1/*
2   +----------------------------------------------------------------------+
3   | Zend Engine                                                          |
4   +----------------------------------------------------------------------+
5   | Copyright (c) 1998-2014 Zend Technologies Ltd. (http://www.zend.com) |
6   +----------------------------------------------------------------------+
7   | This source file is subject to version 2.00 of the Zend license,     |
8   | that is bundled with this package in the file LICENSE, and is        |
9   | available through the world-wide-web at the following url:           |
10   | http://www.zend.com/license/2_00.txt.                                |
11   | If you did not receive a copy of the Zend license and are unable to  |
12   | obtain it through the world-wide-web, please send a note to          |
13   | license@zend.com so we can mail you a copy immediately.              |
14   +----------------------------------------------------------------------+
15   | Authors: Andi Gutmans <andi@zend.com>                                |
16   |          Zeev Suraski <zeev@zend.com>                                |
17   |          Dmitry Stogov <dmitry@zend.com>                             |
18   +----------------------------------------------------------------------+
19*/
20
21/* $Id$ */
22
23/* If you change this file, please regenerate the zend_vm_execute.h and
24 * zend_vm_opcodes.h files by running:
25 * php zend_vm_gen.php
26 */
27
28ZEND_VM_HANDLER(1, ZEND_ADD, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
29{
30    USE_OPLINE
31    zend_free_op free_op1, free_op2;
32
33    SAVE_OPLINE();
34    fast_add_function(EX_VAR(opline->result.var),
35        GET_OP1_ZVAL_PTR(BP_VAR_R),
36        GET_OP2_ZVAL_PTR(BP_VAR_R) TSRMLS_CC);
37    FREE_OP1();
38    FREE_OP2();
39    CHECK_EXCEPTION();
40    ZEND_VM_NEXT_OPCODE();
41}
42
43ZEND_VM_HANDLER(2, ZEND_SUB, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
44{
45    USE_OPLINE
46    zend_free_op free_op1, free_op2;
47
48    SAVE_OPLINE();
49    fast_sub_function(EX_VAR(opline->result.var),
50        GET_OP1_ZVAL_PTR(BP_VAR_R),
51        GET_OP2_ZVAL_PTR(BP_VAR_R) TSRMLS_CC);
52    FREE_OP1();
53    FREE_OP2();
54    CHECK_EXCEPTION();
55    ZEND_VM_NEXT_OPCODE();
56}
57
58ZEND_VM_HANDLER(3, ZEND_MUL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
59{
60    USE_OPLINE
61    zend_free_op free_op1, free_op2;
62
63    SAVE_OPLINE();
64    fast_mul_function(EX_VAR(opline->result.var),
65        GET_OP1_ZVAL_PTR(BP_VAR_R),
66        GET_OP2_ZVAL_PTR(BP_VAR_R) TSRMLS_CC);
67    FREE_OP1();
68    FREE_OP2();
69    CHECK_EXCEPTION();
70    ZEND_VM_NEXT_OPCODE();
71}
72
73ZEND_VM_HANDLER(4, ZEND_DIV, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
74{
75    USE_OPLINE
76    zend_free_op free_op1, free_op2;
77
78    SAVE_OPLINE();
79    fast_div_function(EX_VAR(opline->result.var),
80        GET_OP1_ZVAL_PTR(BP_VAR_R),
81        GET_OP2_ZVAL_PTR(BP_VAR_R) TSRMLS_CC);
82    FREE_OP1();
83    FREE_OP2();
84    CHECK_EXCEPTION();
85    ZEND_VM_NEXT_OPCODE();
86}
87
88ZEND_VM_HANDLER(5, ZEND_MOD, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
89{
90    USE_OPLINE
91    zend_free_op free_op1, free_op2;
92
93    SAVE_OPLINE();
94    fast_mod_function(EX_VAR(opline->result.var),
95        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
96        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
97    FREE_OP1();
98    FREE_OP2();
99    CHECK_EXCEPTION();
100    ZEND_VM_NEXT_OPCODE();
101}
102
103ZEND_VM_HANDLER(6, ZEND_SL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
104{
105    USE_OPLINE
106    zend_free_op free_op1, free_op2;
107
108    SAVE_OPLINE();
109    shift_left_function(EX_VAR(opline->result.var),
110        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
111        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
112    FREE_OP1();
113    FREE_OP2();
114    CHECK_EXCEPTION();
115    ZEND_VM_NEXT_OPCODE();
116}
117
118ZEND_VM_HANDLER(7, ZEND_SR, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
119{
120    USE_OPLINE
121    zend_free_op free_op1, free_op2;
122
123    SAVE_OPLINE();
124    shift_right_function(EX_VAR(opline->result.var),
125        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
126        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
127    FREE_OP1();
128    FREE_OP2();
129    CHECK_EXCEPTION();
130    ZEND_VM_NEXT_OPCODE();
131}
132
133ZEND_VM_HANDLER(8, ZEND_CONCAT, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
134{
135    USE_OPLINE
136    zend_free_op free_op1, free_op2;
137
138    SAVE_OPLINE();
139    concat_function(EX_VAR(opline->result.var),
140        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
141        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
142    FREE_OP1();
143    FREE_OP2();
144    CHECK_EXCEPTION();
145    ZEND_VM_NEXT_OPCODE();
146}
147
148ZEND_VM_HANDLER(15, ZEND_IS_IDENTICAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
149{
150    USE_OPLINE
151    zend_free_op free_op1, free_op2;
152
153    SAVE_OPLINE();
154    fast_is_identical_function(EX_VAR(opline->result.var),
155        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
156        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
157    FREE_OP1();
158    FREE_OP2();
159    CHECK_EXCEPTION();
160    ZEND_VM_NEXT_OPCODE();
161}
162
163ZEND_VM_HANDLER(16, ZEND_IS_NOT_IDENTICAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
164{
165    USE_OPLINE
166    zend_free_op free_op1, free_op2;
167    zval *result = EX_VAR(opline->result.var);
168
169    SAVE_OPLINE();
170    fast_is_not_identical_function(result,
171        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
172        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
173    FREE_OP1();
174    FREE_OP2();
175    CHECK_EXCEPTION();
176    ZEND_VM_NEXT_OPCODE();
177}
178
179ZEND_VM_HANDLER(17, ZEND_IS_EQUAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
180{
181    USE_OPLINE
182    zend_free_op free_op1, free_op2;
183    zval *result = EX_VAR(opline->result.var);
184
185    SAVE_OPLINE();
186    fast_equal_function(result,
187        GET_OP1_ZVAL_PTR(BP_VAR_R),
188        GET_OP2_ZVAL_PTR(BP_VAR_R) TSRMLS_CC);
189    FREE_OP1();
190    FREE_OP2();
191    CHECK_EXCEPTION();
192    ZEND_VM_NEXT_OPCODE();
193}
194
195ZEND_VM_HANDLER(18, ZEND_IS_NOT_EQUAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
196{
197    USE_OPLINE
198    zend_free_op free_op1, free_op2;
199    zval *result = EX_VAR(opline->result.var);
200
201    SAVE_OPLINE();
202    fast_not_equal_function(result,
203        GET_OP1_ZVAL_PTR(BP_VAR_R),
204        GET_OP2_ZVAL_PTR(BP_VAR_R) TSRMLS_CC);
205    FREE_OP1();
206    FREE_OP2();
207    CHECK_EXCEPTION();
208    ZEND_VM_NEXT_OPCODE();
209}
210
211ZEND_VM_HANDLER(19, ZEND_IS_SMALLER, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
212{
213    USE_OPLINE
214    zend_free_op free_op1, free_op2;
215    zval *result = EX_VAR(opline->result.var);
216
217    SAVE_OPLINE();
218    fast_is_smaller_function(result,
219        GET_OP1_ZVAL_PTR(BP_VAR_R),
220        GET_OP2_ZVAL_PTR(BP_VAR_R) TSRMLS_CC);
221    FREE_OP1();
222    FREE_OP2();
223    CHECK_EXCEPTION();
224    ZEND_VM_NEXT_OPCODE();
225}
226
227ZEND_VM_HANDLER(20, ZEND_IS_SMALLER_OR_EQUAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
228{
229    USE_OPLINE
230    zend_free_op free_op1, free_op2;
231    zval *result = EX_VAR(opline->result.var);
232
233    SAVE_OPLINE();
234    fast_is_smaller_or_equal_function(result,
235        GET_OP1_ZVAL_PTR(BP_VAR_R),
236        GET_OP2_ZVAL_PTR(BP_VAR_R) TSRMLS_CC);
237    FREE_OP1();
238    FREE_OP2();
239    CHECK_EXCEPTION();
240    ZEND_VM_NEXT_OPCODE();
241}
242
243ZEND_VM_HANDLER(9, ZEND_BW_OR, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
244{
245    USE_OPLINE
246    zend_free_op free_op1, free_op2;
247
248    SAVE_OPLINE();
249    bitwise_or_function(EX_VAR(opline->result.var),
250        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
251        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
252    FREE_OP1();
253    FREE_OP2();
254    CHECK_EXCEPTION();
255    ZEND_VM_NEXT_OPCODE();
256}
257
258ZEND_VM_HANDLER(10, ZEND_BW_AND, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
259{
260    USE_OPLINE
261    zend_free_op free_op1, free_op2;
262
263    SAVE_OPLINE();
264    bitwise_and_function(EX_VAR(opline->result.var),
265        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
266        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
267    FREE_OP1();
268    FREE_OP2();
269    CHECK_EXCEPTION();
270    ZEND_VM_NEXT_OPCODE();
271}
272
273ZEND_VM_HANDLER(11, ZEND_BW_XOR, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
274{
275    USE_OPLINE
276    zend_free_op free_op1, free_op2;
277
278    SAVE_OPLINE();
279    bitwise_xor_function(EX_VAR(opline->result.var),
280        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
281        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
282    FREE_OP1();
283    FREE_OP2();
284    CHECK_EXCEPTION();
285    ZEND_VM_NEXT_OPCODE();
286}
287
288ZEND_VM_HANDLER(14, ZEND_BOOL_XOR, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
289{
290    USE_OPLINE
291    zend_free_op free_op1, free_op2;
292
293    SAVE_OPLINE();
294    boolean_xor_function(EX_VAR(opline->result.var),
295        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
296        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
297    FREE_OP1();
298    FREE_OP2();
299    CHECK_EXCEPTION();
300    ZEND_VM_NEXT_OPCODE();
301}
302
303ZEND_VM_HANDLER(12, ZEND_BW_NOT, CONST|TMP|VAR|CV, ANY)
304{
305    USE_OPLINE
306    zend_free_op free_op1;
307
308    SAVE_OPLINE();
309    bitwise_not_function(EX_VAR(opline->result.var),
310        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
311    FREE_OP1();
312    CHECK_EXCEPTION();
313    ZEND_VM_NEXT_OPCODE();
314}
315
316ZEND_VM_HANDLER(13, ZEND_BOOL_NOT, CONST|TMP|VAR|CV, ANY)
317{
318    USE_OPLINE
319    zend_free_op free_op1;
320
321    SAVE_OPLINE();
322    boolean_not_function(EX_VAR(opline->result.var),
323        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R) TSRMLS_CC);
324    FREE_OP1();
325    CHECK_EXCEPTION();
326    ZEND_VM_NEXT_OPCODE();
327}
328
329ZEND_VM_HELPER_EX(zend_binary_assign_op_obj_helper, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV, int (*binary_op)(zval *result, zval *op1, zval *op2 TSRMLS_DC))
330{
331    USE_OPLINE
332    zend_free_op free_op1, free_op2, free_op_data1;
333    zval *object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
334    zval *property = GET_OP2_ZVAL_PTR(BP_VAR_R);
335    zval *value;
336    zval *zptr;
337
338    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
339        zend_error_noreturn(E_ERROR, "Cannot use string offset as an object");
340    }
341
342    if (OP1_TYPE != IS_UNUSED) {
343        object = make_real_object(object TSRMLS_CC);
344    }
345
346    value = get_zval_ptr_deref((opline+1)->op1_type, &(opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
347
348    if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
349        zend_error(E_WARNING, "Attempt to assign property of non-object");
350        FREE_OP2();
351        FREE_OP(free_op_data1);
352
353        if (RETURN_VALUE_USED(opline)) {
354            ZVAL_NULL(EX_VAR(opline->result.var));
355        }
356    } else {
357        /* here we are sure we are dealing with an object */
358        if (opline->extended_value == ZEND_ASSIGN_OBJ
359            && EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
360            && EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL) TSRMLS_CC)) != NULL)) {
361
362            ZVAL_DEREF(zptr);
363            SEPARATE_ZVAL_NOREF(zptr);
364
365            binary_op(zptr, zptr, value TSRMLS_CC);
366            if (RETURN_VALUE_USED(opline)) {
367                ZVAL_COPY(EX_VAR(opline->result.var), zptr);
368            }
369        } else {
370            zval *z = NULL;
371            zval rv;
372
373            if (opline->extended_value == ZEND_ASSIGN_OBJ) {
374                if (Z_OBJ_HT_P(object)->read_property) {
375                    z = Z_OBJ_HT_P(object)->read_property(object, property, BP_VAR_R, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL), &rv TSRMLS_CC);
376                }
377            } else /* if (opline->extended_value == ZEND_ASSIGN_DIM) */ {
378                if (Z_OBJ_HT_P(object)->read_dimension) {
379                    z = Z_OBJ_HT_P(object)->read_dimension(object, property, BP_VAR_R, &rv TSRMLS_CC);
380                }
381            }
382            if (z) {
383                if (Z_TYPE_P(z) == IS_OBJECT && Z_OBJ_HT_P(z)->get) {
384                    zval rv;
385                    zval *value = Z_OBJ_HT_P(z)->get(z, &rv TSRMLS_CC);
386
387                    if (Z_REFCOUNT_P(z) == 0) {
388                        zend_objects_store_del(Z_OBJ_P(z) TSRMLS_CC);
389                    }
390                    ZVAL_COPY_VALUE(z, value);
391                }
392//???               if (Z_REFCOUNTED_P(z)) Z_ADDREF_P(z);
393                SEPARATE_ZVAL_IF_NOT_REF(z);
394                binary_op(z, z, value TSRMLS_CC);
395                if (opline->extended_value == ZEND_ASSIGN_OBJ) {
396                    Z_OBJ_HT_P(object)->write_property(object, property, z, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL) TSRMLS_CC);
397                } else /* if (opline->extended_value == ZEND_ASSIGN_DIM) */ {
398                    Z_OBJ_HT_P(object)->write_dimension(object, property, z TSRMLS_CC);
399                }
400                if (RETURN_VALUE_USED(opline)) {
401                    ZVAL_COPY(EX_VAR(opline->result.var), z);
402                }
403                zval_ptr_dtor(z);
404            } else {
405                zend_error(E_WARNING, "Attempt to assign property of non-object");
406                if (RETURN_VALUE_USED(opline)) {
407                    ZVAL_NULL(EX_VAR(opline->result.var));
408                }
409            }
410        }
411
412        FREE_OP2();
413        FREE_OP(free_op_data1);
414    }
415
416    FREE_OP1_VAR_PTR();
417    /* assign_obj has two opcodes! */
418    CHECK_EXCEPTION();
419    ZEND_VM_INC_OPCODE();
420    ZEND_VM_NEXT_OPCODE();
421}
422
423ZEND_VM_HELPER_EX(zend_binary_assign_op_dim_helper, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV, int (*binary_op)(zval *result, zval *op1, zval *op2 TSRMLS_DC))
424{
425    USE_OPLINE
426    zend_free_op free_op1, free_op2, free_op_data1;
427    zval *var_ptr, rv;
428    zval *value, *container;
429
430    SAVE_OPLINE();
431    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
432    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
433        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
434    }
435    if (OP1_TYPE != IS_UNUSED) {
436        ZVAL_DEREF(container);
437    }
438    if (OP1_TYPE == IS_UNUSED || UNEXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
439        if (OP1_TYPE == IS_VAR && !OP1_FREE) {
440            Z_ADDREF_P(container);  /* undo the effect of get_obj_zval_ptr_ptr() */
441        }
442        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, binary_op);
443    } else {
444        zval *dim = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
445
446        zend_fetch_dimension_address_RW(&rv, container, dim, OP2_TYPE TSRMLS_CC);
447        value = get_zval_ptr_deref((opline+1)->op1_type, &(opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
448        ZEND_ASSERT(Z_TYPE(rv) == IS_INDIRECT);
449        var_ptr = Z_INDIRECT(rv);
450    }
451
452    if (UNEXPECTED(var_ptr == NULL)) {
453        zend_error_noreturn(E_ERROR, "Cannot use assign-op operators with overloaded objects nor string offsets");
454    }
455
456    if (UNEXPECTED(var_ptr == &EG(error_zval))) {
457        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
458            ZVAL_NULL(EX_VAR(opline->result.var));
459        }
460    } else {
461        ZVAL_DEREF(var_ptr);
462        SEPARATE_ZVAL_NOREF(var_ptr);
463
464        binary_op(var_ptr, var_ptr, value TSRMLS_CC);
465
466        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
467            ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
468        }
469    }
470
471    FREE_OP2();
472    FREE_OP(free_op_data1);
473    FREE_OP1_VAR_PTR();
474    CHECK_EXCEPTION();
475    ZEND_VM_INC_OPCODE();
476    ZEND_VM_NEXT_OPCODE();
477}
478
479ZEND_VM_HELPER_EX(zend_binary_assign_op_helper, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV, int (*binary_op)(zval *result, zval *op1, zval *op2 TSRMLS_DC))
480{
481    USE_OPLINE
482    zend_free_op free_op1, free_op2;
483    zval *var_ptr;
484    zval *value;
485
486    SAVE_OPLINE();
487    value = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
488    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
489
490    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
491        zend_error_noreturn(E_ERROR, "Cannot use assign-op operators with overloaded objects nor string offsets");
492    }
493
494    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
495        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
496            ZVAL_NULL(EX_VAR(opline->result.var));
497        }
498    } else {
499        ZVAL_DEREF(var_ptr);
500        SEPARATE_ZVAL_NOREF(var_ptr);
501
502        binary_op(var_ptr, var_ptr, value TSRMLS_CC);
503
504        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
505            ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
506        }
507    }
508
509    FREE_OP2();
510    FREE_OP1_VAR_PTR();
511    CHECK_EXCEPTION();
512    ZEND_VM_NEXT_OPCODE();
513}
514
515ZEND_VM_HANDLER(23, ZEND_ASSIGN_ADD, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
516{
517    USE_OPLINE
518
519    if (EXPECTED(opline->extended_value == 0)) {
520        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, add_function);
521    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
522        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, add_function);
523    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
524        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, add_function);
525    }
526}
527
528ZEND_VM_HANDLER(24, ZEND_ASSIGN_SUB, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
529{
530    USE_OPLINE
531
532    if (EXPECTED(opline->extended_value == 0)) {
533        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, sub_function);
534    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
535        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, sub_function);
536    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
537        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, sub_function);
538    }
539}
540
541ZEND_VM_HANDLER(25, ZEND_ASSIGN_MUL, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
542{
543    USE_OPLINE
544
545    if (EXPECTED(opline->extended_value == 0)) {
546        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, mul_function);
547    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
548        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, mul_function);
549    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
550        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, mul_function);
551    }
552}
553
554ZEND_VM_HANDLER(26, ZEND_ASSIGN_DIV, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
555{
556    USE_OPLINE
557
558    if (EXPECTED(opline->extended_value == 0)) {
559        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, div_function);
560    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
561        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, div_function);
562    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
563        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, div_function);
564    }
565}
566
567ZEND_VM_HANDLER(27, ZEND_ASSIGN_MOD, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
568{
569    USE_OPLINE
570
571    if (EXPECTED(opline->extended_value == 0)) {
572        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, mod_function);
573    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
574        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, mod_function);
575    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
576        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, mod_function);
577    }
578}
579
580ZEND_VM_HANDLER(28, ZEND_ASSIGN_SL, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
581{
582    USE_OPLINE
583
584    if (EXPECTED(opline->extended_value == 0)) {
585        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, shift_left_function);
586    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
587        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, shift_left_function);
588    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
589        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, shift_left_function);
590    }
591}
592
593ZEND_VM_HANDLER(29, ZEND_ASSIGN_SR, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
594{
595    USE_OPLINE
596
597    if (EXPECTED(opline->extended_value == 0)) {
598        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, shift_right_function);
599    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
600        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, shift_right_function);
601    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
602        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, shift_right_function);
603    }
604}
605
606ZEND_VM_HANDLER(30, ZEND_ASSIGN_CONCAT, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
607{
608    USE_OPLINE
609
610    if (EXPECTED(opline->extended_value == 0)) {
611        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, concat_function);
612    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
613        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, concat_function);
614    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
615        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, concat_function);
616    }
617}
618
619ZEND_VM_HANDLER(31, ZEND_ASSIGN_BW_OR, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
620{
621    USE_OPLINE
622
623    if (EXPECTED(opline->extended_value == 0)) {
624        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, bitwise_or_function);
625    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
626        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_or_function);
627    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
628        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, bitwise_or_function);
629    }
630}
631
632ZEND_VM_HANDLER(32, ZEND_ASSIGN_BW_AND, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
633{
634    USE_OPLINE
635
636    if (EXPECTED(opline->extended_value == 0)) {
637        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, bitwise_and_function);
638    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
639        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_and_function);
640    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
641        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, bitwise_and_function);
642    }
643}
644
645ZEND_VM_HANDLER(33, ZEND_ASSIGN_BW_XOR, VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
646{
647    USE_OPLINE
648
649    if (EXPECTED(opline->extended_value == 0)) {
650        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, bitwise_xor_function);
651    } else if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
652        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_xor_function);
653    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
654        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, bitwise_xor_function);
655    }
656}
657
658ZEND_VM_HELPER_EX(zend_pre_incdec_property_helper, VAR|UNUSED|CV, CONST|TMP|VAR|CV, incdec_t incdec_op)
659{
660    USE_OPLINE
661    zend_free_op free_op1, free_op2;
662    zval *object;
663    zval *property;
664    zval *retval;
665    zval *zptr;
666
667    SAVE_OPLINE();
668    object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
669    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
670    retval = EX_VAR(opline->result.var);
671
672    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
673        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
674    }
675
676    if (OP1_TYPE != IS_UNUSED) {
677        object = make_real_object(object TSRMLS_CC); /* this should modify object only if it's empty */
678    }
679
680    if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
681        zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
682        FREE_OP2();
683        if (RETURN_VALUE_USED(opline)) {
684            ZVAL_NULL(retval);
685        }
686        FREE_OP1_VAR_PTR();
687        CHECK_EXCEPTION();
688        ZEND_VM_NEXT_OPCODE();
689    }
690
691    /* here we are sure we are dealing with an object */
692
693    if (EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
694        && EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL) TSRMLS_CC)) != NULL)) {
695
696        ZVAL_DEREF(zptr);
697        SEPARATE_ZVAL_NOREF(zptr);
698
699        incdec_op(zptr);
700        if (RETURN_VALUE_USED(opline)) {
701            ZVAL_COPY(retval, zptr);
702        }
703    } else {
704        zval rv;
705
706        if (Z_OBJ_HT_P(object)->read_property && Z_OBJ_HT_P(object)->write_property) {
707            zval *z = Z_OBJ_HT_P(object)->read_property(object, property, BP_VAR_R, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL), &rv TSRMLS_CC);
708
709            if (UNEXPECTED(Z_TYPE_P(z) == IS_OBJECT) && Z_OBJ_HT_P(z)->get) {
710                zval rv;
711                zval *value = Z_OBJ_HT_P(z)->get(z, &rv TSRMLS_CC);
712
713                if (Z_REFCOUNT_P(z) == 0) {
714                    zend_objects_store_del(Z_OBJ_P(z) TSRMLS_CC);
715                }
716                ZVAL_COPY_VALUE(z, value);
717            }
718            if (Z_REFCOUNTED_P(z)) Z_ADDREF_P(z);
719            SEPARATE_ZVAL_IF_NOT_REF(z);
720            incdec_op(z);
721            ZVAL_COPY_VALUE(retval, z);
722            Z_OBJ_HT_P(object)->write_property(object, property, z, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL) TSRMLS_CC);
723            SELECTIVE_PZVAL_LOCK(retval, opline);
724            zval_ptr_dtor(z);
725        } else {
726            zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
727            if (RETURN_VALUE_USED(opline)) {
728                ZVAL_NULL(retval);
729            }
730        }
731    }
732
733    FREE_OP2();
734    FREE_OP1_VAR_PTR();
735    CHECK_EXCEPTION();
736    ZEND_VM_NEXT_OPCODE();
737}
738
739ZEND_VM_HANDLER(132, ZEND_PRE_INC_OBJ, VAR|UNUSED|CV, CONST|TMP|VAR|CV)
740{
741    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_pre_incdec_property_helper, incdec_op, increment_function);
742}
743
744ZEND_VM_HANDLER(133, ZEND_PRE_DEC_OBJ, VAR|UNUSED|CV, CONST|TMP|VAR|CV)
745{
746    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_pre_incdec_property_helper, incdec_op, decrement_function);
747}
748
749ZEND_VM_HELPER_EX(zend_post_incdec_property_helper, VAR|UNUSED|CV, CONST|TMP|VAR|CV, incdec_t incdec_op)
750{
751    USE_OPLINE
752    zend_free_op free_op1, free_op2;
753    zval *object;
754    zval *property;
755    zval *retval;
756    zval *zptr;
757
758    SAVE_OPLINE();
759    object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
760    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
761    retval = EX_VAR(opline->result.var);
762
763    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
764        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
765    }
766
767    if (OP1_TYPE != IS_UNUSED) {
768        object = make_real_object(object TSRMLS_CC); /* this should modify object only if it's empty */
769    }
770
771    if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
772        zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
773        FREE_OP2();
774        ZVAL_NULL(retval);
775        FREE_OP1_VAR_PTR();
776        CHECK_EXCEPTION();
777        ZEND_VM_NEXT_OPCODE();
778    }
779
780    /* here we are sure we are dealing with an object */
781
782    if (EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
783        && EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL) TSRMLS_CC)) != NULL)) {
784
785        ZVAL_DEREF(zptr);
786        ZVAL_COPY(retval, zptr);
787
788        SEPARATE_ZVAL_NOREF(zptr);
789        incdec_op(zptr);
790    } else {
791        if (Z_OBJ_HT_P(object)->read_property && Z_OBJ_HT_P(object)->write_property) {
792            zval rv;
793            zval *z = Z_OBJ_HT_P(object)->read_property(object, property, BP_VAR_R, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL), &rv TSRMLS_CC);
794            zval z_copy;
795
796            if (UNEXPECTED(Z_TYPE_P(z) == IS_OBJECT) && Z_OBJ_HT_P(z)->get) {
797                zval rv;
798                zval *value = Z_OBJ_HT_P(z)->get(z, &rv TSRMLS_CC);
799
800                if (Z_REFCOUNT_P(z) == 0) {
801                    zend_objects_store_del(Z_OBJ_P(z) TSRMLS_CC);
802                }
803                ZVAL_COPY_VALUE(z, value);
804            }
805            ZVAL_DUP(retval, z);
806            ZVAL_DUP(&z_copy, z);
807            incdec_op(&z_copy);
808            if (Z_REFCOUNTED_P(z)) Z_ADDREF_P(z);
809            Z_OBJ_HT_P(object)->write_property(object, property, &z_copy, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL) TSRMLS_CC);
810            zval_ptr_dtor(&z_copy);
811            zval_ptr_dtor(z);
812        } else {
813            zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
814            ZVAL_NULL(retval);
815        }
816    }
817
818    FREE_OP2();
819    FREE_OP1_VAR_PTR();
820    CHECK_EXCEPTION();
821    ZEND_VM_NEXT_OPCODE();
822}
823
824ZEND_VM_HANDLER(134, ZEND_POST_INC_OBJ, VAR|UNUSED|CV, CONST|TMP|VAR|CV)
825{
826    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_post_incdec_property_helper, incdec_op, increment_function);
827}
828
829ZEND_VM_HANDLER(135, ZEND_POST_DEC_OBJ, VAR|UNUSED|CV, CONST|TMP|VAR|CV)
830{
831    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_post_incdec_property_helper, incdec_op, decrement_function);
832}
833
834ZEND_VM_HANDLER(34, ZEND_PRE_INC, VAR|CV, ANY)
835{
836    USE_OPLINE
837    zend_free_op free_op1;
838    zval *var_ptr;
839
840    SAVE_OPLINE();
841    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
842
843    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
844        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
845    }
846
847    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
848        fast_increment_function(var_ptr);
849        if (RETURN_VALUE_USED(opline)) {
850            ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
851        }
852        ZEND_VM_NEXT_OPCODE();
853    }
854
855    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
856        if (RETURN_VALUE_USED(opline)) {
857            ZVAL_NULL(EX_VAR(opline->result.var));
858        }
859        CHECK_EXCEPTION();
860        ZEND_VM_NEXT_OPCODE();
861    }
862
863    ZVAL_DEREF(var_ptr);
864    SEPARATE_ZVAL_NOREF(var_ptr);
865
866    increment_function(var_ptr);
867
868    if (RETURN_VALUE_USED(opline)) {
869        ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
870    }
871
872    FREE_OP1_VAR_PTR();
873    CHECK_EXCEPTION();
874    ZEND_VM_NEXT_OPCODE();
875}
876
877ZEND_VM_HANDLER(35, ZEND_PRE_DEC, VAR|CV, ANY)
878{
879    USE_OPLINE
880    zend_free_op free_op1;
881    zval *var_ptr;
882
883    SAVE_OPLINE();
884    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
885
886    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
887        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
888    }
889
890    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
891        fast_decrement_function(var_ptr);
892        if (RETURN_VALUE_USED(opline)) {
893            ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
894        }
895        ZEND_VM_NEXT_OPCODE();
896    }
897
898    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
899        if (RETURN_VALUE_USED(opline)) {
900            ZVAL_NULL(EX_VAR(opline->result.var));
901        }
902        CHECK_EXCEPTION();
903        ZEND_VM_NEXT_OPCODE();
904    }
905
906    ZVAL_DEREF(var_ptr);
907    SEPARATE_ZVAL_NOREF(var_ptr);
908
909    decrement_function(var_ptr);
910
911    if (RETURN_VALUE_USED(opline)) {
912        ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
913    }
914
915    FREE_OP1_VAR_PTR();
916    CHECK_EXCEPTION();
917    ZEND_VM_NEXT_OPCODE();
918}
919
920ZEND_VM_HANDLER(36, ZEND_POST_INC, VAR|CV, ANY)
921{
922    USE_OPLINE
923    zend_free_op free_op1;
924    zval *var_ptr;
925
926    SAVE_OPLINE();
927    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
928
929    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
930        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
931    }
932
933    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
934        ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
935        fast_increment_function(var_ptr);
936        ZEND_VM_NEXT_OPCODE();
937    }
938
939    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
940        ZVAL_NULL(EX_VAR(opline->result.var));
941        CHECK_EXCEPTION();
942        ZEND_VM_NEXT_OPCODE();
943    }
944
945    if (UNEXPECTED(Z_ISREF_P(var_ptr))) {
946        var_ptr = Z_REFVAL_P(var_ptr);
947        ZVAL_DUP(EX_VAR(opline->result.var), var_ptr);
948    } else {
949        ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
950        zval_opt_copy_ctor(var_ptr);
951    }
952
953    increment_function(var_ptr);
954
955    FREE_OP1_VAR_PTR();
956    CHECK_EXCEPTION();
957    ZEND_VM_NEXT_OPCODE();
958}
959
960ZEND_VM_HANDLER(37, ZEND_POST_DEC, VAR|CV, ANY)
961{
962    USE_OPLINE
963    zend_free_op free_op1;
964    zval *var_ptr;
965
966    SAVE_OPLINE();
967    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
968
969    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
970        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
971    }
972
973    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
974        ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
975        fast_decrement_function(var_ptr);
976        ZEND_VM_NEXT_OPCODE();
977    }
978
979    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
980        ZVAL_NULL(EX_VAR(opline->result.var));
981        CHECK_EXCEPTION();
982        ZEND_VM_NEXT_OPCODE();
983    }
984
985    if (UNEXPECTED(Z_ISREF_P(var_ptr))) {
986        var_ptr = Z_REFVAL_P(var_ptr);
987        ZVAL_DUP(EX_VAR(opline->result.var), var_ptr);
988    } else {
989        ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
990        zval_opt_copy_ctor(var_ptr);
991    }
992
993    decrement_function(var_ptr);
994
995    FREE_OP1_VAR_PTR();
996    CHECK_EXCEPTION();
997    ZEND_VM_NEXT_OPCODE();
998}
999
1000ZEND_VM_HANDLER(40, ZEND_ECHO, CONST|TMP|VAR|CV, ANY)
1001{
1002    USE_OPLINE
1003    zend_free_op free_op1;
1004    zval *z;
1005
1006    SAVE_OPLINE();
1007    z = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
1008
1009    zend_print_variable(z TSRMLS_CC);
1010
1011    FREE_OP1();
1012    CHECK_EXCEPTION();
1013    ZEND_VM_NEXT_OPCODE();
1014}
1015
1016ZEND_VM_HANDLER(41, ZEND_PRINT, CONST|TMP|VAR|CV, ANY)
1017{
1018    USE_OPLINE
1019
1020    ZVAL_LONG(EX_VAR(opline->result.var), 1);
1021    ZEND_VM_DISPATCH_TO_HANDLER(ZEND_ECHO);
1022}
1023
1024ZEND_VM_HELPER_EX(zend_fetch_var_address_helper, CONST|TMP|VAR|CV, UNUSED|CONST|VAR, int type)
1025{
1026    USE_OPLINE
1027    zend_free_op free_op1;
1028    zval *varname;
1029    zval *retval;
1030    zend_string *name;
1031    HashTable *target_symbol_table;
1032
1033    SAVE_OPLINE();
1034    varname = GET_OP1_ZVAL_PTR(BP_VAR_R);
1035
1036    if (OP1_TYPE == IS_CONST) {
1037        name = Z_STR_P(varname);
1038    } else if (EXPECTED(Z_TYPE_P(varname) == IS_STRING)) {
1039        name = Z_STR_P(varname);
1040        zend_string_addref(name);
1041    } else {
1042        name = zval_get_string(varname);
1043    }
1044
1045    if (OP2_TYPE != IS_UNUSED) {
1046        zend_class_entry *ce;
1047
1048        if (OP2_TYPE == IS_CONST) {
1049            if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv))) {
1050                ce = CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv));
1051            } else {
1052                ce = zend_fetch_class_by_name(Z_STR_P(opline->op2.zv), opline->op2.zv + 1, 0 TSRMLS_CC);
1053                if (UNEXPECTED(ce == NULL)) {
1054                    if (OP1_TYPE != IS_CONST) {
1055                        zend_string_release(name);
1056                    }
1057                    FREE_OP1();
1058                    CHECK_EXCEPTION();
1059                    ZEND_VM_NEXT_OPCODE();
1060                }
1061                CACHE_PTR(Z_CACHE_SLOT_P(opline->op2.zv), ce);
1062            }
1063        } else {
1064            ce = Z_CE_P(EX_VAR(opline->op2.var));
1065        }
1066        retval = zend_std_get_static_property(ce, name, 0, ((OP1_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(varname)) : NULL) TSRMLS_CC);
1067        FREE_OP1();
1068    } else {
1069        target_symbol_table = zend_get_target_symbol_table(execute_data, opline->extended_value & ZEND_FETCH_TYPE_MASK TSRMLS_CC);
1070        retval = zend_hash_find(target_symbol_table, name);
1071        if (retval == NULL) {
1072            switch (type) {
1073                case BP_VAR_R:
1074                case BP_VAR_UNSET:
1075                    zend_error(E_NOTICE,"Undefined variable: %s", name->val);
1076                    /* break missing intentionally */
1077                case BP_VAR_IS:
1078                    retval = &EG(uninitialized_zval);
1079                    break;
1080                case BP_VAR_RW:
1081                    zend_error(E_NOTICE,"Undefined variable: %s", name->val);
1082                    /* break missing intentionally */
1083                case BP_VAR_W:
1084                    retval = zend_hash_add_new(target_symbol_table, name, &EG(uninitialized_zval));
1085                    break;
1086                EMPTY_SWITCH_DEFAULT_CASE()
1087            }
1088        /* GLOBAL or $$name variable may be an INDIRECT pointer to CV */
1089        } else if (Z_TYPE_P(retval) == IS_INDIRECT) {
1090            retval = Z_INDIRECT_P(retval);
1091            if (Z_TYPE_P(retval) == IS_UNDEF) {
1092                switch (type) {
1093                    case BP_VAR_R:
1094                    case BP_VAR_UNSET:
1095                        zend_error(E_NOTICE,"Undefined variable: %s", name->val);
1096                        /* break missing intentionally */
1097                    case BP_VAR_IS:
1098                        retval = &EG(uninitialized_zval);
1099                        break;
1100                    case BP_VAR_RW:
1101                        zend_error(E_NOTICE,"Undefined variable: %s", name->val);
1102                        /* break missing intentionally */
1103                    case BP_VAR_W:
1104                        ZVAL_NULL(retval);
1105                        break;
1106                    EMPTY_SWITCH_DEFAULT_CASE()
1107                }
1108            }
1109        }
1110        if ((opline->extended_value & ZEND_FETCH_TYPE_MASK) == ZEND_FETCH_STATIC) {
1111            if (Z_CONSTANT_P(retval)) {
1112                zval_update_constant(retval, 1 TSRMLS_CC);
1113            }
1114        } else if ((opline->extended_value & ZEND_FETCH_TYPE_MASK) != ZEND_FETCH_GLOBAL_LOCK) {
1115            FREE_OP1();
1116        }
1117    }
1118
1119    if (OP1_TYPE != IS_CONST) {
1120        zend_string_release(name);
1121    }
1122
1123    ZEND_ASSERT(retval != NULL);
1124    if (type == BP_VAR_R || type == BP_VAR_IS) {
1125        if (/*type == BP_VAR_R &&*/ Z_ISREF_P(retval) && Z_REFCOUNT_P(retval) == 1) {
1126            ZVAL_UNREF(retval);
1127        }
1128        ZVAL_COPY(EX_VAR(opline->result.var), retval);
1129    } else {
1130        ZVAL_INDIRECT(EX_VAR(opline->result.var), retval);
1131    }
1132    CHECK_EXCEPTION();
1133    ZEND_VM_NEXT_OPCODE();
1134}
1135
1136ZEND_VM_HANDLER(80, ZEND_FETCH_R, CONST|TMP|VAR|CV, UNUSED|CONST|VAR)
1137{
1138    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_R);
1139}
1140
1141ZEND_VM_HANDLER(83, ZEND_FETCH_W, CONST|TMP|VAR|CV, UNUSED|CONST|VAR)
1142{
1143    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_W);
1144}
1145
1146ZEND_VM_HANDLER(86, ZEND_FETCH_RW, CONST|TMP|VAR|CV, UNUSED|CONST|VAR)
1147{
1148    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_RW);
1149}
1150
1151ZEND_VM_HANDLER(92, ZEND_FETCH_FUNC_ARG, CONST|TMP|VAR|CV, UNUSED|CONST|VAR)
1152{
1153    USE_OPLINE
1154
1155    if (zend_is_by_ref_func_arg_fetch(opline, EX(call) TSRMLS_CC)) {
1156        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_W);
1157    } else {
1158        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_R);
1159    }
1160}
1161
1162ZEND_VM_HANDLER(95, ZEND_FETCH_UNSET, CONST|TMP|VAR|CV, UNUSED|CONST|VAR)
1163{
1164    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_UNSET);
1165}
1166
1167ZEND_VM_HANDLER(89, ZEND_FETCH_IS, CONST|TMP|VAR|CV, UNUSED|CONST|VAR)
1168{
1169    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_IS);
1170}
1171
1172ZEND_VM_HANDLER(81, ZEND_FETCH_DIM_R, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
1173{
1174    USE_OPLINE
1175    zend_free_op free_op1, free_op2;
1176    zval *container;
1177
1178    SAVE_OPLINE();
1179    container = GET_OP1_ZVAL_PTR(BP_VAR_R);
1180    zend_fetch_dimension_address_read_R(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R), OP2_TYPE TSRMLS_CC);
1181    FREE_OP2();
1182    FREE_OP1();
1183    CHECK_EXCEPTION();
1184    ZEND_VM_NEXT_OPCODE();
1185}
1186
1187ZEND_VM_HANDLER(84, ZEND_FETCH_DIM_W, VAR|CV, CONST|TMP|VAR|UNUSED|CV)
1188{
1189    USE_OPLINE
1190    zend_free_op free_op1, free_op2;
1191    zval *container;
1192
1193    SAVE_OPLINE();
1194    container = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
1195
1196    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1197        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1198    }
1199    ZVAL_DEREF(container);
1200    zend_fetch_dimension_address_W(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R), OP2_TYPE TSRMLS_CC);
1201    FREE_OP2();
1202    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1203        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1204    }
1205    FREE_OP1_VAR_PTR();
1206    CHECK_EXCEPTION();
1207    ZEND_VM_NEXT_OPCODE();
1208}
1209
1210ZEND_VM_HANDLER(87, ZEND_FETCH_DIM_RW, VAR|CV, CONST|TMP|VAR|UNUSED|CV)
1211{
1212    USE_OPLINE
1213    zend_free_op free_op1, free_op2;
1214    zval *container;
1215
1216    SAVE_OPLINE();
1217    container = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
1218
1219    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1220        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1221    }
1222    ZVAL_DEREF(container);
1223    zend_fetch_dimension_address_RW(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R), OP2_TYPE TSRMLS_CC);
1224    FREE_OP2();
1225    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1226        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1227    }
1228    FREE_OP1_VAR_PTR();
1229    CHECK_EXCEPTION();
1230    ZEND_VM_NEXT_OPCODE();
1231}
1232
1233ZEND_VM_HANDLER(90, ZEND_FETCH_DIM_IS, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
1234{
1235    USE_OPLINE
1236    zend_free_op free_op1, free_op2;
1237    zval *container;
1238
1239    SAVE_OPLINE();
1240    container = GET_OP1_ZVAL_PTR(BP_VAR_IS);
1241    zend_fetch_dimension_address_read_IS(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R), OP2_TYPE TSRMLS_CC);
1242    FREE_OP2();
1243    FREE_OP1();
1244    CHECK_EXCEPTION();
1245    ZEND_VM_NEXT_OPCODE();
1246}
1247
1248ZEND_VM_HANDLER(93, ZEND_FETCH_DIM_FUNC_ARG, CONST|TMP|VAR|CV, CONST|TMP|VAR|UNUSED|CV)
1249{
1250    USE_OPLINE
1251    zval *container;
1252    zend_free_op free_op1, free_op2;
1253
1254    SAVE_OPLINE();
1255
1256    if (zend_is_by_ref_func_arg_fetch(opline, EX(call) TSRMLS_CC)) {
1257        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
1258            zend_error_noreturn(E_ERROR, "Cannot use temporary expression in write context");
1259        }
1260        container = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
1261        if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1262            zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1263        }
1264        ZVAL_DEREF(container);
1265        zend_fetch_dimension_address_W(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R), OP2_TYPE TSRMLS_CC);
1266        if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1267            EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1268        }
1269        FREE_OP2();
1270        FREE_OP1_VAR_PTR();
1271    } else {
1272        if (OP2_TYPE == IS_UNUSED) {
1273            zend_error_noreturn(E_ERROR, "Cannot use [] for reading");
1274        }
1275        container = GET_OP1_ZVAL_PTR(BP_VAR_R);
1276        zend_fetch_dimension_address_read_R(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R), OP2_TYPE TSRMLS_CC);
1277        FREE_OP2();
1278        FREE_OP1();
1279    }
1280    CHECK_EXCEPTION();
1281    ZEND_VM_NEXT_OPCODE();
1282}
1283
1284ZEND_VM_HANDLER(96, ZEND_FETCH_DIM_UNSET, VAR|CV, CONST|TMP|VAR|CV)
1285{
1286    USE_OPLINE
1287    zend_free_op free_op1, free_op2;
1288    zval *container;
1289
1290    SAVE_OPLINE();
1291    container = GET_OP1_ZVAL_PTR_PTR(BP_VAR_UNSET);
1292
1293    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1294        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1295    }
1296    ZVAL_DEREF(container);
1297    zend_fetch_dimension_address_UNSET(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R), OP2_TYPE TSRMLS_CC);
1298    FREE_OP2();
1299    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1300        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1301    }
1302    FREE_OP1_VAR_PTR();
1303    CHECK_EXCEPTION();
1304    ZEND_VM_NEXT_OPCODE();
1305}
1306
1307ZEND_VM_HANDLER(82, ZEND_FETCH_OBJ_R, CONST|TMP|VAR|UNUSED|CV, CONST|TMP|VAR|CV)
1308{
1309    USE_OPLINE
1310    zend_free_op free_op1;
1311    zval *container;
1312    zend_free_op free_op2;
1313    zval *offset;
1314
1315    SAVE_OPLINE();
1316    container = GET_OP1_OBJ_ZVAL_PTR_DEREF(BP_VAR_R);
1317    offset  = GET_OP2_ZVAL_PTR(BP_VAR_R);
1318
1319    if ((OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) ||
1320        UNEXPECTED(Z_OBJ_HT_P(container)->read_property == NULL)) {
1321        zend_error(E_NOTICE, "Trying to get property of non-object");
1322        ZVAL_NULL(EX_VAR(opline->result.var));
1323    } else {
1324        zval *retval;
1325
1326        /* here we are sure we are dealing with an object */
1327        do {
1328            if (OP2_TYPE == IS_CONST &&
1329                EXPECTED(Z_OBJCE_P(container) == CACHED_PTR(Z_CACHE_SLOT_P(offset)))) {
1330                zend_property_info *prop_info = CACHED_PTR(Z_CACHE_SLOT_P(offset) + 1);
1331                zend_object *zobj = Z_OBJ_P(container);
1332
1333                if (EXPECTED(prop_info)) {
1334                    retval = OBJ_PROP(zobj, prop_info->offset);
1335                    if (EXPECTED(Z_TYPE_P(retval) != IS_UNDEF)) {
1336                        ZVAL_COPY(EX_VAR(opline->result.var), retval);
1337                        break;
1338                    }
1339                } else if (EXPECTED(zobj->properties != NULL)) {
1340                    retval = zend_hash_find(zobj->properties, Z_STR_P(offset));
1341                    if (EXPECTED(retval)) {
1342                        ZVAL_COPY(EX_VAR(opline->result.var), retval);
1343                        break;
1344                    }
1345                }
1346            }
1347
1348            retval = Z_OBJ_HT_P(container)->read_property(container, offset, BP_VAR_R, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(offset)) : NULL), EX_VAR(opline->result.var) TSRMLS_CC);
1349
1350            if (retval != EX_VAR(opline->result.var)) {
1351                ZVAL_COPY(EX_VAR(opline->result.var), retval);
1352            }
1353        } while (0);
1354    }
1355
1356    FREE_OP2();
1357    FREE_OP1();
1358    CHECK_EXCEPTION();
1359    ZEND_VM_NEXT_OPCODE();
1360}
1361
1362ZEND_VM_HANDLER(85, ZEND_FETCH_OBJ_W, VAR|UNUSED|CV, CONST|TMP|VAR|CV)
1363{
1364    USE_OPLINE
1365    zend_free_op free_op1, free_op2;
1366    zval *property;
1367    zval *container;
1368
1369    SAVE_OPLINE();
1370    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1371
1372    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_W);
1373    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1374        zend_error_noreturn(E_ERROR, "Cannot use string offset as an object");
1375    }
1376
1377    zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_W TSRMLS_CC);
1378    FREE_OP2();
1379    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1380        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1381    }
1382    FREE_OP1_VAR_PTR();
1383    CHECK_EXCEPTION();
1384    ZEND_VM_NEXT_OPCODE();
1385}
1386
1387ZEND_VM_HANDLER(88, ZEND_FETCH_OBJ_RW, VAR|UNUSED|CV, CONST|TMP|VAR|CV)
1388{
1389    USE_OPLINE
1390    zend_free_op free_op1, free_op2;
1391    zval *property;
1392    zval *container;
1393
1394    SAVE_OPLINE();
1395    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1396    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
1397
1398    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1399        zend_error_noreturn(E_ERROR, "Cannot use string offset as an object");
1400    }
1401    zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_RW TSRMLS_CC);
1402    FREE_OP2();
1403    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1404        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1405    }
1406    FREE_OP1_VAR_PTR();
1407    CHECK_EXCEPTION();
1408    ZEND_VM_NEXT_OPCODE();
1409}
1410
1411ZEND_VM_HANDLER(91, ZEND_FETCH_OBJ_IS, CONST|TMP|VAR|UNUSED|CV, CONST|TMP|VAR|CV)
1412{
1413    USE_OPLINE
1414    zend_free_op free_op1;
1415    zval *container;
1416    zend_free_op free_op2;
1417    zval *offset;
1418
1419    SAVE_OPLINE();
1420    container = GET_OP1_OBJ_ZVAL_PTR_DEREF(BP_VAR_IS);
1421    offset  = GET_OP2_ZVAL_PTR(BP_VAR_R);
1422
1423    if ((OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) ||
1424        UNEXPECTED(Z_OBJ_HT_P(container)->read_property == NULL)) {
1425        ZVAL_NULL(EX_VAR(opline->result.var));
1426    } else {
1427        zval *retval;
1428
1429        /* here we are sure we are dealing with an object */
1430        do {
1431            if (OP2_TYPE == IS_CONST &&
1432                EXPECTED(Z_OBJCE_P(container) == CACHED_PTR(Z_CACHE_SLOT_P(offset)))) {
1433                zend_property_info *prop_info = CACHED_PTR(Z_CACHE_SLOT_P(offset) + 1);
1434                zend_object *zobj = Z_OBJ_P(container);
1435
1436                if (EXPECTED(prop_info)) {
1437                    retval = OBJ_PROP(zobj, prop_info->offset);
1438                    if (EXPECTED(Z_TYPE_P(retval) != IS_UNDEF)) {
1439                        ZVAL_COPY(EX_VAR(opline->result.var), retval);
1440                        break;
1441                    }
1442                } else if (EXPECTED(zobj->properties != NULL)) {
1443                    retval = zend_hash_find(zobj->properties, Z_STR_P(offset));
1444                    if (EXPECTED(retval)) {
1445                        ZVAL_COPY(EX_VAR(opline->result.var), retval);
1446                        break;
1447                    }
1448                }
1449            }
1450
1451            retval = Z_OBJ_HT_P(container)->read_property(container, offset, BP_VAR_IS, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(offset)) : NULL), EX_VAR(opline->result.var) TSRMLS_CC);
1452
1453            if (retval != EX_VAR(opline->result.var)) {
1454                ZVAL_COPY(EX_VAR(opline->result.var), retval);
1455            }
1456        } while (0);
1457    }
1458
1459    FREE_OP2();
1460    FREE_OP1();
1461    CHECK_EXCEPTION();
1462    ZEND_VM_NEXT_OPCODE();
1463}
1464
1465ZEND_VM_HANDLER(94, ZEND_FETCH_OBJ_FUNC_ARG, CONST|TMP|VAR|UNUSED|CV, CONST|TMP|VAR|CV)
1466{
1467    USE_OPLINE
1468    zval *container;
1469
1470    if (zend_is_by_ref_func_arg_fetch(opline, EX(call) TSRMLS_CC)) {
1471        /* Behave like FETCH_OBJ_W */
1472        zend_free_op free_op1, free_op2;
1473        zval *property;
1474
1475        SAVE_OPLINE();
1476        property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1477        container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_W);
1478
1479        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
1480            zend_error_noreturn(E_ERROR, "Cannot use temporary expression in write context");
1481        }
1482        if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1483            zend_error_noreturn(E_ERROR, "Cannot use string offset as an object");
1484        }
1485        zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_W TSRMLS_CC);
1486        FREE_OP2();
1487        if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1488            EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1489        }
1490        FREE_OP1_VAR_PTR();
1491        CHECK_EXCEPTION();
1492        ZEND_VM_NEXT_OPCODE();
1493    } else {
1494        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_FETCH_OBJ_R);
1495    }
1496}
1497
1498ZEND_VM_HANDLER(97, ZEND_FETCH_OBJ_UNSET, VAR|UNUSED|CV, CONST|TMP|VAR|CV)
1499{
1500    USE_OPLINE
1501    zend_free_op free_op1, free_op2;
1502    zval *container, *property;
1503
1504    SAVE_OPLINE();
1505    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_UNSET);
1506    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1507
1508    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1509        zend_error_noreturn(E_ERROR, "Cannot use string offset as an object");
1510    }
1511    zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_UNSET TSRMLS_CC);
1512    FREE_OP2();
1513    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1514        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1515    }
1516    FREE_OP1_VAR_PTR();
1517    CHECK_EXCEPTION();
1518    ZEND_VM_NEXT_OPCODE();
1519}
1520
1521ZEND_VM_HANDLER(98, ZEND_FETCH_LIST, CONST|TMP|VAR|CV, CONST)
1522{
1523    USE_OPLINE
1524    zend_free_op free_op1;
1525    zval *container;
1526
1527    SAVE_OPLINE();
1528    container = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
1529
1530    if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
1531        zend_free_op free_op2;
1532        zval *value = zend_fetch_dimension_address_inner(Z_ARRVAL_P(container), GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R), OP2_TYPE, BP_VAR_R TSRMLS_CC);
1533
1534        ZVAL_COPY(EX_VAR(opline->result.var), value);
1535    } else if (UNEXPECTED(Z_TYPE_P(container) == IS_OBJECT) &&
1536               EXPECTED(Z_OBJ_HT_P(container)->read_dimension)) {
1537        zval *result = EX_VAR(opline->result.var);
1538        zval *retval = Z_OBJ_HT_P(container)->read_dimension(container, GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R), BP_VAR_R, result TSRMLS_CC);
1539
1540        if (retval) {
1541            if (result != retval) {
1542                ZVAL_COPY(result, retval);
1543            }
1544        } else {
1545            ZVAL_NULL(result);
1546        }
1547    } else {
1548        ZVAL_NULL(EX_VAR(opline->result.var));
1549    }
1550    CHECK_EXCEPTION();
1551    ZEND_VM_NEXT_OPCODE();
1552}
1553
1554ZEND_VM_HANDLER(136, ZEND_ASSIGN_OBJ, VAR|UNUSED|CV, CONST|TMP|VAR|CV)
1555{
1556    USE_OPLINE
1557    zend_free_op free_op1, free_op2;
1558    zval *object;
1559    zval *property_name;
1560
1561    SAVE_OPLINE();
1562    object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_W);
1563    property_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
1564
1565    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
1566        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1567    }
1568    zend_assign_to_object(RETURN_VALUE_USED(opline)?EX_VAR(opline->result.var):NULL, object, OP1_TYPE, property_name, (opline+1)->op1_type, &(opline+1)->op1, execute_data, ZEND_ASSIGN_OBJ, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property_name)) : NULL) TSRMLS_CC);
1569    FREE_OP2();
1570    FREE_OP1_VAR_PTR();
1571    /* assign_obj has two opcodes! */
1572    CHECK_EXCEPTION();
1573    ZEND_VM_INC_OPCODE();
1574    ZEND_VM_NEXT_OPCODE();
1575}
1576
1577ZEND_VM_HANDLER(147, ZEND_ASSIGN_DIM, VAR|CV, CONST|TMP|VAR|UNUSED|CV)
1578{
1579    USE_OPLINE
1580    zend_free_op free_op1;
1581    zval *object_ptr;
1582
1583    SAVE_OPLINE();
1584    object_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
1585
1586    if (OP1_TYPE == IS_VAR && UNEXPECTED(object_ptr == NULL)) {
1587        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1588    }
1589    ZVAL_DEREF(object_ptr);
1590    if (UNEXPECTED(Z_TYPE_P(object_ptr) == IS_OBJECT)) {
1591        zend_free_op free_op2;
1592        zval *property_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
1593
1594        zend_assign_to_object(RETURN_VALUE_USED(opline)?EX_VAR(opline->result.var):NULL, object_ptr, OP1_TYPE, property_name, (opline+1)->op1_type, &(opline+1)->op1, execute_data, ZEND_ASSIGN_DIM, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(property_name)) : NULL) TSRMLS_CC);
1595        FREE_OP2();
1596    } else {
1597        zend_free_op free_op2, free_op_data1;
1598        zval  rv;
1599        zval *value;
1600        zval *dim = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
1601        zval *variable_ptr;
1602
1603        if (UNEXPECTED(Z_TYPE_P(object_ptr) == IS_STRING) &&
1604            EXPECTED(Z_STRLEN_P(object_ptr) != 0)) {
1605            zend_long offset = zend_fetch_string_offset(object_ptr, dim, BP_VAR_W TSRMLS_CC);
1606            FREE_OP2();
1607            value = get_zval_ptr_deref((opline+1)->op1_type, &(opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
1608            zend_assign_to_string_offset(object_ptr, offset, value, (RETURN_VALUE_USED(opline) ? EX_VAR(opline->result.var) : NULL) TSRMLS_CC);
1609            FREE_OP(free_op_data1);
1610        } else {
1611            zend_fetch_dimension_address_W(&rv, object_ptr, dim, OP2_TYPE TSRMLS_CC);
1612            FREE_OP2();
1613            value = get_zval_ptr_deref((opline+1)->op1_type, &(opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
1614            ZEND_ASSERT(Z_TYPE(rv) == IS_INDIRECT);
1615            variable_ptr = Z_INDIRECT(rv);
1616            if (UNEXPECTED(variable_ptr == &EG(error_zval))) {
1617                FREE_OP(free_op_data1);
1618                if (RETURN_VALUE_USED(opline)) {
1619                    ZVAL_NULL(EX_VAR(opline->result.var));
1620                }
1621            } else {
1622                value = zend_assign_to_variable(variable_ptr, value, (opline+1)->op1_type TSRMLS_CC);
1623                if ((opline+1)->op1_type == IS_VAR) {
1624                    FREE_OP(free_op_data1);
1625                }
1626                if (RETURN_VALUE_USED(opline)) {
1627                    ZVAL_COPY(EX_VAR(opline->result.var), value);
1628                }
1629            }
1630        }
1631    }
1632    FREE_OP1_VAR_PTR();
1633    /* assign_dim has two opcodes! */
1634    CHECK_EXCEPTION();
1635    ZEND_VM_INC_OPCODE();
1636    ZEND_VM_NEXT_OPCODE();
1637}
1638
1639ZEND_VM_HANDLER(38, ZEND_ASSIGN, VAR|CV, CONST|TMP|VAR|CV)
1640{
1641    USE_OPLINE
1642    zend_free_op free_op1, free_op2;
1643    zval *value;
1644    zval *variable_ptr;
1645
1646    SAVE_OPLINE();
1647    value = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
1648    variable_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1649
1650    if (OP1_TYPE == IS_VAR && UNEXPECTED(variable_ptr == &EG(error_zval))) {
1651        if (OP2_TYPE == IS_TMP_VAR) {
1652            FREE_OP2();
1653        }
1654        if (RETURN_VALUE_USED(opline)) {
1655            ZVAL_NULL(EX_VAR(opline->result.var));
1656        }
1657    } else {
1658        value = zend_assign_to_variable(variable_ptr, value, OP2_TYPE TSRMLS_CC);
1659        if (RETURN_VALUE_USED(opline)) {
1660            ZVAL_COPY(EX_VAR(opline->result.var), value);
1661        }
1662        FREE_OP1_VAR_PTR();
1663    }
1664
1665    /* zend_assign_to_variable() always takes care of op2, never free it! */
1666    FREE_OP2_IF_VAR();
1667
1668    CHECK_EXCEPTION();
1669    ZEND_VM_NEXT_OPCODE();
1670}
1671
1672ZEND_VM_HANDLER(39, ZEND_ASSIGN_REF, VAR|CV, VAR|CV)
1673{
1674    USE_OPLINE
1675    zend_free_op free_op1, free_op2;
1676    zval *variable_ptr;
1677    zval *value_ptr;
1678
1679    SAVE_OPLINE();
1680    value_ptr = GET_OP2_ZVAL_PTR_PTR(BP_VAR_W);
1681
1682    if (OP2_TYPE == IS_VAR && UNEXPECTED(value_ptr == NULL)) {
1683        zend_error_noreturn(E_ERROR, "Cannot create references to/from string offsets nor overloaded objects");
1684    }
1685    if (OP2_TYPE == IS_VAR &&
1686        (value_ptr == &EG(uninitialized_zval) ||
1687         (opline->extended_value == ZEND_RETURNS_FUNCTION &&
1688          !(Z_VAR_FLAGS_P(value_ptr) & IS_VAR_RET_REF)))) {
1689        if (!OP2_FREE) {
1690            PZVAL_LOCK(value_ptr); /* undo the effect of get_zval_ptr_ptr() */
1691        }
1692        zend_error(E_STRICT, "Only variables should be assigned by reference");
1693        if (UNEXPECTED(EG(exception) != NULL)) {
1694            FREE_OP2_VAR_PTR();
1695            HANDLE_EXCEPTION();
1696        }
1697        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_ASSIGN);
1698    } else if (OP2_TYPE == IS_VAR && opline->extended_value == ZEND_RETURNS_NEW) {
1699        if (!OP2_FREE) {
1700            PZVAL_LOCK(value_ptr);
1701        }
1702    }
1703
1704    variable_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1705    if (OP1_TYPE == IS_VAR && UNEXPECTED(variable_ptr == NULL)) {
1706        zend_error_noreturn(E_ERROR, "Cannot create references to/from string offsets nor overloaded objects");
1707    }
1708    if (OP1_TYPE == IS_VAR &&
1709        UNEXPECTED(Z_TYPE_P(EX_VAR(opline->op1.var)) != IS_INDIRECT) &&
1710        UNEXPECTED(!Z_ISREF_P(variable_ptr))) {
1711        zend_error_noreturn(E_ERROR, "Cannot assign by reference to overloaded object");
1712    }
1713    if ((OP1_TYPE == IS_VAR && UNEXPECTED(variable_ptr == &EG(error_zval))) ||
1714        (OP2_TYPE == IS_VAR && UNEXPECTED(value_ptr == &EG(error_zval)))) {
1715        variable_ptr = &EG(uninitialized_zval);
1716    } else {
1717        zend_assign_to_variable_reference(variable_ptr, value_ptr TSRMLS_CC);
1718    }
1719
1720    if (OP2_TYPE == IS_VAR && opline->extended_value == ZEND_RETURNS_NEW) {
1721        if (!OP2_FREE) {
1722            Z_DELREF_P(variable_ptr);
1723        }
1724    }
1725
1726    if (RETURN_VALUE_USED(opline)) {
1727        ZVAL_COPY(EX_VAR(opline->result.var), variable_ptr);
1728    }
1729
1730    FREE_OP1_VAR_PTR();
1731    FREE_OP2_VAR_PTR();
1732
1733    CHECK_EXCEPTION();
1734    ZEND_VM_NEXT_OPCODE();
1735}
1736
1737ZEND_VM_HELPER(zend_leave_helper, ANY, ANY)
1738{
1739    zend_call_kind call_kind = EX_CALL_KIND();
1740
1741    if (call_kind == ZEND_CALL_NESTED_FUNCTION) {
1742        zend_object *object;
1743
1744        i_free_compiled_variables(execute_data TSRMLS_CC);
1745        if (UNEXPECTED(EX(symbol_table) != NULL)) {
1746            zend_clean_and_cache_symbol_table(EX(symbol_table) TSRMLS_CC);
1747        }
1748        zend_vm_stack_free_extra_args(execute_data TSRMLS_CC);
1749        EG(current_execute_data) = EX(prev_execute_data);
1750        if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_CLOSURE) != 0) && EX(func)->op_array.prototype) {
1751            OBJ_RELEASE((zend_object*)EX(func)->op_array.prototype);
1752        }
1753        object = Z_OBJ(EX(This));
1754        zend_vm_stack_free_call_frame(execute_data TSRMLS_CC);
1755
1756        execute_data = EG(current_execute_data);
1757
1758        if (object) {
1759            if (UNEXPECTED(EG(exception) != NULL) && (EX(opline)->op1.num & ZEND_CALL_CTOR)) {
1760                if (!(EX(opline)->op1.num & ZEND_CALL_CTOR_RESULT_UNUSED)) {
1761                    GC_REFCOUNT(object)--;
1762                }
1763                if (GC_REFCOUNT(object) == 1) {
1764                    zend_object_store_ctor_failed(object TSRMLS_CC);
1765                }
1766            }
1767            OBJ_RELEASE(object);
1768        }
1769        EG(scope) = EX(func)->op_array.scope;
1770
1771        if (UNEXPECTED(EG(exception) != NULL)) {
1772            const zend_op *opline = EX(opline);
1773            zend_throw_exception_internal(NULL TSRMLS_CC);
1774            if (RETURN_VALUE_USED(opline)) {
1775                zval_ptr_dtor(EX_VAR(opline->result.var));
1776            }
1777            HANDLE_EXCEPTION_LEAVE();
1778        }
1779
1780        LOAD_OPLINE();
1781        ZEND_VM_INC_OPCODE();
1782        ZEND_VM_LEAVE();
1783    } else if (call_kind == ZEND_CALL_NESTED_CODE) {
1784        zend_detach_symbol_table(execute_data);
1785        destroy_op_array(&EX(func)->op_array TSRMLS_CC);
1786        efree_size(EX(func), sizeof(zend_op_array));
1787        EG(current_execute_data) = EX(prev_execute_data);
1788        zend_vm_stack_free_call_frame(execute_data TSRMLS_CC);
1789
1790        execute_data = EG(current_execute_data);
1791        zend_attach_symbol_table(execute_data);
1792        if (UNEXPECTED(EG(exception) != NULL)) {
1793            zend_throw_exception_internal(NULL TSRMLS_CC);
1794            HANDLE_EXCEPTION_LEAVE();
1795        }
1796
1797        LOAD_OPLINE();
1798        ZEND_VM_INC_OPCODE();
1799        ZEND_VM_LEAVE();
1800    } else {
1801        if (call_kind == ZEND_CALL_TOP_FUNCTION) {
1802            i_free_compiled_variables(execute_data TSRMLS_CC);
1803            if (UNEXPECTED(EX(symbol_table) != NULL)) {
1804                zend_clean_and_cache_symbol_table(EX(symbol_table) TSRMLS_CC);
1805            }
1806            zend_vm_stack_free_extra_args(execute_data TSRMLS_CC);
1807            EG(current_execute_data) = EX(prev_execute_data);
1808            if ((EX(func)->op_array.fn_flags & ZEND_ACC_CLOSURE) && EX(func)->op_array.prototype) {
1809                OBJ_RELEASE((zend_object*)EX(func)->op_array.prototype);
1810            }
1811        } else /* if (call_kind == ZEND_CALL_TOP_CODE) */ {
1812            zend_array *symbol_table = EX(symbol_table);
1813            zend_execute_data *old_execute_data;
1814
1815            zend_detach_symbol_table(execute_data);
1816            old_execute_data = EX(prev_execute_data);
1817            while (old_execute_data) {
1818                if (old_execute_data->func && ZEND_USER_CODE(old_execute_data->func->op_array.type)) {
1819                    if (old_execute_data->symbol_table == symbol_table) {
1820                        zend_attach_symbol_table(old_execute_data);
1821                    }
1822                    break;
1823                }
1824                old_execute_data = old_execute_data->prev_execute_data;
1825            }
1826            EG(current_execute_data) = EX(prev_execute_data);
1827        }
1828        zend_vm_stack_free_call_frame(execute_data TSRMLS_CC);
1829
1830        ZEND_VM_RETURN();
1831    }
1832}
1833
1834ZEND_VM_HANDLER(42, ZEND_JMP, ANY, ANY)
1835{
1836    USE_OPLINE
1837
1838    ZEND_VM_SET_OPCODE(opline->op1.jmp_addr);
1839    ZEND_VM_CONTINUE();
1840}
1841
1842ZEND_VM_HANDLER(43, ZEND_JMPZ, CONST|TMP|VAR|CV, ANY)
1843{
1844    USE_OPLINE
1845    zend_free_op free_op1;
1846    zval *val;
1847
1848    SAVE_OPLINE();
1849    val = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
1850
1851    if (OP1_TYPE == IS_TMP_VAR) {
1852        if (Z_TYPE_P(val) == IS_TRUE) {
1853            ZEND_VM_SET_OPCODE(opline + 1);
1854            ZEND_VM_CONTINUE();
1855        } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
1856            ZEND_VM_SET_OPCODE(opline->op2.jmp_addr);
1857            ZEND_VM_CONTINUE();
1858        }
1859    }
1860
1861    if (i_zend_is_true(val TSRMLS_CC)) {
1862        opline++;
1863    } else {
1864        opline = opline->op2.jmp_addr;
1865    }
1866    FREE_OP1();
1867    if (UNEXPECTED(EG(exception) != NULL)) {
1868        HANDLE_EXCEPTION();
1869    }
1870    ZEND_VM_JMP(opline);
1871}
1872
1873ZEND_VM_HANDLER(44, ZEND_JMPNZ, CONST|TMP|VAR|CV, ANY)
1874{
1875    USE_OPLINE
1876    zend_free_op free_op1;
1877    zval *val;
1878
1879    SAVE_OPLINE();
1880    val = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
1881
1882    if (OP1_TYPE == IS_TMP_VAR) {
1883        if (Z_TYPE_P(val) == IS_TRUE) {
1884            ZEND_VM_SET_OPCODE(opline->op2.jmp_addr);
1885            ZEND_VM_CONTINUE();
1886        } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
1887            ZEND_VM_SET_OPCODE(opline + 1);
1888            ZEND_VM_CONTINUE();
1889        }
1890    }
1891
1892    if (i_zend_is_true(val TSRMLS_CC)) {
1893        opline = opline->op2.jmp_addr;
1894    } else {
1895        opline++;
1896    }
1897    FREE_OP1();
1898    if (UNEXPECTED(EG(exception) != NULL)) {
1899        HANDLE_EXCEPTION();
1900    }
1901    ZEND_VM_JMP(opline);
1902}
1903
1904ZEND_VM_HANDLER(45, ZEND_JMPZNZ, CONST|TMP|VAR|CV, ANY)
1905{
1906    USE_OPLINE
1907    zend_free_op free_op1;
1908    zval *val;
1909
1910    SAVE_OPLINE();
1911    val = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
1912
1913    if (OP1_TYPE == IS_TMP_VAR) {
1914        if (EXPECTED(Z_TYPE_P(val) == IS_TRUE)) {
1915            ZEND_VM_SET_RELATIVE_OPCODE(opline, opline->extended_value);
1916            ZEND_VM_CONTINUE();
1917        } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
1918            ZEND_VM_SET_OPCODE(opline->op2.jmp_addr);
1919            ZEND_VM_CONTINUE();
1920        }
1921    }
1922
1923    if (i_zend_is_true(val TSRMLS_CC)) {
1924        opline = (zend_op*)(((char*)opline) + opline->extended_value);
1925    } else {
1926        opline = opline->op2.jmp_addr;
1927    }
1928    FREE_OP1();
1929    if (UNEXPECTED(EG(exception) != NULL)) {
1930        HANDLE_EXCEPTION();
1931    }
1932    ZEND_VM_JMP(opline);
1933}
1934
1935ZEND_VM_HANDLER(46, ZEND_JMPZ_EX, CONST|TMP|VAR|CV, ANY)
1936{
1937    USE_OPLINE
1938    zend_free_op free_op1;
1939    zval *val;
1940
1941    SAVE_OPLINE();
1942    val = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
1943
1944    if (OP1_TYPE == IS_TMP_VAR) {
1945        if (Z_TYPE_P(val) == IS_TRUE) {
1946            ZVAL_TRUE(EX_VAR(opline->result.var));
1947            ZEND_VM_SET_OPCODE(opline + 1);
1948            ZEND_VM_CONTINUE();
1949        } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
1950            ZVAL_FALSE(EX_VAR(opline->result.var));
1951            ZEND_VM_SET_OPCODE(opline->op2.jmp_addr);
1952            ZEND_VM_CONTINUE();
1953        }
1954    }
1955
1956    if (i_zend_is_true(val TSRMLS_CC)) {
1957        FREE_OP1();
1958        ZVAL_TRUE(EX_VAR(opline->result.var));
1959        opline++;
1960    } else {
1961        FREE_OP1();
1962        ZVAL_FALSE(EX_VAR(opline->result.var));
1963        opline = opline->op2.jmp_addr;
1964    }
1965    if (UNEXPECTED(EG(exception) != NULL)) {
1966        HANDLE_EXCEPTION();
1967    }
1968    ZEND_VM_JMP(opline);
1969}
1970
1971ZEND_VM_HANDLER(47, ZEND_JMPNZ_EX, CONST|TMP|VAR|CV, ANY)
1972{
1973    USE_OPLINE
1974    zend_free_op free_op1;
1975    zval *val;
1976
1977    SAVE_OPLINE();
1978    val = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
1979
1980    if (OP1_TYPE == IS_TMP_VAR) {
1981        if (Z_TYPE_P(val) == IS_TRUE) {
1982            ZVAL_TRUE(EX_VAR(opline->result.var));
1983            ZEND_VM_SET_OPCODE(opline->op2.jmp_addr);
1984            ZEND_VM_CONTINUE();
1985        } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
1986            ZVAL_FALSE(EX_VAR(opline->result.var));
1987            ZEND_VM_SET_OPCODE(opline + 1);
1988            ZEND_VM_CONTINUE();
1989        }
1990    }
1991    if (i_zend_is_true(val TSRMLS_CC)) {
1992        ZVAL_TRUE(EX_VAR(opline->result.var));
1993        opline = opline->op2.jmp_addr;
1994    } else {
1995        ZVAL_FALSE(EX_VAR(opline->result.var));
1996        opline++;
1997    }
1998    FREE_OP1();
1999    if (UNEXPECTED(EG(exception) != NULL)) {
2000        HANDLE_EXCEPTION();
2001    }
2002    ZEND_VM_JMP(opline);
2003}
2004
2005ZEND_VM_HANDLER(70, ZEND_FREE, TMP|VAR, ANY)
2006{
2007    USE_OPLINE
2008
2009    SAVE_OPLINE();
2010    zval_ptr_dtor_nogc(EX_VAR(opline->op1.var));
2011    CHECK_EXCEPTION();
2012    ZEND_VM_NEXT_OPCODE();
2013}
2014
2015ZEND_VM_HANDLER(54, ZEND_ADD_CHAR, TMP|UNUSED, CONST)
2016{
2017    USE_OPLINE
2018    zval *str = EX_VAR(opline->result.var);
2019
2020    SAVE_OPLINE();
2021
2022    if (OP1_TYPE == IS_UNUSED) {
2023        /* Initialize for erealloc in add_char_to_string */
2024        ZVAL_EMPTY_STRING(str);
2025    }
2026
2027    add_char_to_string(str, str, opline->op2.zv);
2028
2029    /* FREE_OP is missing intentionally here - we're always working on the same temporary variable */
2030    /*CHECK_EXCEPTION();*/
2031    ZEND_VM_NEXT_OPCODE();
2032}
2033
2034ZEND_VM_HANDLER(55, ZEND_ADD_STRING, TMP|UNUSED, CONST)
2035{
2036    USE_OPLINE
2037    zval *str = EX_VAR(opline->result.var);
2038
2039    SAVE_OPLINE();
2040
2041    if (OP1_TYPE == IS_UNUSED) {
2042        /* Initialize for erealloc in add_string_to_string */
2043        ZVAL_EMPTY_STRING(str);
2044    }
2045
2046    add_string_to_string(str, str, opline->op2.zv);
2047
2048    /* FREE_OP is missing intentionally here - we're always working on the same temporary variable */
2049    /*CHECK_EXCEPTION();*/
2050    ZEND_VM_NEXT_OPCODE();
2051}
2052
2053ZEND_VM_HANDLER(56, ZEND_ADD_VAR, TMP|UNUSED, TMP|VAR|CV)
2054{
2055    USE_OPLINE
2056    zend_free_op free_op2;
2057    zval *str = EX_VAR(opline->result.var);
2058    zval *var;
2059    zval var_copy;
2060    int use_copy = 0;
2061
2062    SAVE_OPLINE();
2063    var = GET_OP2_ZVAL_PTR(BP_VAR_R);
2064
2065    if (OP1_TYPE == IS_UNUSED) {
2066        /* Initialize for erealloc in add_string_to_string */
2067        ZVAL_EMPTY_STRING(str);
2068    }
2069
2070    if (Z_TYPE_P(var) != IS_STRING) {
2071        ZVAL_DEREF(var);
2072        if (Z_TYPE_P(var) != IS_STRING) {
2073            use_copy = zend_make_printable_zval(var, &var_copy TSRMLS_CC);
2074
2075            if (use_copy) {
2076                var = &var_copy;
2077            }
2078        }
2079    }
2080    add_string_to_string(str, str, var);
2081
2082    if (use_copy) {
2083        zend_string_release(Z_STR_P(var));
2084    }
2085    /* original comment, possibly problematic:
2086     * FREE_OP is missing intentionally here - we're always working on the same temporary variable
2087     * (Zeev):  I don't think it's problematic, we only use variables
2088     * which aren't affected by FREE_OP(Ts, )'s anyway, unless they're
2089     * string offsets or overloaded objects
2090     */
2091    FREE_OP2();
2092
2093    CHECK_EXCEPTION();
2094    ZEND_VM_NEXT_OPCODE();
2095}
2096
2097ZEND_VM_HANDLER(109, ZEND_FETCH_CLASS, ANY, CONST|TMP|VAR|UNUSED|CV)
2098{
2099    USE_OPLINE
2100
2101    SAVE_OPLINE();
2102    if (EG(exception)) {
2103        zend_exception_save(TSRMLS_C);
2104    }
2105    if (OP2_TYPE == IS_UNUSED) {
2106        Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class(NULL, opline->extended_value TSRMLS_CC);
2107        CHECK_EXCEPTION();
2108        ZEND_VM_NEXT_OPCODE();
2109    } else {
2110        zend_free_op free_op2;
2111        zval *class_name = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
2112
2113        if (OP2_TYPE == IS_CONST) {
2114            if (CACHED_PTR(Z_CACHE_SLOT_P(class_name))) {
2115                Z_CE_P(EX_VAR(opline->result.var)) = CACHED_PTR(Z_CACHE_SLOT_P(class_name));
2116            } else {
2117                Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class_by_name(Z_STR_P(class_name), opline->op2.zv + 1, opline->extended_value TSRMLS_CC);
2118                CACHE_PTR(Z_CACHE_SLOT_P(class_name), Z_CE_P(EX_VAR(opline->result.var)));
2119            }
2120        } else if (Z_TYPE_P(class_name) == IS_OBJECT) {
2121            Z_CE_P(EX_VAR(opline->result.var)) = Z_OBJCE_P(class_name);
2122        } else if (Z_TYPE_P(class_name) == IS_STRING) {
2123            Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class(Z_STR_P(class_name), opline->extended_value TSRMLS_CC);
2124        } else {
2125            if (UNEXPECTED(EG(exception) != NULL)) {
2126                HANDLE_EXCEPTION();
2127            }
2128            zend_error_noreturn(E_ERROR, "Class name must be a valid object or a string");
2129        }
2130
2131        FREE_OP2();
2132        CHECK_EXCEPTION();
2133        ZEND_VM_NEXT_OPCODE();
2134    }
2135}
2136
2137ZEND_VM_HANDLER(112, ZEND_INIT_METHOD_CALL, TMP|VAR|UNUSED|CV, CONST|TMP|VAR|CV)
2138{
2139    USE_OPLINE
2140    zval *function_name;
2141    zend_free_op free_op1, free_op2;
2142    zval *object;
2143    zend_function *fbc;
2144    zend_class_entry *called_scope;
2145    zend_object *obj;
2146
2147    SAVE_OPLINE();
2148
2149    function_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2150
2151    if (OP2_TYPE != IS_CONST &&
2152        UNEXPECTED(Z_TYPE_P(function_name) != IS_STRING)) {
2153        if (UNEXPECTED(EG(exception) != NULL)) {
2154            HANDLE_EXCEPTION();
2155        }
2156        zend_error_noreturn(E_ERROR, "Method name must be a string");
2157    }
2158
2159    object = GET_OP1_OBJ_ZVAL_PTR_DEREF(BP_VAR_R);
2160
2161    if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
2162        uint32_t nesting = 1;
2163
2164        if (UNEXPECTED(EG(exception) != NULL)) {
2165            FREE_OP2();
2166            HANDLE_EXCEPTION();
2167        }
2168
2169        zend_error(E_RECOVERABLE_ERROR, "Call to a member function %s() on %s",  Z_STRVAL_P(function_name), zend_get_type_by_const(Z_TYPE_P(object)));
2170        FREE_OP2();
2171        FREE_OP1_IF_VAR();
2172
2173        if (EG(exception) != NULL) {
2174            HANDLE_EXCEPTION();
2175        }
2176
2177        /* No exception raised: Skip over arguments until fcall opcode with correct
2178         * nesting level. Return NULL (except when return value unused) */
2179        do {
2180            opline++;
2181            if (opline->opcode == ZEND_INIT_FCALL ||
2182                opline->opcode == ZEND_INIT_FCALL_BY_NAME ||
2183                opline->opcode == ZEND_INIT_NS_FCALL_BY_NAME ||
2184                opline->opcode == ZEND_INIT_METHOD_CALL ||
2185                opline->opcode == ZEND_INIT_STATIC_METHOD_CALL ||
2186                opline->opcode == ZEND_INIT_USER_CALL ||
2187                opline->opcode == ZEND_NEW
2188            ) {
2189                nesting++;
2190            } else if (opline->opcode == ZEND_DO_FCALL) {
2191                nesting--;
2192            }
2193        } while (nesting);
2194
2195        if (RETURN_VALUE_USED(opline)) {
2196            ZVAL_NULL(EX_VAR(opline->result.var));
2197        }
2198
2199        /* We've skipped EXT_FCALL_BEGIND, so also skip the ending opcode */
2200        if ((opline + 1)->opcode == ZEND_EXT_FCALL_END) {
2201            opline++;
2202        }
2203        ZEND_VM_JMP(++opline);
2204    }
2205
2206    obj = Z_OBJ_P(object);
2207    called_scope = obj->ce;
2208
2209    if (OP2_TYPE != IS_CONST ||
2210        EXPECTED((fbc = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), called_scope)) == NULL)) {
2211        zend_object *orig_obj = obj;
2212
2213        if (UNEXPECTED(obj->handlers->get_method == NULL)) {
2214            zend_error_noreturn(E_ERROR, "Object does not support method calls");
2215        }
2216
2217        /* First, locate the function. */
2218        fbc = obj->handlers->get_method(&obj, Z_STR_P(function_name), ((OP2_TYPE == IS_CONST) ? (opline->op2.zv + 1) : NULL) TSRMLS_CC);
2219        if (UNEXPECTED(fbc == NULL)) {
2220            zend_error_noreturn(E_ERROR, "Call to undefined method %s::%s()", obj->ce->name->val, Z_STRVAL_P(function_name));
2221        }
2222        if (OP2_TYPE == IS_CONST &&
2223            EXPECTED(fbc->type <= ZEND_USER_FUNCTION) &&
2224            EXPECTED((fbc->common.fn_flags & (ZEND_ACC_CALL_VIA_HANDLER|ZEND_ACC_NEVER_CACHE)) == 0) &&
2225            EXPECTED(obj == orig_obj)) {
2226            CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), called_scope, fbc);
2227        }
2228    }
2229
2230    if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_STATIC) != 0)) {
2231        obj = NULL;
2232    } else {
2233        GC_REFCOUNT(obj)++; /* For $this pointer */
2234    }
2235
2236    EX(call) = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
2237        fbc, opline->extended_value, called_scope, obj, EX(call) TSRMLS_CC);
2238
2239    FREE_OP2();
2240    FREE_OP1_IF_VAR();
2241
2242    CHECK_EXCEPTION();
2243    ZEND_VM_NEXT_OPCODE();
2244}
2245
2246ZEND_VM_HANDLER(113, ZEND_INIT_STATIC_METHOD_CALL, CONST|VAR, CONST|TMP|VAR|UNUSED|CV)
2247{
2248    USE_OPLINE
2249    zval *function_name;
2250    zend_class_entry *ce;
2251    zend_object *object;
2252    zend_function *fbc;
2253
2254    SAVE_OPLINE();
2255
2256    if (OP1_TYPE == IS_CONST) {
2257        /* no function found. try a static method in class */
2258        if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op1.zv))) {
2259            ce = CACHED_PTR(Z_CACHE_SLOT_P(opline->op1.zv));
2260        } else {
2261            ce = zend_fetch_class_by_name(Z_STR_P(opline->op1.zv), opline->op1.zv + 1, ZEND_FETCH_CLASS_DEFAULT TSRMLS_CC);
2262            if (UNEXPECTED(EG(exception) != NULL)) {
2263                HANDLE_EXCEPTION();
2264            }
2265            if (UNEXPECTED(ce == NULL)) {
2266                zend_error_noreturn(E_ERROR, "Class '%s' not found", Z_STRVAL_P(opline->op1.zv));
2267            }
2268            CACHE_PTR(Z_CACHE_SLOT_P(opline->op1.zv), ce);
2269        }
2270    } else {
2271        ce = Z_CE_P(EX_VAR(opline->op1.var));
2272    }
2273
2274    if (OP1_TYPE == IS_CONST &&
2275        OP2_TYPE == IS_CONST &&
2276        CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv))) {
2277        fbc = CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv));
2278    } else if (OP1_TYPE != IS_CONST &&
2279               OP2_TYPE == IS_CONST &&
2280               (fbc = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(opline->op2.zv), ce))) {
2281        /* do nothing */
2282    } else if (OP2_TYPE != IS_UNUSED) {
2283        zend_free_op free_op2;
2284
2285        function_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2286        if (OP2_TYPE != IS_CONST) {
2287            if (UNEXPECTED(Z_TYPE_P(function_name) != IS_STRING)) {
2288                if (UNEXPECTED(EG(exception) != NULL)) {
2289                    HANDLE_EXCEPTION();
2290                }
2291                zend_error_noreturn(E_ERROR, "Function name must be a string");
2292            }
2293        }
2294
2295        if (ce->get_static_method) {
2296            fbc = ce->get_static_method(ce, Z_STR_P(function_name) TSRMLS_CC);
2297        } else {
2298            fbc = zend_std_get_static_method(ce, Z_STR_P(function_name), ((OP2_TYPE == IS_CONST) ? (opline->op2.zv + 1) : NULL) TSRMLS_CC);
2299        }
2300        if (UNEXPECTED(fbc == NULL)) {
2301            zend_error_noreturn(E_ERROR, "Call to undefined method %s::%s()", ce->name->val, Z_STRVAL_P(function_name));
2302        }
2303        if (OP2_TYPE == IS_CONST &&
2304            EXPECTED(fbc->type <= ZEND_USER_FUNCTION) &&
2305            EXPECTED((fbc->common.fn_flags & (ZEND_ACC_CALL_VIA_HANDLER|ZEND_ACC_NEVER_CACHE)) == 0)) {
2306            if (OP1_TYPE == IS_CONST) {
2307                CACHE_PTR(Z_CACHE_SLOT_P(function_name), fbc);
2308            } else {
2309                CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), ce, fbc);
2310            }
2311        }
2312        if (OP2_TYPE != IS_CONST) {
2313            FREE_OP2();
2314        }
2315    } else {
2316        if (UNEXPECTED(ce->constructor == NULL)) {
2317            zend_error_noreturn(E_ERROR, "Cannot call constructor");
2318        }
2319        if (Z_OBJ(EX(This)) && Z_OBJ(EX(This))->ce != ce->constructor->common.scope && (ce->constructor->common.fn_flags & ZEND_ACC_PRIVATE)) {
2320            zend_error_noreturn(E_ERROR, "Cannot call private %s::__construct()", ce->name->val);
2321        }
2322        fbc = ce->constructor;
2323    }
2324
2325    object = NULL;
2326    if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
2327        if (Z_OBJ(EX(This))) {
2328            object = Z_OBJ(EX(This));
2329            GC_REFCOUNT(object)++;
2330        }
2331        if (!object ||
2332            !instanceof_function(object->ce, ce TSRMLS_CC)) {
2333            /* We are calling method of the other (incompatible) class,
2334               but passing $this. This is done for compatibility with php-4. */
2335            if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
2336                zend_error(
2337                    object ? E_DEPRECATED : E_STRICT,
2338                    "Non-static method %s::%s() should not be called statically%s",
2339                    fbc->common.scope->name->val, fbc->common.function_name->val,
2340                    object ? ", assuming $this from incompatible context" : "");
2341            } else {
2342                /* An internal function assumes $this is present and won't check that. So PHP would crash by allowing the call. */
2343                zend_error_noreturn(
2344                    E_ERROR,
2345                    "Non-static method %s::%s() cannot be called statically%s",
2346                    fbc->common.scope->name->val, fbc->common.function_name->val,
2347                    object ? ", assuming $this from incompatible context" : "");
2348            }
2349        }
2350    }
2351
2352    if (OP1_TYPE != IS_CONST) {
2353        /* previous opcode is ZEND_FETCH_CLASS */
2354        if ((opline-1)->extended_value == ZEND_FETCH_CLASS_PARENT || (opline-1)->extended_value == ZEND_FETCH_CLASS_SELF) {
2355            ce = EX(called_scope);
2356        }
2357    }
2358
2359    EX(call) = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
2360        fbc, opline->extended_value, ce, object, EX(call) TSRMLS_CC);
2361
2362    if (OP2_TYPE == IS_UNUSED) {
2363        EX(call)->return_value = NULL;
2364    }
2365
2366    CHECK_EXCEPTION();
2367    ZEND_VM_NEXT_OPCODE();
2368}
2369
2370ZEND_VM_HANDLER(59, ZEND_INIT_FCALL_BY_NAME, ANY, CONST|TMP|VAR|CV)
2371{
2372    USE_OPLINE
2373    zend_function *fbc;
2374    zval *function_name, *func;
2375
2376    if (OP2_TYPE == IS_CONST && Z_TYPE_P(opline->op2.zv) == IS_STRING) {
2377        function_name = (zval*)(opline->op2.zv+1);
2378        if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv))) {
2379            fbc = CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv));
2380        } else if (UNEXPECTED((func = zend_hash_find(EG(function_table), Z_STR_P(function_name))) == NULL)) {
2381            SAVE_OPLINE();
2382            zend_error_noreturn(E_ERROR, "Call to undefined function %s()", Z_STRVAL_P(opline->op2.zv));
2383        } else {
2384            fbc = Z_FUNC_P(func);
2385            CACHE_PTR(Z_CACHE_SLOT_P(opline->op2.zv), fbc);
2386        }
2387
2388        EX(call) = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
2389            fbc, opline->extended_value, NULL, NULL, EX(call) TSRMLS_CC);
2390
2391        /*CHECK_EXCEPTION();*/
2392        ZEND_VM_NEXT_OPCODE();
2393    } else {
2394        zend_string *lcname;
2395        zend_free_op free_op2;
2396        zend_class_entry *called_scope;
2397        zend_object *object;
2398        zval *function_name_ptr;
2399
2400        SAVE_OPLINE();
2401        function_name_ptr = function_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2402
2403        ZVAL_DEREF(function_name);
2404        if (EXPECTED(Z_TYPE_P(function_name) == IS_STRING)) {
2405            if (Z_STRVAL_P(function_name)[0] == '\\') {
2406                lcname = zend_string_alloc(Z_STRLEN_P(function_name) - 1, 0);
2407                zend_str_tolower_copy(lcname->val, Z_STRVAL_P(function_name) + 1, Z_STRLEN_P(function_name) - 1);
2408            } else {
2409                lcname = zend_string_alloc(Z_STRLEN_P(function_name), 0);
2410                zend_str_tolower_copy(lcname->val, Z_STRVAL_P(function_name), Z_STRLEN_P(function_name));
2411            }
2412            if (UNEXPECTED((func = zend_hash_find(EG(function_table), lcname)) == NULL)) {
2413                zend_error_noreturn(E_ERROR, "Call to undefined function %s()", Z_STRVAL_P(function_name));
2414            }
2415            zend_string_free(lcname);
2416            FREE_OP2();
2417
2418            fbc = Z_FUNC_P(func);
2419            called_scope = NULL;
2420            object = NULL;
2421        } else if (OP2_TYPE != IS_CONST &&
2422            EXPECTED(Z_TYPE_P(function_name) == IS_OBJECT) &&
2423            Z_OBJ_HANDLER_P(function_name, get_closure) &&
2424            Z_OBJ_HANDLER_P(function_name, get_closure)(function_name, &called_scope, &fbc, &object TSRMLS_CC) == SUCCESS) {
2425            if (object) {
2426                GC_REFCOUNT(object)++;
2427            }
2428            if (OP2_TYPE == IS_VAR && OP2_FREE && Z_REFCOUNT_P(function_name) == 1 &&
2429                fbc->common.fn_flags & ZEND_ACC_CLOSURE) {
2430                /* Delay closure destruction until its invocation */
2431                fbc->common.prototype = (zend_function*)Z_OBJ_P(function_name_ptr);
2432            } else if (OP2_TYPE == IS_CV) {
2433                FREE_OP2();
2434            }
2435        } else if (EXPECTED(Z_TYPE_P(function_name) == IS_ARRAY) &&
2436                zend_hash_num_elements(Z_ARRVAL_P(function_name)) == 2) {
2437            zval *obj;
2438            zval *method;
2439
2440            obj = zend_hash_index_find(Z_ARRVAL_P(function_name), 0);
2441            method = zend_hash_index_find(Z_ARRVAL_P(function_name), 1);
2442
2443            if (!obj || !method) {
2444                zend_error_noreturn(E_ERROR, "Array callback has to contain indices 0 and 1");
2445            }
2446
2447            ZVAL_DEREF(obj);
2448            if (Z_TYPE_P(obj) != IS_STRING && Z_TYPE_P(obj) != IS_OBJECT) {
2449                zend_error_noreturn(E_ERROR, "First array member is not a valid class name or object");
2450            }
2451
2452            ZVAL_DEREF(method);
2453            if (Z_TYPE_P(method) != IS_STRING) {
2454                zend_error_noreturn(E_ERROR, "Second array member is not a valid method");
2455            }
2456
2457            if (Z_TYPE_P(obj) == IS_STRING) {
2458                object = NULL;
2459                called_scope = zend_fetch_class_by_name(Z_STR_P(obj), NULL, 0 TSRMLS_CC);
2460                if (UNEXPECTED(called_scope == NULL)) {
2461                    CHECK_EXCEPTION();
2462                    ZEND_VM_NEXT_OPCODE();
2463                }
2464
2465                if (called_scope->get_static_method) {
2466                    fbc = called_scope->get_static_method(called_scope, Z_STR_P(method) TSRMLS_CC);
2467                } else {
2468                    fbc = zend_std_get_static_method(called_scope, Z_STR_P(method), NULL TSRMLS_CC);
2469                }
2470                if (UNEXPECTED(fbc == NULL)) {
2471                    zend_error_noreturn(E_ERROR, "Call to undefined method %s::%s()", called_scope->name->val, Z_STRVAL_P(method));
2472                }
2473                if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
2474                    if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
2475                        zend_error(E_STRICT,
2476                        "Non-static method %s::%s() should not be called statically",
2477                        fbc->common.scope->name->val, fbc->common.function_name->val);
2478                    } else {
2479                        zend_error_noreturn(
2480                            E_ERROR,
2481                            "Non-static method %s::%s() cannot be called statically",
2482                            fbc->common.scope->name->val, fbc->common.function_name->val);
2483                    }
2484                }
2485            } else {
2486                called_scope = Z_OBJCE_P(obj);
2487                object = Z_OBJ_P(obj);
2488
2489                fbc = Z_OBJ_HT_P(obj)->get_method(&object, Z_STR_P(method), NULL TSRMLS_CC);
2490                if (UNEXPECTED(fbc == NULL)) {
2491                    zend_error_noreturn(E_ERROR, "Call to undefined method %s::%s()", object->ce->name->val, Z_STRVAL_P(method));
2492                }
2493
2494                if ((fbc->common.fn_flags & ZEND_ACC_STATIC) != 0) {
2495                    object = NULL;
2496                } else {
2497                    GC_REFCOUNT(object)++; /* For $this pointer */
2498                }
2499            }
2500            FREE_OP2();
2501        } else {
2502            if (UNEXPECTED(EG(exception) != NULL)) {
2503                HANDLE_EXCEPTION();
2504            }
2505            zend_error_noreturn(E_ERROR, "Function name must be a string");
2506            ZEND_VM_CONTINUE(); /* Never reached */
2507        }
2508        EX(call) = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
2509            fbc, opline->extended_value, called_scope, object, EX(call) TSRMLS_CC);
2510
2511        CHECK_EXCEPTION();
2512        ZEND_VM_NEXT_OPCODE();
2513    }
2514}
2515
2516ZEND_VM_HANDLER(118, ZEND_INIT_USER_CALL, CONST, CONST|TMP|VAR|CV)
2517{
2518    USE_OPLINE
2519    zend_free_op free_op2;
2520    zval *function_name = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
2521    zend_fcall_info_cache fcc;
2522    char *error = NULL;
2523    zend_function *func;
2524    zend_class_entry *called_scope;
2525    zend_object *object;
2526
2527    if (zend_is_callable_ex(function_name, NULL, 0, NULL, &fcc, &error TSRMLS_CC)) {
2528        if (error) {
2529            efree(error);
2530        }
2531        func = fcc.function_handler;
2532        if (func->common.fn_flags & ZEND_ACC_CLOSURE) {
2533            /* Delay closure destruction until its invocation */
2534            func->common.prototype = (zend_function*)Z_OBJ_P(function_name);
2535            Z_ADDREF_P(function_name);
2536        }
2537        called_scope = fcc.called_scope;
2538        object = fcc.object;
2539        if (object) {
2540            GC_REFCOUNT(object)++; /* For $this pointer */
2541        } else if (func->common.scope &&
2542                   !(func->common.fn_flags & ZEND_ACC_STATIC)) {
2543            if (func->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
2544                zend_error(E_STRICT,
2545                "Non-static method %s::%s() should not be called statically",
2546                func->common.scope->name->val, func->common.function_name->val);
2547            } else {
2548                zend_error_noreturn(
2549                    E_ERROR,
2550                    "Non-static method %s::%s() cannot be called statically",
2551                    func->common.scope->name->val, func->common.function_name->val);
2552            }
2553        }
2554    } else {
2555        zend_error(E_WARNING, "%s() expects parameter 1 to be a valid callback, %s", Z_STRVAL_P(opline->op1.zv), error);
2556        efree(error);
2557        func = (zend_function*)&zend_pass_function;
2558        called_scope = NULL;
2559        object = NULL;
2560    }
2561
2562    EX(call) = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
2563        func, opline->extended_value, called_scope, object, EX(call) TSRMLS_CC);
2564
2565    FREE_OP2();
2566    CHECK_EXCEPTION();
2567    ZEND_VM_NEXT_OPCODE();
2568}
2569
2570ZEND_VM_HANDLER(69, ZEND_INIT_NS_FCALL_BY_NAME, ANY, CONST)
2571{
2572    USE_OPLINE
2573    zval *func_name;
2574    zval *func;
2575    zend_function *fbc;
2576
2577    func_name = opline->op2.zv + 1;
2578    if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv))) {
2579        fbc = CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv));
2580    } else if ((func = zend_hash_find(EG(function_table), Z_STR_P(func_name))) == NULL) {
2581        func_name++;
2582        if (UNEXPECTED((func = zend_hash_find(EG(function_table), Z_STR_P(func_name))) == NULL)) {
2583            SAVE_OPLINE();
2584            zend_error_noreturn(E_ERROR, "Call to undefined function %s()", Z_STRVAL_P(opline->op2.zv));
2585        } else {
2586            fbc = Z_FUNC_P(func);
2587            CACHE_PTR(Z_CACHE_SLOT_P(opline->op2.zv), fbc);
2588        }
2589    } else {
2590        fbc = Z_FUNC_P(func);
2591        CACHE_PTR(Z_CACHE_SLOT_P(opline->op2.zv), fbc);
2592    }
2593
2594    EX(call) = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
2595        fbc, opline->extended_value, NULL, NULL, EX(call) TSRMLS_CC);
2596
2597    ZEND_VM_NEXT_OPCODE();
2598}
2599
2600ZEND_VM_HANDLER(61, ZEND_INIT_FCALL, ANY, CONST)
2601{
2602    USE_OPLINE
2603    zend_free_op free_op2;
2604    zval *fname = GET_OP2_ZVAL_PTR(BP_VAR_R);
2605    zval *func;
2606    zend_function *fbc;
2607
2608    if (CACHED_PTR(Z_CACHE_SLOT_P(fname))) {
2609        fbc = CACHED_PTR(Z_CACHE_SLOT_P(fname));
2610    } else if (UNEXPECTED((func = zend_hash_find(EG(function_table), Z_STR_P(fname))) == NULL)) {
2611        SAVE_OPLINE();
2612        zend_error_noreturn(E_ERROR, "Call to undefined function %s()", Z_STRVAL_P(fname));
2613    } else {
2614        fbc = Z_FUNC_P(func);
2615        CACHE_PTR(Z_CACHE_SLOT_P(fname), fbc);
2616    }
2617
2618    EX(call) = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
2619        fbc, opline->extended_value, NULL, NULL, EX(call) TSRMLS_CC);
2620
2621    FREE_OP2();
2622
2623    ZEND_VM_NEXT_OPCODE();
2624}
2625
2626ZEND_VM_HANDLER(60, ZEND_DO_FCALL, ANY, ANY)
2627{
2628    USE_OPLINE
2629    zend_execute_data *call = EX(call);
2630    zend_function *fbc = call->func;
2631    zend_object *object = Z_OBJ(call->This);
2632
2633    SAVE_OPLINE();
2634    EX(call) = call->prev_execute_data;
2635    if (UNEXPECTED((fbc->common.fn_flags & (ZEND_ACC_ABSTRACT|ZEND_ACC_DEPRECATED)) != 0)) {
2636        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_ABSTRACT) != 0)) {
2637            zend_error_noreturn(E_ERROR, "Cannot call abstract method %s::%s()", fbc->common.scope->name->val, fbc->common.function_name->val);
2638        }
2639        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_DEPRECATED) != 0)) {
2640            zend_error(E_DEPRECATED, "Function %s%s%s() is deprecated",
2641                fbc->common.scope ? fbc->common.scope->name->val : "",
2642                fbc->common.scope ? "::" : "",
2643                fbc->common.function_name->val);
2644            if (UNEXPECTED(EG(exception) != NULL)) {
2645                HANDLE_EXCEPTION();
2646            }
2647        }
2648    }
2649
2650    LOAD_OPLINE();
2651
2652    if (UNEXPECTED(fbc->type == ZEND_INTERNAL_FUNCTION)) {
2653        int should_change_scope = 0;
2654        zval *ret;
2655
2656        if (fbc->common.scope) {
2657            should_change_scope = 1;
2658            /* TODO: we don't set scope if we call an object method ??? */
2659            /* See: ext/pdo_sqlite/tests/pdo_fetch_func_001.phpt */
2660#if 1
2661            EG(scope) = object ? NULL : fbc->common.scope;
2662#else
2663            EG(scope) = fbc->common.scope;
2664#endif
2665        } else {
2666            call->called_scope = EX(called_scope);
2667            Z_OBJ(call->This) = Z_OBJ(EX(This));
2668        }
2669
2670        call->prev_execute_data = execute_data;
2671        EG(current_execute_data) = call;
2672
2673        if (fbc->common.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) {
2674            uint32_t i;
2675            zval *p = ZEND_CALL_ARG(call, 1);
2676
2677            for (i = 0; i < ZEND_CALL_NUM_ARGS(call); ++i) {
2678                zend_verify_arg_type(fbc, i + 1, p, NULL TSRMLS_CC);
2679                p++;
2680            }
2681            if (UNEXPECTED(EG(exception) != NULL)) {
2682                EG(current_execute_data) = call->prev_execute_data;
2683                zend_vm_stack_free_args(call TSRMLS_CC);
2684                zend_vm_stack_free_call_frame(call TSRMLS_CC);
2685                if (RETURN_VALUE_USED(opline)) {
2686                    ZVAL_UNDEF(EX_VAR(opline->result.var));
2687                }
2688                if (UNEXPECTED(should_change_scope)) {
2689                    ZEND_VM_C_GOTO(fcall_end_change_scope);
2690                } else {
2691                    ZEND_VM_C_GOTO(fcall_end);
2692                }
2693            }
2694        }
2695
2696        ret = EX_VAR(opline->result.var);
2697        ZVAL_NULL(ret);
2698        Z_VAR_FLAGS_P(ret) = (fbc->common.fn_flags & ZEND_ACC_RETURN_REFERENCE) != 0 ? IS_VAR_RET_REF : 0;
2699
2700        if (!zend_execute_internal) {
2701            /* saves one function call if zend_execute_internal is not used */
2702            fbc->internal_function.handler(call, ret TSRMLS_CC);
2703        } else {
2704            zend_execute_internal(call, ret TSRMLS_CC);
2705        }
2706        EG(current_execute_data) = call->prev_execute_data;
2707        zend_vm_stack_free_args(call TSRMLS_CC);
2708        zend_vm_stack_free_call_frame(call TSRMLS_CC);
2709
2710        if (!RETURN_VALUE_USED(opline)) {
2711            zval_ptr_dtor(ret);
2712        }
2713
2714        if (UNEXPECTED(should_change_scope)) {
2715            ZEND_VM_C_GOTO(fcall_end_change_scope);
2716        } else {
2717            ZEND_VM_C_GOTO(fcall_end);
2718        }
2719    } else if (EXPECTED(fbc->type == ZEND_USER_FUNCTION)) {
2720        EG(scope) = fbc->common.scope;
2721        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_GENERATOR) != 0)) {
2722            if (RETURN_VALUE_USED(opline)) {
2723                zend_generator_create_zval(call, &fbc->op_array, EX_VAR(opline->result.var) TSRMLS_CC);
2724            } else {
2725                zend_vm_stack_free_args(call TSRMLS_CC);
2726            }
2727
2728            zend_vm_stack_free_call_frame(call TSRMLS_CC);
2729        } else {
2730            zval *return_value = NULL;
2731
2732            call->symbol_table = NULL;
2733            if (RETURN_VALUE_USED(opline)) {
2734                return_value = EX_VAR(opline->result.var);
2735
2736                ZVAL_NULL(return_value);
2737                Z_VAR_FLAGS_P(return_value) = 0;
2738            }
2739
2740            call->prev_execute_data = execute_data;
2741            i_init_func_execute_data(call, &fbc->op_array, return_value TSRMLS_CC);
2742
2743            if (EXPECTED(zend_execute_ex == execute_ex)) {
2744                ZEND_VM_ENTER();
2745            } else {
2746                ZEND_ADD_CALL_FLAG(call, ZEND_CALL_TOP);
2747                zend_execute_ex(call TSRMLS_CC);
2748            }
2749        }
2750    } else { /* ZEND_OVERLOADED_FUNCTION */
2751        EG(scope) = fbc->common.scope;
2752
2753        ZVAL_NULL(EX_VAR(opline->result.var));
2754
2755        /* Not sure what should be done here if it's a static method */
2756        if (EXPECTED(object != NULL)) {
2757            call->prev_execute_data = execute_data;
2758            EG(current_execute_data) = call;
2759            object->handlers->call_method(fbc->common.function_name, object, call, EX_VAR(opline->result.var) TSRMLS_CC);
2760            EG(current_execute_data) = call->prev_execute_data;
2761        } else {
2762            zend_error_noreturn(E_ERROR, "Cannot call overloaded function for non-object");
2763        }
2764
2765        zend_vm_stack_free_args(call TSRMLS_CC);
2766
2767        zend_vm_stack_free_call_frame(call TSRMLS_CC);
2768
2769        if (fbc->type == ZEND_OVERLOADED_FUNCTION_TEMPORARY) {
2770            zend_string_release(fbc->common.function_name);
2771        }
2772        efree(fbc);
2773
2774        if (!RETURN_VALUE_USED(opline)) {
2775            zval_ptr_dtor(EX_VAR(opline->result.var));
2776        } else {
2777//???           Z_UNSET_ISREF_P(EX_T(opline->result.var).var.ptr);
2778//???           Z_SET_REFCOUNT_P(EX_T(opline->result.var).var.ptr, 1);
2779            Z_VAR_FLAGS_P(EX_VAR(opline->result.var)) = 0;
2780        }
2781    }
2782
2783ZEND_VM_C_LABEL(fcall_end_change_scope):
2784    if (object) {
2785        if (UNEXPECTED(EG(exception) != NULL) && (opline->op1.num & ZEND_CALL_CTOR)) {
2786            if (!(opline->op1.num & ZEND_CALL_CTOR_RESULT_UNUSED)) {
2787                GC_REFCOUNT(object)--;
2788            }
2789            if (GC_REFCOUNT(object) == 1) {
2790                zend_object_store_ctor_failed(object TSRMLS_CC);
2791            }
2792        }
2793        OBJ_RELEASE(object);
2794    }
2795    EG(scope) = EX(func)->op_array.scope;
2796
2797ZEND_VM_C_LABEL(fcall_end):
2798    if (UNEXPECTED(EG(exception) != NULL)) {
2799        zend_throw_exception_internal(NULL TSRMLS_CC);
2800        if (RETURN_VALUE_USED(opline)) {
2801            zval_ptr_dtor(EX_VAR(opline->result.var));
2802        }
2803        HANDLE_EXCEPTION();
2804    }
2805
2806    ZEND_VM_NEXT_OPCODE();
2807}
2808
2809ZEND_VM_HANDLER(62, ZEND_RETURN, CONST|TMP|VAR|CV, ANY)
2810{
2811    USE_OPLINE
2812    zval *retval_ptr;
2813    zend_free_op free_op1;
2814
2815    SAVE_OPLINE();
2816    retval_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
2817
2818    if (!EX(return_value)) {
2819        FREE_OP1();
2820    } else {
2821        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
2822            ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
2823            if (OP1_TYPE == IS_CONST) {
2824                if (UNEXPECTED(Z_OPT_COPYABLE_P(EX(return_value)))) {
2825                    zval_copy_ctor_func(EX(return_value));
2826                }
2827            }
2828        } else if ((OP1_TYPE == IS_CV || OP1_TYPE == IS_VAR) && Z_ISREF_P(retval_ptr)) {
2829            ZVAL_COPY(EX(return_value), Z_REFVAL_P(retval_ptr));
2830            FREE_OP1_IF_VAR();
2831        } else {
2832            ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
2833            if (OP1_TYPE == IS_CV) {
2834                if (Z_OPT_REFCOUNTED_P(retval_ptr)) Z_ADDREF_P(retval_ptr);
2835            }
2836        }
2837    }
2838    ZEND_VM_DISPATCH_TO_HELPER(zend_leave_helper);
2839}
2840
2841ZEND_VM_HANDLER(111, ZEND_RETURN_BY_REF, CONST|TMP|VAR|CV, ANY)
2842{
2843    USE_OPLINE
2844    zval *retval_ptr;
2845    zend_free_op free_op1;
2846
2847    SAVE_OPLINE();
2848
2849    do {
2850        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR ||
2851            (OP1_TYPE == IS_VAR && opline->extended_value == ZEND_RETURNS_VALUE)) {
2852            /* Not supposed to happen, but we'll allow it */
2853            zend_error(E_NOTICE, "Only variable references should be returned by reference");
2854
2855            retval_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
2856            if (!EX(return_value)) {
2857                if (OP1_TYPE == IS_TMP_VAR) {
2858                    FREE_OP1();
2859                }
2860            } else {
2861                ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
2862                Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
2863                if (OP1_TYPE != IS_TMP_VAR) {
2864                    zval_opt_copy_ctor_no_imm(EX(return_value));
2865                }
2866            }
2867            break;
2868        }
2869
2870        retval_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
2871
2872        if (OP1_TYPE == IS_VAR && UNEXPECTED(retval_ptr == NULL)) {
2873            zend_error_noreturn(E_ERROR, "Cannot return string offsets by reference");
2874        }
2875
2876        if (OP1_TYPE == IS_VAR) {
2877            if (retval_ptr == &EG(uninitialized_zval) ||
2878                (opline->extended_value == ZEND_RETURNS_FUNCTION &&
2879                 !(Z_VAR_FLAGS_P(retval_ptr) & IS_VAR_RET_REF))) {
2880                zend_error(E_NOTICE, "Only variable references should be returned by reference");
2881                if (EX(return_value)) {
2882                    ZVAL_NEW_REF(EX(return_value), retval_ptr);
2883                    Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
2884                    if (Z_REFCOUNTED_P(retval_ptr)) Z_ADDREF_P(retval_ptr);
2885                }
2886                break;
2887            }
2888        }
2889
2890        if (EX(return_value)) {
2891            ZVAL_MAKE_REF(retval_ptr);
2892            Z_ADDREF_P(retval_ptr);
2893            ZVAL_REF(EX(return_value), Z_REF_P(retval_ptr));
2894            Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
2895        }
2896    } while (0);
2897
2898    FREE_OP1_VAR_PTR();
2899    ZEND_VM_DISPATCH_TO_HELPER(zend_leave_helper);
2900}
2901
2902ZEND_VM_HANDLER(161, ZEND_GENERATOR_RETURN, ANY, ANY)
2903{
2904    /* The generator object is stored in EX(return_value) */
2905    zend_generator *generator = (zend_generator *) EX(return_value);
2906
2907    /* Close the generator to free up resources */
2908    zend_generator_close(generator, 1 TSRMLS_CC);
2909
2910    /* Pass execution back to handling code */
2911    ZEND_VM_RETURN();
2912}
2913
2914ZEND_VM_HANDLER(108, ZEND_THROW, CONST|TMP|VAR|CV, ANY)
2915{
2916    USE_OPLINE
2917    zval *value;
2918    zend_free_op free_op1;
2919
2920    SAVE_OPLINE();
2921    value = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
2922
2923    if (OP1_TYPE == IS_CONST || UNEXPECTED(Z_TYPE_P(value) != IS_OBJECT)) {
2924        if (UNEXPECTED(EG(exception) != NULL)) {
2925            HANDLE_EXCEPTION();
2926        }
2927        zend_error_noreturn(E_ERROR, "Can only throw objects");
2928    }
2929
2930    zend_exception_save(TSRMLS_C);
2931    if (OP1_TYPE != IS_TMP_VAR) {
2932        if (Z_REFCOUNTED_P(value)) Z_ADDREF_P(value);
2933    }
2934
2935    zend_throw_exception_object(value TSRMLS_CC);
2936    zend_exception_restore(TSRMLS_C);
2937    FREE_OP1_IF_VAR();
2938    HANDLE_EXCEPTION();
2939}
2940
2941ZEND_VM_HANDLER(107, ZEND_CATCH, CONST, CV)
2942{
2943    USE_OPLINE
2944    zend_class_entry *ce, *catch_ce;
2945    zend_object *exception;
2946
2947    SAVE_OPLINE();
2948    /* Check whether an exception has been thrown, if not, jump over code */
2949    zend_exception_restore(TSRMLS_C);
2950    if (EG(exception) == NULL) {
2951        ZEND_VM_SET_OPCODE(&EX(func)->op_array.opcodes[opline->extended_value]);
2952        ZEND_VM_CONTINUE(); /* CHECK_ME */
2953    }
2954    if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op1.zv))) {
2955        catch_ce = CACHED_PTR(Z_CACHE_SLOT_P(opline->op1.zv));
2956    } else {
2957        catch_ce = zend_fetch_class_by_name(Z_STR_P(opline->op1.zv), opline->op1.zv + 1, ZEND_FETCH_CLASS_NO_AUTOLOAD TSRMLS_CC);
2958
2959        CACHE_PTR(Z_CACHE_SLOT_P(opline->op1.zv), catch_ce);
2960    }
2961    ce = EG(exception)->ce;
2962
2963#ifdef HAVE_DTRACE
2964    if (DTRACE_EXCEPTION_CAUGHT_ENABLED()) {
2965        DTRACE_EXCEPTION_CAUGHT((char *)ce->name);
2966    }
2967#endif /* HAVE_DTRACE */
2968
2969    if (ce != catch_ce) {
2970        if (!instanceof_function(ce, catch_ce TSRMLS_CC)) {
2971            if (opline->result.num) {
2972                zend_throw_exception_internal(NULL TSRMLS_CC);
2973                HANDLE_EXCEPTION();
2974            }
2975            ZEND_VM_SET_OPCODE(&EX(func)->op_array.opcodes[opline->extended_value]);
2976            ZEND_VM_CONTINUE(); /* CHECK_ME */
2977        }
2978    }
2979
2980    exception = EG(exception);
2981    zval_ptr_dtor(EX_VAR(opline->op2.var));
2982    ZVAL_OBJ(EX_VAR(opline->op2.var), EG(exception));
2983    if (UNEXPECTED(EG(exception) != exception)) {
2984        GC_REFCOUNT(EG(exception))++;
2985        HANDLE_EXCEPTION();
2986    } else {
2987        EG(exception) = NULL;
2988        ZEND_VM_NEXT_OPCODE();
2989    }
2990}
2991
2992ZEND_VM_HANDLER(65, ZEND_SEND_VAL, CONST|TMP, ANY)
2993{
2994    USE_OPLINE
2995    zval *value, *arg;
2996    zend_free_op free_op1;
2997
2998    SAVE_OPLINE();
2999    value = GET_OP1_ZVAL_PTR(BP_VAR_R);
3000    arg = ZEND_CALL_ARG(EX(call), opline->op2.num);
3001    ZEND_CALL_NUM_ARGS(EX(call)) = opline->op2.num;
3002    ZVAL_COPY_VALUE(arg, value);
3003    if (OP1_TYPE == IS_CONST) {
3004        if (UNEXPECTED(Z_OPT_COPYABLE_P(arg))) {
3005            zval_copy_ctor_func(arg);
3006        }
3007    }
3008    ZEND_VM_NEXT_OPCODE();
3009}
3010
3011ZEND_VM_HANDLER(116, ZEND_SEND_VAL_EX, CONST|TMP, ANY)
3012{
3013    USE_OPLINE
3014    zval *value, *arg;
3015    zend_free_op free_op1;
3016
3017    SAVE_OPLINE();
3018    if (ARG_MUST_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3019        zend_error_noreturn(E_ERROR, "Cannot pass parameter %d by reference", opline->op2.num);
3020    }
3021    value = GET_OP1_ZVAL_PTR(BP_VAR_R);
3022    arg = ZEND_CALL_ARG(EX(call), opline->op2.num);
3023    ZEND_CALL_NUM_ARGS(EX(call)) = opline->op2.num;
3024    ZVAL_COPY_VALUE(arg, value);
3025    if (OP1_TYPE == IS_CONST) {
3026        if (UNEXPECTED(Z_OPT_COPYABLE_P(arg))) {
3027            zval_copy_ctor_func(arg);
3028        }
3029    }
3030    ZEND_VM_NEXT_OPCODE();
3031}
3032
3033ZEND_VM_HANDLER(117, ZEND_SEND_VAR, VAR|CV, ANY)
3034{
3035    USE_OPLINE
3036    zval *varptr, *arg;
3037    zend_free_op free_op1;
3038
3039    varptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
3040    arg = ZEND_CALL_ARG(EX(call), opline->op2.num);
3041    ZEND_CALL_NUM_ARGS(EX(call)) = opline->op2.num;
3042    if ((OP1_TYPE == IS_CV || OP1_TYPE == IS_VAR) && Z_ISREF_P(varptr)) {
3043        ZVAL_COPY(arg, Z_REFVAL_P(varptr));
3044        FREE_OP1();
3045    } else {
3046        ZVAL_COPY_VALUE(arg, varptr);
3047        if (OP1_TYPE == IS_CV) {
3048            if (Z_OPT_REFCOUNTED_P(arg)) Z_ADDREF_P(arg);
3049        }
3050    }
3051    ZEND_VM_NEXT_OPCODE();
3052}
3053
3054ZEND_VM_HANDLER(106, ZEND_SEND_VAR_NO_REF, VAR|CV, ANY)
3055{
3056    USE_OPLINE
3057    zend_free_op free_op1;
3058    zval *varptr, *arg;
3059
3060    SAVE_OPLINE();
3061
3062    if (!(opline->extended_value & ZEND_ARG_COMPILE_TIME_BOUND)) {
3063        if (!ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3064            ZEND_VM_DISPATCH_TO_HANDLER(ZEND_SEND_VAR);
3065        }
3066    }
3067
3068    varptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
3069    if ((!(opline->extended_value & ZEND_ARG_SEND_FUNCTION) ||
3070         (Z_VAR_FLAGS_P(varptr) & IS_VAR_RET_REF)) &&
3071        (Z_ISREF_P(varptr) || Z_TYPE_P(varptr) == IS_OBJECT)) {
3072
3073        ZVAL_MAKE_REF(varptr);
3074        if (OP1_TYPE == IS_CV) {
3075            Z_ADDREF_P(varptr);
3076        }
3077    } else {
3078        if ((opline->extended_value & ZEND_ARG_COMPILE_TIME_BOUND) ?
3079            !(opline->extended_value & ZEND_ARG_SEND_SILENT) :
3080            !ARG_MAY_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3081            zend_error(E_STRICT, "Only variables should be passed by reference");
3082        }
3083    }
3084
3085    arg = ZEND_CALL_ARG(EX(call), opline->op2.num);
3086    ZEND_CALL_NUM_ARGS(EX(call)) = opline->op2.num;
3087    ZVAL_COPY_VALUE(arg, varptr);
3088
3089    CHECK_EXCEPTION();
3090    ZEND_VM_NEXT_OPCODE();
3091}
3092
3093ZEND_VM_HANDLER(67, ZEND_SEND_REF, VAR|CV, ANY)
3094{
3095    USE_OPLINE
3096    zend_free_op free_op1;
3097    zval *varptr, *arg;
3098
3099    SAVE_OPLINE();
3100    varptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
3101
3102    if (OP1_TYPE == IS_VAR && UNEXPECTED(varptr == NULL)) {
3103        zend_error_noreturn(E_ERROR, "Only variables can be passed by reference");
3104    }
3105
3106    arg = ZEND_CALL_ARG(EX(call), opline->op2.num);
3107    ZEND_CALL_NUM_ARGS(EX(call)) = opline->op2.num;
3108    if (OP1_TYPE == IS_VAR && UNEXPECTED(varptr == &EG(error_zval))) {
3109        ZVAL_NEW_REF(arg, &EG(uninitialized_zval));
3110        ZEND_VM_NEXT_OPCODE();
3111    }
3112
3113    if (Z_ISREF_P(varptr)) {
3114        Z_ADDREF_P(varptr);
3115        ZVAL_COPY_VALUE(arg, varptr);
3116    } else if (OP1_TYPE == IS_VAR &&
3117        UNEXPECTED(Z_TYPE_P(EX_VAR(opline->op1.var)) != IS_INDIRECT)) {
3118        ZVAL_NEW_REF(arg, varptr);
3119    } else {
3120        ZVAL_NEW_REF(arg, varptr);
3121        Z_ADDREF_P(arg);
3122        ZVAL_REF(varptr, Z_REF_P(arg));
3123    }
3124
3125    FREE_OP1_VAR_PTR();
3126    ZEND_VM_NEXT_OPCODE();
3127}
3128
3129ZEND_VM_HANDLER(66, ZEND_SEND_VAR_EX, VAR|CV, ANY)
3130{
3131    USE_OPLINE
3132    zval *varptr, *arg;
3133    zend_free_op free_op1;
3134
3135    if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3136        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_SEND_REF);
3137    }
3138    varptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
3139    arg = ZEND_CALL_ARG(EX(call), opline->op2.num);
3140    ZEND_CALL_NUM_ARGS(EX(call)) = opline->op2.num;
3141    if ((OP1_TYPE == IS_CV || OP1_TYPE == IS_VAR) && Z_ISREF_P(varptr)) {
3142        ZVAL_COPY(arg, Z_REFVAL_P(varptr));
3143        FREE_OP1();
3144    } else {
3145        ZVAL_COPY_VALUE(arg, varptr);
3146        if (OP1_TYPE == IS_CV) {
3147            if (Z_OPT_REFCOUNTED_P(arg)) Z_ADDREF_P(arg);
3148        }
3149    }
3150    ZEND_VM_NEXT_OPCODE();
3151}
3152
3153ZEND_VM_HANDLER(165, ZEND_SEND_UNPACK, ANY, ANY)
3154{
3155    USE_OPLINE
3156    zend_free_op free_op1;
3157    zval *args;
3158    int arg_num;
3159    SAVE_OPLINE();
3160
3161    args = GET_OP1_ZVAL_PTR(BP_VAR_R);
3162    arg_num = ZEND_CALL_NUM_ARGS(EX(call)) + 1;
3163
3164ZEND_VM_C_LABEL(send_again):
3165    switch (Z_TYPE_P(args)) {
3166        case IS_ARRAY: {
3167            HashTable *ht = Z_ARRVAL_P(args);
3168            zval *arg, *top;
3169            zend_string *name;
3170
3171            zend_vm_stack_extend_call_frame(&EX(call), arg_num - 1, zend_hash_num_elements(ht) TSRMLS_CC);
3172
3173            if (OP1_TYPE != IS_CONST && OP1_TYPE != IS_TMP_VAR && Z_IMMUTABLE_P(args)) {
3174                uint32_t i;
3175                int separate = 0;
3176
3177                /* check if any of arguments are going to be passed by reference */
3178                for (i = 0; i < zend_hash_num_elements(ht); i++) {
3179                    if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num + i)) {
3180                        separate = 1;
3181                        break;
3182                    }
3183                }
3184                if (separate) {
3185                    zval_copy_ctor(args);
3186                    ht = Z_ARRVAL_P(args);
3187                }
3188            }
3189
3190            ZEND_HASH_FOREACH_STR_KEY_VAL(ht, name, arg) {
3191                if (name) {
3192                    zend_error(E_RECOVERABLE_ERROR, "Cannot unpack array with string keys");
3193                    FREE_OP1();
3194                    CHECK_EXCEPTION();
3195                    ZEND_VM_NEXT_OPCODE();
3196                }
3197
3198                top = ZEND_CALL_ARG(EX(call), arg_num);
3199                if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
3200                    if (!Z_IMMUTABLE_P(args)) {
3201                        ZVAL_MAKE_REF(arg);
3202                        Z_ADDREF_P(arg);
3203                        ZVAL_REF(top, Z_REF_P(arg));
3204                    } else {
3205                        ZVAL_DUP(top, arg);
3206                    }
3207                } else if (Z_ISREF_P(arg)) {
3208                    ZVAL_COPY(top, Z_REFVAL_P(arg));
3209                } else {
3210                    ZVAL_COPY(top, arg);
3211                }
3212
3213                ZEND_CALL_NUM_ARGS(EX(call))++;
3214                arg_num++;
3215            } ZEND_HASH_FOREACH_END();
3216
3217            break;
3218        }
3219        case IS_OBJECT: {
3220            zend_class_entry *ce = Z_OBJCE_P(args);
3221            zend_object_iterator *iter;
3222
3223            if (!ce || !ce->get_iterator) {
3224                zend_error(E_WARNING, "Only arrays and Traversables can be unpacked");
3225                break;
3226            }
3227
3228            iter = ce->get_iterator(ce, args, 0 TSRMLS_CC);
3229            if (UNEXPECTED(!iter)) {
3230                FREE_OP1();
3231                if (!EG(exception)) {
3232                    zend_throw_exception_ex(
3233                        NULL, 0 TSRMLS_CC, "Object of type %s did not create an Iterator", ce->name->val
3234                    );
3235                }
3236                HANDLE_EXCEPTION();
3237            }
3238
3239            if (iter->funcs->rewind) {
3240                iter->funcs->rewind(iter TSRMLS_CC);
3241                if (UNEXPECTED(EG(exception) != NULL)) {
3242                    ZEND_VM_C_GOTO(unpack_iter_dtor);
3243                }
3244            }
3245
3246            for (; iter->funcs->valid(iter TSRMLS_CC) == SUCCESS; ++arg_num) {
3247                zval *arg, *top;
3248
3249                if (UNEXPECTED(EG(exception) != NULL)) {
3250                    ZEND_VM_C_GOTO(unpack_iter_dtor);
3251                }
3252
3253                arg = iter->funcs->get_current_data(iter TSRMLS_CC);
3254                if (UNEXPECTED(EG(exception) != NULL)) {
3255                    ZEND_VM_C_GOTO(unpack_iter_dtor);
3256                }
3257
3258                if (iter->funcs->get_current_key) {
3259                    zval key;
3260                    iter->funcs->get_current_key(iter, &key TSRMLS_CC);
3261                    if (UNEXPECTED(EG(exception) != NULL)) {
3262                        ZEND_VM_C_GOTO(unpack_iter_dtor);
3263                    }
3264
3265                    if (Z_TYPE(key) == IS_STRING) {
3266                        zend_error(E_RECOVERABLE_ERROR,
3267                            "Cannot unpack Traversable with string keys");
3268                        zend_string_release(Z_STR(key));
3269                        ZEND_VM_C_GOTO(unpack_iter_dtor);
3270                    }
3271
3272                    zval_dtor(&key);
3273                }
3274
3275                if (ARG_MUST_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
3276                    zend_error(
3277                        E_WARNING, "Cannot pass by-reference argument %d of %s%s%s()"
3278                        " by unpacking a Traversable, passing by-value instead", arg_num,
3279                        EX(call)->func->common.scope ? EX(call)->func->common.scope->name->val : "",
3280                        EX(call)->func->common.scope ? "::" : "",
3281                        EX(call)->func->common.function_name->val
3282                    );
3283                }
3284
3285                if (Z_ISREF_P(arg)) {
3286                    ZVAL_DUP(arg, Z_REFVAL_P(arg));
3287                } else {
3288                    if (Z_REFCOUNTED_P(arg)) Z_ADDREF_P(arg);
3289                }
3290
3291                zend_vm_stack_extend_call_frame(&EX(call), arg_num - 1, 1 TSRMLS_CC);
3292                top = ZEND_CALL_ARG(EX(call), arg_num);
3293                ZVAL_COPY_VALUE(top, arg);
3294                ZEND_CALL_NUM_ARGS(EX(call))++;
3295
3296                iter->funcs->move_forward(iter TSRMLS_CC);
3297                if (UNEXPECTED(EG(exception) != NULL)) {
3298                    ZEND_VM_C_GOTO(unpack_iter_dtor);
3299                }
3300            }
3301
3302ZEND_VM_C_LABEL(unpack_iter_dtor):
3303            zend_iterator_dtor(iter TSRMLS_CC);
3304            break;
3305        }
3306        case IS_REFERENCE:
3307            args = Z_REFVAL_P(args);
3308            ZEND_VM_C_GOTO(send_again);
3309            break;
3310        default:
3311            zend_error(E_WARNING, "Only arrays and Traversables can be unpacked");
3312    }
3313
3314    FREE_OP1();
3315    CHECK_EXCEPTION();
3316    ZEND_VM_NEXT_OPCODE();
3317}
3318
3319ZEND_VM_HANDLER(119, ZEND_SEND_ARRAY, ANY, ANY)
3320{
3321    USE_OPLINE
3322    zend_free_op free_op1;
3323    zval *args;
3324    SAVE_OPLINE();
3325
3326    args = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
3327
3328    if (Z_TYPE_P(args) != IS_ARRAY) {
3329        zend_error(E_WARNING, "call_user_func_array() expects parameter 2 to be array, %s given", zend_get_type_by_const(Z_TYPE_P(args)));
3330        if (EX(call)->func->common.fn_flags & ZEND_ACC_CLOSURE) {
3331            OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
3332        }
3333        if (Z_OBJ(EX(call)->This)) {
3334            OBJ_RELEASE(Z_OBJ(EX(call)->This));
3335        }
3336        EX(call)->func = (zend_function*)&zend_pass_function;
3337        EX(call)->called_scope = NULL;
3338        Z_OBJ(EX(call)->This) = NULL;
3339    } else {
3340        uint32_t arg_num = 1;
3341
3342        HashTable *ht = Z_ARRVAL_P(args);
3343        zval *arg, *param, tmp;
3344
3345        zend_vm_stack_extend_call_frame(&EX(call), 0, zend_hash_num_elements(ht) TSRMLS_CC);
3346
3347        if (OP1_TYPE != IS_CONST && OP1_TYPE != IS_TMP_VAR && Z_IMMUTABLE_P(args)) {
3348            uint32_t i;
3349            int separate = 0;
3350
3351            /* check if any of arguments are going to be passed by reference */
3352            for (i = 0; i < zend_hash_num_elements(ht); i++) {
3353                if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num + i)) {
3354                    separate = 1;
3355                    break;
3356                }
3357            }
3358            if (separate) {
3359                zval_copy_ctor(args);
3360                ht = Z_ARRVAL_P(args);
3361            }
3362        }
3363
3364        param = ZEND_CALL_ARG(EX(call), arg_num);
3365        ZEND_HASH_FOREACH_VAL(ht, arg) {
3366            if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
3367                // TODO: Scalar values don't have reference counters anymore.
3368                // They are assumed to be 1, and they may be easily passed by
3369                // reference now. However, previously scalars with refcount==1
3370                // might be passed and with refcount>1 might not. We can support
3371                // only single behavior ???
3372#if 0
3373                if (Z_REFCOUNTED_P(arg) &&
3374                    // This solution breaks the following test (omit warning message) ???
3375                    // Zend/tests/bug61273.phpt
3376                    // ext/reflection/tests/bug42976.phpt
3377                    // ext/standard/tests/general_functions/call_user_func_array_variation_001.phpt
3378#else
3379                if (!Z_REFCOUNTED_P(arg) ||
3380                    // This solution breaks the following test (emit warning message) ???
3381                    // ext/pdo_sqlite/tests/pdo_005.phpt
3382#endif
3383                    (!Z_ISREF_P(arg) && Z_REFCOUNT_P(arg) > 1)) {
3384
3385                    if (!ARG_MAY_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
3386
3387                        zend_error(E_WARNING, "Parameter %d to %s%s%s() expected to be a reference, value given",
3388                            arg_num,
3389                            EX(call)->func->common.scope ? EX(call)->func->common.scope->name->val : "",
3390                            EX(call)->func->common.scope ? "::" : "",
3391                            EX(call)->func->common.function_name->val);
3392
3393                        if (EX(call)->func->common.fn_flags & ZEND_ACC_CLOSURE) {
3394                            OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
3395                        }
3396                        if (Z_OBJ(EX(call)->This)) {
3397                            OBJ_RELEASE(Z_OBJ(EX(call)->This));
3398                        }
3399                        EX(call)->func = (zend_function*)&zend_pass_function;
3400                        EX(call)->called_scope = NULL;
3401                        Z_OBJ(EX(call)->This) = NULL;
3402
3403                        break;
3404                    }
3405
3406                    if (Z_REFCOUNTED_P(arg)) {
3407                        Z_DELREF_P(arg);
3408                    }
3409                    ZVAL_DUP(&tmp, arg);
3410                    ZVAL_NEW_REF(arg, &tmp);
3411                    Z_ADDREF_P(arg);
3412                } else if (!Z_ISREF_P(arg)) {
3413                    ZVAL_NEW_REF(arg, arg);
3414                    Z_ADDREF_P(arg);
3415                } else if (Z_REFCOUNTED_P(arg)) {
3416                    Z_ADDREF_P(arg);
3417                }
3418                ZVAL_COPY_VALUE(param, arg);
3419            } else if (Z_ISREF_P(arg) &&
3420                   /* don't separate references for __call */
3421                   (EX(call)->func->common.fn_flags & ZEND_ACC_CALL_VIA_HANDLER) == 0) {
3422                ZVAL_DUP(param, Z_REFVAL_P(arg));
3423            } else {
3424                ZVAL_COPY(param, arg);
3425            }
3426            ZEND_CALL_NUM_ARGS(EX(call))++;
3427            arg_num++;
3428            param++;
3429        } ZEND_HASH_FOREACH_END();
3430    }
3431    FREE_OP1();
3432    CHECK_EXCEPTION();
3433    ZEND_VM_NEXT_OPCODE();
3434}
3435
3436ZEND_VM_HANDLER(120, ZEND_SEND_USER, VAR|CV, ANY)
3437{
3438    USE_OPLINE
3439    zval *arg, *param, tmp;
3440    zend_free_op free_op1;
3441
3442    arg = GET_OP1_ZVAL_PTR(BP_VAR_R);
3443    param = ZEND_CALL_ARG(EX(call), opline->op2.num);
3444
3445    if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3446        // TODO: Scalar values don't have reference counters anymore.
3447        // They are assumed to be 1, and they may be easily passed by
3448        // reference now. However, previously scalars with refcount==1
3449        // might be passed and with refcount>1 might not. We can support
3450        // only single behavior ???
3451#if 0
3452        if (Z_REFCOUNTED_P(arg) &&
3453            // This solution breaks the following test (omit warning message) ???
3454            // Zend/tests/bug61273.phpt
3455            // ext/reflection/tests/bug42976.phpt
3456            // ext/standard/tests/general_functions/call_user_func_array_variation_001.phpt
3457#else
3458        if (!Z_REFCOUNTED_P(arg) ||
3459            // This solution breaks the following test (emit warning message) ???
3460            // ext/pdo_sqlite/tests/pdo_005.phpt
3461#endif
3462            (!Z_ISREF_P(arg) /*&& Z_REFCOUNT_P(arg) > 1???*/)) {
3463
3464            if (!ARG_MAY_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3465
3466                zend_error(E_WARNING, "Parameter %d to %s%s%s() expected to be a reference, value given",
3467                    opline->op2.num,
3468                    EX(call)->func->common.scope ? EX(call)->func->common.scope->name->val : "",
3469                    EX(call)->func->common.scope ? "::" : "",
3470                    EX(call)->func->common.function_name->val);
3471
3472                if (EX(call)->func->common.fn_flags & ZEND_ACC_CLOSURE) {
3473                    OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
3474                }
3475                if (Z_OBJ(EX(call)->This)) {
3476                    OBJ_RELEASE(Z_OBJ(EX(call)->This));
3477                }
3478                EX(call)->func = (zend_function*)&zend_pass_function;
3479                EX(call)->called_scope = NULL;
3480                Z_OBJ(EX(call)->This) = NULL;
3481
3482                FREE_OP1();
3483                CHECK_EXCEPTION();
3484                ZEND_VM_NEXT_OPCODE();
3485            }
3486
3487            if (Z_REFCOUNTED_P(arg)) {
3488                Z_DELREF_P(arg);
3489            }
3490            ZVAL_DUP(&tmp, arg);
3491            ZVAL_NEW_REF(arg, &tmp);
3492            Z_ADDREF_P(arg);
3493        } else if (!Z_ISREF_P(arg)) {
3494            ZVAL_NEW_REF(arg, arg);
3495            Z_ADDREF_P(arg);
3496        } else if (Z_REFCOUNTED_P(arg)) {
3497            Z_ADDREF_P(arg);
3498        }
3499        ZVAL_COPY_VALUE(param, arg);
3500    } else if (Z_ISREF_P(arg) &&
3501               /* don't separate references for __call */
3502               (EX(call)->func->common.fn_flags & ZEND_ACC_CALL_VIA_HANDLER) == 0) {
3503        ZVAL_DUP(param, Z_REFVAL_P(arg));
3504    } else {
3505        ZVAL_COPY(param, arg);
3506    }
3507
3508    ZEND_CALL_NUM_ARGS(EX(call)) = opline->op2.num;
3509
3510    FREE_OP1();
3511    CHECK_EXCEPTION();
3512    ZEND_VM_NEXT_OPCODE();
3513}
3514
3515ZEND_VM_HANDLER(63, ZEND_RECV, ANY, ANY)
3516{
3517    USE_OPLINE
3518    uint32_t arg_num = opline->op1.num;
3519
3520    SAVE_OPLINE();
3521    if (UNEXPECTED(arg_num > EX_NUM_ARGS())) {
3522        zend_verify_missing_arg(execute_data, arg_num TSRMLS_CC);
3523        CHECK_EXCEPTION();
3524    } else if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
3525        zval *param = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var TSRMLS_CC);
3526
3527        zend_verify_arg_type(EX(func), arg_num, param, NULL TSRMLS_CC);
3528        CHECK_EXCEPTION();
3529    }
3530
3531    ZEND_VM_NEXT_OPCODE();
3532}
3533
3534ZEND_VM_HANDLER(64, ZEND_RECV_INIT, ANY, CONST)
3535{
3536    USE_OPLINE
3537    uint32_t arg_num = opline->op1.num;
3538    zval *param;
3539
3540    SAVE_OPLINE();
3541    param = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var TSRMLS_CC);
3542    if (arg_num > EX_NUM_ARGS()) {
3543        ZVAL_COPY_VALUE(param, opline->op2.zv);
3544        if (Z_OPT_CONSTANT_P(param)) {
3545            zval_update_constant(param, 0 TSRMLS_CC);
3546        } else {
3547            /* IS_CONST can't be IS_OBJECT, IS_RESOURCE or IS_REFERENCE */
3548            if (UNEXPECTED(Z_OPT_COPYABLE_P(param))) {
3549                zval_copy_ctor_func(param);
3550            }
3551        }
3552    }
3553
3554    if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
3555        zend_verify_arg_type(EX(func), arg_num, param, opline->op2.zv TSRMLS_CC);
3556    }
3557
3558    CHECK_EXCEPTION();
3559    ZEND_VM_NEXT_OPCODE();
3560}
3561
3562ZEND_VM_HANDLER(164, ZEND_RECV_VARIADIC, ANY, ANY)
3563{
3564    USE_OPLINE
3565    uint32_t arg_num = opline->op1.num;
3566    uint32_t arg_count = EX_NUM_ARGS();
3567    zval *params;
3568
3569    SAVE_OPLINE();
3570
3571    params = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var TSRMLS_CC);
3572
3573    if (arg_num <= arg_count) {
3574        zval *param;
3575
3576        array_init_size(params, arg_count - arg_num + 1);
3577        param = EX_VAR_NUM(EX(func)->op_array.last_var + EX(func)->op_array.T);
3578        if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
3579            do {
3580                zend_verify_arg_type(EX(func), arg_num, param, NULL TSRMLS_CC);
3581                zend_hash_next_index_insert_new(Z_ARRVAL_P(params), param);
3582                if (Z_REFCOUNTED_P(param)) Z_ADDREF_P(param);
3583                param++;
3584            } while (++arg_num <= arg_count);
3585        } else {
3586            do {
3587                zend_hash_next_index_insert_new(Z_ARRVAL_P(params), param);
3588                if (Z_REFCOUNTED_P(param)) Z_ADDREF_P(param);
3589                param++;
3590            } while (++arg_num <= arg_count);
3591        }
3592    } else {
3593        array_init(params);
3594    }
3595
3596    CHECK_EXCEPTION();
3597    ZEND_VM_NEXT_OPCODE();
3598}
3599
3600ZEND_VM_HANDLER(52, ZEND_BOOL, CONST|TMP|VAR|CV, ANY)
3601{
3602    USE_OPLINE
3603    zend_free_op free_op1;
3604    zval *retval = EX_VAR(opline->result.var);
3605
3606    SAVE_OPLINE();
3607    /* PHP 3.0 returned "" for false and 1 for true, here we use 0 and 1 for now */
3608    ZVAL_BOOL(retval, i_zend_is_true(GET_OP1_ZVAL_PTR(BP_VAR_R) TSRMLS_CC));
3609    FREE_OP1();
3610
3611    CHECK_EXCEPTION();
3612    ZEND_VM_NEXT_OPCODE();
3613}
3614
3615ZEND_VM_HANDLER(50, ZEND_BRK, ANY, CONST)
3616{
3617    USE_OPLINE
3618    zend_brk_cont_element *el;
3619
3620    SAVE_OPLINE();
3621    el = zend_brk_cont(Z_LVAL_P(opline->op2.zv), opline->op1.opline_num,
3622                       &EX(func)->op_array, execute_data TSRMLS_CC);
3623    ZEND_VM_JMP(EX(func)->op_array.opcodes + el->brk);
3624}
3625
3626ZEND_VM_HANDLER(51, ZEND_CONT, ANY, CONST)
3627{
3628    USE_OPLINE
3629    zend_brk_cont_element *el;
3630
3631    SAVE_OPLINE();
3632    el = zend_brk_cont(Z_LVAL_P(opline->op2.zv), opline->op1.opline_num,
3633                       &EX(func)->op_array, execute_data TSRMLS_CC);
3634    ZEND_VM_JMP(EX(func)->op_array.opcodes + el->cont);
3635}
3636
3637ZEND_VM_HANDLER(100, ZEND_GOTO, ANY, CONST)
3638{
3639    zend_op *brk_opline;
3640    USE_OPLINE
3641    zend_brk_cont_element *el;
3642
3643    SAVE_OPLINE();
3644    el = zend_brk_cont(Z_LVAL_P(opline->op2.zv), opline->extended_value,
3645                       &EX(func)->op_array, execute_data TSRMLS_CC);
3646
3647    brk_opline = EX(func)->op_array.opcodes + el->brk;
3648
3649    if (brk_opline->opcode == ZEND_FREE) {
3650        if (!(brk_opline->extended_value & EXT_TYPE_FREE_ON_RETURN)) {
3651            zval_ptr_dtor_nogc(EX_VAR(brk_opline->op1.var));
3652        }
3653    }
3654    ZEND_VM_JMP(opline->op1.jmp_addr);
3655}
3656
3657ZEND_VM_HANDLER(48, ZEND_CASE, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
3658{
3659    USE_OPLINE
3660    zend_free_op free_op1, free_op2;
3661    zval *result = EX_VAR(opline->result.var);
3662
3663    SAVE_OPLINE();
3664    fast_equal_function(result,
3665         GET_OP1_ZVAL_PTR(BP_VAR_R),
3666         GET_OP2_ZVAL_PTR(BP_VAR_R) TSRMLS_CC);
3667
3668    FREE_OP2();
3669    CHECK_EXCEPTION();
3670    ZEND_VM_NEXT_OPCODE();
3671}
3672
3673ZEND_VM_HANDLER(68, ZEND_NEW, CONST|VAR, ANY)
3674{
3675    USE_OPLINE
3676    zval object_zval;
3677    zend_function *constructor;
3678    zend_class_entry *ce;
3679
3680    SAVE_OPLINE();
3681    if (OP1_TYPE == IS_CONST) {
3682        if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op1.zv))) {
3683            ce = CACHED_PTR(Z_CACHE_SLOT_P(opline->op1.zv));
3684        } else {
3685            ce = zend_fetch_class_by_name(Z_STR_P(opline->op1.zv), opline->op1.zv + 1, 0 TSRMLS_CC);
3686            if (UNEXPECTED(ce == NULL)) {
3687                CHECK_EXCEPTION();
3688                ZEND_VM_NEXT_OPCODE();
3689            }
3690            CACHE_PTR(Z_CACHE_SLOT_P(opline->op1.zv), ce);
3691        }
3692    } else {
3693        ce = Z_CE_P(EX_VAR(opline->op1.var));
3694    }
3695    if (UNEXPECTED((ce->ce_flags & (ZEND_ACC_INTERFACE|ZEND_ACC_IMPLICIT_ABSTRACT_CLASS|ZEND_ACC_EXPLICIT_ABSTRACT_CLASS)) != 0)) {
3696        if (ce->ce_flags & ZEND_ACC_INTERFACE) {
3697            zend_error_noreturn(E_ERROR, "Cannot instantiate interface %s", ce->name->val);
3698        } else if ((ce->ce_flags & ZEND_ACC_TRAIT) == ZEND_ACC_TRAIT) {
3699            zend_error_noreturn(E_ERROR, "Cannot instantiate trait %s", ce->name->val);
3700        } else {
3701            zend_error_noreturn(E_ERROR, "Cannot instantiate abstract class %s", ce->name->val);
3702        }
3703    }
3704    object_init_ex(&object_zval, ce);
3705    constructor = Z_OBJ_HT(object_zval)->get_constructor(Z_OBJ(object_zval) TSRMLS_CC);
3706
3707    if (constructor == NULL) {
3708        if (RETURN_VALUE_USED(opline)) {
3709            ZVAL_COPY_VALUE(EX_VAR(opline->result.var), &object_zval);
3710        } else {
3711            OBJ_RELEASE(Z_OBJ(object_zval));
3712        }
3713        ZEND_VM_JMP(opline->op2.jmp_addr);
3714    } else {
3715        /* We are not handling overloaded classes right now */
3716        EX(call) = zend_vm_stack_push_call_frame(
3717                ZEND_CALL_FUNCTION | ZEND_CALL_CTOR |
3718                (RETURN_VALUE_USED(opline) ? 0 : ZEND_CALL_CTOR_RESULT_UNUSED),
3719            constructor,
3720            opline->extended_value,
3721            ce,
3722            Z_OBJ(object_zval),
3723            EX(call) TSRMLS_CC);
3724
3725        if (RETURN_VALUE_USED(opline)) {
3726            ZVAL_COPY(EX_VAR(opline->result.var), &object_zval);
3727            EX(call)->return_value = EX_VAR(opline->result.var);
3728        } else {
3729            EX(call)->return_value = NULL;
3730        }
3731
3732        CHECK_EXCEPTION();
3733        ZEND_VM_NEXT_OPCODE();
3734    }
3735}
3736
3737ZEND_VM_HANDLER(110, ZEND_CLONE, CONST|TMP|VAR|UNUSED|CV, ANY)
3738{
3739    USE_OPLINE
3740    zend_free_op free_op1;
3741    zval *obj;
3742    zend_class_entry *ce;
3743    zend_function *clone;
3744    zend_object_clone_obj_t clone_call;
3745
3746    SAVE_OPLINE();
3747    obj = GET_OP1_OBJ_ZVAL_PTR_DEREF(BP_VAR_R);
3748
3749    if (OP1_TYPE == IS_CONST ||
3750        (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(obj) != IS_OBJECT))) {
3751        if (UNEXPECTED(EG(exception) != NULL)) {
3752            HANDLE_EXCEPTION();
3753        }
3754        zend_error_noreturn(E_ERROR, "__clone method called on non-object");
3755    }
3756
3757    ce = Z_OBJCE_P(obj);
3758    clone = ce ? ce->clone : NULL;
3759    clone_call =  Z_OBJ_HT_P(obj)->clone_obj;
3760    if (UNEXPECTED(clone_call == NULL)) {
3761        if (ce) {
3762            zend_error_noreturn(E_ERROR, "Trying to clone an uncloneable object of class %s", ce->name->val);
3763        } else {
3764            zend_error_noreturn(E_ERROR, "Trying to clone an uncloneable object");
3765        }
3766    }
3767
3768    if (ce && clone) {
3769        if (clone->op_array.fn_flags & ZEND_ACC_PRIVATE) {
3770            /* Ensure that if we're calling a private function, we're allowed to do so.
3771             */
3772            if (UNEXPECTED(ce != EG(scope))) {
3773                zend_error_noreturn(E_ERROR, "Call to private %s::__clone() from context '%s'", ce->name->val, EG(scope) ? EG(scope)->name->val : "");
3774            }
3775        } else if ((clone->common.fn_flags & ZEND_ACC_PROTECTED)) {
3776            /* Ensure that if we're calling a protected function, we're allowed to do so.
3777             */
3778            if (UNEXPECTED(!zend_check_protected(zend_get_function_root_class(clone), EG(scope)))) {
3779                zend_error_noreturn(E_ERROR, "Call to protected %s::__clone() from context '%s'", ce->name->val, EG(scope) ? EG(scope)->name->val : "");
3780            }
3781        }
3782    }
3783
3784    if (EXPECTED(EG(exception) == NULL)) {
3785        ZVAL_OBJ(EX_VAR(opline->result.var), clone_call(obj TSRMLS_CC));
3786        if (!RETURN_VALUE_USED(opline) || UNEXPECTED(EG(exception) != NULL)) {
3787            OBJ_RELEASE(Z_OBJ_P(EX_VAR(opline->result.var)));
3788        }
3789    }
3790    FREE_OP1_IF_VAR();
3791    CHECK_EXCEPTION();
3792    ZEND_VM_NEXT_OPCODE();
3793}
3794
3795ZEND_VM_HANDLER(99, ZEND_FETCH_CONSTANT, VAR|CONST|UNUSED, CONST)
3796{
3797    USE_OPLINE
3798
3799    SAVE_OPLINE();
3800    if (OP1_TYPE == IS_UNUSED) {
3801        zend_constant *c;
3802        zval *retval;
3803
3804        if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv))) {
3805            c = CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv));
3806        } else if ((c = zend_quick_get_constant(opline->op2.zv + 1, opline->extended_value TSRMLS_CC)) == NULL) {
3807            if ((opline->extended_value & IS_CONSTANT_UNQUALIFIED) != 0) {
3808                char *actual = (char *)zend_memrchr(Z_STRVAL_P(opline->op2.zv), '\\', Z_STRLEN_P(opline->op2.zv));
3809                if (!actual) {
3810                    ZVAL_STR(EX_VAR(opline->result.var), zend_string_copy(Z_STR_P(opline->op2.zv)));
3811                } else {
3812                    actual++;
3813                    ZVAL_STRINGL(EX_VAR(opline->result.var),
3814                            actual, Z_STRLEN_P(opline->op2.zv) - (actual - Z_STRVAL_P(opline->op2.zv)));
3815                }
3816                /* non-qualified constant - allow text substitution */
3817                zend_error(E_NOTICE, "Use of undefined constant %s - assumed '%s'",
3818                        Z_STRVAL_P(EX_VAR(opline->result.var)), Z_STRVAL_P(EX_VAR(opline->result.var)));
3819                CHECK_EXCEPTION();
3820                ZEND_VM_NEXT_OPCODE();
3821            } else {
3822                zend_error_noreturn(E_ERROR, "Undefined constant '%s'", Z_STRVAL_P(opline->op2.zv));
3823            }
3824        } else {
3825            CACHE_PTR(Z_CACHE_SLOT_P(opline->op2.zv), c);
3826        }
3827        retval = EX_VAR(opline->result.var);
3828        ZVAL_COPY_VALUE(retval, &c->value);
3829        if (Z_OPT_COPYABLE_P(retval) || Z_OPT_REFCOUNTED_P(retval)) {
3830            if (Z_OPT_COPYABLE_P(retval)) {
3831                zval_copy_ctor_func(retval);
3832            } else {
3833                Z_ADDREF_P(retval);
3834            }
3835        }
3836    } else {
3837        /* class constant */
3838        zend_class_entry *ce;
3839        zval *value;
3840
3841        if (OP1_TYPE == IS_CONST) {
3842            if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv))) {
3843                value = CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv));
3844                ZVAL_DEREF(value);
3845                ZVAL_DUP(EX_VAR(opline->result.var), value);
3846                ZEND_VM_C_GOTO(constant_fetch_end);
3847            } else if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op1.zv))) {
3848                ce = CACHED_PTR(Z_CACHE_SLOT_P(opline->op1.zv));
3849            } else {
3850                ce = zend_fetch_class_by_name(Z_STR_P(opline->op1.zv), opline->op1.zv + 1, 0 TSRMLS_CC);
3851                if (UNEXPECTED(EG(exception) != NULL)) {
3852                    HANDLE_EXCEPTION();
3853                }
3854                if (UNEXPECTED(ce == NULL)) {
3855                    zend_error_noreturn(E_ERROR, "Class '%s' not found", Z_STRVAL_P(opline->op1.zv));
3856                }
3857                CACHE_PTR(Z_CACHE_SLOT_P(opline->op1.zv), ce);
3858            }
3859        } else {
3860            ce = Z_CE_P(EX_VAR(opline->op1.var));
3861            if ((value = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(opline->op2.zv), ce)) != NULL) {
3862                ZVAL_DEREF(value);
3863                ZVAL_DUP(EX_VAR(opline->result.var), value);
3864                ZEND_VM_C_GOTO(constant_fetch_end);
3865            }
3866        }
3867
3868        if (EXPECTED((value = zend_hash_find(&ce->constants_table, Z_STR_P(opline->op2.zv))) != NULL)) {
3869            ZVAL_DEREF(value);
3870            if (Z_CONSTANT_P(value)) {
3871                EG(scope) = ce;
3872                zval_update_constant(value, 1 TSRMLS_CC);
3873                EG(scope) = EX(func)->op_array.scope;
3874            }
3875            if (OP1_TYPE == IS_CONST) {
3876                CACHE_PTR(Z_CACHE_SLOT_P(opline->op2.zv), value);
3877            } else {
3878                CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(opline->op2.zv), ce, value);
3879            }
3880            ZVAL_DUP(EX_VAR(opline->result.var), value);
3881        } else if (Z_STRLEN_P(opline->op2.zv) == sizeof("class")-1 && memcmp(Z_STRVAL_P(opline->op2.zv), "class", sizeof("class") - 1) == 0) {
3882            /* "class" is assigned as a case-sensitive keyword from zend_do_resolve_class_name */
3883            ZVAL_STR_COPY(EX_VAR(opline->result.var), ce->name);
3884        } else {
3885            zend_error_noreturn(E_ERROR, "Undefined class constant '%s'", Z_STRVAL_P(opline->op2.zv));
3886        }
3887    }
3888ZEND_VM_C_LABEL(constant_fetch_end):
3889    CHECK_EXCEPTION();
3890    ZEND_VM_NEXT_OPCODE();
3891}
3892
3893ZEND_VM_HANDLER(72, ZEND_ADD_ARRAY_ELEMENT, CONST|TMP|VAR|CV, CONST|TMP|VAR|UNUSED|CV)
3894{
3895    USE_OPLINE
3896    zend_free_op free_op1;
3897    zval *expr_ptr, new_expr;
3898
3899    SAVE_OPLINE();
3900    if ((OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) &&
3901        (opline->extended_value & ZEND_ARRAY_ELEMENT_REF)) {
3902        expr_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
3903        if (OP1_TYPE == IS_VAR && UNEXPECTED(expr_ptr == NULL)) {
3904            zend_error_noreturn(E_ERROR, "Cannot create references to/from string offsets");
3905        }
3906        ZVAL_MAKE_REF(expr_ptr);
3907        Z_ADDREF_P(expr_ptr);
3908        FREE_OP1_VAR_PTR();
3909    } else {
3910        expr_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
3911        if (OP1_TYPE == IS_TMP_VAR) {
3912            ZVAL_COPY_VALUE(&new_expr, expr_ptr);
3913            expr_ptr = &new_expr;
3914        } else if (OP1_TYPE == IS_CONST) {
3915            if (!Z_IMMUTABLE_P(expr_ptr)) {
3916                ZVAL_DUP(&new_expr, expr_ptr);
3917                expr_ptr = &new_expr;
3918            }
3919        } else if ((OP1_TYPE == IS_CV || OP1_TYPE == IS_VAR) && Z_ISREF_P(expr_ptr)) {
3920            expr_ptr = Z_REFVAL_P(expr_ptr);
3921            if (Z_REFCOUNTED_P(expr_ptr)) Z_ADDREF_P(expr_ptr);
3922            FREE_OP1_IF_VAR();
3923        } else if (OP1_TYPE == IS_CV && Z_REFCOUNTED_P(expr_ptr)) {
3924            Z_ADDREF_P(expr_ptr);
3925        }
3926    }
3927
3928    if (OP2_TYPE != IS_UNUSED) {
3929        zend_free_op free_op2;
3930        zval *offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
3931        zend_string *str;
3932        zend_ulong hval;
3933
3934ZEND_VM_C_LABEL(add_again):
3935        switch (Z_TYPE_P(offset)) {
3936            case IS_DOUBLE:
3937                hval = zend_dval_to_lval(Z_DVAL_P(offset));
3938                ZEND_VM_C_GOTO(num_index);
3939            case IS_LONG:
3940                hval = Z_LVAL_P(offset);
3941ZEND_VM_C_LABEL(num_index):
3942                zend_hash_index_update(Z_ARRVAL_P(EX_VAR(opline->result.var)), hval, expr_ptr);
3943                break;
3944            case IS_STRING:
3945                str = Z_STR_P(offset);
3946                if (OP2_TYPE != IS_CONST) {
3947                    if (ZEND_HANDLE_NUMERIC(str, hval)) {
3948                        ZEND_VM_C_GOTO(num_index);
3949                    }
3950                }
3951ZEND_VM_C_LABEL(str_index):
3952                zend_hash_update(Z_ARRVAL_P(EX_VAR(opline->result.var)), str, expr_ptr);
3953                break;
3954            case IS_NULL:
3955                str = STR_EMPTY_ALLOC();
3956                ZEND_VM_C_GOTO(str_index);
3957            case IS_FALSE:
3958                hval = 0;
3959                ZEND_VM_C_GOTO(num_index);
3960            case IS_TRUE:
3961                hval = 1;
3962                ZEND_VM_C_GOTO(num_index);
3963            case IS_REFERENCE:
3964                offset = Z_REFVAL_P(offset);
3965                ZEND_VM_C_GOTO(add_again);
3966                break;
3967            default:
3968                zend_error(E_WARNING, "Illegal offset type");
3969                zval_ptr_dtor(expr_ptr);
3970                /* do nothing */
3971                break;
3972        }
3973        FREE_OP2();
3974    } else {
3975        zend_hash_next_index_insert(Z_ARRVAL_P(EX_VAR(opline->result.var)), expr_ptr);
3976    }
3977    CHECK_EXCEPTION();
3978    ZEND_VM_NEXT_OPCODE();
3979}
3980
3981ZEND_VM_HANDLER(71, ZEND_INIT_ARRAY, CONST|TMP|VAR|UNUSED|CV, CONST|TMP|VAR|UNUSED|CV)
3982{
3983    zval *array;
3984    uint32_t size;
3985    USE_OPLINE
3986
3987    array = EX_VAR(opline->result.var);
3988    if (OP1_TYPE != IS_UNUSED) {
3989        size = opline->extended_value >> ZEND_ARRAY_SIZE_SHIFT;
3990    } else {
3991        size = 0;
3992    }
3993    ZVAL_NEW_ARR(array);
3994    zend_hash_init(Z_ARRVAL_P(array), size, NULL, ZVAL_PTR_DTOR, 0);
3995
3996    if (OP1_TYPE != IS_UNUSED) {
3997        /* Explicitly initialize array as not-packed if flag is set */
3998        if (opline->extended_value & ZEND_ARRAY_NOT_PACKED) {
3999            zend_hash_real_init(Z_ARRVAL_P(array), 0);
4000        }
4001    }
4002
4003    if (OP1_TYPE == IS_UNUSED) {
4004        ZEND_VM_NEXT_OPCODE();
4005#if !defined(ZEND_VM_SPEC) || OP1_TYPE != IS_UNUSED
4006    } else {
4007        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_ADD_ARRAY_ELEMENT);
4008#endif
4009    }
4010}
4011
4012ZEND_VM_HANDLER(21, ZEND_CAST, CONST|TMP|VAR|CV, ANY)
4013{
4014    USE_OPLINE
4015    zend_free_op free_op1;
4016    zval *expr;
4017    zval *result = EX_VAR(opline->result.var);
4018
4019    SAVE_OPLINE();
4020    expr = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
4021
4022    switch (opline->extended_value) {
4023        case IS_NULL:
4024            /* This code is taken from convert_to_null. However, it does not seems very useful,
4025             * because a conversion to null always results in the same value. This could only
4026             * be relevant if a cast_object handler for IS_NULL has some kind of side-effect. */
4027#if 0
4028            if (OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) {
4029                ZVAL_DEREF(expr);
4030            }
4031            if (Z_TYPE_P(expr) == IS_OBJECT && Z_OBJ_HT_P(expr)->cast_object) {
4032                if (Z_OBJ_HT_P(expr)->cast_object(expr, result, IS_NULL TSRMLS_CC) == SUCCESS) {
4033                    break;
4034                }
4035            }
4036#endif
4037
4038            ZVAL_NULL(result);
4039            break;
4040        case _IS_BOOL:
4041            ZVAL_BOOL(result, zend_is_true(expr TSRMLS_CC));
4042            break;
4043        case IS_LONG:
4044            ZVAL_LONG(result, zval_get_long(expr));
4045            break;
4046        case IS_DOUBLE:
4047            ZVAL_DOUBLE(result, zval_get_double(expr));
4048            break;
4049        case IS_STRING:
4050            ZVAL_STR(result, zval_get_string(expr));
4051            break;
4052        default:
4053            /* If value is already of correct type, return it directly */
4054            if (Z_TYPE_P(expr) == opline->extended_value) {
4055                ZVAL_COPY_VALUE(result, expr);
4056                if (OP1_TYPE == IS_CONST) {
4057                    if (UNEXPECTED(Z_OPT_COPYABLE_P(result))) {
4058                        zval_copy_ctor_func(result);
4059                    }
4060                } else if (OP1_TYPE != IS_TMP_VAR) {
4061                    if (Z_OPT_REFCOUNTED_P(expr)) Z_ADDREF_P(expr);
4062                }
4063
4064                FREE_OP1_IF_VAR();
4065                CHECK_EXCEPTION();
4066                ZEND_VM_NEXT_OPCODE();
4067            }
4068
4069            if (opline->extended_value == IS_ARRAY) {
4070                if (Z_TYPE_P(expr) != IS_OBJECT) {
4071                    ZVAL_NEW_ARR(result);
4072                    zend_hash_init(Z_ARRVAL_P(result), 8, NULL, ZVAL_PTR_DTOR, 0);
4073                    if (Z_TYPE_P(expr) != IS_NULL) {
4074                        expr = zend_hash_index_add_new(Z_ARRVAL_P(result), 0, expr);
4075                        if (OP1_TYPE == IS_CONST) {
4076                            if (UNEXPECTED(Z_OPT_COPYABLE_P(expr))) {
4077                                zval_copy_ctor_func(expr);
4078                            }
4079                        } else {
4080                            if (Z_OPT_REFCOUNTED_P(expr)) Z_ADDREF_P(expr);
4081                        }
4082                    }
4083                } else {
4084                    ZVAL_COPY_VALUE(result, expr);
4085                    Z_ADDREF_P(result);
4086                    convert_to_array(result);
4087                }
4088            } else {
4089                if (Z_TYPE_P(expr) != IS_ARRAY) {
4090                    object_init(result);
4091                    if (Z_TYPE_P(expr) != IS_NULL) {
4092                        expr = zend_hash_str_add_new(Z_OBJPROP_P(result), "scalar", sizeof("scalar")-1, expr);
4093                        if (OP1_TYPE == IS_CONST) {
4094                            if (UNEXPECTED(Z_OPT_COPYABLE_P(expr))) {
4095                                zval_copy_ctor_func(expr);
4096                            }
4097                        } else {
4098                            if (Z_OPT_REFCOUNTED_P(expr)) Z_ADDREF_P(expr);
4099                        }
4100                    }
4101                } else {
4102                    ZVAL_COPY_VALUE(result, expr);
4103                    zval_opt_copy_ctor(result);
4104                    convert_to_object(result);
4105                }
4106            }
4107    }
4108
4109    FREE_OP1();
4110    CHECK_EXCEPTION();
4111    ZEND_VM_NEXT_OPCODE();
4112}
4113
4114ZEND_VM_HANDLER(73, ZEND_INCLUDE_OR_EVAL, CONST|TMP|VAR|CV, ANY)
4115{
4116    USE_OPLINE
4117    zend_op_array *new_op_array=NULL;
4118    zend_free_op free_op1;
4119    zval *inc_filename;
4120    zval tmp_inc_filename;
4121    zend_bool failure_retval=0;
4122
4123    SAVE_OPLINE();
4124    inc_filename = GET_OP1_ZVAL_PTR(BP_VAR_R);
4125
4126    ZVAL_UNDEF(&tmp_inc_filename);
4127    if (Z_TYPE_P(inc_filename) != IS_STRING) {
4128        ZVAL_STR(&tmp_inc_filename, zval_get_string(inc_filename));
4129        inc_filename = &tmp_inc_filename;
4130    }
4131
4132    if (opline->extended_value != ZEND_EVAL && strlen(Z_STRVAL_P(inc_filename)) != Z_STRLEN_P(inc_filename)) {
4133        if (opline->extended_value == ZEND_INCLUDE_ONCE || opline->extended_value == ZEND_INCLUDE) {
4134            zend_message_dispatcher(ZMSG_FAILED_INCLUDE_FOPEN, Z_STRVAL_P(inc_filename) TSRMLS_CC);
4135        } else {
4136            zend_message_dispatcher(ZMSG_FAILED_REQUIRE_FOPEN, Z_STRVAL_P(inc_filename) TSRMLS_CC);
4137        }
4138    } else {
4139        switch (opline->extended_value) {
4140            case ZEND_INCLUDE_ONCE:
4141            case ZEND_REQUIRE_ONCE: {
4142                    zend_file_handle file_handle;
4143                    char *resolved_path;
4144
4145                    resolved_path = zend_resolve_path(Z_STRVAL_P(inc_filename), (int)Z_STRLEN_P(inc_filename) TSRMLS_CC);
4146                    if (resolved_path) {
4147                        failure_retval = zend_hash_str_exists(&EG(included_files), resolved_path, (int)strlen(resolved_path));
4148                    } else {
4149                        resolved_path = Z_STRVAL_P(inc_filename);
4150                    }
4151
4152                    if (failure_retval) {
4153                        /* do nothing, file already included */
4154                    } else if (SUCCESS == zend_stream_open(resolved_path, &file_handle TSRMLS_CC)) {
4155
4156                        if (!file_handle.opened_path) {
4157                            file_handle.opened_path = estrdup(resolved_path);
4158                        }
4159
4160                        if (zend_hash_str_add_empty_element(&EG(included_files), file_handle.opened_path, (int)strlen(file_handle.opened_path))) {
4161                            new_op_array = zend_compile_file(&file_handle, (opline->extended_value==ZEND_INCLUDE_ONCE?ZEND_INCLUDE:ZEND_REQUIRE) TSRMLS_CC);
4162                            zend_destroy_file_handle(&file_handle TSRMLS_CC);
4163                        } else {
4164                            zend_file_handle_dtor(&file_handle TSRMLS_CC);
4165                            failure_retval=1;
4166                        }
4167                    } else {
4168                        if (opline->extended_value == ZEND_INCLUDE_ONCE) {
4169                            zend_message_dispatcher(ZMSG_FAILED_INCLUDE_FOPEN, Z_STRVAL_P(inc_filename) TSRMLS_CC);
4170                        } else {
4171                            zend_message_dispatcher(ZMSG_FAILED_REQUIRE_FOPEN, Z_STRVAL_P(inc_filename) TSRMLS_CC);
4172                        }
4173                    }
4174                    if (resolved_path != Z_STRVAL_P(inc_filename)) {
4175                        efree(resolved_path);
4176                    }
4177                }
4178                break;
4179            case ZEND_INCLUDE:
4180            case ZEND_REQUIRE:
4181                new_op_array = compile_filename(opline->extended_value, inc_filename TSRMLS_CC);
4182                break;
4183            case ZEND_EVAL: {
4184                    char *eval_desc = zend_make_compiled_string_description("eval()'d code" TSRMLS_CC);
4185
4186                    new_op_array = zend_compile_string(inc_filename, eval_desc TSRMLS_CC);
4187                    efree(eval_desc);
4188                }
4189                break;
4190            EMPTY_SWITCH_DEFAULT_CASE()
4191        }
4192    }
4193    if (Z_TYPE(tmp_inc_filename) != IS_UNDEF) {
4194        zend_string_release(Z_STR(tmp_inc_filename));
4195    }
4196    FREE_OP1();
4197    if (UNEXPECTED(EG(exception) != NULL)) {
4198        HANDLE_EXCEPTION();
4199    } else if (EXPECTED(new_op_array != NULL)) {
4200        zval *return_value = NULL;
4201        zend_execute_data *call;
4202
4203        if (RETURN_VALUE_USED(opline)) {
4204            return_value = EX_VAR(opline->result.var);
4205        }
4206
4207        new_op_array->scope = EG(scope); /* ??? */
4208
4209        call = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_CODE,
4210            (zend_function*)new_op_array, 0, EX(called_scope), Z_OBJ(EX(This)), NULL TSRMLS_CC);
4211
4212        if (EX(symbol_table)) {
4213            call->symbol_table = EX(symbol_table);
4214        } else {
4215            call->symbol_table = zend_rebuild_symbol_table(TSRMLS_C);
4216        }
4217
4218        call->prev_execute_data = execute_data;
4219        i_init_code_execute_data(call, new_op_array, return_value TSRMLS_CC);
4220        if (EXPECTED(zend_execute_ex == execute_ex)) {
4221            ZEND_VM_ENTER();
4222        } else {
4223            ZEND_ADD_CALL_FLAG(call, ZEND_CALL_TOP);
4224            zend_execute_ex(call TSRMLS_CC);
4225        }
4226
4227        destroy_op_array(new_op_array TSRMLS_CC);
4228        efree_size(new_op_array, sizeof(zend_op_array));
4229        if (UNEXPECTED(EG(exception) != NULL)) {
4230            zend_throw_exception_internal(NULL TSRMLS_CC);
4231            HANDLE_EXCEPTION();
4232        }
4233
4234    } else if (RETURN_VALUE_USED(opline)) {
4235        ZVAL_BOOL(EX_VAR(opline->result.var), failure_retval);
4236    }
4237    ZEND_VM_NEXT_OPCODE();
4238}
4239
4240ZEND_VM_HANDLER(74, ZEND_UNSET_VAR, CONST|TMP|VAR|CV, UNUSED|CONST|VAR)
4241{
4242    USE_OPLINE
4243    zval tmp, *varname;
4244    HashTable *target_symbol_table;
4245    zend_free_op free_op1;
4246
4247    SAVE_OPLINE();
4248    if (OP1_TYPE == IS_CV &&
4249        OP2_TYPE == IS_UNUSED &&
4250        (opline->extended_value & ZEND_QUICK_SET)) {
4251        zval *var = EX_VAR(opline->op1.var);
4252
4253        if (Z_REFCOUNTED_P(var)) {
4254            zend_refcounted *garbage = Z_COUNTED_P(var);
4255
4256            if (!--GC_REFCOUNT(garbage)) {
4257                ZVAL_UNDEF(var);
4258                _zval_dtor_func_for_ptr(garbage ZEND_FILE_LINE_CC);
4259            } else {
4260                GC_ZVAL_CHECK_POSSIBLE_ROOT(var);
4261                ZVAL_UNDEF(var);
4262            }
4263        } else {
4264            ZVAL_UNDEF(var);
4265        }
4266        CHECK_EXCEPTION();
4267        ZEND_VM_NEXT_OPCODE();
4268    }
4269
4270    varname = GET_OP1_ZVAL_PTR(BP_VAR_R);
4271
4272    ZVAL_UNDEF(&tmp);
4273    if (OP1_TYPE != IS_CONST && Z_TYPE_P(varname) != IS_STRING) {
4274        ZVAL_STR(&tmp, zval_get_string(varname));
4275        varname = &tmp;
4276    }
4277
4278    if (OP2_TYPE != IS_UNUSED) {
4279        zend_class_entry *ce;
4280
4281        if (OP2_TYPE == IS_CONST) {
4282            if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv))) {
4283                ce = CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv));
4284            } else {
4285                ce = zend_fetch_class_by_name(Z_STR_P(opline->op2.zv), opline->op2.zv + 1, 0 TSRMLS_CC);
4286                if (UNEXPECTED(EG(exception) != NULL)) {
4287                    if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
4288                        zend_string_release(Z_STR(tmp));
4289                    }
4290                    FREE_OP1();
4291                    HANDLE_EXCEPTION();
4292                }
4293                if (UNEXPECTED(ce == NULL)) {
4294                    zend_error_noreturn(E_ERROR, "Class '%s' not found", Z_STRVAL_P(opline->op2.zv));
4295                }
4296                CACHE_PTR(Z_CACHE_SLOT_P(opline->op2.zv), ce);
4297            }
4298        } else {
4299            ce = Z_CE_P(EX_VAR(opline->op2.var));
4300        }
4301        zend_std_unset_static_property(ce, Z_STR_P(varname), ((OP1_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(varname)) : NULL) TSRMLS_CC);
4302    } else {
4303        target_symbol_table = zend_get_target_symbol_table(execute_data, opline->extended_value & ZEND_FETCH_TYPE_MASK TSRMLS_CC);
4304        zend_hash_del_ind(target_symbol_table, Z_STR_P(varname));
4305    }
4306
4307    if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
4308        zend_string_release(Z_STR(tmp));
4309    }
4310    FREE_OP1();
4311    CHECK_EXCEPTION();
4312    ZEND_VM_NEXT_OPCODE();
4313}
4314
4315ZEND_VM_HANDLER(75, ZEND_UNSET_DIM, VAR|UNUSED|CV, CONST|TMP|VAR|CV)
4316{
4317    USE_OPLINE
4318    zend_free_op free_op1, free_op2;
4319    zval *container;
4320    zval *offset;
4321    zend_ulong hval;
4322
4323    SAVE_OPLINE();
4324    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_UNSET);
4325    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
4326        zend_error_noreturn(E_ERROR, "Cannot unset string offsets");
4327    }
4328    if (OP1_TYPE != IS_UNUSED) {
4329        ZVAL_DEREF(container);
4330        SEPARATE_ZVAL_NOREF(container);
4331    }
4332    offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
4333
4334    if (OP1_TYPE != IS_UNUSED && EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
4335        HashTable *ht = Z_ARRVAL_P(container);
4336ZEND_VM_C_LABEL(offset_again):
4337        switch (Z_TYPE_P(offset)) {
4338            case IS_DOUBLE:
4339                hval = zend_dval_to_lval(Z_DVAL_P(offset));
4340                zend_hash_index_del(ht, hval);
4341                break;
4342            case IS_LONG:
4343                hval = Z_LVAL_P(offset);
4344ZEND_VM_C_LABEL(num_index_dim):
4345                zend_hash_index_del(ht, hval);
4346                break;
4347            case IS_STRING:
4348                if (OP2_TYPE != IS_CONST) {
4349                    if (ZEND_HANDLE_NUMERIC(Z_STR_P(offset), hval)) {
4350                        ZEND_VM_C_GOTO(num_index_dim);
4351                    }
4352                }
4353                if (ht == &EG(symbol_table).ht) {
4354                    zend_delete_global_variable(Z_STR_P(offset) TSRMLS_CC);
4355                } else {
4356                    zend_hash_del(ht, Z_STR_P(offset));
4357                }
4358                break;
4359            case IS_NULL:
4360                zend_hash_del(ht, STR_EMPTY_ALLOC());
4361                break;
4362            case IS_FALSE:
4363                hval = 0;
4364                ZEND_VM_C_GOTO(num_index_dim);
4365            case IS_TRUE:
4366                hval = 1;
4367                ZEND_VM_C_GOTO(num_index_dim);
4368            case IS_RESOURCE:
4369                hval = Z_RES_HANDLE_P(offset);
4370                ZEND_VM_C_GOTO(num_index_dim);
4371            case IS_REFERENCE:
4372                offset = Z_REFVAL_P(offset);
4373                ZEND_VM_C_GOTO(offset_again);
4374                break;
4375            default:
4376                zend_error(E_WARNING, "Illegal offset type in unset");
4377                break;
4378        }
4379        FREE_OP2();
4380    } else if (OP1_TYPE == IS_UNUSED || EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
4381        if (UNEXPECTED(Z_OBJ_HT_P(container)->unset_dimension == NULL)) {
4382            zend_error_noreturn(E_ERROR, "Cannot use object as array");
4383        }
4384//???       if (OP2_TYPE == IS_CONST) {
4385//???           zval_copy_ctor(offset);
4386//???       }
4387        Z_OBJ_HT_P(container)->unset_dimension(container, offset TSRMLS_CC);
4388        FREE_OP2();
4389    } else if (UNEXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
4390        zend_error_noreturn(E_ERROR, "Cannot unset string offsets");
4391        ZEND_VM_CONTINUE(); /* bailed out before */
4392    } else {
4393        FREE_OP2();
4394    }
4395    FREE_OP1_VAR_PTR();
4396    CHECK_EXCEPTION();
4397    ZEND_VM_NEXT_OPCODE();
4398}
4399
4400ZEND_VM_HANDLER(76, ZEND_UNSET_OBJ, VAR|UNUSED|CV, CONST|TMP|VAR|CV)
4401{
4402    USE_OPLINE
4403    zend_free_op free_op1, free_op2;
4404    zval *container;
4405    zval *offset;
4406
4407    SAVE_OPLINE();
4408    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_UNSET);
4409    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
4410        zend_error_noreturn(E_ERROR, "Cannot unset string offsets");
4411    }
4412    offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
4413
4414    ZVAL_DEREF(container);
4415    if (OP1_TYPE == IS_UNUSED || Z_TYPE_P(container) == IS_OBJECT) {
4416        if (Z_OBJ_HT_P(container)->unset_property) {
4417            Z_OBJ_HT_P(container)->unset_property(container, offset, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(offset)) : NULL) TSRMLS_CC);
4418        } else {
4419            zend_error(E_NOTICE, "Trying to unset property of non-object");
4420        }
4421    }
4422    FREE_OP2();
4423    FREE_OP1_VAR_PTR();
4424    CHECK_EXCEPTION();
4425    ZEND_VM_NEXT_OPCODE();
4426}
4427
4428ZEND_VM_HANDLER(77, ZEND_FE_RESET, CONST|TMP|VAR|CV, ANY)
4429{
4430    USE_OPLINE
4431    zend_free_op free_op1;
4432    zval *array_ptr, *array_ref, iterator, tmp;
4433    HashTable *fe_ht;
4434    zend_object_iterator *iter = NULL;
4435    zend_class_entry *ce = NULL;
4436    zend_bool is_empty = 0;
4437
4438    SAVE_OPLINE();
4439
4440    if ((OP1_TYPE == IS_CV || OP1_TYPE == IS_VAR) &&
4441        (opline->extended_value & ZEND_FE_FETCH_BYREF)) {
4442        array_ptr = array_ref = GET_OP1_ZVAL_PTR_PTR(BP_VAR_R);
4443        ZVAL_DEREF(array_ptr);
4444        if (Z_TYPE_P(array_ptr) == IS_ARRAY) {
4445            SEPARATE_ARRAY(array_ptr);
4446            if (!Z_ISREF_P(array_ref)) {
4447                ZVAL_NEW_REF(array_ref, array_ref);
4448                array_ptr = Z_REFVAL_P(array_ref);
4449            }
4450            if (Z_REFCOUNTED_P(array_ref)) Z_ADDREF_P(array_ref);
4451        } else if (Z_TYPE_P(array_ptr) == IS_OBJECT) {
4452            ce = Z_OBJCE_P(array_ptr);
4453            if (ce->get_iterator == NULL) {
4454                Z_ADDREF_P(array_ptr);
4455            }
4456            array_ref = array_ptr;
4457        } else {
4458            if (Z_REFCOUNTED_P(array_ref)) Z_ADDREF_P(array_ref);
4459        }
4460    } else {
4461        array_ptr = array_ref = GET_OP1_ZVAL_PTR(BP_VAR_R);
4462        ZVAL_DEREF(array_ptr);
4463        if (OP1_TYPE == IS_TMP_VAR) {
4464            ZVAL_COPY_VALUE(&tmp, array_ptr);
4465            if (Z_OPT_IMMUTABLE_P(&tmp)) {
4466                zval_copy_ctor_func(&tmp);
4467            }
4468            array_ref = array_ptr = &tmp;
4469            if (Z_TYPE_P(array_ptr) == IS_OBJECT) {
4470                ce = Z_OBJCE_P(array_ptr);
4471                if (ce && ce->get_iterator) {
4472                    Z_DELREF_P(array_ref);
4473                }
4474            }
4475        } else if (Z_TYPE_P(array_ptr) == IS_OBJECT) {
4476            ce = Z_OBJCE_P(array_ptr);
4477            if (!ce->get_iterator) {
4478                if (OP1_TYPE == IS_CV) {
4479                    Z_ADDREF_P(array_ref);
4480                }
4481            }
4482        } else if (Z_IMMUTABLE_P(array_ref)) {
4483            if (OP1_TYPE == IS_CV) {
4484                zval_copy_ctor_func(array_ref);
4485                Z_ADDREF_P(array_ref);
4486            } else {
4487                ZVAL_COPY_VALUE(&tmp, array_ref);
4488                zval_copy_ctor_func(&tmp);
4489                array_ptr = array_ref = &tmp;
4490            }
4491        } else if (Z_REFCOUNTED_P(array_ref)) {
4492            if (OP1_TYPE == IS_CONST ||
4493                       (OP1_TYPE == IS_CV &&
4494                        !Z_ISREF_P(array_ref) &&
4495                        Z_REFCOUNT_P(array_ref) > 1) ||
4496                       (OP1_TYPE == IS_VAR &&
4497                        !Z_ISREF_P(array_ref) &&
4498                        Z_REFCOUNT_P(array_ref) > 2)) {
4499                if (OP1_TYPE == IS_VAR) {
4500                    Z_DELREF_P(array_ref);
4501                }
4502                ZVAL_DUP(&tmp, array_ref);
4503                array_ptr = array_ref = &tmp;
4504            } else if (OP1_TYPE == IS_CV || OP1_TYPE == IS_VAR) {
4505                if (Z_ISREF_P(array_ref) && Z_REFCOUNT_P(array_ref) == 1) {
4506                    ZVAL_UNREF(array_ref);
4507                    array_ptr = array_ref;
4508                }
4509                if (Z_IMMUTABLE_P(array_ptr)) {
4510                    zval_copy_ctor_func(array_ptr);
4511                } else if (Z_ISREF_P(array_ref) &&
4512                           Z_COPYABLE_P(array_ptr) &&
4513                           Z_REFCOUNT_P(array_ptr) > 1) {
4514                    Z_DELREF_P(array_ptr);
4515                    zval_copy_ctor_func(array_ptr);
4516                }
4517                if (OP1_TYPE == IS_CV) {
4518                    Z_ADDREF_P(array_ref);
4519                }
4520            }
4521        }
4522    }
4523
4524    if (ce && ce->get_iterator) {
4525        iter = ce->get_iterator(ce, array_ptr, opline->extended_value & ZEND_FE_FETCH_BYREF TSRMLS_CC);
4526
4527        if (OP1_TYPE == IS_VAR && !(opline->extended_value & ZEND_FE_FETCH_BYREF)) {
4528            FREE_OP1_IF_VAR();
4529        }
4530        if (iter && EXPECTED(EG(exception) == NULL)) {
4531            ZVAL_OBJ(&iterator, &iter->std);
4532            array_ptr = array_ref = &iterator;
4533        } else {
4534            if (OP1_TYPE == IS_VAR && opline->extended_value & ZEND_FE_FETCH_BYREF) {
4535                FREE_OP1_VAR_PTR();
4536            }
4537            if (!EG(exception)) {
4538                zend_throw_exception_ex(NULL, 0 TSRMLS_CC, "Object of type %s did not create an Iterator", ce->name->val);
4539            }
4540            zend_throw_exception_internal(NULL TSRMLS_CC);
4541            HANDLE_EXCEPTION();
4542        }
4543    }
4544
4545    ZVAL_COPY_VALUE(EX_VAR(opline->result.var), array_ref);
4546
4547    if (iter) {
4548        iter->index = 0;
4549        if (iter->funcs->rewind) {
4550            iter->funcs->rewind(iter TSRMLS_CC);
4551            if (UNEXPECTED(EG(exception) != NULL)) {
4552                zval_ptr_dtor(array_ref);
4553                if (OP1_TYPE == IS_VAR && opline->extended_value & ZEND_FE_FETCH_BYREF) {
4554                    FREE_OP1_VAR_PTR();
4555                }
4556                HANDLE_EXCEPTION();
4557            }
4558        }
4559        is_empty = iter->funcs->valid(iter TSRMLS_CC) != SUCCESS;
4560        if (UNEXPECTED(EG(exception) != NULL)) {
4561            zval_ptr_dtor(array_ref);
4562            if (OP1_TYPE == IS_VAR && opline->extended_value & ZEND_FE_FETCH_BYREF) {
4563                FREE_OP1_VAR_PTR();
4564            }
4565            HANDLE_EXCEPTION();
4566        }
4567        iter->index = -1; /* will be set to 0 before using next handler */
4568    } else if ((fe_ht = HASH_OF(array_ptr)) != NULL) {
4569        HashPointer *ptr = (HashPointer*)EX_VAR((opline+2)->op1.var);
4570        HashPosition pos = 0;
4571        Bucket *p;
4572
4573        while (1) {
4574            if (pos >= fe_ht->nNumUsed) {
4575                is_empty = 1;
4576                if (OP1_TYPE == IS_VAR && opline->extended_value & ZEND_FE_FETCH_BYREF) {
4577                    FREE_OP1_VAR_PTR();
4578                }
4579                ZEND_VM_JMP(opline->op2.jmp_addr);
4580            }
4581            p = fe_ht->arData + pos;
4582            if (Z_TYPE(p->val) == IS_UNDEF ||
4583                (Z_TYPE(p->val) == IS_INDIRECT &&
4584                 Z_TYPE_P(Z_INDIRECT(p->val)) == IS_UNDEF)) {
4585                pos++;
4586                continue;
4587            }
4588            if (!ce ||
4589                !p->key ||
4590                zend_check_property_access(Z_OBJ_P(array_ptr), p->key TSRMLS_CC) == SUCCESS) {
4591                break;
4592            }
4593            pos++;
4594        }
4595        fe_ht->nInternalPointer = pos;
4596        ptr->pos = pos;
4597        ptr->ht = fe_ht;
4598        ptr->h = fe_ht->arData[pos].h;
4599        ptr->key = fe_ht->arData[pos].key;
4600        is_empty = 0;
4601    } else {
4602        zend_error(E_WARNING, "Invalid argument supplied for foreach()");
4603        is_empty = 1;
4604    }
4605
4606    if (OP1_TYPE == IS_VAR && opline->extended_value & ZEND_FE_FETCH_BYREF) {
4607        FREE_OP1_VAR_PTR();
4608    }
4609    if (is_empty) {
4610        ZEND_VM_JMP(opline->op2.jmp_addr);
4611    } else {
4612        CHECK_EXCEPTION();
4613        ZEND_VM_NEXT_OPCODE();
4614    }
4615}
4616
4617ZEND_VM_HANDLER(78, ZEND_FE_FETCH, VAR, ANY)
4618{
4619    USE_OPLINE
4620    zend_free_op free_op1;
4621    zval *array, *array_ref;
4622    zval *value;
4623    HashTable *fe_ht;
4624    HashPointer *ptr;
4625    HashPosition pos;
4626    Bucket *p;
4627
4628    array = array_ref = EX_VAR(opline->op1.var);
4629    if (Z_ISREF_P(array)) {
4630        array = Z_REFVAL_P(array);
4631        // TODO: referenced value might be changed to different array ???
4632        if (Z_IMMUTABLE_P(array)) {
4633            zval_copy_ctor_func(array);
4634        }
4635    }
4636
4637    SAVE_OPLINE();
4638
4639    if (EXPECTED(Z_TYPE_P(array) == IS_ARRAY)) {
4640        fe_ht = Z_ARRVAL_P(array);
4641        ptr = (HashPointer*)EX_VAR((opline+1)->op1.var);
4642        pos = ptr->pos;
4643        if (UNEXPECTED(pos == INVALID_IDX)) {
4644            /* reached end of iteration */
4645            ZEND_VM_JMP(opline->op2.jmp_addr);
4646        } else if (UNEXPECTED(ptr->ht != fe_ht)) {
4647            ptr->ht = fe_ht;
4648            pos = 0;
4649        } else if (UNEXPECTED(fe_ht->nInternalPointer != ptr->pos)) {
4650            if (fe_ht->u.flags & HASH_FLAG_PACKED) {
4651                pos = ptr->h;
4652            } else {
4653                pos = fe_ht->arHash[ptr->h & fe_ht->nTableMask];
4654                while (1) {
4655                    if (pos == INVALID_IDX) {
4656                        pos = fe_ht->nInternalPointer;
4657                        break;
4658                    } else if (fe_ht->arData[pos].h == ptr->h && fe_ht->arData[pos].key == ptr->key) {
4659                        break;
4660                    }
4661                    pos = Z_NEXT(fe_ht->arData[pos].val);
4662                }
4663            }
4664        }
4665        while (1) {
4666            if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
4667                /* reached end of iteration */
4668                ZEND_VM_JMP(opline->op2.jmp_addr);
4669            }
4670            p = fe_ht->arData + pos;
4671            value = &p->val;
4672            if (UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
4673                pos++;
4674                continue;
4675            } else if (UNEXPECTED(Z_TYPE_P(value) == IS_INDIRECT)) {
4676                value = Z_INDIRECT_P(value);
4677                if (UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
4678                    pos++;
4679                    continue;
4680                }
4681            }
4682            if (opline->extended_value & ZEND_FE_FETCH_BYREF) {
4683                ZVAL_MAKE_REF(value);
4684                Z_ADDREF_P(value);
4685                ZVAL_REF(EX_VAR(opline->result.var), Z_REF_P(value));
4686            } else {
4687                ZVAL_COPY(EX_VAR(opline->result.var), value);
4688            }
4689            if (opline->extended_value & ZEND_FE_FETCH_WITH_KEY) {
4690                if (!p->key) {
4691                    ZVAL_LONG(EX_VAR((opline+1)->result.var), p->h);
4692                } else {
4693                    ZVAL_STR_COPY(EX_VAR((opline+1)->result.var), p->key);
4694                }
4695            }
4696            break;
4697        }
4698        do {
4699            pos++;
4700            if (pos >= fe_ht->nNumUsed) {
4701                fe_ht->nInternalPointer = ptr->pos = INVALID_IDX;
4702                ZEND_VM_INC_OPCODE();
4703                ZEND_VM_NEXT_OPCODE();
4704            }
4705            p = fe_ht->arData + pos;
4706        } while (Z_TYPE(p->val) == IS_UNDEF ||
4707                 (Z_TYPE(p->val) == IS_INDIRECT &&
4708                  Z_TYPE_P(Z_INDIRECT(p->val)) == IS_UNDEF));
4709        fe_ht->nInternalPointer = ptr->pos = pos;
4710        ptr->h = fe_ht->arData[pos].h;
4711        ptr->key = fe_ht->arData[pos].key;
4712        ZEND_VM_INC_OPCODE();
4713        ZEND_VM_NEXT_OPCODE();
4714    } else if (EXPECTED(Z_TYPE_P(array) == IS_OBJECT)) {
4715        zend_object_iterator *iter;
4716
4717        if ((iter = zend_iterator_unwrap(array TSRMLS_CC)) == NULL) {
4718            /* plain object */
4719            zend_object *zobj = Z_OBJ_P(array);
4720
4721            fe_ht = Z_OBJPROP_P(array);
4722            ptr = (HashPointer*)EX_VAR((opline+1)->op1.var);
4723            pos = ptr->pos;
4724            if (pos == INVALID_IDX) {
4725                /* reached end of iteration */
4726                ZEND_VM_JMP(opline->op2.jmp_addr);
4727            } else if (UNEXPECTED(ptr->ht != fe_ht)) {
4728                ptr->ht = fe_ht;
4729                pos = 0;
4730            } else if (UNEXPECTED(fe_ht->nInternalPointer != ptr->pos)) {
4731                if (fe_ht->u.flags & HASH_FLAG_PACKED) {
4732                    pos = ptr->h;
4733                } else {
4734                    pos = fe_ht->arHash[ptr->h & fe_ht->nTableMask];
4735                    while (1) {
4736                        if (pos == INVALID_IDX) {
4737                            pos = fe_ht->nInternalPointer;
4738                            break;
4739                        } else if (fe_ht->arData[pos].h == ptr->h && fe_ht->arData[pos].key == ptr->key) {
4740                            break;
4741                        }
4742                        pos = Z_NEXT(fe_ht->arData[pos].val);
4743                    }
4744                }
4745            }
4746            while (1) {
4747                if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
4748                    /* reached end of iteration */
4749                    ZEND_VM_JMP(opline->op2.jmp_addr);
4750                }
4751
4752                p = fe_ht->arData + pos;
4753                value = &p->val;
4754                if (UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
4755                    pos++;
4756                    continue;
4757                } else if (UNEXPECTED(Z_TYPE_P(value) == IS_INDIRECT)) {
4758                    value = Z_INDIRECT_P(value);
4759                    if (UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
4760                        pos++;
4761                        continue;
4762                    }
4763                }
4764
4765                if (UNEXPECTED(!p->key)) {
4766                    if (opline->extended_value & ZEND_FE_FETCH_WITH_KEY) {
4767                        ZVAL_LONG(EX_VAR((opline+1)->result.var), p->h);
4768                    }
4769                    break;
4770                } else if (zend_check_property_access(zobj, p->key TSRMLS_CC) == SUCCESS) {
4771                    if (opline->extended_value & ZEND_FE_FETCH_WITH_KEY) {
4772                        if (p->key->val[0]) {
4773                            ZVAL_STR_COPY(EX_VAR((opline+1)->result.var), p->key);
4774                        } else {
4775                            const char *class_name, *prop_name;
4776                            size_t prop_name_len;
4777                            zend_unmangle_property_name_ex(
4778                                p->key, &class_name, &prop_name, &prop_name_len);
4779                            ZVAL_STRINGL(EX_VAR((opline+1)->result.var), prop_name, prop_name_len);
4780                        }
4781                    }
4782                    break;
4783                }
4784                pos++;
4785            }
4786            if (opline->extended_value & ZEND_FE_FETCH_BYREF) {
4787                ZVAL_MAKE_REF(value);
4788                Z_ADDREF_P(value);
4789                ZVAL_REF(EX_VAR(opline->result.var), Z_REF_P(value));
4790            } else {
4791                ZVAL_COPY(EX_VAR(opline->result.var), value);
4792            }
4793            do {
4794                pos++;
4795                if (pos >= fe_ht->nNumUsed) {
4796                    fe_ht->nInternalPointer = ptr->pos = INVALID_IDX;
4797                    ZEND_VM_INC_OPCODE();
4798                    ZEND_VM_NEXT_OPCODE();
4799                }
4800                p = fe_ht->arData + pos;
4801            } while (Z_TYPE(p->val) == IS_UNDEF ||
4802                     (Z_TYPE(p->val) == IS_INDIRECT &&
4803                      Z_TYPE_P(Z_INDIRECT(p->val)) == IS_UNDEF) ||
4804                     (EXPECTED(p->key != NULL) &&
4805                      zend_check_property_access(zobj, p->key TSRMLS_CC) == FAILURE));
4806            fe_ht->nInternalPointer = ptr->pos = pos;
4807            ptr->h = fe_ht->arData[pos].h;
4808            ptr->key = fe_ht->arData[pos].key;
4809            ZEND_VM_INC_OPCODE();
4810            ZEND_VM_NEXT_OPCODE();
4811        } else {
4812            /* !iter happens from exception */
4813            if (iter && ++iter->index > 0) {
4814                /* This could cause an endless loop if index becomes zero again.
4815                 * In case that ever happens we need an additional flag. */
4816                iter->funcs->move_forward(iter TSRMLS_CC);
4817                if (UNEXPECTED(EG(exception) != NULL)) {
4818                    zval_ptr_dtor(array_ref);
4819                    HANDLE_EXCEPTION();
4820                }
4821            }
4822            /* If index is zero we come from FE_RESET and checked valid() already. */
4823            if (!iter || (iter->index > 0 && iter->funcs->valid(iter TSRMLS_CC) == FAILURE)) {
4824                /* reached end of iteration */
4825                if (UNEXPECTED(EG(exception) != NULL)) {
4826                    zval_ptr_dtor(array_ref);
4827                    HANDLE_EXCEPTION();
4828                }
4829                ZEND_VM_JMP(opline->op2.jmp_addr);
4830            }
4831            value = iter->funcs->get_current_data(iter TSRMLS_CC);
4832            if (UNEXPECTED(EG(exception) != NULL)) {
4833                zval_ptr_dtor(array_ref);
4834                HANDLE_EXCEPTION();
4835            }
4836            if (!value) {
4837                /* failure in get_current_data */
4838                ZEND_VM_JMP(opline->op2.jmp_addr);
4839            }
4840            if (opline->extended_value & ZEND_FE_FETCH_BYREF) {
4841                ZVAL_MAKE_REF(value);
4842                Z_ADDREF_P(value);
4843                ZVAL_REF(EX_VAR(opline->result.var), Z_REF_P(value));
4844            } else {
4845                ZVAL_COPY(EX_VAR(opline->result.var), value);
4846            }
4847            if (opline->extended_value & ZEND_FE_FETCH_WITH_KEY) {
4848                if (iter->funcs->get_current_key) {
4849                    iter->funcs->get_current_key(iter, EX_VAR((opline+1)->result.var) TSRMLS_CC);
4850                    if (UNEXPECTED(EG(exception) != NULL)) {
4851                        zval_ptr_dtor(array_ref);
4852                        HANDLE_EXCEPTION();
4853                    }
4854                } else {
4855                    ZVAL_LONG(EX_VAR((opline+1)->result.var), iter->index);
4856                }
4857            }
4858            ZEND_VM_INC_OPCODE();
4859            ZEND_VM_NEXT_OPCODE();
4860        }
4861    } else {
4862        zend_error(E_WARNING, "Invalid argument supplied for foreach()");
4863        ZEND_VM_JMP(opline->op2.jmp_addr);
4864    }
4865}
4866
4867ZEND_VM_HANDLER(114, ZEND_ISSET_ISEMPTY_VAR, CONST|TMP|VAR|CV, UNUSED|CONST|VAR)
4868{
4869    USE_OPLINE
4870    zval *value;
4871
4872    SAVE_OPLINE();
4873    if (OP1_TYPE == IS_CV &&
4874        OP2_TYPE == IS_UNUSED &&
4875        (opline->extended_value & ZEND_QUICK_SET)) {
4876        value = EX_VAR(opline->op1.var);
4877        if (opline->extended_value & ZEND_ISSET) {
4878            ZVAL_BOOL(EX_VAR(opline->result.var),
4879                Z_TYPE_P(value) > IS_NULL &&
4880                (!Z_ISREF_P(value) || Z_TYPE_P(Z_REFVAL_P(value)) != IS_NULL));
4881        } else /* if (opline->extended_value & ZEND_ISEMPTY) */ {
4882            ZVAL_BOOL(EX_VAR(opline->result.var),
4883                !i_zend_is_true(value TSRMLS_CC));
4884            CHECK_EXCEPTION();
4885        }
4886        ZEND_VM_NEXT_OPCODE();
4887    } else {
4888        zend_free_op free_op1;
4889        zval tmp, *varname = GET_OP1_ZVAL_PTR(BP_VAR_IS);
4890
4891        ZVAL_UNDEF(&tmp);
4892        if (OP1_TYPE != IS_CONST && Z_TYPE_P(varname) != IS_STRING) {
4893            ZVAL_STR(&tmp, zval_get_string(varname));
4894            varname = &tmp;
4895        }
4896
4897        if (OP2_TYPE != IS_UNUSED) {
4898            zend_class_entry *ce;
4899
4900            if (OP2_TYPE == IS_CONST) {
4901                if (CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv))) {
4902                    ce = CACHED_PTR(Z_CACHE_SLOT_P(opline->op2.zv));
4903                } else {
4904                    ce = zend_fetch_class_by_name(Z_STR_P(opline->op2.zv), opline->op2.zv + 1, 0 TSRMLS_CC);
4905                    if (UNEXPECTED(ce == NULL)) {
4906                        CHECK_EXCEPTION();
4907                        ZEND_VM_NEXT_OPCODE();
4908                    }
4909                    CACHE_PTR(Z_CACHE_SLOT_P(opline->op2.zv), ce);
4910                }
4911            } else {
4912                ce = Z_CE_P(EX_VAR(opline->op2.var));
4913            }
4914            value = zend_std_get_static_property(ce, Z_STR_P(varname), 1, ((OP1_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(varname)) : NULL) TSRMLS_CC);
4915        } else {
4916            HashTable *target_symbol_table = zend_get_target_symbol_table(execute_data, opline->extended_value & ZEND_FETCH_TYPE_MASK TSRMLS_CC);
4917            value = zend_hash_find_ind(target_symbol_table, Z_STR_P(varname));
4918        }
4919
4920        if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
4921            zend_string_release(Z_STR(tmp));
4922        }
4923        FREE_OP1();
4924
4925        if (opline->extended_value & ZEND_ISSET) {
4926            ZVAL_BOOL(EX_VAR(opline->result.var),
4927                value && Z_TYPE_P(value) > IS_NULL &&
4928                (!Z_ISREF_P(value) || Z_TYPE_P(Z_REFVAL_P(value)) != IS_NULL));
4929        } else /* if (opline->extended_value & ZEND_ISEMPTY) */ {
4930            ZVAL_BOOL(EX_VAR(opline->result.var),
4931                !value || !i_zend_is_true(value TSRMLS_CC));
4932        }
4933
4934        CHECK_EXCEPTION();
4935        ZEND_VM_NEXT_OPCODE();
4936    }
4937}
4938
4939ZEND_VM_HANDLER(115, ZEND_ISSET_ISEMPTY_DIM_OBJ, CONST|TMP|VAR|UNUSED|CV, CONST|TMP|VAR|CV)
4940{
4941    USE_OPLINE
4942    zend_free_op free_op1, free_op2;
4943    zval *container;
4944    int result;
4945    zend_ulong hval;
4946    zval *offset;
4947
4948    SAVE_OPLINE();
4949    container = GET_OP1_OBJ_ZVAL_PTR_DEREF(BP_VAR_IS);
4950    offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
4951
4952    if (OP1_TYPE != IS_UNUSED && EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
4953        HashTable *ht = Z_ARRVAL_P(container);
4954        zval *value;
4955        zend_string *str;
4956
4957ZEND_VM_C_LABEL(isset_again):
4958        if (EXPECTED(Z_TYPE_P(offset) == IS_STRING)) {
4959            str = Z_STR_P(offset);
4960            if (OP2_TYPE != IS_CONST) {
4961                if (ZEND_HANDLE_NUMERIC(str, hval)) {
4962                    ZEND_VM_C_GOTO(num_index_prop);
4963                }
4964            }
4965ZEND_VM_C_LABEL(str_index_prop):
4966            value = zend_hash_find_ind(ht, str);
4967        } else if (EXPECTED(Z_TYPE_P(offset) == IS_LONG)) {
4968            hval = Z_LVAL_P(offset);
4969ZEND_VM_C_LABEL(num_index_prop):
4970            value = zend_hash_index_find(ht, hval);
4971        } else {
4972            switch (Z_TYPE_P(offset)) {
4973                case IS_DOUBLE:
4974                    hval = zend_dval_to_lval(Z_DVAL_P(offset));
4975                    ZEND_VM_C_GOTO(num_index_prop);
4976                case IS_NULL:
4977                    str = STR_EMPTY_ALLOC();
4978                    ZEND_VM_C_GOTO(str_index_prop);
4979                case IS_FALSE:
4980                    hval = 0;
4981                    ZEND_VM_C_GOTO(num_index_prop);
4982                case IS_TRUE:
4983                    hval = 1;
4984                    ZEND_VM_C_GOTO(num_index_prop);
4985                case IS_RESOURCE:
4986                    hval = Z_RES_HANDLE_P(offset);
4987                    ZEND_VM_C_GOTO(num_index_prop);
4988                case IS_REFERENCE:
4989                    offset = Z_REFVAL_P(offset);
4990                    ZEND_VM_C_GOTO(isset_again);
4991                default:
4992                    zend_error(E_WARNING, "Illegal offset type in isset or empty");
4993                    value = NULL;
4994                    break;
4995            }
4996        }
4997
4998        if (opline->extended_value & ZEND_ISSET) {
4999            /* > IS_NULL means not IS_UNDEF and not IS_NULL */
5000            result = value != NULL && Z_TYPE_P(value) > IS_NULL &&
5001                (!Z_ISREF_P(value) || Z_TYPE_P(Z_REFVAL_P(value)) != IS_NULL);
5002        } else /* if (opline->extended_value & ZEND_ISEMPTY) */ {
5003            result = (value == NULL || !i_zend_is_true(value TSRMLS_CC));
5004        }
5005    } else if (OP1_TYPE == IS_UNUSED || EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
5006        if (EXPECTED(Z_OBJ_HT_P(container)->has_dimension)) {
5007            result = Z_OBJ_HT_P(container)->has_dimension(container, offset, (opline->extended_value & ZEND_ISSET) == 0 TSRMLS_CC);
5008        } else {
5009            zend_error(E_NOTICE, "Trying to check element of non-array");
5010            result = 0;
5011        }
5012        if ((opline->extended_value & ZEND_ISSET) == 0) {
5013            result = !result;
5014        }
5015    } else if (EXPECTED(Z_TYPE_P(container) == IS_STRING)) { /* string offsets */
5016        zval tmp;
5017
5018        result = 0;
5019        if (UNEXPECTED(Z_TYPE_P(offset) != IS_LONG)) {
5020            if (OP2_TYPE == IS_CV || OP2_TYPE == IS_VAR) {
5021                ZVAL_DEREF(offset);
5022            }
5023            if (Z_TYPE_P(offset) < IS_STRING /* simple scalar types */
5024                    || (Z_TYPE_P(offset) == IS_STRING /* or numeric string */
5025                        && IS_LONG == is_numeric_string(Z_STRVAL_P(offset), Z_STRLEN_P(offset), NULL, NULL, 0))) {
5026                ZVAL_DUP(&tmp, offset);
5027                convert_to_long(&tmp);
5028                offset = &tmp;
5029            }
5030        }
5031        if (EXPECTED(Z_TYPE_P(offset) == IS_LONG)) {
5032            if (offset->value.lval >= 0 && (size_t)offset->value.lval < Z_STRLEN_P(container)) {
5033                if ((opline->extended_value & ZEND_ISSET) ||
5034                    Z_STRVAL_P(container)[offset->value.lval] != '0') {
5035                    result = 1;
5036                }
5037            }
5038        }
5039        if ((opline->extended_value & ZEND_ISSET) == 0) {
5040            result = !result;
5041        }
5042    } else {
5043        result = ((opline->extended_value & ZEND_ISSET) == 0);
5044    }
5045
5046    FREE_OP2();
5047    ZVAL_BOOL(EX_VAR(opline->result.var), result);
5048    FREE_OP1();
5049    CHECK_EXCEPTION();
5050    ZEND_VM_NEXT_OPCODE();
5051}
5052
5053ZEND_VM_HANDLER(148, ZEND_ISSET_ISEMPTY_PROP_OBJ, CONST|TMP|VAR|UNUSED|CV, CONST|TMP|VAR|CV)
5054{
5055    USE_OPLINE
5056    zend_free_op free_op1, free_op2;
5057    zval *container;
5058    int result;
5059    zval *offset;
5060
5061    SAVE_OPLINE();
5062    container = GET_OP1_OBJ_ZVAL_PTR_DEREF(BP_VAR_IS);
5063    offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
5064
5065    if (OP1_TYPE == IS_UNUSED || EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
5066        if (EXPECTED(Z_OBJ_HT_P(container)->has_property)) {
5067            result = Z_OBJ_HT_P(container)->has_property(container, offset, (opline->extended_value & ZEND_ISSET) == 0, ((OP2_TYPE == IS_CONST) ? (EX(run_time_cache) + Z_CACHE_SLOT_P(offset)) : NULL) TSRMLS_CC);
5068        } else {
5069            zend_error(E_NOTICE, "Trying to check property of non-object");
5070            result = 0;
5071        }
5072        if ((opline->extended_value & ZEND_ISSET) == 0) {
5073            result = !result;
5074        }
5075    } else {
5076        result = ((opline->extended_value & ZEND_ISSET) == 0);
5077    }
5078
5079    FREE_OP2();
5080    ZVAL_BOOL(EX_VAR(opline->result.var), result);
5081    FREE_OP1();
5082    CHECK_EXCEPTION();
5083    ZEND_VM_NEXT_OPCODE();
5084}
5085
5086ZEND_VM_HANDLER(79, ZEND_EXIT, CONST|TMP|VAR|UNUSED|CV, ANY)
5087{
5088#if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
5089    USE_OPLINE
5090
5091    SAVE_OPLINE();
5092    if (OP1_TYPE != IS_UNUSED) {
5093        zend_free_op free_op1;
5094        zval *ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
5095
5096        if (Z_TYPE_P(ptr) == IS_LONG) {
5097            EG(