1/*
2   +----------------------------------------------------------------------+
3   | Zend Engine                                                          |
4   +----------------------------------------------------------------------+
5   | Copyright (c) 1998-2016 Zend Technologies Ltd. (http://www.zend.com) |
6   +----------------------------------------------------------------------+
7   | This source file is subject to version 2.00 of the Zend license,     |
8   | that is bundled with this package in the file LICENSE, and is        |
9   | available through the world-wide-web at the following url:           |
10   | http://www.zend.com/license/2_00.txt.                                |
11   | If you did not receive a copy of the Zend license and are unable to  |
12   | obtain it through the world-wide-web, please send a note to          |
13   | license@zend.com so we can mail you a copy immediately.              |
14   +----------------------------------------------------------------------+
15   | Authors: Andi Gutmans <andi@zend.com>                                |
16   |          Zeev Suraski <zeev@zend.com>                                |
17   |          Dmitry Stogov <dmitry@zend.com>                             |
18   +----------------------------------------------------------------------+
19*/
20
21/* $Id$ */
22
23/* If you change this file, please regenerate the zend_vm_execute.h and
24 * zend_vm_opcodes.h files by running:
25 * php zend_vm_gen.php
26 */
27
28ZEND_VM_HANDLER(1, ZEND_ADD, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
29{
30	USE_OPLINE
31	zend_free_op free_op1, free_op2;
32	zval *op1, *op2, *result;
33
34	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
35	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
36	if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
37		if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
38			result = EX_VAR(opline->result.var);
39			fast_long_add_function(result, op1, op2);
40			ZEND_VM_NEXT_OPCODE();
41		} else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
42			result = EX_VAR(opline->result.var);
43			ZVAL_DOUBLE(result, ((double)Z_LVAL_P(op1)) + Z_DVAL_P(op2));
44			ZEND_VM_NEXT_OPCODE();
45		}
46	} else if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_DOUBLE)) {
47		if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
48			result = EX_VAR(opline->result.var);
49			ZVAL_DOUBLE(result, Z_DVAL_P(op1) + Z_DVAL_P(op2));
50			ZEND_VM_NEXT_OPCODE();
51		} else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
52			result = EX_VAR(opline->result.var);
53			ZVAL_DOUBLE(result, Z_DVAL_P(op1) + ((double)Z_LVAL_P(op2)));
54			ZEND_VM_NEXT_OPCODE();
55		}
56	}
57
58	SAVE_OPLINE();
59	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
60		op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
61	}
62	if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
63		op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
64	}
65	add_function(EX_VAR(opline->result.var), op1, op2);
66	FREE_OP1();
67	FREE_OP2();
68	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
69}
70
71ZEND_VM_HANDLER(2, ZEND_SUB, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
72{
73	USE_OPLINE
74	zend_free_op free_op1, free_op2;
75	zval *op1, *op2, *result;
76
77	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
78	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
79	if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
80		if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
81			result = EX_VAR(opline->result.var);
82			fast_long_sub_function(result, op1, op2);
83			ZEND_VM_NEXT_OPCODE();
84		} else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
85			result = EX_VAR(opline->result.var);
86			ZVAL_DOUBLE(result, ((double)Z_LVAL_P(op1)) - Z_DVAL_P(op2));
87			ZEND_VM_NEXT_OPCODE();
88		}
89	} else if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_DOUBLE)) {
90		if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
91			result = EX_VAR(opline->result.var);
92			ZVAL_DOUBLE(result, Z_DVAL_P(op1) - Z_DVAL_P(op2));
93			ZEND_VM_NEXT_OPCODE();
94		} else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
95			result = EX_VAR(opline->result.var);
96			ZVAL_DOUBLE(result, Z_DVAL_P(op1) - ((double)Z_LVAL_P(op2)));
97			ZEND_VM_NEXT_OPCODE();
98		}
99	}
100
101	SAVE_OPLINE();
102	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
103		op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
104	}
105	if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
106		op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
107	}
108	sub_function(EX_VAR(opline->result.var), op1, op2);
109	FREE_OP1();
110	FREE_OP2();
111	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
112}
113
114ZEND_VM_HANDLER(3, ZEND_MUL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
115{
116	USE_OPLINE
117	zend_free_op free_op1, free_op2;
118	zval *op1, *op2, *result;
119
120	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
121	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
122	if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
123		if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
124			zend_long overflow;
125
126			result = EX_VAR(opline->result.var);
127			ZEND_SIGNED_MULTIPLY_LONG(Z_LVAL_P(op1), Z_LVAL_P(op2), Z_LVAL_P(result), Z_DVAL_P(result), overflow);
128			Z_TYPE_INFO_P(result) = overflow ? IS_DOUBLE : IS_LONG;
129			ZEND_VM_NEXT_OPCODE();
130		} else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
131			result = EX_VAR(opline->result.var);
132			ZVAL_DOUBLE(result, ((double)Z_LVAL_P(op1)) * Z_DVAL_P(op2));
133			ZEND_VM_NEXT_OPCODE();
134		}
135	} else if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_DOUBLE)) {
136		if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
137			result = EX_VAR(opline->result.var);
138			ZVAL_DOUBLE(result, Z_DVAL_P(op1) * Z_DVAL_P(op2));
139			ZEND_VM_NEXT_OPCODE();
140		} else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
141			result = EX_VAR(opline->result.var);
142			ZVAL_DOUBLE(result, Z_DVAL_P(op1) * ((double)Z_LVAL_P(op2)));
143			ZEND_VM_NEXT_OPCODE();
144		}
145	}
146
147	SAVE_OPLINE();
148	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
149		op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
150	}
151	if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
152		op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
153	}
154	mul_function(EX_VAR(opline->result.var), op1, op2);
155	FREE_OP1();
156	FREE_OP2();
157	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
158}
159
160ZEND_VM_HANDLER(4, ZEND_DIV, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
161{
162	USE_OPLINE
163	zend_free_op free_op1, free_op2;
164	zval *op1, *op2;
165
166	SAVE_OPLINE();
167	op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
168	op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
169	fast_div_function(EX_VAR(opline->result.var), op1, op2);
170	FREE_OP1();
171	FREE_OP2();
172	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
173}
174
175ZEND_VM_HANDLER(5, ZEND_MOD, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
176{
177	USE_OPLINE
178	zend_free_op free_op1, free_op2;
179	zval *op1, *op2, *result;
180
181	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
182	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
183	if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
184		if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
185			result = EX_VAR(opline->result.var);
186			if (UNEXPECTED(Z_LVAL_P(op2) == 0)) {
187				SAVE_OPLINE();
188				zend_throw_exception_ex(zend_ce_division_by_zero_error, 0, "Modulo by zero");
189				HANDLE_EXCEPTION();
190			} else if (UNEXPECTED(Z_LVAL_P(op2) == -1)) {
191				/* Prevent overflow error/crash if op1==ZEND_LONG_MIN */
192				ZVAL_LONG(result, 0);
193			} else {
194				ZVAL_LONG(result, Z_LVAL_P(op1) % Z_LVAL_P(op2));
195			}
196			ZEND_VM_NEXT_OPCODE();
197		}
198	}
199
200	SAVE_OPLINE();
201	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
202		op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
203	}
204	if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
205		op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
206	}
207	mod_function(EX_VAR(opline->result.var), op1, op2);
208	FREE_OP1();
209	FREE_OP2();
210	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
211}
212
213ZEND_VM_HANDLER(6, ZEND_SL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
214{
215	USE_OPLINE
216	zend_free_op free_op1, free_op2;
217	zval *op1, *op2;
218
219	SAVE_OPLINE();
220	op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
221	op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
222	shift_left_function(EX_VAR(opline->result.var), op1, op2);
223	FREE_OP1();
224	FREE_OP2();
225	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
226}
227
228ZEND_VM_HANDLER(7, ZEND_SR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
229{
230	USE_OPLINE
231	zend_free_op free_op1, free_op2;
232	zval *op1, *op2;
233
234	SAVE_OPLINE();
235	op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
236	op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
237	shift_right_function(EX_VAR(opline->result.var), op1, op2);
238	FREE_OP1();
239	FREE_OP2();
240	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
241}
242
243ZEND_VM_HANDLER(166, ZEND_POW, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
244{
245	USE_OPLINE
246	zend_free_op free_op1, free_op2;
247	zval *op1, *op2;
248
249	SAVE_OPLINE();
250	op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
251	op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
252	pow_function(EX_VAR(opline->result.var), op1, op2);
253	FREE_OP1();
254	FREE_OP2();
255	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
256}
257
258ZEND_VM_HANDLER(8, ZEND_CONCAT, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
259{
260	USE_OPLINE
261	zend_free_op free_op1, free_op2;
262	zval *op1, *op2;
263
264	SAVE_OPLINE();
265	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
266	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
267
268	do {
269		if ((OP1_TYPE == IS_CONST || EXPECTED(Z_TYPE_P(op1) == IS_STRING)) &&
270		    (OP2_TYPE == IS_CONST || EXPECTED(Z_TYPE_P(op2) == IS_STRING))) {
271			zend_string *op1_str = Z_STR_P(op1);
272			zend_string *op2_str = Z_STR_P(op2);
273			zend_string *str;
274
275			if (OP1_TYPE != IS_CONST) {
276				if (UNEXPECTED(ZSTR_LEN(op1_str) == 0)) {
277					ZVAL_STR_COPY(EX_VAR(opline->result.var), op2_str);
278					FREE_OP1();
279					break;
280				}
281			}
282			if (OP2_TYPE != IS_CONST) {
283				if (UNEXPECTED(ZSTR_LEN(op2_str) == 0)) {
284					ZVAL_STR_COPY(EX_VAR(opline->result.var), op1_str);
285					FREE_OP1();
286					break;
287				}
288			}
289			if (OP1_TYPE != IS_CONST && OP1_TYPE != IS_CV &&
290			    !ZSTR_IS_INTERNED(op1_str) && GC_REFCOUNT(op1_str) == 1) {
291			    size_t len = ZSTR_LEN(op1_str);
292
293				str = zend_string_realloc(op1_str, len + ZSTR_LEN(op2_str), 0);
294				memcpy(ZSTR_VAL(str) + len, ZSTR_VAL(op2_str), ZSTR_LEN(op2_str)+1);
295				ZVAL_NEW_STR(EX_VAR(opline->result.var), str);
296				break;
297			} else {
298				str = zend_string_alloc(ZSTR_LEN(op1_str) + ZSTR_LEN(op2_str), 0);
299				memcpy(ZSTR_VAL(str), ZSTR_VAL(op1_str), ZSTR_LEN(op1_str));
300				memcpy(ZSTR_VAL(str) + ZSTR_LEN(op1_str), ZSTR_VAL(op2_str), ZSTR_LEN(op2_str)+1);
301				ZVAL_NEW_STR(EX_VAR(opline->result.var), str);
302			}
303		} else {
304			if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op1) == IS_UNDEF)) {
305				op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
306			}
307			if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op2) == IS_UNDEF)) {
308				op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
309			}
310			concat_function(EX_VAR(opline->result.var), op1, op2);
311		}
312		FREE_OP1();
313	} while (0);
314	FREE_OP2();
315	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
316}
317
318ZEND_VM_HANDLER(15, ZEND_IS_IDENTICAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
319{
320	USE_OPLINE
321	zend_free_op free_op1, free_op2;
322	zval *op1, *op2;
323	int result;
324
325	SAVE_OPLINE();
326	op1 = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
327	op2 = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
328	result = fast_is_identical_function(op1, op2);
329	FREE_OP1();
330	FREE_OP2();
331	ZEND_VM_SMART_BRANCH(result, 1);
332	ZVAL_BOOL(EX_VAR(opline->result.var), result);
333	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
334}
335
336ZEND_VM_HANDLER(16, ZEND_IS_NOT_IDENTICAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
337{
338	USE_OPLINE
339	zend_free_op free_op1, free_op2;
340	zval *op1, *op2;
341	int result;
342
343	SAVE_OPLINE();
344	op1 = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
345	op2 = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
346	result = fast_is_not_identical_function(op1, op2);
347	FREE_OP1();
348	FREE_OP2();
349	ZEND_VM_SMART_BRANCH(result, 1);
350	ZVAL_BOOL(EX_VAR(opline->result.var), result);
351	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
352}
353
354ZEND_VM_HANDLER(17, ZEND_IS_EQUAL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
355{
356	USE_OPLINE
357	zend_free_op free_op1, free_op2;
358	zval *op1, *op2, *result;
359
360	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
361	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
362	do {
363		int result;
364
365		if (EXPECTED(Z_TYPE_P(op1) == IS_LONG)) {
366			if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
367				result = (Z_LVAL_P(op1) == Z_LVAL_P(op2));
368			} else if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
369				result = ((double)Z_LVAL_P(op1) == Z_DVAL_P(op2));
370			} else {
371				break;
372			}
373		} else if (EXPECTED(Z_TYPE_P(op1) == IS_DOUBLE)) {
374			if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
375				result = (Z_DVAL_P(op1) == Z_DVAL_P(op2));
376			} else if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
377				result = (Z_DVAL_P(op1) == ((double)Z_LVAL_P(op2)));
378			} else {
379				break;
380			}
381		} else if (EXPECTED(Z_TYPE_P(op1) == IS_STRING)) {
382			if (EXPECTED(Z_TYPE_P(op2) == IS_STRING)) {
383				if (Z_STR_P(op1) == Z_STR_P(op2)) {
384					result = 1;
385				} else if (Z_STRVAL_P(op1)[0] > '9' || Z_STRVAL_P(op2)[0] > '9') {
386					if (Z_STRLEN_P(op1) != Z_STRLEN_P(op2)) {
387						result = 0;
388					} else {
389						result = (memcmp(Z_STRVAL_P(op1), Z_STRVAL_P(op2), Z_STRLEN_P(op1)) == 0);
390					}
391				} else {
392					result = (zendi_smart_strcmp(Z_STR_P(op1), Z_STR_P(op2)) == 0);
393				}
394				FREE_OP1();
395				FREE_OP2();
396			} else {
397				break;
398			}
399		} else {
400			break;
401		}
402		ZEND_VM_SMART_BRANCH(result, 0);
403		ZVAL_BOOL(EX_VAR(opline->result.var), result);
404		ZEND_VM_NEXT_OPCODE();
405	} while (0);
406
407	SAVE_OPLINE();
408	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op1) == IS_UNDEF)) {
409		op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
410	}
411	if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op2) == IS_UNDEF)) {
412		op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
413	}
414	result = EX_VAR(opline->result.var);
415	compare_function(result, op1, op2);
416	ZVAL_BOOL(result, Z_LVAL_P(result) == 0);
417	FREE_OP1();
418	FREE_OP2();
419	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
420}
421
422ZEND_VM_HANDLER(18, ZEND_IS_NOT_EQUAL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
423{
424	USE_OPLINE
425	zend_free_op free_op1, free_op2;
426	zval *op1, *op2, *result;
427
428	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
429	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
430	do {
431		int result;
432
433		if (EXPECTED(Z_TYPE_P(op1) == IS_LONG)) {
434			if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
435				result = (Z_LVAL_P(op1) != Z_LVAL_P(op2));
436			} else if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
437				result = ((double)Z_LVAL_P(op1) != Z_DVAL_P(op2));
438			} else {
439				break;
440			}
441		} else if (EXPECTED(Z_TYPE_P(op1) == IS_DOUBLE)) {
442			if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
443				result = (Z_DVAL_P(op1) != Z_DVAL_P(op2));
444			} else if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
445				result = (Z_DVAL_P(op1) != ((double)Z_LVAL_P(op2)));
446			} else {
447				break;
448			}
449		} else if (EXPECTED(Z_TYPE_P(op1) == IS_STRING)) {
450			if (EXPECTED(Z_TYPE_P(op2) == IS_STRING)) {
451				if (Z_STR_P(op1) == Z_STR_P(op2)) {
452					result = 0;
453				} else if (Z_STRVAL_P(op1)[0] > '9' || Z_STRVAL_P(op2)[0] > '9') {
454					if (Z_STRLEN_P(op1) != Z_STRLEN_P(op2)) {
455						result = 1;
456					} else {
457						result = (memcmp(Z_STRVAL_P(op1), Z_STRVAL_P(op2), Z_STRLEN_P(op1)) != 0);
458					}
459				} else {
460					result = (zendi_smart_strcmp(Z_STR_P(op1), Z_STR_P(op2)) != 0);
461				}
462				FREE_OP1();
463				FREE_OP2();
464			} else {
465				break;
466			}
467		} else {
468			break;
469		}
470		ZEND_VM_SMART_BRANCH(result, 0);
471		ZVAL_BOOL(EX_VAR(opline->result.var), result);
472		ZEND_VM_NEXT_OPCODE();
473	} while (0);
474
475	SAVE_OPLINE();
476	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op1) == IS_UNDEF)) {
477		op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
478	}
479	if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op2) == IS_UNDEF)) {
480		op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
481	}
482	result = EX_VAR(opline->result.var);
483	compare_function(result, op1, op2);
484	ZVAL_BOOL(result, Z_LVAL_P(result) != 0);
485	FREE_OP1();
486	FREE_OP2();
487	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
488}
489
490ZEND_VM_HANDLER(19, ZEND_IS_SMALLER, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
491{
492	USE_OPLINE
493	zend_free_op free_op1, free_op2;
494	zval *op1, *op2, *result;
495
496	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
497	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
498	do {
499		int result;
500
501		if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
502			if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
503				result = (Z_LVAL_P(op1) < Z_LVAL_P(op2));
504			} else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
505				result = ((double)Z_LVAL_P(op1) < Z_DVAL_P(op2));
506			} else {
507				break;
508			}
509		} else if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_DOUBLE)) {
510			if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
511				result = (Z_DVAL_P(op1) < Z_DVAL_P(op2));
512			} else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
513				result = (Z_DVAL_P(op1) < ((double)Z_LVAL_P(op2)));
514			} else {
515				break;
516			}
517		} else {
518			break;
519		}
520		ZEND_VM_SMART_BRANCH(result, 0);
521		ZVAL_BOOL(EX_VAR(opline->result.var), result);
522		ZEND_VM_NEXT_OPCODE();
523	} while (0);
524
525	SAVE_OPLINE();
526	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
527		op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
528	}
529	if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
530		op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
531	}
532	result = EX_VAR(opline->result.var);
533	compare_function(result, op1, op2);
534	ZVAL_BOOL(result, Z_LVAL_P(result) < 0);
535	FREE_OP1();
536	FREE_OP2();
537	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
538}
539
540ZEND_VM_HANDLER(20, ZEND_IS_SMALLER_OR_EQUAL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
541{
542	USE_OPLINE
543	zend_free_op free_op1, free_op2;
544	zval *op1, *op2, *result;
545
546	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
547	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
548	do {
549		int result;
550
551		if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
552			if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
553				result = (Z_LVAL_P(op1) <= Z_LVAL_P(op2));
554			} else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
555				result = ((double)Z_LVAL_P(op1) <= Z_DVAL_P(op2));
556			} else {
557				break;
558			}
559		} else if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_DOUBLE)) {
560			if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
561				result = (Z_DVAL_P(op1) <= Z_DVAL_P(op2));
562			} else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
563				result = (Z_DVAL_P(op1) <= ((double)Z_LVAL_P(op2)));
564			} else {
565				break;
566			}
567		} else {
568			break;
569		}
570		ZEND_VM_SMART_BRANCH(result, 0);
571		ZVAL_BOOL(EX_VAR(opline->result.var), result);
572		ZEND_VM_NEXT_OPCODE();
573	} while (0);
574
575	SAVE_OPLINE();
576	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
577		op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
578	}
579	if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
580		op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
581	}
582	result = EX_VAR(opline->result.var);
583	compare_function(result, op1, op2);
584	ZVAL_BOOL(result, Z_LVAL_P(result) <= 0);
585	FREE_OP1();
586	FREE_OP2();
587	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
588}
589
590ZEND_VM_HANDLER(170, ZEND_SPACESHIP, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
591{
592	USE_OPLINE
593	zend_free_op free_op1, free_op2;
594	zval *op1, *op2;
595
596	SAVE_OPLINE();
597	op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
598	op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
599	compare_function(EX_VAR(opline->result.var), op1, op2);
600	FREE_OP1();
601	FREE_OP2();
602	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
603}
604
605ZEND_VM_HANDLER(9, ZEND_BW_OR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
606{
607	USE_OPLINE
608	zend_free_op free_op1, free_op2;
609	zval *op1, *op2;
610
611	SAVE_OPLINE();
612	op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
613	op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
614	bitwise_or_function(EX_VAR(opline->result.var), op1, op2);
615	FREE_OP1();
616	FREE_OP2();
617	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
618}
619
620ZEND_VM_HANDLER(10, ZEND_BW_AND, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
621{
622	USE_OPLINE
623	zend_free_op free_op1, free_op2;
624	zval *op1, *op2;
625
626	SAVE_OPLINE();
627	op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
628	op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
629	bitwise_and_function(EX_VAR(opline->result.var), op1, op2);
630	FREE_OP1();
631	FREE_OP2();
632	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
633}
634
635ZEND_VM_HANDLER(11, ZEND_BW_XOR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
636{
637	USE_OPLINE
638	zend_free_op free_op1, free_op2;
639	zval *op1, *op2;
640
641	SAVE_OPLINE();
642	op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
643	op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
644	bitwise_xor_function(EX_VAR(opline->result.var), op1, op2);
645	FREE_OP1();
646	FREE_OP2();
647	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
648}
649
650ZEND_VM_HANDLER(14, ZEND_BOOL_XOR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
651{
652	USE_OPLINE
653	zend_free_op free_op1, free_op2;
654	zval *op1, *op2;
655
656	SAVE_OPLINE();
657	op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
658	op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
659	boolean_xor_function(EX_VAR(opline->result.var), op1, op2);
660	FREE_OP1();
661	FREE_OP2();
662	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
663}
664
665ZEND_VM_HANDLER(12, ZEND_BW_NOT, CONST|TMPVAR|CV, ANY)
666{
667	USE_OPLINE
668	zend_free_op free_op1;
669
670	SAVE_OPLINE();
671	bitwise_not_function(EX_VAR(opline->result.var),
672		GET_OP1_ZVAL_PTR(BP_VAR_R));
673	FREE_OP1();
674	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
675}
676
677ZEND_VM_HANDLER(13, ZEND_BOOL_NOT, CONST|TMPVAR|CV, ANY)
678{
679	USE_OPLINE
680	zval *val;
681	zend_free_op free_op1;
682
683	val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
684	if (Z_TYPE_INFO_P(val) == IS_TRUE) {
685		ZVAL_FALSE(EX_VAR(opline->result.var));
686	} else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
687		ZVAL_TRUE(EX_VAR(opline->result.var));
688		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
689			SAVE_OPLINE();
690			GET_OP1_UNDEF_CV(val, BP_VAR_R);
691			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
692		}
693	} else {
694		SAVE_OPLINE();
695		ZVAL_BOOL(EX_VAR(opline->result.var), !i_zend_is_true(val));
696		FREE_OP1();
697		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
698	}
699	ZEND_VM_NEXT_OPCODE();
700}
701
702ZEND_VM_HELPER(zend_binary_assign_op_obj_helper, VAR|UNUSED|CV, CONST|TMPVAR|CV, binary_op_type binary_op)
703{
704	USE_OPLINE
705	zend_free_op free_op1, free_op2, free_op_data1;
706	zval *object;
707	zval *property;
708	zval *value;
709	zval *zptr;
710
711	SAVE_OPLINE();
712	object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
713
714	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(object) == NULL)) {
715		zend_throw_error(NULL, "Using $this when not in object context");
716		FREE_UNFETCHED_OP((opline+1)->op1_type, (opline+1)->op1.var);
717		FREE_UNFETCHED_OP2();
718		HANDLE_EXCEPTION();
719	}
720
721	property = GET_OP2_ZVAL_PTR(BP_VAR_R);
722
723	do {
724		value = get_zval_ptr_r((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1);
725
726		if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
727			ZVAL_DEREF(object);
728			if (UNEXPECTED(!make_real_object(object))) {
729				zend_error(E_WARNING, "Attempt to assign property of non-object");
730				if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
731					ZVAL_NULL(EX_VAR(opline->result.var));
732				}
733				break;
734			}
735		}
736
737		/* here we are sure we are dealing with an object */
738		if (EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
739			&& EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL))) != NULL)) {
740
741			ZVAL_DEREF(zptr);
742			SEPARATE_ZVAL_NOREF(zptr);
743
744			binary_op(zptr, zptr, value);
745			if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
746				ZVAL_COPY(EX_VAR(opline->result.var), zptr);
747			}
748		} else {
749			zend_assign_op_overloaded_property(object, property, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), value, binary_op, (UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL));
750		}
751	} while (0);
752
753	FREE_OP(free_op_data1);
754	FREE_OP2();
755	FREE_OP1_VAR_PTR();
756	/* assign_obj has two opcodes! */
757	ZEND_VM_NEXT_OPCODE_EX(1, 2);
758}
759
760ZEND_VM_HELPER(zend_binary_assign_op_dim_helper, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV, binary_op_type binary_op)
761{
762	USE_OPLINE
763	zend_free_op free_op1, free_op2, free_op_data1;
764	zval *var_ptr, rv;
765	zval *value, *container, *dim;
766
767	SAVE_OPLINE();
768	container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
769	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
770		zend_throw_error(NULL, "Using $this when not in object context");
771		FREE_UNFETCHED_OP((opline+1)->op1_type, (opline+1)->op1.var);
772		FREE_UNFETCHED_OP2();
773		HANDLE_EXCEPTION();
774	}
775
776	dim = GET_OP2_ZVAL_PTR(BP_VAR_R);
777
778	do {
779		if (OP1_TYPE == IS_UNUSED || UNEXPECTED(Z_TYPE_P(container) != IS_ARRAY)) {
780			if (OP1_TYPE != IS_UNUSED) {
781				ZVAL_DEREF(container);
782			}
783			if (OP1_TYPE == IS_UNUSED || EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
784				value = get_zval_ptr_r((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1);
785				zend_binary_assign_op_obj_dim(container, dim, value, UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL, binary_op);
786				break;
787			}
788		}
789
790		zend_fetch_dimension_address_RW(&rv, container, dim, OP2_TYPE);
791		value = get_zval_ptr_r((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1);
792
793		if (UNEXPECTED(Z_ISERROR(rv))) {
794			if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
795				ZVAL_NULL(EX_VAR(opline->result.var));
796			}
797		} else {
798			ZEND_ASSERT(Z_TYPE(rv) == IS_INDIRECT);
799			var_ptr = Z_INDIRECT(rv);
800			ZVAL_DEREF(var_ptr);
801			SEPARATE_ZVAL_NOREF(var_ptr);
802
803			binary_op(var_ptr, var_ptr, value);
804
805			if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
806				ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
807			}
808		}
809	} while (0);
810
811	FREE_OP2();
812	FREE_OP(free_op_data1);
813	FREE_OP1_VAR_PTR();
814	ZEND_VM_NEXT_OPCODE_EX(1, 2);
815}
816
817ZEND_VM_HELPER(zend_binary_assign_op_helper, VAR|CV, CONST|TMPVAR|CV, binary_op_type binary_op)
818{
819	USE_OPLINE
820	zend_free_op free_op1, free_op2;
821	zval *var_ptr;
822	zval *value;
823
824	SAVE_OPLINE();
825	value = GET_OP2_ZVAL_PTR(BP_VAR_R);
826	var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
827
828	if (OP1_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(var_ptr))) {
829		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
830			ZVAL_NULL(EX_VAR(opline->result.var));
831		}
832	} else {
833		ZVAL_DEREF(var_ptr);
834		SEPARATE_ZVAL_NOREF(var_ptr);
835
836		binary_op(var_ptr, var_ptr, value);
837
838		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
839			ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
840		}
841	}
842
843	FREE_OP2();
844	FREE_OP1_VAR_PTR();
845	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
846}
847
848ZEND_VM_HANDLER(23, ZEND_ASSIGN_ADD, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
849{
850#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
851	USE_OPLINE
852
853# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
854	if (EXPECTED(opline->extended_value == 0)) {
855		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, add_function);
856	}
857# endif
858	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
859		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, add_function);
860	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
861		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, add_function);
862	}
863#else
864	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, add_function);
865#endif
866}
867
868ZEND_VM_HANDLER(24, ZEND_ASSIGN_SUB, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
869{
870#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
871	USE_OPLINE
872
873# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
874	if (EXPECTED(opline->extended_value == 0)) {
875		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, sub_function);
876	}
877# endif
878	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
879		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, sub_function);
880	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
881		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, sub_function);
882	}
883#else
884	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, sub_function);
885#endif
886}
887
888ZEND_VM_HANDLER(25, ZEND_ASSIGN_MUL, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
889{
890#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
891	USE_OPLINE
892
893# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
894	if (EXPECTED(opline->extended_value == 0)) {
895		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, mul_function);
896	}
897# endif
898	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
899		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, mul_function);
900	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
901		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, mul_function);
902	}
903#else
904	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, mul_function);
905#endif
906}
907
908ZEND_VM_HANDLER(26, ZEND_ASSIGN_DIV, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
909{
910#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
911	USE_OPLINE
912
913# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
914	if (EXPECTED(opline->extended_value == 0)) {
915		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, div_function);
916	}
917# endif
918	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
919		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, div_function);
920	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
921		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, div_function);
922	}
923#else
924	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, div_function);
925#endif
926}
927
928ZEND_VM_HANDLER(27, ZEND_ASSIGN_MOD, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
929{
930#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
931	USE_OPLINE
932
933# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
934	if (EXPECTED(opline->extended_value == 0)) {
935		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, mod_function);
936	}
937# endif
938	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
939		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, mod_function);
940	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
941		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, mod_function);
942	}
943#else
944	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, mod_function);
945#endif
946}
947
948ZEND_VM_HANDLER(28, ZEND_ASSIGN_SL, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
949{
950#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
951	USE_OPLINE
952
953# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
954	if (EXPECTED(opline->extended_value == 0)) {
955		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, shift_left_function);
956	}
957# endif
958	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
959		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, shift_left_function);
960	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
961		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, shift_left_function);
962	}
963#else
964	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, shift_left_function);
965#endif
966}
967
968ZEND_VM_HANDLER(29, ZEND_ASSIGN_SR, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
969{
970#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
971	USE_OPLINE
972
973# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
974	if (EXPECTED(opline->extended_value == 0)) {
975		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, shift_right_function);
976	}
977# endif
978	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
979		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, shift_right_function);
980	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
981		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, shift_right_function);
982	}
983#else
984	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, shift_right_function);
985#endif
986}
987
988ZEND_VM_HANDLER(30, ZEND_ASSIGN_CONCAT, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
989{
990#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
991	USE_OPLINE
992
993# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
994	if (EXPECTED(opline->extended_value == 0)) {
995		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, concat_function);
996	}
997# endif
998	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
999		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, concat_function);
1000	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
1001		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, concat_function);
1002	}
1003#else
1004	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, concat_function);
1005#endif
1006}
1007
1008ZEND_VM_HANDLER(31, ZEND_ASSIGN_BW_OR, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
1009{
1010#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
1011	USE_OPLINE
1012
1013# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
1014	if (EXPECTED(opline->extended_value == 0)) {
1015		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, bitwise_or_function);
1016	}
1017# endif
1018	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
1019		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, bitwise_or_function);
1020	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
1021		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, bitwise_or_function);
1022	}
1023#else
1024	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, bitwise_or_function);
1025#endif
1026}
1027
1028ZEND_VM_HANDLER(32, ZEND_ASSIGN_BW_AND, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
1029{
1030#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
1031	USE_OPLINE
1032
1033# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
1034	if (EXPECTED(opline->extended_value == 0)) {
1035		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, bitwise_and_function);
1036	}
1037# endif
1038	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
1039		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, bitwise_and_function);
1040	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
1041		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, bitwise_and_function);
1042	}
1043#else
1044	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, bitwise_and_function);
1045#endif
1046}
1047
1048ZEND_VM_HANDLER(33, ZEND_ASSIGN_BW_XOR, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
1049{
1050#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
1051	USE_OPLINE
1052
1053# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
1054	if (EXPECTED(opline->extended_value == 0)) {
1055		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, bitwise_xor_function);
1056	}
1057# endif
1058	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
1059		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, bitwise_xor_function);
1060	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
1061		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, bitwise_xor_function);
1062	}
1063#else
1064	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, bitwise_xor_function);
1065#endif
1066}
1067
1068ZEND_VM_HANDLER(167, ZEND_ASSIGN_POW, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
1069{
1070#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
1071	USE_OPLINE
1072
1073# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
1074	if (EXPECTED(opline->extended_value == 0)) {
1075		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, pow_function);
1076	}
1077# endif
1078	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
1079		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, pow_function);
1080	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
1081		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, pow_function);
1082	}
1083#else
1084	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, pow_function);
1085#endif
1086}
1087
1088ZEND_VM_HELPER(zend_pre_incdec_property_helper, VAR|UNUSED|CV, CONST|TMPVAR|CV, int inc)
1089{
1090	USE_OPLINE
1091	zend_free_op free_op1, free_op2;
1092	zval *object;
1093	zval *property;
1094	zval *zptr;
1095
1096	SAVE_OPLINE();
1097	object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
1098
1099	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(object) == NULL)) {
1100		zend_throw_error(NULL, "Using $this when not in object context");
1101		FREE_UNFETCHED_OP2();
1102		HANDLE_EXCEPTION();
1103	}
1104
1105	property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1106
1107	do {
1108		if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
1109			ZVAL_DEREF(object);
1110			if (UNEXPECTED(!make_real_object(object))) {
1111				zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
1112				if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1113					ZVAL_NULL(EX_VAR(opline->result.var));
1114				}
1115				break;
1116			}
1117		}
1118
1119		/* here we are sure we are dealing with an object */
1120
1121		if (EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
1122			&& EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL))) != NULL)) {
1123
1124			if (EXPECTED(Z_TYPE_P(zptr) == IS_LONG)) {
1125				if (inc) {
1126					fast_long_increment_function(zptr);
1127				} else {
1128					fast_long_decrement_function(zptr);
1129				}
1130			} else {
1131				ZVAL_DEREF(zptr);
1132				SEPARATE_ZVAL_NOREF(zptr);
1133
1134				if (inc) {
1135					increment_function(zptr);
1136				} else {
1137					decrement_function(zptr);
1138				}
1139			}
1140			if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1141				ZVAL_COPY(EX_VAR(opline->result.var), zptr);
1142			}
1143		} else {
1144			zend_pre_incdec_overloaded_property(object, property, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), inc, (UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL));
1145		}
1146	} while (0);
1147
1148	FREE_OP2();
1149	FREE_OP1_VAR_PTR();
1150	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1151}
1152
1153ZEND_VM_HANDLER(132, ZEND_PRE_INC_OBJ, VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
1154{
1155	ZEND_VM_DISPATCH_TO_HELPER(zend_pre_incdec_property_helper, inc, 1);
1156}
1157
1158ZEND_VM_HANDLER(133, ZEND_PRE_DEC_OBJ, VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
1159{
1160	ZEND_VM_DISPATCH_TO_HELPER(zend_pre_incdec_property_helper, inc, 0);
1161}
1162
1163ZEND_VM_HELPER(zend_post_incdec_property_helper, VAR|UNUSED|CV, CONST|TMPVAR|CV, int inc)
1164{
1165	USE_OPLINE
1166	zend_free_op free_op1, free_op2;
1167	zval *object;
1168	zval *property;
1169	zval *zptr;
1170
1171	SAVE_OPLINE();
1172	object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
1173
1174	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(object) == NULL)) {
1175		zend_throw_error(NULL, "Using $this when not in object context");
1176		FREE_UNFETCHED_OP2();
1177		HANDLE_EXCEPTION();
1178	}
1179
1180	property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1181
1182	do {
1183		if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
1184			ZVAL_DEREF(object);
1185			if (UNEXPECTED(!make_real_object(object))) {
1186				zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
1187				ZVAL_NULL(EX_VAR(opline->result.var));
1188				break;
1189			}
1190		}
1191
1192		/* here we are sure we are dealing with an object */
1193
1194		if (EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
1195			&& EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL))) != NULL)) {
1196
1197			if (EXPECTED(Z_TYPE_P(zptr) == IS_LONG)) {
1198				ZVAL_COPY_VALUE(EX_VAR(opline->result.var), zptr);
1199				if (inc) {
1200					fast_long_increment_function(zptr);
1201				} else {
1202					fast_long_decrement_function(zptr);
1203				}
1204			} else {
1205				ZVAL_DEREF(zptr);
1206				ZVAL_COPY_VALUE(EX_VAR(opline->result.var), zptr);
1207				zval_opt_copy_ctor(zptr);
1208				if (inc) {
1209					increment_function(zptr);
1210				} else {
1211					decrement_function(zptr);
1212				}
1213			}
1214		} else {
1215			zend_post_incdec_overloaded_property(object, property, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), inc, EX_VAR(opline->result.var));
1216		}
1217	} while (0);
1218
1219	FREE_OP2();
1220	FREE_OP1_VAR_PTR();
1221	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1222}
1223
1224ZEND_VM_HANDLER(134, ZEND_POST_INC_OBJ, VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
1225{
1226	ZEND_VM_DISPATCH_TO_HELPER(zend_post_incdec_property_helper, inc, 1);
1227}
1228
1229ZEND_VM_HANDLER(135, ZEND_POST_DEC_OBJ, VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
1230{
1231	ZEND_VM_DISPATCH_TO_HELPER(zend_post_incdec_property_helper, inc, 0);
1232}
1233
1234ZEND_VM_HANDLER(34, ZEND_PRE_INC, VAR|CV, ANY, SPEC(RETVAL))
1235{
1236	USE_OPLINE
1237	zend_free_op free_op1;
1238	zval *var_ptr;
1239
1240	var_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_RW);
1241
1242	if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1243		fast_long_increment_function(var_ptr);
1244		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1245			ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1246		}
1247		ZEND_VM_NEXT_OPCODE();
1248	}
1249
1250	if (OP1_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(var_ptr))) {
1251		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1252			ZVAL_NULL(EX_VAR(opline->result.var));
1253		}
1254		ZEND_VM_NEXT_OPCODE();
1255	}
1256
1257	SAVE_OPLINE();
1258	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var_ptr) == IS_UNDEF)) {
1259		var_ptr = GET_OP1_UNDEF_CV(var_ptr, BP_VAR_RW);
1260	}
1261	ZVAL_DEREF(var_ptr);
1262	SEPARATE_ZVAL_NOREF(var_ptr);
1263
1264	increment_function(var_ptr);
1265
1266	if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1267		ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
1268	}
1269
1270	FREE_OP1_VAR_PTR();
1271	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1272}
1273
1274ZEND_VM_HANDLER(35, ZEND_PRE_DEC, VAR|CV, ANY, SPEC(RETVAL))
1275{
1276	USE_OPLINE
1277	zend_free_op free_op1;
1278	zval *var_ptr;
1279
1280	var_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_RW);
1281
1282	if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1283		fast_long_decrement_function(var_ptr);
1284		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1285			ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1286		}
1287		ZEND_VM_NEXT_OPCODE();
1288	}
1289
1290	if (OP1_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(var_ptr))) {
1291		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1292			ZVAL_NULL(EX_VAR(opline->result.var));
1293		}
1294		ZEND_VM_NEXT_OPCODE();
1295	}
1296
1297	SAVE_OPLINE();
1298	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var_ptr) == IS_UNDEF)) {
1299		var_ptr = GET_OP1_UNDEF_CV(var_ptr, BP_VAR_RW);
1300	}
1301	ZVAL_DEREF(var_ptr);
1302	SEPARATE_ZVAL_NOREF(var_ptr);
1303
1304	decrement_function(var_ptr);
1305
1306	if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1307		ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
1308	}
1309
1310	FREE_OP1_VAR_PTR();
1311	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1312}
1313
1314ZEND_VM_HANDLER(36, ZEND_POST_INC, VAR|CV, ANY)
1315{
1316	USE_OPLINE
1317	zend_free_op free_op1;
1318	zval *var_ptr;
1319
1320	var_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_RW);
1321
1322	if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1323		ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1324		fast_long_increment_function(var_ptr);
1325		ZEND_VM_NEXT_OPCODE();
1326	}
1327
1328	if (OP1_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(var_ptr))) {
1329		ZVAL_NULL(EX_VAR(opline->result.var));
1330		ZEND_VM_NEXT_OPCODE();
1331	}
1332
1333	SAVE_OPLINE();
1334	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var_ptr) == IS_UNDEF)) {
1335		var_ptr = GET_OP1_UNDEF_CV(var_ptr, BP_VAR_RW);
1336	}
1337	ZVAL_DEREF(var_ptr);
1338	ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1339	zval_opt_copy_ctor(var_ptr);
1340
1341	increment_function(var_ptr);
1342
1343	FREE_OP1_VAR_PTR();
1344	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1345}
1346
1347ZEND_VM_HANDLER(37, ZEND_POST_DEC, VAR|CV, ANY)
1348{
1349	USE_OPLINE
1350	zend_free_op free_op1;
1351	zval *var_ptr;
1352
1353	var_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_RW);
1354
1355	if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1356		ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1357		fast_long_decrement_function(var_ptr);
1358		ZEND_VM_NEXT_OPCODE();
1359	}
1360
1361	if (OP1_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(var_ptr))) {
1362		ZVAL_NULL(EX_VAR(opline->result.var));
1363		ZEND_VM_NEXT_OPCODE();
1364	}
1365
1366	SAVE_OPLINE();
1367	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var_ptr) == IS_UNDEF)) {
1368		var_ptr = GET_OP1_UNDEF_CV(var_ptr, BP_VAR_RW);
1369	}
1370	ZVAL_DEREF(var_ptr);
1371	ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1372	zval_opt_copy_ctor(var_ptr);
1373
1374	decrement_function(var_ptr);
1375
1376	FREE_OP1_VAR_PTR();
1377	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1378}
1379
1380ZEND_VM_HANDLER(40, ZEND_ECHO, CONST|TMPVAR|CV, ANY)
1381{
1382	USE_OPLINE
1383	zend_free_op free_op1;
1384	zval *z;
1385
1386	SAVE_OPLINE();
1387	z = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
1388
1389	if (Z_TYPE_P(z) == IS_STRING) {
1390		zend_string *str = Z_STR_P(z);
1391
1392		if (ZSTR_LEN(str) != 0) {
1393			zend_write(ZSTR_VAL(str), ZSTR_LEN(str));
1394		}
1395	} else {
1396		zend_string *str = _zval_get_string_func(z);
1397
1398		if (ZSTR_LEN(str) != 0) {
1399			zend_write(ZSTR_VAL(str), ZSTR_LEN(str));
1400		} else if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(z) == IS_UNDEF)) {
1401			GET_OP1_UNDEF_CV(z, BP_VAR_R);
1402		}
1403		zend_string_release(str);
1404	}
1405
1406	FREE_OP1();
1407	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1408}
1409
1410ZEND_VM_HELPER(zend_fetch_var_address_helper, CONST|TMPVAR|CV, UNUSED, int type)
1411{
1412	USE_OPLINE
1413	zend_free_op free_op1;
1414	zval *varname;
1415	zval *retval;
1416	zend_string *name;
1417	HashTable *target_symbol_table;
1418
1419	SAVE_OPLINE();
1420	varname = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
1421
1422 	if (OP1_TYPE == IS_CONST) {
1423		name = Z_STR_P(varname);
1424	} else if (EXPECTED(Z_TYPE_P(varname) == IS_STRING)) {
1425		name = Z_STR_P(varname);
1426		zend_string_addref(name);
1427	} else {
1428		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(varname) == IS_UNDEF)) {
1429			GET_OP1_UNDEF_CV(varname, BP_VAR_R);
1430		}
1431		name = zval_get_string(varname);
1432	}
1433
1434	target_symbol_table = zend_get_target_symbol_table(execute_data, opline->extended_value & ZEND_FETCH_TYPE_MASK);
1435	retval = zend_hash_find(target_symbol_table, name);
1436	if (retval == NULL) {
1437		switch (type) {
1438			case BP_VAR_R:
1439			case BP_VAR_UNSET:
1440				zend_error(E_NOTICE,"Undefined variable: %s", ZSTR_VAL(name));
1441				/* break missing intentionally */
1442			case BP_VAR_IS:
1443				retval = &EG(uninitialized_zval);
1444				break;
1445			case BP_VAR_RW:
1446				zend_error(E_NOTICE,"Undefined variable: %s", ZSTR_VAL(name));
1447				retval = zend_hash_update(target_symbol_table, name, &EG(uninitialized_zval));
1448				break;
1449			case BP_VAR_W:
1450				retval = zend_hash_add_new(target_symbol_table, name, &EG(uninitialized_zval));
1451				break;
1452			EMPTY_SWITCH_DEFAULT_CASE()
1453		}
1454	/* GLOBAL or $$name variable may be an INDIRECT pointer to CV */
1455	} else if (Z_TYPE_P(retval) == IS_INDIRECT) {
1456		retval = Z_INDIRECT_P(retval);
1457		if (Z_TYPE_P(retval) == IS_UNDEF) {
1458			switch (type) {
1459				case BP_VAR_R:
1460				case BP_VAR_UNSET:
1461					zend_error(E_NOTICE,"Undefined variable: %s", ZSTR_VAL(name));
1462					/* break missing intentionally */
1463				case BP_VAR_IS:
1464					retval = &EG(uninitialized_zval);
1465					break;
1466				case BP_VAR_RW:
1467					zend_error(E_NOTICE,"Undefined variable: %s", ZSTR_VAL(name));
1468					/* break missing intentionally */
1469				case BP_VAR_W:
1470					ZVAL_NULL(retval);
1471					break;
1472				EMPTY_SWITCH_DEFAULT_CASE()
1473			}
1474		}
1475	}
1476
1477	if ((opline->extended_value & ZEND_FETCH_TYPE_MASK) != ZEND_FETCH_GLOBAL_LOCK) {
1478		FREE_OP1();
1479	}
1480
1481	if (OP1_TYPE != IS_CONST) {
1482		zend_string_release(name);
1483	}
1484
1485	ZEND_ASSERT(retval != NULL);
1486	if (type == BP_VAR_R || type == BP_VAR_IS) {
1487		if (/*type == BP_VAR_R &&*/ Z_ISREF_P(retval) && Z_REFCOUNT_P(retval) == 1) {
1488			ZVAL_UNREF(retval);
1489		}
1490		ZVAL_COPY(EX_VAR(opline->result.var), retval);
1491	} else {
1492		ZVAL_INDIRECT(EX_VAR(opline->result.var), retval);
1493	}
1494	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1495}
1496
1497ZEND_VM_HANDLER(80, ZEND_FETCH_R, CONST|TMPVAR|CV, UNUSED, VAR_FETCH)
1498{
1499	ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_var_address_helper, type, BP_VAR_R);
1500}
1501
1502ZEND_VM_HANDLER(83, ZEND_FETCH_W, CONST|TMPVAR|CV, UNUSED, VAR_FETCH)
1503{
1504	ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_var_address_helper, type, BP_VAR_W);
1505}
1506
1507ZEND_VM_HANDLER(86, ZEND_FETCH_RW, CONST|TMPVAR|CV, UNUSED, VAR_FETCH)
1508{
1509	ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_var_address_helper, type, BP_VAR_RW);
1510}
1511
1512ZEND_VM_HANDLER(92, ZEND_FETCH_FUNC_ARG, CONST|TMPVAR|CV, UNUSED, VAR_FETCH|ARG_NUM)
1513{
1514	USE_OPLINE
1515
1516	if (zend_is_by_ref_func_arg_fetch(opline, EX(call))) {
1517		ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_var_address_helper, type, BP_VAR_W);
1518	} else {
1519		ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_var_address_helper, type, BP_VAR_R);
1520	}
1521}
1522
1523ZEND_VM_HANDLER(95, ZEND_FETCH_UNSET, CONST|TMPVAR|CV, UNUSED, VAR_FETCH)
1524{
1525	ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_var_address_helper, type, BP_VAR_UNSET);
1526}
1527
1528ZEND_VM_HANDLER(89, ZEND_FETCH_IS, CONST|TMPVAR|CV, UNUSED, VAR_FETCH)
1529{
1530	ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_var_address_helper, type, BP_VAR_IS);
1531}
1532
1533ZEND_VM_HELPER(zend_fetch_static_prop_helper, CONST|TMPVAR|CV, UNUSED|CONST|VAR, int type)
1534{
1535	USE_OPLINE
1536	zend_free_op free_op1;
1537	zval *varname;
1538	zval *retval;
1539	zend_string *name;
1540	zend_class_entry *ce;
1541
1542	SAVE_OPLINE();
1543	varname = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
1544
1545 	if (OP1_TYPE == IS_CONST) {
1546		name = Z_STR_P(varname);
1547	} else if (EXPECTED(Z_TYPE_P(varname) == IS_STRING)) {
1548		name = Z_STR_P(varname);
1549		zend_string_addref(name);
1550	} else {
1551		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(varname) == IS_UNDEF)) {
1552			GET_OP1_UNDEF_CV(varname, BP_VAR_R);
1553		}
1554		name = zval_get_string(varname);
1555	}
1556
1557	if (OP2_TYPE == IS_CONST) {
1558		if (OP1_TYPE == IS_CONST && EXPECTED((ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)))) != NULL)) {
1559			retval = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)) + sizeof(void*));
1560
1561			/* check if static properties were destoyed */
1562			if (UNEXPECTED(CE_STATIC_MEMBERS(ce) == NULL)) {
1563				zend_throw_error(NULL, "Access to undeclared static property: %s::$%s", ZSTR_VAL(ce->name), ZSTR_VAL(name));
1564				FREE_OP1();
1565				HANDLE_EXCEPTION();
1566			}
1567
1568			ZEND_VM_C_GOTO(fetch_static_prop_return);
1569		} else if (UNEXPECTED((ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) == NULL)) {
1570			ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op2)), EX_CONSTANT(opline->op2) + 1, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
1571			if (UNEXPECTED(ce == NULL)) {
1572				if (OP1_TYPE != IS_CONST) {
1573					zend_string_release(name);
1574				}
1575				FREE_OP1();
1576				ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1577			}
1578			CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce);
1579		}
1580	} else {
1581		if (OP2_TYPE == IS_UNUSED) {
1582			ce = zend_fetch_class(NULL, opline->op2.num);
1583			if (UNEXPECTED(ce == NULL)) {
1584				ZEND_ASSERT(EG(exception));
1585				if (OP1_TYPE != IS_CONST) {
1586					zend_string_release(name);
1587				}
1588				FREE_OP1();
1589				HANDLE_EXCEPTION();
1590			}
1591		} else {
1592			ce = Z_CE_P(EX_VAR(opline->op2.var));
1593		}
1594		if (OP1_TYPE == IS_CONST &&
1595		    (retval = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce)) != NULL) {
1596
1597			/* check if static properties were destoyed */
1598			if (UNEXPECTED(CE_STATIC_MEMBERS(ce) == NULL)) {
1599				zend_throw_error(NULL, "Access to undeclared static property: %s::$%s", ZSTR_VAL(ce->name), ZSTR_VAL(name));
1600				FREE_OP1();
1601				HANDLE_EXCEPTION();
1602			}
1603
1604			ZEND_VM_C_GOTO(fetch_static_prop_return);
1605		}
1606	}
1607	retval = zend_std_get_static_property(ce, name, 0);
1608	if (UNEXPECTED(EG(exception))) {
1609		if (OP1_TYPE != IS_CONST) {
1610			zend_string_release(name);
1611		}
1612		FREE_OP1();
1613		HANDLE_EXCEPTION();
1614	}
1615	if (OP1_TYPE == IS_CONST && retval) {
1616		CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce, retval);
1617	}
1618
1619	FREE_OP1();
1620
1621	if (OP1_TYPE != IS_CONST) {
1622		zend_string_release(name);
1623	}
1624
1625ZEND_VM_C_LABEL(fetch_static_prop_return):
1626	ZEND_ASSERT(retval != NULL);
1627	if (type == BP_VAR_R || type == BP_VAR_IS) {
1628		if (/*type == BP_VAR_R &&*/ Z_ISREF_P(retval) && Z_REFCOUNT_P(retval) == 1) {
1629			ZVAL_UNREF(retval);
1630		}
1631		ZVAL_COPY(EX_VAR(opline->result.var), retval);
1632	} else {
1633		ZVAL_INDIRECT(EX_VAR(opline->result.var), retval);
1634	}
1635	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1636}
1637
1638ZEND_VM_HANDLER(173, ZEND_FETCH_STATIC_PROP_R, CONST|TMPVAR|CV, UNUSED|CLASS_FETCH|CONST|VAR)
1639{
1640	ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_static_prop_helper, type, BP_VAR_R);
1641}
1642
1643ZEND_VM_HANDLER(174, ZEND_FETCH_STATIC_PROP_W, CONST|TMPVAR|CV, UNUSED|CLASS_FETCH|CONST|VAR)
1644{
1645	ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_static_prop_helper, type, BP_VAR_W);
1646}
1647
1648ZEND_VM_HANDLER(175, ZEND_FETCH_STATIC_PROP_RW, CONST|TMPVAR|CV, UNUSED|CLASS_FETCH|CONST|VAR)
1649{
1650	ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_static_prop_helper, type, BP_VAR_RW);
1651}
1652
1653ZEND_VM_HANDLER(177, ZEND_FETCH_STATIC_PROP_FUNC_ARG, CONST|TMPVAR|CV, UNUSED|CLASS_FETCH|CONST|VAR, NUM)
1654{
1655	USE_OPLINE
1656
1657	if (zend_is_by_ref_func_arg_fetch(opline, EX(call))) {
1658		ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_static_prop_helper, type, BP_VAR_W);
1659	} else {
1660		ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_static_prop_helper, type, BP_VAR_R);
1661	}
1662}
1663
1664ZEND_VM_HANDLER(178, ZEND_FETCH_STATIC_PROP_UNSET, CONST|TMPVAR|CV, UNUSED|CLASS_FETCH|CONST|VAR)
1665{
1666	ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_static_prop_helper, type, BP_VAR_UNSET);
1667}
1668
1669ZEND_VM_HANDLER(176, ZEND_FETCH_STATIC_PROP_IS, CONST|TMPVAR|CV, UNUSED|CLASS_FETCH|CONST|VAR)
1670{
1671	ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_static_prop_helper, type, BP_VAR_IS);
1672}
1673
1674ZEND_VM_HANDLER(81, ZEND_FETCH_DIM_R, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
1675{
1676	USE_OPLINE
1677	zend_free_op free_op1, free_op2;
1678	zval *container;
1679
1680	SAVE_OPLINE();
1681	container = GET_OP1_ZVAL_PTR(BP_VAR_R);
1682	zend_fetch_dimension_address_read_R(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1683	FREE_OP2();
1684	FREE_OP1();
1685	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1686}
1687
1688ZEND_VM_HANDLER(84, ZEND_FETCH_DIM_W, VAR|CV, CONST|TMPVAR|UNUSED|NEXT|CV)
1689{
1690	USE_OPLINE
1691	zend_free_op free_op1, free_op2;
1692	zval *container;
1693
1694	SAVE_OPLINE();
1695	container = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1696
1697	zend_fetch_dimension_address_W(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1698	FREE_OP2();
1699	if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1700		EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1701	}
1702	FREE_OP1_VAR_PTR();
1703	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1704}
1705
1706ZEND_VM_HANDLER(87, ZEND_FETCH_DIM_RW, VAR|CV, CONST|TMPVAR|UNUSED|NEXT|CV)
1707{
1708	USE_OPLINE
1709	zend_free_op free_op1, free_op2;
1710	zval *container;
1711
1712	SAVE_OPLINE();
1713	container = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
1714
1715	zend_fetch_dimension_address_RW(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1716	FREE_OP2();
1717	if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1718		EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1719	}
1720	FREE_OP1_VAR_PTR();
1721	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1722}
1723
1724ZEND_VM_HANDLER(90, ZEND_FETCH_DIM_IS, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
1725{
1726	USE_OPLINE
1727	zend_free_op free_op1, free_op2;
1728	zval *container;
1729
1730	SAVE_OPLINE();
1731	container = GET_OP1_ZVAL_PTR(BP_VAR_IS);
1732	zend_fetch_dimension_address_read_IS(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1733	FREE_OP2();
1734	FREE_OP1();
1735	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1736}
1737
1738ZEND_VM_HANDLER(93, ZEND_FETCH_DIM_FUNC_ARG, CONST|TMP|VAR|CV, CONST|TMPVAR|UNUSED|NEXT|CV, NUM)
1739{
1740	USE_OPLINE
1741	zval *container;
1742	zend_free_op free_op1, free_op2;
1743
1744	SAVE_OPLINE();
1745
1746	if (zend_is_by_ref_func_arg_fetch(opline, EX(call))) {
1747        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
1748            zend_throw_error(NULL, "Cannot use temporary expression in write context");
1749			FREE_UNFETCHED_OP2();
1750			FREE_UNFETCHED_OP1();
1751			HANDLE_EXCEPTION();
1752        }
1753		container = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1754		zend_fetch_dimension_address_W(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1755		if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1756			EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1757		}
1758		FREE_OP2();
1759		FREE_OP1_VAR_PTR();
1760	} else {
1761		if (OP2_TYPE == IS_UNUSED) {
1762			zend_throw_error(NULL, "Cannot use [] for reading");
1763			FREE_UNFETCHED_OP2();
1764			FREE_UNFETCHED_OP1();
1765			HANDLE_EXCEPTION();
1766		}
1767		container = GET_OP1_ZVAL_PTR(BP_VAR_R);
1768		zend_fetch_dimension_address_read_R(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1769		FREE_OP2();
1770		FREE_OP1();
1771	}
1772	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1773}
1774
1775ZEND_VM_HANDLER(96, ZEND_FETCH_DIM_UNSET, VAR|CV, CONST|TMPVAR|CV)
1776{
1777	USE_OPLINE
1778	zend_free_op free_op1, free_op2;
1779	zval *container;
1780
1781	SAVE_OPLINE();
1782	container = GET_OP1_ZVAL_PTR_PTR(BP_VAR_UNSET);
1783
1784	zend_fetch_dimension_address_UNSET(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1785	FREE_OP2();
1786	if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1787		EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1788	}
1789	FREE_OP1_VAR_PTR();
1790	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1791}
1792
1793ZEND_VM_HANDLER(82, ZEND_FETCH_OBJ_R, CONST|TMP|VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
1794{
1795	USE_OPLINE
1796	zend_free_op free_op1;
1797	zval *container;
1798	zend_free_op free_op2;
1799	zval *offset;
1800
1801	SAVE_OPLINE();
1802	container = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_R);
1803
1804	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
1805		zend_throw_error(NULL, "Using $this when not in object context");
1806		FREE_UNFETCHED_OP2();
1807		HANDLE_EXCEPTION();
1808	}
1809
1810	offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
1811
1812	if (OP1_TYPE == IS_CONST ||
1813	    (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT))) {
1814		if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(container)) {
1815			container = Z_REFVAL_P(container);
1816			if (UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
1817				ZEND_VM_C_GOTO(fetch_obj_r_no_object);
1818			}
1819		} else {
1820			ZEND_VM_C_GOTO(fetch_obj_r_no_object);
1821		}
1822	}
1823
1824	/* here we are sure we are dealing with an object */
1825	do {
1826		zend_object *zobj = Z_OBJ_P(container);
1827		zval *retval;
1828
1829		if (OP2_TYPE == IS_CONST &&
1830			EXPECTED(zobj->ce == CACHED_PTR(Z_CACHE_SLOT_P(offset)))) {
1831			uint32_t prop_offset = (uint32_t)(intptr_t)CACHED_PTR(Z_CACHE_SLOT_P(offset) + sizeof(void*));
1832
1833			if (EXPECTED(prop_offset != (uint32_t)ZEND_DYNAMIC_PROPERTY_OFFSET)) {
1834				retval = OBJ_PROP(zobj, prop_offset);
1835				if (EXPECTED(Z_TYPE_P(retval) != IS_UNDEF)) {
1836					ZVAL_COPY(EX_VAR(opline->result.var), retval);
1837					break;
1838				}
1839			} else if (EXPECTED(zobj->properties != NULL)) {
1840				retval = zend_hash_find(zobj->properties, Z_STR_P(offset));
1841				if (EXPECTED(retval)) {
1842					ZVAL_COPY(EX_VAR(opline->result.var), retval);
1843					break;
1844				}
1845			}
1846		}
1847
1848		if (UNEXPECTED(zobj->handlers->read_property == NULL)) {
1849ZEND_VM_C_LABEL(fetch_obj_r_no_object):
1850			zend_error(E_NOTICE, "Trying to get property of non-object");
1851			ZVAL_NULL(EX_VAR(opline->result.var));
1852		} else {
1853			retval = zobj->handlers->read_property(container, offset, BP_VAR_R, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(offset)) : NULL), EX_VAR(opline->result.var));
1854
1855			if (retval != EX_VAR(opline->result.var)) {
1856				ZVAL_COPY(EX_VAR(opline->result.var), retval);
1857			}
1858		}
1859	} while (0);
1860
1861	FREE_OP2();
1862	FREE_OP1();
1863	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1864}
1865
1866ZEND_VM_HANDLER(85, ZEND_FETCH_OBJ_W, VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
1867{
1868	USE_OPLINE
1869	zend_free_op free_op1, free_op2;
1870	zval *property;
1871	zval *container;
1872
1873	SAVE_OPLINE();
1874	property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1875
1876	container = GET_OP1_OBJ_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1877	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
1878		zend_throw_error(NULL, "Using $this when not in object context");
1879		FREE_OP2();
1880		HANDLE_EXCEPTION();
1881	}
1882
1883	zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_W);
1884	FREE_OP2();
1885	if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1886		EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1887	}
1888	FREE_OP1_VAR_PTR();
1889	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1890}
1891
1892ZEND_VM_HANDLER(88, ZEND_FETCH_OBJ_RW, VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
1893{
1894	USE_OPLINE
1895	zend_free_op free_op1, free_op2;
1896	zval *property;
1897	zval *container;
1898
1899	SAVE_OPLINE();
1900	property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1901	container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
1902
1903	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
1904		zend_throw_error(NULL, "Using $this when not in object context");
1905		FREE_OP2();
1906		HANDLE_EXCEPTION();
1907	}
1908	zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_RW);
1909	FREE_OP2();
1910	if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1911		EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1912	}
1913	FREE_OP1_VAR_PTR();
1914	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1915}
1916
1917ZEND_VM_HANDLER(91, ZEND_FETCH_OBJ_IS, CONST|TMPVAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
1918{
1919	USE_OPLINE
1920	zend_free_op free_op1;
1921	zval *container;
1922	zend_free_op free_op2;
1923	zval *offset;
1924
1925	SAVE_OPLINE();
1926	container = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_IS);
1927
1928	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
1929		zend_throw_error(NULL, "Using $this when not in object context");
1930		FREE_UNFETCHED_OP2();
1931		HANDLE_EXCEPTION();
1932	}
1933
1934	offset  = GET_OP2_ZVAL_PTR(BP_VAR_R);
1935
1936	if (OP1_TYPE == IS_CONST ||
1937	    (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT))) {
1938		if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(container)) {
1939			container = Z_REFVAL_P(container);
1940			if (UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
1941				ZEND_VM_C_GOTO(fetch_obj_is_no_object);
1942			}
1943		} else {
1944			ZEND_VM_C_GOTO(fetch_obj_is_no_object);
1945		}
1946	}
1947
1948	/* here we are sure we are dealing with an object */
1949	do {
1950		zend_object *zobj = Z_OBJ_P(container);
1951		zval *retval;
1952
1953		if (OP2_TYPE == IS_CONST &&
1954			EXPECTED(zobj->ce == CACHED_PTR(Z_CACHE_SLOT_P(offset)))) {
1955			uint32_t prop_offset = (uint32_t)(intptr_t)CACHED_PTR(Z_CACHE_SLOT_P(offset) + sizeof(void*));
1956
1957			if (EXPECTED(prop_offset != (uint32_t)ZEND_DYNAMIC_PROPERTY_OFFSET)) {
1958				retval = OBJ_PROP(zobj, prop_offset);
1959				if (EXPECTED(Z_TYPE_P(retval) != IS_UNDEF)) {
1960					ZVAL_COPY(EX_VAR(opline->result.var), retval);
1961					break;
1962				}
1963			} else if (EXPECTED(zobj->properties != NULL)) {
1964				retval = zend_hash_find(zobj->properties, Z_STR_P(offset));
1965				if (EXPECTED(retval)) {
1966					ZVAL_COPY(EX_VAR(opline->result.var), retval);
1967					break;
1968				}
1969			}
1970		}
1971
1972		if (UNEXPECTED(zobj->handlers->read_property == NULL)) {
1973ZEND_VM_C_LABEL(fetch_obj_is_no_object):
1974			ZVAL_NULL(EX_VAR(opline->result.var));
1975		} else {
1976
1977			retval = zobj->handlers->read_property(container, offset, BP_VAR_IS, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(offset)) : NULL), EX_VAR(opline->result.var));
1978
1979			if (retval != EX_VAR(opline->result.var)) {
1980				ZVAL_COPY(EX_VAR(opline->result.var), retval);
1981			}
1982		}
1983	} while (0);
1984
1985	FREE_OP2();
1986	FREE_OP1();
1987	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1988}
1989
1990ZEND_VM_HANDLER(94, ZEND_FETCH_OBJ_FUNC_ARG, CONST|TMP|VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV, NUM)
1991{
1992	USE_OPLINE
1993	zval *container;
1994
1995	if (zend_is_by_ref_func_arg_fetch(opline, EX(call))) {
1996		/* Behave like FETCH_OBJ_W */
1997		zend_free_op free_op1, free_op2;
1998		zval *property;
1999
2000		SAVE_OPLINE();
2001		property = GET_OP2_ZVAL_PTR(BP_VAR_R);
2002		container = GET_OP1_OBJ_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
2003
2004		if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
2005			zend_throw_error(NULL, "Using $this when not in object context");
2006			FREE_OP2();
2007			HANDLE_EXCEPTION();
2008		}
2009		if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
2010			zend_throw_error(NULL, "Cannot use temporary expression in write context");
2011			FREE_OP2();
2012			FREE_OP1_VAR_PTR();
2013			HANDLE_EXCEPTION();
2014		}
2015		zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_W);
2016		FREE_OP2();
2017		if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
2018			EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
2019		}
2020		FREE_OP1_VAR_PTR();
2021		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2022	} else {
2023		ZEND_VM_DISPATCH_TO_HANDLER(ZEND_FETCH_OBJ_R);
2024	}
2025}
2026
2027ZEND_VM_HANDLER(97, ZEND_FETCH_OBJ_UNSET, VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
2028{
2029	USE_OPLINE
2030	zend_free_op free_op1, free_op2;
2031	zval *container, *property;
2032
2033	SAVE_OPLINE();
2034	container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_UNSET);
2035
2036	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
2037		zend_throw_error(NULL, "Using $this when not in object context");
2038		FREE_UNFETCHED_OP2();
2039		HANDLE_EXCEPTION();
2040	}
2041
2042	property = GET_OP2_ZVAL_PTR(BP_VAR_R);
2043
2044	zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_UNSET);
2045	FREE_OP2();
2046	if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
2047		EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
2048	}
2049	FREE_OP1_VAR_PTR();
2050	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2051}
2052
2053ZEND_VM_HANDLER(98, ZEND_FETCH_LIST, CONST|TMPVAR|CV, CONST)
2054{
2055	USE_OPLINE
2056	zend_free_op free_op1;
2057	zval *container;
2058
2059	SAVE_OPLINE();
2060	container = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2061
2062ZEND_VM_C_LABEL(try_fetch_list):
2063	if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
2064		zval *value = zend_hash_index_find(Z_ARRVAL_P(container), Z_LVAL_P(EX_CONSTANT(opline->op2)));
2065
2066		if (UNEXPECTED(value == NULL)) {
2067			zend_error(E_NOTICE,"Undefined offset: " ZEND_ULONG_FMT, Z_LVAL_P(EX_CONSTANT(opline->op2)));
2068			ZVAL_NULL(EX_VAR(opline->result.var));
2069		} else {
2070			ZVAL_COPY(EX_VAR(opline->result.var), value);
2071		}
2072	} else if (OP1_TYPE != IS_CONST &&
2073	           UNEXPECTED(Z_TYPE_P(container) == IS_OBJECT) &&
2074	           EXPECTED(Z_OBJ_HT_P(container)->read_dimension)) {
2075		zval *result = EX_VAR(opline->result.var);
2076		zval *retval = Z_OBJ_HT_P(container)->read_dimension(container, EX_CONSTANT(opline->op2), BP_VAR_R, result);
2077
2078		if (retval) {
2079			if (result != retval) {
2080				ZVAL_COPY(result, retval);
2081			}
2082		} else {
2083			ZVAL_NULL(result);
2084		}
2085	} else if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_TYPE_P(container) == IS_REFERENCE) {
2086		container = Z_REFVAL_P(container);
2087		ZEND_VM_C_GOTO(try_fetch_list);
2088	} else {
2089		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(container) == IS_UNDEF)) {
2090			GET_OP1_UNDEF_CV(container, BP_VAR_R);
2091		}
2092		ZVAL_NULL(EX_VAR(opline->result.var));
2093	}
2094	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2095}
2096
2097ZEND_VM_HANDLER(136, ZEND_ASSIGN_OBJ, VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV, SPEC(OP_DATA=CONST|TMP|VAR|CV))
2098{
2099	USE_OPLINE
2100	zend_free_op free_op1, free_op2, free_op_data;
2101	zval *object, *property_name, *value, tmp;
2102
2103	SAVE_OPLINE();
2104	object = GET_OP1_OBJ_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
2105
2106	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(object) == NULL)) {
2107		zend_throw_error(NULL, "Using $this when not in object context");
2108		FREE_UNFETCHED_OP2();
2109		HANDLE_EXCEPTION();
2110	}
2111
2112	property_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2113	value = GET_OP_DATA_ZVAL_PTR(BP_VAR_R);
2114
2115	if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
2116		do {
2117			if (OP1_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(object))) {
2118				if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2119					ZVAL_NULL(EX_VAR(opline->result.var));
2120				}
2121				FREE_OP_DATA();
2122				ZEND_VM_C_GOTO(exit_assign_obj);
2123			}
2124			if (Z_ISREF_P(object)) {
2125				object = Z_REFVAL_P(object);
2126				if (EXPECTED(Z_TYPE_P(object) == IS_OBJECT)) {
2127					break;
2128				}
2129			}
2130			if (EXPECTED(Z_TYPE_P(object) <= IS_FALSE ||
2131			    (Z_TYPE_P(object) == IS_STRING && Z_STRLEN_P(object) == 0))) {
2132				zend_object *obj;
2133
2134				zval_ptr_dtor(object);
2135				object_init(object);
2136				Z_ADDREF_P(object);
2137				obj = Z_OBJ_P(object);
2138				zend_error(E_WARNING, "Creating default object from empty value");
2139				if (GC_REFCOUNT(obj) == 1) {
2140					/* the enclosing container was deleted, obj is unreferenced */
2141					if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2142						ZVAL_NULL(EX_VAR(opline->result.var));
2143					}
2144					FREE_OP_DATA();
2145					OBJ_RELEASE(obj);
2146					ZEND_VM_C_GOTO(exit_assign_obj);
2147				}
2148				Z_DELREF_P(object);
2149			} else {
2150				zend_error(E_WARNING, "Attempt to assign property of non-object");
2151				if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2152					ZVAL_NULL(EX_VAR(opline->result.var));
2153				}
2154				FREE_OP_DATA();
2155				ZEND_VM_C_GOTO(exit_assign_obj);
2156			}
2157		} while (0);
2158	}
2159
2160	if (OP2_TYPE == IS_CONST &&
2161	    EXPECTED(Z_OBJCE_P(object) == CACHED_PTR(Z_CACHE_SLOT_P(property_name)))) {
2162		uint32_t prop_offset = (uint32_t)(intptr_t)CACHED_PTR(Z_CACHE_SLOT_P(property_name) + sizeof(void*));
2163		zend_object *zobj = Z_OBJ_P(object);
2164		zval *property;
2165
2166		if (EXPECTED(prop_offset != (uint32_t)ZEND_DYNAMIC_PROPERTY_OFFSET)) {
2167			property = OBJ_PROP(zobj, prop_offset);
2168			if (Z_TYPE_P(property) != IS_UNDEF) {
2169ZEND_VM_C_LABEL(fast_assign_obj):
2170				value = zend_assign_to_variable(property, value, OP_DATA_TYPE);
2171				if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2172					ZVAL_COPY(EX_VAR(opline->result.var), value);
2173				}
2174				ZEND_VM_C_GOTO(exit_assign_obj);
2175			}
2176		} else {
2177			if (EXPECTED(zobj->properties != NULL)) {
2178				if (UNEXPECTED(GC_REFCOUNT(zobj->properties) > 1)) {
2179					if (EXPECTED(!(GC_FLAGS(zobj->properties) & IS_ARRAY_IMMUTABLE))) {
2180						GC_REFCOUNT(zobj->properties)--;
2181					}
2182					zobj->properties = zend_array_dup(zobj->properties);
2183				}
2184				property = zend_hash_find(zobj->properties, Z_STR_P(property_name));
2185				if (property) {
2186					ZEND_VM_C_GOTO(fast_assign_obj);
2187				}
2188			}
2189
2190			if (!zobj->ce->__set) {
2191
2192				if (EXPECTED(zobj->properties == NULL)) {
2193					rebuild_object_properties(zobj);
2194				}
2195				/* separate our value if necessary */
2196				if (OP_DATA_TYPE == IS_CONST) {
2197					if (UNEXPECTED(Z_OPT_COPYABLE_P(value))) {
2198						ZVAL_COPY_VALUE(&tmp, value);
2199						zval_copy_ctor_func(&tmp);
2200						value = &tmp;
2201					}
2202				} else if (OP_DATA_TYPE != IS_TMP_VAR) {
2203					if (Z_ISREF_P(value)) {
2204						if (OP_DATA_TYPE == IS_VAR) {
2205							zend_reference *ref = Z_REF_P(value);
2206							if (--GC_REFCOUNT(ref) == 0) {
2207								ZVAL_COPY_VALUE(&tmp, Z_REFVAL_P(value));
2208								efree_size(ref, sizeof(zend_reference));
2209								value = &tmp;
2210							} else {
2211								value = Z_REFVAL_P(value);
2212								if (Z_REFCOUNTED_P(value)) {
2213									Z_ADDREF_P(value);
2214								}
2215							}
2216						} else {
2217							value = Z_REFVAL_P(value);
2218							if (Z_REFCOUNTED_P(value)) {
2219								Z_ADDREF_P(value);
2220							}
2221						}
2222					} else if (OP_DATA_TYPE == IS_CV && Z_REFCOUNTED_P(value)) {
2223						Z_ADDREF_P(value);
2224					}
2225				}
2226				zend_hash_add_new(zobj->properties, Z_STR_P(property_name), value);
2227				if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2228					ZVAL_COPY(EX_VAR(opline->result.var), value);
2229				}
2230				ZEND_VM_C_GOTO(exit_assign_obj);
2231			}
2232		}
2233	}
2234
2235	if (!Z_OBJ_HT_P(object)->write_property) {
2236		zend_error(E_WARNING, "Attempt to assign property of non-object");
2237		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2238			ZVAL_NULL(EX_VAR(opline->result.var));
2239		}
2240		FREE_OP_DATA();
2241		ZEND_VM_C_GOTO(exit_assign_obj);
2242	}
2243
2244	/* separate our value if necessary */
2245	if (OP_DATA_TYPE == IS_CONST) {
2246		if (UNEXPECTED(Z_OPT_COPYABLE_P(value))) {
2247			ZVAL_COPY_VALUE(&tmp, value);
2248			zval_copy_ctor_func(&tmp);
2249			value = &tmp;
2250		}
2251	} else if (OP_DATA_TYPE != IS_TMP_VAR) {
2252		ZVAL_DEREF(value);
2253	}
2254
2255	Z_OBJ_HT_P(object)->write_property(object, property_name, value, (OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property_name)) : NULL);
2256
2257	if (UNEXPECTED(RETURN_VALUE_USED(opline)) && EXPECTED(!EG(exception))) {
2258		ZVAL_COPY(EX_VAR(opline->result.var), value);
2259	}
2260	if (OP_DATA_TYPE == IS_CONST) {
2261		zval_ptr_dtor_nogc(value);
2262	} else {
2263		FREE_OP_DATA();
2264	}
2265ZEND_VM_C_LABEL(exit_assign_obj):
2266	FREE_OP2();
2267	FREE_OP1_VAR_PTR();
2268	/* assign_obj has two opcodes! */
2269	ZEND_VM_NEXT_OPCODE_EX(1, 2);
2270}
2271
2272ZEND_VM_HANDLER(147, ZEND_ASSIGN_DIM, VAR|CV, CONST|TMPVAR|UNUSED|NEXT|CV, SPEC(OP_DATA=CONST|TMP|VAR|CV))
2273{
2274	USE_OPLINE
2275	zend_free_op free_op1;
2276	zval *object_ptr;
2277	zend_free_op free_op2, free_op_data;
2278	zval *value;
2279	zval *variable_ptr;
2280	zval *dim;
2281
2282	SAVE_OPLINE();
2283	object_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
2284
2285	if (EXPECTED(Z_TYPE_P(object_ptr) == IS_ARRAY)) {
2286ZEND_VM_C_LABEL(try_assign_dim_array):
2287		if (OP2_TYPE == IS_UNUSED) {
2288			SEPARATE_ARRAY(object_ptr);
2289			variable_ptr = zend_hash_next_index_insert(Z_ARRVAL_P(object_ptr), &EG(uninitialized_zval));
2290			if (UNEXPECTED(variable_ptr == NULL)) {
2291				zend_error(E_WARNING, "Cannot add element to the array as the next element is already occupied");
2292				variable_ptr = NULL;
2293			}
2294		} else {
2295			dim = GET_OP2_ZVAL_PTR(BP_VAR_R);
2296			SEPARATE_ARRAY(object_ptr);
2297			variable_ptr = zend_fetch_dimension_address_inner(Z_ARRVAL_P(object_ptr), dim, OP2_TYPE, BP_VAR_W);
2298			FREE_OP2();
2299		}
2300		if (UNEXPECTED(variable_ptr == NULL)) {
2301			FREE_UNFETCHED_OP_DATA();
2302			if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2303				ZVAL_NULL(EX_VAR(opline->result.var));
2304			}
2305		} else {
2306			value = GET_OP_DATA_ZVAL_PTR(BP_VAR_R);
2307			value = zend_assign_to_variable(variable_ptr, value, OP_DATA_TYPE);
2308			if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2309				ZVAL_COPY(EX_VAR(opline->result.var), value);
2310			}
2311		}
2312	} else {
2313		if (EXPECTED(Z_ISREF_P(object_ptr))) {
2314			object_ptr = Z_REFVAL_P(object_ptr);
2315			if (EXPECTED(Z_TYPE_P(object_ptr) == IS_ARRAY)) {
2316				ZEND_VM_C_GOTO(try_assign_dim_array);
2317			}
2318		}
2319		if (EXPECTED(Z_TYPE_P(object_ptr) == IS_OBJECT)) {
2320			zend_free_op free_op2;
2321			zval *property_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2322
2323			zend_assign_to_object_dim(UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL, object_ptr, property_name, OP_DATA_TYPE, (opline+1)->op1, execute_data);
2324			FREE_OP2();
2325		} else if (EXPECTED(Z_TYPE_P(object_ptr) == IS_STRING)) {
2326			if (EXPECTED(Z_STRLEN_P(object_ptr) != 0)) {
2327				if (OP2_TYPE == IS_UNUSED) {
2328					zend_throw_error(NULL, "[] operator not supported for strings");
2329					FREE_UNFETCHED_OP_DATA();
2330					FREE_OP1_VAR_PTR();
2331					HANDLE_EXCEPTION();
2332				} else {
2333					zend_long offset;
2334
2335					dim = GET_OP2_ZVAL_PTR(BP_VAR_R);
2336					offset = zend_fetch_string_offset(object_ptr, dim, BP_VAR_W);
2337					FREE_OP2();
2338					value = GET_OP_DATA_ZVAL_PTR_DEREF(BP_VAR_R);
2339					zend_assign_to_string_offset(object_ptr, offset, value, (UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL));
2340					FREE_OP_DATA();
2341				}
2342			} else {
2343				zval_ptr_dtor_nogc(object_ptr);
2344ZEND_VM_C_LABEL(assign_dim_convert_to_array):
2345				ZVAL_NEW_ARR(object_ptr);
2346				zend_hash_init(Z_ARRVAL_P(object_ptr), 8, NULL, ZVAL_PTR_DTOR, 0);
2347				ZEND_VM_C_GOTO(try_assign_dim_array);
2348			}
2349		} else if (EXPECTED(Z_TYPE_P(object_ptr) <= IS_FALSE)) {
2350			ZEND_VM_C_GOTO(assign_dim_convert_to_array);
2351		} else if (OP1_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(object_ptr))) {
2352			ZEND_VM_C_GOTO(assign_dim_clean);
2353		} else {
2354			zend_error(E_WARNING, "Cannot use a scalar value as an array");
2355ZEND_VM_C_LABEL(assign_dim_clean):
2356			FREE_UNFETCHED_OP2();
2357			FREE_UNFETCHED_OP_DATA();
2358			if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2359				ZVAL_NULL(EX_VAR(opline->result.var));
2360			}
2361		}
2362	}
2363	FREE_OP1_VAR_PTR();
2364	/* assign_dim has two opcodes! */
2365	ZEND_VM_NEXT_OPCODE_EX(1, 2);
2366}
2367
2368ZEND_VM_HANDLER(38, ZEND_ASSIGN, VAR|CV, CONST|TMP|VAR|CV, SPEC(RETVAL))
2369{
2370	USE_OPLINE
2371	zend_free_op free_op1, free_op2;
2372	zval *value;
2373	zval *variable_ptr;
2374
2375	SAVE_OPLINE();
2376	value = GET_OP2_ZVAL_PTR(BP_VAR_R);
2377	variable_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
2378
2379	if (OP1_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(variable_ptr))) {
2380		FREE_OP2();
2381		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2382			ZVAL_NULL(EX_VAR(opline->result.var));
2383		}
2384	} else {
2385		value = zend_assign_to_variable(variable_ptr, value, OP2_TYPE);
2386		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2387			ZVAL_COPY(EX_VAR(opline->result.var), value);
2388		}
2389		FREE_OP1_VAR_PTR();
2390		/* zend_assign_to_variable() always takes care of op2, never free it! */
2391	}
2392
2393	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2394}
2395
2396ZEND_VM_HANDLER(39, ZEND_ASSIGN_REF, VAR|CV, VAR|CV, SRC)
2397{
2398	USE_OPLINE
2399	zend_free_op free_op1, free_op2;
2400	zval *variable_ptr;
2401	zval *value_ptr;
2402
2403	SAVE_OPLINE();
2404	value_ptr = GET_OP2_ZVAL_PTR_PTR(BP_VAR_W);
2405	variable_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
2406
2407	if (OP1_TYPE == IS_VAR &&
2408	    UNEXPECTED(Z_TYPE_P(EX_VAR(opline->op1.var)) != IS_INDIRECT) &&
2409	    UNEXPECTED(!Z_ISREF_P(EX_VAR(opline->op1.var))) &&
2410	    UNEXPECTED(!Z_ISERROR_P(EX_VAR(opline->op1.var)))) {
2411
2412		zend_throw_error(NULL, "Cannot assign by reference to overloaded object");
2413		FREE_OP2_VAR_PTR();
2414		HANDLE_EXCEPTION();
2415
2416	} else if (OP2_TYPE == IS_VAR &&
2417	           opline->extended_value == ZEND_RETURNS_FUNCTION &&
2418	           UNEXPECTED(!(Z_VAR_FLAGS_P(value_ptr) & IS_VAR_RET_REF))) {
2419
2420		zend_error(E_NOTICE, "Only variables should be assigned by reference");
2421		if (UNEXPECTED(EG(exception) != NULL)) {
2422			FREE_OP2_VAR_PTR();
2423			HANDLE_EXCEPTION();
2424		}
2425
2426		value_ptr = zend_assign_to_variable(variable_ptr, value_ptr, OP2_TYPE);
2427		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2428			ZVAL_COPY(EX_VAR(opline->result.var), value_ptr);
2429		}
2430		/* zend_assign_to_variable() always takes care of op2, never free it! */
2431
2432	} else {
2433
2434		if ((OP1_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(variable_ptr))) ||
2435		    (OP2_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(value_ptr)))) {
2436			variable_ptr = &EG(uninitialized_zval);
2437		} else {
2438			zend_assign_to_variable_reference(variable_ptr, value_ptr);
2439		}
2440
2441		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2442			ZVAL_COPY(EX_VAR(opline->result.var), variable_ptr);
2443		}
2444
2445		FREE_OP2_VAR_PTR();
2446	}
2447
2448	FREE_OP1_VAR_PTR();
2449	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2450}
2451
2452ZEND_VM_HELPER(zend_leave_helper, ANY, ANY)
2453{
2454	zend_execute_data *old_execute_data;
2455	uint32_t call_info = EX_CALL_INFO();
2456
2457	if (EXPECTED(ZEND_CALL_KIND_EX(call_info) == ZEND_CALL_NESTED_FUNCTION)) {
2458		zend_object *object;
2459
2460		i_free_compiled_variables(execute_data);
2461		if (UNEXPECTED(EX(symbol_table) != NULL)) {
2462			zend_clean_and_cache_symbol_table(EX(symbol_table));
2463		}
2464		zend_vm_stack_free_extra_args_ex(call_info, execute_data);
2465		old_execute_data = execute_data;
2466		execute_data = EG(current_execute_data) = EX(prev_execute_data);
2467		if (UNEXPECTED(call_info & ZEND_CALL_CLOSURE)) {
2468			OBJ_RELEASE((zend_object*)old_execute_data->func->op_array.prototype);
2469		}
2470		if (UNEXPECTED(call_info & ZEND_CALL_RELEASE_THIS)) {
2471			object = Z_OBJ(old_execute_data->This);
2472#if 0
2473			if (UNEXPECTED(EG(exception) != NULL) && (EX(opline)->op1.num & ZEND_CALL_CTOR)) {
2474#else
2475			if (UNEXPECTED(EG(exception) != NULL) && (call_info & ZEND_CALL_CTOR)) {
2476#endif
2477				GC_REFCOUNT(object)--;
2478				if (GC_REFCOUNT(object) == 1) {
2479					zend_object_store_ctor_failed(object);
2480				}
2481			}
2482			OBJ_RELEASE(object);
2483		}
2484		EG(scope) = EX(func)->op_array.scope;
2485
2486		zend_vm_stack_free_call_frame_ex(call_info, old_execute_data);
2487
2488		if (UNEXPECTED(EG(exception) != NULL)) {
2489			const zend_op *old_opline = EX(opline);
2490			zend_throw_exception_internal(NULL);
2491			if (old_opline->opcode != ZEND_HANDLE_EXCEPTION && RETURN_VALUE_USED(old_opline)) {
2492				zval_ptr_dtor(EX_VAR(old_opline->result.var));
2493			}
2494			HANDLE_EXCEPTION_LEAVE();
2495		}
2496
2497		LOAD_NEXT_OPLINE();
2498		ZEND_VM_LEAVE();
2499	}
2500	if (EXPECTED((ZEND_CALL_KIND_EX(call_info) & ZEND_CALL_TOP) == 0)) {
2501		zend_detach_symbol_table(execute_data);
2502		destroy_op_array(&EX(func)->op_array);
2503		efree_size(EX(func), sizeof(zend_op_array));
2504		old_execute_data = execute_data;
2505		execute_data = EG(current_execute_data) = EX(prev_execute_data);
2506		zend_vm_stack_free_call_frame_ex(call_info, old_execute_data);
2507
2508		zend_attach_symbol_table(execute_data);
2509		if (UNEXPECTED(EG(exception) != NULL)) {
2510			zend_throw_exception_internal(NULL);
2511			HANDLE_EXCEPTION_LEAVE();
2512		}
2513
2514		LOAD_NEXT_OPLINE();
2515		ZEND_VM_LEAVE();
2516	} else {
2517		if (ZEND_CALL_KIND_EX(call_info) == ZEND_CALL_TOP_FUNCTION) {
2518			i_free_compiled_variables(execute_data);
2519			if (UNEXPECTED(EX(symbol_table) != NULL)) {
2520				zend_clean_and_cache_symbol_table(EX(symbol_table));
2521			}
2522			zend_vm_stack_free_extra_args_ex(call_info, execute_data);
2523			EG(current_execute_data) = EX(prev_execute_data);
2524			if (UNEXPECTED(call_info & ZEND_CALL_CLOSURE)) {
2525				OBJ_RELEASE((zend_object*)EX(func)->op_array.prototype);
2526			}
2527		} else /* if (call_kind == ZEND_CALL_TOP_CODE) */ {
2528			zend_array *symbol_table = EX(symbol_table);
2529
2530			zend_detach_symbol_table(execute_data);
2531			old_execute_data = EX(prev_execute_data);
2532			while (old_execute_data) {
2533				if (old_execute_data->func && ZEND_USER_CODE(old_execute_data->func->op_array.type)) {
2534					if (old_execute_data->symbol_table == symbol_table) {
2535						zend_attach_symbol_table(old_execute_data);
2536					}
2537					break;
2538				}
2539				old_execute_data = old_execute_data->prev_execute_data;
2540			}
2541			EG(current_execute_data) = EX(prev_execute_data);
2542		}
2543
2544		ZEND_VM_RETURN();
2545	}
2546}
2547
2548ZEND_VM_HANDLER(42, ZEND_JMP, JMP_ADDR, ANY)
2549{
2550	USE_OPLINE
2551
2552	ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op1));
2553	ZEND_VM_CONTINUE();
2554}
2555
2556ZEND_VM_HANDLER(43, ZEND_JMPZ, CONST|TMPVAR|CV, JMP_ADDR)
2557{
2558	USE_OPLINE
2559	zend_free_op free_op1;
2560	zval *val;
2561
2562	val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2563
2564	if (Z_TYPE_INFO_P(val) == IS_TRUE) {
2565		ZEND_VM_SET_NEXT_OPCODE(opline + 1);
2566		ZEND_VM_CONTINUE();
2567	} else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
2568		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
2569			SAVE_OPLINE();
2570			GET_OP1_UNDEF_CV(val, BP_VAR_R);
2571			ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
2572		} else {
2573			ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2574			ZEND_VM_CONTINUE();
2575		}
2576	}
2577
2578	SAVE_OPLINE();
2579	if (i_zend_is_true(val)) {
2580		opline++;
2581	} else {
2582		opline = OP_JMP_ADDR(opline, opline->op2);
2583	}
2584	FREE_OP1();
2585	if (UNEXPECTED(EG(exception) != NULL)) {
2586		HANDLE_EXCEPTION();
2587	}
2588	ZEND_VM_JMP(opline);
2589}
2590
2591ZEND_VM_HANDLER(44, ZEND_JMPNZ, CONST|TMPVAR|CV, JMP_ADDR)
2592{
2593	USE_OPLINE
2594	zend_free_op free_op1;
2595	zval *val;
2596
2597	val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2598
2599	if (Z_TYPE_INFO_P(val) == IS_TRUE) {
2600		ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2601		ZEND_VM_CONTINUE();
2602	} else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
2603		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
2604			SAVE_OPLINE();
2605			GET_OP1_UNDEF_CV(val, BP_VAR_R);
2606			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2607		} else {
2608			ZEND_VM_NEXT_OPCODE();
2609		}
2610	}
2611
2612	SAVE_OPLINE();
2613	if (i_zend_is_true(val)) {
2614		opline = OP_JMP_ADDR(opline, opline->op2);
2615	} else {
2616		opline++;
2617	}
2618	FREE_OP1();
2619	if (UNEXPECTED(EG(exception) != NULL)) {
2620		HANDLE_EXCEPTION();
2621	}
2622	ZEND_VM_JMP(opline);
2623}
2624
2625ZEND_VM_HANDLER(45, ZEND_JMPZNZ, CONST|TMPVAR|CV, JMP_ADDR, JMP_ADDR)
2626{
2627	USE_OPLINE
2628	zend_free_op free_op1;
2629	zval *val;
2630
2631	val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2632
2633	if (EXPECTED(Z_TYPE_INFO_P(val) == IS_TRUE)) {
2634		ZEND_VM_SET_RELATIVE_OPCODE(opline, opline->extended_value);
2635		ZEND_VM_CONTINUE();
2636	} else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
2637		if (OP1_TYPE == IS_CV) {
2638			if (UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
2639				SAVE_OPLINE();
2640				GET_OP1_UNDEF_CV(val, BP_VAR_R);
2641			}
2642			ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
2643		} else {
2644			ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2645			ZEND_VM_CONTINUE();
2646		}
2647	}
2648
2649	SAVE_OPLINE();
2650	if (i_zend_is_true(val)) {
2651		opline = ZEND_OFFSET_TO_OPLINE(opline, opline->extended_value);
2652	} else {
2653		opline = OP_JMP_ADDR(opline, opline->op2);
2654	}
2655	FREE_OP1();
2656	if (UNEXPECTED(EG(exception) != NULL)) {
2657		HANDLE_EXCEPTION();
2658	}
2659	ZEND_VM_JMP(opline);
2660}
2661
2662ZEND_VM_HANDLER(46, ZEND_JMPZ_EX, CONST|TMPVAR|CV, JMP_ADDR)
2663{
2664	USE_OPLINE
2665	zend_free_op free_op1;
2666	zval *val;
2667	int ret;
2668
2669	val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2670
2671	if (Z_TYPE_INFO_P(val) == IS_TRUE) {
2672		ZVAL_TRUE(EX_VAR(opline->result.var));
2673		ZEND_VM_SET_NEXT_OPCODE(opline + 1);
2674		ZEND_VM_CONTINUE();
2675	} else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
2676		ZVAL_FALSE(EX_VAR(opline->result.var));
2677		if (OP1_TYPE == IS_CV) {
2678			if (UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
2679				SAVE_OPLINE();
2680				GET_OP1_UNDEF_CV(val, BP_VAR_R);
2681			}
2682			ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
2683		} else {
2684			ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2685			ZEND_VM_CONTINUE();
2686		}
2687	}
2688
2689	SAVE_OPLINE();
2690	ret = i_zend_is_true(val);
2691	FREE_OP1();
2692	if (ret) {
2693		ZVAL_TRUE(EX_VAR(opline->result.var));
2694		opline++;
2695	} else {
2696		ZVAL_FALSE(EX_VAR(opline->result.var));
2697		opline = OP_JMP_ADDR(opline, opline->op2);
2698	}
2699	if (UNEXPECTED(EG(exception) != NULL)) {
2700		HANDLE_EXCEPTION();
2701	}
2702	ZEND_VM_JMP(opline);
2703}
2704
2705ZEND_VM_HANDLER(47, ZEND_JMPNZ_EX, CONST|TMPVAR|CV, JMP_ADDR)
2706{
2707	USE_OPLINE
2708	zend_free_op free_op1;
2709	zval *val;
2710	int ret;
2711
2712	val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2713
2714	if (Z_TYPE_INFO_P(val) == IS_TRUE) {
2715		ZVAL_TRUE(EX_VAR(opline->result.var));
2716		ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2717		ZEND_VM_CONTINUE();
2718	} else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
2719		ZVAL_FALSE(EX_VAR(opline->result.var));
2720		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
2721			SAVE_OPLINE();
2722			GET_OP1_UNDEF_CV(val, BP_VAR_R);
2723			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2724		} else {
2725			ZEND_VM_NEXT_OPCODE();
2726		}
2727	}
2728
2729	SAVE_OPLINE();
2730	ret = i_zend_is_true(val);
2731	FREE_OP1();
2732	if (ret) {
2733		ZVAL_TRUE(EX_VAR(opline->result.var));
2734		opline = OP_JMP_ADDR(opline, opline->op2);
2735	} else {
2736		ZVAL_FALSE(EX_VAR(opline->result.var));
2737		opline++;
2738	}
2739	if (UNEXPECTED(EG(exception) != NULL)) {
2740		HANDLE_EXCEPTION();
2741	}
2742	ZEND_VM_JMP(opline);
2743}
2744
2745ZEND_VM_HANDLER(70, ZEND_FREE, TMPVAR, LIVE_RANGE)
2746{
2747	USE_OPLINE
2748
2749	SAVE_OPLINE();
2750	zval_ptr_dtor_nogc(EX_VAR(opline->op1.var));
2751	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2752}
2753
2754ZEND_VM_HANDLER(127, ZEND_FE_FREE, TMPVAR, LIVE_RANGE)
2755{
2756	zval *var;
2757	USE_OPLINE
2758
2759	SAVE_OPLINE();
2760	var = EX_VAR(opline->op1.var);
2761	if (Z_TYPE_P(var) != IS_ARRAY && Z_FE_ITER_P(var) != (uint32_t)-1) {
2762		zend_hash_iterator_del(Z_FE_ITER_P(var));
2763	}
2764	zval_ptr_dtor_nogc(var);
2765	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2766}
2767
2768ZEND_VM_HANDLER(53, ZEND_FAST_CONCAT, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
2769{
2770	USE_OPLINE
2771	zend_free_op free_op1, free_op2;
2772	zval *op1, *op2;
2773	zend_string *op1_str, *op2_str, *str;
2774
2775	SAVE_OPLINE();
2776	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2777	if (OP1_TYPE == IS_CONST) {
2778		op1_str = Z_STR_P(op1);
2779	} else if (EXPECTED(Z_TYPE_P(op1) == IS_STRING)) {
2780		op1_str = zend_string_copy(Z_STR_P(op1));
2781	} else {
2782		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op1) == IS_UNDEF)) {
2783			GET_OP1_UNDEF_CV(op1, BP_VAR_R);
2784		}
2785		op1_str = _zval_get_string_func(op1);
2786	}
2787	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2788	if (OP2_TYPE == IS_CONST) {
2789		op2_str = Z_STR_P(op2);
2790	} else if (EXPECTED(Z_TYPE_P(op2) == IS_STRING)) {
2791		op2_str = zend_string_copy(Z_STR_P(op2));
2792	} else {
2793		if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op2) == IS_UNDEF)) {
2794			GET_OP2_UNDEF_CV(op2, BP_VAR_R);
2795		}
2796		op2_str = _zval_get_string_func(op2);
2797	}
2798	do {
2799		if (OP1_TYPE != IS_CONST) {
2800			if (UNEXPECTED(ZSTR_LEN(op1_str) == 0)) {
2801				if (OP2_TYPE == IS_CONST) {
2802					zend_string_addref(op2_str);
2803				}
2804				ZVAL_STR(EX_VAR(opline->result.var), op2_str);
2805				zend_string_release(op1_str);
2806				break;
2807			}
2808		}
2809		if (OP2_TYPE != IS_CONST) {
2810			if (UNEXPECTED(ZSTR_LEN(op2_str) == 0)) {
2811				if (OP1_TYPE == IS_CONST) {
2812					zend_string_addref(op1_str);
2813				}
2814				ZVAL_STR(EX_VAR(opline->result.var), op1_str);
2815				zend_string_release(op2_str);
2816				break;
2817			}
2818		}
2819		str = zend_string_alloc(ZSTR_LEN(op1_str) + ZSTR_LEN(op2_str), 0);
2820		memcpy(ZSTR_VAL(str), ZSTR_VAL(op1_str), ZSTR_LEN(op1_str));
2821		memcpy(ZSTR_VAL(str) + ZSTR_LEN(op1_str), ZSTR_VAL(op2_str), ZSTR_LEN(op2_str)+1);
2822		ZVAL_NEW_STR(EX_VAR(opline->result.var), str);
2823		if (OP1_TYPE != IS_CONST) {
2824			zend_string_release(op1_str);
2825		}
2826		if (OP2_TYPE != IS_CONST) {
2827			zend_string_release(op2_str);
2828		}
2829	} while (0);
2830	FREE_OP1();
2831	FREE_OP2();
2832	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2833}
2834
2835ZEND_VM_HANDLER(54, ZEND_ROPE_INIT, UNUSED, CONST|TMPVAR|CV, NUM)
2836{
2837	USE_OPLINE
2838	zend_free_op free_op2;
2839	zend_string **rope;
2840	zval *var;
2841
2842	/* Compiler allocates the necessary number of zval slots to keep the rope */
2843	rope = (zend_string**)EX_VAR(opline->result.var);
2844	if (OP2_TYPE == IS_CONST) {
2845		var = GET_OP2_ZVAL_PTR(BP_VAR_R);
2846		rope[0] = zend_string_copy(Z_STR_P(var));
2847	} else {
2848		var = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2849		if (EXPECTED(Z_TYPE_P(var) == IS_STRING)) {
2850			if (OP2_TYPE == IS_CV) {
2851				rope[0] = zend_string_copy(Z_STR_P(var));
2852			} else {
2853				rope[0] = Z_STR_P(var);
2854			}
2855		} else {
2856			SAVE_OPLINE();
2857			if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var) == IS_UNDEF)) {
2858				GET_OP2_UNDEF_CV(var, BP_VAR_R);
2859			}
2860			rope[0] = _zval_get_string_func(var);
2861			FREE_OP2();
2862			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2863		}
2864	}
2865	ZEND_VM_NEXT_OPCODE();
2866}
2867
2868ZEND_VM_HANDLER(55, ZEND_ROPE_ADD, TMP, CONST|TMPVAR|CV, NUM)
2869{
2870	USE_OPLINE
2871	zend_free_op free_op2;
2872	zend_string **rope;
2873	zval *var;
2874
2875	/* op1 and result are the same */
2876	rope = (zend_string**)EX_VAR(opline->op1.var);
2877	if (OP2_TYPE == IS_CONST) {
2878		var = GET_OP2_ZVAL_PTR(BP_VAR_R);
2879		rope[opline->extended_value] = zend_string_copy(Z_STR_P(var));
2880	} else {
2881		var = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2882		if (EXPECTED(Z_TYPE_P(var) == IS_STRING)) {
2883			if (OP2_TYPE == IS_CV) {
2884				rope[opline->extended_value] = zend_string_copy(Z_STR_P(var));
2885			} else {
2886				rope[opline->extended_value] = Z_STR_P(var);
2887			}
2888		} else {
2889			SAVE_OPLINE();
2890			if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var) == IS_UNDEF)) {
2891				GET_OP2_UNDEF_CV(var, BP_VAR_R);
2892			}
2893			rope[opline->extended_value] = _zval_get_string_func(var);
2894			FREE_OP2();
2895			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2896		}
2897	}
2898	ZEND_VM_NEXT_OPCODE();
2899}
2900
2901ZEND_VM_HANDLER(56, ZEND_ROPE_END, TMP, CONST|TMPVAR|CV, NUM)
2902{
2903	USE_OPLINE
2904	zend_free_op free_op2;
2905	zend_string **rope;
2906	zval *var, *ret;
2907	uint32_t i;
2908	size_t len = 0;
2909	char *target;
2910
2911	rope = (zend_string**)EX_VAR(opline->op1.var);
2912	if (OP2_TYPE == IS_CONST) {
2913		var = GET_OP2_ZVAL_PTR(BP_VAR_R);
2914		rope[opline->extended_value] = zend_string_copy(Z_STR_P(var));
2915	} else {
2916		var = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2917		if (EXPECTED(Z_TYPE_P(var) == IS_STRING)) {
2918			if (OP2_TYPE == IS_CV) {
2919				rope[opline->extended_value] = zend_string_copy(Z_STR_P(var));
2920			} else {
2921				rope[opline->extended_value] = Z_STR_P(var);
2922			}
2923		} else {
2924			SAVE_OPLINE();
2925			if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var) == IS_UNDEF)) {
2926				GET_OP2_UNDEF_CV(var, BP_VAR_R);
2927			}
2928			rope[opline->extended_value] = _zval_get_string_func(var);
2929			FREE_OP2();
2930			if (UNEXPECTED(EG(exception))) {
2931				for (i = 0; i <= opline->extended_value; i++) {
2932					zend_string_release(rope[i]);
2933				}
2934				HANDLE_EXCEPTION();
2935			}
2936		}
2937	}
2938	for (i = 0; i <= opline->extended_value; i++) {
2939		len += ZSTR_LEN(rope[i]);
2940	}
2941	ret = EX_VAR(opline->result.var);
2942	ZVAL_STR(ret, zend_string_alloc(len, 0));
2943	target = Z_STRVAL_P(ret);
2944	for (i = 0; i <= opline->extended_value; i++) {
2945		memcpy(target, ZSTR_VAL(rope[i]), ZSTR_LEN(rope[i]));
2946		target += ZSTR_LEN(rope[i]);
2947		zend_string_release(rope[i]);
2948	}
2949	*target = '\0';
2950
2951	ZEND_VM_NEXT_OPCODE();
2952}
2953
2954ZEND_VM_HANDLER(109, ZEND_FETCH_CLASS, ANY, CONST|TMPVAR|UNUSED|CV, CLASS_FETCH)
2955{
2956	USE_OPLINE
2957
2958	SAVE_OPLINE();
2959	if (OP2_TYPE == IS_UNUSED) {
2960		Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class(NULL, opline->extended_value);
2961		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2962	} else {
2963		zend_free_op free_op2;
2964		zval *class_name = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2965
2966ZEND_VM_C_LABEL(try_class_name):
2967		if (OP2_TYPE == IS_CONST) {
2968			zend_class_entry *ce = CACHED_PTR(Z_CACHE_SLOT_P(class_name));
2969
2970			if (UNEXPECTED(ce == NULL)) {
2971				ce = zend_fetch_class_by_name(Z_STR_P(class_name), EX_CONSTANT(opline->op2) + 1, opline->extended_value);
2972				CACHE_PTR(Z_CACHE_SLOT_P(class_name), ce);
2973			}
2974			Z_CE_P(EX_VAR(opline->result.var)) = ce;
2975		} else if (Z_TYPE_P(class_name) == IS_OBJECT) {
2976			Z_CE_P(EX_VAR(opline->result.var)) = Z_OBJCE_P(class_name);
2977		} else if (Z_TYPE_P(class_name) == IS_STRING) {
2978			Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class(Z_STR_P(class_name), opline->extended_value);
2979		} else if ((OP2_TYPE & (IS_VAR|IS_CV)) && Z_TYPE_P(class_name) == IS_REFERENCE) {
2980			class_name = Z_REFVAL_P(class_name);
2981			ZEND_VM_C_GOTO(try_class_name);
2982		} else {
2983			if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(class_name) == IS_UNDEF)) {
2984				GET_OP2_UNDEF_CV(class_name, BP_VAR_R);
2985				if (UNEXPECTED(EG(exception) != NULL)) {
2986					HANDLE_EXCEPTION();
2987				}
2988			}
2989			zend_throw_error(NULL, "Class name must be a valid object or a string");
2990		}
2991
2992		FREE_OP2();
2993		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2994	}
2995}
2996
2997ZEND_VM_HANDLER(112, ZEND_INIT_METHOD_CALL, CONST|TMPVAR|UNUSED|THIS|CV, CONST|TMPVAR|CV, NUM)
2998{
2999	USE_OPLINE
3000	zval *function_name;
3001	zend_free_op free_op1, free_op2;
3002	zval *object;
3003	zend_function *fbc;
3004	zend_class_entry *called_scope;
3005	zend_object *obj;
3006	zend_execute_data *call;
3007	uint32_t call_info;
3008
3009	SAVE_OPLINE();
3010
3011	function_name = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
3012
3013	if (OP2_TYPE != IS_CONST &&
3014	    UNEXPECTED(Z_TYPE_P(function_name) != IS_STRING)) {
3015		do {
3016			if ((OP2_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(function_name)) {
3017				function_name = Z_REFVAL_P(function_name);
3018				if (EXPECTED(Z_TYPE_P(function_name) == IS_STRING)) {
3019					break;
3020				}
3021			} else if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(function_name) == IS_UNDEF)) {
3022				GET_OP2_UNDEF_CV(function_name, BP_VAR_R);
3023				if (UNEXPECTED(EG(exception) != NULL)) {
3024					HANDLE_EXCEPTION();
3025				}
3026			}
3027			zend_throw_error(NULL, "Method name must be a string");
3028			FREE_OP2();
3029			FREE_UNFETCHED_OP1();
3030			HANDLE_EXCEPTION();
3031		} while (0);
3032	}
3033
3034	object = GET_OP1_OBJ_ZVAL_PTR_UNDEF(BP_VAR_R);
3035
3036	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(object) == NULL)) {
3037		zend_throw_error(NULL, "Using $this when not in object context");
3038		FREE_OP2();
3039		HANDLE_EXCEPTION();
3040	}
3041
3042	if (OP1_TYPE != IS_UNUSED) {
3043		do {
3044			if (OP1_TYPE == IS_CONST || UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
3045				if ((OP1_TYPE & (IS_VAR|IS_CV)) && EXPECTED(Z_ISREF_P(object))) {
3046					object = Z_REFVAL_P(object);
3047					if (EXPECTED(Z_TYPE_P(object) == IS_OBJECT)) {
3048						break;
3049					}
3050				}
3051				if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(object) == IS_UNDEF)) {
3052					GET_OP1_UNDEF_CV(object, BP_VAR_R);
3053					if (UNEXPECTED(EG(exception) != NULL)) {
3054						FREE_OP2();
3055						HANDLE_EXCEPTION();
3056					}
3057				}
3058				zend_throw_error(NULL, "Call to a member function %s() on %s", Z_STRVAL_P(function_name), zend_get_type_by_const(Z_TYPE_P(object)));
3059				FREE_OP2();
3060				FREE_OP1();
3061				HANDLE_EXCEPTION();
3062			}
3063		} while (0);
3064	}
3065
3066	obj = Z_OBJ_P(object);
3067	called_scope = obj->ce;
3068
3069	if (OP2_TYPE != IS_CONST ||
3070	    UNEXPECTED((fbc = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), called_scope)) == NULL)) {
3071	    zend_object *orig_obj = obj;
3072
3073		if (UNEXPECTED(obj->handlers->get_method == NULL)) {
3074			zend_throw_error(NULL, "Object does not support method calls");
3075			FREE_OP2();
3076			FREE_OP1();
3077			HANDLE_EXCEPTION();
3078		}
3079
3080		/* First, locate the function. */
3081		fbc = obj->handlers->get_method(&obj, Z_STR_P(function_name), ((OP2_TYPE == IS_CONST) ? (EX_CONSTANT(opline->op2) + 1) : NULL));
3082		if (UNEXPECTED(fbc == NULL)) {
3083			if (EXPECTED(!EG(exception))) {
3084				zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(obj->ce->name), Z_STRVAL_P(function_name));
3085			}
3086			FREE_OP2();
3087			FREE_OP1();
3088			HANDLE_EXCEPTION();
3089		}
3090		if (OP2_TYPE == IS_CONST &&
3091		    EXPECTED(fbc->type <= ZEND_USER_FUNCTION) &&
3092		    EXPECTED(!(fbc->common.fn_flags & (ZEND_ACC_CALL_VIA_TRAMPOLINE|ZEND_ACC_NEVER_CACHE))) &&
3093		    EXPECTED(obj == orig_obj)) {
3094			CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), called_scope, fbc);
3095		}
3096	}
3097
3098	call_info = ZEND_CALL_NESTED_FUNCTION;
3099	if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_STATIC) != 0)) {
3100		obj = NULL;
3101	} else if (OP1_TYPE & (IS_VAR|IS_TMP_VAR|IS_CV)) {
3102		/* CV may be changed indirectly (e.g. when it's a reference) */
3103		call_info = ZEND_CALL_NESTED_FUNCTION | ZEND_CALL_RELEASE_THIS;
3104		GC_REFCOUNT(obj)++; /* For $this pointer */
3105	}
3106
3107	call = zend_vm_stack_push_call_frame(call_info,
3108		fbc, opline->extended_value, called_scope, obj);
3109	call->prev_execute_data = EX(call);
3110	EX(call) = call;
3111
3112	FREE_OP2();
3113	FREE_OP1();
3114
3115	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
3116}
3117
3118ZEND_VM_HANDLER(113, ZEND_INIT_STATIC_METHOD_CALL, UNUSED|CLASS_FETCH|CONST|VAR, CONST|TMPVAR|UNUSED|CONSTRUCTOR|CV, NUM)
3119{
3120	USE_OPLINE
3121	zval *function_name;
3122	zend_class_entry *ce;
3123	zend_object *object;
3124	zend_function *fbc;
3125	zend_execute_data *call;
3126
3127	SAVE_OPLINE();
3128
3129	if (OP1_TYPE == IS_CONST) {
3130		/* no function found. try a static method in class */
3131		ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
3132		if (UNEXPECTED(ce == NULL)) {
3133			ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, ZEND_FETCH_CLASS_DEFAULT |  ZEND_FETCH_CLASS_EXCEPTION);
3134			if (UNEXPECTED(ce == NULL)) {
3135				if (UNEXPECTED(EG(exception) != NULL)) {
3136					HANDLE_EXCEPTION();
3137				}
3138				zend_throw_error(NULL, "Class '%s' not found", Z_STRVAL_P(EX_CONSTANT(opline->op1)));
3139				HANDLE_EXCEPTION();
3140			}
3141			CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce);
3142		}
3143	} else if (OP1_TYPE == IS_UNUSED) {
3144		ce = zend_fetch_class(NULL, opline->op1.num);
3145		if (UNEXPECTED(ce == NULL)) {
3146			ZEND_ASSERT(EG(exception));
3147			FREE_UNFETCHED_OP2();
3148			HANDLE_EXCEPTION();
3149		}
3150	} else {
3151		ce = Z_CE_P(EX_VAR(opline->op1.var));
3152	}
3153
3154	if (OP1_TYPE == IS_CONST &&
3155	    OP2_TYPE == IS_CONST &&
3156	    EXPECTED((fbc = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) != NULL)) {
3157		/* nothing to do */
3158	} else if (OP1_TYPE != IS_CONST &&
3159	           OP2_TYPE == IS_CONST &&
3160	           (fbc = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce))) {
3161		/* do nothing */
3162	} else if (OP2_TYPE != IS_UNUSED) {
3163		zend_free_op free_op2;
3164
3165		function_name = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
3166		if (OP2_TYPE != IS_CONST) {
3167			if (UNEXPECTED(Z_TYPE_P(function_name) != IS_STRING)) {
3168				if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(function_name) == IS_UNDEF)) {
3169					GET_OP2_UNDEF_CV(function_name, BP_VAR_R);
3170					if (UNEXPECTED(EG(exception) != NULL)) {
3171						HANDLE_EXCEPTION();
3172					}
3173				}
3174				zend_throw_error(NULL, "Function name must be a string");
3175				FREE_OP2();
3176				HANDLE_EXCEPTION();
3177 			}
3178		}
3179
3180		if (ce->get_static_method) {
3181			fbc = ce->get_static_method(ce, Z_STR_P(function_name));
3182		} else {
3183			fbc = zend_std_get_static_method(ce, Z_STR_P(function_name), ((OP2_TYPE == IS_CONST) ? (EX_CONSTANT(opline->op2) + 1) : NULL));
3184		}
3185		if (UNEXPECTED(fbc == NULL)) {
3186			if (EXPECTED(!EG(exception))) {
3187				zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(ce->name), Z_STRVAL_P(function_name));
3188			}
3189			FREE_OP2();
3190			HANDLE_EXCEPTION();
3191		}
3192		if (OP2_TYPE == IS_CONST &&
3193		    EXPECTED(fbc->type <= ZEND_USER_FUNCTION) &&
3194		    EXPECTED(!(fbc->common.fn_flags & (ZEND_ACC_CALL_VIA_TRAMPOLINE|ZEND_ACC_NEVER_CACHE)))) {
3195			if (OP1_TYPE == IS_CONST) {
3196				CACHE_PTR(Z_CACHE_SLOT_P(function_name), fbc);
3197			} else {
3198				CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), ce, fbc);
3199			}
3200		}
3201		if (OP2_TYPE != IS_CONST) {
3202			FREE_OP2();
3203		}
3204	} else {
3205		if (UNEXPECTED(ce->constructor == NULL)) {
3206			zend_throw_error(NULL, "Cannot call constructor");
3207			HANDLE_EXCEPTION();
3208		}
3209		if (Z_OBJ(EX(This)) && Z_OBJ(EX(This))->ce != ce->constructor->common.scope && (ce->constructor->common.fn_flags & ZEND_ACC_PRIVATE)) {
3210			zend_throw_error(NULL, "Cannot call private %s::__construct()", ZSTR_VAL(ce->name));
3211			HANDLE_EXCEPTION();
3212		}
3213		fbc = ce->constructor;
3214	}
3215
3216	object = NULL;
3217	if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
3218		if (Z_OBJ(EX(This)) && instanceof_function(Z_OBJCE(EX(This)), ce)) {
3219			object = Z_OBJ(EX(This));
3220			ce = object->ce;
3221		} else {
3222			if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
3223				/* Allowed for PHP 4 compatibility. */
3224				zend_error(
3225					E_DEPRECATED,
3226					"Non-static method %s::%s() should not be called statically",
3227					ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3228				if (UNEXPECTED(EG(exception) != NULL)) {
3229					HANDLE_EXCEPTION();
3230				}
3231			} else {
3232				/* An internal function assumes $this is present and won't check that.
3233				 * So PHP would crash by allowing the call. */
3234				zend_throw_error(
3235					zend_ce_error,
3236					"Non-static method %s::%s() cannot be called statically",
3237					ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3238				HANDLE_EXCEPTION();
3239			}
3240		}
3241	}
3242
3243	if (OP1_TYPE == IS_UNUSED) {
3244		/* previous opcode is ZEND_FETCH_CLASS */
3245		if ((opline->op1.num & ZEND_FETCH_CLASS_MASK) == ZEND_FETCH_CLASS_PARENT ||
3246		    (opline->op1.num & ZEND_FETCH_CLASS_MASK) == ZEND_FETCH_CLASS_SELF) {
3247			ce = EX(called_scope);
3248		}
3249	}
3250
3251	call = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
3252		fbc, opline->extended_value, ce, object);
3253	call->prev_execute_data = EX(call);
3254	EX(call) = call;
3255
3256	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
3257}
3258
3259ZEND_VM_HANDLER(59, ZEND_INIT_FCALL_BY_NAME, ANY, CONST, NUM)
3260{
3261	USE_OPLINE
3262	zend_function *fbc;
3263	zval *function_name, *func;
3264	zend_execute_data *call;
3265
3266	fbc = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
3267	if (UNEXPECTED(fbc == NULL)) {
3268		function_name = (zval*)(EX_CONSTANT(opline->op2)+1);
3269		func = zend_hash_find(EG(function_table), Z_STR_P(function_name));
3270		if (UNEXPECTED(func == NULL)) {
3271			SAVE_OPLINE();
3272			zend_throw_error(NULL, "Call to undefined function %s()", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
3273			HANDLE_EXCEPTION();
3274		}
3275		fbc = Z_FUNC_P(func);
3276		CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), fbc);
3277	}
3278	call = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
3279		fbc, opline->extended_value, NULL, NULL);
3280	call->prev_execute_data = EX(call);
3281	EX(call) = call;
3282
3283	ZEND_VM_NEXT_OPCODE();
3284}
3285
3286ZEND_VM_HANDLER(128, ZEND_INIT_DYNAMIC_CALL, ANY, CONST|TMPVAR|CV, NUM)
3287{
3288	USE_OPLINE
3289	zend_function *fbc;
3290	zval *function_name, *func;
3291	zend_string *lcname;
3292	zend_free_op free_op2;
3293	zend_class_entry *called_scope;
3294	zend_object *object;
3295	zend_execute_data *call;
3296	uint32_t call_info = ZEND_CALL_NESTED_FUNCTION;
3297
3298	SAVE_OPLINE();
3299	function_name = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
3300
3301ZEND_VM_C_LABEL(try_function_name):
3302	if (OP2_TYPE != IS_CONST && EXPECTED(Z_TYPE_P(function_name) == IS_STRING)) {
3303		const char *colon;
3304
3305		if ((colon = zend_memrchr(Z_STRVAL_P(function_name), ':', Z_STRLEN_P(function_name))) != NULL &&
3306			colon > Z_STRVAL_P(function_name) &&
3307			*(colon-1) == ':'
3308		) {
3309			zend_string *mname;
3310			size_t cname_length = colon - Z_STRVAL_P(function_name) - 1;
3311			size_t mname_length = Z_STRLEN_P(function_name) - cname_length - (sizeof("::") - 1);
3312
3313			lcname = zend_string_init(Z_STRVAL_P(function_name), cname_length, 0);
3314
3315			object = NULL;
3316			called_scope = zend_fetch_class_by_name(lcname, NULL, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
3317			if (UNEXPECTED(called_scope == NULL)) {
3318				zend_string_release(lcname);
3319				ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
3320			}
3321
3322			mname = zend_string_init(Z_STRVAL_P(function_name) + (cname_length + sizeof("::") - 1), mname_length, 0);
3323
3324			if (called_scope->get_static_method) {
3325				fbc = called_scope->get_static_method(called_scope, mname);
3326			} else {
3327				fbc = zend_std_get_static_method(called_scope, mname, NULL);
3328			}
3329			if (UNEXPECTED(fbc == NULL)) {
3330				if (EXPECTED(!EG(exception))) {
3331					zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(called_scope->name), ZSTR_VAL(mname));
3332				}
3333				zend_string_release(lcname);
3334				zend_string_release(mname);
3335				FREE_OP2();
3336				HANDLE_EXCEPTION();
3337			}
3338
3339			zend_string_release(lcname);
3340			zend_string_release(mname);
3341
3342			if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
3343				if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
3344					zend_error(E_DEPRECATED,
3345						"Non-static method %s::%s() should not be called statically",
3346						ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3347					if (UNEXPECTED(EG(exception) != NULL)) {
3348						HANDLE_EXCEPTION();
3349					}
3350				} else {
3351					zend_throw_error(
3352						zend_ce_error,
3353						"Non-static method %s::%s() cannot be called statically",
3354						ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3355					FREE_OP2();
3356					HANDLE_EXCEPTION();
3357				}
3358			}
3359		} else {
3360			if (Z_STRVAL_P(function_name)[0] == '\\') {
3361				lcname = zend_string_alloc(Z_STRLEN_P(function_name) - 1, 0);
3362				zend_str_tolower_copy(ZSTR_VAL(lcname), Z_STRVAL_P(function_name) + 1, Z_STRLEN_P(function_name) - 1);
3363			} else {
3364				lcname = zend_string_tolower(Z_STR_P(function_name));
3365			}
3366			if (UNEXPECTED((func = zend_hash_find(EG(function_table), lcname)) == NULL)) {
3367				zend_throw_error(NULL, "Call to undefined function %s()", Z_STRVAL_P(function_name));
3368				zend_string_release(lcname);
3369				FREE_OP2();
3370				HANDLE_EXCEPTION();
3371			}
3372			zend_string_release(lcname);
3373
3374			fbc = Z_FUNC_P(func);
3375			called_scope = NULL;
3376			object = NULL;
3377		}
3378		FREE_OP2();
3379	} else if (OP2_TYPE != IS_CONST &&
3380	    EXPECTED(Z_TYPE_P(function_name) == IS_OBJECT) &&
3381		Z_OBJ_HANDLER_P(function_name, get_closure) &&
3382		Z_OBJ_HANDLER_P(function_name, get_closure)(function_name, &called_scope, &fbc, &object) == SUCCESS) {
3383		if (fbc->common.fn_flags & ZEND_ACC_CLOSURE) {
3384			/* Delay closure destruction until its invocation */
3385			ZEND_ASSERT(GC_TYPE((zend_object*)fbc->common.prototype) == IS_OBJECT);
3386			GC_REFCOUNT((zend_object*)fbc->common.prototype)++;
3387			call_info |= ZEND_CALL_CLOSURE;
3388		} else if (object) {
3389			call_info |= ZEND_CALL_RELEASE_THIS;
3390			GC_REFCOUNT(object)++; /* For $this pointer */
3391		}
3392		FREE_OP2();
3393	} else if (EXPECTED(Z_TYPE_P(function_name) == IS_ARRAY) &&
3394			zend_hash_num_elements(Z_ARRVAL_P(function_name)) == 2) {
3395		zval *obj;
3396		zval *method;
3397		obj = zend_hash_index_find(Z_ARRVAL_P(function_name), 0);
3398		method = zend_hash_index_find(Z_ARRVAL_P(function_name), 1);
3399
3400		if (!obj || !method) {
3401			zend_throw_error(NULL, "Array callback has to contain indices 0 and 1");
3402			FREE_OP2();
3403			HANDLE_EXCEPTION();
3404		}
3405
3406		ZVAL_DEREF(obj);
3407		if (Z_TYPE_P(obj) != IS_STRING && Z_TYPE_P(obj) != IS_OBJECT) {
3408			zend_throw_error(NULL, "First array member is not a valid class name or object");
3409			FREE_OP2();
3410			HANDLE_EXCEPTION();
3411		}
3412
3413		ZVAL_DEREF(method);
3414		if (Z_TYPE_P(method) != IS_STRING) {
3415			zend_throw_error(NULL, "Second array member is not a valid method");
3416			FREE_OP2();
3417			HANDLE_EXCEPTION();
3418		}
3419
3420		if (Z_TYPE_P(obj) == IS_STRING) {
3421			object = NULL;
3422			called_scope = zend_fetch_class_by_name(Z_STR_P(obj), NULL, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
3423			if (UNEXPECTED(called_scope == NULL)) {
3424				ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
3425			}
3426
3427			if (called_scope->get_static_method) {
3428				fbc = called_scope->get_static_method(called_scope, Z_STR_P(method));
3429			} else {
3430				fbc = zend_std_get_static_method(called_scope, Z_STR_P(method), NULL);
3431			}
3432			if (UNEXPECTED(fbc == NULL)) {
3433				if (EXPECTED(!EG(exception))) {
3434					zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(called_scope->name), Z_STRVAL_P(method));
3435				}
3436				FREE_OP2();
3437				HANDLE_EXCEPTION();
3438			}
3439			if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
3440				if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
3441					zend_error(E_DEPRECATED,
3442						"Non-static method %s::%s() should not be called statically",
3443						ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3444					if (UNEXPECTED(EG(exception) != NULL)) {
3445						HANDLE_EXCEPTION();
3446					}
3447				} else {
3448					zend_throw_error(
3449						zend_ce_error,
3450						"Non-static method %s::%s() cannot be called statically",
3451						ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3452					FREE_OP2();
3453					HANDLE_EXCEPTION();
3454				}
3455			}
3456		} else {
3457			called_scope = Z_OBJCE_P(obj);
3458			object = Z_OBJ_P(obj);
3459
3460			fbc = Z_OBJ_HT_P(obj)->get_method(&object, Z_STR_P(method), NULL);
3461			if (UNEXPECTED(fbc == NULL)) {
3462				if (EXPECTED(!EG(exception))) {
3463					zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(object->ce->name), Z_STRVAL_P(method));
3464				}
3465				FREE_OP2();
3466				HANDLE_EXCEPTION();
3467			}
3468
3469			if ((fbc->common.fn_flags & ZEND_ACC_STATIC) != 0) {
3470				object = NULL;
3471			} else {
3472				call_info |= ZEND_CALL_RELEASE_THIS;
3473				GC_REFCOUNT(object)++; /* For $this pointer */
3474			}
3475		}
3476		FREE_OP2();
3477	} else if ((OP2_TYPE & (IS_VAR|IS_CV)) && Z_TYPE_P(function_name) == IS_REFERENCE) {
3478		function_name = Z_REFVAL_P(function_name);
3479		ZEND_VM_C_GOTO(try_function_name);
3480	} else {
3481		if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(function_name) == IS_UNDEF)) {
3482			GET_OP2_UNDEF_CV(function_name, BP_VAR_R);
3483			if (UNEXPECTED(EG(exception) != NULL)) {
3484				HANDLE_EXCEPTION();
3485			}
3486		}
3487		zend_throw_error(NULL, "Function name must be a string");
3488		FREE_OP2();
3489		HANDLE_EXCEPTION();
3490	}
3491	call = zend_vm_stack_push_call_frame(call_info,
3492		fbc, opline->extended_value, called_scope, object);
3493	call->prev_execute_data = EX(call);
3494	EX(call) = call;
3495
3496	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
3497}
3498
3499ZEND_VM_HANDLER(118, ZEND_INIT_USER_CALL, CONST, CONST|TMPVAR|CV, NUM)
3500{
3501	USE_OPLINE
3502	zend_free_op free_op2;
3503	zval *function_name;
3504	zend_fcall_info_cache fcc;
3505	char *error = NULL;
3506	zend_function *func;
3507	zend_class_entry *called_scope;
3508	zend_object *object;
3509	zend_execute_data *call;
3510	uint32_t call_info = ZEND_CALL_NESTED_FUNCTION;
3511
3512	SAVE_OPLINE();
3513	function_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
3514	if (zend_is_callable_ex(function_name, NULL, 0, NULL, &fcc, &error)) {
3515		func = fcc.function_handler;
3516		if (func->common.fn_flags & ZEND_ACC_CLOSURE) {
3517			/* Delay closure destruction until its invocation */
3518			if (OP2_TYPE & (IS_VAR|IS_CV)) {
3519				ZVAL_DEREF(function_name);
3520			}
3521			ZEND_ASSERT(GC_TYPE((zend_object*)func->common.prototype) == IS_OBJECT);
3522			GC_REFCOUNT((zend_object*)func->common.prototype)++;
3523			call_info |= ZEND_CALL_CLOSURE;
3524		}
3525		called_scope = fcc.called_scope;
3526		object = fcc.object;
3527		if (object) {
3528			call_info |= ZEND_CALL_RELEASE_THIS;
3529			GC_REFCOUNT(object)++; /* For $this pointer */
3530		}
3531		if (error) {
3532			efree(error);
3533			/* This is the only soft error is_callable() can generate */
3534			zend_error(E_DEPRECATED,
3535				"Non-static method %s::%s() should not be called statically",
3536				ZSTR_VAL(func->common.scope->name), ZSTR_VAL(func->common.function_name));
3537			if (UNEXPECTED(EG(exception) != NULL)) {
3538				HANDLE_EXCEPTION();
3539			}
3540		}
3541	} else {
3542		zend_internal_type_error(EX_USES_STRICT_TYPES(), "%s() expects parameter 1 to be a valid callback, %s", Z_STRVAL_P(EX_CONSTANT(opline->op1)), error);
3543		efree(error);
3544		func = (zend_function*)&zend_pass_function;
3545		called_scope = NULL;
3546		object = NULL;
3547	}
3548
3549	call = zend_vm_stack_push_call_frame(call_info,
3550		func, opline->extended_value, called_scope, object);
3551	call->prev_execute_data = EX(call);
3552	EX(call) = call;
3553
3554	FREE_OP2();
3555	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
3556}
3557
3558ZEND_VM_HANDLER(69, ZEND_INIT_NS_FCALL_BY_NAME, ANY, CONST, NUM)
3559{
3560	USE_OPLINE
3561	zval *func_name;
3562	zval *func;
3563	zend_function *fbc;
3564	zend_execute_data *call;
3565
3566	func_name = EX_CONSTANT(opline->op2) + 1;
3567	fbc = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
3568	if (UNEXPECTED(fbc == NULL)) {
3569		func = zend_hash_find(EG(function_table), Z_STR_P(func_name));
3570		if (func == NULL) {
3571			func_name++;
3572			func = zend_hash_find(EG(function_table), Z_STR_P(func_name));
3573			if (UNEXPECTED(func == NULL)) {
3574				SAVE_OPLINE();
3575				zend_throw_error(NULL, "Call to undefined function %s()", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
3576				HANDLE_EXCEPTION();
3577			}
3578		}
3579		fbc = Z_FUNC_P(func);
3580		CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), fbc);
3581	}
3582
3583	call = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
3584		fbc, opline->extended_value, NULL, NULL);
3585	call->prev_execute_data = EX(call);
3586	EX(call) = call;
3587
3588	ZEND_VM_NEXT_OPCODE();
3589}
3590
3591ZEND_VM_HANDLER(61, ZEND_INIT_FCALL, NUM, CONST, NUM)
3592{
3593	USE_OPLINE
3594	zend_free_op free_op2;
3595	zval *fname = GET_OP2_ZVAL_PTR(BP_VAR_R);
3596	zval *func;
3597	zend_function *fbc;
3598	zend_execute_data *call;
3599
3600	fbc = CACHED_PTR(Z_CACHE_SLOT_P(fname));
3601	if (UNEXPECTED(fbc == NULL)) {
3602		func = zend_hash_find(EG(function_table), Z_STR_P(fname));
3603		if (UNEXPECTED(func == NULL)) {
3604		    SAVE_OPLINE();
3605			zend_throw_error(NULL, "Call to undefined function %s()", Z_STRVAL_P(fname));
3606			HANDLE_EXCEPTION();
3607		}
3608		fbc = Z_FUNC_P(func);
3609		CACHE_PTR(Z_CACHE_SLOT_P(fname), fbc);
3610	}
3611
3612	call = zend_vm_stack_push_call_frame_ex(
3613		opline->op1.num, ZEND_CALL_NESTED_FUNCTION,
3614		fbc, opline->extended_value, NULL, NULL);
3615	call->prev_execute_data = EX(call);
3616	EX(call) = call;
3617
3618	ZEND_VM_NEXT_OPCODE();
3619}
3620
3621ZEND_VM_HANDLER(129, ZEND_DO_ICALL, ANY, ANY, SPEC(RETVAL))
3622{
3623	USE_OPLINE
3624	zend_execute_data *call = EX(call);
3625	zend_function *fbc = call->func;
3626	zval *ret;
3627	zval retval;
3628
3629	SAVE_OPLINE();
3630	EX(call) = call->prev_execute_data;
3631
3632	call->prev_execute_data = execute_data;
3633	EG(current_execute_data) = call;
3634
3635	ret = RETURN_VALUE_USED(opline) ? EX_VAR(opline->result.var) : &retval;
3636	ZVAL_NULL(ret);
3637	Z_VAR_FLAGS_P(ret) = 0;
3638
3639	fbc->internal_function.handler(call, ret);
3640
3641#if ZEND_DEBUG
3642	ZEND_ASSERT(
3643		EG(exception) || !call->func ||
3644		!(call->func->common.fn_flags & ZEND_ACC_HAS_RETURN_TYPE) ||
3645		zend_verify_internal_return_type(call->func, ret));
3646#endif
3647
3648	EG(current_execute_data) = call->prev_execute_data;
3649	zend_vm_stack_free_args(call);
3650	zend_vm_stack_free_call_frame(call);
3651
3652	if (!RETURN_VALUE_USED(opline)) {
3653		zval_ptr_dtor(ret);
3654	}
3655
3656	if (UNEXPECTED(EG(exception) != NULL)) {
3657		zend_throw_exception_internal(NULL);
3658		if (RETURN_VALUE_USED(opline)) {
3659			zval_ptr_dtor(EX_VAR(opline->result.var));
3660		}
3661		HANDLE_EXCEPTION();
3662	}
3663
3664	ZEND_VM_INTERRUPT_CHECK();
3665	ZEND_VM_NEXT_OPCODE();
3666}
3667
3668ZEND_VM_HANDLER(130, ZEND_DO_UCALL, ANY, ANY, SPEC(RETVAL))
3669{
3670	USE_OPLINE
3671	zend_execute_data *call = EX(call);
3672	zend_function *fbc = call->func;
3673	zval *ret;
3674
3675	SAVE_OPLINE();
3676	EX(call) = call->prev_execute_data;
3677
3678	EG(scope) = NULL;
3679	ret = NULL;
3680	call->symbol_table = NULL;
3681	if (RETURN_VALUE_USED(opline)) {
3682		ret = EX_VAR(opline->result.var);
3683		ZVAL_NULL(ret);
3684		Z_VAR_FLAGS_P(ret) = 0;
3685	}
3686
3687	call->prev_execute_data = execute_data;
3688	i_init_func_execute_data(call, &fbc->op_array, ret, 0);
3689
3690	ZEND_VM_ENTER();
3691}
3692
3693ZEND_VM_HANDLER(131, ZEND_DO_FCALL_BY_NAME, ANY, ANY, SPEC(RETVAL))
3694{
3695	USE_OPLINE
3696	zend_execute_data *call = EX(call);
3697	zend_function *fbc = call->func;
3698	zval *ret;
3699
3700	SAVE_OPLINE();
3701	EX(call) = call->prev_execute_data;
3702
3703	if (EXPECTED(fbc->type == ZEND_USER_FUNCTION)) {
3704		EG(scope) = NULL;
3705		if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_GENERATOR) != 0)) {
3706			if (EXPECTED(RETURN_VALUE_USED(opline))) {
3707				ret = EX_VAR(opline->result.var);
3708				zend_generator_create_zval(call, &fbc->op_array, ret);
3709				Z_VAR_FLAGS_P(ret) = 0;
3710			} else {
3711				zend_vm_stack_free_args(call);
3712			}
3713
3714			zend_vm_stack_free_call_frame(call);
3715		} else {
3716			ret = NULL;
3717			call->symbol_table = NULL;
3718			if (RETURN_VALUE_USED(opline)) {
3719				ret = EX_VAR(opline->result.var);
3720				ZVAL_NULL(ret);
3721				Z_VAR_FLAGS_P(ret) = 0;
3722			}
3723
3724			call->prev_execute_data = execute_data;
3725			i_init_func_execute_data(call, &fbc->op_array, ret, 0);
3726
3727			ZEND_VM_ENTER();
3728		}
3729		EG(scope) = EX(func)->op_array.scope;
3730	} else {
3731		zval retval;
3732		ZEND_ASSERT(fbc->type == ZEND_INTERNAL_FUNCTION);
3733
3734		if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_DEPRECATED) != 0)) {
3735			zend_error(E_DEPRECATED, "Function %s%s%s() is deprecated",
3736				fbc->common.scope ? ZSTR_VAL(fbc->common.scope->name) : "",
3737				fbc->common.scope ? "::" : "",
3738				ZSTR_VAL(fbc->common.function_name));
3739			if (UNEXPECTED(EG(exception) != NULL)) {
3740				HANDLE_EXCEPTION();
3741			}
3742		}
3743
3744		call->prev_execute_data = execute_data;
3745		EG(current_execute_data) = call;
3746
3747		if (fbc->common.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) {
3748			uint32_t i;
3749			uint32_t num_args = ZEND_CALL_NUM_ARGS(call);
3750			zval *p = ZEND_CALL_ARG(call, 1);
3751
3752			for (i = 0; i < num_args; ++i) {
3753				if (UNEXPECTED(!zend_verify_internal_arg_type(fbc, i + 1, p))) {
3754					EG(current_execute_data) = call->prev_execute_data;
3755					zend_vm_stack_free_args(call);
3756					zend_vm_stack_free_call_frame(call);
3757					zend_throw_exception_internal(NULL);
3758					HANDLE_EXCEPTION();
3759				}
3760				p++;
3761			}
3762		}
3763
3764		ret = RETURN_VALUE_USED(opline) ? EX_VAR(opline->result.var) : &retval;
3765		ZVAL_NULL(ret);
3766		Z_VAR_FLAGS_P(ret) = (fbc->common.fn_flags & ZEND_ACC_RETURN_REFERENCE) != 0 ? IS_VAR_RET_REF : 0;
3767
3768		fbc->internal_function.handler(call, ret);
3769
3770#if ZEND_DEBUG
3771		ZEND_ASSERT(
3772			EG(exception) || !call->func ||
3773			!(call->func->common.fn_flags & ZEND_ACC_HAS_RETURN_TYPE) ||
3774			zend_verify_internal_return_type(call->func, ret));
3775#endif
3776
3777		EG(current_execute_data) = call->prev_execute_data;
3778		zend_vm_stack_free_args(call);
3779		zend_vm_stack_free_call_frame(call);
3780
3781		if (!RETURN_VALUE_USED(opline)) {
3782			zval_ptr_dtor(ret);
3783		}
3784	}
3785
3786	if (UNEXPECTED(EG(exception) != NULL)) {
3787		zend_throw_exception_internal(NULL);
3788		if (RETURN_VALUE_USED(opline)) {
3789			zval_ptr_dtor(EX_VAR(opline->result.var));
3790		}
3791		HANDLE_EXCEPTION();
3792	}
3793	ZEND_VM_INTERRUPT_CHECK();
3794	ZEND_VM_NEXT_OPCODE();
3795}
3796
3797ZEND_VM_HANDLER(60, ZEND_DO_FCALL, ANY, ANY, SPEC(RETVAL))
3798{
3799	USE_OPLINE
3800	zend_execute_data *call = EX(call);
3801	zend_function *fbc = call->func;
3802	zend_object *object;
3803	zval *ret;
3804
3805	SAVE_OPLINE();
3806	EX(call) = call->prev_execute_data;
3807	if (UNEXPECTED((fbc->common.fn_flags & (ZEND_ACC_ABSTRACT|ZEND_ACC_DEPRECATED)) != 0)) {
3808		if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_ABSTRACT) != 0)) {
3809			zend_throw_error(NULL, "Cannot call abstract method %s::%s()", ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3810			HANDLE_EXCEPTION();
3811		}
3812		if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_DEPRECATED) != 0)) {
3813			zend_error(E_DEPRECATED, "Function %s%s%s() is deprecated",
3814				fbc->common.scope ? ZSTR_VAL(fbc->common.scope->name) : "",
3815				fbc->common.scope ? "::" : "",
3816				ZSTR_VAL(fbc->common.function_name));
3817			if (UNEXPECTED(EG(exception) != NULL)) {
3818				HANDLE_EXCEPTION();
3819			}
3820		}
3821	}
3822
3823	LOAD_OPLINE();
3824
3825	if (EXPECTED(fbc->type == ZEND_USER_FUNCTION)) {
3826		EG(scope) = fbc->common.scope;
3827		if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_GENERATOR) != 0)) {
3828			if (EXPECTED(RETURN_VALUE_USED(opline))) {
3829				ret = EX_VAR(opline->result.var);
3830				zend_generator_create_zval(call, &fbc->op_array, ret);
3831				Z_VAR_FLAGS_P(ret) = 0;
3832			} else {
3833				if (UNEXPECTED(ZEND_CALL_INFO(call) & ZEND_CALL_CLOSURE)) {
3834					OBJ_RELEASE((zend_object*)fbc->op_array.prototype);
3835				}
3836				zend_vm_stack_free_args(call);
3837			}
3838		} else {
3839			ret = NULL;
3840			call->symbol_table = NULL;
3841			if (RETURN_VALUE_USED(opline)) {
3842				ret = EX_VAR(opline->result.var);
3843				ZVAL_NULL(ret);
3844				Z_VAR_FLAGS_P(ret) = 0;
3845			}
3846
3847			call->prev_execute_data = execute_data;
3848			i_init_func_execute_data(call, &fbc->op_array, ret, 1);
3849
3850			if (EXPECTED(zend_execute_ex == execute_ex)) {
3851				ZEND_VM_ENTER();
3852			} else {
3853				ZEND_ADD_CALL_FLAG(call, ZEND_CALL_TOP);
3854				zend_execute_ex(call);
3855			}
3856		}
3857	} else if (EXPECTED(fbc->type < ZEND_USER_FUNCTION)) {
3858		int should_change_scope = 0;
3859		zval retval;
3860
3861		if (fbc->common.scope) {
3862			should_change_scope = 1;
3863			EG(scope) = fbc->common.scope;
3864		}
3865
3866		call->prev_execute_data = execute_data;
3867		EG(current_execute_data) = call;
3868
3869		if (fbc->common.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) {
3870			uint32_t i;
3871			uint32_t num_args = ZEND_CALL_NUM_ARGS(call);
3872			zval *p = ZEND_CALL_ARG(call, 1);
3873
3874			for (i = 0; i < num_args; ++i) {
3875				if (UNEXPECTED(!zend_verify_internal_arg_type(fbc, i + 1, p))) {
3876					EG(current_execute_data) = call->prev_execute_data;
3877					zend_vm_stack_free_args(call);
3878					if (RETURN_VALUE_USED(opline)) {
3879						ZVAL_UNDEF(EX_VAR(opline->result.var));
3880					}
3881					if (UNEXPECTED(should_change_scope)) {
3882						ZEND_VM_C_GOTO(fcall_end_change_scope);
3883					} else {
3884						ZEND_VM_C_GOTO(fcall_end);
3885					}
3886				}
3887				p++;
3888			}
3889		}
3890
3891		ret = RETURN_VALUE_USED(opline) ? EX_VAR(opline->result.var) : &retval;
3892		ZVAL_NULL(ret);
3893		Z_VAR_FLAGS_P(ret) = (fbc->common.fn_flags & ZEND_ACC_RETURN_REFERENCE) != 0 ? IS_VAR_RET_REF : 0;
3894
3895		if (!zend_execute_internal) {
3896			/* saves one function call if zend_execute_internal is not used */
3897			fbc->internal_function.handler(call, ret);
3898		} else {
3899			zend_execute_internal(call, ret);
3900		}
3901
3902#if ZEND_DEBUG
3903		ZEND_ASSERT(
3904			EG(exception) || !call->func ||
3905			!(call->func->common.fn_flags & ZEND_ACC_HAS_RETURN_TYPE) ||
3906			zend_verify_internal_return_type(call->func, ret));
3907#endif
3908
3909		EG(current_execute_data) = call->prev_execute_data;
3910		zend_vm_stack_free_args(call);
3911
3912		if (!RETURN_VALUE_USED(opline)) {
3913			zval_ptr_dtor(ret);
3914		}
3915
3916		if (UNEXPECTED(should_change_scope)) {
3917			ZEND_VM_C_GOTO(fcall_end_change_scope);
3918		} else {
3919			ZEND_VM_C_GOTO(fcall_end);
3920		}
3921	} else { /* ZEND_OVERLOADED_FUNCTION */
3922		zval retval;
3923		/* Not sure what should be done here if it's a static method */
3924		object = Z_OBJ(call->This);
3925		if (UNEXPECTED(object == NULL)) {
3926			zend_vm_stack_free_args(call);
3927			if (fbc->type == ZEND_OVERLOADED_FUNCTION_TEMPORARY) {
3928				zend_string_release(fbc->common.function_name);
3929			}
3930			efree(fbc);
3931			zend_vm_stack_free_call_frame(call);
3932
3933			zend_throw_error(NULL, "Cannot call overloaded function for non-object");
3934			HANDLE_EXCEPTION();
3935		}
3936
3937		EG(scope) = fbc->common.scope;
3938
3939		ret = RETURN_VALUE_USED(opline) ? EX_VAR(opline->result.var) : &retval;
3940		ZVAL_NULL(ret);
3941
3942		call->prev_execute_data = execute_data;
3943		EG(current_execute_data) = call;
3944		object->handlers->call_method(fbc->common.function_name, object, call, ret);
3945		EG(current_execute_data) = call->prev_execute_data;
3946
3947		zend_vm_stack_free_args(call);
3948
3949		if (fbc->type == ZEND_OVERLOADED_FUNCTION_TEMPORARY) {
3950			zend_string_release(fbc->common.function_name);
3951		}
3952		efree(fbc);
3953
3954		if (!RETURN_VALUE_USED(opline)) {
3955			zval_ptr_dtor(ret);
3956		} else {
3957			Z_VAR_FLAGS_P(ret) = 0;
3958		}
3959	}
3960
3961ZEND_VM_C_LABEL(fcall_end_change_scope):
3962	if (UNEXPECTED(ZEND_CALL_INFO(call) & ZEND_CALL_RELEASE_THIS)) {
3963		object = Z_OBJ(call->This);
3964#if 0
3965		if (UNEXPECTED(EG(exception) != NULL) && (opline->op1.num & ZEND_CALL_CTOR)) {
3966#else
3967		if (UNEXPECTED(EG(exception) != NULL) && (ZEND_CALL_INFO(call) & ZEND_CALL_CTOR)) {
3968#endif
3969			GC_REFCOUNT(object)--;
3970			if (GC_REFCOUNT(object) == 1) {
3971				zend_object_store_ctor_failed(object);
3972			}
3973		}
3974		OBJ_RELEASE(object);
3975	}
3976	EG(scope) = EX(func)->op_array.scope;
3977
3978ZEND_VM_C_LABEL(fcall_end):
3979	zend_vm_stack_free_call_frame(call);
3980	if (UNEXPECTED(EG(exception) != NULL)) {
3981		zend_throw_exception_internal(NULL);
3982		if (RETURN_VALUE_USED(opline)) {
3983			zval_ptr_dtor(EX_VAR(opline->result.var));
3984		}
3985		HANDLE_EXCEPTION();
3986	}
3987
3988	ZEND_VM_INTERRUPT_CHECK();
3989	ZEND_VM_NEXT_OPCODE();
3990}
3991
3992ZEND_VM_HANDLER(124, ZEND_VERIFY_RETURN_TYPE, CONST|TMP|VAR|UNUSED|CV, UNUSED)
3993{
3994	USE_OPLINE
3995
3996	SAVE_OPLINE();
3997	if (OP1_TYPE == IS_UNUSED) {
3998		zend_verify_missing_return_type(EX(func), CACHE_ADDR(opline->op2.num));
3999	} else {
4000/* prevents "undefined variable opline" errors */
4001#if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
4002		zval *retval_ref, *retval_ptr;
4003		zend_free_op free_op1;
4004		zend_arg_info *ret_info = EX(func)->common.arg_info - 1;
4005
4006		retval_ref = retval_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
4007
4008		if (OP1_TYPE == IS_CONST) {
4009			ZVAL_COPY(EX_VAR(opline->result.var), retval_ptr);
4010			retval_ref = retval_ptr = EX_VAR(opline->result.var);
4011		} else if (OP1_TYPE == IS_VAR) {
4012			if (UNEXPECTED(Z_TYPE_P(retval_ptr) == IS_INDIRECT)) {
4013				retval_ptr = Z_INDIRECT_P(retval_ptr);
4014			}
4015			ZVAL_DEREF(retval_ptr);
4016		} else if (OP1_TYPE == IS_CV) {
4017			ZVAL_DEREF(retval_ptr);
4018		}
4019
4020		if (UNEXPECTED(!ret_info->class_name
4021			&& ret_info->type_hint != IS_CALLABLE
4022			&& !ZEND_SAME_FAKE_TYPE(ret_info->type_hint, Z_TYPE_P(retval_ptr))
4023			&& !(EX(func)->op_array.fn_flags & ZEND_ACC_RETURN_REFERENCE)
4024			&& retval_ref != retval_ptr)
4025		) {
4026			/* A cast might happen - unwrap the reference if this is a by-value return */
4027			if (Z_REFCOUNT_P(retval_ref) == 1) {
4028				ZVAL_UNREF(retval_ref);
4029			} else {
4030				Z_DELREF_P(retval_ref);
4031				ZVAL_COPY(retval_ref, retval_ptr);
4032			}
4033			retval_ptr = retval_ref;
4034		}
4035		zend_verify_return_type(EX(func), retval_ptr, CACHE_ADDR(opline->op2.num));
4036
4037		if (UNEXPECTED(EG(exception) != NULL)) {
4038			if (OP1_TYPE == IS_CONST) {
4039				zval_ptr_dtor_nogc(retval_ptr);
4040			}
4041		}
4042#endif
4043	}
4044	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4045}
4046
4047ZEND_VM_HANDLER(62, ZEND_RETURN, CONST|TMP|VAR|CV, ANY)
4048{
4049	USE_OPLINE
4050	zval *retval_ptr;
4051	zend_free_op free_op1;
4052
4053	retval_ptr = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4054	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(retval_ptr) == IS_UNDEF)) {
4055		SAVE_OPLINE();
4056		retval_ptr = GET_OP1_UNDEF_CV(retval_ptr, BP_VAR_R);
4057		if (EX(return_value)) {
4058			ZVAL_NULL(EX(return_value));
4059		}
4060	} else if (!EX(return_value)) {
4061		if (OP1_TYPE == IS_VAR || OP1_TYPE == IS_TMP_VAR ) {
4062			if (Z_REFCOUNTED_P(free_op1) && !Z_DELREF_P(free_op1)) {
4063				SAVE_OPLINE();
4064				zval_dtor_func_for_ptr(Z_COUNTED_P(free_op1));
4065			}
4066		}
4067	} else {
4068		if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
4069			ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
4070			if (OP1_TYPE == IS_CONST) {
4071				if (UNEXPECTED(Z_OPT_COPYABLE_P(EX(return_value)))) {
4072					zval_copy_ctor_func(EX(return_value));
4073				}
4074			}
4075		} else if (OP1_TYPE == IS_CV) {
4076			ZVAL_DEREF(retval_ptr);
4077			ZVAL_COPY(EX(return_value), retval_ptr);
4078		} else /* if (OP1_TYPE == IS_VAR) */ {
4079			if (UNEXPECTED(Z_ISREF_P(retval_ptr))) {
4080				zend_refcounted *ref = Z_COUNTED_P(retval_ptr);
4081
4082				retval_ptr = Z_REFVAL_P(retval_ptr);
4083				ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
4084				if (UNEXPECTED(--GC_REFCOUNT(ref) == 0)) {
4085					efree_size(ref, sizeof(zend_reference));
4086				} else if (Z_OPT_REFCOUNTED_P(retval_ptr)) {
4087					Z_ADDREF_P(retval_ptr);
4088				}
4089			} else {
4090				ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
4091			}
4092		}
4093	}
4094	ZEND_VM_DISPATCH_TO_HELPER(zend_leave_helper);
4095}
4096
4097ZEND_VM_HANDLER(111, ZEND_RETURN_BY_REF, CONST|TMP|VAR|CV, ANY, SRC)
4098{
4099	USE_OPLINE
4100	zval *retval_ptr;
4101	zend_free_op free_op1;
4102
4103	SAVE_OPLINE();
4104
4105	do {
4106		if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR ||
4107		    (OP1_TYPE == IS_VAR && opline->extended_value == ZEND_RETURNS_VALUE)) {
4108			/* Not supposed to happen, but we'll allow it */
4109			zend_error(E_NOTICE, "Only variable references should be returned by reference");
4110
4111			retval_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
4112			if (!EX(return_value)) {
4113				if (OP1_TYPE == IS_TMP_VAR) {
4114					FREE_OP1();
4115				}
4116			} else {
4117				ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
4118				Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
4119				if (OP1_TYPE != IS_TMP_VAR) {
4120					zval_opt_copy_ctor_no_imm(EX(return_value));
4121				}
4122			}
4123			break;
4124		}
4125
4126		retval_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
4127
4128		if (OP1_TYPE == IS_VAR) {
4129			if (retval_ptr == &EG(uninitialized_zval) ||
4130			    (opline->extended_value == ZEND_RETURNS_FUNCTION &&
4131			     !(Z_VAR_FLAGS_P(retval_ptr) & IS_VAR_RET_REF))) {
4132				zend_error(E_NOTICE, "Only variable references should be returned by reference");
4133				if (EX(return_value)) {
4134					ZVAL_NEW_REF(EX(return_value), retval_ptr);
4135					Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
4136					if (Z_REFCOUNTED_P(retval_ptr)) Z_ADDREF_P(retval_ptr);
4137				}
4138				break;
4139			}
4140		}
4141
4142		if (EX(return_value)) {
4143			ZVAL_MAKE_REF(retval_ptr);
4144			Z_ADDREF_P(retval_ptr);
4145			ZVAL_REF(EX(return_value), Z_REF_P(retval_ptr));
4146			Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
4147		}
4148	} while (0);
4149
4150	FREE_OP1_VAR_PTR();
4151	ZEND_VM_DISPATCH_TO_HELPER(zend_leave_helper);
4152}
4153
4154ZEND_VM_HANDLER(161, ZEND_GENERATOR_RETURN, CONST|TMP|VAR|CV, ANY)
4155{
4156	USE_OPLINE
4157	zval *retval;
4158	zend_free_op free_op1;
4159
4160	zend_generator *generator = zend_get_running_generator(execute_data);
4161
4162	SAVE_OPLINE();
4163	retval = GET_OP1_ZVAL_PTR(BP_VAR_R);
4164
4165	/* Copy return value into generator->retval */
4166	if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
4167		ZVAL_COPY_VALUE(&generator->retval, retval);
4168		if (OP1_TYPE == IS_CONST) {
4169			if (UNEXPECTED(Z_OPT_COPYABLE(generator->retval))) {
4170				zval_copy_ctor_func(&generator->retval);
4171			}
4172		}
4173	} else if (OP1_TYPE == IS_CV) {
4174		ZVAL_DEREF(retval);
4175		ZVAL_COPY(&generator->retval, retval);
4176	} else /* if (OP1_TYPE == IS_VAR) */ {
4177		if (UNEXPECTED(Z_ISREF_P(retval))) {
4178			zend_refcounted *ref = Z_COUNTED_P(retval);
4179
4180			retval = Z_REFVAL_P(retval);
4181			ZVAL_COPY_VALUE(&generator->retval, retval);
4182			if (UNEXPECTED(--GC_REFCOUNT(ref) == 0)) {
4183				efree_size(ref, sizeof(zend_reference));
4184			} else if (Z_OPT_REFCOUNTED_P(retval)) {
4185				Z_ADDREF_P(retval);
4186			}
4187		} else {
4188			ZVAL_COPY_VALUE(&generator->retval, retval);
4189		}
4190	}
4191
4192	/* Close the generator to free up resources */
4193	zend_generator_close(generator, 1);
4194
4195	/* Pass execution back to handling code */
4196	ZEND_VM_RETURN();
4197}
4198
4199ZEND_VM_HANDLER(108, ZEND_THROW, CONST|TMP|VAR|CV, ANY)
4200{
4201	USE_OPLINE
4202	zval *value;
4203	zend_free_op free_op1;
4204
4205	SAVE_OPLINE();
4206	value = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4207
4208	do {
4209		if (OP1_TYPE == IS_CONST || UNEXPECTED(Z_TYPE_P(value) != IS_OBJECT)) {
4210			if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(value)) {
4211				value = Z_REFVAL_P(value);
4212				if (EXPECTED(Z_TYPE_P(value) == IS_OBJECT)) {
4213					break;
4214				}
4215			}
4216			if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
4217				GET_OP1_UNDEF_CV(value, BP_VAR_R);
4218				if (UNEXPECTED(EG(exception) != NULL)) {
4219					HANDLE_EXCEPTION();
4220				}
4221			}
4222			zend_throw_error(NULL, "Can only throw objects");
4223			FREE_OP1();
4224			HANDLE_EXCEPTION();
4225		}
4226	} while (0);
4227
4228	zend_exception_save();
4229	if (OP1_TYPE != IS_TMP_VAR) {
4230		if (Z_REFCOUNTED_P(value)) Z_ADDREF_P(value);
4231	}
4232
4233	zend_throw_exception_object(value);
4234	zend_exception_restore();
4235	FREE_OP1_IF_VAR();
4236	HANDLE_EXCEPTION();
4237}
4238
4239ZEND_VM_HANDLER(107, ZEND_CATCH, CONST, CV, JMP_ADDR)
4240{
4241	USE_OPLINE
4242	zend_class_entry *ce, *catch_ce;
4243	zend_object *exception;
4244
4245	SAVE_OPLINE();
4246	/* Check whether an exception has been thrown, if not, jump over code */
4247	zend_exception_restore();
4248	if (EG(exception) == NULL) {
4249		ZEND_VM_SET_RELATIVE_OPCODE(opline, opline->extended_value);
4250		ZEND_VM_CONTINUE();
4251	}
4252	catch_ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
4253	if (UNEXPECTED(catch_ce == NULL)) {
4254		catch_ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, ZEND_FETCH_CLASS_NO_AUTOLOAD);
4255
4256		CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), catch_ce);
4257	}
4258	ce = EG(exception)->ce;
4259
4260#ifdef HAVE_DTRACE
4261	if (DTRACE_EXCEPTION_CAUGHT_ENABLED()) {
4262		DTRACE_EXCEPTION_CAUGHT((char *)ce->name);
4263	}
4264#endif /* HAVE_DTRACE */
4265
4266	if (ce != catch_ce) {
4267		if (!catch_ce || !instanceof_function(ce, catch_ce)) {
4268			if (opline->result.num) {
4269				zend_throw_exception_internal(NULL);
4270				HANDLE_EXCEPTION();
4271			}
4272			ZEND_VM_SET_RELATIVE_OPCODE(opline, opline->extended_value);
4273			ZEND_VM_CONTINUE();
4274		}
4275	}
4276
4277	exception = EG(exception);
4278	zval_ptr_dtor(EX_VAR(opline->op2.var));
4279	ZVAL_OBJ(EX_VAR(opline->op2.var), EG(exception));
4280	if (UNEXPECTED(EG(exception) != exception)) {
4281		GC_REFCOUNT(EG(exception))++;
4282		HANDLE_EXCEPTION();
4283	} else {
4284		EG(exception) = NULL;
4285		ZEND_VM_NEXT_OPCODE();
4286	}
4287}
4288
4289ZEND_VM_HANDLER(65, ZEND_SEND_VAL, CONST|TMP, NUM)
4290{
4291	USE_OPLINE
4292	zval *value, *arg;
4293	zend_free_op free_op1;
4294
4295	value = GET_OP1_ZVAL_PTR(BP_VAR_R);
4296	arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4297	ZVAL_COPY_VALUE(arg, value);
4298	if (OP1_TYPE == IS_CONST) {
4299		if (UNEXPECTED(Z_OPT_COPYABLE_P(arg))) {
4300			zval_copy_ctor_func(arg);
4301		}
4302	}
4303	ZEND_VM_NEXT_OPCODE();
4304}
4305
4306ZEND_VM_HANDLER(116, ZEND_SEND_VAL_EX, CONST|TMP, NUM, SPEC(QUICK_ARG))
4307{
4308	USE_OPLINE
4309	zval *value, *arg;
4310	zend_free_op free_op1;
4311	uint32_t arg_num = opline->op2.num;
4312
4313	if (EXPECTED(arg_num <= MAX_ARG_FLAG_NUM)) {
4314		if (QUICK_ARG_MUST_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4315			ZEND_VM_C_GOTO(send_val_by_ref);
4316		}
4317	} else if (ARG_MUST_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4318ZEND_VM_C_LABEL(send_val_by_ref):
4319		SAVE_OPLINE();
4320		zend_throw_error(NULL, "Cannot pass parameter %d by reference", arg_num);
4321		FREE_UNFETCHED_OP1();
4322		arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4323		ZVAL_UNDEF(arg);
4324		HANDLE_EXCEPTION();
4325	}
4326	value = GET_OP1_ZVAL_PTR(BP_VAR_R);
4327	arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4328	ZVAL_COPY_VALUE(arg, value);
4329	if (OP1_TYPE == IS_CONST) {
4330		if (UNEXPECTED(Z_OPT_COPYABLE_P(arg))) {
4331			zval_copy_ctor_func(arg);
4332		}
4333	}
4334	ZEND_VM_NEXT_OPCODE();
4335}
4336
4337ZEND_VM_HANDLER(117, ZEND_SEND_VAR, VAR|CV, NUM)
4338{
4339	USE_OPLINE
4340	zval *varptr, *arg;
4341	zend_free_op free_op1;
4342
4343	varptr = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4344	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(varptr) == IS_UNDEF)) {
4345		SAVE_OPLINE();
4346		GET_OP1_UNDEF_CV(varptr, BP_VAR_R);
4347		arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4348		ZVAL_NULL(arg);
4349		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4350	}
4351
4352	arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4353
4354	if (OP1_TYPE == IS_CV) {
4355		ZVAL_OPT_DEREF(varptr);
4356		ZVAL_COPY(arg, varptr);
4357	} else /* if (OP1_TYPE == IS_VAR) */ {
4358		if (UNEXPECTED(Z_ISREF_P(varptr))) {
4359			zend_refcounted *ref = Z_COUNTED_P(varptr);
4360
4361			varptr = Z_REFVAL_P(varptr);
4362			ZVAL_COPY_VALUE(arg, varptr);
4363			if (UNEXPECTED(--GC_REFCOUNT(ref) == 0)) {
4364				efree_size(ref, sizeof(zend_reference));
4365			} else if (Z_OPT_REFCOUNTED_P(arg)) {
4366				Z_ADDREF_P(arg);
4367			}
4368		} else {
4369			ZVAL_COPY_VALUE(arg, varptr);
4370		}
4371	}
4372
4373	ZEND_VM_NEXT_OPCODE();
4374}
4375
4376ZEND_VM_HANDLER(106, ZEND_SEND_VAR_NO_REF, VAR, NUM, SEND)
4377{
4378	USE_OPLINE
4379	zend_free_op free_op1;
4380	zval *varptr, *arg;
4381
4382	if (!(opline->extended_value & ZEND_ARG_COMPILE_TIME_BOUND)) {
4383		if (!ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4384			ZEND_VM_DISPATCH_TO_HANDLER(ZEND_SEND_VAR);
4385		}
4386	}
4387
4388	varptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
4389
4390	if ((!(opline->extended_value & ZEND_ARG_SEND_FUNCTION) ||
4391	     (Z_VAR_FLAGS_P(varptr) & IS_VAR_RET_REF)) &&
4392	    (Z_ISREF_P(varptr) || Z_TYPE_P(varptr) == IS_OBJECT)) {
4393
4394		ZVAL_MAKE_REF(varptr);
4395	} else {
4396		if ((opline->extended_value & ZEND_ARG_COMPILE_TIME_BOUND) ?
4397			!(opline->extended_value & ZEND_ARG_SEND_SILENT) :
4398			!ARG_MAY_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4399			SAVE_OPLINE();
4400			zend_error(E_NOTICE, "Only variables should be passed by reference");
4401			arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4402			ZVAL_COPY_VALUE(arg, varptr);
4403			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4404		}
4405	}
4406
4407	arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4408	ZVAL_COPY_VALUE(arg, varptr);
4409
4410	ZEND_VM_NEXT_OPCODE();
4411}
4412
4413ZEND_VM_HANDLER(67, ZEND_SEND_REF, VAR|CV, NUM)
4414{
4415	USE_OPLINE
4416	zend_free_op free_op1;
4417	zval *varptr, *arg;
4418
4419	SAVE_OPLINE();
4420	varptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
4421
4422	arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4423	if (OP1_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(varptr))) {
4424		ZVAL_NEW_REF(arg, &EG(uninitialized_zval));
4425		ZEND_VM_NEXT_OPCODE();
4426	}
4427
4428	if (Z_ISREF_P(varptr)) {
4429		Z_ADDREF_P(varptr);
4430		ZVAL_COPY_VALUE(arg, varptr);
4431	} else {
4432		ZVAL_NEW_REF(arg, varptr);
4433		Z_ADDREF_P(arg);
4434		ZVAL_REF(varptr, Z_REF_P(arg));
4435	}
4436
4437	FREE_OP1_VAR_PTR();
4438	ZEND_VM_NEXT_OPCODE();
4439}
4440
4441ZEND_VM_HANDLER(66, ZEND_SEND_VAR_EX, VAR|CV, NUM, SPEC(QUICK_ARG))
4442{
4443	USE_OPLINE
4444	zval *varptr, *arg;
4445	zend_free_op free_op1;
4446	uint32_t arg_num = opline->op2.num;
4447
4448	if (EXPECTED(arg_num <= MAX_ARG_FLAG_NUM)) {
4449		if (QUICK_ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4450			ZEND_VM_C_GOTO(send_var_by_ref);
4451		}
4452	} else if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4453ZEND_VM_C_LABEL(send_var_by_ref):
4454		ZEND_VM_DISPATCH_TO_HANDLER(ZEND_SEND_REF);
4455	}
4456
4457	varptr = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4458	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(varptr) == IS_UNDEF)) {
4459		SAVE_OPLINE();
4460		GET_OP1_UNDEF_CV(varptr, BP_VAR_R);
4461		arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4462		ZVAL_NULL(arg);
4463		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4464	}
4465
4466	arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4467
4468	if (OP1_TYPE == IS_CV) {
4469		ZVAL_OPT_DEREF(varptr);
4470		ZVAL_COPY(arg, varptr);
4471	} else /* if (OP1_TYPE == IS_VAR) */ {
4472		if (UNEXPECTED(Z_ISREF_P(varptr))) {
4473			zend_refcounted *ref = Z_COUNTED_P(varptr);
4474
4475			varptr = Z_REFVAL_P(varptr);
4476			ZVAL_COPY_VALUE(arg, varptr);
4477			if (UNEXPECTED(--GC_REFCOUNT(ref) == 0)) {
4478				efree_size(ref, sizeof(zend_reference));
4479			} else if (Z_OPT_REFCOUNTED_P(arg)) {
4480				Z_ADDREF_P(arg);
4481			}
4482		} else {
4483			ZVAL_COPY_VALUE(arg, varptr);
4484		}
4485	}
4486
4487	ZEND_VM_NEXT_OPCODE();
4488}
4489
4490ZEND_VM_HANDLER(165, ZEND_SEND_UNPACK, ANY, ANY)
4491{
4492	USE_OPLINE
4493	zend_free_op free_op1;
4494	zval *args;
4495	int arg_num;
4496
4497	SAVE_OPLINE();
4498	args = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4499	arg_num = ZEND_CALL_NUM_ARGS(EX(call)) + 1;
4500
4501ZEND_VM_C_LABEL(send_again):
4502	if (EXPECTED(Z_TYPE_P(args) == IS_ARRAY)) {
4503		HashTable *ht = Z_ARRVAL_P(args);
4504		zval *arg, *top;
4505		zend_string *name;
4506
4507		zend_vm_stack_extend_call_frame(&EX(call), arg_num - 1, zend_hash_num_elements(ht));
4508
4509		if (OP1_TYPE != IS_CONST && OP1_TYPE != IS_TMP_VAR && Z_IMMUTABLE_P(args)) {
4510			uint32_t i;
4511			int separate = 0;
4512
4513			/* check if any of arguments are going to be passed by reference */
4514			for (i = 0; i < zend_hash_num_elements(ht); i++) {
4515				if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num + i)) {
4516					separate = 1;
4517					break;
4518				}
4519			}
4520			if (separate) {
4521				zval_copy_ctor(args);
4522				ht = Z_ARRVAL_P(args);
4523			}
4524		}
4525
4526		ZEND_HASH_FOREACH_STR_KEY_VAL(ht, name, arg) {
4527			if (name) {
4528				zend_throw_error(NULL, "Cannot unpack array with string keys");
4529				FREE_OP1();
4530				HANDLE_EXCEPTION();
4531			}
4532
4533			top = ZEND_CALL_ARG(EX(call), arg_num);
4534			if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4535				if (!Z_IMMUTABLE_P(args)) {
4536					ZVAL_MAKE_REF(arg);
4537					Z_ADDREF_P(arg);
4538					ZVAL_REF(top, Z_REF_P(arg));
4539				} else {
4540					ZVAL_DUP(top, arg);
4541				}
4542			} else if (Z_ISREF_P(arg)) {
4543				ZVAL_COPY(top, Z_REFVAL_P(arg));
4544			} else {
4545				ZVAL_COPY(top, arg);
4546			}
4547
4548			ZEND_CALL_NUM_ARGS(EX(call))++;
4549			arg_num++;
4550		} ZEND_HASH_FOREACH_END();
4551
4552	} else if (EXPECTED(Z_TYPE_P(args) == IS_OBJECT)) {
4553		zend_class_entry *ce = Z_OBJCE_P(args);
4554		zend_object_iterator *iter;
4555
4556		if (!ce || !ce->get_iterator) {
4557			zend_error(E_WARNING, "Only arrays and Traversables can be unpacked");
4558		} else {
4559
4560			iter = ce->get_iterator(ce, args, 0);
4561			if (UNEXPECTED(!iter)) {
4562				FREE_OP1();
4563				if (!EG(exception)) {
4564					zend_throw_exception_ex(
4565						NULL, 0, "Object of type %s did not create an Iterator", ZSTR_VAL(ce->name)
4566					);
4567				}
4568				HANDLE_EXCEPTION();
4569			}
4570
4571			if (iter->funcs->rewind) {
4572				iter->funcs->rewind(iter);
4573				if (UNEXPECTED(EG(exception) != NULL)) {
4574					ZEND_VM_C_GOTO(unpack_iter_dtor);
4575				}
4576			}
4577
4578			for (; iter->funcs->valid(iter) == SUCCESS; ++arg_num) {
4579				zval *arg, *top;
4580
4581				if (UNEXPECTED(EG(exception) != NULL)) {
4582					ZEND_VM_C_GOTO(unpack_iter_dtor);
4583				}
4584
4585				arg = iter->funcs->get_current_data(iter);
4586				if (UNEXPECTED(EG(exception) != NULL)) {
4587					ZEND_VM_C_GOTO(unpack_iter_dtor);
4588				}
4589
4590				if (iter->funcs->get_current_key) {
4591					zval key;
4592					iter->funcs->get_current_key(iter, &key);
4593					if (UNEXPECTED(EG(exception) != NULL)) {
4594						ZEND_VM_C_GOTO(unpack_iter_dtor);
4595					}
4596
4597					if (Z_TYPE(key) == IS_STRING) {
4598						zend_throw_error(NULL,
4599							"Cannot unpack Traversable with string keys");
4600						zend_string_release(Z_STR(key));
4601						ZEND_VM_C_GOTO(unpack_iter_dtor);
4602					}
4603
4604					zval_dtor(&key);
4605				}
4606
4607				if (ARG_MUST_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4608					zend_error(
4609						E_WARNING, "Cannot pass by-reference argument %d of %s%s%s()"
4610						" by unpacking a Traversable, passing by-value instead", arg_num,
4611						EX(call)->func->common.scope ? ZSTR_VAL(EX(call)->func->common.scope->name) : "",
4612						EX(call)->func->common.scope ? "::" : "",
4613						ZSTR_VAL(EX(call)->func->common.function_name)
4614					);
4615				}
4616
4617				if (Z_ISREF_P(arg)) {
4618					ZVAL_DUP(arg, Z_REFVAL_P(arg));
4619				} else {
4620					if (Z_REFCOUNTED_P(arg)) Z_ADDREF_P(arg);
4621				}
4622
4623				zend_vm_stack_extend_call_frame(&EX(call), arg_num - 1, 1);
4624				top = ZEND_CALL_ARG(EX(call), arg_num);
4625				ZVAL_COPY_VALUE(top, arg);
4626				ZEND_CALL_NUM_ARGS(EX(call))++;
4627
4628				iter->funcs->move_forward(iter);
4629				if (UNEXPECTED(EG(exception) != NULL)) {
4630					ZEND_VM_C_GOTO(unpack_iter_dtor);
4631				}
4632			}
4633
4634ZEND_VM_C_LABEL(unpack_iter_dtor):
4635			zend_iterator_dtor(iter);
4636		}
4637	} else if (EXPECTED(Z_ISREF_P(args))) {
4638		args = Z_REFVAL_P(args);
4639		ZEND_VM_C_GOTO(send_again);
4640	} else {
4641		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(args) == IS_UNDEF)) {
4642			GET_OP1_UNDEF_CV(args, BP_VAR_R);
4643		}
4644		zend_error(E_WARNING, "Only arrays and Traversables can be unpacked");
4645	}
4646
4647	FREE_OP1();
4648	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4649}
4650
4651ZEND_VM_HANDLER(119, ZEND_SEND_ARRAY, ANY, ANY)
4652{
4653	USE_OPLINE
4654	zend_free_op free_op1;
4655	zval *args;
4656	SAVE_OPLINE();
4657
4658	SAVE_OPLINE();
4659	args = GET_OP1_ZVAL_PTR(BP_VAR_R);
4660
4661	if (UNEXPECTED(Z_TYPE_P(args) != IS_ARRAY)) {
4662		if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(args)) {
4663			args = Z_REFVAL_P(args);
4664			if (EXPECTED(Z_TYPE_P(args) == IS_ARRAY)) {
4665				ZEND_VM_C_GOTO(send_array);
4666			}
4667		}
4668		zend_internal_type_error(EX_USES_STRICT_TYPES(), "call_user_func_array() expects parameter 2 to be array, %s given", zend_get_type_by_const(Z_TYPE_P(args)));
4669		if (ZEND_CALL_INFO(EX(call)) & ZEND_CALL_CLOSURE) {
4670			OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
4671		}
4672		if (Z_OBJ(EX(call)->This)) {
4673			OBJ_RELEASE(Z_OBJ(EX(call)->This));
4674		}
4675		EX(call)->func = (zend_function*)&zend_pass_function;
4676		EX(call)->called_scope = NULL;
4677		Z_OBJ(EX(call)->This) = NULL;
4678	} else {
4679		uint32_t arg_num;
4680		HashTable *ht;
4681		zval *arg, *param;
4682
4683ZEND_VM_C_LABEL(send_array):
4684		ht = Z_ARRVAL_P(args);
4685		zend_vm_stack_extend_call_frame(&EX(call), 0, zend_hash_num_elements(ht));
4686
4687		if (OP1_TYPE != IS_CONST && OP1_TYPE != IS_TMP_VAR && Z_IMMUTABLE_P(args)) {
4688			int separate = 0;
4689
4690			/* check if any of arguments are going to be passed by reference */
4691			for (arg_num = 0; arg_num < zend_hash_num_elements(ht); arg_num++) {
4692				if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num + 1)) {
4693					separate = 1;
4694					break;
4695				}
4696			}
4697			if (separate) {
4698				zval_copy_ctor(args);
4699				ht = Z_ARRVAL_P(args);
4700			}
4701		}
4702
4703		arg_num = 1;
4704		param = ZEND_CALL_ARG(EX(call), 1);
4705		ZEND_HASH_FOREACH_VAL(ht, arg) {
4706			if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4707				if (UNEXPECTED(!Z_ISREF_P(arg))) {
4708					if (!ARG_MAY_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4709
4710						zend_error(E_WARNING, "Parameter %d to %s%s%s() expected to be a reference, value given",
4711							arg_num,
4712							EX(call)->func->common.scope ? ZSTR_VAL(EX(call)->func->common.scope->name) : "",
4713							EX(call)->func->common.scope ? "::" : "",
4714							ZSTR_VAL(EX(call)->func->common.function_name));
4715
4716						if (ZEND_CALL_INFO(EX(call)) & ZEND_CALL_CLOSURE) {
4717							OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
4718						}
4719						if (Z_OBJ(EX(call)->This)) {
4720							OBJ_RELEASE(Z_OBJ(EX(call)->This));
4721						}
4722						EX(call)->func = (zend_function*)&zend_pass_function;
4723						EX(call)->called_scope = NULL;
4724						Z_OBJ(EX(call)->This) = NULL;
4725
4726						break;
4727					}
4728
4729					ZVAL_NEW_REF(arg, arg);
4730				}
4731				Z_ADDREF_P(arg);
4732			} else{
4733				if (Z_ISREF_P(arg) &&
4734				    !(EX(call)->func->common.fn_flags & ZEND_ACC_CALL_VIA_TRAMPOLINE)) {
4735					/* don't separate references for __call */
4736					arg = Z_REFVAL_P(arg);
4737				}
4738				if (Z_OPT_REFCOUNTED_P(arg)) {
4739					Z_ADDREF_P(arg);
4740				}
4741			}
4742			ZVAL_COPY_VALUE(param, arg);
4743			ZEND_CALL_NUM_ARGS(EX(call))++;
4744			arg_num++;
4745			param++;
4746		} ZEND_HASH_FOREACH_END();
4747	}
4748	FREE_OP1();
4749	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4750}
4751
4752ZEND_VM_HANDLER(120, ZEND_SEND_USER, VAR|CV, NUM)
4753{
4754	USE_OPLINE
4755	zval *arg, *param;
4756	zend_free_op free_op1;
4757
4758	SAVE_OPLINE();
4759	arg = GET_OP1_ZVAL_PTR(BP_VAR_R);
4760	param = ZEND_CALL_VAR(EX(call), opline->result.var);
4761
4762	if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4763		if (UNEXPECTED(!Z_ISREF_P(arg))) {
4764
4765			if (!ARG_MAY_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4766
4767				zend_error(E_WARNING, "Parameter %d to %s%s%s() expected to be a reference, value given",
4768					opline->op2.num,
4769					EX(call)->func->common.scope ? ZSTR_VAL(EX(call)->func->common.scope->name) : "",
4770					EX(call)->func->common.scope ? "::" : "",
4771					ZSTR_VAL(EX(call)->func->common.function_name));
4772
4773				if (ZEND_CALL_INFO(EX(call)) & ZEND_CALL_CLOSURE) {
4774					OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
4775				}
4776				if (Z_OBJ(EX(call)->This)) {
4777					OBJ_RELEASE(Z_OBJ(EX(call)->This));
4778				}
4779				ZVAL_UNDEF(param);
4780				EX(call)->func = (zend_function*)&zend_pass_function;
4781				EX(call)->called_scope = NULL;
4782				Z_OBJ(EX(call)->This) = NULL;
4783
4784				FREE_OP1();
4785				ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4786			}
4787
4788			ZVAL_NEW_REF(arg, arg);
4789		}
4790		Z_ADDREF_P(arg);
4791	} else {
4792		if (Z_ISREF_P(arg) &&
4793		    !(EX(call)->func->common.fn_flags & ZEND_ACC_CALL_VIA_TRAMPOLINE)) {
4794			/* don't separate references for __call */
4795			arg = Z_REFVAL_P(arg);
4796		}
4797		if (Z_OPT_REFCOUNTED_P(arg)) {
4798			Z_ADDREF_P(arg);
4799		}
4800	}
4801	ZVAL_COPY_VALUE(param, arg);
4802
4803	FREE_OP1();
4804	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4805}
4806
4807ZEND_VM_HANDLER(63, ZEND_RECV, NUM, ANY)
4808{
4809	USE_OPLINE
4810	uint32_t arg_num = opline->op1.num;
4811
4812	if (UNEXPECTED(arg_num > EX_NUM_ARGS())) {
4813		SAVE_OPLINE();
4814		zend_verify_missing_arg(execute_data, arg_num, CACHE_ADDR(opline->op2.num));
4815		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4816	} else if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
4817		zval *param = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var);
4818
4819		SAVE_OPLINE();
4820		if (UNEXPECTED(!zend_verify_arg_type(EX(func), arg_num, param, NULL, CACHE_ADDR(opline->op2.num)))) {
4821			HANDLE_EXCEPTION();
4822		}
4823	}
4824
4825	ZEND_VM_NEXT_OPCODE();
4826}
4827
4828ZEND_VM_HANDLER(64, ZEND_RECV_INIT, NUM, CONST)
4829{
4830	USE_OPLINE
4831	uint32_t arg_num;
4832	zval *param;
4833
4834	ZEND_VM_REPEATABLE_OPCODE
4835
4836	arg_num = opline->op1.num;
4837	param = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var);
4838	if (arg_num > EX_NUM_ARGS()) {
4839		ZVAL_COPY_VALUE(param, EX_CONSTANT(opline->op2));
4840		if (Z_OPT_CONSTANT_P(param)) {
4841			SAVE_OPLINE();
4842			if (UNEXPECTED(zval_update_constant_ex(param, 0, NULL) != SUCCESS)) {
4843				ZVAL_UNDEF(param);
4844				HANDLE_EXCEPTION();
4845			}
4846		} else {
4847			/* IS_CONST can't be IS_OBJECT, IS_RESOURCE or IS_REFERENCE */
4848			if (UNEXPECTED(Z_OPT_COPYABLE_P(param))) {
4849				zval_copy_ctor_func(param);
4850			}
4851		}
4852	}
4853
4854	if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
4855		zval *default_value = EX_CONSTANT(opline->op2);
4856
4857		SAVE_OPLINE();
4858		if (UNEXPECTED(!zend_verify_arg_type(EX(func), arg_num, param, default_value, CACHE_ADDR(Z_CACHE_SLOT_P(default_value))))) {
4859			HANDLE_EXCEPTION();
4860		}
4861	}
4862
4863	ZEND_VM_REPEAT_OPCODE(ZEND_RECV_INIT);
4864	ZEND_VM_NEXT_OPCODE();
4865}
4866
4867ZEND_VM_HANDLER(164, ZEND_RECV_VARIADIC, NUM, ANY)
4868{
4869	USE_OPLINE
4870	uint32_t arg_num = opline->op1.num;
4871	uint32_t arg_count = EX_NUM_ARGS();
4872	zval *params;
4873
4874	SAVE_OPLINE();
4875
4876	params = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var);
4877
4878	if (arg_num <= arg_count) {
4879		zval *param;
4880
4881		array_init_size(params, arg_count - arg_num + 1);
4882		zend_hash_real_init(Z_ARRVAL_P(params), 1);
4883		ZEND_HASH_FILL_PACKED(Z_ARRVAL_P(params)) {
4884			param = EX_VAR_NUM(EX(func)->op_array.last_var + EX(func)->op_array.T);
4885			if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
4886				do {
4887					zend_verify_arg_type(EX(func), arg_num, param, NULL, CACHE_ADDR(opline->op2.num));
4888					if (Z_OPT_REFCOUNTED_P(param)) Z_ADDREF_P(param);
4889					ZEND_HASH_FILL_ADD(param);
4890					param++;
4891				} while (++arg_num <= arg_count);
4892			} else {
4893				do {
4894					if (Z_OPT_REFCOUNTED_P(param)) Z_ADDREF_P(param);
4895					ZEND_HASH_FILL_ADD(param);
4896					param++;
4897				} while (++arg_num <= arg_count);
4898			}
4899		} ZEND_HASH_FILL_END();
4900	} else {
4901		array_init(params);
4902	}
4903
4904	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4905}
4906
4907ZEND_VM_HANDLER(52, ZEND_BOOL, CONST|TMPVAR|CV, ANY)
4908{
4909	USE_OPLINE
4910	zval *val;
4911	zend_free_op free_op1;
4912
4913	val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4914	if (Z_TYPE_INFO_P(val) == IS_TRUE) {
4915		ZVAL_TRUE(EX_VAR(opline->result.var));
4916	} else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
4917		ZVAL_FALSE(EX_VAR(opline->result.var));
4918		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
4919			SAVE_OPLINE();
4920			GET_OP1_UNDEF_CV(val, BP_VAR_R);
4921			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4922		}
4923	} else {
4924		SAVE_OPLINE();
4925		ZVAL_BOOL(EX_VAR(opline->result.var), i_zend_is_true(val));
4926		FREE_OP1();
4927		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4928	}
4929	ZEND_VM_NEXT_OPCODE();
4930}
4931
4932ZEND_VM_HANDLER(48, ZEND_CASE, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
4933{
4934	USE_OPLINE
4935	zend_free_op free_op1, free_op2;
4936	zval *op1, *op2, *result;
4937
4938	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4939	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
4940	do {
4941		int result;
4942
4943		if (EXPECTED(Z_TYPE_P(op1) == IS_LONG)) {
4944			if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
4945				result = (Z_LVAL_P(op1) == Z_LVAL_P(op2));
4946			} else if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
4947				result = ((double)Z_LVAL_P(op1) == Z_DVAL_P(op2));
4948			} else {
4949				break;
4950			}
4951		} else if (EXPECTED(Z_TYPE_P(op1) == IS_DOUBLE)) {
4952			if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
4953				result = (Z_DVAL_P(op1) == Z_DVAL_P(op2));
4954			} else if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
4955				result = (Z_DVAL_P(op1) == ((double)Z_LVAL_P(op2)));
4956			} else {
4957				break;
4958			}
4959		} else if (EXPECTED(Z_TYPE_P(op1) == IS_STRING)) {
4960			if (EXPECTED(Z_TYPE_P(op2) == IS_STRING)) {
4961				if (Z_STR_P(op1) == Z_STR_P(op2)) {
4962					result = 1;
4963				} else if (Z_STRVAL_P(op1)[0] > '9' || Z_STRVAL_P(op2)[0] > '9') {
4964					if (Z_STRLEN_P(op1) != Z_STRLEN_P(op2)) {
4965						result = 0;
4966					} else {
4967						result = (memcmp(Z_STRVAL_P(op1), Z_STRVAL_P(op2), Z_STRLEN_P(op1)) == 0);
4968					}
4969				} else {
4970					result = (zendi_smart_strcmp(Z_STR_P(op1), Z_STR_P(op2)) == 0);
4971				}
4972				FREE_OP2();
4973			} else {
4974				break;
4975			}
4976		} else {
4977			break;
4978		}
4979		ZEND_VM_SMART_BRANCH(result, 0);
4980		ZVAL_BOOL(EX_VAR(opline->result.var), result);
4981		ZEND_VM_NEXT_OPCODE();
4982	} while (0);
4983
4984	SAVE_OPLINE();
4985	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op1) == IS_UNDEF)) {
4986		op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
4987	}
4988	if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op2) == IS_UNDEF)) {
4989		op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
4990	}
4991	result = EX_VAR(opline->result.var);
4992	compare_function(result, op1, op2);
4993	ZVAL_BOOL(result, Z_LVAL_P(result) == 0);
4994	FREE_OP2();
4995	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4996}
4997
4998ZEND_VM_HANDLER(68, ZEND_NEW, UNUSED|CLASS_FETCH|CONST|VAR, JMP_ADDR, NUM)
4999{
5000	USE_OPLINE
5001	zval *result;
5002	zend_function *constructor;
5003	zend_class_entry *ce;
5004
5005	SAVE_OPLINE();
5006	if (OP1_TYPE == IS_CONST) {
5007		ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
5008		if (UNEXPECTED(ce == NULL)) {
5009			ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
5010			if (UNEXPECTED(ce == NULL)) {
5011				ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5012			}
5013			CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce);
5014		}
5015	} else if (OP1_TYPE == IS_UNUSED) {
5016		ce = zend_fetch_class(NULL, opline->op1.num);
5017		if (UNEXPECTED(ce == NULL)) {
5018			ZEND_ASSERT(EG(exception));
5019			HANDLE_EXCEPTION();
5020		}
5021	} else {
5022		ce = Z_CE_P(EX_VAR(opline->op1.var));
5023	}
5024
5025	result = EX_VAR(opline->result.var);
5026	if (UNEXPECTED(object_init_ex(result, ce) != SUCCESS)) {
5027		HANDLE_EXCEPTION();
5028	}
5029
5030	constructor = Z_OBJ_HT_P(result)->get_constructor(Z_OBJ_P(result));
5031	if (constructor == NULL) {
5032		ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
5033	} else {
5034		/* We are not handling overloaded classes right now */
5035		zend_execute_data *call = zend_vm_stack_push_call_frame(
5036			ZEND_CALL_FUNCTION | ZEND_CALL_RELEASE_THIS | ZEND_CALL_CTOR,
5037			constructor,
5038			opline->extended_value,
5039			ce,
5040			Z_OBJ_P(result));
5041		call->prev_execute_data = EX(call);
5042		EX(call) = call;
5043		Z_ADDREF_P(result);
5044
5045		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5046	}
5047}
5048
5049ZEND_VM_HANDLER(110, ZEND_CLONE, CONST|TMPVAR|UNUSED|THIS|CV, ANY)
5050{
5051	USE_OPLINE
5052	zend_free_op free_op1;
5053	zval *obj;
5054	zend_class_entry *ce;
5055	zend_function *clone;
5056	zend_object_clone_obj_t clone_call;
5057
5058	SAVE_OPLINE();
5059	obj = GET_OP1_OBJ_ZVAL_PTR_UNDEF(BP_VAR_R);
5060
5061	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(obj) == NULL)) {
5062		zend_throw_error(NULL, "Using $this when not in object context");
5063		HANDLE_EXCEPTION();
5064	}
5065
5066	do {
5067		if (OP1_TYPE == IS_CONST ||
5068		    (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(obj) != IS_OBJECT))) {
5069		    if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(obj)) {
5070		    	obj = Z_REFVAL_P(obj);
5071		    	if (EXPECTED(Z_TYPE_P(obj) == IS_OBJECT)) {
5072		    		break;
5073				}
5074			}
5075			if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(obj) == IS_UNDEF)) {
5076				GET_OP1_UNDEF_CV(obj, BP_VAR_R);
5077				if (UNEXPECTED(EG(exception) != NULL)) {
5078					HANDLE_EXCEPTION();
5079				}
5080			}
5081			zend_throw_error(NULL, "__clone method called on non-object");
5082			FREE_OP1();
5083			HANDLE_EXCEPTION();
5084		}
5085	} while (0);
5086
5087	ce = Z_OBJCE_P(obj);
5088	clone = ce->clone;
5089	clone_call = Z_OBJ_HT_P(obj)->clone_obj;
5090	if (UNEXPECTED(clone_call == NULL)) {
5091		zend_throw_error(NULL, "Trying to clone an uncloneable object of class %s", ZSTR_VAL(ce->name));
5092		FREE_OP1();
5093		HANDLE_EXCEPTION();
5094	}
5095
5096	if (clone) {
5097		if (clone->op_array.fn_flags & ZEND_ACC_PRIVATE) {
5098			/* Ensure that if we're calling a private function, we're allowed to do so.
5099			 */
5100			if (UNEXPECTED(ce != EG(scope))) {
5101				zend_throw_error(NULL, "Call to private %s::__clone() from context '%s'", ZSTR_VAL(ce->name), EG(scope) ? ZSTR_VAL(EG(scope)->name) : "");
5102				FREE_OP1();
5103				HANDLE_EXCEPTION();
5104			}
5105		} else if ((clone->common.fn_flags & ZEND_ACC_PROTECTED)) {
5106			/* Ensure that if we're calling a protected function, we're allowed to do so.
5107			 */
5108			if (UNEXPECTED(!zend_check_protected(zend_get_function_root_class(clone), EG(scope)))) {
5109				zend_throw_error(NULL, "Call to protected %s::__clone() from context '%s'", ZSTR_VAL(ce->name), EG(scope) ? ZSTR_VAL(EG(scope)->name) : "");
5110				FREE_OP1();
5111				HANDLE_EXCEPTION();
5112			}
5113		}
5114	}
5115
5116	ZVAL_OBJ(EX_VAR(opline->result.var), clone_call(obj));
5117	if (UNEXPECTED(EG(exception) != NULL)) {
5118		OBJ_RELEASE(Z_OBJ_P(EX_VAR(opline->result.var)));
5119	}
5120
5121	FREE_OP1();
5122	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5123}
5124
5125ZEND_VM_HANDLER(99, ZEND_FETCH_CONSTANT, UNUSED, CONST, CONST_FETCH)
5126{
5127	USE_OPLINE
5128	zend_constant *c;
5129
5130	SAVE_OPLINE();
5131
5132	if (EXPECTED(CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2))))) {
5133		c = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
5134	} else if ((c = zend_quick_get_constant(EX_CONSTANT(opline->op2) + 1, opline->extended_value)) == NULL) {
5135		if ((opline->extended_value & IS_CONSTANT_UNQUALIFIED) != 0) {
5136			char *actual = (char *)zend_memrchr(Z_STRVAL_P(EX_CONSTANT(opline->op2)), '\\', Z_STRLEN_P(EX_CONSTANT(opline->op2)));
5137			if (!actual) {
5138				ZVAL_STR_COPY(EX_VAR(opline->result.var), Z_STR_P(EX_CONSTANT(opline->op2)));
5139			} else {
5140				actual++;
5141				ZVAL_STRINGL(EX_VAR(opline->result.var),
5142						actual, Z_STRLEN_P(EX_CONSTANT(opline->op2)) - (actual - Z_STRVAL_P(EX_CONSTANT(opline->op2))));
5143			}
5144			/* non-qualified constant - allow text substitution */
5145			zend_error(E_NOTICE, "Use of undefined constant %s - assumed '%s'",
5146					Z_STRVAL_P(EX_VAR(opline->result.var)), Z_STRVAL_P(EX_VAR(opline->result.var)));
5147			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5148		} else {
5149			zend_throw_error(NULL, "Undefined constant '%s'", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
5150			HANDLE_EXCEPTION();
5151		}
5152	} else {
5153		CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), c);
5154	}
5155
5156#ifdef ZTS
5157	if (c->flags & CONST_PERSISTENT) {
5158		ZVAL_DUP(EX_VAR(opline->result.var), &c->value);
5159	} else {
5160		ZVAL_COPY(EX_VAR(opline->result.var), &c->value);
5161	}
5162#else
5163	ZVAL_COPY(EX_VAR(opline->result.var), &c->value);
5164#endif
5165
5166	ZEND_VM_NEXT_OPCODE();
5167}
5168
5169ZEND_VM_HANDLER(181, ZEND_FETCH_CLASS_CONSTANT, VAR|CONST|UNUSED|CLASS_FETCH, CONST)
5170{
5171	zend_class_entry *ce;
5172	zend_class_constant *c;
5173	zval *value;
5174	USE_OPLINE
5175
5176	SAVE_OPLINE();
5177
5178	do {
5179		if (OP1_TYPE == IS_CONST) {
5180			if (EXPECTED(CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2))))) {
5181				value = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
5182#ifdef ZTS
5183				ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
5184#endif
5185				break;
5186			} else if (EXPECTED(CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1))))) {
5187				ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
5188			} else {
5189				ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
5190				if (UNEXPECTED(ce == NULL)) {
5191					if (EXPECTED(!EG(exception))) {
5192						zend_throw_error(NULL, "Class '%s' not found", Z_STRVAL_P(EX_CONSTANT(opline->op1)));
5193					}
5194					HANDLE_EXCEPTION();
5195				}
5196				CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce);
5197			}
5198		} else {
5199			if (OP1_TYPE == IS_UNUSED) {
5200				ce = zend_fetch_class(NULL, opline->op1.num);
5201				if (UNEXPECTED(ce == NULL)) {
5202					ZEND_ASSERT(EG(exception));
5203					HANDLE_EXCEPTION();
5204				}
5205			} else {
5206				ce = Z_CE_P(EX_VAR(opline->op1.var));
5207			}
5208			if ((value = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce)) != NULL) {
5209				break;
5210			}
5211		}
5212
5213		if (EXPECTED((c = zend_hash_find_ptr(&ce->constants_table, Z_STR_P(EX_CONSTANT(opline->op2)))) != NULL)) {
5214			if (!zend_verify_const_access(c, EG(scope))) {
5215				zend_throw_error(NULL, "Cannot access %s const %s::%s", zend_visibility_string(Z_ACCESS_FLAGS(c->value)), ZSTR_VAL(ce->name), Z_STRVAL_P(EX_CONSTANT(opline->op2)));
5216				HANDLE_EXCEPTION();
5217			}
5218			value = &c->value;
5219			if (Z_CONSTANT_P(value)) {
5220				EG(scope) = ce;
5221				zval_update_constant_ex(value, 1, NULL);
5222				EG(scope) = EX(func)->op_array.scope;
5223				if (UNEXPECTED(EG(exception) != NULL)) {
5224					HANDLE_EXCEPTION();
5225				}
5226			}
5227			if (OP1_TYPE == IS_CONST) {
5228				CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), value);
5229			} else {
5230				CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce, value);
5231			}
5232		} else {
5233			zend_throw_error(NULL, "Undefined class constant '%s'", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
5234			HANDLE_EXCEPTION();
5235		}
5236	} while (0);
5237
5238#ifdef ZTS
5239	if (ce->type == ZEND_INTERNAL_CLASS) {
5240		ZVAL_DUP(EX_VAR(opline->result.var), value);
5241	} else {
5242		ZVAL_COPY(EX_VAR(opline->result.var), value);
5243	}
5244#else
5245	ZVAL_COPY(EX_VAR(opline->result.var), value);
5246#endif
5247
5248	ZEND_VM_NEXT_OPCODE();
5249}
5250
5251ZEND_VM_HANDLER(72, ZEND_ADD_ARRAY_ELEMENT, CONST|TMP|VAR|CV, CONST|TMPVAR|UNUSED|NEXT|CV, REF)
5252{
5253	USE_OPLINE
5254	zend_free_op free_op1;
5255	zval *expr_ptr, new_expr;
5256
5257	SAVE_OPLINE();
5258	if ((OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) &&
5259	    UNEXPECTED(opline->extended_value & ZEND_ARRAY_ELEMENT_REF)) {
5260		expr_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
5261		ZVAL_MAKE_REF(expr_ptr);
5262		Z_ADDREF_P(expr_ptr);
5263		FREE_OP1_VAR_PTR();
5264	} else {
5265		expr_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
5266		if (OP1_TYPE == IS_TMP_VAR) {
5267			/* pass */
5268		} else if (OP1_TYPE == IS_CONST) {
5269			if (UNEXPECTED(Z_OPT_COPYABLE_P(expr_ptr))) {
5270				ZVAL_COPY_VALUE(&new_expr, expr_ptr);
5271				zval_copy_ctor_func(&new_expr);
5272				expr_ptr = &new_expr;
5273			}
5274		} else if (OP1_TYPE == IS_CV) {
5275			ZVAL_DEREF(expr_ptr);
5276			if (Z_REFCOUNTED_P(expr_ptr)) {
5277				Z_ADDREF_P(expr_ptr);
5278			}
5279		} else /* if (OP1_TYPE == IS_VAR) */ {
5280			if (UNEXPECTED(Z_ISREF_P(expr_ptr))) {
5281				zend_refcounted *ref = Z_COUNTED_P(expr_ptr);
5282
5283				expr_ptr = Z_REFVAL_P(expr_ptr);
5284				if (UNEXPECTED(--GC_REFCOUNT(ref) == 0)) {
5285					ZVAL_COPY_VALUE(&new_expr, expr_ptr);
5286					expr_ptr = &new_expr;
5287					efree_size(ref, sizeof(zend_reference));
5288				} else if (Z_OPT_REFCOUNTED_P(expr_ptr)) {
5289					Z_ADDREF_P(expr_ptr);
5290				}
5291			}
5292		}
5293	}
5294
5295	if (OP2_TYPE != IS_UNUSED) {
5296		zend_free_op free_op2;
5297		zval *offset = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
5298		zend_string *str;
5299		zend_ulong hval;
5300
5301ZEND_VM_C_LABEL(add_again):
5302		if (EXPECTED(Z_TYPE_P(offset) == IS_STRING)) {
5303			str = Z_STR_P(offset);
5304			if (OP2_TYPE != IS_CONST) {
5305				if (ZEND_HANDLE_NUMERIC(str, hval)) {
5306					ZEND_VM_C_GOTO(num_index);
5307				}
5308			}
5309ZEND_VM_C_LABEL(str_index):
5310			zend_hash_update(Z_ARRVAL_P(EX_VAR(opline->result.var)), str, expr_ptr);
5311		} else if (EXPECTED(Z_TYPE_P(offset) == IS_LONG)) {
5312			hval = Z_LVAL_P(offset);
5313ZEND_VM_C_LABEL(num_index):
5314			zend_hash_index_update(Z_ARRVAL_P(EX_VAR(opline->result.var)), hval, expr_ptr);
5315		} else if ((OP2_TYPE & (IS_VAR|IS_CV)) && EXPECTED(Z_TYPE_P(offset) == IS_REFERENCE)) {
5316			offset = Z_REFVAL_P(offset);
5317			ZEND_VM_C_GOTO(add_again);
5318		} else if (Z_TYPE_P(offset) == IS_NULL) {
5319			str = ZSTR_EMPTY_ALLOC();
5320			ZEND_VM_C_GOTO(str_index);
5321		} else if (Z_TYPE_P(offset) == IS_DOUBLE) {
5322			hval = zend_dval_to_lval(Z_DVAL_P(offset));
5323			ZEND_VM_C_GOTO(num_index);
5324		} else if (Z_TYPE_P(offset) == IS_FALSE) {
5325			hval = 0;
5326			ZEND_VM_C_GOTO(num_index);
5327		} else if (Z_TYPE_P(offset) == IS_TRUE) {
5328			hval = 1;
5329			ZEND_VM_C_GOTO(num_index);
5330		} else if (OP2_TYPE == IS_CV && Z_TYPE_P(offset) == IS_UNDEF) {
5331			GET_OP2_UNDEF_CV(offset, BP_VAR_R);
5332			str = ZSTR_EMPTY_ALLOC();
5333			ZEND_VM_C_GOTO(str_index);
5334		} else {
5335			zend_error(E_WARNING, "Illegal offset type");
5336			zval_ptr_dtor(expr_ptr);
5337		}
5338		FREE_OP2();
5339	} else {
5340		zend_hash_next_index_insert(Z_ARRVAL_P(EX_VAR(opline->result.var)), expr_ptr);
5341	}
5342	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5343}
5344
5345ZEND_VM_HANDLER(71, ZEND_INIT_ARRAY, CONST|TMP|VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|NEXT|CV, ARRAY_INIT|REF)
5346{
5347	zval *array;
5348	uint32_t size;
5349	USE_OPLINE
5350
5351	array = EX_VAR(opline->result.var);
5352	if (OP1_TYPE != IS_UNUSED) {
5353		size = opline->extended_value >> ZEND_ARRAY_SIZE_SHIFT;
5354	} else {
5355		size = 0;
5356	}
5357	ZVAL_NEW_ARR(array);
5358	zend_hash_init(Z_ARRVAL_P(array), size, NULL, ZVAL_PTR_DTOR, 0);
5359
5360	if (OP1_TYPE != IS_UNUSED) {
5361		/* Explicitly initialize array as not-packed if flag is set */
5362		if (opline->extended_value & ZEND_ARRAY_NOT_PACKED) {
5363			zend_hash_real_init(Z_ARRVAL_P(array), 0);
5364		}
5365	}
5366
5367	if (OP1_TYPE == IS_UNUSED) {
5368		ZEND_VM_NEXT_OPCODE();
5369#if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
5370	} else {
5371		ZEND_VM_DISPATCH_TO_HANDLER(ZEND_ADD_ARRAY_ELEMENT);
5372#endif
5373	}
5374}
5375
5376ZEND_VM_HANDLER(21, ZEND_CAST, CONST|TMP|VAR|CV, ANY, TYPE)
5377{
5378	USE_OPLINE
5379	zend_free_op free_op1;
5380	zval *expr;
5381	zval *result = EX_VAR(opline->result.var);
5382
5383	SAVE_OPLINE();
5384	expr = GET_OP1_ZVAL_PTR(BP_VAR_R);
5385
5386	switch (opline->extended_value) {
5387		case IS_NULL:
5388			/* This code is taken from convert_to_null. However, it does not seems very useful,
5389			 * because a conversion to null always results in the same value. This could only
5390			 * be relevant if a cast_object handler for IS_NULL has some kind of side-effect. */
5391#if 0
5392			if (OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) {
5393				ZVAL_DEREF(expr);
5394			}
5395			if (Z_TYPE_P(expr) == IS_OBJECT && Z_OBJ_HT_P(expr)->cast_object) {
5396				if (Z_OBJ_HT_P(expr)->cast_object(expr, result, IS_NULL) == SUCCESS) {
5397					break;
5398				}
5399			}
5400#endif
5401
5402			ZVAL_NULL(result);
5403			break;
5404		case _IS_BOOL:
5405			ZVAL_BOOL(result, zend_is_true(expr));
5406			break;
5407		case IS_LONG:
5408			ZVAL_LONG(result, zval_get_long(expr));
5409			break;
5410		case IS_DOUBLE:
5411			ZVAL_DOUBLE(result, zval_get_double(expr));
5412			break;
5413		case IS_STRING:
5414			ZVAL_STR(result, zval_get_string(expr));
5415			break;
5416		default:
5417			if (OP1_TYPE & (IS_VAR|IS_CV)) {
5418				ZVAL_DEREF(expr);
5419			}
5420			/* If value is already of correct type, return it directly */
5421			if (Z_TYPE_P(expr) == opline->extended_value) {
5422				ZVAL_COPY_VALUE(result, expr);
5423				if (OP1_TYPE == IS_CONST) {
5424					if (UNEXPECTED(Z_OPT_COPYABLE_P(result))) {
5425						zval_copy_ctor_func(result);
5426					}
5427				} else if (OP1_TYPE != IS_TMP_VAR) {
5428					if (Z_OPT_REFCOUNTED_P(expr)) Z_ADDREF_P(expr);
5429				}
5430
5431				FREE_OP1_IF_VAR();
5432				ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5433			}
5434
5435			if (opline->extended_value == IS_ARRAY) {
5436				if (Z_TYPE_P(expr) != IS_OBJECT) {
5437					ZVAL_NEW_ARR(result);
5438					zend_hash_init(Z_ARRVAL_P(result), 8, NULL, ZVAL_PTR_DTOR, 0);
5439					if (Z_TYPE_P(expr) != IS_NULL) {
5440						expr = zend_hash_index_add_new(Z_ARRVAL_P(result), 0, expr);
5441						if (OP1_TYPE == IS_CONST) {
5442							if (UNEXPECTED(Z_OPT_COPYABLE_P(expr))) {
5443								zval_copy_ctor_func(expr);
5444							}
5445						} else {
5446							if (Z_OPT_REFCOUNTED_P(expr)) Z_ADDREF_P(expr);
5447						}
5448					}
5449				} else {
5450					ZVAL_COPY_VALUE(result, expr);
5451					Z_ADDREF_P(result);
5452					convert_to_array(result);
5453				}
5454			} else {
5455				if (Z_TYPE_P(expr) != IS_ARRAY) {
5456					object_init(result);
5457					if (Z_TYPE_P(expr) != IS_NULL) {
5458						expr = zend_hash_str_add_new(Z_OBJPROP_P(result), "scalar", sizeof("scalar")-1, expr);
5459						if (OP1_TYPE == IS_CONST) {
5460							if (UNEXPECTED(Z_OPT_COPYABLE_P(expr))) {
5461								zval_copy_ctor_func(expr);
5462							}
5463						} else {
5464							if (Z_OPT_REFCOUNTED_P(expr)) Z_ADDREF_P(expr);
5465						}
5466					}
5467				} else {
5468					ZVAL_COPY(result, expr);
5469					convert_to_object(result);
5470				}
5471			}
5472	}
5473
5474	FREE_OP1();
5475	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5476}
5477
5478ZEND_VM_HANDLER(73, ZEND_INCLUDE_OR_EVAL, CONST|TMPVAR|CV, ANY, EVAL)
5479{
5480	USE_OPLINE
5481	zend_op_array *new_op_array=NULL;
5482	zend_free_op free_op1;
5483	zval *inc_filename;
5484	zval tmp_inc_filename;
5485	zend_bool failure_retval=0;
5486
5487	SAVE_OPLINE();
5488	inc_filename = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
5489
5490	ZVAL_UNDEF(&tmp_inc_filename);
5491	if (Z_TYPE_P(inc_filename) != IS_STRING) {
5492		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(inc_filename) == IS_UNDEF)) {
5493			inc_filename = GET_OP1_UNDEF_CV(inc_filename, BP_VAR_R);
5494		}
5495		ZVAL_STR(&tmp_inc_filename, zval_get_string(inc_filename));
5496		inc_filename = &tmp_inc_filename;
5497	}
5498
5499	if (opline->extended_value != ZEND_EVAL && strlen(Z_STRVAL_P(inc_filename)) != Z_STRLEN_P(inc_filename)) {
5500		if (opline->extended_value == ZEND_INCLUDE_ONCE || opline->extended_value == ZEND_INCLUDE) {
5501			zend_message_dispatcher(ZMSG_FAILED_INCLUDE_FOPEN, Z_STRVAL_P(inc_filename));
5502		} else {
5503			zend_message_dispatcher(ZMSG_FAILED_REQUIRE_FOPEN, Z_STRVAL_P(inc_filename));
5504		}
5505	} else {
5506		switch (opline->extended_value) {
5507			case ZEND_INCLUDE_ONCE:
5508			case ZEND_REQUIRE_ONCE: {
5509					zend_file_handle file_handle;
5510					zend_string *resolved_path;
5511
5512					resolved_path = zend_resolve_path(Z_STRVAL_P(inc_filename), (int)Z_STRLEN_P(inc_filename));
5513					if (resolved_path) {
5514						failure_retval = zend_hash_exists(&EG(included_files), resolved_path);
5515					} else {
5516						resolved_path = zend_string_copy(Z_STR_P(inc_filename));
5517					}
5518
5519					if (failure_retval) {
5520						/* do nothing, file already included */
5521					} else if (SUCCESS == zend_stream_open(ZSTR_VAL(resolved_path), &file_handle)) {
5522
5523						if (!file_handle.opened_path) {
5524							file_handle.opened_path = zend_string_copy(resolved_path);
5525						}
5526
5527						if (zend_hash_add_empty_element(&EG(included_files), file_handle.opened_path)) {
5528							new_op_array = zend_compile_file(&file_handle, (opline->extended_value==ZEND_INCLUDE_ONCE?ZEND_INCLUDE:ZEND_REQUIRE));
5529							zend_destroy_file_handle(&file_handle);
5530						} else {
5531							zend_file_handle_dtor(&file_handle);
5532							failure_retval=1;
5533						}
5534					} else {
5535						if (opline->extended_value == ZEND_INCLUDE_ONCE) {
5536							zend_message_dispatcher(ZMSG_FAILED_INCLUDE_FOPEN, Z_STRVAL_P(inc_filename));
5537						} else {
5538							zend_message_dispatcher(ZMSG_FAILED_REQUIRE_FOPEN, Z_STRVAL_P(inc_filename));
5539						}
5540					}
5541					zend_string_release(resolved_path);
5542				}
5543				break;
5544			case ZEND_INCLUDE:
5545			case ZEND_REQUIRE:
5546				new_op_array = compile_filename(opline->extended_value, inc_filename);
5547				break;
5548			case ZEND_EVAL: {
5549					char *eval_desc = zend_make_compiled_string_description("eval()'d code");
5550
5551					new_op_array = zend_compile_string(inc_filename, eval_desc);
5552					efree(eval_desc);
5553				}
5554				break;
5555			EMPTY_SWITCH_DEFAULT_CASE()
5556		}
5557	}
5558	if (Z_TYPE(tmp_inc_filename) != IS_UNDEF) {
5559		zend_string_release(Z_STR(tmp_inc_filename));
5560	}
5561	FREE_OP1();
5562	if (UNEXPECTED(EG(exception) != NULL)) {
5563		HANDLE_EXCEPTION();
5564	} else if (EXPECTED(new_op_array != NULL)) {
5565		zval *return_value = NULL;
5566		zend_execute_data *call;
5567
5568		if (RETURN_VALUE_USED(opline)) {
5569			return_value = EX_VAR(opline->result.var);
5570		}
5571
5572		new_op_array->scope = EG(scope);
5573
5574		call = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_CODE,
5575			(zend_function*)new_op_array, 0, EX(called_scope), Z_OBJ(EX(This)));
5576
5577		if (EX(symbol_table)) {
5578			call->symbol_table = EX(symbol_table);
5579		} else {
5580			call->symbol_table = zend_rebuild_symbol_table();
5581		}
5582
5583		call->prev_execute_data = execute_data;
5584	    i_init_code_execute_data(call, new_op_array, return_value);
5585		if (EXPECTED(zend_execute_ex == execute_ex)) {
5586			ZEND_VM_ENTER();
5587		} else {
5588			ZEND_ADD_CALL_FLAG(call, ZEND_CALL_TOP);
5589			zend_execute_ex(call);
5590			zend_vm_stack_free_call_frame(call);
5591		}
5592
5593		destroy_op_array(new_op_array);
5594		efree_size(new_op_array, sizeof(zend_op_array));
5595		if (UNEXPECTED(EG(exception) != NULL)) {
5596			zend_throw_exception_internal(NULL);
5597			HANDLE_EXCEPTION();
5598		}
5599
5600	} else if (RETURN_VALUE_USED(opline)) {
5601		ZVAL_BOOL(EX_VAR(opline->result.var), failure_retval);
5602	}
5603	ZEND_VM_INTERRUPT_CHECK();
5604	ZEND_VM_NEXT_OPCODE();
5605}
5606
5607ZEND_VM_HANDLER(74, ZEND_UNSET_VAR, CONST|TMPVAR|CV, UNUSED, VAR_FETCH|ISSET)
5608{
5609	USE_OPLINE
5610	zval tmp, *varname;
5611	HashTable *target_symbol_table;
5612	zend_free_op free_op1;
5613
5614	SAVE_OPLINE();
5615	if (OP1_TYPE == IS_CV &&
5616	    (opline->extended_value & ZEND_QUICK_SET)) {
5617		zval *var = EX_VAR(opline->op1.var);
5618
5619		if (Z_REFCOUNTED_P(var)) {
5620			zend_refcounted *garbage = Z_COUNTED_P(var);
5621
5622			if (!--GC_REFCOUNT(garbage)) {
5623				ZVAL_UNDEF(var);
5624				zval_dtor_func_for_ptr(garbage);
5625			} else {
5626				zval *z = var;
5627				ZVAL_DEREF(z);
5628				if (Z_COLLECTABLE_P(z) && UNEXPECTED(!Z_GC_INFO_P(z))) {
5629					ZVAL_UNDEF(var);
5630					gc_possible_root(Z_COUNTED_P(z));
5631				} else {
5632					ZVAL_UNDEF(var);
5633				}
5634			}
5635		} else {
5636			ZVAL_UNDEF(var);
5637		}
5638		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5639	}
5640
5641	varname = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
5642
5643	ZVAL_UNDEF(&tmp);
5644	if (OP1_TYPE != IS_CONST && Z_TYPE_P(varname) != IS_STRING) {
5645		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(varname) == IS_UNDEF)) {
5646			varname = GET_OP1_UNDEF_CV(varname, BP_VAR_R);
5647		}
5648		ZVAL_STR(&tmp, zval_get_string(varname));
5649		varname = &tmp;
5650	}
5651
5652	target_symbol_table = zend_get_target_symbol_table(execute_data, opline->extended_value & ZEND_FETCH_TYPE_MASK);
5653	zend_hash_del_ind(target_symbol_table, Z_STR_P(varname));
5654
5655	if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
5656		zend_string_release(Z_STR(tmp));
5657	}
5658	FREE_OP1();
5659	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5660}
5661
5662ZEND_VM_HANDLER(179, ZEND_UNSET_STATIC_PROP, CONST|TMPVAR|CV, UNUSED|CLASS_FETCH|CONST|VAR)
5663{
5664	USE_OPLINE
5665	zval tmp, *varname;
5666	zend_class_entry *ce;
5667	zend_free_op free_op1;
5668
5669	SAVE_OPLINE();
5670
5671	varname = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
5672
5673	ZVAL_UNDEF(&tmp);
5674	if (OP1_TYPE != IS_CONST && Z_TYPE_P(varname) != IS_STRING) {
5675		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(varname) == IS_UNDEF)) {
5676			varname = GET_OP1_UNDEF_CV(varname, BP_VAR_R);
5677		}
5678		ZVAL_STR(&tmp, zval_get_string(varname));
5679		varname = &tmp;
5680	}
5681
5682	if (OP2_TYPE == IS_CONST) {
5683		ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
5684		if (UNEXPECTED(ce == NULL)) {
5685			ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op2)), EX_CONSTANT(opline->op2) + 1, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
5686			if (UNEXPECTED(ce == NULL)) {
5687				if (EXPECTED(!EG(exception))) {
5688					zend_throw_error(NULL, "Class '%s' not found", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
5689				}
5690				if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
5691					zend_string_release(Z_STR(tmp));
5692				}
5693				FREE_OP1();
5694				HANDLE_EXCEPTION();
5695			}
5696			CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce);
5697		}
5698	} else if (OP2_TYPE == IS_UNUSED) {
5699		ce = zend_fetch_class(NULL, opline->op2.num);
5700		if (UNEXPECTED(ce == NULL)) {
5701			ZEND_ASSERT(EG(exception));
5702			if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
5703				zend_string_release(Z_STR(tmp));
5704			}
5705			FREE_OP1();
5706			HANDLE_EXCEPTION();
5707		}
5708	} else {
5709		ce = Z_CE_P(EX_VAR(opline->op2.var));
5710	}
5711	zend_std_unset_static_property(ce, Z_STR_P(varname));
5712
5713	if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
5714		zend_string_release(Z_STR(tmp));
5715	}
5716	FREE_OP1();
5717	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5718}
5719
5720ZEND_VM_HANDLER(75, ZEND_UNSET_DIM, VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
5721{
5722	USE_OPLINE
5723	zend_free_op free_op1, free_op2;
5724	zval *container;
5725	zval *offset;
5726	zend_ulong hval;
5727	zend_string *key;
5728
5729	SAVE_OPLINE();
5730	container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_UNSET);
5731	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
5732		zend_throw_error(NULL, "Using $this when not in object context");
5733		FREE_UNFETCHED_OP2();
5734		HANDLE_EXCEPTION();
5735	}
5736	offset = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
5737
5738	do {
5739		if (OP1_TYPE != IS_UNUSED && EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
5740			HashTable *ht;
5741
5742ZEND_VM_C_LABEL(unset_dim_array):
5743			SEPARATE_ARRAY(container);
5744			ht = Z_ARRVAL_P(container);
5745ZEND_VM_C_LABEL(offset_again):
5746			if (EXPECTED(Z_TYPE_P(offset) == IS_STRING)) {
5747				key = Z_STR_P(offset);
5748				if (OP2_TYPE != IS_CONST) {
5749					if (ZEND_HANDLE_NUMERIC(key, hval)) {
5750						ZEND_VM_C_GOTO(num_index_dim);
5751					}
5752				}
5753ZEND_VM_C_LABEL(str_index_dim):
5754				if (ht == &EG(symbol_table)) {
5755					zend_delete_global_variable(key);
5756				} else {
5757					zend_hash_del(ht, key);
5758				}
5759			} else if (EXPECTED(Z_TYPE_P(offset) == IS_LONG)) {
5760				hval = Z_LVAL_P(offset);
5761ZEND_VM_C_LABEL(num_index_dim):
5762				zend_hash_index_del(ht, hval);
5763			} else if ((OP2_TYPE & (IS_VAR|IS_CV)) && EXPECTED(Z_TYPE_P(offset) == IS_REFERENCE)) {
5764				offset = Z_REFVAL_P(offset);
5765				ZEND_VM_C_GOTO(offset_again);
5766			} else if (Z_TYPE_P(offset) == IS_DOUBLE) {
5767				hval = zend_dval_to_lval(Z_DVAL_P(offset));
5768				ZEND_VM_C_GOTO(num_index_dim);
5769			} else if (Z_TYPE_P(offset) == IS_NULL) {
5770				key = ZSTR_EMPTY_ALLOC();
5771				ZEND_VM_C_GOTO(str_index_dim);
5772			} else if (Z_TYPE_P(offset) == IS_FALSE) {
5773				hval = 0;
5774				ZEND_VM_C_GOTO(num_index_dim);
5775			} else if (Z_TYPE_P(offset) == IS_TRUE) {
5776				hval = 1;
5777				ZEND_VM_C_GOTO(num_index_dim);
5778			} else if (Z_TYPE_P(offset) == IS_RESOURCE) {
5779				hval = Z_RES_HANDLE_P(offset);
5780				ZEND_VM_C_GOTO(num_index_dim);
5781			} else if (OP2_TYPE == IS_CV && Z_TYPE_P(offset) == IS_UNDEF) {
5782				GET_OP2_UNDEF_CV(offset, BP_VAR_R);
5783				key = ZSTR_EMPTY_ALLOC();
5784				ZEND_VM_C_GOTO(str_index_dim);
5785			} else {
5786				zend_error(E_WARNING, "Illegal offset type in unset");
5787			}
5788			break;
5789		} else if (OP1_TYPE != IS_UNUSED && Z_ISREF_P(container)) {
5790			container = Z_REFVAL_P(container);
5791			if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
5792				ZEND_VM_C_GOTO(unset_dim_array);
5793			}
5794		}
5795		if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(offset) == IS_UNDEF)) {
5796			offset = GET_OP2_UNDEF_CV(offset, BP_VAR_R);
5797		}
5798		if (OP1_TYPE == IS_UNUSED || EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
5799			if (UNEXPECTED(Z_OBJ_HT_P(container)->unset_dimension == NULL)) {
5800				zend_throw_error(NULL, "Cannot use object as array");
5801			} else {
5802				Z_OBJ_HT_P(container)->unset_dimension(container, offset);
5803			}
5804		} else if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) == IS_STRING)) {
5805			zend_throw_error(NULL, "Cannot unset string offsets");
5806		}
5807	} while (0);
5808
5809	FREE_OP2();
5810	FREE_OP1_VAR_PTR();
5811	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5812}
5813
5814ZEND_VM_HANDLER(76, ZEND_UNSET_OBJ, VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
5815{
5816	USE_OPLINE
5817	zend_free_op free_op1, free_op2;
5818	zval *container;
5819	zval *offset;
5820
5821	SAVE_OPLINE();
5822	container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_UNSET);
5823	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
5824		zend_throw_error(NULL, "Using $this when not in object context");
5825		FREE_UNFETCHED_OP2();
5826		HANDLE_EXCEPTION();
5827	}
5828	offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
5829
5830	do {
5831		if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
5832			if (Z_ISREF_P(container)) {
5833				container = Z_REFVAL_P(container);
5834				if (Z_TYPE_P(container) != IS_OBJECT) {
5835					break;
5836				}
5837			} else {
5838				break;
5839			}
5840		}
5841		if (Z_OBJ_HT_P(container)->unset_property) {
5842			Z_OBJ_HT_P(container)->unset_property(container, offset, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(offset)) : NULL));
5843		} else {
5844			zend_error(E_NOTICE, "Trying to unset property of non-object");
5845		}
5846	} while (0);
5847
5848	FREE_OP2();
5849	FREE_OP1_VAR_PTR();
5850	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5851}
5852
5853ZEND_VM_HANDLER(77, ZEND_FE_RESET_R, CONST|TMP|VAR|CV, JMP_ADDR)
5854{
5855	USE_OPLINE
5856	zend_free_op free_op1;
5857	zval *array_ptr, *result;
5858	HashTable *fe_ht;
5859
5860	SAVE_OPLINE();
5861
5862	array_ptr = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
5863	if (EXPECTED(Z_TYPE_P(array_ptr) == IS_ARRAY)) {
5864		result = EX_VAR(opline->result.var);
5865		ZVAL_COPY_VALUE(result, array_ptr);
5866		if (OP1_TYPE != IS_TMP_VAR && Z_OPT_REFCOUNTED_P(result)) {
5867			Z_ADDREF_P(array_ptr);
5868		}
5869		Z_FE_POS_P(result) = 0;
5870
5871		FREE_OP1_IF_VAR();
5872		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5873	} else if (OP1_TYPE != IS_CONST && EXPECTED(Z_TYPE_P(array_ptr) == IS_OBJECT)) {
5874		if (!Z_OBJCE_P(array_ptr)->get_iterator) {
5875			HashPosition pos = 0;
5876			Bucket *p;
5877
5878			result = EX_VAR(opline->result.var);
5879			ZVAL_COPY_VALUE(result, array_ptr);
5880			if (OP1_TYPE != IS_TMP_VAR) {
5881				Z_ADDREF_P(array_ptr);
5882			}
5883			fe_ht = Z_OBJPROP_P(array_ptr);
5884			pos = 0;
5885			p = fe_ht->arData;
5886			while (1) {
5887				if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
5888					FREE_OP1_IF_VAR();
5889					Z_FE_ITER_P(EX_VAR(opline->result.var)) = (uint32_t)-1;
5890					ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
5891				}
5892				if ((EXPECTED(Z_TYPE(p->val) != IS_UNDEF) &&
5893				     (EXPECTED(Z_TYPE(p->val) != IS_INDIRECT) ||
5894				      EXPECTED(Z_TYPE_P(Z_INDIRECT(p->val)) != IS_UNDEF))) &&
5895				    (UNEXPECTED(!p->key) ||
5896				     EXPECTED(zend_check_property_access(Z_OBJ_P(array_ptr), p->key) == SUCCESS))) {
5897					break;
5898				}
5899				pos++;
5900				p++;
5901			}
5902			Z_FE_ITER_P(EX_VAR(opline->result.var)) = zend_hash_iterator_add(fe_ht, pos);
5903
5904			FREE_OP1_IF_VAR();
5905			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5906		} else {
5907			zend_class_entry *ce = Z_OBJCE_P(array_ptr);
5908			zend_object_iterator *iter = ce->get_iterator(ce, array_ptr, 0);
5909			zend_bool is_empty;
5910
5911			if (UNEXPECTED(!iter) || UNEXPECTED(EG(exception))) {
5912				FREE_OP1();
5913				if (!EG(exception)) {
5914					zend_throw_exception_ex(NULL, 0, "Object of type %s did not create an Iterator", ZSTR_VAL(ce->name));
5915				}
5916				zend_throw_exception_internal(NULL);
5917				HANDLE_EXCEPTION();
5918			}
5919
5920			iter->index = 0;
5921			if (iter->funcs->rewind) {
5922				iter->funcs->rewind(iter);
5923				if (UNEXPECTED(EG(exception) != NULL)) {
5924					OBJ_RELEASE(&iter->std);
5925					FREE_OP1();
5926					HANDLE_EXCEPTION();
5927				}
5928			}
5929
5930			is_empty = iter->funcs->valid(iter) != SUCCESS;
5931
5932			if (UNEXPECTED(EG(exception) != NULL)) {
5933				OBJ_RELEASE(&iter->std);
5934				FREE_OP1();
5935				HANDLE_EXCEPTION();
5936			}
5937			iter->index = -1; /* will be set to 0 before using next handler */
5938
5939			ZVAL_OBJ(EX_VAR(opline->result.var), &iter->std);
5940			Z_FE_ITER_P(EX_VAR(opline->result.var)) = (uint32_t)-1;
5941
5942			FREE_OP1();
5943			if (is_empty) {
5944				ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
5945			} else {
5946				ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5947			}
5948		}
5949	} else {
5950		zend_error(E_WARNING, "Invalid argument supplied for foreach()");
5951		ZVAL_UNDEF(EX_VAR(opline->result.var));
5952		Z_FE_ITER_P(EX_VAR(opline->result.var)) = (uint32_t)-1;
5953		FREE_OP1();
5954		ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
5955	}
5956}
5957
5958ZEND_VM_HANDLER(125, ZEND_FE_RESET_RW, CONST|TMP|VAR|CV, JMP_ADDR)
5959{
5960	USE_OPLINE
5961	zend_free_op free_op1;
5962	zval *array_ptr, *array_ref;
5963	HashTable *fe_ht;
5964	HashPosition pos = 0;
5965	Bucket *p;
5966
5967	SAVE_OPLINE();
5968
5969	if (OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) {
5970		array_ref = array_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_R);
5971		if (Z_ISREF_P(array_ref)) {
5972			array_ptr = Z_REFVAL_P(array_ref);
5973		}
5974	} else {
5975		array_ref = array_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
5976	}
5977
5978	if (EXPECTED(Z_TYPE_P(array_ptr) == IS_ARRAY)) {
5979		if (OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) {
5980			if (array_ptr == array_ref) {
5981				ZVAL_NEW_REF(array_ref, array_ref);
5982				array_ptr = Z_REFVAL_P(array_ref);
5983			}
5984			Z_ADDREF_P(array_ref);
5985			ZVAL_COPY_VALUE(EX_VAR(opline->result.var), array_ref);
5986		} else {
5987			array_ref = EX_VAR(opline->result.var);
5988			ZVAL_NEW_REF(array_ref, array_ptr);
5989			array_ptr = Z_REFVAL_P(array_ref);
5990		}
5991		if (OP1_TYPE == IS_CONST) {
5992			zval_copy_ctor_func(array_ptr);
5993		} else {
5994			SEPARATE_ARRAY(array_ptr);
5995		}
5996		fe_ht = Z_ARRVAL_P(array_ptr);
5997		p = fe_ht->arData;
5998		while (1) {
5999			if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
6000				FREE_OP1_VAR_PTR();
6001				Z_FE_ITER_P(EX_VAR(opline->result.var)) = (uint32_t)-1;
6002				ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
6003			}
6004			if (EXPECTED(Z_TYPE(p->val) != IS_UNDEF) &&
6005			    (EXPECTED(Z_TYPE(p->val) != IS_INDIRECT) ||
6006			     EXPECTED(Z_TYPE_P(Z_INDIRECT(p->val)) != IS_UNDEF))) {
6007				break;
6008			}
6009			pos++;
6010			p++;
6011		}
6012		Z_FE_ITER_P(EX_VAR(opline->result.var)) = zend_hash_iterator_add(fe_ht, pos);
6013
6014		FREE_OP1_VAR_PTR();
6015		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6016	} else if (OP1_TYPE != IS_CONST && EXPECTED(Z_TYPE_P(array_ptr) == IS_OBJECT)) {
6017		if (!Z_OBJCE_P(array_ptr)->get_iterator) {
6018			if (OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) {
6019				if (array_ptr == array_ref) {
6020					ZVAL_NEW_REF(array_ref, array_ref);
6021					array_ptr = Z_REFVAL_P(array_ref);
6022				}
6023				Z_ADDREF_P(array_ref);
6024				ZVAL_COPY_VALUE(EX_VAR(opline->result.var), array_ref);
6025			} else {
6026				array_ptr = EX_VAR(opline->result.var);
6027				ZVAL_COPY_VALUE(array_ptr, array_ref);
6028			}
6029			fe_ht = Z_OBJPROP_P(array_ptr);
6030			p = fe_ht->arData;
6031			while (1) {
6032				if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
6033					FREE_OP1_VAR_PTR();
6034					Z_FE_ITER_P(EX_VAR(opline->result.var)) = (uint32_t)-1;
6035					ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
6036				}
6037				if ((EXPECTED(Z_TYPE(p->val) != IS_UNDEF) &&
6038				     (EXPECTED(Z_TYPE(p->val) != IS_INDIRECT) ||
6039				      EXPECTED(Z_TYPE_P(Z_INDIRECT(p->val)) != IS_UNDEF))) &&
6040				    (UNEXPECTED(!p->key) ||
6041				     EXPECTED(zend_check_property_access(Z_OBJ_P(array_ptr), p->key) == SUCCESS))) {
6042					break;
6043				}
6044				pos++;
6045				p++;
6046			}
6047			Z_FE_ITER_P(EX_VAR(opline->result.var)) = zend_hash_iterator_add(fe_ht, pos);
6048
6049			FREE_OP1_VAR_PTR();
6050			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6051		} else {
6052			zend_class_entry *ce = Z_OBJCE_P(array_ptr);
6053			zend_object_iterator *iter = ce->get_iterator(ce, array_ptr, 1);
6054			zend_bool is_empty;
6055
6056			if (UNEXPECTED(!iter) || UNEXPECTED(EG(exception))) {
6057				if (OP1_TYPE == IS_VAR) {
6058					FREE_OP1_VAR_PTR();
6059				} else {
6060					FREE_OP1();
6061				}
6062				if (!EG(exception)) {
6063					zend_throw_exception_ex(NULL, 0, "Object of type %s did not create an Iterator", ZSTR_VAL(ce->name));
6064				}
6065				zend_throw_exception_internal(NULL);
6066				HANDLE_EXCEPTION();
6067			}
6068
6069			iter->index = 0;
6070			if (iter->funcs->rewind) {
6071				iter->funcs->rewind(iter);
6072				if (UNEXPECTED(EG(exception) != NULL)) {
6073					OBJ_RELEASE(&iter->std);
6074					if (OP1_TYPE == IS_VAR) {
6075						FREE_OP1_VAR_PTR();
6076					} else {
6077						FREE_OP1();
6078					}
6079					HANDLE_EXCEPTION();
6080				}
6081			}
6082
6083			is_empty = iter->funcs->valid(iter) != SUCCESS;
6084
6085			if (UNEXPECTED(EG(exception) != NULL)) {
6086				OBJ_RELEASE(&iter->std);
6087				if (OP1_TYPE == IS_VAR) {
6088					FREE_OP1_VAR_PTR();
6089				} else {
6090					FREE_OP1();
6091				}
6092				HANDLE_EXCEPTION();
6093			}
6094			iter->index = -1; /* will be set to 0 before using next handler */
6095
6096			ZVAL_OBJ(EX_VAR(opline->result.var), &iter->std);
6097			Z_FE_ITER_P(EX_VAR(opline->result.var)) = (uint32_t)-1;
6098
6099			if (OP1_TYPE == IS_VAR) {
6100				FREE_OP1_VAR_PTR();
6101			} else {
6102				FREE_OP1();
6103			}
6104			if (is_empty) {
6105				ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
6106			} else {
6107				ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6108			}
6109		}
6110	} else {
6111		zend_error(E_WARNING, "Invalid argument supplied for foreach()");
6112		ZVAL_UNDEF(EX_VAR(opline->result.var));
6113		Z_FE_ITER_P(EX_VAR(opline->result.var)) = (uint32_t)-1;
6114		if (OP1_TYPE == IS_VAR) {
6115			FREE_OP1_VAR_PTR();
6116		} else {
6117			FREE_OP1();
6118		}
6119		ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
6120	}
6121}
6122
6123ZEND_VM_HANDLER(78, ZEND_FE_FETCH_R, VAR, ANY, JMP_ADDR)
6124{
6125	USE_OPLINE
6126	zval *array;
6127	zval *value;
6128	uint32_t value_type;
6129	HashTable *fe_ht;
6130	HashPosition pos;
6131	Bucket *p;
6132
6133	array = EX_VAR(opline->op1.var);
6134	SAVE_OPLINE();
6135	if (EXPECTED(Z_TYPE_P(array) == IS_ARRAY)) {
6136		fe_ht = Z_ARRVAL_P(array);
6137		pos = Z_FE_POS_P(array);
6138		p = fe_ht->arData + pos;
6139		while (1) {
6140			if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
6141				/* reached end of iteration */
6142				ZEND_VM_C_GOTO(fe_fetch_r_exit);
6143			}
6144			value = &p->val;
6145			value_type = Z_TYPE_INFO_P(value);
6146			if (value_type == IS_UNDEF) {
6147				pos++;
6148				p++;
6149				continue;
6150			} else if (UNEXPECTED(value_type == IS_INDIRECT)) {
6151				value = Z_INDIRECT_P(value);
6152				value_type = Z_TYPE_INFO_P(value);
6153				if (UNEXPECTED(value_type == IS_UNDEF)) {
6154					pos++;
6155					p++;
6156					continue;
6157				}
6158			}
6159			break;
6160		}
6161		Z_FE_POS_P(array) = pos + 1;
6162		if (opline->result_type & (IS_TMP_VAR|IS_CV)) {
6163			if (!p->key) {
6164				ZVAL_LONG(EX_VAR(opline->result.var), p->h);
6165			} else {
6166				ZVAL_STR_COPY(EX_VAR(opline->result.var), p->key);
6167			}
6168		}
6169	} else if (EXPECTED(Z_TYPE_P(array) == IS_OBJECT)) {
6170		zend_object_iterator *iter;
6171
6172		if ((iter = zend_iterator_unwrap(array)) == NULL) {
6173			/* plain object */
6174
6175 			fe_ht = Z_OBJPROP_P(array);
6176			pos = zend_hash_iterator_pos(Z_FE_ITER_P(array), fe_ht);
6177			p = fe_ht->arData + pos;
6178			while (1) {
6179				if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
6180					/* reached end of iteration */
6181					ZEND_VM_C_GOTO(fe_fetch_r_exit);
6182				}
6183
6184				value = &p->val;
6185				value_type = Z_TYPE_INFO_P(value);
6186				if (UNEXPECTED(value_type == IS_UNDEF)) {
6187					pos++;
6188					p++;
6189					continue;
6190				} else if (UNEXPECTED(value_type == IS_INDIRECT)) {
6191					value = Z_INDIRECT_P(value);
6192					value_type = Z_TYPE_INFO_P(value);
6193					if (UNEXPECTED(value_type == IS_UNDEF)) {
6194						pos++;
6195						p++;
6196						continue;
6197					}
6198				}
6199				if (UNEXPECTED(!p->key) ||
6200				    EXPECTED(zend_check_property_access(Z_OBJ_P(array), p->key) == SUCCESS)) {
6201					break;
6202				}
6203				pos++;
6204				p++;
6205			}
6206			if (opline->result_type & (IS_TMP_VAR|IS_CV)) {
6207				if (UNEXPECTED(!p->key)) {
6208					ZVAL_LONG(EX_VAR(opline->result.var), p->h);
6209				} else if (ZSTR_VAL(p->key)[0]) {
6210					ZVAL_STR_COPY(EX_VAR(opline->result.var), p->key);
6211				} else {
6212					const char *class_name, *prop_name;
6213					size_t prop_name_len;
6214					zend_unmangle_property_name_ex(
6215						p->key, &class_name, &prop_name, &prop_name_len);
6216					ZVAL_STRINGL(EX_VAR(opline->result.var), prop_name, prop_name_len);
6217				}
6218			}
6219			while (1) {
6220				pos++;
6221				if (pos >= fe_ht->nNumUsed) {
6222					pos = HT_INVALID_IDX;
6223					break;
6224				}
6225				p++;
6226				if ((EXPECTED(Z_TYPE(p->val) != IS_UNDEF) &&
6227				     (EXPECTED(Z_TYPE(p->val) != IS_INDIRECT) ||
6228				      EXPECTED(Z_TYPE_P(Z_INDIRECT(p->val)) != IS_UNDEF))) &&
6229				    (UNEXPECTED(!p->key) ||
6230				     EXPECTED(zend_check_property_access(Z_OBJ_P(array), p->key) == SUCCESS))) {
6231					break;
6232				}
6233			}
6234			EG(ht_iterators)[Z_FE_ITER_P(array)].pos = pos;
6235		} else {
6236			if (EXPECTED(++iter->index > 0)) {
6237				/* This could cause an endless loop if index becomes zero again.
6238				 * In case that ever happens we need an additional flag. */
6239				iter->funcs->move_forward(iter);
6240				if (UNEXPECTED(EG(exception) != NULL)) {
6241					HANDLE_EXCEPTION();
6242				}
6243				if (UNEXPECTED(iter->funcs->valid(iter) == FAILURE)) {
6244					/* reached end of iteration */
6245					if (UNEXPECTED(EG(exception) != NULL)) {
6246						HANDLE_EXCEPTION();
6247					}
6248					ZEND_VM_C_GOTO(fe_fetch_r_exit);
6249				}
6250			}
6251			value = iter->funcs->get_current_data(iter);
6252			if (UNEXPECTED(EG(exception) != NULL)) {
6253				HANDLE_EXCEPTION();
6254			}
6255			if (!value) {
6256				/* failure in get_current_data */
6257				ZEND_VM_C_GOTO(fe_fetch_r_exit);
6258			}
6259			if (opline->result_type & (IS_TMP_VAR|IS_CV)) {
6260				if (iter->funcs->get_current_key) {
6261					iter->funcs->get_current_key(iter, EX_VAR(opline->result.var));
6262					if (UNEXPECTED(EG(exception) != NULL)) {
6263						HANDLE_EXCEPTION();
6264					}
6265				} else {
6266					ZVAL_LONG(EX_VAR(opline->result.var), iter->index);
6267				}
6268			}
6269			value_type = Z_TYPE_INFO_P(value);
6270		}
6271	} else {
6272		zend_error(E_WARNING, "Invalid argument supplied for foreach()");
6273		if (UNEXPECTED(EG(exception))) {
6274			HANDLE_EXCEPTION();
6275		}
6276ZEND_VM_C_LABEL(fe_fetch_r_exit):
6277		ZEND_VM_SET_RELATIVE_OPCODE(opline, opline->extended_value);
6278		ZEND_VM_CONTINUE();
6279	}
6280
6281	if (EXPECTED(OP2_TYPE == IS_CV)) {
6282		zval *variable_ptr = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->op2.var);
6283		zend_assign_to_variable(variable_ptr, value, IS_CV);
6284	} else {
6285		zval *res = EX_VAR(opline->op2.var);
6286		zend_refcounted *gc = Z_COUNTED_P(value);
6287
6288		ZVAL_COPY_VALUE_EX(res, value, gc, value_type);
6289		if (EXPECTED((value_type & (IS_TYPE_REFCOUNTED << Z_TYPE_FLAGS_SHIFT)) != 0)) {
6290			GC_REFCOUNT(gc)++;
6291		}
6292	}
6293	ZEND_VM_NEXT_OPCODE();
6294}
6295
6296ZEND_VM_HANDLER(126, ZEND_FE_FETCH_RW, VAR, ANY, JMP_ADDR)
6297{
6298	USE_OPLINE
6299	zval *array;
6300	zval *value;
6301	uint32_t value_type;
6302	HashTable *fe_ht;
6303	HashPosition pos;
6304	Bucket *p;
6305
6306	array = EX_VAR(opline->op1.var);
6307	SAVE_OPLINE();
6308
6309	ZVAL_DEREF(array);
6310	if (EXPECTED(Z_TYPE_P(array) == IS_ARRAY)) {
6311		pos = zend_hash_iterator_pos_ex(Z_FE_ITER_P(EX_VAR(opline->op1.var)), array);
6312		fe_ht = Z_ARRVAL_P(array);
6313		p = fe_ht->arData + pos;
6314		while (1) {
6315			if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
6316				/* reached end of iteration */
6317				ZEND_VM_C_GOTO(fe_fetch_w_exit);
6318			}
6319			value = &p->val;
6320			value_type = Z_TYPE_INFO_P(value);
6321			if (UNEXPECTED(value_type == IS_UNDEF)) {
6322				pos++;
6323				p++;
6324				continue;
6325			} else if (UNEXPECTED(value_type == IS_INDIRECT)) {
6326				value = Z_INDIRECT_P(value);
6327				value_type = Z_TYPE_INFO_P(value);
6328				if (UNEXPECTED(value_type == IS_UNDEF)) {
6329					pos++;
6330					p++;
6331					continue;
6332				}
6333			}
6334			break;
6335		}
6336		if (opline->result_type & (IS_TMP_VAR|IS_CV)) {
6337			if (!p->key) {
6338				ZVAL_LONG(EX_VAR(opline->result.var), p->h);
6339			} else {
6340				ZVAL_STR_COPY(EX_VAR(opline->result.var), p->key);
6341			}
6342		}
6343		while (1) {
6344			pos++;
6345			if (pos >= fe_ht->nNumUsed) {
6346				pos = HT_INVALID_IDX;
6347				break;
6348			}
6349			p++;
6350			if (EXPECTED(Z_TYPE(p->val) != IS_UNDEF) &&
6351			    (EXPECTED(Z_TYPE(p->val) != IS_INDIRECT) ||
6352			     EXPECTED(Z_TYPE_P(Z_INDIRECT(p->val)) != IS_UNDEF))) {
6353				break;
6354			}
6355		}
6356		EG(ht_iterators)[Z_FE_ITER_P(EX_VAR(opline->op1.var))].pos = pos;
6357	} else if (EXPECTED(Z_TYPE_P(array) == IS_OBJECT)) {
6358		zend_object_iterator *iter;
6359
6360		if ((iter = zend_iterator_unwrap(array)) == NULL) {
6361			/* plain object */
6362
6363 			fe_ht = Z_OBJPROP_P(array);
6364			pos = zend_hash_iterator_pos(Z_FE_ITER_P(EX_VAR(opline->op1.var)), fe_ht);
6365			p = fe_ht->arData + pos;
6366			while (1) {
6367				if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
6368					/* reached end of iteration */
6369					ZEND_VM_C_GOTO(fe_fetch_w_exit);
6370				}
6371
6372				value = &p->val;
6373				value_type = Z_TYPE_INFO_P(value);
6374				if (UNEXPECTED(value_type == IS_UNDEF)) {
6375					pos++;
6376					p++;
6377					continue;
6378				} else if (UNEXPECTED(value_type == IS_INDIRECT)) {
6379					value = Z_INDIRECT_P(value);
6380					value_type = Z_TYPE_INFO_P(value);
6381					if (UNEXPECTED(value_type == IS_UNDEF)) {
6382						pos++;
6383						p++;
6384						continue;
6385					}
6386				}
6387				if (UNEXPECTED(!p->key) ||
6388				    EXPECTED(zend_check_property_access(Z_OBJ_P(array), p->key) == SUCCESS)) {
6389					break;
6390				}
6391				pos++;
6392				p++;
6393			}
6394			if (opline->result_type & (IS_TMP_VAR|IS_CV)) {
6395				if (UNEXPECTED(!p->key)) {
6396					ZVAL_LONG(EX_VAR(opline->result.var), p->h);
6397				} else if (ZSTR_VAL(p->key)[0]) {
6398					ZVAL_STR_COPY(EX_VAR(opline->result.var), p->key);
6399				} else {
6400					const char *class_name, *prop_name;
6401					size_t prop_name_len;
6402					zend_unmangle_property_name_ex(
6403						p->key, &class_name, &prop_name, &prop_name_len);
6404					ZVAL_STRINGL(EX_VAR(opline->result.var), prop_name, prop_name_len);
6405				}
6406			}
6407			while (1) {
6408				pos++;
6409				if (pos >= fe_ht->nNumUsed) {
6410					pos = HT_INVALID_IDX;
6411					break;
6412				}
6413				p++;
6414				if ((EXPECTED(Z_TYPE(p->val) != IS_UNDEF) &&
6415				     (EXPECTED(Z_TYPE(p->val) != IS_INDIRECT) ||
6416				      EXPECTED(Z_TYPE_P(Z_INDIRECT(p->val)) != IS_UNDEF))) &&
6417				    (UNEXPECTED(!p->key) ||
6418				     EXPECTED(zend_check_property_access(Z_OBJ_P(array), p->key) == SUCCESS))) {
6419					break;
6420				}
6421			}
6422			EG(ht_iterators)[Z_FE_ITER_P(EX_VAR(opline->op1.var))].pos = pos;
6423		} else {
6424			if (++iter->index > 0) {
6425				/* This could cause an endless loop if index becomes zero again.
6426				 * In case that ever happens we need an additional flag. */
6427				iter->funcs->move_forward(iter);
6428				if (UNEXPECTED(EG(exception) != NULL)) {
6429					HANDLE_EXCEPTION();
6430				}
6431				if (UNEXPECTED(iter->funcs->valid(iter) == FAILURE)) {
6432					/* reached end of iteration */
6433					if (UNEXPECTED(EG(exception) != NULL)) {
6434						HANDLE_EXCEPTION();
6435					}
6436					ZEND_VM_C_GOTO(fe_fetch_w_exit);
6437				}
6438			}
6439			value = iter->funcs->get_current_data(iter);
6440			if (UNEXPECTED(EG(exception) != NULL)) {
6441				HANDLE_EXCEPTION();
6442			}
6443			if (!value) {
6444				/* failure in get_current_data */
6445				ZEND_VM_C_GOTO(fe_fetch_w_exit);
6446			}
6447			if (opline->result_type & (IS_TMP_VAR|IS_CV)) {
6448				if (iter->funcs->get_current_key) {
6449					iter->funcs->get_current_key(iter, EX_VAR(opline->result.var));
6450					if (UNEXPECTED(EG(exception) != NULL)) {
6451						HANDLE_EXCEPTION();
6452					}
6453				} else {
6454					ZVAL_LONG(EX_VAR(opline->result.var), iter->index);
6455				}
6456			}
6457			value_type = Z_TYPE_INFO_P(value);
6458		}
6459	} else {
6460		zend_error(E_WARNING, "Invalid argument supplied for foreach()");
6461		if (UNEXPECTED(EG(exception))) {
6462			HANDLE_EXCEPTION();
6463		}
6464ZEND_VM_C_LABEL(fe_fetch_w_exit):
6465		ZEND_VM_SET_RELATIVE_OPCODE(opline, opline->extended_value);
6466		ZEND_VM_CONTINUE();
6467	}
6468
6469	if (EXPECTED((value_type & Z_TYPE_MASK) != IS_REFERENCE)) {
6470		zend_refcounted *gc = Z_COUNTED_P(value);
6471		zval *ref;
6472		ZVAL_NEW_EMPTY_REF(value);
6473		ref = Z_REFVAL_P(value);
6474		ZVAL_COPY_VALUE_EX(ref, value, gc, value_type);
6475	}
6476	if (EXPECTED(OP2_TYPE == IS_CV)) {
6477		zval *variable_ptr = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->op2.var);
6478		if (EXPECTED(variable_ptr != value)) {
6479			zend_reference *ref;
6480
6481			ref = Z_REF_P(value);
6482			GC_REFCOUNT(ref)++;
6483			zval_ptr_dtor(variable_ptr);
6484			ZVAL_REF(variable_ptr, ref);
6485		}
6486	} else {
6487		Z_ADDREF_P(value);
6488		ZVAL_REF(EX_VAR(opline->op2.var), Z_REF_P(value));
6489	}
6490	ZEND_VM_NEXT_OPCODE();
6491}
6492
6493ZEND_VM_HANDLER(114, ZEND_ISSET_ISEMPTY_VAR, CONST|TMPVAR|CV, UNUSED, VAR_FETCH|ISSET)
6494{
6495	USE_OPLINE
6496	zval *value;
6497	int result;
6498
6499	if (OP1_TYPE == IS_CV &&
6500	    (opline->extended_value & ZEND_QUICK_SET)) {
6501		value = EX_VAR(opline->op1.var);
6502		if (opline->extended_value & ZEND_ISSET) {
6503			result =
6504				Z_TYPE_P(value) > IS_NULL &&
6505			    (!Z_ISREF_P(value) || Z_TYPE_P(Z_REFVAL_P(value)) != IS_NULL);
6506		} else /* if (opline->extended_value & ZEND_ISEMPTY) */ {
6507			SAVE_OPLINE();
6508			result = !i_zend_is_true(value);
6509			if (UNEXPECTED(EG(exception))) {
6510				HANDLE_EXCEPTION();
6511			}
6512		}
6513		ZEND_VM_SMART_BRANCH(result, 0);
6514		ZVAL_BOOL(EX_VAR(opline->result.var), result);
6515		ZEND_VM_SET_NEXT_OPCODE(opline + 1);
6516		ZEND_VM_CONTINUE();
6517	} else {
6518		zend_free_op free_op1;
6519		zval tmp, *varname;
6520		HashTable *target_symbol_table;
6521
6522		SAVE_OPLINE();
6523		varname = GET_OP1_ZVAL_PTR(BP_VAR_IS);
6524		ZVAL_UNDEF(&tmp);
6525		if (OP1_TYPE != IS_CONST && Z_TYPE_P(varname) != IS_STRING) {
6526			ZVAL_STR(&tmp, zval_get_string(varname));
6527			varname = &tmp;
6528		}
6529
6530		target_symbol_table = zend_get_target_symbol_table(execute_data, opline->extended_value & ZEND_FETCH_TYPE_MASK);
6531		value = zend_hash_find_ind(target_symbol_table, Z_STR_P(varname));
6532
6533		if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
6534			zend_string_release(Z_STR(tmp));
6535		}
6536		FREE_OP1();
6537
6538		if (opline->extended_value & ZEND_ISSET) {
6539			result = value && Z_TYPE_P(value) > IS_NULL &&
6540			    (!Z_ISREF_P(value) || Z_TYPE_P(Z_REFVAL_P(value)) != IS_NULL);
6541		} else /* if (opline->extended_value & ZEND_ISEMPTY) */ {
6542			result = !value || !i_zend_is_true(value);
6543		}
6544
6545		ZEND_VM_SMART_BRANCH(result, 1);
6546		ZVAL_BOOL(EX_VAR(opline->result.var), result);
6547		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6548	}
6549}
6550
6551ZEND_VM_HANDLER(180, ZEND_ISSET_ISEMPTY_STATIC_PROP, CONST|TMPVAR|CV, UNUSED|CLASS_FETCH|CONST|VAR, ISSET)
6552{
6553	USE_OPLINE
6554	zval *value;
6555	int result;
6556	zend_free_op free_op1;
6557	zval tmp, *varname;
6558	zend_class_entry *ce;
6559
6560	SAVE_OPLINE();
6561	varname = GET_OP1_ZVAL_PTR(BP_VAR_IS);
6562	ZVAL_UNDEF(&tmp);
6563	if (OP1_TYPE != IS_CONST && Z_TYPE_P(varname) != IS_STRING) {
6564		ZVAL_STR(&tmp, zval_get_string(varname));
6565		varname = &tmp;
6566	}
6567
6568	if (OP2_TYPE == IS_CONST) {
6569		if (OP1_TYPE == IS_CONST && EXPECTED((ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)))) != NULL)) {
6570			value = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)) + sizeof(void*));
6571
6572			/* check if static properties were destoyed */
6573			if (UNEXPECTED(CE_STATIC_MEMBERS(ce) == NULL)) {
6574				value = NULL;
6575			}
6576
6577			ZEND_VM_C_GOTO(is_static_prop_return);
6578		} else if (UNEXPECTED((ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) == NULL)) {
6579			ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op2)), EX_CONSTANT(opline->op2) + 1, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
6580			if (UNEXPECTED(ce == NULL)) {
6581				ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6582			}
6583			CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce);
6584		}
6585	} else {
6586		if (OP2_TYPE == IS_UNUSED) {
6587			ce = zend_fetch_class(NULL, opline->op2.num);
6588			if (UNEXPECTED(ce == NULL)) {
6589				ZEND_ASSERT(EG(exception));
6590				if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
6591					zend_string_release(Z_STR(tmp));
6592				}
6593				FREE_OP1();
6594				HANDLE_EXCEPTION();
6595			}
6596		} else {
6597			ce = Z_CE_P(EX_VAR(opline->op2.var));
6598		}
6599		if (OP1_TYPE == IS_CONST &&
6600		    (value = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce)) != NULL) {
6601
6602			/* check if static properties were destoyed */
6603			if (UNEXPECTED(CE_STATIC_MEMBERS(ce) == NULL)) {
6604				value = NULL;
6605			}
6606
6607			ZEND_VM_C_GOTO(is_static_prop_return);
6608		}
6609	}
6610
6611	value = zend_std_get_static_property(ce, Z_STR_P(varname), 1);
6612
6613	if (OP1_TYPE == IS_CONST && value) {
6614		CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce, value);
6615	}
6616
6617	if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
6618		zend_string_release(Z_STR(tmp));
6619	}
6620	FREE_OP1();
6621
6622ZEND_VM_C_LABEL(is_static_prop_return):
6623	if (opline->extended_value & ZEND_ISSET) {
6624		result = value && Z_TYPE_P(value) > IS_NULL &&
6625		    (!Z_ISREF_P(value) || Z_TYPE_P(Z_REFVAL_P(value)) != IS_NULL);
6626	} else /* if (opline->extended_value & ZEND_ISEMPTY) */ {
6627		result = !value || !i_zend_is_true(value);
6628	}
6629
6630	ZEND_VM_SMART_BRANCH(result, 1);
6631	ZVAL_BOOL(EX_VAR(opline->result.var), result);
6632	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6633}
6634
6635ZEND_VM_HANDLER(115, ZEND_ISSET_ISEMPTY_DIM_OBJ, CONST|TMPVAR|UNUSED|THIS|CV, CONST|TMPVAR|CV, ISSET)
6636{
6637	USE_OPLINE
6638	zend_free_op free_op1, free_op2;
6639	zval *container;
6640	int result;
6641	zend_ulong hval;
6642	zval *offset;
6643
6644	SAVE_OPLINE();
6645	container = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_IS);
6646
6647	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
6648		zend_throw_error(NULL, "Using $this when not in object context");
6649		FREE_UNFETCHED_OP2();
6650		HANDLE_EXCEPTION();
6651	}
6652
6653	offset = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
6654
6655	if (OP1_TYPE != IS_UNUSED && EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
6656		HashTable *ht;
6657		zval *value;
6658		zend_string *str;
6659
6660ZEND_VM_C_LABEL(isset_dim_obj_array):
6661		ht = Z_ARRVAL_P(container);
6662ZEND_VM_C_LABEL(isset_again):
6663		if (EXPECTED(Z_TYPE_P(offset) == IS_STRING)) {
6664			str = Z_STR_P(offset);
6665			if (OP2_TYPE != IS_CONST) {
6666				if (ZEND_HANDLE_NUMERIC(str, hval)) {
6667					ZEND_VM_C_GOTO(num_index_prop);
6668				}
6669			}
6670ZEND_VM_C_LABEL(str_index_prop):
6671			value = zend_hash_find_ind(ht, str);
6672		} else if (EXPECTED(Z_TYPE_P(offset) == IS_LONG)) {
6673			hval = Z_LVAL_P(offset);
6674ZEND_VM_C_LABEL(num_index_prop):
6675			value = zend_hash_index_find(ht, hval);
6676		} else if ((OP2_TYPE & (IS_VAR|IS_CV)) && EXPECTED(Z_ISREF_P(offset))) {
6677			offset = Z_REFVAL_P(offset);
6678			ZEND_VM_C_GOTO(isset_again);
6679		} else if (Z_TYPE_P(offset) == IS_DOUBLE) {
6680			hval = zend_dval_to_lval(Z_DVAL_P(offset));
6681			ZEND_VM_C_GOTO(num_index_prop);
6682		} else if (Z_TYPE_P(offset) == IS_NULL) {
6683			str = ZSTR_EMPTY_ALLOC();
6684			ZEND_VM_C_GOTO(str_index_prop);
6685		} else if (Z_TYPE_P(offset) == IS_FALSE) {
6686			hval = 0;
6687			ZEND_VM_C_GOTO(num_index_prop);
6688		} else if (Z_TYPE_P(offset) == IS_TRUE) {
6689			hval = 1;
6690			ZEND_VM_C_GOTO(num_index_prop);
6691		} else if (Z_TYPE_P(offset) == IS_RESOURCE) {
6692			hval = Z_RES_HANDLE_P(offset);
6693			ZEND_VM_C_GOTO(num_index_prop);
6694		} else if (OP2_TYPE == IS_CV && Z_TYPE_P(offset) == IS_UNDEF) {
6695			GET_OP2_UNDEF_CV(offset, BP_VAR_R);
6696			str = ZSTR_EMPTY_ALLOC();
6697			ZEND_VM_C_GOTO(str_index_prop);
6698		} else {
6699			zend_error(E_WARNING, "Illegal offset type in isset or empty");
6700			ZEND_VM_C_GOTO(isset_not_found);
6701		}
6702
6703		if (opline->extended_value & ZEND_ISSET) {
6704			/* > IS_NULL means not IS_UNDEF and not IS_NULL */
6705			result = value != NULL && Z_TYPE_P(value) > IS_NULL &&
6706			    (!Z_ISREF_P(value) || Z_TYPE_P(Z_REFVAL_P(value)) != IS_NULL);
6707		} else /* if (opline->extended_value & ZEND_ISEMPTY) */ {
6708			result = (value == NULL || !i_zend_is_true(value));
6709		}
6710		ZEND_VM_C_GOTO(isset_dim_obj_exit);
6711	} else if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(container)) {
6712		container = Z_REFVAL_P(container);
6713		if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
6714			ZEND_VM_C_GOTO(isset_dim_obj_array);
6715		}
6716	}
6717
6718	if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(offset) == IS_UNDEF)) {
6719		offset = GET_OP2_UNDEF_CV(offset, BP_VAR_R);
6720	}
6721
6722	if (OP1_TYPE == IS_UNUSED ||
6723	    (OP1_TYPE != IS_CONST && EXPECTED(Z_TYPE_P(container) == IS_OBJECT))) {
6724		if (EXPECTED(Z_OBJ_HT_P(container)->has_dimension)) {
6725			result =
6726				((opline->extended_value & ZEND_ISSET) == 0) ^
6727				Z_OBJ_HT_P(container)->has_dimension(container, offset, (opline->extended_value & ZEND_ISSET) == 0);
6728		} else {
6729			zend_error(E_NOTICE, "Trying to check element of non-array");
6730			ZEND_VM_C_GOTO(isset_not_found);
6731		}
6732	} else if (EXPECTED(Z_TYPE_P(container) == IS_STRING)) { /* string offsets */
6733		zend_long lval;
6734
6735		if (EXPECTED(Z_TYPE_P(offset) == IS_LONG)) {
6736			lval = Z_LVAL_P(offset);
6737ZEND_VM_C_LABEL(isset_str_offset):
6738			if (EXPECTED(lval >= 0) && (size_t)lval < Z_STRLEN_P(container)) {
6739				if (opline->extended_value & ZEND_ISSET) {
6740					result = 1;
6741				} else {
6742					result = (Z_STRVAL_P(container)[lval] == '0');
6743				}
6744			} else {
6745				ZEND_VM_C_GOTO(isset_not_found);
6746			}
6747		} else {
6748			if (OP2_TYPE & (IS_CV|IS_VAR)) {
6749				ZVAL_DEREF(offset);
6750			}
6751			if (Z_TYPE_P(offset) < IS_STRING /* simple scalar types */
6752					|| (Z_TYPE_P(offset) == IS_STRING /* or numeric string */
6753						&& IS_LONG == is_numeric_string(Z_STRVAL_P(offset), Z_STRLEN_P(offset), NULL, NULL, 0))) {
6754				lval = zval_get_long(offset);
6755				ZEND_VM_C_GOTO(isset_str_offset);
6756			}
6757			ZEND_VM_C_GOTO(isset_not_found);
6758		}
6759	} else {
6760ZEND_VM_C_LABEL(isset_not_found):
6761		result = ((opline->extended_value & ZEND_ISSET) == 0);
6762	}
6763
6764ZEND_VM_C_LABEL(isset_dim_obj_exit):
6765	FREE_OP2();
6766	FREE_OP1();
6767	ZEND_VM_SMART_BRANCH(result, 1);
6768	ZVAL_BOOL(EX_VAR(opline->result.var), result);
6769	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6770}
6771
6772ZEND_VM_HANDLER(148, ZEND_ISSET_ISEMPTY_PROP_OBJ, CONST|TMPVAR|UNUSED|THIS|CV, CONST|TMPVAR|CV, ISSET)
6773{
6774	USE_OPLINE
6775	zend_free_op free_op1, free_op2;
6776	zval *container;
6777	int result;
6778	zval *offset;
6779
6780	SAVE_OPLINE();
6781	container = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_IS);
6782
6783	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
6784		zend_throw_error(NULL, "Using $this when not in object context");
6785		FREE_UNFETCHED_OP2();
6786		HANDLE_EXCEPTION();
6787	}
6788
6789	offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
6790
6791	if (OP1_TYPE == IS_CONST ||
6792	    (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT))) {
6793		if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(container)) {
6794			container = Z_REFVAL_P(container);
6795			if (UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
6796				ZEND_VM_C_GOTO(isset_no_object);
6797			}
6798		} else {
6799			ZEND_VM_C_GOTO(isset_no_object);
6800		}
6801	}
6802	if (UNEXPECTED(!Z_OBJ_HT_P(container)->has_property)) {
6803		zend_error(E_NOTICE, "Trying to check property of non-object");
6804ZEND_VM_C_LABEL(isset_no_object):
6805		result = ((opline->extended_value & ZEND_ISSET) == 0);
6806	} else {
6807		result =
6808			((opline->extended_value & ZEND_ISSET) == 0) ^
6809			Z_OBJ_HT_P(container)->has_property(container, offset, (opline->extended_value & ZEND_ISSET) == 0, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(offset)) : NULL));
6810	}
6811
6812	FREE_OP2();
6813	FREE_OP1();
6814	ZEND_VM_SMART_BRANCH(result, 1);
6815	ZVAL_BOOL(EX_VAR(opline->result.var), result);
6816	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6817}
6818
6819ZEND_VM_HANDLER(79, ZEND_EXIT, CONST|TMPVAR|UNUSED|CV, ANY)
6820{
6821	USE_OPLINE
6822
6823	SAVE_OPLINE();
6824	if (OP1_TYPE != IS_UNUSED) {
6825		zend_free_op free_op1;
6826		zval *ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
6827
6828		do {
6829			if (Z_TYPE_P(ptr) == IS_LONG) {
6830				EG(exit_status) = Z_LVAL_P(ptr);
6831			} else {
6832				if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(ptr)) {
6833					ptr = Z_REFVAL_P(ptr);
6834					if (Z_TYPE_P(ptr) == IS_LONG) {
6835						EG(exit_status) = Z_LVAL_P(ptr);
6836						break;
6837					}
6838				}
6839				zend_print_variable(ptr);
6840			}
6841		} while (0);
6842		FREE_OP1();
6843	}
6844	zend_bailout();
6845	ZEND_VM_NEXT_OPCODE(); /* Never reached */
6846}
6847
6848ZEND_VM_HANDLER(57, ZEND_BEGIN_SILENCE, ANY, ANY)
6849{
6850	USE_OPLINE
6851
6852	ZVAL_LONG(EX_VAR(opline->result.var), EG(error_reporting));
6853
6854	if (EG(error_reporting)) {
6855		do {
6856			EG(error_reporting) = 0;
6857			if (!EG(error_reporting_ini_entry)) {
6858				zend_ini_entry *p = zend_hash_str_find_ptr(EG(ini_directives), "error_reporting", sizeof("error_reporting")-1);
6859				if (p) {
6860					EG(error_reporting_ini_entry) = p;
6861				} else {
6862					break;
6863				}
6864			}
6865			if (!EG(error_reporting_ini_entry)->modified) {
6866				if (!EG(modified_ini_directives)) {
6867					ALLOC_HASHTABLE(EG(modified_ini_directives));
6868					zend_hash_init(EG(modified_ini_directives), 8, NULL, NULL, 0);
6869				}
6870				if (EXPECTED(zend_hash_str_add_ptr(EG(modified_ini_directives), "error_reporting", sizeof("error_reporting")-1, EG(error_reporting_ini_entry)) != NULL)) {
6871					EG(error_reporting_ini_entry)->orig_value = EG(error_reporting_ini_entry)->value;
6872					EG(error_reporting_ini_entry)->orig_modifiable = EG(error_reporting_ini_entry)->modifiable;
6873					EG(error_reporting_ini_entry)->modified = 1;
6874				}
6875			}
6876		} while (0);
6877	}
6878	ZEND_VM_NEXT_OPCODE();
6879}
6880
6881ZEND_VM_HANDLER(58, ZEND_END_SILENCE, TMP, ANY)
6882{
6883	USE_OPLINE
6884
6885	if (!EG(error_reporting) && Z_LVAL_P(EX_VAR(opline->op1.var)) != 0) {
6886		EG(error_reporting) = Z_LVAL_P(EX_VAR(opline->op1.var));
6887	}
6888	ZEND_VM_NEXT_OPCODE();
6889}
6890
6891ZEND_VM_HANDLER(152, ZEND_JMP_SET, CONST|TMP|VAR|CV, JMP_ADDR)
6892{
6893	USE_OPLINE
6894	zend_free_op free_op1;
6895	zval *value;
6896	zval *ref = NULL;
6897
6898	SAVE_OPLINE();
6899	value = GET_OP1_ZVAL_PTR(BP_VAR_R);
6900
6901	if ((OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) && Z_ISREF_P(value)) {
6902		if (OP1_TYPE == IS_VAR) {
6903			ref = value;
6904		}
6905		value = Z_REFVAL_P(value);
6906	}
6907	if (i_zend_is_true(value)) {
6908		ZVAL_COPY_VALUE(EX_VAR(opline->result.var), value);
6909		if (OP1_TYPE == IS_CONST) {
6910			if (UNEXPECTED(Z_OPT_COPYABLE_P(value))) {
6911				zval_copy_ctor_func(EX_VAR(opline->result.var));
6912			}
6913		} else if (OP1_TYPE == IS_CV) {
6914			if (Z_OPT_REFCOUNTED_P(value)) Z_ADDREF_P(value);
6915		} else if (OP1_TYPE == IS_VAR && ref) {
6916			zend_reference *r = Z_REF_P(ref);
6917
6918			if (Z_OPT_REFCOUNTED_P(value)) Z_ADDREF_P(value);
6919			if (UNEXPECTED(--GC_REFCOUNT(r) == 0)) {
6920				efree_size(r, sizeof(zend_reference));
6921			}
6922		}
6923		ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
6924	}
6925
6926	FREE_OP1();
6927	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6928}
6929
6930ZEND_VM_HANDLER(169, ZEND_COALESCE, CONST|TMP|VAR|CV, JMP_ADDR)
6931{
6932	USE_OPLINE
6933	zend_free_op free_op1;
6934	zval *value;
6935	zval *ref = NULL;
6936
6937	SAVE_OPLINE();
6938	value = GET_OP1_ZVAL_PTR(BP_VAR_IS);
6939
6940	if ((OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) && Z_ISREF_P(value)) {
6941		if (OP1_TYPE == IS_VAR) {
6942			ref = value;
6943		}
6944		value = Z_REFVAL_P(value);
6945	}
6946
6947	if (Z_TYPE_P(value) > IS_NULL) {
6948		ZVAL_COPY_VALUE(EX_VAR(opline->result.var), value);
6949		if (OP1_TYPE == IS_CONST) {
6950			if (UNEXPECTED(Z_OPT_COPYABLE_P(value))) {
6951				zval_copy_ctor_func(EX_VAR(opline->result.var));
6952			}
6953		} else if (OP1_TYPE == IS_CV) {
6954			if (Z_OPT_REFCOUNTED_P(value)) Z_ADDREF_P(value);
6955		} else if (OP1_TYPE == IS_VAR && ref) {
6956			zend_reference *r = Z_REF_P(ref);
6957
6958			if (Z_OPT_REFCOUNTED_P(value)) Z_ADDREF_P(value);
6959			if (UNEXPECTED(--GC_REFCOUNT(r) == 0)) {
6960				efree_size(r, sizeof(zend_reference));
6961			}
6962		}
6963		ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
6964	}
6965
6966	FREE_OP1();
6967	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6968}
6969
6970ZEND_VM_HANDLER(22, ZEND_QM_ASSIGN, CONST|TMP|VAR|CV, ANY)
6971{
6972	USE_OPLINE
6973	zend_free_op free_op1;
6974	zval *value;
6975
6976	value = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
6977	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
6978		SAVE_OPLINE();
6979		GET_OP1_UNDEF_CV(value, BP_VAR_R);
6980		ZVAL_NULL(EX_VAR(opline->result.var));
6981		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6982	}
6983
6984	if ((OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) && Z_ISREF_P(value)) {
6985		ZVAL_COPY(EX_VAR(opline->result.var), Z_REFVAL_P(value));
6986		if (OP1_TYPE == IS_VAR) {
6987			if (UNEXPECTED(Z_DELREF_P(value) == 0)) {
6988				efree_size(Z_REF_P(value), sizeof(zend_reference));
6989			}
6990		}
6991	} else {
6992		ZVAL_COPY_VALUE(EX_VAR(opline->result.var), value);
6993		if (OP1_TYPE == IS_CONST) {
6994			if (UNEXPECTED(Z_OPT_COPYABLE_P(value))) {
6995				zval_copy_ctor_func(EX_VAR(opline->result.var));
6996			}
6997		} else if (OP1_TYPE == IS_CV) {
6998			if (Z_OPT_REFCOUNTED_P(value)) Z_ADDREF_P(value);
6999		}
7000	}
7001	ZEND_VM_NEXT_OPCODE();
7002}
7003
7004ZEND_VM_HANDLER(101, ZEND_EXT_STMT, ANY, ANY)
7005{
7006	USE_OPLINE
7007
7008	if (!EG(no_extensions)) {
7009		SAVE_OPLINE();
7010		zend_llist_apply_with_argument(&zend_extensions, (llist_apply_with_arg_func_t) zend_extension_statement_handler, EX(func));
7011		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7012	}
7013	ZEND_VM_NEXT_OPCODE();
7014}
7015
7016ZEND_VM_HANDLER(102, ZEND_EXT_FCALL_BEGIN, ANY, ANY)
7017{
7018	USE_OPLINE
7019
7020	if (!EG(no_extensions)) {
7021		SAVE_OPLINE();
7022		zend_llist_apply_with_argument(&zend_extensions, (llist_apply_with_arg_func_t) zend_extension_fcall_begin_handler, EX(func));
7023		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7024	}
7025	ZEND_VM_NEXT_OPCODE();
7026}
7027
7028ZEND_VM_HANDLER(103, ZEND_EXT_FCALL_END, ANY, ANY)
7029{
7030	USE_OPLINE
7031
7032	if (!EG(no_extensions)) {
7033		SAVE_OPLINE();
7034		zend_llist_apply_with_argument(&zend_extensions, (llist_apply_with_arg_func_t) zend_extension_fcall_end_handler, EX(func));
7035		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7036	}
7037	ZEND_VM_NEXT_OPCODE();
7038}
7039
7040ZEND_VM_HANDLER(139, ZEND_DECLARE_CLASS, ANY, ANY)
7041{
7042	USE_OPLINE
7043
7044	SAVE_OPLINE();
7045	Z_CE_P(EX_VAR(opline->result.var)) = do_bind_class(&EX(func)->op_array, opline, EG(class_table), 0);
7046	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7047}
7048
7049ZEND_VM_HANDLER(140, ZEND_DECLARE_INHERITED_CLASS, ANY, VAR)
7050{
7051	USE_OPLINE
7052
7053	SAVE_OPLINE();
7054	Z_CE_P(EX_VAR(opline->result.var)) = do_bind_inherited_class(&EX(func)->op_array, opline, EG(class_table), Z_CE_P(EX_VAR(opline->op2.var)), 0);
7055	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7056}
7057
7058ZEND_VM_HANDLER(145, ZEND_DECLARE_INHERITED_CLASS_DELAYED, ANY, VAR)
7059{
7060	USE_OPLINE
7061	zval *zce, *orig_zce;
7062
7063	SAVE_OPLINE();
7064	if ((zce = zend_hash_find(EG(class_table), Z_STR_P(EX_CONSTANT(opline->op1)))) == NULL ||
7065	    ((orig_zce = zend_hash_find(EG(class_table), Z_STR_P(EX_CONSTANT(opline->op1)+1))) != NULL &&
7066	     Z_CE_P(zce) != Z_CE_P(orig_zce))) {
7067		do_bind_inherited_class(&EX(func)->op_array, opline, EG(class_table), Z_CE_P(EX_VAR(opline->op2.var)), 0);
7068	}
7069	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7070}
7071
7072ZEND_VM_HANDLER(171, ZEND_DECLARE_ANON_CLASS, ANY, ANY, JMP_ADDR)
7073{
7074	zend_class_entry *ce;
7075	USE_OPLINE
7076
7077	SAVE_OPLINE();
7078	ce = zend_hash_find_ptr(EG(class_table), Z_STR_P(EX_CONSTANT(opline->op1)));
7079	Z_CE_P(EX_VAR(opline->result.var)) = ce;
7080	ZEND_ASSERT(ce != NULL);
7081
7082	if (ce->ce_flags & ZEND_ACC_ANON_BOUND) {
7083		ZEND_VM_SET_RELATIVE_OPCODE(opline, opline->extended_value);
7084		ZEND_VM_CONTINUE();
7085	}
7086
7087	if (!(ce->ce_flags & (ZEND_ACC_INTERFACE|ZEND_ACC_IMPLEMENT_INTERFACES|ZEND_ACC_IMPLEMENT_TRAITS))) {
7088		zend_verify_abstract_class(ce);
7089	}
7090	ce->ce_flags |= ZEND_ACC_ANON_BOUND;
7091	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7092}
7093
7094ZEND_VM_HANDLER(172, ZEND_DECLARE_ANON_INHERITED_CLASS, ANY, VAR, JMP_ADDR)
7095{
7096	zend_class_entry *ce;
7097	USE_OPLINE
7098
7099	SAVE_OPLINE();
7100	ce = zend_hash_find_ptr(EG(class_table), Z_STR_P(EX_CONSTANT(opline->op1)));
7101	Z_CE_P(EX_VAR(opline->result.var)) = ce;
7102	ZEND_ASSERT(ce != NULL);
7103
7104	if (ce->ce_flags & ZEND_ACC_ANON_BOUND) {
7105		ZEND_VM_SET_RELATIVE_OPCODE(opline, opline->extended_value);
7106		ZEND_VM_CONTINUE();
7107	}
7108
7109	zend_do_inheritance(ce, Z_CE_P(EX_VAR(opline->op2.var)));
7110	ce->ce_flags |= ZEND_ACC_ANON_BOUND;
7111	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7112}
7113
7114ZEND_VM_HANDLER(141, ZEND_DECLARE_FUNCTION, ANY, ANY)
7115{
7116	USE_OPLINE
7117
7118	SAVE_OPLINE();
7119	do_bind_function(&EX(func)->op_array, opline, EG(function_table), 0);
7120	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7121}
7122
7123ZEND_VM_HANDLER(105, ZEND_TICKS, ANY, ANY, NUM)
7124{
7125	USE_OPLINE
7126
7127	if ((uint32_t)++EG(ticks_count) >= opline->extended_value) {
7128		EG(ticks_count) = 0;
7129		if (zend_ticks_function) {
7130			SAVE_OPLINE();
7131			zend_ticks_function(opline->extended_value);
7132			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7133		}
7134	}
7135	ZEND_VM_NEXT_OPCODE();
7136}
7137
7138ZEND_VM_HANDLER(138, ZEND_INSTANCEOF, TMPVAR|CV, UNUSED|CLASS_FETCH|CONST|VAR)
7139{
7140	USE_OPLINE
7141	zend_free_op free_op1;
7142	zval *expr;
7143	zend_bool result;
7144
7145	SAVE_OPLINE();
7146	expr = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
7147
7148ZEND_VM_C_LABEL(try_instanceof):
7149	if (Z_TYPE_P(expr) == IS_OBJECT) {
7150		zend_class_entry *ce;
7151
7152		if (OP2_TYPE == IS_CONST) {
7153			ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
7154			if (UNEXPECTED(ce == NULL)) {
7155				ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op2)), EX_CONSTANT(opline->op2) + 1, ZEND_FETCH_CLASS_NO_AUTOLOAD);
7156				if (UNEXPECTED(ce == NULL)) {
7157					ZVAL_FALSE(EX_VAR(opline->result.var));
7158					FREE_OP1();
7159					ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7160				}
7161				CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce);
7162			}
7163		} else if (OP2_TYPE == IS_UNUSED) {
7164			ce = zend_fetch_class(NULL, opline->op2.num);
7165			if (UNEXPECTED(ce == NULL)) {
7166				ZEND_ASSERT(EG(exception));
7167				FREE_OP1();
7168				HANDLE_EXCEPTION();
7169			}
7170		} else {
7171			ce = Z_CE_P(EX_VAR(opline->op2.var));
7172		}
7173		result = ce && instanceof_function(Z_OBJCE_P(expr), ce);
7174	} else if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_TYPE_P(expr) == IS_REFERENCE) {
7175		expr = Z_REFVAL_P(expr);
7176		ZEND_VM_C_GOTO(try_instanceof);
7177	} else {
7178		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(expr) == IS_UNDEF)) {
7179			GET_OP1_UNDEF_CV(expr, BP_VAR_R);
7180		}
7181		result = 0;
7182	}
7183	FREE_OP1();
7184	ZEND_V