1/*
2   +----------------------------------------------------------------------+
3   | Zend Engine                                                          |
4   +----------------------------------------------------------------------+
5   | Copyright (c) 1998-2015 Zend Technologies Ltd. (http://www.zend.com) |
6   +----------------------------------------------------------------------+
7   | This source file is subject to version 2.00 of the Zend license,     |
8   | that is bundled with this package in the file LICENSE, and is        |
9   | available through the world-wide-web at the following url:           |
10   | http://www.zend.com/license/2_00.txt.                                |
11   | If you did not receive a copy of the Zend license and are unable to  |
12   | obtain it through the world-wide-web, please send a note to          |
13   | license@zend.com so we can mail you a copy immediately.              |
14   +----------------------------------------------------------------------+
15   | Authors: Andi Gutmans <andi@zend.com>                                |
16   |          Zeev Suraski <zeev@zend.com>                                |
17   |          Dmitry Stogov <dmitry@zend.com>                             |
18   +----------------------------------------------------------------------+
19*/
20
21/* $Id$ */
22
23/* If you change this file, please regenerate the zend_vm_execute.h and
24 * zend_vm_opcodes.h files by running:
25 * php zend_vm_gen.php
26 */
27
28ZEND_VM_HANDLER(1, ZEND_ADD, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
29{
30    USE_OPLINE
31    zend_free_op free_op1, free_op2;
32    zval *op1, *op2, *result;
33
34    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
35    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
36    if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
37        if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
38            result = EX_VAR(opline->result.var);
39            fast_long_add_function(result, op1, op2);
40            ZEND_VM_NEXT_OPCODE();
41        } else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
42            result = EX_VAR(opline->result.var);
43            ZVAL_DOUBLE(result, ((double)Z_LVAL_P(op1)) + Z_DVAL_P(op2));
44            ZEND_VM_NEXT_OPCODE();
45        }
46    } else if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_DOUBLE)) {
47        if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
48            result = EX_VAR(opline->result.var);
49            ZVAL_DOUBLE(result, Z_DVAL_P(op1) + Z_DVAL_P(op2));
50            ZEND_VM_NEXT_OPCODE();
51        } else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
52            result = EX_VAR(opline->result.var);
53            ZVAL_DOUBLE(result, Z_DVAL_P(op1) + ((double)Z_LVAL_P(op2)));
54            ZEND_VM_NEXT_OPCODE();
55        }
56    }
57
58    SAVE_OPLINE();
59    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
60        op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
61    }
62    if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
63        op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
64    }
65    add_function(EX_VAR(opline->result.var), op1, op2);
66    FREE_OP1();
67    FREE_OP2();
68    CHECK_EXCEPTION();
69    ZEND_VM_NEXT_OPCODE();
70}
71
72ZEND_VM_HANDLER(2, ZEND_SUB, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
73{
74    USE_OPLINE
75    zend_free_op free_op1, free_op2;
76    zval *op1, *op2, *result;
77
78    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
79    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
80    if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
81        if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
82            result = EX_VAR(opline->result.var);
83            fast_long_sub_function(result, op1, op2);
84            ZEND_VM_NEXT_OPCODE();
85        } else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
86            result = EX_VAR(opline->result.var);
87            ZVAL_DOUBLE(result, ((double)Z_LVAL_P(op1)) - Z_DVAL_P(op2));
88            ZEND_VM_NEXT_OPCODE();
89        }
90    } else if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_DOUBLE)) {
91        if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
92            result = EX_VAR(opline->result.var);
93            ZVAL_DOUBLE(result, Z_DVAL_P(op1) - Z_DVAL_P(op2));
94            ZEND_VM_NEXT_OPCODE();
95        } else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
96            result = EX_VAR(opline->result.var);
97            ZVAL_DOUBLE(result, Z_DVAL_P(op1) - ((double)Z_LVAL_P(op2)));
98            ZEND_VM_NEXT_OPCODE();
99        }
100    }
101
102    SAVE_OPLINE();
103    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
104        op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
105    }
106    if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
107        op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
108    }
109    sub_function(EX_VAR(opline->result.var), op1, op2);
110    FREE_OP1();
111    FREE_OP2();
112    CHECK_EXCEPTION();
113    ZEND_VM_NEXT_OPCODE();
114}
115
116ZEND_VM_HANDLER(3, ZEND_MUL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
117{
118    USE_OPLINE
119    zend_free_op free_op1, free_op2;
120    zval *op1, *op2, *result;
121
122    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
123    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
124    if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
125        if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
126            zend_long overflow;
127
128            result = EX_VAR(opline->result.var);
129            ZEND_SIGNED_MULTIPLY_LONG(Z_LVAL_P(op1), Z_LVAL_P(op2), Z_LVAL_P(result), Z_DVAL_P(result), overflow);
130            Z_TYPE_INFO_P(result) = overflow ? IS_DOUBLE : IS_LONG;
131            ZEND_VM_NEXT_OPCODE();
132        } else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
133            result = EX_VAR(opline->result.var);
134            ZVAL_DOUBLE(result, ((double)Z_LVAL_P(op1)) * Z_DVAL_P(op2));
135            ZEND_VM_NEXT_OPCODE();
136        }
137    } else if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_DOUBLE)) {
138        if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
139            result = EX_VAR(opline->result.var);
140            ZVAL_DOUBLE(result, Z_DVAL_P(op1) * Z_DVAL_P(op2));
141            ZEND_VM_NEXT_OPCODE();
142        } else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
143            result = EX_VAR(opline->result.var);
144            ZVAL_DOUBLE(result, Z_DVAL_P(op1) * ((double)Z_LVAL_P(op2)));
145            ZEND_VM_NEXT_OPCODE();
146        }
147    }
148
149    SAVE_OPLINE();
150    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
151        op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
152    }
153    if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
154        op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
155    }
156    mul_function(EX_VAR(opline->result.var), op1, op2);
157    FREE_OP1();
158    FREE_OP2();
159    CHECK_EXCEPTION();
160    ZEND_VM_NEXT_OPCODE();
161}
162
163ZEND_VM_HANDLER(4, ZEND_DIV, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
164{
165    USE_OPLINE
166    zend_free_op free_op1, free_op2;
167    zval *op1, *op2;
168
169    SAVE_OPLINE();
170    op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
171    op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
172    fast_div_function(EX_VAR(opline->result.var), op1, op2);
173    FREE_OP1();
174    FREE_OP2();
175    CHECK_EXCEPTION();
176    ZEND_VM_NEXT_OPCODE();
177}
178
179ZEND_VM_HANDLER(5, ZEND_MOD, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
180{
181    USE_OPLINE
182    zend_free_op free_op1, free_op2;
183    zval *op1, *op2, *result;
184
185    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
186    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
187    if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
188        if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
189            result = EX_VAR(opline->result.var);
190            if (UNEXPECTED(Z_LVAL_P(op2) == 0)) {
191                SAVE_OPLINE();
192                zend_throw_exception_ex(zend_ce_division_by_zero_error, 0, "Modulo by zero");
193                HANDLE_EXCEPTION();
194            } else if (UNEXPECTED(Z_LVAL_P(op2) == -1)) {
195                /* Prevent overflow error/crash if op1==ZEND_LONG_MIN */
196                ZVAL_LONG(result, 0);
197            } else {
198                ZVAL_LONG(result, Z_LVAL_P(op1) % Z_LVAL_P(op2));
199            }
200            ZEND_VM_NEXT_OPCODE();
201        }
202    }
203
204    SAVE_OPLINE();
205    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
206        op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
207    }
208    if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
209        op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
210    }
211    mod_function(EX_VAR(opline->result.var), op1, op2);
212    FREE_OP1();
213    FREE_OP2();
214    CHECK_EXCEPTION();
215    ZEND_VM_NEXT_OPCODE();
216}
217
218ZEND_VM_HANDLER(6, ZEND_SL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
219{
220    USE_OPLINE
221    zend_free_op free_op1, free_op2;
222    zval *op1, *op2;
223
224    SAVE_OPLINE();
225    op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
226    op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
227    shift_left_function(EX_VAR(opline->result.var), op1, op2);
228    FREE_OP1();
229    FREE_OP2();
230    CHECK_EXCEPTION();
231    ZEND_VM_NEXT_OPCODE();
232}
233
234ZEND_VM_HANDLER(7, ZEND_SR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
235{
236    USE_OPLINE
237    zend_free_op free_op1, free_op2;
238    zval *op1, *op2;
239
240    SAVE_OPLINE();
241    op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
242    op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
243    shift_right_function(EX_VAR(opline->result.var), op1, op2);
244    FREE_OP1();
245    FREE_OP2();
246    CHECK_EXCEPTION();
247    ZEND_VM_NEXT_OPCODE();
248}
249
250ZEND_VM_HANDLER(8, ZEND_CONCAT, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
251{
252    USE_OPLINE
253    zend_free_op free_op1, free_op2;
254    zval *op1, *op2;
255
256    SAVE_OPLINE();
257    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
258    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
259
260    do {
261        if ((OP1_TYPE == IS_CONST || EXPECTED(Z_TYPE_P(op1) == IS_STRING)) &&
262            (OP2_TYPE == IS_CONST || EXPECTED(Z_TYPE_P(op2) == IS_STRING))) {
263            zend_string *op1_str = Z_STR_P(op1);
264            zend_string *op2_str = Z_STR_P(op2);
265            zend_string *str;
266
267            if (OP1_TYPE != IS_CONST) {
268                if (UNEXPECTED(ZSTR_LEN(op1_str) == 0)) {
269                    ZVAL_STR_COPY(EX_VAR(opline->result.var), op2_str);
270                    FREE_OP1();
271                    break;
272                }
273            }
274            if (OP2_TYPE != IS_CONST) {
275                if (UNEXPECTED(ZSTR_LEN(op2_str) == 0)) {
276                    ZVAL_STR_COPY(EX_VAR(opline->result.var), op1_str);
277                    FREE_OP1();
278                    break;
279                }
280            }
281            if (OP1_TYPE != IS_CONST && OP1_TYPE != IS_CV &&
282                !ZSTR_IS_INTERNED(op1_str) && GC_REFCOUNT(op1_str) == 1) {
283                size_t len = ZSTR_LEN(op1_str);
284
285                str = zend_string_realloc(op1_str, len + ZSTR_LEN(op2_str), 0);
286                memcpy(ZSTR_VAL(str) + len, ZSTR_VAL(op2_str), ZSTR_LEN(op2_str)+1);
287                ZVAL_NEW_STR(EX_VAR(opline->result.var), str);
288                break;
289            } else {
290                str = zend_string_alloc(ZSTR_LEN(op1_str) + ZSTR_LEN(op2_str), 0);
291                memcpy(ZSTR_VAL(str), ZSTR_VAL(op1_str), ZSTR_LEN(op1_str));
292                memcpy(ZSTR_VAL(str) + ZSTR_LEN(op1_str), ZSTR_VAL(op2_str), ZSTR_LEN(op2_str)+1);
293                ZVAL_NEW_STR(EX_VAR(opline->result.var), str);
294            }
295        } else {
296            if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op1) == IS_UNDEF)) {
297                op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
298            }
299            if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op2) == IS_UNDEF)) {
300                op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
301            }
302            concat_function(EX_VAR(opline->result.var), op1, op2);
303        }
304        FREE_OP1();
305    } while (0);
306    FREE_OP2();
307    CHECK_EXCEPTION();
308    ZEND_VM_NEXT_OPCODE();
309}
310
311ZEND_VM_HANDLER(15, ZEND_IS_IDENTICAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
312{
313    USE_OPLINE
314    zend_free_op free_op1, free_op2;
315    zval *op1, *op2;
316    int result;
317
318    SAVE_OPLINE();
319    op1 = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
320    op2 = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
321    result = fast_is_identical_function(op1, op2);
322    FREE_OP1();
323    FREE_OP2();
324    ZEND_VM_SMART_BRANCH(result, (OP1_TYPE|OP2_TYPE) & (IS_VAR|IS_TMP_VAR));
325    ZVAL_BOOL(EX_VAR(opline->result.var), result);
326    if ((OP1_TYPE|OP2_TYPE) & (IS_VAR|IS_TMP_VAR)) {
327        CHECK_EXCEPTION();
328    }
329    ZEND_VM_NEXT_OPCODE();
330}
331
332ZEND_VM_HANDLER(16, ZEND_IS_NOT_IDENTICAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
333{
334    USE_OPLINE
335    zend_free_op free_op1, free_op2;
336    zval *op1, *op2;
337    int result;
338
339    SAVE_OPLINE();
340    op1 = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
341    op2 = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
342    result = fast_is_not_identical_function(op1, op2);
343    FREE_OP1();
344    FREE_OP2();
345    ZEND_VM_SMART_BRANCH(result, (OP1_TYPE|OP2_TYPE) & (IS_VAR|IS_TMP_VAR));
346    ZVAL_BOOL(EX_VAR(opline->result.var), result);
347    if ((OP1_TYPE|OP2_TYPE) & (IS_VAR|IS_TMP_VAR)) {
348        CHECK_EXCEPTION();
349    }
350    ZEND_VM_NEXT_OPCODE();
351}
352
353ZEND_VM_HANDLER(17, ZEND_IS_EQUAL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
354{
355    USE_OPLINE
356    zend_free_op free_op1, free_op2;
357    zval *op1, *op2, *result;
358
359    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
360    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
361    do {
362        int result;
363
364        if (EXPECTED(Z_TYPE_P(op1) == IS_LONG)) {
365            if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
366                result = (Z_LVAL_P(op1) == Z_LVAL_P(op2));
367            } else if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
368                result = ((double)Z_LVAL_P(op1) == Z_DVAL_P(op2));
369            } else {
370                break;
371            }
372        } else if (EXPECTED(Z_TYPE_P(op1) == IS_DOUBLE)) {
373            if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
374                result = (Z_DVAL_P(op1) == Z_DVAL_P(op2));
375            } else if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
376                result = (Z_DVAL_P(op1) == ((double)Z_LVAL_P(op2)));
377            } else {
378                break;
379            }
380        } else if (EXPECTED(Z_TYPE_P(op1) == IS_STRING)) {
381            if (EXPECTED(Z_TYPE_P(op2) == IS_STRING)) {
382                if (Z_STR_P(op1) == Z_STR_P(op2)) {
383                    result = 1;
384                } else if (Z_STRVAL_P(op1)[0] > '9' || Z_STRVAL_P(op2)[0] > '9') {
385                    if (Z_STRLEN_P(op1) != Z_STRLEN_P(op2)) {
386                        result = 0;
387                    } else {
388                        result = (memcmp(Z_STRVAL_P(op1), Z_STRVAL_P(op2), Z_STRLEN_P(op1)) == 0);
389                    }
390                } else {
391                    result = (zendi_smart_strcmp(op1, op2) == 0);
392                }
393                FREE_OP1();
394                FREE_OP2();
395            } else {
396                break;
397            }
398        } else {
399            break;
400        }
401        ZEND_VM_SMART_BRANCH(result, 0);
402        ZVAL_BOOL(EX_VAR(opline->result.var), result);
403        ZEND_VM_NEXT_OPCODE();
404    } while (0);
405
406    SAVE_OPLINE();
407    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op1) == IS_UNDEF)) {
408        op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
409    }
410    if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op2) == IS_UNDEF)) {
411        op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
412    }
413    result = EX_VAR(opline->result.var);
414    compare_function(result, op1, op2);
415    ZVAL_BOOL(result, Z_LVAL_P(result) == 0);
416    FREE_OP1();
417    FREE_OP2();
418    CHECK_EXCEPTION();
419    ZEND_VM_NEXT_OPCODE();
420}
421
422ZEND_VM_HANDLER(18, ZEND_IS_NOT_EQUAL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
423{
424    USE_OPLINE
425    zend_free_op free_op1, free_op2;
426    zval *op1, *op2, *result;
427
428    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
429    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
430    do {
431        int result;
432
433        if (EXPECTED(Z_TYPE_P(op1) == IS_LONG)) {
434            if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
435                result = (Z_LVAL_P(op1) != Z_LVAL_P(op2));
436            } else if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
437                result = ((double)Z_LVAL_P(op1) != Z_DVAL_P(op2));
438            } else {
439                break;
440            }
441        } else if (EXPECTED(Z_TYPE_P(op1) == IS_DOUBLE)) {
442            if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
443                result = (Z_DVAL_P(op1) != Z_DVAL_P(op2));
444            } else if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
445                result = (Z_DVAL_P(op1) != ((double)Z_LVAL_P(op2)));
446            } else {
447                break;
448            }
449        } else if (EXPECTED(Z_TYPE_P(op1) == IS_STRING)) {
450            if (EXPECTED(Z_TYPE_P(op2) == IS_STRING)) {
451                if (Z_STR_P(op1) == Z_STR_P(op2)) {
452                    result = 0;
453                } else if (Z_STRVAL_P(op1)[0] > '9' || Z_STRVAL_P(op2)[0] > '9') {
454                    if (Z_STRLEN_P(op1) != Z_STRLEN_P(op2)) {
455                        result = 1;
456                    } else {
457                        result = (memcmp(Z_STRVAL_P(op1), Z_STRVAL_P(op2), Z_STRLEN_P(op1)) != 0);
458                    }
459                } else {
460                    result = (zendi_smart_strcmp(op1, op2) != 0);
461                }
462                FREE_OP1();
463                FREE_OP2();
464            } else {
465                break;
466            }
467        } else {
468            break;
469        }
470        ZEND_VM_SMART_BRANCH(result, 0);
471        ZVAL_BOOL(EX_VAR(opline->result.var), result);
472        ZEND_VM_NEXT_OPCODE();
473    } while (0);
474
475    SAVE_OPLINE();
476    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op1) == IS_UNDEF)) {
477        op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
478    }
479    if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op2) == IS_UNDEF)) {
480        op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
481    }
482    result = EX_VAR(opline->result.var);
483    compare_function(result, op1, op2);
484    ZVAL_BOOL(result, Z_LVAL_P(result) != 0);
485    FREE_OP1();
486    FREE_OP2();
487    CHECK_EXCEPTION();
488    ZEND_VM_NEXT_OPCODE();
489}
490
491ZEND_VM_HANDLER(19, ZEND_IS_SMALLER, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
492{
493    USE_OPLINE
494    zend_free_op free_op1, free_op2;
495    zval *op1, *op2, *result;
496
497    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
498    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
499    do {
500        int result;
501
502        if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
503            if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
504                result = (Z_LVAL_P(op1) < Z_LVAL_P(op2));
505            } else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
506                result = ((double)Z_LVAL_P(op1) < Z_DVAL_P(op2));
507            } else {
508                break;
509            }
510        } else if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_DOUBLE)) {
511            if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
512                result = (Z_DVAL_P(op1) < Z_DVAL_P(op2));
513            } else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
514                result = (Z_DVAL_P(op1) < ((double)Z_LVAL_P(op2)));
515            } else {
516                break;
517            }
518        } else {
519            break;
520        }
521        ZEND_VM_SMART_BRANCH(result, 0);
522        ZVAL_BOOL(EX_VAR(opline->result.var), result);
523        ZEND_VM_NEXT_OPCODE();
524    } while (0);
525
526    SAVE_OPLINE();
527    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
528        op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
529    }
530    if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
531        op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
532    }
533    result = EX_VAR(opline->result.var);
534    compare_function(result, op1, op2);
535    ZVAL_BOOL(result, Z_LVAL_P(result) < 0);
536    FREE_OP1();
537    FREE_OP2();
538    CHECK_EXCEPTION();
539    ZEND_VM_NEXT_OPCODE();
540}
541
542ZEND_VM_HANDLER(20, ZEND_IS_SMALLER_OR_EQUAL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
543{
544    USE_OPLINE
545    zend_free_op free_op1, free_op2;
546    zval *op1, *op2, *result;
547
548    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
549    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
550    do {
551        int result;
552
553        if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
554            if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
555                result = (Z_LVAL_P(op1) <= Z_LVAL_P(op2));
556            } else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
557                result = ((double)Z_LVAL_P(op1) <= Z_DVAL_P(op2));
558            } else {
559                break;
560            }
561        } else if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_DOUBLE)) {
562            if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
563                result = (Z_DVAL_P(op1) <= Z_DVAL_P(op2));
564            } else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
565                result = (Z_DVAL_P(op1) <= ((double)Z_LVAL_P(op2)));
566            } else {
567                break;
568            }
569        } else {
570            break;
571        }
572        ZEND_VM_SMART_BRANCH(result, 0);
573        ZVAL_BOOL(EX_VAR(opline->result.var), result);
574        ZEND_VM_NEXT_OPCODE();
575    } while (0);
576
577    SAVE_OPLINE();
578    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
579        op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
580    }
581    if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
582        op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
583    }
584    result = EX_VAR(opline->result.var);
585    compare_function(result, op1, op2);
586    ZVAL_BOOL(result, Z_LVAL_P(result) <= 0);
587    FREE_OP1();
588    FREE_OP2();
589    CHECK_EXCEPTION();
590    ZEND_VM_NEXT_OPCODE();
591}
592
593ZEND_VM_HANDLER(170, ZEND_SPACESHIP, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
594{
595    USE_OPLINE
596    zend_free_op free_op1, free_op2;
597    zval *op1, *op2;
598
599    SAVE_OPLINE();
600    op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
601    op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
602    compare_function(EX_VAR(opline->result.var), op1, op2);
603    FREE_OP1();
604    FREE_OP2();
605    CHECK_EXCEPTION();
606    ZEND_VM_NEXT_OPCODE();
607}
608
609ZEND_VM_HANDLER(9, ZEND_BW_OR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
610{
611    USE_OPLINE
612    zend_free_op free_op1, free_op2;
613    zval *op1, *op2;
614
615    SAVE_OPLINE();
616    op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
617    op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
618    bitwise_or_function(EX_VAR(opline->result.var), op1, op2);
619    FREE_OP1();
620    FREE_OP2();
621    CHECK_EXCEPTION();
622    ZEND_VM_NEXT_OPCODE();
623}
624
625ZEND_VM_HANDLER(10, ZEND_BW_AND, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
626{
627    USE_OPLINE
628    zend_free_op free_op1, free_op2;
629    zval *op1, *op2;
630
631    SAVE_OPLINE();
632    op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
633    op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
634    bitwise_and_function(EX_VAR(opline->result.var), op1, op2);
635    FREE_OP1();
636    FREE_OP2();
637    CHECK_EXCEPTION();
638    ZEND_VM_NEXT_OPCODE();
639}
640
641ZEND_VM_HANDLER(11, ZEND_BW_XOR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
642{
643    USE_OPLINE
644    zend_free_op free_op1, free_op2;
645    zval *op1, *op2;
646
647    SAVE_OPLINE();
648    op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
649    op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
650    bitwise_xor_function(EX_VAR(opline->result.var), op1, op2);
651    FREE_OP1();
652    FREE_OP2();
653    CHECK_EXCEPTION();
654    ZEND_VM_NEXT_OPCODE();
655}
656
657ZEND_VM_HANDLER(14, ZEND_BOOL_XOR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
658{
659    USE_OPLINE
660    zend_free_op free_op1, free_op2;
661    zval *op1, *op2;
662
663    SAVE_OPLINE();
664    op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
665    op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
666    boolean_xor_function(EX_VAR(opline->result.var), op1, op2);
667    FREE_OP1();
668    FREE_OP2();
669    CHECK_EXCEPTION();
670    ZEND_VM_NEXT_OPCODE();
671}
672
673ZEND_VM_HANDLER(12, ZEND_BW_NOT, CONST|TMPVAR|CV, ANY)
674{
675    USE_OPLINE
676    zend_free_op free_op1;
677
678    SAVE_OPLINE();
679    bitwise_not_function(EX_VAR(opline->result.var),
680        GET_OP1_ZVAL_PTR(BP_VAR_R));
681    FREE_OP1();
682    CHECK_EXCEPTION();
683    ZEND_VM_NEXT_OPCODE();
684}
685
686ZEND_VM_HANDLER(13, ZEND_BOOL_NOT, CONST|TMPVAR|CV, ANY)
687{
688    USE_OPLINE
689    zval *val;
690    zend_free_op free_op1;
691
692    val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
693    if (Z_TYPE_INFO_P(val) == IS_TRUE) {
694        ZVAL_FALSE(EX_VAR(opline->result.var));
695    } else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
696        if (UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
697            SAVE_OPLINE();
698            GET_OP1_UNDEF_CV(val, BP_VAR_R);
699            CHECK_EXCEPTION();
700        }
701        ZVAL_TRUE(EX_VAR(opline->result.var));
702    } else {
703        SAVE_OPLINE();
704        ZVAL_BOOL(EX_VAR(opline->result.var), !i_zend_is_true(val));
705        FREE_OP1();
706        CHECK_EXCEPTION();
707    }
708    ZEND_VM_NEXT_OPCODE();
709}
710
711ZEND_VM_HELPER_EX(zend_binary_assign_op_obj_helper, VAR|UNUSED|CV, CONST|TMPVAR|CV, binary_op_type binary_op)
712{
713    USE_OPLINE
714    zend_free_op free_op1, free_op2, free_op_data1;
715    zval *object;
716    zval *property;
717    zval *value;
718    zval *zptr;
719
720    SAVE_OPLINE();
721    object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
722
723    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(object) == NULL)) {
724        zend_throw_error(zend_ce_error, "Using $this when not in object context");
725        FREE_UNFETCHED_OP((opline+1)->op1_type, (opline+1)->op1.var);
726        FREE_UNFETCHED_OP2();
727        HANDLE_EXCEPTION();
728    }
729
730    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
731
732    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
733        zend_throw_error(zend_ce_error, "Cannot use string offset as an object");
734        FREE_UNFETCHED_OP((opline+1)->op1_type, (opline+1)->op1.var);
735        FREE_OP2();
736        HANDLE_EXCEPTION();
737    }
738
739    do {
740        value = get_zval_ptr((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
741
742        if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
743            ZVAL_DEREF(object);
744            if (UNEXPECTED(!make_real_object(object))) {
745                zend_error(E_WARNING, "Attempt to assign property of non-object");
746                if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
747                    ZVAL_NULL(EX_VAR(opline->result.var));
748                }
749                break;
750            }
751        }
752
753        /* here we are sure we are dealing with an object */
754        if (EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
755            && EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL))) != NULL)) {
756
757            ZVAL_DEREF(zptr);
758            SEPARATE_ZVAL_NOREF(zptr);
759
760            binary_op(zptr, zptr, value);
761            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
762                ZVAL_COPY(EX_VAR(opline->result.var), zptr);
763            }
764        } else {
765            zend_assign_op_overloaded_property(object, property, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), value, binary_op, (UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL));
766        }
767    } while (0);
768
769    FREE_OP(free_op_data1);
770    FREE_OP2();
771    FREE_OP1_VAR_PTR();
772    /* assign_obj has two opcodes! */
773    CHECK_EXCEPTION();
774    ZEND_VM_INC_OPCODE();
775    ZEND_VM_NEXT_OPCODE();
776}
777
778ZEND_VM_HELPER_EX(zend_binary_assign_op_dim_helper, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV, binary_op_type binary_op)
779{
780    USE_OPLINE
781    zend_free_op free_op1, free_op2, free_op_data1;
782    zval *var_ptr, rv;
783    zval *value, *container, *dim;
784
785    SAVE_OPLINE();
786    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
787    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
788        zend_throw_error(zend_ce_error, "Using $this when not in object context");
789        FREE_UNFETCHED_OP((opline+1)->op1_type, (opline+1)->op1.var);
790        FREE_UNFETCHED_OP2();
791        HANDLE_EXCEPTION();
792    }
793    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
794        zend_throw_error(zend_ce_error, "Cannot use string offset as an array");
795        FREE_UNFETCHED_OP((opline+1)->op1_type, (opline+1)->op1.var);
796        FREE_UNFETCHED_OP2();
797        HANDLE_EXCEPTION();
798    }
799
800    dim = GET_OP2_ZVAL_PTR(BP_VAR_R);
801
802    do {
803        if (OP1_TYPE == IS_UNUSED || UNEXPECTED(Z_TYPE_P(container) != IS_ARRAY)) {
804            if (OP1_TYPE != IS_UNUSED) {
805                ZVAL_DEREF(container);
806            }
807            if (OP1_TYPE == IS_UNUSED || EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
808                value = get_zval_ptr((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
809                zend_binary_assign_op_obj_dim(container, dim, value, UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL, binary_op);
810                break;
811            }
812        }
813
814        zend_fetch_dimension_address_RW(&rv, container, dim, OP2_TYPE);
815        value = get_zval_ptr((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
816        ZEND_ASSERT(Z_TYPE(rv) == IS_INDIRECT);
817        var_ptr = Z_INDIRECT(rv);
818
819        if (UNEXPECTED(var_ptr == NULL)) {
820            zend_throw_error(zend_ce_error, "Cannot use assign-op operators with overloaded objects nor string offsets");
821            FREE_OP2();
822            FREE_OP(free_op_data1);
823            FREE_OP1_VAR_PTR();
824            HANDLE_EXCEPTION();
825        }
826
827        if (UNEXPECTED(var_ptr == &EG(error_zval))) {
828            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
829                ZVAL_NULL(EX_VAR(opline->result.var));
830            }
831        } else {
832            ZVAL_DEREF(var_ptr);
833            SEPARATE_ZVAL_NOREF(var_ptr);
834
835            binary_op(var_ptr, var_ptr, value);
836
837            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
838                ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
839            }
840        }
841    } while (0);
842
843    FREE_OP2();
844    FREE_OP(free_op_data1);
845    FREE_OP1_VAR_PTR();
846    CHECK_EXCEPTION();
847    ZEND_VM_INC_OPCODE();
848    ZEND_VM_NEXT_OPCODE();
849}
850
851ZEND_VM_HELPER_EX(zend_binary_assign_op_helper, VAR|CV, CONST|TMPVAR|CV, binary_op_type binary_op)
852{
853    USE_OPLINE
854    zend_free_op free_op1, free_op2;
855    zval *var_ptr;
856    zval *value;
857
858    SAVE_OPLINE();
859    value = GET_OP2_ZVAL_PTR(BP_VAR_R);
860    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
861
862    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
863        zend_throw_error(zend_ce_error, "Cannot use assign-op operators with overloaded objects nor string offsets");
864        FREE_OP2();
865        HANDLE_EXCEPTION();
866    }
867
868    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
869        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
870            ZVAL_NULL(EX_VAR(opline->result.var));
871        }
872    } else {
873        ZVAL_DEREF(var_ptr);
874        SEPARATE_ZVAL_NOREF(var_ptr);
875
876        binary_op(var_ptr, var_ptr, value);
877
878        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
879            ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
880        }
881    }
882
883    FREE_OP2();
884    FREE_OP1_VAR_PTR();
885    CHECK_EXCEPTION();
886    ZEND_VM_NEXT_OPCODE();
887}
888
889ZEND_VM_HANDLER(23, ZEND_ASSIGN_ADD, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
890{
891#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
892    USE_OPLINE
893
894# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
895    if (EXPECTED(opline->extended_value == 0)) {
896        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, add_function);
897    }
898# endif
899    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
900        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, add_function);
901    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
902        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, add_function);
903    }
904#else
905    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, add_function);
906#endif
907}
908
909ZEND_VM_HANDLER(24, ZEND_ASSIGN_SUB, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
910{
911#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
912    USE_OPLINE
913
914# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
915    if (EXPECTED(opline->extended_value == 0)) {
916        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, sub_function);
917    }
918# endif
919    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
920        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, sub_function);
921    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
922        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, sub_function);
923    }
924#else
925    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, sub_function);
926#endif
927}
928
929ZEND_VM_HANDLER(25, ZEND_ASSIGN_MUL, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
930{
931#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
932    USE_OPLINE
933
934# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
935    if (EXPECTED(opline->extended_value == 0)) {
936        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, mul_function);
937    }
938# endif
939    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
940        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, mul_function);
941    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
942        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, mul_function);
943    }
944#else
945    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, mul_function);
946#endif
947}
948
949ZEND_VM_HANDLER(26, ZEND_ASSIGN_DIV, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
950{
951#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
952    USE_OPLINE
953
954# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
955    if (EXPECTED(opline->extended_value == 0)) {
956        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, div_function);
957    }
958# endif
959    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
960        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, div_function);
961    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
962        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, div_function);
963    }
964#else
965    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, div_function);
966#endif
967}
968
969ZEND_VM_HANDLER(27, ZEND_ASSIGN_MOD, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
970{
971#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
972    USE_OPLINE
973
974# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
975    if (EXPECTED(opline->extended_value == 0)) {
976        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, mod_function);
977    }
978# endif
979    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
980        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, mod_function);
981    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
982        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, mod_function);
983    }
984#else
985    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, mod_function);
986#endif
987}
988
989ZEND_VM_HANDLER(28, ZEND_ASSIGN_SL, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
990{
991#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
992    USE_OPLINE
993
994# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
995    if (EXPECTED(opline->extended_value == 0)) {
996        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, shift_left_function);
997    }
998# endif
999    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
1000        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, shift_left_function);
1001    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
1002        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, shift_left_function);
1003    }
1004#else
1005    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, shift_left_function);
1006#endif
1007}
1008
1009ZEND_VM_HANDLER(29, ZEND_ASSIGN_SR, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
1010{
1011#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
1012    USE_OPLINE
1013
1014# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
1015    if (EXPECTED(opline->extended_value == 0)) {
1016        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, shift_right_function);
1017    }
1018# endif
1019    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
1020        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, shift_right_function);
1021    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
1022        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, shift_right_function);
1023    }
1024#else
1025    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, shift_right_function);
1026#endif
1027}
1028
1029ZEND_VM_HANDLER(30, ZEND_ASSIGN_CONCAT, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
1030{
1031#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
1032    USE_OPLINE
1033
1034# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
1035    if (EXPECTED(opline->extended_value == 0)) {
1036        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, concat_function);
1037    }
1038# endif
1039    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
1040        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, concat_function);
1041    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
1042        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, concat_function);
1043    }
1044#else
1045    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, concat_function);
1046#endif
1047}
1048
1049ZEND_VM_HANDLER(31, ZEND_ASSIGN_BW_OR, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
1050{
1051#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
1052    USE_OPLINE
1053
1054# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
1055    if (EXPECTED(opline->extended_value == 0)) {
1056        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, bitwise_or_function);
1057    }
1058# endif
1059    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
1060        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_or_function);
1061    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
1062        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, bitwise_or_function);
1063    }
1064#else
1065    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_or_function);
1066#endif
1067}
1068
1069ZEND_VM_HANDLER(32, ZEND_ASSIGN_BW_AND, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
1070{
1071#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
1072    USE_OPLINE
1073
1074# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
1075    if (EXPECTED(opline->extended_value == 0)) {
1076        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, bitwise_and_function);
1077    }
1078# endif
1079    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
1080        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_and_function);
1081    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
1082        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, bitwise_and_function);
1083    }
1084#else
1085    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_and_function);
1086#endif
1087}
1088
1089ZEND_VM_HANDLER(33, ZEND_ASSIGN_BW_XOR, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
1090{
1091#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
1092    USE_OPLINE
1093
1094# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
1095    if (EXPECTED(opline->extended_value == 0)) {
1096        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, bitwise_xor_function);
1097    }
1098# endif
1099    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
1100        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_xor_function);
1101    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
1102        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, bitwise_xor_function);
1103    }
1104#else
1105    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_xor_function);
1106#endif
1107}
1108
1109ZEND_VM_HELPER_EX(zend_pre_incdec_property_helper, VAR|UNUSED|CV, CONST|TMPVAR|CV, int inc)
1110{
1111    USE_OPLINE
1112    zend_free_op free_op1, free_op2;
1113    zval *object;
1114    zval *property;
1115    zval *zptr;
1116
1117    SAVE_OPLINE();
1118    object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
1119
1120    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(object) == NULL)) {
1121        zend_throw_error(zend_ce_error, "Using $this when not in object context");
1122        FREE_UNFETCHED_OP2();
1123        HANDLE_EXCEPTION();
1124    }
1125
1126    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1127
1128    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
1129        zend_throw_error(zend_ce_error, "Cannot increment/decrement overloaded objects nor string offsets");
1130        FREE_OP2();
1131        HANDLE_EXCEPTION();
1132    }
1133
1134    do {
1135        if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
1136            ZVAL_DEREF(object);
1137            if (UNEXPECTED(!make_real_object(object))) {
1138                zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
1139                if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1140                    ZVAL_NULL(EX_VAR(opline->result.var));
1141                }
1142                break;
1143            }
1144        }
1145
1146        /* here we are sure we are dealing with an object */
1147
1148        if (EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
1149            && EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL))) != NULL)) {
1150
1151            if (EXPECTED(Z_TYPE_P(zptr) == IS_LONG)) {
1152                if (inc) {
1153                    fast_long_increment_function(zptr);
1154                } else {
1155                    fast_long_decrement_function(zptr);
1156                }
1157            } else {
1158                ZVAL_DEREF(zptr);
1159                SEPARATE_ZVAL_NOREF(zptr);
1160
1161                if (inc) {
1162                    increment_function(zptr);
1163                } else {
1164                    decrement_function(zptr);
1165                }
1166            }
1167            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1168                ZVAL_COPY(EX_VAR(opline->result.var), zptr);
1169            }
1170        } else {
1171            zend_pre_incdec_overloaded_property(object, property, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), inc, (UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL));
1172        }
1173    } while (0);
1174
1175    FREE_OP2();
1176    FREE_OP1_VAR_PTR();
1177    CHECK_EXCEPTION();
1178    ZEND_VM_NEXT_OPCODE();
1179}
1180
1181ZEND_VM_HANDLER(132, ZEND_PRE_INC_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
1182{
1183    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_pre_incdec_property_helper, inc, 1);
1184}
1185
1186ZEND_VM_HANDLER(133, ZEND_PRE_DEC_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
1187{
1188    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_pre_incdec_property_helper, inc, 0);
1189}
1190
1191ZEND_VM_HELPER_EX(zend_post_incdec_property_helper, VAR|UNUSED|CV, CONST|TMPVAR|CV, int inc)
1192{
1193    USE_OPLINE
1194    zend_free_op free_op1, free_op2;
1195    zval *object;
1196    zval *property;
1197    zval *zptr;
1198
1199    SAVE_OPLINE();
1200    object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
1201
1202    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(object) == NULL)) {
1203        zend_throw_error(zend_ce_error, "Using $this when not in object context");
1204        FREE_UNFETCHED_OP2();
1205        HANDLE_EXCEPTION();
1206    }
1207
1208    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1209
1210    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
1211        zend_throw_error(zend_ce_error, "Cannot increment/decrement overloaded objects nor string offsets");
1212        FREE_OP2();
1213        HANDLE_EXCEPTION();
1214    }
1215
1216    do {
1217        if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
1218            ZVAL_DEREF(object);
1219            if (UNEXPECTED(!make_real_object(object))) {
1220                zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
1221                ZVAL_NULL(EX_VAR(opline->result.var));
1222                break;
1223            }
1224        }
1225
1226        /* here we are sure we are dealing with an object */
1227
1228        if (EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
1229            && EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL))) != NULL)) {
1230
1231            if (EXPECTED(Z_TYPE_P(zptr) == IS_LONG)) {
1232                ZVAL_COPY_VALUE(EX_VAR(opline->result.var), zptr);
1233                if (inc) {
1234                    fast_long_increment_function(zptr);
1235                } else {
1236                    fast_long_decrement_function(zptr);
1237                }
1238            } else {
1239                ZVAL_DEREF(zptr);
1240                ZVAL_COPY_VALUE(EX_VAR(opline->result.var), zptr);
1241                zval_opt_copy_ctor(zptr);
1242                if (inc) {
1243                    increment_function(zptr);
1244                } else {
1245                    decrement_function(zptr);
1246                }
1247            }
1248        } else {
1249            zend_post_incdec_overloaded_property(object, property, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), inc, EX_VAR(opline->result.var));
1250        }
1251    } while (0);
1252
1253    FREE_OP2();
1254    FREE_OP1_VAR_PTR();
1255    CHECK_EXCEPTION();
1256    ZEND_VM_NEXT_OPCODE();
1257}
1258
1259ZEND_VM_HANDLER(134, ZEND_POST_INC_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
1260{
1261    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_post_incdec_property_helper, inc, 1);
1262}
1263
1264ZEND_VM_HANDLER(135, ZEND_POST_DEC_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
1265{
1266    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_post_incdec_property_helper, inc, 0);
1267}
1268
1269ZEND_VM_HANDLER(34, ZEND_PRE_INC, VAR|CV, ANY)
1270{
1271    USE_OPLINE
1272    zend_free_op free_op1;
1273    zval *var_ptr;
1274
1275    var_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_RW);
1276
1277    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
1278        SAVE_OPLINE();
1279        zend_throw_error(zend_ce_error, "Cannot increment/decrement overloaded objects nor string offsets");
1280        HANDLE_EXCEPTION();
1281    }
1282
1283    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1284        fast_long_increment_function(var_ptr);
1285        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1286            ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1287        }
1288        ZEND_VM_NEXT_OPCODE();
1289    }
1290
1291    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
1292        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1293            ZVAL_NULL(EX_VAR(opline->result.var));
1294        }
1295        ZEND_VM_NEXT_OPCODE();
1296    }
1297
1298    SAVE_OPLINE();
1299    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var_ptr) == IS_UNDEF)) {
1300        var_ptr = GET_OP1_UNDEF_CV(var_ptr, BP_VAR_RW);
1301    }
1302    ZVAL_DEREF(var_ptr);
1303    SEPARATE_ZVAL_NOREF(var_ptr);
1304
1305    increment_function(var_ptr);
1306
1307    if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1308        ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
1309    }
1310
1311    FREE_OP1_VAR_PTR();
1312    CHECK_EXCEPTION();
1313    ZEND_VM_NEXT_OPCODE();
1314}
1315
1316ZEND_VM_HANDLER(35, ZEND_PRE_DEC, VAR|CV, ANY)
1317{
1318    USE_OPLINE
1319    zend_free_op free_op1;
1320    zval *var_ptr;
1321
1322    var_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_RW);
1323
1324    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
1325        SAVE_OPLINE();
1326        zend_throw_error(zend_ce_error, "Cannot increment/decrement overloaded objects nor string offsets");
1327        HANDLE_EXCEPTION();
1328    }
1329
1330    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1331        fast_long_decrement_function(var_ptr);
1332        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1333            ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1334        }
1335        ZEND_VM_NEXT_OPCODE();
1336    }
1337
1338    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
1339        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1340            ZVAL_NULL(EX_VAR(opline->result.var));
1341        }
1342        ZEND_VM_NEXT_OPCODE();
1343    }
1344
1345    SAVE_OPLINE();
1346    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var_ptr) == IS_UNDEF)) {
1347        var_ptr = GET_OP1_UNDEF_CV(var_ptr, BP_VAR_RW);
1348    }
1349    ZVAL_DEREF(var_ptr);
1350    SEPARATE_ZVAL_NOREF(var_ptr);
1351
1352    decrement_function(var_ptr);
1353
1354    if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1355        ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
1356    }
1357
1358    FREE_OP1_VAR_PTR();
1359    CHECK_EXCEPTION();
1360    ZEND_VM_NEXT_OPCODE();
1361}
1362
1363ZEND_VM_HANDLER(36, ZEND_POST_INC, VAR|CV, ANY)
1364{
1365    USE_OPLINE
1366    zend_free_op free_op1;
1367    zval *var_ptr;
1368
1369    var_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_RW);
1370
1371    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
1372        SAVE_OPLINE();
1373        zend_throw_error(zend_ce_error, "Cannot increment/decrement overloaded objects nor string offsets");
1374        HANDLE_EXCEPTION();
1375    }
1376
1377    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1378        ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1379        fast_long_increment_function(var_ptr);
1380        ZEND_VM_NEXT_OPCODE();
1381    }
1382
1383    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
1384        ZVAL_NULL(EX_VAR(opline->result.var));
1385        ZEND_VM_NEXT_OPCODE();
1386    }
1387
1388    SAVE_OPLINE();
1389    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var_ptr) == IS_UNDEF)) {
1390        var_ptr = GET_OP1_UNDEF_CV(var_ptr, BP_VAR_RW);
1391    }
1392    ZVAL_DEREF(var_ptr);
1393    ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1394    zval_opt_copy_ctor(var_ptr);
1395
1396    increment_function(var_ptr);
1397
1398    FREE_OP1_VAR_PTR();
1399    CHECK_EXCEPTION();
1400    ZEND_VM_NEXT_OPCODE();
1401}
1402
1403ZEND_VM_HANDLER(37, ZEND_POST_DEC, VAR|CV, ANY)
1404{
1405    USE_OPLINE
1406    zend_free_op free_op1;
1407    zval *var_ptr;
1408
1409    var_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_RW);
1410
1411    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
1412        SAVE_OPLINE();
1413        zend_throw_error(zend_ce_error, "Cannot increment/decrement overloaded objects nor string offsets");
1414        HANDLE_EXCEPTION();
1415    }
1416
1417    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1418        ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1419        fast_long_decrement_function(var_ptr);
1420        ZEND_VM_NEXT_OPCODE();
1421    }
1422
1423    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
1424        ZVAL_NULL(EX_VAR(opline->result.var));
1425        ZEND_VM_NEXT_OPCODE();
1426    }
1427
1428    SAVE_OPLINE();
1429    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var_ptr) == IS_UNDEF)) {
1430        var_ptr = GET_OP1_UNDEF_CV(var_ptr, BP_VAR_RW);
1431    }
1432    ZVAL_DEREF(var_ptr);
1433    ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1434    zval_opt_copy_ctor(var_ptr);
1435
1436    decrement_function(var_ptr);
1437
1438    FREE_OP1_VAR_PTR();
1439    CHECK_EXCEPTION();
1440    ZEND_VM_NEXT_OPCODE();
1441}
1442
1443ZEND_VM_HANDLER(40, ZEND_ECHO, CONST|TMPVAR|CV, ANY)
1444{
1445    USE_OPLINE
1446    zend_free_op free_op1;
1447    zval *z;
1448
1449    SAVE_OPLINE();
1450    z = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
1451
1452    if (Z_TYPE_P(z) == IS_STRING) {
1453        zend_string *str = Z_STR_P(z);
1454
1455        if (ZSTR_LEN(str) != 0) {
1456            zend_write(ZSTR_VAL(str), ZSTR_LEN(str));
1457        }
1458    } else {
1459        zend_string *str = _zval_get_string_func(z);
1460
1461        if (ZSTR_LEN(str) != 0) {
1462            zend_write(ZSTR_VAL(str), ZSTR_LEN(str));
1463        } else if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(z) == IS_UNDEF)) {
1464            GET_OP1_UNDEF_CV(z, BP_VAR_R);
1465        }
1466        zend_string_release(str);
1467    }
1468
1469    FREE_OP1();
1470    CHECK_EXCEPTION();
1471    ZEND_VM_NEXT_OPCODE();
1472}
1473
1474ZEND_VM_HELPER_EX(zend_fetch_var_address_helper, CONST|TMPVAR|CV, UNUSED|CONST|VAR, int type)
1475{
1476    USE_OPLINE
1477    zend_free_op free_op1;
1478    zval *varname;
1479    zval *retval;
1480    zend_string *name;
1481    HashTable *target_symbol_table;
1482
1483    SAVE_OPLINE();
1484    varname = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
1485
1486    if (OP1_TYPE == IS_CONST) {
1487        name = Z_STR_P(varname);
1488    } else if (EXPECTED(Z_TYPE_P(varname) == IS_STRING)) {
1489        name = Z_STR_P(varname);
1490        zend_string_addref(name);
1491    } else {
1492        if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(varname) == IS_UNDEF)) {
1493            GET_OP1_UNDEF_CV(varname, BP_VAR_R);
1494        }
1495        name = zval_get_string(varname);
1496    }
1497
1498    if (OP2_TYPE != IS_UNUSED) {
1499        zend_class_entry *ce;
1500
1501        if (OP2_TYPE == IS_CONST) {
1502            if (OP1_TYPE == IS_CONST && CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)))) {
1503
1504                ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
1505                retval = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)) + sizeof(void*));
1506
1507                /* check if static properties were destoyed */
1508                if (UNEXPECTED(CE_STATIC_MEMBERS(ce) == NULL)) {
1509                    zend_throw_error(zend_ce_error, "Access to undeclared static property: %s::$%s", ZSTR_VAL(ce->name), ZSTR_VAL(name));
1510                    FREE_OP1();
1511                    HANDLE_EXCEPTION();
1512                }
1513
1514                ZEND_VM_C_GOTO(fetch_var_return);
1515            } else if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) {
1516                ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
1517            } else {
1518                ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op2)), EX_CONSTANT(opline->op2) + 1, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
1519                if (UNEXPECTED(ce == NULL)) {
1520                    if (OP1_TYPE != IS_CONST) {
1521                        zend_string_release(name);
1522                    }
1523                    FREE_OP1();
1524                    CHECK_EXCEPTION();
1525                    ZEND_VM_NEXT_OPCODE();
1526                }
1527                CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce);
1528            }
1529        } else {
1530            ce = Z_CE_P(EX_VAR(opline->op2.var));
1531            if (OP1_TYPE == IS_CONST &&
1532                (retval = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce)) != NULL) {
1533
1534                /* check if static properties were destoyed */
1535                if (UNEXPECTED(CE_STATIC_MEMBERS(ce) == NULL)) {
1536                    zend_throw_error(zend_ce_error, "Access to undeclared static property: %s::$%s", ZSTR_VAL(ce->name), ZSTR_VAL(name));
1537                    FREE_OP1();
1538                    HANDLE_EXCEPTION();
1539                }
1540
1541                ZEND_VM_C_GOTO(fetch_var_return);
1542            }
1543        }
1544        retval = zend_std_get_static_property(ce, name, 0);
1545        if (UNEXPECTED(EG(exception))) {
1546            FREE_OP1();
1547            HANDLE_EXCEPTION();
1548        }
1549        if (OP1_TYPE == IS_CONST && retval) {
1550            CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce, retval);
1551        }
1552
1553        FREE_OP1();
1554    } else {
1555        target_symbol_table = zend_get_target_symbol_table(execute_data, opline->extended_value & ZEND_FETCH_TYPE_MASK);
1556        retval = zend_hash_find(target_symbol_table, name);
1557        if (retval == NULL) {
1558            switch (type) {
1559                case BP_VAR_R:
1560                case BP_VAR_UNSET:
1561                    zend_error(E_NOTICE,"Undefined variable: %s", ZSTR_VAL(name));
1562                    /* break missing intentionally */
1563                case BP_VAR_IS:
1564                    retval = &EG(uninitialized_zval);
1565                    break;
1566                case BP_VAR_RW:
1567                    zend_error(E_NOTICE,"Undefined variable: %s", ZSTR_VAL(name));
1568                    /* break missing intentionally */
1569                case BP_VAR_W:
1570                    retval = zend_hash_add_new(target_symbol_table, name, &EG(uninitialized_zval));
1571                    break;
1572                EMPTY_SWITCH_DEFAULT_CASE()
1573            }
1574        /* GLOBAL or $$name variable may be an INDIRECT pointer to CV */
1575        } else if (Z_TYPE_P(retval) == IS_INDIRECT) {
1576            retval = Z_INDIRECT_P(retval);
1577            if (Z_TYPE_P(retval) == IS_UNDEF) {
1578                switch (type) {
1579                    case BP_VAR_R:
1580                    case BP_VAR_UNSET:
1581                        zend_error(E_NOTICE,"Undefined variable: %s", ZSTR_VAL(name));
1582                        /* break missing intentionally */
1583                    case BP_VAR_IS:
1584                        retval = &EG(uninitialized_zval);
1585                        break;
1586                    case BP_VAR_RW:
1587                        zend_error(E_NOTICE,"Undefined variable: %s", ZSTR_VAL(name));
1588                        /* break missing intentionally */
1589                    case BP_VAR_W:
1590                        ZVAL_NULL(retval);
1591                        break;
1592                    EMPTY_SWITCH_DEFAULT_CASE()
1593                }
1594            }
1595        }
1596        if ((opline->extended_value & ZEND_FETCH_TYPE_MASK) == ZEND_FETCH_STATIC) {
1597            if (Z_CONSTANT_P(retval)) {
1598                if (UNEXPECTED(zval_update_constant_ex(retval, 1, NULL) != SUCCESS)) {
1599                    FREE_OP1();
1600                    HANDLE_EXCEPTION();
1601                }
1602            }
1603        } else if ((opline->extended_value & ZEND_FETCH_TYPE_MASK) != ZEND_FETCH_GLOBAL_LOCK) {
1604            FREE_OP1();
1605        }
1606    }
1607
1608    if (OP1_TYPE != IS_CONST) {
1609        zend_string_release(name);
1610    }
1611
1612ZEND_VM_C_LABEL(fetch_var_return):
1613    ZEND_ASSERT(retval != NULL);
1614    if (type == BP_VAR_R || type == BP_VAR_IS) {
1615        if (/*type == BP_VAR_R &&*/ Z_ISREF_P(retval) && Z_REFCOUNT_P(retval) == 1) {
1616            ZVAL_UNREF(retval);
1617        }
1618        ZVAL_COPY(EX_VAR(opline->result.var), retval);
1619    } else {
1620        ZVAL_INDIRECT(EX_VAR(opline->result.var), retval);
1621    }
1622    CHECK_EXCEPTION();
1623    ZEND_VM_NEXT_OPCODE();
1624}
1625
1626ZEND_VM_HANDLER(80, ZEND_FETCH_R, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1627{
1628    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_R);
1629}
1630
1631ZEND_VM_HANDLER(83, ZEND_FETCH_W, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1632{
1633    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_W);
1634}
1635
1636ZEND_VM_HANDLER(86, ZEND_FETCH_RW, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1637{
1638    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_RW);
1639}
1640
1641ZEND_VM_HANDLER(92, ZEND_FETCH_FUNC_ARG, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1642{
1643    USE_OPLINE
1644
1645    if (zend_is_by_ref_func_arg_fetch(opline, EX(call))) {
1646        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_W);
1647    } else {
1648        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_R);
1649    }
1650}
1651
1652ZEND_VM_HANDLER(95, ZEND_FETCH_UNSET, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1653{
1654    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_UNSET);
1655}
1656
1657ZEND_VM_HANDLER(89, ZEND_FETCH_IS, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1658{
1659    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_IS);
1660}
1661
1662ZEND_VM_HANDLER(81, ZEND_FETCH_DIM_R, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
1663{
1664    USE_OPLINE
1665    zend_free_op free_op1, free_op2;
1666    zval *container;
1667
1668    SAVE_OPLINE();
1669    container = GET_OP1_ZVAL_PTR(BP_VAR_R);
1670    zend_fetch_dimension_address_read_R(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1671    FREE_OP2();
1672    FREE_OP1();
1673    CHECK_EXCEPTION();
1674    ZEND_VM_NEXT_OPCODE();
1675}
1676
1677ZEND_VM_HANDLER(84, ZEND_FETCH_DIM_W, VAR|CV, CONST|TMPVAR|UNUSED|CV)
1678{
1679    USE_OPLINE
1680    zend_free_op free_op1, free_op2;
1681    zval *container;
1682
1683    SAVE_OPLINE();
1684    container = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1685
1686    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1687        zend_throw_error(zend_ce_error, "Cannot use string offset as an array");
1688        HANDLE_EXCEPTION();
1689    }
1690    zend_fetch_dimension_address_W(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1691    FREE_OP2();
1692    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1693        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1694    }
1695    FREE_OP1_VAR_PTR();
1696    CHECK_EXCEPTION();
1697    ZEND_VM_NEXT_OPCODE();
1698}
1699
1700ZEND_VM_HANDLER(87, ZEND_FETCH_DIM_RW, VAR|CV, CONST|TMPVAR|UNUSED|CV)
1701{
1702    USE_OPLINE
1703    zend_free_op free_op1, free_op2;
1704    zval *container;
1705
1706    SAVE_OPLINE();
1707    container = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
1708
1709    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1710        zend_throw_error(zend_ce_error, "Cannot use string offset as an array");
1711        HANDLE_EXCEPTION();
1712    }
1713    zend_fetch_dimension_address_RW(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1714    FREE_OP2();
1715    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1716        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1717    }
1718    FREE_OP1_VAR_PTR();
1719    CHECK_EXCEPTION();
1720    ZEND_VM_NEXT_OPCODE();
1721}
1722
1723ZEND_VM_HANDLER(90, ZEND_FETCH_DIM_IS, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
1724{
1725    USE_OPLINE
1726    zend_free_op free_op1, free_op2;
1727    zval *container;
1728
1729    SAVE_OPLINE();
1730    container = GET_OP1_ZVAL_PTR(BP_VAR_IS);
1731    zend_fetch_dimension_address_read_IS(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1732    FREE_OP2();
1733    FREE_OP1();
1734    CHECK_EXCEPTION();
1735    ZEND_VM_NEXT_OPCODE();
1736}
1737
1738ZEND_VM_HANDLER(93, ZEND_FETCH_DIM_FUNC_ARG, CONST|TMP|VAR|CV, CONST|TMPVAR|UNUSED|CV)
1739{
1740    USE_OPLINE
1741    zval *container;
1742    zend_free_op free_op1, free_op2;
1743
1744    SAVE_OPLINE();
1745
1746    if (zend_is_by_ref_func_arg_fetch(opline, EX(call))) {
1747        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
1748            zend_throw_error(zend_ce_error, "Cannot use temporary expression in write context");
1749            FREE_UNFETCHED_OP2();
1750            FREE_UNFETCHED_OP1();
1751            HANDLE_EXCEPTION();
1752        }
1753        container = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1754        if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1755            zend_throw_error(zend_ce_error, "Cannot use string offset as an array");
1756            FREE_UNFETCHED_OP2();
1757            HANDLE_EXCEPTION();
1758        }
1759        zend_fetch_dimension_address_W(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1760        if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1761            EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1762        }
1763        FREE_OP2();
1764        FREE_OP1_VAR_PTR();
1765    } else {
1766        if (OP2_TYPE == IS_UNUSED) {
1767            zend_throw_error(zend_ce_error, "Cannot use [] for reading");
1768            FREE_UNFETCHED_OP2();
1769            FREE_UNFETCHED_OP1();
1770            HANDLE_EXCEPTION();
1771        }
1772        container = GET_OP1_ZVAL_PTR(BP_VAR_R);
1773        zend_fetch_dimension_address_read_R(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1774        FREE_OP2();
1775        FREE_OP1();
1776    }
1777    CHECK_EXCEPTION();
1778    ZEND_VM_NEXT_OPCODE();
1779}
1780
1781ZEND_VM_HANDLER(96, ZEND_FETCH_DIM_UNSET, VAR|CV, CONST|TMPVAR|CV)
1782{
1783    USE_OPLINE
1784    zend_free_op free_op1, free_op2;
1785    zval *container;
1786
1787    SAVE_OPLINE();
1788    container = GET_OP1_ZVAL_PTR_PTR(BP_VAR_UNSET);
1789
1790    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1791        zend_throw_error(zend_ce_error, "Cannot use string offset as an array");
1792        FREE_UNFETCHED_OP2();
1793        HANDLE_EXCEPTION();
1794    }
1795    zend_fetch_dimension_address_UNSET(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1796    FREE_OP2();
1797    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1798        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1799    }
1800    FREE_OP1_VAR_PTR();
1801    CHECK_EXCEPTION();
1802    ZEND_VM_NEXT_OPCODE();
1803}
1804
1805ZEND_VM_HANDLER(82, ZEND_FETCH_OBJ_R, CONST|TMP|VAR|UNUSED|CV, CONST|TMPVAR|CV)
1806{
1807    USE_OPLINE
1808    zend_free_op free_op1;
1809    zval *container;
1810    zend_free_op free_op2;
1811    zval *offset;
1812
1813    SAVE_OPLINE();
1814    container = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_R);
1815
1816    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
1817        zend_throw_error(zend_ce_error, "Using $this when not in object context");
1818        FREE_UNFETCHED_OP2();
1819        HANDLE_EXCEPTION();
1820    }
1821
1822    offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
1823
1824    if (OP1_TYPE == IS_CONST ||
1825        (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT))) {
1826        if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(container)) {
1827            container = Z_REFVAL_P(container);
1828            if (UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
1829                ZEND_VM_C_GOTO(fetch_obj_r_no_object);
1830            }
1831        } else {
1832            ZEND_VM_C_GOTO(fetch_obj_r_no_object);
1833        }
1834    }
1835
1836    /* here we are sure we are dealing with an object */
1837    do {
1838        zend_object *zobj = Z_OBJ_P(container);
1839        zval *retval;
1840
1841        if (OP2_TYPE == IS_CONST &&
1842            EXPECTED(zobj->ce == CACHED_PTR(Z_CACHE_SLOT_P(offset)))) {
1843            uint32_t prop_offset = (uint32_t)(intptr_t)CACHED_PTR(Z_CACHE_SLOT_P(offset) + sizeof(void*));
1844
1845            if (EXPECTED(prop_offset != (uint32_t)ZEND_DYNAMIC_PROPERTY_OFFSET)) {
1846                retval = OBJ_PROP(zobj, prop_offset);
1847                if (EXPECTED(Z_TYPE_P(retval) != IS_UNDEF)) {
1848                    ZVAL_COPY(EX_VAR(opline->result.var), retval);
1849                    break;
1850                }
1851            } else if (EXPECTED(zobj->properties != NULL)) {
1852                retval = zend_hash_find(zobj->properties, Z_STR_P(offset));
1853                if (EXPECTED(retval)) {
1854                    ZVAL_COPY(EX_VAR(opline->result.var), retval);
1855                    break;
1856                }
1857            }
1858        }
1859
1860        if (UNEXPECTED(zobj->handlers->read_property == NULL)) {
1861ZEND_VM_C_LABEL(fetch_obj_r_no_object):
1862            zend_error(E_NOTICE, "Trying to get property of non-object");
1863            ZVAL_NULL(EX_VAR(opline->result.var));
1864        } else {
1865            retval = zobj->handlers->read_property(container, offset, BP_VAR_R, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(offset)) : NULL), EX_VAR(opline->result.var));
1866
1867            if (retval != EX_VAR(opline->result.var)) {
1868                ZVAL_COPY(EX_VAR(opline->result.var), retval);
1869            }
1870        }
1871    } while (0);
1872
1873    FREE_OP2();
1874    FREE_OP1();
1875    CHECK_EXCEPTION();
1876    ZEND_VM_NEXT_OPCODE();
1877}
1878
1879ZEND_VM_HANDLER(85, ZEND_FETCH_OBJ_W, VAR|UNUSED|CV, CONST|TMPVAR|CV)
1880{
1881    USE_OPLINE
1882    zend_free_op free_op1, free_op2;
1883    zval *property;
1884    zval *container;
1885
1886    SAVE_OPLINE();
1887    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1888
1889    container = GET_OP1_OBJ_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1890    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
1891        zend_throw_error(zend_ce_error, "Using $this when not in object context");
1892        FREE_OP2();
1893        HANDLE_EXCEPTION();
1894    }
1895    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1896        zend_throw_error(zend_ce_error, "Cannot use string offset as an object");
1897        FREE_OP2();
1898        HANDLE_EXCEPTION();
1899    }
1900
1901    zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_W);
1902    FREE_OP2();
1903    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1904        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1905    }
1906    FREE_OP1_VAR_PTR();
1907    CHECK_EXCEPTION();
1908    ZEND_VM_NEXT_OPCODE();
1909}
1910
1911ZEND_VM_HANDLER(88, ZEND_FETCH_OBJ_RW, VAR|UNUSED|CV, CONST|TMPVAR|CV)
1912{
1913    USE_OPLINE
1914    zend_free_op free_op1, free_op2;
1915    zval *property;
1916    zval *container;
1917
1918    SAVE_OPLINE();
1919    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1920    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
1921
1922    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
1923        zend_throw_error(zend_ce_error, "Using $this when not in object context");
1924        FREE_OP2();
1925        HANDLE_EXCEPTION();
1926    }
1927    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1928        zend_throw_error(zend_ce_error, "Cannot use string offset as an object");
1929        FREE_OP2();
1930        HANDLE_EXCEPTION();
1931    }
1932    zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_RW);
1933    FREE_OP2();
1934    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1935        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1936    }
1937    FREE_OP1_VAR_PTR();
1938    CHECK_EXCEPTION();
1939    ZEND_VM_NEXT_OPCODE();
1940}
1941
1942ZEND_VM_HANDLER(91, ZEND_FETCH_OBJ_IS, CONST|TMPVAR|UNUSED|CV, CONST|TMPVAR|CV)
1943{
1944    USE_OPLINE
1945    zend_free_op free_op1;
1946    zval *container;
1947    zend_free_op free_op2;
1948    zval *offset;
1949
1950    SAVE_OPLINE();
1951    container = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_IS);
1952
1953    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
1954        zend_throw_error(zend_ce_error, "Using $this when not in object context");
1955        FREE_UNFETCHED_OP2();
1956        HANDLE_EXCEPTION();
1957    }
1958
1959    offset  = GET_OP2_ZVAL_PTR(BP_VAR_R);
1960
1961    if (OP1_TYPE == IS_CONST ||
1962        (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT))) {
1963        if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(container)) {
1964            container = Z_REFVAL_P(container);
1965            if (UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
1966                ZEND_VM_C_GOTO(fetch_obj_is_no_object);
1967            }
1968        } else {
1969            ZEND_VM_C_GOTO(fetch_obj_is_no_object);
1970        }
1971    }
1972
1973    /* here we are sure we are dealing with an object */
1974    do {
1975        zend_object *zobj = Z_OBJ_P(container);
1976        zval *retval;
1977
1978        if (OP2_TYPE == IS_CONST &&
1979            EXPECTED(zobj->ce == CACHED_PTR(Z_CACHE_SLOT_P(offset)))) {
1980            uint32_t prop_offset = (uint32_t)(intptr_t)CACHED_PTR(Z_CACHE_SLOT_P(offset) + sizeof(void*));
1981
1982            if (EXPECTED(prop_offset != (uint32_t)ZEND_DYNAMIC_PROPERTY_OFFSET)) {
1983                retval = OBJ_PROP(zobj, prop_offset);
1984                if (EXPECTED(Z_TYPE_P(retval) != IS_UNDEF)) {
1985                    ZVAL_COPY(EX_VAR(opline->result.var), retval);
1986                    break;
1987                }
1988            } else if (EXPECTED(zobj->properties != NULL)) {
1989                retval = zend_hash_find(zobj->properties, Z_STR_P(offset));
1990                if (EXPECTED(retval)) {
1991                    ZVAL_COPY(EX_VAR(opline->result.var), retval);
1992                    break;
1993                }
1994            }
1995        }
1996
1997        if (UNEXPECTED(zobj->handlers->read_property == NULL)) {
1998ZEND_VM_C_LABEL(fetch_obj_is_no_object):
1999            ZVAL_NULL(EX_VAR(opline->result.var));
2000        } else {
2001
2002            retval = zobj->handlers->read_property(container, offset, BP_VAR_IS, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(offset)) : NULL), EX_VAR(opline->result.var));
2003
2004            if (retval != EX_VAR(opline->result.var)) {
2005                ZVAL_COPY(EX_VAR(opline->result.var), retval);
2006            }
2007        }
2008    } while (0);
2009
2010    FREE_OP2();
2011    FREE_OP1();
2012    CHECK_EXCEPTION();
2013    ZEND_VM_NEXT_OPCODE();
2014}
2015
2016ZEND_VM_HANDLER(94, ZEND_FETCH_OBJ_FUNC_ARG, CONST|TMP|VAR|UNUSED|CV, CONST|TMPVAR|CV)
2017{
2018    USE_OPLINE
2019    zval *container;
2020
2021    if (zend_is_by_ref_func_arg_fetch(opline, EX(call))) {
2022        /* Behave like FETCH_OBJ_W */
2023        zend_free_op free_op1, free_op2;
2024        zval *property;
2025
2026        SAVE_OPLINE();
2027        property = GET_OP2_ZVAL_PTR(BP_VAR_R);
2028        container = GET_OP1_OBJ_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
2029
2030        if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
2031            zend_throw_error(zend_ce_error, "Using $this when not in object context");
2032            FREE_OP2();
2033            HANDLE_EXCEPTION();
2034        }
2035        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
2036            zend_throw_error(zend_ce_error, "Cannot use temporary expression in write context");
2037            FREE_OP2();
2038            FREE_OP1_VAR_PTR();
2039            HANDLE_EXCEPTION();
2040        }
2041        if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
2042            zend_throw_error(zend_ce_error, "Cannot use string offset as an object");
2043            FREE_OP2();
2044            HANDLE_EXCEPTION();
2045        }
2046        zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_W);
2047        FREE_OP2();
2048        if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
2049            EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
2050        }
2051        FREE_OP1_VAR_PTR();
2052        CHECK_EXCEPTION();
2053        ZEND_VM_NEXT_OPCODE();
2054    } else {
2055        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_FETCH_OBJ_R);
2056    }
2057}
2058
2059ZEND_VM_HANDLER(97, ZEND_FETCH_OBJ_UNSET, VAR|UNUSED|CV, CONST|TMPVAR|CV)
2060{
2061    USE_OPLINE
2062    zend_free_op free_op1, free_op2;
2063    zval *container, *property;
2064
2065    SAVE_OPLINE();
2066    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_UNSET);
2067
2068    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
2069        zend_throw_error(zend_ce_error, "Using $this when not in object context");
2070        FREE_UNFETCHED_OP2();
2071        HANDLE_EXCEPTION();
2072    }
2073
2074    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
2075
2076    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
2077        zend_throw_error(zend_ce_error, "Cannot use string offset as an object");
2078        FREE_OP2();
2079        HANDLE_EXCEPTION();
2080    }
2081    zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_UNSET);
2082    FREE_OP2();
2083    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
2084        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
2085    }
2086    FREE_OP1_VAR_PTR();
2087    CHECK_EXCEPTION();
2088    ZEND_VM_NEXT_OPCODE();
2089}
2090
2091ZEND_VM_HANDLER(98, ZEND_FETCH_LIST, CONST|TMPVAR|CV, CONST)
2092{
2093    USE_OPLINE
2094    zend_free_op free_op1;
2095    zval *container;
2096
2097    SAVE_OPLINE();
2098    container = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2099
2100ZEND_VM_C_LABEL(try_fetch_list):
2101    if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
2102        zval *value = zend_hash_index_find(Z_ARRVAL_P(container), Z_LVAL_P(EX_CONSTANT(opline->op2)));
2103
2104        if (UNEXPECTED(value == NULL)) {
2105            zend_error(E_NOTICE,"Undefined offset: " ZEND_ULONG_FMT, Z_LVAL_P(EX_CONSTANT(opline->op2)));
2106            ZVAL_NULL(EX_VAR(opline->result.var));
2107        } else {
2108            ZVAL_COPY(EX_VAR(opline->result.var), value);
2109        }
2110    } else if (OP1_TYPE != IS_CONST &&
2111               UNEXPECTED(Z_TYPE_P(container) == IS_OBJECT) &&
2112               EXPECTED(Z_OBJ_HT_P(container)->read_dimension)) {
2113        zval *result = EX_VAR(opline->result.var);
2114        zval *retval = Z_OBJ_HT_P(container)->read_dimension(container, EX_CONSTANT(opline->op2), BP_VAR_R, result);
2115
2116        if (retval) {
2117            if (result != retval) {
2118                ZVAL_COPY(result, retval);
2119            }
2120        } else {
2121            ZVAL_NULL(result);
2122        }
2123    } else if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_TYPE_P(container) == IS_REFERENCE) {
2124        container = Z_REFVAL_P(container);
2125        ZEND_VM_C_GOTO(try_fetch_list);
2126    } else {
2127        if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(container) == IS_UNDEF)) {
2128            GET_OP1_UNDEF_CV(container, BP_VAR_R);
2129        }
2130        ZVAL_NULL(EX_VAR(opline->result.var));
2131    }
2132    CHECK_EXCEPTION();
2133    ZEND_VM_NEXT_OPCODE();
2134}
2135
2136ZEND_VM_HANDLER(136, ZEND_ASSIGN_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
2137{
2138    USE_OPLINE
2139    zend_free_op free_op1, free_op2;
2140    zval *object;
2141    zval *property_name;
2142
2143    SAVE_OPLINE();
2144    object = GET_OP1_OBJ_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
2145
2146    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(object) == NULL)) {
2147        zend_throw_error(zend_ce_error, "Using $this when not in object context");
2148        FREE_UNFETCHED_OP2();
2149        HANDLE_EXCEPTION();
2150    }
2151
2152    property_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2153
2154    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
2155        zend_throw_error(zend_ce_error, "Cannot use string offset as an array");
2156        FREE_OP2();
2157        HANDLE_EXCEPTION();
2158    }
2159    zend_assign_to_object(UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL, object, OP1_TYPE, property_name, OP2_TYPE, (opline+1)->op1_type, (opline+1)->op1, execute_data, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property_name)) : NULL));
2160    FREE_OP2();
2161    FREE_OP1_VAR_PTR();
2162    /* assign_obj has two opcodes! */
2163    CHECK_EXCEPTION();
2164    ZEND_VM_INC_OPCODE();
2165    ZEND_VM_NEXT_OPCODE();
2166}
2167
2168ZEND_VM_HANDLER(147, ZEND_ASSIGN_DIM, VAR|CV, CONST|TMPVAR|UNUSED|CV)
2169{
2170    USE_OPLINE
2171    zend_free_op free_op1;
2172    zval *object_ptr;
2173    zend_free_op free_op2, free_op_data1;
2174    zval *value;
2175    zval *variable_ptr;
2176    zval *dim;
2177
2178    SAVE_OPLINE();
2179    object_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
2180
2181    if (OP1_TYPE == IS_VAR && UNEXPECTED(object_ptr == NULL)) {
2182        zend_throw_error(zend_ce_error, "Cannot use string offset as an array");
2183        FREE_UNFETCHED_OP((opline+1)->op1_type, (opline+1)->op1.var);
2184        FREE_UNFETCHED_OP2();
2185        HANDLE_EXCEPTION();
2186    }
2187
2188    if (EXPECTED(Z_TYPE_P(object_ptr) == IS_ARRAY)) {
2189ZEND_VM_C_LABEL(try_assign_dim_array):
2190        if (OP2_TYPE == IS_UNUSED) {
2191            SEPARATE_ARRAY(object_ptr);
2192            variable_ptr = zend_hash_next_index_insert(Z_ARRVAL_P(object_ptr), &EG(uninitialized_zval));
2193            if (UNEXPECTED(variable_ptr == NULL)) {
2194                zend_error(E_WARNING, "Cannot add element to the array as the next element is already occupied");
2195                variable_ptr = &EG(error_zval);
2196            }
2197        } else {
2198            dim = GET_OP2_ZVAL_PTR(BP_VAR_R);
2199            SEPARATE_ARRAY(object_ptr);
2200            variable_ptr = zend_fetch_dimension_address_inner(Z_ARRVAL_P(object_ptr), dim, OP2_TYPE, BP_VAR_W);
2201            FREE_OP2();
2202        }
2203        value = get_zval_ptr((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
2204        if (UNEXPECTED(variable_ptr == &EG(error_zval))) {
2205            FREE_OP(free_op_data1);
2206            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2207                ZVAL_NULL(EX_VAR(opline->result.var));
2208            }
2209        } else {
2210            value = zend_assign_to_variable(variable_ptr, value, (opline+1)->op1_type);
2211            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2212                ZVAL_COPY(EX_VAR(opline->result.var), value);
2213            }
2214        }
2215    } else {
2216        if (EXPECTED(Z_ISREF_P(object_ptr))) {
2217            object_ptr = Z_REFVAL_P(object_ptr);
2218            if (EXPECTED(Z_TYPE_P(object_ptr) == IS_ARRAY)) {
2219                ZEND_VM_C_GOTO(try_assign_dim_array);
2220            }
2221        }
2222        if (EXPECTED(Z_TYPE_P(object_ptr) == IS_OBJECT)) {
2223            zend_free_op free_op2;
2224            zval *property_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2225
2226            zend_assign_to_object_dim(UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL, object_ptr, property_name, (opline+1)->op1_type, (opline+1)->op1, execute_data);
2227            FREE_OP2();
2228        } else if (EXPECTED(Z_TYPE_P(object_ptr) == IS_STRING)) {
2229            if (EXPECTED(Z_STRLEN_P(object_ptr) != 0)) {
2230                if (OP2_TYPE == IS_UNUSED) {
2231                    zend_throw_error(zend_ce_error, "[] operator not supported for strings");
2232                    FREE_UNFETCHED_OP((opline+1)->op1_type, (opline+1)->op1.var);
2233                    FREE_OP1_VAR_PTR();
2234                    HANDLE_EXCEPTION();
2235                } else {
2236                    zend_long offset;
2237
2238                    dim = GET_OP2_ZVAL_PTR(BP_VAR_R);
2239                    offset = zend_fetch_string_offset(object_ptr, dim, BP_VAR_W);
2240                    FREE_OP2();
2241                    value = get_zval_ptr_deref((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
2242                    zend_assign_to_string_offset(object_ptr, offset, value, (UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL));
2243                    FREE_OP(free_op_data1);
2244                }
2245            } else {
2246                zval_ptr_dtor_nogc(object_ptr);
2247ZEND_VM_C_LABEL(assign_dim_convert_to_array):
2248                ZVAL_NEW_ARR(object_ptr);
2249                zend_hash_init(Z_ARRVAL_P(object_ptr), 8, NULL, ZVAL_PTR_DTOR, 0);
2250                ZEND_VM_C_GOTO(try_assign_dim_array);
2251            }
2252        } else if (EXPECTED(Z_TYPE_P(object_ptr) <= IS_FALSE)) {
2253            if (OP1_TYPE == IS_VAR && UNEXPECTED(object_ptr == &EG(error_zval))) {
2254                ZEND_VM_C_GOTO(assign_dim_clean);
2255            }
2256            ZEND_VM_C_GOTO(assign_dim_convert_to_array);
2257        } else {
2258            zend_error(E_WARNING, "Cannot use a scalar value as an array");
2259ZEND_VM_C_LABEL(assign_dim_clean):
2260            dim = GET_OP2_ZVAL_PTR(BP_VAR_R);
2261            FREE_OP2();
2262            value = get_zval_ptr((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
2263            FREE_OP(free_op_data1);
2264            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2265                ZVAL_NULL(EX_VAR(opline->result.var));
2266            }
2267        }
2268    }
2269    FREE_OP1_VAR_PTR();
2270    /* assign_dim has two opcodes! */
2271    CHECK_EXCEPTION();
2272    ZEND_VM_INC_OPCODE();
2273    ZEND_VM_NEXT_OPCODE();
2274}
2275
2276ZEND_VM_HANDLER(38, ZEND_ASSIGN, VAR|CV, CONST|TMP|VAR|CV)
2277{
2278    USE_OPLINE
2279    zend_free_op free_op1, free_op2;
2280    zval *value;
2281    zval *variable_ptr;
2282
2283    SAVE_OPLINE();
2284    value = GET_OP2_ZVAL_PTR(BP_VAR_R);
2285    variable_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
2286
2287    if (OP1_TYPE == IS_VAR && UNEXPECTED(variable_ptr == &EG(error_zval))) {
2288        FREE_OP2();
2289        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2290            ZVAL_NULL(EX_VAR(opline->result.var));
2291        }
2292    } else {
2293        value = zend_assign_to_variable(variable_ptr, value, OP2_TYPE);
2294        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2295            ZVAL_COPY(EX_VAR(opline->result.var), value);
2296        }
2297        FREE_OP1_VAR_PTR();
2298        /* zend_assign_to_variable() always takes care of op2, never free it! */
2299    }
2300
2301    CHECK_EXCEPTION();
2302    ZEND_VM_NEXT_OPCODE();
2303}
2304
2305ZEND_VM_HANDLER(39, ZEND_ASSIGN_REF, VAR|CV, VAR|CV)
2306{
2307    USE_OPLINE
2308    zend_free_op free_op1, free_op2;
2309    zval *variable_ptr;
2310    zval *value_ptr;
2311
2312    SAVE_OPLINE();
2313    value_ptr = GET_OP2_ZVAL_PTR_PTR(BP_VAR_W);
2314
2315    if (OP2_TYPE == IS_VAR && UNEXPECTED(value_ptr == NULL)) {
2316        zend_throw_error(zend_ce_error, "Cannot create references to/from string offsets nor overloaded objects");
2317        FREE_UNFETCHED_OP1();
2318        HANDLE_EXCEPTION();
2319    }
2320    if (OP2_TYPE == IS_VAR &&
2321        (value_ptr == &EG(uninitialized_zval) ||
2322         (opline->extended_value == ZEND_RETURNS_FUNCTION &&
2323          !(Z_VAR_FLAGS_P(value_ptr) & IS_VAR_RET_REF)))) {
2324        if (!OP2_FREE) {
2325            PZVAL_LOCK(value_ptr); /* undo the effect of get_zval_ptr_ptr() */
2326        }
2327        zend_error(E_NOTICE, "Only variables should be assigned by reference");
2328        if (UNEXPECTED(EG(exception) != NULL)) {
2329            FREE_OP2_VAR_PTR();
2330            HANDLE_EXCEPTION();
2331        }
2332        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_ASSIGN);
2333    }
2334
2335    variable_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
2336    if (OP1_TYPE == IS_VAR && UNEXPECTED(variable_ptr == NULL)) {
2337        zend_throw_error(zend_ce_error, "Cannot create references to/from string offsets nor overloaded objects");
2338        FREE_OP2_VAR_PTR();
2339        HANDLE_EXCEPTION();
2340    }
2341    if (OP1_TYPE == IS_VAR &&
2342        UNEXPECTED(Z_TYPE_P(EX_VAR(opline->op1.var)) != IS_INDIRECT) &&
2343        UNEXPECTED(!Z_ISREF_P(variable_ptr))) {
2344        zend_throw_error(zend_ce_error, "Cannot assign by reference to overloaded object");
2345        FREE_OP2_VAR_PTR();
2346        FREE_OP1_VAR_PTR();
2347        HANDLE_EXCEPTION();
2348    }
2349    if ((OP1_TYPE == IS_VAR && UNEXPECTED(variable_ptr == &EG(error_zval))) ||
2350        (OP2_TYPE == IS_VAR && UNEXPECTED(value_ptr == &EG(error_zval)))) {
2351        variable_ptr = &EG(uninitialized_zval);
2352    } else {
2353        zend_assign_to_variable_reference(variable_ptr, value_ptr);
2354    }
2355
2356    if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2357        ZVAL_COPY(EX_VAR(opline->result.var), variable_ptr);
2358    }
2359
2360    FREE_OP1_VAR_PTR();
2361    FREE_OP2_VAR_PTR();
2362
2363    CHECK_EXCEPTION();
2364    ZEND_VM_NEXT_OPCODE();
2365}
2366
2367ZEND_VM_HELPER(zend_leave_helper, ANY, ANY)
2368{
2369    zend_execute_data *old_execute_data;
2370    uint32_t call_info = EX_CALL_INFO();
2371
2372    if (ZEND_CALL_KIND_EX(call_info) == ZEND_CALL_NESTED_FUNCTION) {
2373        zend_object *object;
2374
2375        i_free_compiled_variables(execute_data);
2376        if (UNEXPECTED(EX(symbol_table) != NULL)) {
2377            zend_clean_and_cache_symbol_table(EX(symbol_table));
2378        }
2379        zend_vm_stack_free_extra_args_ex(call_info, execute_data);
2380        old_execute_data = execute_data;
2381        execute_data = EG(current_execute_data) = EX(prev_execute_data);
2382        if (UNEXPECTED(call_info & ZEND_CALL_CLOSURE)) {
2383            OBJ_RELEASE((zend_object*)old_execute_data->func->op_array.prototype);
2384        }
2385        if (UNEXPECTED(call_info & ZEND_CALL_RELEASE_THIS)) {
2386            object = Z_OBJ(old_execute_data->This);
2387#if 0
2388            if (UNEXPECTED(EG(exception) != NULL) && (EX(opline)->op1.num & ZEND_CALL_CTOR)) {
2389                if (!(EX(opline)->op1.num & ZEND_CALL_CTOR_RESULT_UNUSED)) {
2390#else
2391            if (UNEXPECTED(EG(exception) != NULL) && (call_info & ZEND_CALL_CTOR)) {
2392                if (!(call_info & ZEND_CALL_CTOR_RESULT_UNUSED)) {
2393#endif
2394                    GC_REFCOUNT(object)--;
2395                }
2396                if (GC_REFCOUNT(object) == 1) {
2397                    zend_object_store_ctor_failed(object);
2398                }
2399            }
2400            OBJ_RELEASE(object);
2401        }
2402        EG(scope) = EX(func)->op_array.scope;
2403
2404        zend_vm_stack_free_call_frame_ex(call_info, old_execute_data);
2405
2406        if (UNEXPECTED(EG(exception) != NULL)) {
2407            const zend_op *old_opline = EX(opline);
2408            zend_throw_exception_internal(NULL);
2409            if (RETURN_VALUE_USED(old_opline)) {
2410                zval_ptr_dtor(EX_VAR(old_opline->result.var));
2411            }
2412            HANDLE_EXCEPTION_LEAVE();
2413        }
2414
2415        LOAD_OPLINE();
2416        ZEND_VM_INC_OPCODE();
2417        ZEND_VM_LEAVE();
2418    } else if (ZEND_CALL_KIND_EX(call_info) == ZEND_CALL_NESTED_CODE) {
2419        zend_detach_symbol_table(execute_data);
2420        destroy_op_array(&EX(func)->op_array);
2421        efree_size(EX(func), sizeof(zend_op_array));
2422        old_execute_data = execute_data;
2423        execute_data = EG(current_execute_data) = EX(prev_execute_data);
2424        zend_vm_stack_free_call_frame_ex(call_info, old_execute_data);
2425
2426        zend_attach_symbol_table(execute_data);
2427        if (UNEXPECTED(EG(exception) != NULL)) {
2428            zend_throw_exception_internal(NULL);
2429            HANDLE_EXCEPTION_LEAVE();
2430        }
2431
2432        LOAD_OPLINE();
2433        ZEND_VM_INC_OPCODE();
2434        ZEND_VM_LEAVE();
2435    } else {
2436        if (ZEND_CALL_KIND_EX(call_info) == ZEND_CALL_TOP_FUNCTION) {
2437            i_free_compiled_variables(execute_data);
2438            if (UNEXPECTED(EX(symbol_table) != NULL)) {
2439                zend_clean_and_cache_symbol_table(EX(symbol_table));
2440            }
2441            zend_vm_stack_free_extra_args_ex(call_info, execute_data);
2442            EG(current_execute_data) = EX(prev_execute_data);
2443            if (UNEXPECTED(call_info & ZEND_CALL_CLOSURE)) {
2444                OBJ_RELEASE((zend_object*)EX(func)->op_array.prototype);
2445            }
2446        } else /* if (call_kind == ZEND_CALL_TOP_CODE) */ {
2447            zend_array *symbol_table = EX(symbol_table);
2448
2449            zend_detach_symbol_table(execute_data);
2450            old_execute_data = EX(prev_execute_data);
2451            while (old_execute_data) {
2452                if (old_execute_data->func && ZEND_USER_CODE(old_execute_data->func->op_array.type)) {
2453                    if (old_execute_data->symbol_table == symbol_table) {
2454                        zend_attach_symbol_table(old_execute_data);
2455                    }
2456                    break;
2457                }
2458                old_execute_data = old_execute_data->prev_execute_data;
2459            }
2460            EG(current_execute_data) = EX(prev_execute_data);
2461        }
2462
2463        ZEND_VM_RETURN();
2464    }
2465}
2466
2467ZEND_VM_HANDLER(42, ZEND_JMP, ANY, ANY)
2468{
2469    USE_OPLINE
2470
2471    ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op1));
2472    ZEND_VM_CONTINUE();
2473}
2474
2475ZEND_VM_HANDLER(43, ZEND_JMPZ, CONST|TMPVAR|CV, ANY)
2476{
2477    USE_OPLINE
2478    zend_free_op free_op1;
2479    zval *val;
2480
2481    val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2482
2483    if (Z_TYPE_INFO_P(val) == IS_TRUE) {
2484        ZEND_VM_SET_NEXT_OPCODE(opline + 1);
2485        ZEND_VM_CONTINUE();
2486    } else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
2487        if (OP1_TYPE == IS_CV) {
2488            if (UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
2489                SAVE_OPLINE();
2490                GET_OP1_UNDEF_CV(val, BP_VAR_R);
2491            }
2492            ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
2493        } else {
2494            ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2495            ZEND_VM_CONTINUE();
2496        }
2497    }
2498
2499    SAVE_OPLINE();
2500    if (i_zend_is_true(val)) {
2501        opline++;
2502    } else {
2503        opline = OP_JMP_ADDR(opline, opline->op2);
2504    }
2505    FREE_OP1();
2506    if (UNEXPECTED(EG(exception) != NULL)) {
2507        HANDLE_EXCEPTION();
2508    }
2509    ZEND_VM_JMP(opline);
2510}
2511
2512ZEND_VM_HANDLER(44, ZEND_JMPNZ, CONST|TMPVAR|CV, ANY)
2513{
2514    USE_OPLINE
2515    zend_free_op free_op1;
2516    zval *val;
2517
2518    val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2519
2520    if (Z_TYPE_INFO_P(val) == IS_TRUE) {
2521        ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2522        ZEND_VM_CONTINUE();
2523    } else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
2524        if (OP1_TYPE == IS_CV) {
2525            if (UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
2526                SAVE_OPLINE();
2527                GET_OP1_UNDEF_CV(val, BP_VAR_R);
2528                CHECK_EXCEPTION();
2529            }
2530            ZEND_VM_NEXT_OPCODE();
2531        } else {
2532            ZEND_VM_SET_NEXT_OPCODE(opline + 1);
2533            ZEND_VM_CONTINUE();
2534        }
2535    }
2536
2537    SAVE_OPLINE();
2538    if (i_zend_is_true(val)) {
2539        opline = OP_JMP_ADDR(opline, opline->op2);
2540    } else {
2541        opline++;
2542    }
2543    FREE_OP1();
2544    if (UNEXPECTED(EG(exception) != NULL)) {
2545        HANDLE_EXCEPTION();
2546    }
2547    ZEND_VM_JMP(opline);
2548}
2549
2550ZEND_VM_HANDLER(45, ZEND_JMPZNZ, CONST|TMPVAR|CV, ANY)
2551{
2552    USE_OPLINE
2553    zend_free_op free_op1;
2554    zval *val;
2555
2556    val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2557
2558    if (EXPECTED(Z_TYPE_INFO_P(val) == IS_TRUE)) {
2559        ZEND_VM_SET_RELATIVE_OPCODE(opline, opline->extended_value);
2560        ZEND_VM_CONTINUE();
2561    } else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
2562        if (OP1_TYPE == IS_CV) {
2563            if (UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
2564                SAVE_OPLINE();
2565                GET_OP1_UNDEF_CV(val, BP_VAR_R);
2566            }
2567            ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
2568        } else {
2569            ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2570            ZEND_VM_CONTINUE();
2571        }
2572    }
2573
2574    SAVE_OPLINE();
2575    if (i_zend_is_true(val)) {
2576        opline = ZEND_OFFSET_TO_OPLINE(opline, opline->extended_value);
2577    } else {
2578        opline = OP_JMP_ADDR(opline, opline->op2);
2579    }
2580    FREE_OP1();
2581    if (UNEXPECTED(EG(exception) != NULL)) {
2582        HANDLE_EXCEPTION();
2583    }
2584    ZEND_VM_JMP(opline);
2585}
2586
2587ZEND_VM_HANDLER(46, ZEND_JMPZ_EX, CONST|TMPVAR|CV, ANY)
2588{
2589    USE_OPLINE
2590    zend_free_op free_op1;
2591    zval *val;
2592    int ret;
2593
2594    val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2595
2596    if (Z_TYPE_INFO_P(val) == IS_TRUE) {
2597        ZVAL_TRUE(EX_VAR(opline->result.var));
2598        ZEND_VM_SET_NEXT_OPCODE(opline + 1);
2599        ZEND_VM_CONTINUE();
2600    } else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
2601        ZVAL_FALSE(EX_VAR(opline->result.var));
2602        if (OP1_TYPE == IS_CV) {
2603            if (UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
2604                SAVE_OPLINE();
2605                GET_OP1_UNDEF_CV(val, BP_VAR_R);
2606            }
2607            ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
2608        } else {
2609            ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2610            ZEND_VM_CONTINUE();
2611        }
2612    }
2613
2614    SAVE_OPLINE();
2615    ret = i_zend_is_true(val);
2616    FREE_OP1();
2617    if (ret) {
2618        ZVAL_TRUE(EX_VAR(opline->result.var));
2619        opline++;
2620    } else {
2621        ZVAL_FALSE(EX_VAR(opline->result.var));
2622        opline = OP_JMP_ADDR(opline, opline->op2);
2623    }
2624    if (UNEXPECTED(EG(exception) != NULL)) {
2625        HANDLE_EXCEPTION();
2626    }
2627    ZEND_VM_JMP(opline);
2628}
2629
2630ZEND_VM_HANDLER(47, ZEND_JMPNZ_EX, CONST|TMPVAR|CV, ANY)
2631{
2632    USE_OPLINE
2633    zend_free_op free_op1;
2634    zval *val;
2635    int ret;
2636
2637    val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2638
2639    if (Z_TYPE_INFO_P(val) == IS_TRUE) {
2640        ZVAL_TRUE(EX_VAR(opline->result.var));
2641        ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2642        ZEND_VM_CONTINUE();
2643    } else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
2644        ZVAL_FALSE(EX_VAR(opline->result.var));
2645        if (OP1_TYPE == IS_CV) {
2646            if (UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
2647                SAVE_OPLINE();
2648                GET_OP1_UNDEF_CV(val, BP_VAR_R);
2649                CHECK_EXCEPTION();
2650            }
2651            ZEND_VM_NEXT_OPCODE();
2652        } else {
2653            ZEND_VM_SET_NEXT_OPCODE(opline + 1);
2654            ZEND_VM_CONTINUE();
2655        }
2656    }
2657
2658    SAVE_OPLINE();
2659    ret = i_zend_is_true(val);
2660    FREE_OP1();
2661    if (ret) {
2662        ZVAL_TRUE(EX_VAR(opline->result.var));
2663        opline = OP_JMP_ADDR(opline, opline->op2);
2664    } else {
2665        ZVAL_FALSE(EX_VAR(opline->result.var));
2666        opline++;
2667    }
2668    if (UNEXPECTED(EG(exception) != NULL)) {
2669        HANDLE_EXCEPTION();
2670    }
2671    ZEND_VM_JMP(opline);
2672}
2673
2674ZEND_VM_HANDLER(70, ZEND_FREE, TMPVAR, ANY)
2675{
2676    USE_OPLINE
2677
2678    SAVE_OPLINE();
2679    zval_ptr_dtor_nogc(EX_VAR(opline->op1.var));
2680    CHECK_EXCEPTION();
2681    ZEND_VM_NEXT_OPCODE();
2682}
2683
2684ZEND_VM_HANDLER(127, ZEND_FE_FREE, TMPVAR, ANY)
2685{
2686    zval *var;
2687    USE_OPLINE
2688
2689    SAVE_OPLINE();
2690    var = EX_VAR(opline->op1.var);
2691    if (Z_TYPE_P(var) != IS_ARRAY && Z_FE_ITER_P(var) != (uint32_t)-1) {
2692        zend_hash_iterator_del(Z_FE_ITER_P(var));
2693    }
2694    zval_ptr_dtor_nogc(var);
2695    CHECK_EXCEPTION();
2696    ZEND_VM_NEXT_OPCODE();
2697}
2698
2699ZEND_VM_HANDLER(53, ZEND_FAST_CONCAT, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
2700{
2701    USE_OPLINE
2702    zend_free_op free_op1, free_op2;
2703    zval *op1, *op2;
2704    zend_string *op1_str, *op2_str, *str;
2705
2706    SAVE_OPLINE();
2707    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2708    if (OP1_TYPE == IS_CONST) {
2709        op1_str = Z_STR_P(op1);
2710    } else if (EXPECTED(Z_TYPE_P(op1) == IS_STRING)) {
2711        op1_str = zend_string_copy(Z_STR_P(op1));
2712    } else {
2713        if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op1) == IS_UNDEF)) {
2714            GET_OP1_UNDEF_CV(op1, BP_VAR_R);
2715        }
2716        op1_str = _zval_get_string_func(op1);
2717    }
2718    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2719    if (OP2_TYPE == IS_CONST) {
2720        op2_str = Z_STR_P(op2);
2721    } else if (EXPECTED(Z_TYPE_P(op2) == IS_STRING)) {
2722        op2_str = zend_string_copy(Z_STR_P(op2));
2723    } else {
2724        if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op2) == IS_UNDEF)) {
2725            GET_OP2_UNDEF_CV(op2, BP_VAR_R);
2726        }
2727        op2_str = _zval_get_string_func(op2);
2728    }
2729    do {
2730        if (OP1_TYPE != IS_CONST) {
2731            if (UNEXPECTED(ZSTR_LEN(op1_str) == 0)) {
2732                if (OP2_TYPE == IS_CONST) {
2733                    zend_string_addref(op2_str);
2734                }
2735                ZVAL_STR(EX_VAR(opline->result.var), op2_str);
2736                zend_string_release(op1_str);
2737                break;
2738            }
2739        }
2740        if (OP2_TYPE != IS_CONST) {
2741            if (UNEXPECTED(ZSTR_LEN(op2_str) == 0)) {
2742                if (OP1_TYPE == IS_CONST) {
2743                    zend_string_addref(op1_str);
2744                }
2745                ZVAL_STR(EX_VAR(opline->result.var), op1_str);
2746                zend_string_release(op2_str);
2747                break;
2748            }
2749        }
2750        str = zend_string_alloc(ZSTR_LEN(op1_str) + ZSTR_LEN(op2_str), 0);
2751        memcpy(ZSTR_VAL(str), ZSTR_VAL(op1_str), ZSTR_LEN(op1_str));
2752        memcpy(ZSTR_VAL(str) + ZSTR_LEN(op1_str), ZSTR_VAL(op2_str), ZSTR_LEN(op2_str)+1);
2753        ZVAL_NEW_STR(EX_VAR(opline->result.var), str);
2754        if (OP1_TYPE != IS_CONST) {
2755            zend_string_release(op1_str);
2756        }
2757        if (OP2_TYPE != IS_CONST) {
2758            zend_string_release(op2_str);
2759        }
2760    } while (0);
2761    FREE_OP1();
2762    FREE_OP2();
2763    CHECK_EXCEPTION();
2764    ZEND_VM_NEXT_OPCODE();
2765}
2766
2767ZEND_VM_HANDLER(54, ZEND_ROPE_INIT, UNUSED, CONST|TMPVAR|CV)
2768{
2769    USE_OPLINE
2770    zend_free_op free_op2;
2771    zend_string **rope;
2772    zval *var;
2773
2774    /* Compiler allocates the necessary number of zval slots to keep the rope */
2775    rope = (zend_string**)EX_VAR(opline->result.var);
2776    if (OP2_TYPE == IS_CONST) {
2777        var = GET_OP2_ZVAL_PTR(BP_VAR_R);
2778        rope[0] = zend_string_copy(Z_STR_P(var));
2779    } else {
2780        var = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2781        if (EXPECTED(Z_TYPE_P(var) == IS_STRING)) {
2782            if (OP2_TYPE == IS_CV) {
2783                rope[0] = zend_string_copy(Z_STR_P(var));
2784            } else {
2785                rope[0] = Z_STR_P(var);
2786            }
2787        } else {
2788            SAVE_OPLINE();
2789            if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var) == IS_UNDEF)) {
2790                GET_OP2_UNDEF_CV(var, BP_VAR_R);
2791            }
2792            rope[0] = _zval_get_string_func(var);
2793            FREE_OP2();
2794            CHECK_EXCEPTION();
2795        }
2796    }
2797    ZEND_VM_NEXT_OPCODE();
2798}
2799
2800ZEND_VM_HANDLER(55, ZEND_ROPE_ADD, TMP, CONST|TMPVAR|CV)
2801{
2802    USE_OPLINE
2803    zend_free_op free_op2;
2804    zend_string **rope;
2805    zval *var;
2806
2807    /* op1 and result are the same */
2808    rope = (zend_string**)EX_VAR(opline->op1.var);
2809    if (OP2_TYPE == IS_CONST) {
2810        var = GET_OP2_ZVAL_PTR(BP_VAR_R);
2811        rope[opline->extended_value] = zend_string_copy(Z_STR_P(var));
2812    } else {
2813        var = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2814        if (EXPECTED(Z_TYPE_P(var) == IS_STRING)) {
2815            if (OP2_TYPE == IS_CV) {
2816                rope[opline->extended_value] = zend_string_copy(Z_STR_P(var));
2817            } else {
2818                rope[opline->extended_value] = Z_STR_P(var);
2819            }
2820        } else {
2821            SAVE_OPLINE();
2822            if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var) == IS_UNDEF)) {
2823                GET_OP2_UNDEF_CV(var, BP_VAR_R);
2824            }
2825            rope[opline->extended_value] = _zval_get_string_func(var);
2826            FREE_OP2();
2827            CHECK_EXCEPTION();
2828        }
2829    }
2830    ZEND_VM_NEXT_OPCODE();
2831}
2832
2833ZEND_VM_HANDLER(56, ZEND_ROPE_END, TMP, CONST|TMPVAR|CV)
2834{
2835    USE_OPLINE
2836    zend_free_op free_op2;
2837    zend_string **rope;
2838    zval *var, *ret;
2839    uint32_t i;
2840    size_t len = 0;
2841    char *target;
2842
2843    rope = (zend_string**)EX_VAR(opline->op1.var);
2844    if (OP2_TYPE == IS_CONST) {
2845        var = GET_OP2_ZVAL_PTR(BP_VAR_R);
2846        rope[opline->extended_value] = zend_string_copy(Z_STR_P(var));
2847    } else {
2848        var = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2849        if (EXPECTED(Z_TYPE_P(var) == IS_STRING)) {
2850            if (OP2_TYPE == IS_CV) {
2851                rope[opline->extended_value] = zend_string_copy(Z_STR_P(var));
2852            } else {
2853                rope[opline->extended_value] = Z_STR_P(var);
2854            }
2855        } else {
2856            SAVE_OPLINE();
2857            if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var) == IS_UNDEF)) {
2858                GET_OP2_UNDEF_CV(var, BP_VAR_R);
2859            }
2860            rope[opline->extended_value] = _zval_get_string_func(var);
2861            FREE_OP2();
2862            CHECK_EXCEPTION();
2863        }
2864    }
2865    for (i = 0; i <= opline->extended_value; i++) {
2866        len += ZSTR_LEN(rope[i]);
2867    }
2868    ret = EX_VAR(opline->result.var);
2869    ZVAL_STR(ret, zend_string_alloc(len, 0));
2870    target = Z_STRVAL_P(ret);
2871    for (i = 0; i <= opline->extended_value; i++) {
2872        memcpy(target, ZSTR_VAL(rope[i]), ZSTR_LEN(rope[i]));
2873        target += ZSTR_LEN(rope[i]);
2874        zend_string_release(rope[i]);
2875    }
2876    *target = '\0';
2877
2878    ZEND_VM_NEXT_OPCODE();
2879}
2880
2881ZEND_VM_HANDLER(109, ZEND_FETCH_CLASS, ANY, CONST|TMPVAR|UNUSED|CV)
2882{
2883    USE_OPLINE
2884
2885    SAVE_OPLINE();
2886    if (EG(exception)) {
2887        zend_exception_save();
2888    }
2889    if (OP2_TYPE == IS_UNUSED) {
2890        Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class(NULL, opline->extended_value);
2891        CHECK_EXCEPTION();
2892        ZEND_VM_NEXT_OPCODE();
2893    } else {
2894        zend_free_op free_op2;
2895        zval *class_name = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2896
2897ZEND_VM_C_LABEL(try_class_name):
2898        if (OP2_TYPE == IS_CONST) {
2899            if (CACHED_PTR(Z_CACHE_SLOT_P(class_name))) {
2900                Z_CE_P(EX_VAR(opline->result.var)) = CACHED_PTR(Z_CACHE_SLOT_P(class_name));
2901            } else {
2902                Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class_by_name(Z_STR_P(class_name), EX_CONSTANT(opline->op2) + 1, opline->extended_value);
2903                CACHE_PTR(Z_CACHE_SLOT_P(class_name), Z_CE_P(EX_VAR(opline->result.var)));
2904            }
2905        } else if (Z_TYPE_P(class_name) == IS_OBJECT) {
2906            Z_CE_P(EX_VAR(opline->result.var)) = Z_OBJCE_P(class_name);
2907        } else if (Z_TYPE_P(class_name) == IS_STRING) {
2908            Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class(Z_STR_P(class_name), opline->extended_value);
2909        } else if ((OP2_TYPE & (IS_VAR|IS_CV)) && Z_TYPE_P(class_name) == IS_REFERENCE) {
2910            class_name = Z_REFVAL_P(class_name);
2911            ZEND_VM_C_GOTO(try_class_name);
2912        } else {
2913            if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(class_name) == IS_UNDEF)) {
2914                GET_OP2_UNDEF_CV(class_name, BP_VAR_R);
2915            }
2916            if (UNEXPECTED(EG(exception) != NULL)) {
2917                HANDLE_EXCEPTION();
2918            }
2919            zend_throw_error(zend_ce_error, "Class name must be a valid object or a string");
2920        }
2921
2922        FREE_OP2();
2923        CHECK_EXCEPTION();
2924        ZEND_VM_NEXT_OPCODE();
2925    }
2926}
2927
2928ZEND_VM_HANDLER(112, ZEND_INIT_METHOD_CALL, CONST|TMPVAR|UNUSED|CV, CONST|TMPVAR|CV)
2929{
2930    USE_OPLINE
2931    zval *function_name;
2932    zend_free_op free_op1, free_op2;
2933    zval *object;
2934    zend_function *fbc;
2935    zend_class_entry *called_scope;
2936    zend_object *obj;
2937    zend_execute_data *call;
2938    uint32_t call_info;
2939
2940    SAVE_OPLINE();
2941
2942    function_name = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2943
2944    if (OP2_TYPE != IS_CONST &&
2945        UNEXPECTED(Z_TYPE_P(function_name) != IS_STRING)) {
2946        do {
2947            if ((OP2_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(function_name)) {
2948                function_name = Z_REFVAL_P(function_name);
2949                if (EXPECTED(Z_TYPE_P(function_name) == IS_STRING)) {
2950                    break;
2951                }
2952            }
2953            if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(function_name) == IS_UNDEF)) {
2954                GET_OP2_UNDEF_CV(function_name, BP_VAR_R);
2955            }
2956            if (UNEXPECTED(EG(exception) != NULL)) {
2957                HANDLE_EXCEPTION();
2958            }
2959            zend_throw_error(zend_ce_error, "Method name must be a string");
2960            FREE_OP2();
2961            FREE_UNFETCHED_OP1();
2962            HANDLE_EXCEPTION();
2963        } while (0);
2964    }
2965
2966    object = GET_OP1_OBJ_ZVAL_PTR_UNDEF(BP_VAR_R);
2967
2968    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(object) == NULL)) {
2969        zend_throw_error(zend_ce_error, "Using $this when not in object context");
2970        FREE_OP2();
2971        HANDLE_EXCEPTION();
2972    }
2973
2974    if (OP1_TYPE != IS_UNUSED) {
2975        do {
2976            if (OP1_TYPE == IS_CONST || UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
2977                if ((OP1_TYPE & (IS_VAR|IS_CV)) && EXPECTED(Z_ISREF_P(object))) {
2978                    object = Z_REFVAL_P(object);
2979                    if (EXPECTED(Z_TYPE_P(object) == IS_OBJECT)) {
2980                        break;
2981                    }
2982                }
2983                if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(object) == IS_UNDEF)) {
2984                    GET_OP1_UNDEF_CV(object, BP_VAR_R);
2985                }
2986                if (UNEXPECTED(EG(exception) != NULL)) {
2987                    HANDLE_EXCEPTION();
2988                }
2989                zend_throw_error(zend_ce_error, "Call to a member function %s() on %s", Z_STRVAL_P(function_name), zend_get_type_by_const(Z_TYPE_P(object)));
2990                FREE_OP2();
2991                FREE_OP1();
2992                HANDLE_EXCEPTION();
2993            }
2994        } while (0);
2995    }
2996
2997    obj = Z_OBJ_P(object);
2998    called_scope = obj->ce;
2999
3000    if (OP2_TYPE != IS_CONST ||
3001        UNEXPECTED((fbc = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), called_scope)) == NULL)) {
3002        zend_object *orig_obj = obj;
3003
3004        if (UNEXPECTED(obj->handlers->get_method == NULL)) {
3005            zend_throw_error(zend_ce_error, "Object does not support method calls");
3006            FREE_OP2();
3007            FREE_OP1();
3008            HANDLE_EXCEPTION();
3009        }
3010
3011        /* First, locate the function. */
3012        fbc = obj->handlers->get_method(&obj, Z_STR_P(function_name), ((OP2_TYPE == IS_CONST) ? (EX_CONSTANT(opline->op2) + 1) : NULL));
3013        if (UNEXPECTED(fbc == NULL)) {
3014            if (EXPECTED(!EG(exception))) {
3015                zend_throw_error(zend_ce_error, "Call to undefined method %s::%s()", ZSTR_VAL(obj->ce->name), Z_STRVAL_P(function_name));
3016            }
3017            FREE_OP2();
3018            FREE_OP1();
3019            HANDLE_EXCEPTION();
3020        }
3021        if (OP2_TYPE == IS_CONST &&
3022            EXPECTED(fbc->type <= ZEND_USER_FUNCTION) &&
3023            EXPECTED(!(fbc->common.fn_flags & (ZEND_ACC_CALL_VIA_TRAMPOLINE|ZEND_ACC_NEVER_CACHE))) &&
3024            EXPECTED(obj == orig_obj)) {
3025            CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), called_scope, fbc);
3026        }
3027    }
3028
3029    call_info = ZEND_CALL_NESTED_FUNCTION;
3030    if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_STATIC) != 0)) {
3031        obj = NULL;
3032    } else if (OP1_TYPE & (IS_VAR|IS_TMP_VAR|IS_CV)) {
3033        /* CV may be changed indirectly (e.g. when it's a reference) */
3034        call_info = ZEND_CALL_NESTED_FUNCTION | ZEND_CALL_RELEASE_THIS;
3035        GC_REFCOUNT(obj)++; /* For $this pointer */
3036    }
3037
3038    call = zend_vm_stack_push_call_frame(call_info,
3039        fbc, opline->extended_value, called_scope, obj);
3040    call->prev_execute_data = EX(call);
3041    EX(call) = call;
3042
3043    FREE_OP2();
3044    FREE_OP1();
3045
3046    CHECK_EXCEPTION();
3047    ZEND_VM_NEXT_OPCODE();
3048}
3049
3050ZEND_VM_HANDLER(113, ZEND_INIT_STATIC_METHOD_CALL, CONST|VAR, CONST|TMPVAR|UNUSED|CV)
3051{
3052    USE_OPLINE
3053    zval *function_name;
3054    zend_class_entry *ce;
3055    zend_object *object;
3056    zend_function *fbc;
3057    zend_execute_data *call;
3058
3059    SAVE_OPLINE();
3060
3061    if (OP1_TYPE == IS_CONST) {
3062        /* no function found. try a static method in class */
3063        if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)))) {
3064            ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
3065        } else {
3066            ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, ZEND_FETCH_CLASS_DEFAULT |  ZEND_FETCH_CLASS_EXCEPTION);
3067            if (UNEXPECTED(EG(exception) != NULL)) {
3068                HANDLE_EXCEPTION();
3069            }
3070            if (UNEXPECTED(ce == NULL)) {
3071                zend_throw_error(zend_ce_error, "Class '%s' not found", Z_STRVAL_P(EX_CONSTANT(opline->op1)));
3072                HANDLE_EXCEPTION();
3073            }
3074            CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce);
3075        }
3076    } else {
3077        ce = Z_CE_P(EX_VAR(opline->op1.var));
3078    }
3079
3080    if (OP1_TYPE == IS_CONST &&
3081        OP2_TYPE == IS_CONST &&
3082        CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) {
3083        fbc = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
3084    } else if (OP1_TYPE != IS_CONST &&
3085               OP2_TYPE == IS_CONST &&
3086               (fbc = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce))) {
3087        /* do nothing */
3088    } else if (OP2_TYPE != IS_UNUSED) {
3089        zend_free_op free_op2;
3090
3091        function_name = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
3092        if (OP2_TYPE != IS_CONST) {
3093            if (UNEXPECTED(Z_TYPE_P(function_name) != IS_STRING)) {
3094                if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(function_name) == IS_UNDEF)) {
3095                    GET_OP2_UNDEF_CV(function_name, BP_VAR_R);
3096                }
3097                if (UNEXPECTED(EG(exception) != NULL)) {
3098                    HANDLE_EXCEPTION();
3099                }
3100                zend_throw_error(zend_ce_error, "Function name must be a string");
3101                FREE_OP2();
3102                HANDLE_EXCEPTION();
3103            }
3104        }
3105
3106        if (ce->get_static_method) {
3107            fbc = ce->get_static_method(ce, Z_STR_P(function_name));
3108        } else {
3109            fbc = zend_std_get_static_method(ce, Z_STR_P(function_name), ((OP2_TYPE == IS_CONST) ? (EX_CONSTANT(opline->op2) + 1) : NULL));
3110        }
3111        if (UNEXPECTED(fbc == NULL)) {
3112            if (EXPECTED(!EG(exception))) {
3113                zend_throw_error(zend_ce_error, "Call to undefined method %s::%s()", ZSTR_VAL(ce->name), Z_STRVAL_P(function_name));
3114            }
3115            FREE_OP2();
3116            HANDLE_EXCEPTION();
3117        }
3118        if (OP2_TYPE == IS_CONST &&
3119            EXPECTED(fbc->type <= ZEND_USER_FUNCTION) &&
3120            EXPECTED(!(fbc->common.fn_flags & (ZEND_ACC_CALL_VIA_TRAMPOLINE|ZEND_ACC_NEVER_CACHE)))) {
3121            if (OP1_TYPE == IS_CONST) {
3122                CACHE_PTR(Z_CACHE_SLOT_P(function_name), fbc);
3123            } else {
3124                CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), ce, fbc);
3125            }
3126        }
3127        if (OP2_TYPE != IS_CONST) {
3128            FREE_OP2();
3129        }
3130    } else {
3131        if (UNEXPECTED(ce->constructor == NULL)) {
3132            zend_throw_error(zend_ce_error, "Cannot call constructor");
3133            HANDLE_EXCEPTION();
3134        }
3135        if (Z_OBJ(EX(This)) && Z_OBJ(EX(This))->ce != ce->constructor->common.scope && (ce->constructor->common.fn_flags & ZEND_ACC_PRIVATE)) {
3136            zend_throw_error(zend_ce_error, "Cannot call private %s::__construct()", ZSTR_VAL(ce->name));
3137            HANDLE_EXCEPTION();
3138        }
3139        fbc = ce->constructor;
3140    }
3141
3142    object = NULL;
3143    if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
3144        if (Z_OBJ(EX(This)) && instanceof_function(Z_OBJCE(EX(This)), ce)) {
3145            object = Z_OBJ(EX(This));
3146        }
3147        if (!object) {
3148            if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
3149                /* Allowed for PHP 4 compatibility. */
3150                zend_error(
3151                    E_DEPRECATED,
3152                    "Non-static method %s::%s() should not be called statically",
3153                    ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3154            } else {
3155                /* An internal function assumes $this is present and won't check that.
3156                 * So PHP would crash by allowing the call. */
3157                zend_throw_error(
3158                    zend_ce_error,
3159                    "Non-static method %s::%s() cannot be called statically",
3160                    ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3161                HANDLE_EXCEPTION();
3162            }
3163        }
3164    }
3165
3166    if (OP1_TYPE != IS_CONST) {
3167        /* previous opcode is ZEND_FETCH_CLASS */
3168        if (((opline-1)->extended_value & ZEND_FETCH_CLASS_MASK) == ZEND_FETCH_CLASS_PARENT ||
3169            ((opline-1)->extended_value & ZEND_FETCH_CLASS_MASK) == ZEND_FETCH_CLASS_SELF) {
3170            ce = EX(called_scope);
3171        }
3172    }
3173
3174    call = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
3175        fbc, opline->extended_value, ce, object);
3176    call->prev_execute_data = EX(call);
3177    EX(call) = call;
3178
3179    CHECK_EXCEPTION();
3180    ZEND_VM_NEXT_OPCODE();
3181}
3182
3183ZEND_VM_HANDLER(59, ZEND_INIT_FCALL_BY_NAME, ANY, CONST)
3184{
3185    USE_OPLINE
3186    zend_function *fbc;
3187    zval *function_name, *func;
3188    zend_execute_data *call;
3189
3190    if (EXPECTED(CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2))))) {
3191        fbc = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
3192    } else {
3193        function_name = (zval*)(EX_CONSTANT(opline->op2)+1);
3194        if (UNEXPECTED((func = zend_hash_find(EG(function_table), Z_STR_P(function_name))) == NULL)) {
3195            SAVE_OPLINE();
3196            zend_throw_error(zend_ce_error, "Call to undefined function %s()", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
3197            HANDLE_EXCEPTION();
3198        } else {
3199            fbc = Z_FUNC_P(func);
3200            CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), fbc);
3201        }
3202    }
3203    call = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
3204        fbc, opline->extended_value, NULL, NULL);
3205    call->prev_execute_data = EX(call);
3206    EX(call) = call;
3207
3208    ZEND_VM_NEXT_OPCODE();
3209}
3210
3211ZEND_VM_HANDLER(128, ZEND_INIT_DYNAMIC_CALL, ANY, CONST|TMPVAR|CV)
3212{
3213    USE_OPLINE
3214    zend_function *fbc;
3215    zval *function_name, *func;
3216    zend_string *lcname;
3217    zend_free_op free_op2;
3218    zend_class_entry *called_scope;
3219    zend_object *object;
3220    zend_execute_data *call;
3221    uint32_t call_info = ZEND_CALL_NESTED_FUNCTION;
3222
3223    SAVE_OPLINE();
3224    function_name = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
3225
3226ZEND_VM_C_LABEL(try_function_name):
3227    if (OP2_TYPE != IS_CONST && EXPECTED(Z_TYPE_P(function_name) == IS_STRING)) {
3228        const char *colon;
3229
3230        if ((colon = zend_memrchr(Z_STRVAL_P(function_name), ':', Z_STRLEN_P(function_name))) != NULL &&
3231            colon > Z_STRVAL_P(function_name) &&
3232            *(colon-1) == ':'
3233        ) {
3234            zend_string *mname;
3235            size_t cname_length = colon - Z_STRVAL_P(function_name) - 1;
3236            size_t mname_length = Z_STRLEN_P(function_name) - cname_length - (sizeof("::") - 1);
3237
3238            lcname = zend_string_init(Z_STRVAL_P(function_name), cname_length, 0);
3239
3240            object = NULL;
3241            called_scope = zend_fetch_class_by_name(lcname, NULL, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
3242            if (UNEXPECTED(called_scope == NULL)) {
3243                zend_string_release(lcname);
3244                CHECK_EXCEPTION();
3245                ZEND_VM_NEXT_OPCODE();
3246            }
3247
3248            mname = zend_string_init(Z_STRVAL_P(function_name) + (cname_length + sizeof("::") - 1), mname_length, 0);
3249
3250            if (called_scope->get_static_method) {
3251                fbc = called_scope->get_static_method(called_scope, mname);
3252            } else {
3253                fbc = zend_std_get_static_method(called_scope, mname, NULL);
3254            }
3255            if (UNEXPECTED(fbc == NULL)) {
3256                if (EXPECTED(!EG(exception))) {
3257                    zend_throw_error(zend_ce_error, "Call to undefined method %s::%s()", ZSTR_VAL(called_scope->name), ZSTR_VAL(mname));
3258                }
3259                zend_string_release(lcname);
3260                zend_string_release(mname);
3261                FREE_OP2();
3262                HANDLE_EXCEPTION();
3263            }
3264
3265            zend_string_release(lcname);
3266            zend_string_release(mname);
3267
3268            if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
3269                if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
3270                    zend_error(E_DEPRECATED,
3271                        "Non-static method %s::%s() should not be called statically",
3272                        ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3273                } else {
3274                    zend_throw_error(
3275                        zend_ce_error,
3276                        "Non-static method %s::%s() cannot be called statically",
3277                        ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3278                    FREE_OP2();
3279                    HANDLE_EXCEPTION();
3280                }
3281            }
3282        } else {
3283            if (Z_STRVAL_P(function_name)[0] == '\\') {
3284                lcname = zend_string_alloc(Z_STRLEN_P(function_name) - 1, 0);
3285                zend_str_tolower_copy(ZSTR_VAL(lcname), Z_STRVAL_P(function_name) + 1, Z_STRLEN_P(function_name) - 1);
3286            } else {
3287                lcname = zend_string_tolower(Z_STR_P(function_name));
3288            }
3289            if (UNEXPECTED((func = zend_hash_find(EG(function_table), lcname)) == NULL)) {
3290                zend_throw_error(zend_ce_error, "Call to undefined function %s()", Z_STRVAL_P(function_name));
3291                zend_string_release(lcname);
3292                FREE_OP2();
3293                HANDLE_EXCEPTION();
3294            }
3295            zend_string_release(lcname);
3296
3297            fbc = Z_FUNC_P(func);
3298            called_scope = NULL;
3299            object = NULL;
3300        }
3301        FREE_OP2();
3302    } else if (OP2_TYPE != IS_CONST &&
3303        EXPECTED(Z_TYPE_P(function_name) == IS_OBJECT) &&
3304        Z_OBJ_HANDLER_P(function_name, get_closure) &&
3305        Z_OBJ_HANDLER_P(function_name, get_closure)(function_name, &called_scope, &fbc, &object) == SUCCESS) {
3306        if (fbc->common.fn_flags & ZEND_ACC_CLOSURE) {
3307            /* Delay closure destruction until its invocation */
3308            ZEND_ASSERT(GC_TYPE(fbc->common.prototype) == IS_OBJECT);
3309            GC_REFCOUNT(fbc->common.prototype)++;
3310            call_info |= ZEND_CALL_CLOSURE;
3311        }
3312        FREE_OP2();
3313    } else if (EXPECTED(Z_TYPE_P(function_name) == IS_ARRAY) &&
3314            zend_hash_num_elements(Z_ARRVAL_P(function_name)) == 2) {
3315        zval *obj;
3316        zval *method;
3317        obj = zend_hash_index_find(Z_ARRVAL_P(function_name), 0);
3318        method = zend_hash_index_find(Z_ARRVAL_P(function_name), 1);
3319
3320        if (!obj || !method) {
3321            zend_throw_error(zend_ce_error, "Array callback has to contain indices 0 and 1");
3322            FREE_OP2();
3323            HANDLE_EXCEPTION();
3324        }
3325
3326        ZVAL_DEREF(obj);
3327        if (Z_TYPE_P(obj) != IS_STRING && Z_TYPE_P(obj) != IS_OBJECT) {
3328            zend_throw_error(zend_ce_error, "First array member is not a valid class name or object");
3329            FREE_OP2();
3330            HANDLE_EXCEPTION();
3331        }
3332
3333        ZVAL_DEREF(method);
3334        if (Z_TYPE_P(method) != IS_STRING) {
3335            zend_throw_error(zend_ce_error, "Second array member is not a valid method");
3336            FREE_OP2();
3337            HANDLE_EXCEPTION();
3338        }
3339
3340        if (Z_TYPE_P(obj) == IS_STRING) {
3341            object = NULL;
3342            called_scope = zend_fetch_class_by_name(Z_STR_P(obj), NULL, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
3343            if (UNEXPECTED(called_scope == NULL)) {
3344                CHECK_EXCEPTION();
3345                ZEND_VM_NEXT_OPCODE();
3346            }
3347
3348            if (called_scope->get_static_method) {
3349                fbc = called_scope->get_static_method(called_scope, Z_STR_P(method));
3350            } else {
3351                fbc = zend_std_get_static_method(called_scope, Z_STR_P(method), NULL);
3352            }
3353            if (UNEXPECTED(fbc == NULL)) {
3354                if (EXPECTED(!EG(exception))) {
3355                    zend_throw_error(zend_ce_error, "Call to undefined method %s::%s()", ZSTR_VAL(called_scope->name), Z_STRVAL_P(method));
3356                }
3357                FREE_OP2();
3358                HANDLE_EXCEPTION();
3359            }
3360            if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
3361                if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
3362                    zend_error(E_DEPRECATED,
3363                        "Non-static method %s::%s() should not be called statically",
3364                        ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3365                } else {
3366                    zend_throw_error(
3367                        zend_ce_error,
3368                        "Non-static method %s::%s() cannot be called statically",
3369                        ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3370                    FREE_OP2();
3371                    HANDLE_EXCEPTION();
3372                }
3373            }
3374        } else {
3375            called_scope = Z_OBJCE_P(obj);
3376            object = Z_OBJ_P(obj);
3377
3378            fbc = Z_OBJ_HT_P(obj)->get_method(&object, Z_STR_P(method), NULL);
3379            if (UNEXPECTED(fbc == NULL)) {
3380                if (EXPECTED(!EG(exception))) {
3381                    zend_throw_error(zend_ce_error, "Call to undefined method %s::%s()", ZSTR_VAL(object->ce->name), Z_STRVAL_P(method));
3382                }
3383                FREE_OP2();
3384                HANDLE_EXCEPTION();
3385            }
3386
3387            if ((fbc->common.fn_flags & ZEND_ACC_STATIC) != 0) {
3388                object = NULL;
3389            } else {
3390                call_info |= ZEND_CALL_RELEASE_THIS;
3391                GC_REFCOUNT(object)++; /* For $this pointer */
3392            }
3393        }
3394        FREE_OP2();
3395    } else if ((OP2_TYPE & (IS_VAR|IS_CV)) && Z_TYPE_P(function_name) == IS_REFERENCE) {
3396        function_name = Z_REFVAL_P(function_name);
3397        ZEND_VM_C_GOTO(try_function_name);
3398    } else {
3399        if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(function_name) == IS_UNDEF)) {
3400            GET_OP2_UNDEF_CV(function_name, BP_VAR_R);
3401        }
3402        if (UNEXPECTED(EG(exception) != NULL)) {
3403            HANDLE_EXCEPTION();
3404        }
3405        zend_throw_error(zend_ce_error, "Function name must be a string");
3406        FREE_OP2();
3407        HANDLE_EXCEPTION();
3408    }
3409    call = zend_vm_stack_push_call_frame(call_info,
3410        fbc, opline->extended_value, called_scope, object);
3411    call->prev_execute_data = EX(call);
3412    EX(call) = call;
3413
3414    CHECK_EXCEPTION();
3415    ZEND_VM_NEXT_OPCODE();
3416}
3417
3418ZEND_VM_HANDLER(118, ZEND_INIT_USER_CALL, CONST, CONST|TMPVAR|CV)
3419{
3420    USE_OPLINE
3421    zend_free_op free_op2;
3422    zval *function_name;
3423    zend_fcall_info_cache fcc;
3424    char *error = NULL;
3425    zend_function *func;
3426    zend_class_entry *called_scope;
3427    zend_object *object;
3428    zend_execute_data *call;
3429    uint32_t call_info = ZEND_CALL_NESTED_FUNCTION;
3430
3431    SAVE_OPLINE();
3432    function_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
3433    if (zend_is_callable_ex(function_name, NULL, 0, NULL, &fcc, &error)) {
3434        func = fcc.function_handler;
3435        if (func->common.fn_flags & ZEND_ACC_CLOSURE) {
3436            /* Delay closure destruction until its invocation */
3437            if (OP2_TYPE & (IS_VAR|IS_CV)) {
3438                ZVAL_DEREF(function_name);
3439            }
3440            ZEND_ASSERT(GC_TYPE(func->common.prototype) == IS_OBJECT);
3441            GC_REFCOUNT(func->common.prototype)++;
3442            call_info |= ZEND_CALL_CLOSURE;
3443        }
3444        called_scope = fcc.called_scope;
3445        object = fcc.object;
3446        if (object) {
3447            call_info |= ZEND_CALL_RELEASE_THIS;
3448            GC_REFCOUNT(object)++; /* For $this pointer */
3449        }
3450        if (error) {
3451            efree(error);
3452            /* This is the only soft error is_callable() can generate */
3453            zend_error(E_DEPRECATED,
3454                "Non-static method %s::%s() should not be called statically",
3455                ZSTR_VAL(func->common.scope->name), ZSTR_VAL(func->common.function_name));
3456        }
3457    } else {
3458        zend_internal_type_error(EX_USES_STRICT_TYPES(), "%s() expects parameter 1 to be a valid callback, %s", Z_STRVAL_P(EX_CONSTANT(opline->op1)), error);
3459        efree(error);
3460        func = (zend_function*)&zend_pass_function;
3461        called_scope = NULL;
3462        object = NULL;
3463    }
3464
3465    call = zend_vm_stack_push_call_frame(call_info,
3466        func, opline->extended_value, called_scope, object);
3467    call->prev_execute_data = EX(call);
3468    EX(call) = call;
3469
3470    FREE_OP2();
3471    CHECK_EXCEPTION();
3472    ZEND_VM_NEXT_OPCODE();
3473}
3474
3475ZEND_VM_HANDLER(69, ZEND_INIT_NS_FCALL_BY_NAME, ANY, CONST)
3476{
3477    USE_OPLINE
3478    zval *func_name;
3479    zval *func;
3480    zend_function *fbc;
3481    zend_execute_data *call;
3482
3483    func_name = EX_CONSTANT(opline->op2) + 1;
3484    if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) {
3485        fbc = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
3486    } else if ((func = zend_hash_find(EG(function_table), Z_STR_P(func_name))) == NULL) {
3487        func_name++;
3488        if (UNEXPECTED((func = zend_hash_find(EG(function_table), Z_STR_P(func_name))) == NULL)) {
3489            SAVE_OPLINE();
3490            zend_throw_error(zend_ce_error, "Call to undefined function %s()", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
3491            HANDLE_EXCEPTION();
3492        } else {
3493            fbc = Z_FUNC_P(func);
3494            CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), fbc);
3495        }
3496    } else {
3497        fbc = Z_FUNC_P(func);
3498        CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), fbc);
3499    }
3500
3501    call = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
3502        fbc, opline->extended_value, NULL, NULL);
3503    call->prev_execute_data = EX(call);
3504    EX(call) = call;
3505
3506    ZEND_VM_NEXT_OPCODE();
3507}
3508
3509ZEND_VM_HANDLER(61, ZEND_INIT_FCALL, ANY, CONST)
3510{
3511    USE_OPLINE
3512    zend_free_op free_op2;
3513    zval *fname = GET_OP2_ZVAL_PTR(BP_VAR_R);
3514    zval *func;
3515    zend_function *fbc;
3516    zend_execute_data *call;
3517
3518    if (CACHED_PTR(Z_CACHE_SLOT_P(fname))) {
3519        fbc = CACHED_PTR(Z_CACHE_SLOT_P(fname));
3520    } else if (UNEXPECTED((func = zend_hash_find(EG(function_table), Z_STR_P(fname))) == NULL)) {
3521        SAVE_OPLINE();
3522        zend_throw_error(zend_ce_error, "Call to undefined function %s()", Z_STRVAL_P(fname));
3523        HANDLE_EXCEPTION();
3524    } else {
3525        fbc = Z_FUNC_P(func);
3526        CACHE_PTR(Z_CACHE_SLOT_P(fname), fbc);
3527    }
3528
3529    call = zend_vm_stack_push_call_frame_ex(
3530        opline->op1.num, ZEND_CALL_NESTED_FUNCTION,
3531        fbc, opline->extended_value, NULL, NULL);
3532    call->prev_execute_data = EX(call);
3533    EX(call) = call;
3534
3535    ZEND_VM_NEXT_OPCODE();
3536}
3537
3538ZEND_VM_HANDLER(129, ZEND_DO_ICALL, ANY, ANY)
3539{
3540    USE_OPLINE
3541    zend_execute_data *call = EX(call);
3542    zend_function *fbc = call->func;
3543    zval *ret;
3544
3545    SAVE_OPLINE();
3546    EX(call) = call->prev_execute_data;
3547
3548    call->prev_execute_data = execute_data;
3549    EG(current_execute_data) = call;
3550
3551    ret = EX_VAR(opline->result.var);
3552    ZVAL_NULL(ret);
3553    Z_VAR_FLAGS_P(ret) = 0;
3554
3555    fbc->internal_function.handler(call, ret);
3556
3557#if ZEND_DEBUG
3558    ZEND_ASSERT(
3559        !call->func ||
3560        !(call->func->common.fn_flags & ZEND_ACC_HAS_RETURN_TYPE) ||
3561        zend_verify_internal_return_type(call->func, EX_VAR(opline->result.var)));
3562#endif
3563
3564    EG(current_execute_data) = call->prev_execute_data;
3565    zend_vm_stack_free_args(call);
3566    zend_vm_stack_free_call_frame(call);
3567
3568    if (!RETURN_VALUE_USED(opline)) {
3569        zval_ptr_dtor(EX_VAR(opline->result.var));
3570    }
3571
3572    if (UNEXPECTED(EG(exception) != NULL)) {
3573        zend_throw_exception_internal(NULL);
3574        if (RETURN_VALUE_USED(opline)) {
3575            zval_ptr_dtor(EX_VAR(opline->result.var));
3576        }
3577        HANDLE_EXCEPTION();
3578    }
3579
3580    ZEND_VM_INTERRUPT_CHECK();
3581    ZEND_VM_NEXT_OPCODE();
3582}
3583
3584ZEND_VM_HANDLER(130, ZEND_DO_UCALL, ANY, ANY)
3585{
3586    USE_OPLINE
3587    zend_execute_data *call = EX(call);
3588    zend_function *fbc = call->func;
3589    zval *ret;
3590
3591    SAVE_OPLINE();
3592    EX(call) = call->prev_execute_data;
3593
3594    EG(scope) = NULL;
3595    ret = NULL;
3596    call->symbol_table = NULL;
3597    if (RETURN_VALUE_USED(opline)) {
3598        ret = EX_VAR(opline->result.var);
3599        ZVAL_NULL(ret);
3600        Z_VAR_FLAGS_P(ret) = 0;
3601    }
3602
3603    call->prev_execute_data = execute_data;
3604    i_init_func_execute_data(call, &fbc->op_array, ret, 0);
3605
3606    ZEND_VM_ENTER();
3607}
3608
3609ZEND_VM_HANDLER(131, ZEND_DO_FCALL_BY_NAME, ANY, ANY)
3610{
3611    USE_OPLINE
3612    zend_execute_data *call = EX(call);
3613    zend_function *fbc = call->func;
3614    zval *ret;
3615
3616    SAVE_OPLINE();
3617    EX(call) = call->prev_execute_data;
3618
3619    if (EXPECTED(fbc->type == ZEND_USER_FUNCTION)) {
3620        EG(scope) = NULL;
3621        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_GENERATOR) != 0)) {
3622            if (EXPECTED(RETURN_VALUE_USED(opline))) {
3623                ret = EX_VAR(opline->result.var);
3624                zend_generator_create_zval(call, &fbc->op_array, ret);
3625                Z_VAR_FLAGS_P(ret) = 0;
3626            } else {
3627                zend_vm_stack_free_args(call);
3628            }
3629
3630            zend_vm_stack_free_call_frame(call);
3631        } else {
3632            ret = NULL;
3633            call->symbol_table = NULL;
3634            if (RETURN_VALUE_USED(opline)) {
3635                ret = EX_VAR(opline->result.var);
3636                ZVAL_NULL(ret);
3637                Z_VAR_FLAGS_P(ret) = 0;
3638            }
3639
3640            call->prev_execute_data = execute_data;
3641            i_init_func_execute_data(call, &fbc->op_array, ret, 0);
3642
3643            ZEND_VM_ENTER();
3644        }
3645        EG(scope) = EX(func)->op_array.scope;
3646    } else {
3647        ZEND_ASSERT(fbc->type == ZEND_INTERNAL_FUNCTION);
3648
3649        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_DEPRECATED) != 0)) {
3650            zend_error(E_DEPRECATED, "Function %s%s%s() is deprecated",
3651                fbc->common.scope ? ZSTR_VAL(fbc->common.scope->name) : "",
3652                fbc->common.scope ? "::" : "",
3653                ZSTR_VAL(fbc->common.function_name));
3654            if (UNEXPECTED(EG(exception) != NULL)) {
3655                HANDLE_EXCEPTION();
3656            }
3657        }
3658
3659        call->prev_execute_data = execute_data;
3660        EG(current_execute_data) = call;
3661
3662        if (fbc->common.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) {
3663            uint32_t i;
3664            uint32_t num_args = ZEND_CALL_NUM_ARGS(call);
3665            zval *p = ZEND_CALL_ARG(call, 1);
3666
3667            for (i = 0; i < num_args; ++i) {
3668                zend_verify_internal_arg_type(fbc, i + 1, p);
3669                p++;
3670            }
3671            if (UNEXPECTED(EG(exception) != NULL)) {
3672                EG(current_execute_data) = call->prev_execute_data;
3673                zend_vm_stack_free_args(call);
3674                zend_vm_stack_free_call_frame(call);
3675                zend_throw_exception_internal(NULL);
3676                HANDLE_EXCEPTION();
3677            }
3678        }
3679
3680        ret = EX_VAR(opline->result.var);
3681        ZVAL_NULL(ret);
3682        Z_VAR_FLAGS_P(ret) = (fbc->common.fn_flags & ZEND_ACC_RETURN_REFERENCE) != 0 ? IS_VAR_RET_REF : 0;
3683
3684        fbc->internal_function.handler(call, ret);
3685
3686#if ZEND_DEBUG
3687        ZEND_ASSERT(
3688            !call->func ||
3689            !(call->func->common.fn_flags & ZEND_ACC_HAS_RETURN_TYPE) ||
3690            zend_verify_internal_return_type(call->func, EX_VAR(opline->result.var)));
3691#endif
3692
3693        EG(current_execute_data) = call->prev_execute_data;
3694        zend_vm_stack_free_args(call);
3695        zend_vm_stack_free_call_frame(call);
3696
3697        if (!RETURN_VALUE_USED(opline)) {
3698            zval_ptr_dtor(EX_VAR(opline->result.var));
3699        }
3700    }
3701
3702    if (UNEXPECTED(EG(exception) != NULL)) {
3703        zend_throw_exception_internal(NULL);
3704        if (RETURN_VALUE_USED(opline)) {
3705            zval_ptr_dtor(EX_VAR(opline->result.var));
3706        }
3707        HANDLE_EXCEPTION();
3708    }
3709    ZEND_VM_INTERRUPT_CHECK();
3710    ZEND_VM_NEXT_OPCODE();
3711}
3712
3713ZEND_VM_HANDLER(60, ZEND_DO_FCALL, ANY, ANY)
3714{
3715    USE_OPLINE
3716    zend_execute_data *call = EX(call);
3717    zend_function *fbc = call->func;
3718    zend_object *object;
3719    zval *ret;
3720
3721    SAVE_OPLINE();
3722    EX(call) = call->prev_execute_data;
3723    if (UNEXPECTED((fbc->common.fn_flags & (ZEND_ACC_ABSTRACT|ZEND_ACC_DEPRECATED)) != 0)) {
3724        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_ABSTRACT) != 0)) {
3725            zend_throw_error(zend_ce_error, "Cannot call abstract method %s::%s()", ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3726            HANDLE_EXCEPTION();
3727        }
3728        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_DEPRECATED) != 0)) {
3729            zend_error(E_DEPRECATED, "Function %s%s%s() is deprecated",
3730                fbc->common.scope ? ZSTR_VAL(fbc->common.scope->name) : "",
3731                fbc->common.scope ? "::" : "",
3732                ZSTR_VAL(fbc->common.function_name));
3733            if (UNEXPECTED(EG(exception) != NULL)) {
3734                HANDLE_EXCEPTION();
3735            }
3736        }
3737    }
3738
3739    LOAD_OPLINE();
3740
3741    if (EXPECTED(fbc->type == ZEND_USER_FUNCTION)) {
3742        EG(scope) = fbc->common.scope;
3743        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_GENERATOR) != 0)) {
3744            if (EXPECTED(RETURN_VALUE_USED(opline))) {
3745                ret = EX_VAR(opline->result.var);
3746                zend_generator_create_zval(call, &fbc->op_array, ret);
3747                Z_VAR_FLAGS_P(ret) = 0;
3748            } else {
3749                if (UNEXPECTED(ZEND_CALL_INFO(call) & ZEND_CALL_CLOSURE)) {
3750                    OBJ_RELEASE((zend_object*)fbc->op_array.prototype);
3751                }
3752                zend_vm_stack_free_args(call);
3753            }
3754        } else {
3755            ret = NULL;
3756            call->symbol_table = NULL;
3757            if (RETURN_VALUE_USED(opline)) {
3758                ret = EX_VAR(opline->result.var);
3759                ZVAL_NULL(ret);
3760                Z_VAR_FLAGS_P(ret) = 0;
3761            }
3762
3763            call->prev_execute_data = execute_data;
3764            i_init_func_execute_data(call, &fbc->op_array, ret, 1);
3765
3766            if (EXPECTED(zend_execute_ex == execute_ex)) {
3767                ZEND_VM_ENTER();
3768            } else {
3769                ZEND_ADD_CALL_FLAG(call, ZEND_CALL_TOP);
3770                zend_execute_ex(call);
3771            }
3772        }
3773    } else if (EXPECTED(fbc->type < ZEND_USER_FUNCTION)) {
3774        int should_change_scope = 0;
3775
3776        if (fbc->common.scope) {
3777            should_change_scope = 1;
3778            EG(scope) = fbc->common.scope;
3779        }
3780
3781        call->prev_execute_data = execute_data;
3782        EG(current_execute_data) = call;
3783
3784        if (fbc->common.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) {
3785            uint32_t i;
3786            uint32_t num_args = ZEND_CALL_NUM_ARGS(call);
3787            zval *p = ZEND_CALL_ARG(call, 1);
3788
3789            for (i = 0; i < num_args; ++i) {
3790                zend_verify_internal_arg_type(fbc, i + 1, p);
3791                if (UNEXPECTED(EG(exception) != NULL)) {
3792                    EG(current_execute_data) = call->prev_execute_data;
3793                    zend_vm_stack_free_args(call);
3794                    if (RETURN_VALUE_USED(opline)) {
3795                        ZVAL_UNDEF(EX_VAR(opline->result.var));
3796                    }
3797                    if (UNEXPECTED(should_change_scope)) {
3798                        ZEND_VM_C_GOTO(fcall_end_change_scope);
3799                    } else {
3800                        ZEND_VM_C_GOTO(fcall_end);
3801                    }
3802                }
3803                p++;
3804            }
3805        }
3806
3807        ret = EX_VAR(opline->result.var);
3808        ZVAL_NULL(ret);
3809        Z_VAR_FLAGS_P(ret) = (fbc->common.fn_flags & ZEND_ACC_RETURN_REFERENCE) != 0 ? IS_VAR_RET_REF : 0;
3810
3811        if (!zend_execute_internal) {
3812            /* saves one function call if zend_execute_internal is not used */
3813            fbc->internal_function.handler(call, ret);
3814        } else {
3815            zend_execute_internal(call, ret);
3816        }
3817
3818#if ZEND_DEBUG
3819        ZEND_ASSERT(
3820            !call->func ||
3821            !(call->func->common.fn_flags & ZEND_ACC_HAS_RETURN_TYPE) ||
3822            zend_verify_internal_return_type(call->func, EX_VAR(opline->result.var)));
3823#endif
3824
3825        EG(current_execute_data) = call->prev_execute_data;
3826        zend_vm_stack_free_args(call);
3827
3828        if (!RETURN_VALUE_USED(opline)) {
3829            zval_ptr_dtor(EX_VAR(opline->result.var));
3830        }
3831
3832        if (UNEXPECTED(should_change_scope)) {
3833            ZEND_VM_C_GOTO(fcall_end_change_scope);
3834        } else {
3835            ZEND_VM_C_GOTO(fcall_end);
3836        }
3837    } else { /* ZEND_OVERLOADED_FUNCTION */
3838        EG(scope) = fbc->common.scope;
3839
3840        ZVAL_NULL(EX_VAR(opline->result.var));
3841
3842        /* Not sure what should be done here if it's a static method */
3843        object = Z_OBJ(call->This);
3844        if (EXPECTED(object != NULL)) {
3845            call->prev_execute_data = execute_data;
3846            EG(current_execute_data) = call;
3847            object->handlers->call_method(fbc->common.function_name, object, call, EX_VAR(opline->result.var));
3848            EG(current_execute_data) = call->prev_execute_data;
3849        } else {
3850            zend_throw_error(zend_ce_error, "Cannot call overloaded function for non-object");
3851#if 0
3852            //TODO: implement clean exit ???
3853            zend_vm_stack_free_args(call);
3854
3855            zend_vm_stack_free_call_frame(call);
3856
3857            if (fbc->type == ZEND_OVERLOADED_FUNCTION_TEMPORARY) {
3858                zend_string_release(fbc->common.function_name);
3859            }
3860            efree(fbc);
3861#endif
3862            HANDLE_EXCEPTION();
3863        }
3864
3865        zend_vm_stack_free_args(call);
3866
3867        if (fbc->type == ZEND_OVERLOADED_FUNCTION_TEMPORARY) {
3868            zend_string_release(fbc->common.function_name);
3869        }
3870        efree(fbc);
3871
3872        if (!RETURN_VALUE_USED(opline)) {
3873            zval_ptr_dtor(EX_VAR(opline->result.var));
3874        } else {
3875            Z_VAR_FLAGS_P(EX_VAR(opline->result.var)) = 0;
3876        }
3877    }
3878
3879ZEND_VM_C_LABEL(fcall_end_change_scope):
3880    if (UNEXPECTED(ZEND_CALL_INFO(call) & ZEND_CALL_RELEASE_THIS)) {
3881        object = Z_OBJ(call->This);
3882#if 0
3883        if (UNEXPECTED(EG(exception) != NULL) && (opline->op1.num & ZEND_CALL_CTOR)) {
3884            if (!(opline->op1.num & ZEND_CALL_CTOR_RESULT_UNUSED)) {
3885#else
3886        if (UNEXPECTED(EG(exception) != NULL) && (ZEND_CALL_INFO(call) & ZEND_CALL_CTOR)) {
3887            if (!(ZEND_CALL_INFO(call) & ZEND_CALL_CTOR_RESULT_UNUSED)) {
3888#endif
3889                GC_REFCOUNT(object)--;
3890            }
3891            if (GC_REFCOUNT(object) == 1) {
3892                zend_object_store_ctor_failed(object);
3893            }
3894        }
3895        OBJ_RELEASE(object);
3896    }
3897    EG(scope) = EX(func)->op_array.scope;
3898
3899ZEND_VM_C_LABEL(fcall_end):
3900    zend_vm_stack_free_call_frame(call);
3901    if (UNEXPECTED(EG(exception) != NULL)) {
3902        zend_throw_exception_internal(NULL);
3903        if (RETURN_VALUE_USED(opline)) {
3904            zval_ptr_dtor(EX_VAR(opline->result.var));
3905        }
3906        HANDLE_EXCEPTION();
3907    }
3908
3909    ZEND_VM_INTERRUPT_CHECK();
3910    ZEND_VM_NEXT_OPCODE();
3911}
3912
3913ZEND_VM_HANDLER(124, ZEND_VERIFY_RETURN_TYPE, CONST|TMP|VAR|UNUSED|CV, UNUSED)
3914{
3915    USE_OPLINE
3916
3917    SAVE_OPLINE();
3918    if (OP1_TYPE == IS_UNUSED) {
3919        zend_verify_missing_return_type(EX(func), CACHE_ADDR(opline->op2.num));
3920    } else {
3921/* prevents "undefined variable opline" errors */
3922#if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
3923        zval *retval_ref, *retval_ptr;
3924        zend_free_op free_op1;
3925        zend_arg_info *ret_info = EX(func)->common.arg_info - 1;
3926
3927        retval_ref = retval_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
3928
3929        if (OP1_TYPE == IS_CONST) {
3930            ZVAL_COPY(EX_VAR(opline->result.var), retval_ptr);
3931            retval_ref = retval_ptr = EX_VAR(opline->result.var);
3932        } else if (OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) {
3933            ZVAL_DEREF(retval_ptr);
3934        }
3935
3936        if (UNEXPECTED(!ret_info->class_name
3937            && ret_info->type_hint != IS_CALLABLE
3938            && !ZEND_SAME_FAKE_TYPE(ret_info->type_hint, Z_TYPE_P(retval_ptr))
3939            && !(EX(func)->op_array.fn_flags & ZEND_ACC_RETURN_REFERENCE)
3940            && retval_ref != retval_ptr)
3941        ) {
3942            /* A cast might happen - unwrap the reference if this is a by-value return */
3943            if (Z_REFCOUNT_P(retval_ref) == 1) {
3944                ZVAL_UNREF(retval_ref);
3945            } else {
3946                Z_DELREF_P(retval_ref);
3947                ZVAL_COPY(retval_ref, retval_ptr);
3948            }
3949            retval_ptr = retval_ref;
3950        }
3951        zend_verify_return_type(EX(func), retval_ptr, CACHE_ADDR(opline->op2.num));
3952
3953        if (UNEXPECTED(EG(exception) != NULL)) {
3954            FREE_OP1();
3955        }
3956#endif
3957    }
3958    CHECK_EXCEPTION();
3959    ZEND_VM_NEXT_OPCODE();
3960}
3961
3962ZEND_VM_HANDLER(62, ZEND_RETURN, CONST|TMP|VAR|CV, ANY)
3963{
3964    USE_OPLINE
3965    zval *retval_ptr;
3966    zend_free_op free_op1;
3967
3968    retval_ptr = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
3969    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(retval_ptr) == IS_UNDEF)) {
3970        SAVE_OPLINE();
3971        retval_ptr = GET_OP1_UNDEF_CV(retval_ptr, BP_VAR_R);
3972        if (EX(return_value)) {
3973            ZVAL_NULL(EX(return_value));
3974        }
3975    } else if (!EX(return_value)) {
3976        if (OP1_TYPE == IS_VAR || OP1_TYPE == IS_TMP_VAR ) {
3977            if (Z_REFCOUNTED_P(free_op1) && !Z_DELREF_P(free_op1)) {
3978                SAVE_OPLINE();
3979                zval_dtor_func_for_ptr(Z_COUNTED_P(free_op1));
3980            }
3981        }
3982    } else {
3983        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
3984            ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
3985            if (OP1_TYPE == IS_CONST) {
3986                if (UNEXPECTED(Z_OPT_COPYABLE_P(EX(return_value)))) {
3987                    zval_copy_ctor_func(EX(return_value));
3988                }
3989            }
3990        } else if (OP1_TYPE == IS_CV) {
3991            ZVAL_DEREF(retval_ptr);
3992            ZVAL_COPY(EX(return_value), retval_ptr);
3993        } else /* if (OP1_TYPE == IS_VAR) */ {
3994            if (UNEXPECTED(Z_ISREF_P(retval_ptr))) {
3995                zend_refcounted *ref = Z_COUNTED_P(retval_ptr);
3996
3997                retval_ptr = Z_REFVAL_P(retval_ptr);
3998                ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
3999                if (UNEXPECTED(--GC_REFCOUNT(ref) == 0)) {
4000                    efree_size(ref, sizeof(zend_reference));
4001                } else if (Z_OPT_REFCOUNTED_P(retval_ptr)) {
4002                    Z_ADDREF_P(retval_ptr);
4003                }
4004            } else {
4005                ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
4006            }
4007        }
4008    }
4009    ZEND_VM_DISPATCH_TO_HELPER(zend_leave_helper);
4010}
4011
4012ZEND_VM_HANDLER(111, ZEND_RETURN_BY_REF, CONST|TMP|VAR|CV, ANY)
4013{
4014    USE_OPLINE
4015    zval *retval_ptr;
4016    zend_free_op free_op1;
4017
4018    SAVE_OPLINE();
4019
4020    do {
4021        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR ||
4022            (OP1_TYPE == IS_VAR && opline->extended_value == ZEND_RETURNS_VALUE)) {
4023            /* Not supposed to happen, but we'll allow it */
4024            zend_error(E_NOTICE, "Only variable references should be returned by reference");
4025
4026            retval_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
4027            if (!EX(return_value)) {
4028                if (OP1_TYPE == IS_TMP_VAR) {
4029                    FREE_OP1();
4030                }
4031            } else {
4032                ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
4033                Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
4034                if (OP1_TYPE != IS_TMP_VAR) {
4035                    zval_opt_copy_ctor_no_imm(EX(return_value));
4036                }
4037            }
4038            break;
4039        }
4040
4041        retval_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
4042
4043        if (OP1_TYPE == IS_VAR && UNEXPECTED(retval_ptr == NULL)) {
4044            zend_throw_error(zend_ce_error, "Cannot return string offsets by reference");
4045            HANDLE_EXCEPTION();
4046        }
4047
4048        if (OP1_TYPE == IS_VAR) {
4049            if (retval_ptr == &EG(uninitialized_zval) ||
4050                (opline->extended_value == ZEND_RETURNS_FUNCTION &&
4051                 !(Z_VAR_FLAGS_P(retval_ptr) & IS_VAR_RET_REF))) {
4052                zend_error(E_NOTICE, "Only variable references should be returned by reference");
4053                if (EX(return_value)) {
4054                    ZVAL_NEW_REF(EX(return_value), retval_ptr);
4055                    Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
4056                    if (Z_REFCOUNTED_P(retval_ptr)) Z_ADDREF_P(retval_ptr);
4057                }
4058                break;
4059            }
4060        }
4061
4062        if (EX(return_value)) {
4063            ZVAL_MAKE_REF(retval_ptr);
4064            Z_ADDREF_P(retval_ptr);
4065            ZVAL_REF(EX(return_value), Z_REF_P(retval_ptr));
4066            Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
4067        }
4068    } while (0);
4069
4070    FREE_OP1_VAR_PTR();
4071    ZEND_VM_DISPATCH_TO_HELPER(zend_leave_helper);
4072}
4073
4074ZEND_VM_HANDLER(161, ZEND_GENERATOR_RETURN, CONST|TMP|VAR|CV, ANY)
4075{
4076    USE_OPLINE
4077    zval *retval;
4078    zend_free_op free_op1;
4079
4080    zend_generator *generator = zend_get_running_generator(execute_data);
4081
4082    SAVE_OPLINE();
4083    retval = GET_OP1_ZVAL_PTR(BP_VAR_R);
4084
4085    /* Copy return value into generator->retval */
4086    if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
4087        ZVAL_COPY_VALUE(&generator->retval, retval);
4088        if (OP1_TYPE == IS_CONST) {
4089            if (UNEXPECTED(Z_OPT_COPYABLE(generator->retval))) {
4090                zval_copy_ctor_func(&generator->retval);
4091            }
4092        }
4093    } else if (OP1_TYPE == IS_CV) {
4094        ZVAL_DEREF(retval);
4095        ZVAL_COPY(&generator->retval, retval);
4096    } else /* if (OP1_TYPE == IS_VAR) */ {
4097        if (UNEXPECTED(Z_ISREF_P(retval))) {
4098            zend_refcounted *ref = Z_COUNTED_P(retval);
4099
4100            retval = Z_REFVAL_P(retval);
4101            ZVAL_COPY_VALUE(&generator->retval, retval);
4102            if (UNEXPECTED(--GC_REFCOUNT(ref) == 0)) {
4103                efree_size(ref, sizeof(zend_reference));
4104            } else if (Z_OPT_REFCOUNTED_P(retval)) {
4105                Z_ADDREF_P(retval);
4106            }
4107        } else {
4108            ZVAL_COPY_VALUE(&generator->retval, retval);
4109        }
4110    }
4111
4112    /* Close the generator to free up resources */
4113    zend_generator_close(generator, 1);
4114
4115    /* Pass execution back to handling code */
4116    ZEND_VM_RETURN();
4117}
4118
4119ZEND_VM_HANDLER(108, ZEND_THROW, CONST|TMP|VAR|CV, ANY)
4120{
4121    USE_OPLINE
4122    zval *value;
4123    zend_free_op free_op1;
4124
4125    SAVE_OPLINE();
4126    value = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4127
4128    do {
4129        if (OP1_TYPE == IS_CONST || UNEXPECTED(Z_TYPE_P(value) != IS_OBJECT)) {
4130            if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(value)) {
4131                value = Z_REFVAL_P(value);
4132                if (EXPECTED(Z_TYPE_P(value) == IS_OBJECT)) {
4133                    break;
4134                }
4135            }
4136            if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
4137                GET_OP1_UNDEF_CV(value, BP_VAR_R);
4138            }
4139            if (UNEXPECTED(EG(exception) != NULL)) {
4140                HANDLE_EXCEPTION();
4141            }
4142            zend_throw_error(zend_ce_error, "Can only throw objects");
4143            FREE_OP1();
4144            HANDLE_EXCEPTION();
4145        }
4146    } while (0);
4147
4148    zend_exception_save();
4149    if (OP1_TYPE != IS_TMP_VAR) {
4150        if (Z_REFCOUNTED_P(value)) Z_ADDREF_P(value);
4151    }
4152
4153    zend_throw_exception_object(value);
4154    zend_exception_restore();
4155    FREE_OP1_IF_VAR();
4156    HANDLE_EXCEPTION();
4157}
4158
4159ZEND_VM_HANDLER(107, ZEND_CATCH, CONST, CV)
4160{
4161    USE_OPLINE
4162    zend_class_entry *ce, *catch_ce;
4163    zend_object *exception;
4164
4165    SAVE_OPLINE();
4166    /* Check whether an exception has been thrown, if not, jump over code */
4167    zend_exception_restore();
4168    if (EG(exception) == NULL) {
4169        ZEND_VM_SET_OPCODE(&EX(func)->op_array.opcodes[opline->extended_value]);
4170        ZEND_VM_CONTINUE(); /* CHECK_ME */
4171    }
4172    if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)))) {
4173        catch_ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
4174    } else {
4175        catch_ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, ZEND_FETCH_CLASS_NO_AUTOLOAD);
4176
4177        CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), catch_ce);
4178    }
4179    ce = EG(exception)->ce;
4180
4181#ifdef HAVE_DTRACE
4182    if (DTRACE_EXCEPTION_CAUGHT_ENABLED()) {
4183        DTRACE_EXCEPTION_CAUGHT((char *)ce->name);
4184    }
4185#endif /* HAVE_DTRACE */
4186
4187    if (ce != catch_ce) {
4188        if (!catch_ce || !instanceof_function(ce, catch_ce)) {
4189            if (opline->result.num) {
4190                zend_throw_exception_internal(NULL);
4191                HANDLE_EXCEPTION();
4192            }
4193            ZEND_VM_SET_OPCODE(&EX(func)->op_array.opcodes[opline->extended_value]);
4194            ZEND_VM_CONTINUE(); /* CHECK_ME */
4195        }
4196    }
4197
4198    exception = EG(exception);
4199    zval_ptr_dtor(EX_VAR(opline->op2.var));
4200    ZVAL_OBJ(EX_VAR(opline->op2.var), EG(exception));
4201    if (UNEXPECTED(EG(exception) != exception)) {
4202        GC_REFCOUNT(EG(exception))++;
4203        HANDLE_EXCEPTION();
4204    } else {
4205        EG(exception) = NULL;
4206        ZEND_VM_NEXT_OPCODE();
4207    }
4208}
4209
4210ZEND_VM_HANDLER(65, ZEND_SEND_VAL, CONST|TMP, ANY)
4211{
4212    USE_OPLINE
4213    zval *value, *arg;
4214    zend_free_op free_op1;
4215
4216    value = GET_OP1_ZVAL_PTR(BP_VAR_R);
4217    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4218    ZVAL_COPY_VALUE(arg, value);
4219    if (OP1_TYPE == IS_CONST) {
4220        if (UNEXPECTED(Z_OPT_COPYABLE_P(arg))) {
4221            zval_copy_ctor_func(arg);
4222        }
4223    }
4224    ZEND_VM_NEXT_OPCODE();
4225}
4226
4227ZEND_VM_HANDLER(116, ZEND_SEND_VAL_EX, CONST|TMP, ANY)
4228{
4229    USE_OPLINE
4230    zval *value, *arg;
4231    zend_free_op free_op1;
4232
4233    if (EXPECTED(opline->op2.num <= MAX_ARG_FLAG_NUM)) {
4234        if (QUICK_ARG_MUST_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4235            ZEND_VM_C_GOTO(send_val_by_ref);
4236        }
4237    } else if (ARG_MUST_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4238ZEND_VM_C_LABEL(send_val_by_ref):
4239        SAVE_OPLINE();
4240        zend_throw_error(zend_ce_error, "Cannot pass parameter %d by reference", opline->op2.num);
4241        FREE_UNFETCHED_OP1();
4242        arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4243        ZVAL_UNDEF(arg);
4244        HANDLE_EXCEPTION();
4245    }
4246    value = GET_OP1_ZVAL_PTR(BP_VAR_R);
4247    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4248    ZVAL_COPY_VALUE(arg, value);
4249    if (OP1_TYPE == IS_CONST) {
4250        if (UNEXPECTED(Z_OPT_COPYABLE_P(arg))) {
4251            zval_copy_ctor_func(arg);
4252        }
4253    }
4254    ZEND_VM_NEXT_OPCODE();
4255}
4256
4257ZEND_VM_HANDLER(117, ZEND_SEND_VAR, VAR|CV, ANY)
4258{
4259    USE_OPLINE
4260    zval *varptr, *arg;
4261    zend_free_op free_op1;
4262
4263    varptr = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4264    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(varptr) == IS_UNDEF)) {
4265        SAVE_OPLINE();
4266        varptr = GET_OP1_UNDEF_CV(varptr, BP_VAR_R);
4267        CHECK_EXCEPTION();
4268    }
4269    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4270
4271    if (OP1_TYPE == IS_CV) {
4272        ZVAL_DEREF(varptr);
4273        ZVAL_COPY(arg, varptr);
4274    } else /* if (OP1_TYPE == IS_VAR) */ {
4275        if (UNEXPECTED(Z_ISREF_P(varptr))) {
4276            zend_refcounted *ref = Z_COUNTED_P(varptr);
4277
4278            varptr = Z_REFVAL_P(varptr);
4279            ZVAL_COPY_VALUE(arg, varptr);
4280            if (UNEXPECTED(--GC_REFCOUNT(ref) == 0)) {
4281                efree_size(ref, sizeof(zend_reference));
4282            } else if (Z_OPT_REFCOUNTED_P(arg)) {
4283                Z_ADDREF_P(arg);
4284            }
4285        } else {
4286            ZVAL_COPY_VALUE(arg, varptr);
4287        }
4288    }
4289
4290    ZEND_VM_NEXT_OPCODE();
4291}
4292
4293ZEND_VM_HANDLER(106, ZEND_SEND_VAR_NO_REF, VAR|CV, ANY)
4294{
4295    USE_OPLINE
4296    zend_free_op free_op1;
4297    zval *varptr, *arg;
4298
4299    if (!(opline->extended_value & ZEND_ARG_COMPILE_TIME_BOUND)) {
4300        if (!ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4301            ZEND_VM_DISPATCH_TO_HANDLER(ZEND_SEND_VAR);
4302        }
4303    }
4304
4305    varptr = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4306    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(varptr) == IS_UNDEF)) {
4307        SAVE_OPLINE();
4308        varptr = GET_OP1_UNDEF_CV(varptr, BP_VAR_R);
4309        CHECK_EXCEPTION();
4310    }
4311    if ((!(opline->extended_value & ZEND_ARG_SEND_FUNCTION) ||
4312         (Z_VAR_FLAGS_P(varptr) & IS_VAR_RET_REF)) &&
4313        (Z_ISREF_P(varptr) || Z_TYPE_P(varptr) == IS_OBJECT)) {
4314
4315        ZVAL_MAKE_REF(varptr);
4316        if (OP1_TYPE == IS_CV) {
4317            Z_ADDREF_P(varptr);
4318        }
4319    } else {
4320        if ((opline->extended_value & ZEND_ARG_COMPILE_TIME_BOUND) ?
4321            !(opline->extended_value & ZEND_ARG_SEND_SILENT) :
4322            !ARG_MAY_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4323            SAVE_OPLINE();
4324            zend_error(E_NOTICE, "Only variables should be passed by reference");
4325            CHECK_EXCEPTION();
4326        }
4327    }
4328
4329    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4330    ZVAL_COPY_VALUE(arg, varptr);
4331
4332    ZEND_VM_NEXT_OPCODE();
4333}
4334
4335ZEND_VM_HANDLER(67, ZEND_SEND_REF, VAR|CV, ANY)
4336{
4337    USE_OPLINE
4338    zend_free_op free_op1;
4339    zval *varptr, *arg;
4340
4341    SAVE_OPLINE();
4342    varptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
4343
4344    if (OP1_TYPE == IS_VAR && UNEXPECTED(varptr == NULL)) {
4345        zend_throw_error(zend_ce_error, "Only variables can be passed by reference");
4346        HANDLE_EXCEPTION();
4347    }
4348
4349    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4350    if (OP1_TYPE == IS_VAR && UNEXPECTED(varptr == &EG(error_zval))) {
4351        ZVAL_NEW_REF(arg, &EG(uninitialized_zval));
4352        ZEND_VM_NEXT_OPCODE();
4353    }
4354
4355    if (Z_ISREF_P(varptr)) {
4356        Z_ADDREF_P(varptr);
4357        ZVAL_COPY_VALUE(arg, varptr);
4358    } else if (OP1_TYPE == IS_VAR &&
4359        UNEXPECTED(Z_TYPE_P(EX_VAR(opline->op1.var)) != IS_INDIRECT)) {
4360        ZVAL_NEW_REF(arg, varptr);
4361    } else {
4362        ZVAL_NEW_REF(arg, varptr);
4363        Z_ADDREF_P(arg);
4364        ZVAL_REF(varptr, Z_REF_P(arg));
4365    }
4366
4367    FREE_OP1_VAR_PTR();
4368    ZEND_VM_NEXT_OPCODE();
4369}
4370
4371ZEND_VM_HANDLER(66, ZEND_SEND_VAR_EX, VAR|CV, ANY)
4372{
4373    USE_OPLINE
4374    zval *varptr, *arg;
4375    zend_free_op free_op1;
4376
4377    if (EXPECTED(opline->op2.num <= MAX_ARG_FLAG_NUM)) {
4378        if (QUICK_ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4379            ZEND_VM_C_GOTO(send_var_by_ref);
4380        }
4381    } else if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4382ZEND_VM_C_LABEL(send_var_by_ref):
4383        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_SEND_REF);
4384    }
4385
4386    varptr = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4387    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(varptr) == IS_UNDEF)) {
4388        SAVE_OPLINE();
4389        varptr = GET_OP1_UNDEF_CV(varptr, BP_VAR_R);
4390        CHECK_EXCEPTION();
4391    }
4392    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4393
4394    if (OP1_TYPE == IS_CV) {
4395        ZVAL_DEREF(varptr);
4396        ZVAL_COPY(arg, varptr);
4397    } else /* if (OP1_TYPE == IS_VAR) */ {
4398        if (UNEXPECTED(Z_ISREF_P(varptr))) {
4399            zend_refcounted *ref = Z_COUNTED_P(varptr);
4400
4401            varptr = Z_REFVAL_P(varptr);
4402            ZVAL_COPY_VALUE(arg, varptr);
4403            if (UNEXPECTED(--GC_REFCOUNT(ref) == 0)) {
4404                efree_size(ref, sizeof(zend_reference));
4405            } else if (Z_OPT_REFCOUNTED_P(arg)) {
4406                Z_ADDREF_P(arg);
4407            }
4408        } else {
4409            ZVAL_COPY_VALUE(arg, varptr);
4410        }
4411    }
4412
4413    ZEND_VM_NEXT_OPCODE();
4414}
4415
4416ZEND_VM_HANDLER(165, ZEND_SEND_UNPACK, ANY, ANY)
4417{
4418    USE_OPLINE
4419    zend_free_op free_op1;
4420    zval *args;
4421    int arg_num;
4422
4423    SAVE_OPLINE();
4424    args = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4425    arg_num = ZEND_CALL_NUM_ARGS(EX(call)) + 1;
4426
4427ZEND_VM_C_LABEL(send_again):
4428    if (EXPECTED(Z_TYPE_P(args) == IS_ARRAY)) {
4429        HashTable *ht = Z_ARRVAL_P(args);
4430        zval *arg, *top;
4431        zend_string *name;
4432
4433        zend_vm_stack_extend_call_frame(&EX(call), arg_num - 1, zend_hash_num_elements(ht));
4434
4435        if (OP1_TYPE != IS_CONST && OP1_TYPE != IS_TMP_VAR && Z_IMMUTABLE_P(args)) {
4436            uint32_t i;
4437            int separate = 0;
4438
4439            /* check if any of arguments are going to be passed by reference */
4440            for (i = 0; i < zend_hash_num_elements(ht); i++) {
4441                if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num + i)) {
4442                    separate = 1;
4443                    break;
4444                }
4445            }
4446            if (separate) {
4447                zval_copy_ctor(args);
4448                ht = Z_ARRVAL_P(args);
4449            }
4450        }
4451
4452        ZEND_HASH_FOREACH_STR_KEY_VAL(ht, name, arg) {
4453            if (name) {
4454                zend_throw_error(zend_ce_error, "Cannot unpack array with string keys");
4455                FREE_OP1();
4456                HANDLE_EXCEPTION();
4457            }
4458
4459            top = ZEND_CALL_ARG(EX(call), arg_num);
4460            if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4461                if (!Z_IMMUTABLE_P(args)) {
4462                    ZVAL_MAKE_REF(arg);
4463                    Z_ADDREF_P(arg);
4464                    ZVAL_REF(top, Z_REF_P(arg));
4465                } else {
4466                    ZVAL_DUP(top, arg);
4467                }
4468            } else if (Z_ISREF_P(arg)) {
4469                ZVAL_COPY(top, Z_REFVAL_P(arg));
4470            } else {
4471                ZVAL_COPY(top, arg);
4472            }
4473
4474            ZEND_CALL_NUM_ARGS(EX(call))++;
4475            arg_num++;
4476        } ZEND_HASH_FOREACH_END();
4477
4478    } else if (EXPECTED(Z_TYPE_P(args) == IS_OBJECT)) {
4479        zend_class_entry *ce = Z_OBJCE_P(args);
4480        zend_object_iterator *iter;
4481
4482        if (!ce || !ce->get_iterator) {
4483            zend_error(E_WARNING, "Only arrays and Traversables can be unpacked");
4484        } else {
4485
4486            iter = ce->get_iterator(ce, args, 0);
4487            if (UNEXPECTED(!iter)) {
4488                FREE_OP1();
4489                if (!EG(exception)) {
4490                    zend_throw_exception_ex(
4491                        NULL, 0, "Object of type %s did not create an Iterator", ZSTR_VAL(ce->name)
4492                    );
4493                }
4494                HANDLE_EXCEPTION();
4495            }
4496
4497            if (iter->funcs->rewind) {
4498                iter->funcs->rewind(iter);
4499                if (UNEXPECTED(EG(exception) != NULL)) {
4500                    ZEND_VM_C_GOTO(unpack_iter_dtor);
4501                }
4502            }
4503
4504            for (; iter->funcs->valid(iter) == SUCCESS; ++arg_num) {
4505                zval *arg, *top;
4506
4507                if (UNEXPECTED(EG(exception) != NULL)) {
4508                    ZEND_VM_C_GOTO(unpack_iter_dtor);
4509                }
4510
4511                arg = iter->funcs->get_current_data(iter);
4512                if (UNEXPECTED(EG(exception) != NULL)) {
4513                    ZEND_VM_C_GOTO(unpack_iter_dtor);
4514                }
4515
4516                if (iter->funcs->get_current_key) {
4517                    zval key;
4518                    iter->funcs->get_current_key(iter, &key);
4519                    if (UNEXPECTED(EG(exception) != NULL)) {
4520                        ZEND_VM_C_GOTO(unpack_iter_dtor);
4521                    }
4522
4523                    if (Z_TYPE(key) == IS_STRING) {
4524                        zend_throw_error(zend_ce_error,
4525                            "Cannot unpack Traversable with string keys");
4526                        zend_string_release(Z_STR(key));
4527                        ZEND_VM_C_GOTO(unpack_iter_dtor);
4528                    }
4529
4530                    zval_dtor(&key);
4531                }
4532
4533                if (ARG_MUST_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4534                    zend_error(
4535                        E_WARNING, "Cannot pass by-reference argument %d of %s%s%s()"
4536                        " by unpacking a Traversable, passing by-value instead", arg_num,
4537                        EX(call)->func->common.scope ? ZSTR_VAL(EX(call)->func->common.scope->name) : "",
4538                        EX(call)->func->common.scope ? "::" : "",
4539                        ZSTR_VAL(EX(call)->func->common.function_name)
4540                    );
4541                }
4542
4543                if (Z_ISREF_P(arg)) {
4544                    ZVAL_DUP(arg, Z_REFVAL_P(arg));
4545                } else {
4546                    if (Z_REFCOUNTED_P(arg)) Z_ADDREF_P(arg);
4547                }
4548
4549                zend_vm_stack_extend_call_frame(&EX(call), arg_num - 1, 1);
4550                top = ZEND_CALL_ARG(EX(call), arg_num);
4551                ZVAL_COPY_VALUE(top, arg);
4552                ZEND_CALL_NUM_ARGS(EX(call))++;
4553
4554                iter->funcs->move_forward(iter);
4555                if (UNEXPECTED(EG(exception) != NULL)) {
4556                    ZEND_VM_C_GOTO(unpack_iter_dtor);
4557                }
4558            }
4559
4560ZEND_VM_C_LABEL(unpack_iter_dtor):
4561            zend_iterator_dtor(iter);
4562        }
4563    } else if (EXPECTED(Z_ISREF_P(args))) {
4564        args = Z_REFVAL_P(args);
4565        ZEND_VM_C_GOTO(send_again);
4566    } else {
4567        if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(args) == IS_UNDEF)) {
4568            GET_OP1_UNDEF_CV(args, BP_VAR_R);
4569        }
4570        zend_error(E_WARNING, "Only arrays and Traversables can be unpacked");
4571    }
4572
4573    FREE_OP1();
4574    CHECK_EXCEPTION();
4575    ZEND_VM_NEXT_OPCODE();
4576}
4577
4578ZEND_VM_HANDLER(119, ZEND_SEND_ARRAY, ANY, ANY)
4579{
4580    USE_OPLINE
4581    zend_free_op free_op1;
4582    zval *args;
4583    SAVE_OPLINE();
4584
4585    SAVE_OPLINE();
4586    args = GET_OP1_ZVAL_PTR(BP_VAR_R);
4587
4588    if (UNEXPECTED(Z_TYPE_P(args) != IS_ARRAY)) {
4589        if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(args)) {
4590            args = Z_REFVAL_P(args);
4591            if (EXPECTED(Z_TYPE_P(args) == IS_ARRAY)) {
4592                ZEND_VM_C_GOTO(send_array);
4593            }
4594        }
4595        zend_internal_type_error(EX_USES_STRICT_TYPES(), "call_user_func_array() expects parameter 2 to be array, %s given", zend_get_type_by_const(Z_TYPE_P(args)));
4596        if (ZEND_CALL_INFO(EX(call)) & ZEND_CALL_CLOSURE) {
4597            OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
4598        }
4599        if (Z_OBJ(EX(call)->This)) {
4600            OBJ_RELEASE(Z_OBJ(EX(call)->This));
4601        }
4602        EX(call)->func = (zend_function*)&zend_pass_function;
4603        EX(call)->called_scope = NULL;
4604        Z_OBJ(EX(call)->This) = NULL;
4605    } else {
4606        uint32_t arg_num;
4607        HashTable *ht;
4608        zval *arg, *param;
4609
4610ZEND_VM_C_LABEL(send_array):
4611        ht = Z_ARRVAL_P(args);
4612        zend_vm_stack_extend_call_frame(&EX(call), 0, zend_hash_num_elements(ht));
4613
4614        if (OP1_TYPE != IS_CONST && OP1_TYPE != IS_TMP_VAR && Z_IMMUTABLE_P(args)) {
4615            int separate = 0;
4616
4617            /* check if any of arguments are going to be passed by reference */
4618            for (arg_num = 0; arg_num < zend_hash_num_elements(ht); arg_num++) {
4619                if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num + 1)) {
4620                    separate = 1;
4621                    break;
4622                }
4623            }
4624            if (separate) {
4625                zval_copy_ctor(args);
4626                ht = Z_ARRVAL_P(args);
4627            }
4628        }
4629
4630        arg_num = 1;
4631        param = ZEND_CALL_ARG(EX(call), 1);
4632        ZEND_HASH_FOREACH_VAL(ht, arg) {
4633            if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4634                if (UNEXPECTED(!Z_ISREF_P(arg))) {
4635                    if (!ARG_MAY_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4636
4637                        zend_error(E_WARNING, "Parameter %d to %s%s%s() expected to be a reference, value given",
4638                            arg_num,
4639                            EX(call)->func->common.scope ? ZSTR_VAL(EX(call)->func->common.scope->name) : "",
4640                            EX(call)->func->common.scope ? "::" : "",
4641                            ZSTR_VAL(EX(call)->func->common.function_name));
4642
4643                        if (ZEND_CALL_INFO(EX(call)) & ZEND_CALL_CLOSURE) {
4644                            OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
4645                        }
4646                        if (Z_OBJ(EX(call)->This)) {
4647                            OBJ_RELEASE(Z_OBJ(EX(call)->This));
4648                        }
4649                        EX(call)->func = (zend_function*)&zend_pass_function;
4650                        EX(call)->called_scope = NULL;
4651                        Z_OBJ(EX(call)->This) = NULL;
4652
4653                        break;
4654                    }
4655
4656                    ZVAL_NEW_REF(arg, arg);
4657                }
4658                Z_ADDREF_P(arg);
4659            } else{
4660                if (Z_ISREF_P(arg) &&
4661                    !(EX(call)->func->common.fn_flags & ZEND_ACC_CALL_VIA_TRAMPOLINE)) {
4662                    /* don't separate references for __call */
4663                    arg = Z_REFVAL_P(arg);
4664                }
4665                if (Z_OPT_REFCOUNTED_P(arg)) {
4666                    Z_ADDREF_P(arg);
4667                }
4668            }
4669            ZVAL_COPY_VALUE(param, arg);
4670            ZEND_CALL_NUM_ARGS(EX(call))++;
4671            arg_num++;
4672            param++;
4673        } ZEND_HASH_FOREACH_END();
4674    }
4675    FREE_OP1();
4676    CHECK_EXCEPTION();
4677    ZEND_VM_NEXT_OPCODE();
4678}
4679
4680ZEND_VM_HANDLER(120, ZEND_SEND_USER, VAR|CV, ANY)
4681{
4682    USE_OPLINE
4683    zval *arg, *param;
4684    zend_free_op free_op1;
4685
4686    SAVE_OPLINE();
4687    arg = GET_OP1_ZVAL_PTR(BP_VAR_R);
4688    param = ZEND_CALL_VAR(EX(call), opline->result.var);
4689
4690    if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4691        if (UNEXPECTED(!Z_ISREF_P(arg))) {
4692
4693            if (!ARG_MAY_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4694
4695                zend_error(E_WARNING, "Parameter %d to %s%s%s() expected to be a reference, value given",
4696                    opline->op2.num,
4697                    EX(call)->func->common.scope ? ZSTR_VAL(EX(call)->func->common.scope->name) : "",
4698                    EX(call)->func->common.scope ? "::" : "",
4699                    ZSTR_VAL(EX(call)->func->common.function_name));
4700
4701                if (ZEND_CALL_INFO(EX(call)) & ZEND_CALL_CLOSURE) {
4702                    OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
4703                }
4704                if (Z_OBJ(EX(call)->This)) {
4705                    OBJ_RELEASE(Z_OBJ(EX(call)->This));
4706                }
4707                ZVAL_UNDEF(param);
4708                EX(call)->func = (zend_function*)&zend_pass_function;
4709                EX(call)->called_scope = NULL;
4710                Z_OBJ(EX(call)->This) = NULL;
4711
4712                FREE_OP1();
4713                CHECK_EXCEPTION();
4714                ZEND_VM_NEXT_OPCODE();
4715            }
4716
4717            ZVAL_NEW_REF(arg, arg);
4718        }
4719        Z_ADDREF_P(arg);
4720    } else {
4721        if (Z_ISREF_P(arg) &&
4722            !(EX(call)->func->common.fn_flags & ZEND_ACC_CALL_VIA_TRAMPOLINE)) {
4723            /* don't separate references for __call */
4724            arg = Z_REFVAL_P(arg);
4725        }
4726        if (Z_OPT_REFCOUNTED_P(arg)) {
4727            Z_ADDREF_P(arg);
4728        }
4729    }
4730    ZVAL_COPY_VALUE(param, arg);
4731
4732    FREE_OP1();
4733    CHECK_EXCEPTION();
4734    ZEND_VM_NEXT_OPCODE();
4735}
4736
4737ZEND_VM_HANDLER(63, ZEND_RECV, ANY, ANY)
4738{
4739    USE_OPLINE
4740    uint32_t arg_num = opline->op1.num;
4741
4742    if (UNEXPECTED(arg_num > EX_NUM_ARGS())) {
4743        SAVE_OPLINE();
4744        if (UNEXPECTED(!zend_verify_missing_arg(execute_data, arg_num, CACHE_ADDR(opline->op2.num)))) {
4745            HANDLE_EXCEPTION();
4746        }
4747    } else if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
4748        zval *param = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var);
4749
4750        SAVE_OPLINE();
4751        if (UNEXPECTED(!zend_verify_arg_type(EX(func), arg_num, param, NULL, CACHE_ADDR(opline->op2.num)))) {
4752            HANDLE_EXCEPTION();
4753        }
4754    }
4755
4756    ZEND_VM_NEXT_OPCODE();
4757}
4758
4759ZEND_VM_HANDLER(64, ZEND_RECV_INIT, ANY, CONST)
4760{
4761    USE_OPLINE
4762    uint32_t arg_num;
4763    zval *param;
4764
4765    ZEND_VM_REPEATABLE_OPCODE
4766
4767    arg_num = opline->op1.num;
4768    param = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var);
4769    if (arg_num > EX_NUM_ARGS()) {
4770        ZVAL_COPY_VALUE(param, EX_CONSTANT(opline->op2));
4771        if (Z_OPT_CONSTANT_P(param)) {
4772            SAVE_OPLINE();
4773            if (UNEXPECTED(zval_update_constant_ex(param, 0, NULL) != SUCCESS)) {
4774                ZVAL_UNDEF(param);
4775                HANDLE_EXCEPTION();
4776            }
4777        } else {
4778            /* IS_CONST can't be IS_OBJECT, IS_RESOURCE or IS_REFERENCE */
4779            if (UNEXPECTED(Z_OPT_COPYABLE_P(param))) {
4780                zval_copy_ctor_func(param);
4781            }
4782        }
4783    }
4784
4785    if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
4786        zval *default_value = EX_CONSTANT(opline->op2);
4787
4788        SAVE_OPLINE();
4789        if (UNEXPECTED(!zend_verify_arg_type(EX(func), arg_num, param, default_value, CACHE_ADDR(Z_CACHE_SLOT_P(default_value))))) {
4790            HANDLE_EXCEPTION();
4791        }
4792    }
4793
4794    ZEND_VM_REPEAT_OPCODE(ZEND_RECV_INIT);
4795    ZEND_VM_NEXT_OPCODE();
4796}
4797
4798ZEND_VM_HANDLER(164, ZEND_RECV_VARIADIC, ANY, ANY)
4799{
4800    USE_OPLINE
4801    uint32_t arg_num = opline->op1.num;
4802    uint32_t arg_count = EX_NUM_ARGS();
4803    zval *params;
4804
4805    SAVE_OPLINE();
4806
4807    params = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var);
4808
4809    if (arg_num <= arg_count) {
4810        zval *param;
4811
4812        array_init_size(params, arg_count - arg_num + 1);
4813        zend_hash_real_init(Z_ARRVAL_P(params), 1);
4814        ZEND_HASH_FILL_PACKED(Z_ARRVAL_P(params)) {
4815            param = EX_VAR_NUM(EX(func)->op_array.last_var + EX(func)->op_array.T);
4816            if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
4817                do {
4818                    zend_verify_arg_type(EX(func), arg_num, param, NULL, CACHE_ADDR(opline->op2.num));
4819                    if (Z_OPT_REFCOUNTED_P(param)) Z_ADDREF_P(param);
4820                    ZEND_HASH_FILL_ADD(param);
4821                    param++;
4822                } while (++arg_num <= arg_count);
4823            } else {
4824                do {
4825                    if (Z_OPT_REFCOUNTED_P(param)) Z_ADDREF_P(param);
4826                    ZEND_HASH_FILL_ADD(param);
4827                    param++;
4828                } while (++arg_num <= arg_count);
4829            }
4830        } ZEND_HASH_FILL_END();
4831    } else {
4832        array_init(params);
4833    }
4834
4835    CHECK_EXCEPTION();
4836    ZEND_VM_NEXT_OPCODE();
4837}
4838
4839ZEND_VM_HANDLER(52, ZEND_BOOL, CONST|TMPVAR|CV, ANY)
4840{
4841    USE_OPLINE
4842    zval *val;
4843    zend_free_op free_op1;
4844
4845    val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4846    if (Z_TYPE_INFO_P(val) == IS_TRUE) {
4847        ZVAL_TRUE(EX_VAR(opline->result.var));
4848    } else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
4849        if (UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
4850            SAVE_OPLINE();
4851            GET_OP1_UNDEF_CV(val, BP_VAR_R);
4852            CHECK_EXCEPTION();
4853        }
4854        ZVAL_FALSE(EX_VAR(opline->result.var));
4855    } else {
4856        SAVE_OPLINE();
4857        ZVAL_BOOL(EX_VAR(opline->result.var), i_zend_is_true(val));
4858        FREE_OP1();
4859        CHECK_EXCEPTION();
4860    }
4861    ZEND_VM_NEXT_OPCODE();
4862}
4863
4864ZEND_VM_HANDLER(100, ZEND_GOTO, ANY, CONST)
4865{
4866    USE_OPLINE
4867    zend_brk_cont_element *el;
4868
4869    SAVE_OPLINE();
4870    el = zend_brk_cont(Z_LVAL_P(EX_CONSTANT(opline->op2)), opline->extended_value,
4871                       &EX(func)->op_array, execute_data);
4872
4873    if (el->start >= 0) {
4874        zend_op *brk_opline = EX(func)->op_array.opcodes + el->brk;
4875
4876        if (brk_opline->opcode == ZEND_FREE) {
4877            zval_ptr_dtor_nogc(EX_VAR(brk_opline->op1.var));
4878        } else if (brk_opline->opcode == ZEND_FE_FREE) {
4879            zval *var = EX_VAR(brk_opline->op1.var);
4880            if (Z_TYPE_P(var) != IS_ARRAY && Z_FE_ITER_P(var) != (uint32_t)-1) {
4881                zend_hash_iterator_del(Z_FE_ITER_P(var));
4882            }
4883            zval_ptr_dtor_nogc(var);
4884        }
4885    }
4886    ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op1));
4887}
4888
4889ZEND_VM_HANDLER(48, ZEND_CASE, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
4890{
4891    USE_OPLINE
4892    zend_free_op free_op1, free_op2;
4893    zval *op1, *op2, *result;
4894
4895    op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4896    op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
4897    do {
4898        int result;
4899
4900        if (EXPECTED(Z_TYPE_P(op1) == IS_LONG)) {
4901            if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
4902                result = (Z_LVAL_P(op1) == Z_LVAL_P(op2));
4903            } else if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
4904                result = ((double)Z_LVAL_P(op1) == Z_DVAL_P(op2));
4905            } else {
4906                break;
4907            }
4908        } else if (EXPECTED(Z_TYPE_P(op1) == IS_DOUBLE)) {
4909            if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
4910                result = (Z_DVAL_P(op1) == Z_DVAL_P(op2));
4911            } else if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
4912                result = (Z_DVAL_P(op1) == ((double)Z_LVAL_P(op2)));
4913            } else {
4914                break;
4915            }
4916        } else if (EXPECTED(Z_TYPE_P(op1) == IS_STRING)) {
4917            if (EXPECTED(Z_TYPE_P(op2) == IS_STRING)) {
4918                if (Z_STR_P(op1) == Z_STR_P(op2)) {
4919                    result = 1;
4920                } else if (Z_STRVAL_P(op1)[0] > '9' || Z_STRVAL_P(op2)[0] > '9') {
4921                    if (Z_STRLEN_P(op1) != Z_STRLEN_P(op2)) {
4922                        result = 0;
4923                    } else {
4924                        result = (memcmp(Z_STRVAL_P(op1), Z_STRVAL_P(op2), Z_STRLEN_P(op1)) == 0);
4925                    }
4926                } else {
4927                    result = (zendi_smart_strcmp(op1, op2) == 0);
4928                }
4929                FREE_OP2();
4930            } else {
4931                break;
4932            }
4933        } else {
4934            break;
4935        }
4936        ZEND_VM_SMART_BRANCH(result, 0);
4937        ZVAL_BOOL(EX_VAR(opline->result.var), result);
4938        ZEND_VM_NEXT_OPCODE();
4939    } while (0);
4940
4941    SAVE_OPLINE();
4942    if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op1) == IS_UNDEF)) {
4943        op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
4944    }
4945    if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op2) == IS_UNDEF)) {
4946        op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
4947    }
4948    result = EX_VAR(opline->result.var);
4949    compare_function(result, op1, op2);
4950    ZVAL_BOOL(result, Z_LVAL_P(result) == 0);
4951    FREE_OP2();
4952    CHECK_EXCEPTION();
4953    ZEND_VM_NEXT_OPCODE();
4954}
4955
4956ZEND_VM_HANDLER(68, ZEND_NEW, CONST|VAR, ANY)
4957{
4958    USE_OPLINE
4959    zval object_zval;
4960    zend_function *constructor;
4961    zend_class_entry *ce;
4962
4963    SAVE_OPLINE();
4964    if (OP1_TYPE == IS_CONST) {
4965        if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)))) {
4966            ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
4967        } else {
4968            ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
4969            if (UNEXPECTED(ce == NULL)) {
4970                CHECK_EXCEPTION();
4971                ZEND_VM_NEXT_OPCODE();
4972            }
4973            CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce);
4974        }
4975    } else {
4976        ce = Z_CE_P(EX_VAR(opline->op1.var));
4977    }
4978    if (UNEXPECTED(object_init_ex(&object_zval, ce) != SUCCESS)) {
4979        HANDLE_EXCEPTION();
4980    }
4981    constructor = Z_OBJ_HT(object_zval)->get_constructor(Z_OBJ(object_zval));
4982
4983    if (constructor == NULL) {
4984        if (EXPECTED(RETURN_VALUE_USED(opline))) {
4985            ZVAL_COPY_VALUE(EX_VAR(opline->result.var), &object_zval);
4986        } else {
4987            OBJ_RELEASE(Z_OBJ(object_zval));
4988        }
4989        ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
4990    } else {
4991        /* We are not handling overloaded classes right now */
4992        zend_execute_data *call = zend_vm_stack_push_call_frame(
4993                ZEND_CALL_FUNCTION | ZEND_CALL_RELEASE_THIS | ZEND_CALL_CTOR |
4994                (EXPECTED(RETURN_VALUE_USED(opline)) ? 0 : ZEND_CALL_CTOR_RESULT_UNUSED),
4995            constructor,
4996            opline->extended_value,
4997            ce,
4998            Z_OBJ(object_zval));
4999        call->prev_execute_data = EX(call);
5000        EX(call) = call;
5001
5002        if (EXPECTED(RETURN_VALUE_USED(opline))) {
5003            ZVAL_COPY(EX_VAR(opline->result.var), &object_zval);
5004        }
5005
5006        CHECK_EXCEPTION();
5007        ZEND_VM_NEXT_OPCODE();
5008    }
5009}
5010
5011ZEND_VM_HANDLER(110, ZEND_CLONE, CONST|TMPVAR|UNUSED|CV, ANY)
5012{
5013    USE_OPLINE
5014    zend_free_op free_op1;
5015    zval *obj;
5016    zend_class_entry *ce;
5017    zend_function *clone;
5018    zend_object_clone_obj_t clone_call;
5019
5020    SAVE_OPLINE();
5021    obj = GET_OP1_OBJ_ZVAL_PTR_UNDEF(BP_VAR_R);
5022
5023    if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(obj) == NULL)) {
5024        zend_throw_error(zend_ce_error, "Using $this when not in object context");
5025        HANDLE_EXCEPTION();
5026    }
5027
5028    do {
5029        if (OP1_TYPE == IS_CONST ||
5030            (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(obj) != IS_OBJECT))) {
5031            if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(obj)) {
5032                obj = Z_REFVAL_P(obj);
5033                if (EXPECTED(Z_TYPE_P(obj) == IS_OBJECT)) {
5034                    break;
5035                }
5036            }
5037            if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(obj) == IS_UNDEF)) {
5038                GET_OP1_UNDEF_CV(obj, BP_VAR_R);
5039            }
5040            if (UNEXPECTED(EG(exception) != NULL)) {
5041                HANDLE_EXCEPTION();
5042            }
5043            zend_throw_error(zend_ce_error, "__clone method called on non-object");
5044            FREE_OP1();
5045            HANDLE_EXCEPTION();
5046        }
5047    } while (0);
5048
5049    ce = Z_OBJCE_P(obj);
5050    clone = ce ? ce->clone : NULL;
5051    clone_call =  Z_OBJ_HT_P(obj)->clone_obj;
5052    if (UNEXPECTED(clone_call == NULL)) {
5053        if (ce) {
5054            zend_throw_error(zend_ce_error, "Trying to clone an uncloneable object of class %s", ZSTR_VAL(ce->name));
5055        } else {
5056            zend_throw_error(zend_ce_error, "Trying to clone an uncloneable object");
5057        }
5058        FREE_OP1();
5059        HANDLE_EXCEPTION();
5060    }
5061
5062    if (ce && clone) {
5063        if (clone->op_array.fn_flags & ZEND_ACC_PRIVATE) {
5064            /* Ensure that if we're calling a private function, we're allowed to do so.
5065             */
5066            if (UNEXPECTED(ce != EG(scope))) {
5067                zend_throw_error(zend_ce_error, "Call to private %s::__clone() from context '%s'", ZSTR_VAL(ce->name), EG(scope) ? ZSTR_VAL(EG(scope)->name) : "");
5068                FREE_OP1();
5069                HANDLE_EXCEPTION();
5070            }
5071        } else if ((clone->common.fn_flags & ZEND_ACC_PROTECTED)) {
5072            /* Ensure that if we're calling a protected function, we're allowed to do so.
5073             */
5074            if (UNEXPECTED(!zend_check_protected(zend_get_function_root_class(clone), EG(scope)))) {
5075                zend_throw_error(zend_ce_error, "Call to protected %s::__clone() from context '%s'", ZSTR_VAL(ce->name), EG(scope) ? ZSTR_VAL(EG(scope)->name) : "");
5076                FREE_OP1();
5077                HANDLE_EXCEPTION();
5078            }
5079        }
5080    }
5081
5082    if (EXPECTED(EG(exception) == NULL)) {
5083        ZVAL_OBJ(EX_VAR(opline->result.var), clone_call(obj));
5084        if (UNEXPECTED(!RETURN_VALUE_USED(opline)) || UNEXPECTED(EG(exception) != NULL)) {
5085            OBJ_RELEASE(Z_OBJ_P(EX_VAR(opline->result.var)));
5086        }
5087    }
5088    FREE_OP1();
5089    CHECK_EXCEPTION();
5090    ZEND_VM_NEXT_OPCODE();
5091}
5092
5093ZEND_VM_HANDLER(99, ZEND_FETCH_CONSTANT, VAR|CONST|UNUSED, CONST)
5094{
5095    USE_OPLINE
5096
5097    SAVE_OPLINE();
5098    if (OP1_TYPE == IS_UNUSED) {
5099        zend_constant *c;
5100
5101        if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) {
5102            c = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
5103        } else if ((c = zend_quick_get_constant(EX_CONSTANT(opline->op2) + 1, opline->extended_value)) == NULL) {
5104            if ((opline->extended_value & IS_CONSTANT_UNQUALIFIED) != 0) {
5105                char *actual = (char *)zend_memrchr(Z_STRVAL_P(EX_CONSTANT(opline->op2)), '\\', Z_STRLEN_P(EX_CONSTANT(opline->op2)));
5106                if (!actual) {
5107                    ZVAL_STR_COPY(EX_VAR(opline->result.var), Z_STR_P(EX_CONSTANT(opline->op2)));
5108                } else {
5109                    actual++;
5110                    ZVAL_STRINGL(EX_VAR(opline->result.var),
5111                            actual, Z_STRLEN_P(EX_CONSTANT(opline->op2)) - (actual - Z_STRVAL_P(EX_CONSTANT(opline->op2))));