
4145        EG(exception) = NULL;
4146        ZEND_VM_NEXT_OPCODE();
4147    }
4148}
4149
4150ZEND_VM_HANDLER(65, ZEND_SEND_VAL, CONST|TMP, ANY)
4151{
4152    USE_OPLINE
4153    zval *value, *arg;
4154    zend_free_op free_op1;
4155
4156    value = GET_OP1_ZVAL_PTR(BP_VAR_R);
4157    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4158    ZVAL_COPY_VALUE(arg, value);
4159    if (OP1_TYPE == IS_CONST) {
4160        if (UNEXPECTED(Z_OPT_COPYABLE_P(arg))) {
4161            zval_copy_ctor_func(arg);
4162        }
4163    }
4164    ZEND_VM_NEXT_OPCODE();
4165}
4166
4167ZEND_VM_HANDLER(116, ZEND_SEND_VAL_EX, CONST|TMP, ANY)
4168{
4169    USE_OPLINE
4170    zval *value, *arg;
4171    zend_free_op free_op1;
4172
4173    if (EXPECTED(opline->op2.num <= MAX_ARG_FLAG_NUM)) {
4174        if (QUICK_ARG_MUST_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4175            ZEND_VM_C_GOTO(send_val_by_ref);
4176        }
4177    } else if (ARG_MUST_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4178ZEND_VM_C_LABEL(send_val_by_ref):
4179        SAVE_OPLINE();
4180        zend_throw_error(NULL, "Cannot pass parameter %d by reference", opline->op2.num);
4181        FREE_UNFETCHED_OP1();
4182        arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4183        ZVAL_UNDEF(arg);
4184        HANDLE_EXCEPTION();
4185    }
4186    value = GET_OP1_ZVAL_PTR(BP_VAR_R);
4187    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4188    ZVAL_COPY_VALUE(arg, value);
4189    if (OP1_TYPE == IS_CONST) {
4190        if (UNEXPECTED(Z_OPT_COPYABLE_P(arg))) {
4191            zval_copy_ctor_func(arg);
4192        }
4193    }
4194    ZEND_VM_NEXT_OPCODE();
4195}
4196
4197ZEND_VM_HANDLER(117, ZEND_SEND_VAR, VAR|CV, ANY)
4198{
4199    USE_OPLINE
4200    zval *varptr, *arg;
4201    zend_free_op free_op1;
4202
4203    varptr = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4204    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(varptr) == IS_UNDEF)) {
4205        SAVE_OPLINE();
4206        GET_OP1_UNDEF_CV(varptr, BP_VAR_R);
4207        arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4208        ZVAL_NULL(arg);
4209        ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4210    }
4211
4212    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4213
4214    if (OP1_TYPE == IS_CV) {
4215        ZVAL_OPT_DEREF(varptr);
4216        ZVAL_COPY(arg, varptr);
4217    } else /* if (OP1_TYPE == IS_VAR) */ {
4218        if (UNEXPECTED(Z_ISREF_P(varptr))) {
4219            zend_refcounted *ref = Z_COUNTED_P(varptr);
4220
4221            varptr = Z_REFVAL_P(varptr);
4222            ZVAL_COPY_VALUE(arg, varptr);
4223            if (UNEXPECTED(--GC_REFCOUNT(ref) == 0)) {
4224                efree_size(ref, sizeof(zend_reference));
4225            } else if (Z_OPT_REFCOUNTED_P(arg)) {
4226                Z_ADDREF_P(arg);
4227            }
4228        } else {
4229            ZVAL_COPY_VALUE(arg, varptr);
4230        }
4231    }
4232
4233    ZEND_VM_NEXT_OPCODE();
4234}
4235
4236ZEND_VM_HANDLER(106, ZEND_SEND_VAR_NO_REF, VAR, ANY)
4237{
4238    USE_OPLINE
4239    zend_free_op free_op1;
4240    zval *varptr, *arg;
4241
4242    if (!(opline->extended_value & ZEND_ARG_COMPILE_TIME_BOUND)) {
4243        if (!ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4244            ZEND_VM_DISPATCH_TO_HANDLER(ZEND_SEND_VAR);
4245        }
4246    }
4247
4248    varptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
4249
4250    if ((!(opline->extended_value & ZEND_ARG_SEND_FUNCTION) ||
4251         (Z_VAR_FLAGS_P(varptr) & IS_VAR_RET_REF)) &&
4252        (Z_ISREF_P(varptr) || Z_TYPE_P(varptr) == IS_OBJECT)) {
4253
4254        ZVAL_MAKE_REF(varptr);
4255    } else {
4256        if ((opline->extended_value & ZEND_ARG_COMPILE_TIME_BOUND) ?
4257            !(opline->extended_value & ZEND_ARG_SEND_SILENT) :
4258            !ARG_MAY_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4259            SAVE_OPLINE();
4260            zend_error(E_NOTICE, "Only variables should be passed by reference");
4261            arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4262            ZVAL_COPY_VALUE(arg, varptr);
4263            ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4264        }
4265    }
4266
4267    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4268    ZVAL_COPY_VALUE(arg, varptr);
4269
4270    ZEND_VM_NEXT_OPCODE();
4271}
4272
4273ZEND_VM_HANDLER(67, ZEND_SEND_REF, VAR|CV, ANY)
4274{
4275    USE_OPLINE
4276    zend_free_op free_op1;
4277    zval *varptr, *arg;
4278
4279    SAVE_OPLINE();
4280    varptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
4281
4282    if (OP1_TYPE == IS_VAR && UNEXPECTED(varptr == NULL)) {
4283        zend_throw_error(NULL, "Only variables can be passed by reference");
4284        arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4285        ZVAL_UNDEF(arg);
4286        HANDLE_EXCEPTION();
4287    }
4288
4289    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4290    if (OP1_TYPE == IS_VAR && UNEXPECTED(varptr == &EG(error_zval))) {
4291        ZVAL_NEW_REF(arg, &EG(uninitialized_zval));
4292        ZEND_VM_NEXT_OPCODE();
4293    }
4294
4295    if (Z_ISREF_P(varptr)) {
4296        Z_ADDREF_P(varptr);
4297        ZVAL_COPY_VALUE(arg, varptr);
4298    } else {
4299        ZVAL_NEW_REF(arg, varptr);
4300        Z_ADDREF_P(arg);
4301        ZVAL_REF(varptr, Z_REF_P(arg));
4302    }
4303
4304    FREE_OP1_VAR_PTR();
4305    ZEND_VM_NEXT_OPCODE();
4306}
4307
4308ZEND_VM_HANDLER(66, ZEND_SEND_VAR_EX, VAR|CV, ANY)
4309{
4310    USE_OPLINE
4311    zval *varptr, *arg;
4312    zend_free_op free_op1;
4313
4314    if (EXPECTED(opline->op2.num <= MAX_ARG_FLAG_NUM)) {
4315        if (QUICK_ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4316            ZEND_VM_C_GOTO(send_var_by_ref);
4317        }
4318    } else if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4319ZEND_VM_C_LABEL(send_var_by_ref):
4320        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_SEND_REF);
4321    }
4322
4323    varptr = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4324    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(varptr) == IS_UNDEF)) {
4325        SAVE_OPLINE();
4326        GET_OP1_UNDEF_CV(varptr, BP_VAR_R);
4327        arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4328        ZVAL_NULL(arg);
4329        ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4330    }
4331
4332    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4333
4334    if (OP1_TYPE == IS_CV) {
4335        ZVAL_OPT_DEREF(varptr);
4336        ZVAL_COPY(arg, varptr);
4337    } else /* if (OP1_TYPE == IS_VAR) */ {
4338        if (UNEXPECTED(Z_ISREF_P(varptr))) {
4339            zend_refcounted *ref = Z_COUNTED_P(varptr);
4340
4341            varptr = Z_REFVAL_P(varptr);
4342            ZVAL_COPY_VALUE(arg, varptr);
4343            if (UNEXPECTED(--GC_REFCOUNT(ref) == 0)) {
4344                efree_size(ref, sizeof(zend_reference));
4345            } else if (Z_OPT_REFCOUNTED_P(arg)) {
4346                Z_ADDREF_P(arg);
4347            }
4348        } else {
4349            ZVAL_COPY_VALUE(arg, varptr);
4350        }
4351    }
4352
4353    ZEND_VM_NEXT_OPCODE();
4354}
4355
4356ZEND_VM_HANDLER(165, ZEND_SEND_UNPACK, ANY, ANY)
4357{
4358    USE_OPLINE
4359    zend_free_op free_op1;
4360    zval *args;
4361    int arg_num;
4362
4363    SAVE_OPLINE();
4364    args = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4365    arg_num = ZEND_CALL_NUM_ARGS(EX(call)) + 1;
4366
4367ZEND_VM_C_LABEL(send_again):
4368    if (EXPECTED(Z_TYPE_P(args) == IS_ARRAY)) {
4369        HashTable *ht = Z_ARRVAL_P(args);
4370        zval *arg, *top;
4371        zend_string *name;
4372
4373        zend_vm_stack_extend_call_frame(&EX(call), arg_num - 1, zend_hash_num_elements(ht));
4374
4375        if (OP1_TYPE != IS_CONST && OP1_TYPE != IS_TMP_VAR && Z_IMMUTABLE_P(args)) {
4376            uint32_t i;
4377            int separate = 0;
4378
4379            /* check if any of arguments are going to be passed by reference */
4380            for (i = 0; i < zend_hash_num_elements(ht); i++) {
4381                if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num + i)) {
4382                    separate = 1;
4383                    break;
4384                }
4385            }
4386            if (separate) {
4387                zval_copy_ctor(args);
4388                ht = Z_ARRVAL_P(args);
4389            }
4390        }
4391
4392        ZEND_HASH_FOREACH_STR_KEY_VAL(ht, name, arg) {
4393            if (name) {
4394                zend_throw_error(NULL, "Cannot unpack array with string keys");
4395                FREE_OP1();
4396                HANDLE_EXCEPTION();
4397            }
4398
4399            top = ZEND_CALL_ARG(EX(call), arg_num);
4400            if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4401                if (!Z_IMMUTABLE_P(args)) {
4402                    ZVAL_MAKE_REF(arg);
4403                    Z_ADDREF_P(arg);
4404                    ZVAL_REF(top, Z_REF_P(arg));
4405                } else {
4406                    ZVAL_DUP(top, arg);
4407                }
4408            } else if (Z_ISREF_P(arg)) {
4409                ZVAL_COPY(top, Z_REFVAL_P(arg));
4410            } else {
4411                ZVAL_COPY(top, arg);
4412            }
4413
4414            ZEND_CALL_NUM_ARGS(EX(call))++;
4415            arg_num++;
4416        } ZEND_HASH_FOREACH_END();
4417
4418    } else if (EXPECTED(Z_TYPE_P(args) == IS_OBJECT)) {
4419        zend_class_entry *ce = Z_OBJCE_P(args);
4420        zend_object_iterator *iter;
4421
4422        if (!ce || !ce->get_iterator) {
4423            zend_error(E_WARNING, "Only arrays and Traversables can be unpacked");
4424        } else {
4425
4426            iter = ce->get_iterator(ce, args, 0);
4427            if (UNEXPECTED(!iter)) {
4428                FREE_OP1();
4429                if (!EG(exception)) {
4430                    zend_throw_exception_ex(
4431                        NULL, 0, "Object of type %s did not create an Iterator", ZSTR_VAL(ce->name)
4432                    );
4433                }
4434                HANDLE_EXCEPTION();
4435            }
4436
4437            if (iter->funcs->rewind) {
4438                iter->funcs->rewind(iter);
4439                if (UNEXPECTED(EG(exception) != NULL)) {
4440                    ZEND_VM_C_GOTO(unpack_iter_dtor);
4441                }
4442            }
4443
4444            for (; iter->funcs->valid(iter) == SUCCESS; ++arg_num) {
4445                zval *arg, *top;
4446
4447                if (UNEXPECTED(EG(exception) != NULL)) {
4448                    ZEND_VM_C_GOTO(unpack_iter_dtor);
4449                }
4450
4451                arg = iter->funcs->get_current_data(iter);
4452                if (UNEXPECTED(EG(exception) != NULL)) {
4453                    ZEND_VM_C_GOTO(unpack_iter_dtor);
4454                }
4455
4456                if (iter->funcs->get_current_key) {
4457                    zval key;
4458                    iter->funcs->get_current_key(iter, &key);
4459                    if (UNEXPECTED(EG(exception) != NULL)) {
4460                        ZEND_VM_C_GOTO(unpack_iter_dtor);
4461                    }
4462
4463                    if (Z_TYPE(key) == IS_STRING) {
4464                        zend_throw_error(NULL,
4465                            "Cannot unpack Traversable with string keys");
4466                        zend_string_release(Z_STR(key));
4467                        ZEND_VM_C_GOTO(unpack_iter_dtor);
4468                    }
4469
4470                    zval_dtor(&key);
4471                }
4472
4473                if (ARG_MUST_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4474                    zend_error(
4475                        E_WARNING, "Cannot pass by-reference argument %d of %s%s%s()"
4476                        " by unpacking a Traversable, passing by-value instead", arg_num,
4477                        EX(call)->func->common.scope ? ZSTR_VAL(EX(call)->func->common.scope->name) : "",
4478                        EX(call)->func->common.scope ? "::" : "",
4479                        ZSTR_VAL(EX(call)->func->common.function_name)
4480                    );
4481                }
4482
4483                if (Z_ISREF_P(arg)) {
4484                    ZVAL_DUP(arg, Z_REFVAL_P(arg));
4485                } else {
4486                    if (Z_REFCOUNTED_P(arg)) Z_ADDREF_P(arg);
4487                }
4488
4489                zend_vm_stack_extend_call_frame(&EX(call), arg_num - 1, 1);
4490                top = ZEND_CALL_ARG(EX(call), arg_num);
4491                ZVAL_COPY_VALUE(top, arg);
4492                ZEND_CALL_NUM_ARGS(EX(call))++;
4493
4494                iter->funcs->move_forward(iter);
4495                if (UNEXPECTED(EG(exception) != NULL)) {
4496                    ZEND_VM_C_GOTO(unpack_iter_dtor);
4497                }
4498            }
4499
4500ZEND_VM_C_LABEL(unpack_iter_dtor):
4501            zend_iterator_dtor(iter);
4502        }
4503    } else if (EXPECTED(Z_ISREF_P(args))) {
4504        args = Z_REFVAL_P(args);
4505        ZEND_VM_C_GOTO(send_again);
4506    } else {
4507        if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(args) == IS_UNDEF)) {
4508            GET_OP1_UNDEF_CV(args, BP_VAR_R);
4509        }
4510        zend_error(E_WARNING, "Only arrays and Traversables can be unpacked");
4511    }
4512
4513    FREE_OP1();
4514    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4515}
4516
4517ZEND_VM_HANDLER(119, ZEND_SEND_ARRAY, ANY, ANY)
4518{
4519    USE_OPLINE
4520    zend_free_op free_op1;
4521    zval *args;
4522    SAVE_OPLINE();
4523
4524    SAVE_OPLINE();
4525    args = GET_OP1_ZVAL_PTR(BP_VAR_R);
4526
4527    if (UNEXPECTED(Z_TYPE_P(args) != IS_ARRAY)) {
4528        if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(args)) {
4529            args = Z_REFVAL_P(args);
4530            if (EXPECTED(Z_TYPE_P(args) == IS_ARRAY)) {
4531                ZEND_VM_C_GOTO(send_array);
4532            }
4533        }
4534        zend_internal_type_error(EX_USES_STRICT_TYPES(), "call_user_func_array() expects parameter 2 to be array, %s given", zend_get_type_by_const(Z_TYPE_P(args)));
4535        if (ZEND_CALL_INFO(EX(call)) & ZEND_CALL_CLOSURE) {
4536            OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
4537        }
4538        if (Z_OBJ(EX(call)->This)) {
4539            OBJ_RELEASE(Z_OBJ(EX(call)->This));
4540        }
4541        EX(call)->func = (zend_function*)&zend_pass_function;
4542        EX(call)->called_scope = NULL;
4543        Z_OBJ(EX(call)->This) = NULL;
4544    } else {
4545        uint32_t arg_num;
4546        HashTable *ht;
4547        zval *arg, *param;
4548
4549ZEND_VM_C_LABEL(send_array):
4550        ht = Z_ARRVAL_P(args);
4551        zend_vm_stack_extend_call_frame(&EX(call), 0, zend_hash_num_elements(ht));
4552
4553        if (OP1_TYPE != IS_CONST && OP1_TYPE != IS_TMP_VAR && Z_IMMUTABLE_P(args)) {
4554            int separate = 0;
4555
4556            /* check if any of arguments are going to be passed by reference */
4557            for (arg_num = 0; arg_num < zend_hash_num_elements(ht); arg_num++) {
4558                if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num + 1)) {
4559                    separate = 1;
4560                    break;
4561                }
4562            }
4563            if (separate) {
4564                zval_copy_ctor(args);
4565                ht = Z_ARRVAL_P(args);
4566            }
4567        }
4568
4569        arg_num = 1;
4570        param = ZEND_CALL_ARG(EX(call), 1);
4571        ZEND_HASH_FOREACH_VAL(ht, arg) {
4572            if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4573                if (UNEXPECTED(!Z_ISREF_P(arg))) {
4574                    if (!ARG_MAY_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4575
4576                        zend_error(E_WARNING, "Parameter %d to %s%s%s() expected to be a reference, value given",
4577                            arg_num,
4578                            EX(call)->func->common.scope ? ZSTR_VAL(EX(call)->func->common.scope->name) : "",
4579                            EX(call)->func->common.scope ? "::" : "",
4580                            ZSTR_VAL(EX(call)->func->common.function_name));
4581
4582                        if (ZEND_CALL_INFO(EX(call)) & ZEND_CALL_CLOSURE) {
4583                            OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
4584                        }
4585                        if (Z_OBJ(EX(call)->This)) {
4586                            OBJ_RELEASE(Z_OBJ(EX(call)->This));
4587                        }
4588                        EX(call)->func = (zend_function*)&zend_pass_function;
4589                        EX(call)->called_scope = NULL;
4590                        Z_OBJ(EX(call)->This) = NULL;
4591
4592                        break;
4593                    }
4594
4595                    ZVAL_NEW_REF(arg, arg);
4596                }
4597                Z_ADDREF_P(arg);
4598            } else{
4599                if (Z_ISREF_P(arg) &&
4600                    !(EX(call)->func->common.fn_flags & ZEND_ACC_CALL_VIA_TRAMPOLINE)) {
4601                    /* don't separate references for __call */
4602                    arg = Z_REFVAL_P(arg);
4603                }
4604                if (Z_OPT_REFCOUNTED_P(arg)) {
4605                    Z_ADDREF_P(arg);
4606                }
4607            }
4608            ZVAL_COPY_VALUE(param, arg);
4609            ZEND_CALL_NUM_ARGS(EX(call))++;
4610            arg_num++;
4611            param++;
4612        } ZEND_HASH_FOREACH_END();
4613    }
4614    FREE_OP1();
4615    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4616}
4617
4618ZEND_VM_HANDLER(120, ZEND_SEND_USER, VAR|CV, ANY)
4619{
4620    USE_OPLINE
4621    zval *arg, *param;
4622    zend_free_op free_op1;
4623
4624    SAVE_OPLINE();
4625    arg = GET_OP1_ZVAL_PTR(BP_VAR_R);
4626    param = ZEND_CALL_VAR(EX(call), opline->result.var);
4627
4628    if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4629        if (UNEXPECTED(!Z_ISREF_P(arg))) {
4630
4631            if (!ARG_MAY_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4632
4633                zend_error(E_WARNING, "Parameter %d to %s%s%s() expected to be a reference, value given",
4634                    opline->op2.num,
4635                    EX(call)->func->common.scope ? ZSTR_VAL(EX(call)->func->common.scope->name) : "",
4636                    EX(call)->func->common.scope ? "::" : "",
4637                    ZSTR_VAL(EX(call)->func->common.function_name));
4638
4639                if (ZEND_CALL_INFO(EX(call)) & ZEND_CALL_CLOSURE) {
4640                    OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
4641                }
4642                if (Z_OBJ(EX(call)->This)) {
4643                    OBJ_RELEASE(Z_OBJ(EX(call)->This));
4644                }
4645                ZVAL_UNDEF(param);
4646                EX(call)->func = (zend_function*)&zend_pass_function;
4647                EX(call)->called_scope = NULL;
4648                Z_OBJ(EX(call)->This) = NULL;
4649
4650                FREE_OP1();
4651                ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4652            }
4653
4654            ZVAL_NEW_REF(arg, arg);
4655        }
4656        Z_ADDREF_P(arg);
4657    } else {
4658        if (Z_ISREF_P(arg) &&
4659            !(EX(call)->func->common.fn_flags & ZEND_ACC_CALL_VIA_TRAMPOLINE)) {
4660            /* don't separate references for __call */
4661            arg = Z_REFVAL_P(arg);
4662        }
4663        if (Z_OPT_REFCOUNTED_P(arg)) {
4664            Z_ADDREF_P(arg);
4665        }
4666    }
4667    ZVAL_COPY_VALUE(param, arg);
4668
4669    FREE_OP1();
4670    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4671}
4672
4673ZEND_VM_HANDLER(63, ZEND_RECV, ANY, ANY)
4674{
4675    USE_OPLINE
4676    uint32_t arg_num = opline->op1.num;
4677
4678    if (UNEXPECTED(arg_num > EX_NUM_ARGS())) {
4679        SAVE_OPLINE();
4680        if (UNEXPECTED(!zend_verify_missing_arg(execute_data, arg_num, CACHE_ADDR(opline->op2.num)))) {
4681            HANDLE_EXCEPTION();
4682        }
4683    } else if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
4684        zval *param = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var);
4685
4686        SAVE_OPLINE();
4687        if (UNEXPECTED(!zend_verify_arg_type(EX(func), arg_num, param, NULL, CACHE_ADDR(opline->op2.num)))) {
4688            HANDLE_EXCEPTION();
4689        }
4690    }
4691
4692    ZEND_VM_NEXT_OPCODE();
4693}
4694
4695ZEND_VM_HANDLER(64, ZEND_RECV_INIT, ANY, CONST)
4696{
4697    USE_OPLINE
4698    uint32_t arg_num;
4699    zval *param;
4700
4701    ZEND_VM_REPEATABLE_OPCODE
4702
4703    arg_num = opline->op1.num;
4704    param = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var);
4705    if (arg_num > EX_NUM_ARGS()) {
4706        ZVAL_COPY_VALUE(param, EX_CONSTANT(opline->op2));
4707        if (Z_OPT_CONSTANT_P(param)) {
4708            SAVE_OPLINE();
4709            if (UNEXPECTED(zval_update_constant_ex(param, 0, NULL) != SUCCESS)) {
4710                ZVAL_UNDEF(param);
4711                HANDLE_EXCEPTION();
4712            }
4713        } else {
4714            /* IS_CONST can't be IS_OBJECT, IS_RESOURCE or IS_REFERENCE */
4715            if (UNEXPECTED(Z_OPT_COPYABLE_P(param))) {
4716                zval_copy_ctor_func(param);
4717            }
4718        }
4719    }
4720
4721    if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
4722        zval *default_value = EX_CONSTANT(opline->op2);
4723
4724        SAVE_OPLINE();
4725        if (UNEXPECTED(!zend_verify_arg_type(EX(func), arg_num, param, default_value, CACHE_ADDR(Z_CACHE_SLOT_P(default_value))))) {
4726            HANDLE_EXCEPTION();
4727        }
4728    }
4729
4730    ZEND_VM_REPEAT_OPCODE(ZEND_RECV_INIT);
4731    ZEND_VM_NEXT_OPCODE();
4732}
4733
4734ZEND_VM_HANDLER(164, ZEND_RECV_VARIADIC, ANY, ANY)
4735{
4736    USE_OPLINE
4737    uint32_t arg_num = opline->op1.num;
4738    uint32_t arg_count = EX_NUM_ARGS();
4739    zval *params;
4740
4741    SAVE_OPLINE();
4742
4743    params = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var);
4744
4745    if (arg_num <= arg_count) {
4746        zval *param;
4747
4748        array_init_size(params, arg_count - arg_num + 1);
4749        zend_hash_real_init(Z_ARRVAL_P(params), 1);
4750        ZEND_HASH_FILL_PACKED(Z_ARRVAL_P(params)) {
4751            param = EX_VAR_NUM(EX(func)->op_array.last_var + EX(func)->op_array.T);
4752            if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
4753                do {
4754                    zend_verify_arg_type(EX(func), arg_num, param, NULL, CACHE_ADDR(opline->op2.num));
4755                    if (Z_OPT_REFCOUNTED_P(param)) Z_ADDREF_P(param);
4756                    ZEND_HASH_FILL_ADD(param);
4757                    param++;
4758                } while (++arg_num <= arg_count);
4759            } else {
4760                do {
4761                    if (Z_OPT_REFCOUNTED_P(param)) Z_ADDREF_P(param);
4762                    ZEND_HASH_FILL_ADD(param);
4763                    param++;
4764                } while (++arg_num <= arg_count);
4765            }
4766        } ZEND_HASH_FILL_END();
4767    } else {
4768        array_init(params);
4769    }
4770
4771    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4772}
4773
4774ZEND_VM_HANDLER(52, ZEND_BOOL, CONST|TMPVAR|CV, ANY)
4775{
4776    USE_OPLINE
4777    zval *val;
4778    zend_free_op free_op1;
4779
4780    val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4781    if (Z_TYPE_INFO_P(val) == IS_TRUE) {
4782        ZVAL_TRUE(EX_VAR(opline->result.var));
4783    } else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
4784        ZVAL_FALSE(EX_VAR(opline->result.var));
4785        if (UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
4786            SAVE_OPLINE();
4787            GET_OP1_UNDEF_CV(val, BP_VAR_R);
4788            ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4789        }
4790    } else {
4791        SAVE_OPLINE();
4792        ZVAL_BOOL(EX_VAR(opline->result.var), i_zend_is_true(val));
4793        FREE_OP1();
4794        ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4795    }
4796    ZEND_VM_NEXT_OPCODE();
4797}
4798
4799ZEND_VM_HANDLER(48, ZEND_CASE, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
4800{
4801    USE_OPLINE
4802    zend_free_op free_op1, free_op2;
4803    zval *op1, *op2, *result;
4804
4805    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4806    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
4807    do {
4808        int result;
4809
4810        if (EXPECTED(Z_TYPE_P(op1) == IS_LONG)) {
4811            if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
4812                result = (Z_LVAL_P(op1) == Z_LVAL_P(op2));
4813            } else if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
4814                result = ((double)Z_LVAL_P(op1) == Z_DVAL_P(op2));
4815            } else {
4816                break;
4817            }
4818        } else if (EXPECTED(Z_TYPE_P(op1) == IS_DOUBLE)) {
4819            if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
4820                result = (Z_DVAL_P(op1) == Z_DVAL_P(op2));
4821            } else if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
4822                result = (Z_DVAL_P(op1) == ((double)Z_LVAL_P(op2)));
4823            } else {
4824                break;
4825            }
4826        } else if (EXPECTED(Z_TYPE_P(op1) == IS_STRING)) {
4827            if (EXPECTED(Z_TYPE_P(op2) == IS_STRING)) {
4828                if (Z_STR_P(op1) == Z_STR_P(op2)) {
4829                    result = 1;
4830                } else if (Z_STRVAL_P(op1)[0] > '9' || Z_STRVAL_P(op2)[0] > '9') {
4831                    if (Z_STRLEN_P(op1) != Z_STRLEN_P(op2)) {
4832                        result = 0;
4833                    } else {
4834                        result = (memcmp(Z_STRVAL_P(op1), Z_STRVAL_P(op2), Z_STRLEN_P(op1)) == 0);
4835                    }
4836                } else {
4837                    result = (zendi_smart_strcmp(op1, op2) == 0);
4838                }
4839                FREE_OP2();
4840            } else {
4841                break;
4842            }
4843        } else {
4844            break;
4845        }
4846        ZEND_VM_SMART_BRANCH(result, 0);
4847        ZVAL_BOOL(EX_VAR(opline->result.var), result);
4848        ZEND_VM_NEXT_OPCODE();
4849    } while (0);
4850
4851    SAVE_OPLINE();
4852    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op1) == IS_UNDEF)) {
4853        op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
4854    }
4855    if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op2) == IS_UNDEF)) {
4856        op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
4857    }
4858    result = EX_VAR(opline->result.var);
4859    compare_function(result, op1, op2);
4860    ZVAL_BOOL(result, Z_LVAL_P(result) == 0);
4861    FREE_OP2();
4862    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4863}
4864
4865ZEND_VM_HANDLER(68, ZEND_NEW, CONST|VAR, ANY)
4866{
4867    USE_OPLINE
4868    zval object_zval;
4869    zend_function *constructor;
4870    zend_class_entry *ce;
4871
4872    SAVE_OPLINE();
4873    if (OP1_TYPE == IS_CONST) {
4874        ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
4875        if (UNEXPECTED(ce == NULL)) {
4876            ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
4877            if (UNEXPECTED(ce == NULL)) {
4878                ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4879            }
4880            CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce);
4881        }
4882    } else {
4883        ce = Z_CE_P(EX_VAR(opline->op1.var));
4884    }
4885    if (UNEXPECTED(object_init_ex(&object_zval, ce) != SUCCESS)) {
4886        HANDLE_EXCEPTION();
4887    }
4888    constructor = Z_OBJ_HT(object_zval)->get_constructor(Z_OBJ(object_zval));
4889
4890    if (constructor == NULL) {
4891        if (EXPECTED(RETURN_VALUE_USED(opline))) {
4892            ZVAL_COPY_VALUE(EX_VAR(opline->result.var), &object_zval);
4893        } else {
4894            OBJ_RELEASE(Z_OBJ(object_zval));
4895        }
4896        ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
4897    } else {
4898        /* We are not handling overloaded classes right now */
4899        zend_execute_data *call = zend_vm_stack_push_call_frame(
4900                ZEND_CALL_FUNCTION | ZEND_CALL_RELEASE_THIS | ZEND_CALL_CTOR |
4901                (EXPECTED(RETURN_VALUE_USED(opline)) ? 0 : ZEND_CALL_CTOR_RESULT_UNUSED),
4902            constructor,
4903            opline->extended_value,
4904            ce,
4905            Z_OBJ(object_zval));
4906        call->prev_execute_data = EX(call);
4907        EX(call) = call;
4908
4909        if (EXPECTED(RETURN_VALUE_USED(opline))) {
4910            ZVAL_COPY(EX_VAR(opline->result.var), &object_zval);
4911        }
4912
4913        ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4914    }
4915}
4916
4917ZEND_VM_HANDLER(110, ZEND_CLONE, CONST|TMPVAR|UNUSED|CV, ANY)
4918{
4919    USE_OPLINE
4920    zend_free_op free_op1;
4921    zval *obj;
4922    zend_class_entry *ce;
4923    zend_function *clone;
4924    zend_object_clone_obj_t clone_call;
4925
4926    SAVE_OPLINE();
4927    obj = GET_OP1_OBJ_ZVAL_PTR_UNDEF(BP_VAR_R);
4928
4929    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(obj) == NULL)) {
4930        zend_throw_error(NULL, "Using $this when not in object context");
4931        HANDLE_EXCEPTION();
4932    }
4933
4934    do {
4935        if (OP1_TYPE == IS_CONST ||
4936            (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(obj) != IS_OBJECT))) {
4937            if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(obj)) {
4938                obj = Z_REFVAL_P(obj);
4939                if (EXPECTED(Z_TYPE_P(obj) == IS_OBJECT)) {
4940                    break;
4941                }
4942            }
4943            if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(obj) == IS_UNDEF)) {
4944                GET_OP1_UNDEF_CV(obj, BP_VAR_R);
4945            }
4946            if (UNEXPECTED(EG(exception) != NULL)) {
4947                HANDLE_EXCEPTION();
4948            }
4949            zend_throw_error(NULL, "__clone method called on non-object");
4950            FREE_OP1();
4951            HANDLE_EXCEPTION();
4952        }
4953    } while (0);
4954
4955    ce = Z_OBJCE_P(obj);
4956    clone = ce ? ce->clone : NULL;
4957    clone_call =  Z_OBJ_HT_P(obj)->clone_obj;
4958    if (UNEXPECTED(clone_call == NULL)) {
4959        if (ce) {
4960            zend_throw_error(NULL, "Trying to clone an uncloneable object of class %s", ZSTR_VAL(ce->name));
4961        } else {
4962            zend_throw_error(NULL, "Trying to clone an uncloneable object");
4963        }
4964        FREE_OP1();
4965        HANDLE_EXCEPTION();
4966    }
4967
4968    if (ce && clone) {
4969        if (clone->op_array.fn_flags & ZEND_ACC_PRIVATE) {
4970            /* Ensure that if we're calling a private function, we're allowed to do so.
4971             */
4972            if (UNEXPECTED(ce != EG(scope))) {
4973                zend_throw_error(NULL, "Call to private %s::__clone() from context '%s'", ZSTR_VAL(ce->name), EG(scope) ? ZSTR_VAL(EG(scope)->name) : "");
4974                FREE_OP1();
4975                HANDLE_EXCEPTION();
4976            }
4977        } else if ((clone->common.fn_flags & ZEND_ACC_PROTECTED)) {
4978            /* Ensure that if we're calling a protected function, we're allowed to do so.
4979             */
4980            if (UNEXPECTED(!zend_check_protected(zend_get_function_root_class(clone), EG(scope)))) {
4981                zend_throw_error(NULL, "Call to protected %s::__clone() from context '%s'", ZSTR_VAL(ce->name), EG(scope) ? ZSTR_VAL(EG(scope)->name) : "");
4982                FREE_OP1();
4983                HANDLE_EXCEPTION();
4984            }
4985        }
4986    }
4987
4988    if (EXPECTED(EG(exception) == NULL)) {
4989        ZVAL_OBJ(EX_VAR(opline->result.var), clone_call(obj));
4990        if (UNEXPECTED(!RETURN_VALUE_USED(opline)) || UNEXPECTED(EG(exception) != NULL)) {
4991            OBJ_RELEASE(Z_OBJ_P(EX_VAR(opline->result.var)));
4992        }
4993    }
4994    FREE_OP1();
4995    ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4996}
4997
4998ZEND_VM_HANDLER(99, ZEND_FETCH_CONSTANT, VAR|CONST|UNUSED, CONST)
4999{
5000    USE_OPLINE
5001
5002    SAVE_OPLINE();
5003    if (OP1_TYPE == IS_UNUSED) {
5004        zend_constant *c;
5005
5006        if (EXPECTED(CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2))))) {
5007            c = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
5008        } else if ((c = zend_quick_get_constant(EX_CONSTANT(opline->op2) + 1, opline->extended_value)) == NULL) {
5009            if ((opline->extended_value & IS_CONSTANT_UNQUALIFIED) != 0) {
5010                char *actual = (char *)zend_memrchr(Z_STRVAL_P(EX_CONSTANT(opline->op2)), '\\', Z_STRLEN_P(EX_CONSTANT(opline->op2)));
5011                if (!actual) {
5012                    ZVAL_STR_COPY(EX_VAR(opline->result.var), Z_STR_P(EX_CONSTANT(opline->op2)));
5013                } else {
5014                    actual++;
5015                    ZVAL_STRINGL(EX_VAR(opline->result.var),
5016                            actual, Z_STRLEN_P(EX_CONSTANT(opline->op2)) - (actual - Z_STRVAL_P(EX_CONSTANT(opline->op2))));
5017                }
5018                /* non-qualified constant - allow text substitution */
5019                zend_error(E_NOTICE, "Use of undefined constant %s - assumed '%s'",
5020                        Z_STRVAL_P(EX_VAR(opline->result.var)), Z_STRVAL_P(EX_VAR(opline->result.var)));
5021                ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5022            } else {
5023                zend_throw_error(NULL, "Undefined constant '%s'", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
5024                HANDLE_EXCEPTION();
5025            }
5026        } else {
5027            CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), c);
5028        }
5029#ifdef ZTS
5030        if (c->flags & CONST_PERSISTENT) {
5031            ZVAL_DUP(EX_VAR(opline->result.var), &c->value);
5032        } else {
5033            ZVAL_COPY(EX_VAR(opline->result.var), &c->value);
5034        }
5035#else
5036        ZVAL_COPY(EX_VAR(opline->result.var), &c->value);
5037#endif
5038    } else {
5039        /* class constant */
5040        zend_class_entry *ce;
5041        zval *value;
5042
5043        do {
5044            if (OP1_TYPE == IS_CONST) {
5045                if (EXPECTED(CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2))))) {
5046                    value = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
5047                    ZVAL_DEREF(value);
5048#ifdef ZTS
5049                    ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
5050#endif
5051                    break;
5052                } else if (EXPECTED(CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1))))) {
5053                    ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
5054                } else {
5055                    ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
5056                    if (UNEXPECTED(EG(exception) != NULL)) {
5057                        HANDLE_EXCEPTION();
5058                    }
5059                    if (UNEXPECTED(ce == NULL)) {
5060                        zend_throw_error(NULL, "Class '%s' not found", Z_STRVAL_P(EX_CONSTANT(opline->op1)));
5061                        HANDLE_EXCEPTION();
5062                    }
5063                    CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce);
5064                }
5065            } else {
5066                ce = Z_CE_P(EX_VAR(opline->op1.var));
5067                if ((value = CACHED_POLYMORPHIC_PTR(