1/*
2   +----------------------------------------------------------------------+
3   | Zend Engine                                                          |
4   +----------------------------------------------------------------------+
5   | Copyright (c) 1998-2014 Zend Technologies Ltd. (http://www.zend.com) |
6   +----------------------------------------------------------------------+
7   | This source file is subject to version 2.00 of the Zend license,     |
8   | that is bundled with this package in the file LICENSE, and is        |
9   | available through the world-wide-web at the following url:           |
10   | http://www.zend.com/license/2_00.txt.                                |
11   | If you did not receive a copy of the Zend license and are unable to  |
12   | obtain it through the world-wide-web, please send a note to          |
13   | license@zend.com so we can mail you a copy immediately.              |
14   +----------------------------------------------------------------------+
15   | Authors: Andi Gutmans <andi@zend.com>                                |
16   |          Zeev Suraski <zeev@zend.com>                                |
17   |          Dmitry Stogov <dmitry@zend.com>                             |
18   +----------------------------------------------------------------------+
19*/
20
21/* $Id$ */
22
23/* If you change this file, please regenerate the zend_vm_execute.h and
24 * zend_vm_opcodes.h files by running:
25 * php zend_vm_gen.php
26 */
27
28ZEND_VM_HANDLER(1, ZEND_ADD, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
29{
30    USE_OPLINE
31    zend_free_op free_op1, free_op2;
32
33    SAVE_OPLINE();
34    fast_add_function(EX_VAR(opline->result.var),
35        GET_OP1_ZVAL_PTR(BP_VAR_R),
36        GET_OP2_ZVAL_PTR(BP_VAR_R));
37    FREE_OP1();
38    FREE_OP2();
39    CHECK_EXCEPTION();
40    ZEND_VM_NEXT_OPCODE();
41}
42
43ZEND_VM_HANDLER(2, ZEND_SUB, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
44{
45    USE_OPLINE
46    zend_free_op free_op1, free_op2;
47
48    SAVE_OPLINE();
49    fast_sub_function(EX_VAR(opline->result.var),
50        GET_OP1_ZVAL_PTR(BP_VAR_R),
51        GET_OP2_ZVAL_PTR(BP_VAR_R));
52    FREE_OP1();
53    FREE_OP2();
54    CHECK_EXCEPTION();
55    ZEND_VM_NEXT_OPCODE();
56}
57
58ZEND_VM_HANDLER(3, ZEND_MUL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
59{
60    USE_OPLINE
61    zend_free_op free_op1, free_op2;
62
63    SAVE_OPLINE();
64    fast_mul_function(EX_VAR(opline->result.var),
65        GET_OP1_ZVAL_PTR(BP_VAR_R),
66        GET_OP2_ZVAL_PTR(BP_VAR_R));
67    FREE_OP1();
68    FREE_OP2();
69    CHECK_EXCEPTION();
70    ZEND_VM_NEXT_OPCODE();
71}
72
73ZEND_VM_HANDLER(4, ZEND_DIV, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
74{
75    USE_OPLINE
76    zend_free_op free_op1, free_op2;
77
78    SAVE_OPLINE();
79    fast_div_function(EX_VAR(opline->result.var),
80        GET_OP1_ZVAL_PTR(BP_VAR_R),
81        GET_OP2_ZVAL_PTR(BP_VAR_R));
82    FREE_OP1();
83    FREE_OP2();
84    CHECK_EXCEPTION();
85    ZEND_VM_NEXT_OPCODE();
86}
87
88ZEND_VM_HANDLER(5, ZEND_MOD, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
89{
90    USE_OPLINE
91    zend_free_op free_op1, free_op2;
92
93    SAVE_OPLINE();
94    fast_mod_function(EX_VAR(opline->result.var),
95        GET_OP1_ZVAL_PTR(BP_VAR_R),
96        GET_OP2_ZVAL_PTR(BP_VAR_R));
97    FREE_OP1();
98    FREE_OP2();
99    CHECK_EXCEPTION();
100    ZEND_VM_NEXT_OPCODE();
101}
102
103ZEND_VM_HANDLER(6, ZEND_SL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
104{
105    USE_OPLINE
106    zend_free_op free_op1, free_op2;
107
108    SAVE_OPLINE();
109    shift_left_function(EX_VAR(opline->result.var),
110        GET_OP1_ZVAL_PTR(BP_VAR_R),
111        GET_OP2_ZVAL_PTR(BP_VAR_R));
112    FREE_OP1();
113    FREE_OP2();
114    CHECK_EXCEPTION();
115    ZEND_VM_NEXT_OPCODE();
116}
117
118ZEND_VM_HANDLER(7, ZEND_SR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
119{
120    USE_OPLINE
121    zend_free_op free_op1, free_op2;
122
123    SAVE_OPLINE();
124    shift_right_function(EX_VAR(opline->result.var),
125        GET_OP1_ZVAL_PTR(BP_VAR_R),
126        GET_OP2_ZVAL_PTR(BP_VAR_R));
127    FREE_OP1();
128    FREE_OP2();
129    CHECK_EXCEPTION();
130    ZEND_VM_NEXT_OPCODE();
131}
132
133ZEND_VM_HANDLER(8, ZEND_CONCAT, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
134{
135    USE_OPLINE
136    zend_free_op free_op1, free_op2;
137
138    SAVE_OPLINE();
139    concat_function(EX_VAR(opline->result.var),
140        GET_OP1_ZVAL_PTR(BP_VAR_R),
141        GET_OP2_ZVAL_PTR(BP_VAR_R));
142    FREE_OP1();
143    FREE_OP2();
144    CHECK_EXCEPTION();
145    ZEND_VM_NEXT_OPCODE();
146}
147
148ZEND_VM_HANDLER(15, ZEND_IS_IDENTICAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
149{
150    USE_OPLINE
151    zend_free_op free_op1, free_op2;
152
153    SAVE_OPLINE();
154    fast_is_identical_function(EX_VAR(opline->result.var),
155        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
156        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R));
157    FREE_OP1();
158    FREE_OP2();
159    CHECK_EXCEPTION();
160    ZEND_VM_NEXT_OPCODE();
161}
162
163ZEND_VM_HANDLER(16, ZEND_IS_NOT_IDENTICAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
164{
165    USE_OPLINE
166    zend_free_op free_op1, free_op2;
167    zval *result = EX_VAR(opline->result.var);
168
169    SAVE_OPLINE();
170    fast_is_not_identical_function(result,
171        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
172        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R));
173    FREE_OP1();
174    FREE_OP2();
175    CHECK_EXCEPTION();
176    ZEND_VM_NEXT_OPCODE();
177}
178
179ZEND_VM_HANDLER(17, ZEND_IS_EQUAL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
180{
181    USE_OPLINE
182    zend_free_op free_op1, free_op2;
183    zval *result = EX_VAR(opline->result.var);
184
185    SAVE_OPLINE();
186    fast_equal_function(result,
187        GET_OP1_ZVAL_PTR(BP_VAR_R),
188        GET_OP2_ZVAL_PTR(BP_VAR_R));
189    FREE_OP1();
190    FREE_OP2();
191    CHECK_EXCEPTION();
192    ZEND_VM_NEXT_OPCODE();
193}
194
195ZEND_VM_HANDLER(18, ZEND_IS_NOT_EQUAL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
196{
197    USE_OPLINE
198    zend_free_op free_op1, free_op2;
199    zval *result = EX_VAR(opline->result.var);
200
201    SAVE_OPLINE();
202    fast_not_equal_function(result,
203        GET_OP1_ZVAL_PTR(BP_VAR_R),
204        GET_OP2_ZVAL_PTR(BP_VAR_R));
205    FREE_OP1();
206    FREE_OP2();
207    CHECK_EXCEPTION();
208    ZEND_VM_NEXT_OPCODE();
209}
210
211ZEND_VM_HANDLER(19, ZEND_IS_SMALLER, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
212{
213    USE_OPLINE
214    zend_free_op free_op1, free_op2;
215    zval *result = EX_VAR(opline->result.var);
216
217    SAVE_OPLINE();
218    fast_is_smaller_function(result,
219        GET_OP1_ZVAL_PTR(BP_VAR_R),
220        GET_OP2_ZVAL_PTR(BP_VAR_R));
221    FREE_OP1();
222    FREE_OP2();
223    CHECK_EXCEPTION();
224    ZEND_VM_NEXT_OPCODE();
225}
226
227ZEND_VM_HANDLER(20, ZEND_IS_SMALLER_OR_EQUAL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
228{
229    USE_OPLINE
230    zend_free_op free_op1, free_op2;
231    zval *result = EX_VAR(opline->result.var);
232
233    SAVE_OPLINE();
234    fast_is_smaller_or_equal_function(result,
235        GET_OP1_ZVAL_PTR(BP_VAR_R),
236        GET_OP2_ZVAL_PTR(BP_VAR_R));
237    FREE_OP1();
238    FREE_OP2();
239    CHECK_EXCEPTION();
240    ZEND_VM_NEXT_OPCODE();
241}
242
243ZEND_VM_HANDLER(9, ZEND_BW_OR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
244{
245    USE_OPLINE
246    zend_free_op free_op1, free_op2;
247
248    SAVE_OPLINE();
249    bitwise_or_function(EX_VAR(opline->result.var),
250        GET_OP1_ZVAL_PTR(BP_VAR_R),
251        GET_OP2_ZVAL_PTR(BP_VAR_R));
252    FREE_OP1();
253    FREE_OP2();
254    CHECK_EXCEPTION();
255    ZEND_VM_NEXT_OPCODE();
256}
257
258ZEND_VM_HANDLER(10, ZEND_BW_AND, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
259{
260    USE_OPLINE
261    zend_free_op free_op1, free_op2;
262
263    SAVE_OPLINE();
264    bitwise_and_function(EX_VAR(opline->result.var),
265        GET_OP1_ZVAL_PTR(BP_VAR_R),
266        GET_OP2_ZVAL_PTR(BP_VAR_R));
267    FREE_OP1();
268    FREE_OP2();
269    CHECK_EXCEPTION();
270    ZEND_VM_NEXT_OPCODE();
271}
272
273ZEND_VM_HANDLER(11, ZEND_BW_XOR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
274{
275    USE_OPLINE
276    zend_free_op free_op1, free_op2;
277
278    SAVE_OPLINE();
279    bitwise_xor_function(EX_VAR(opline->result.var),
280        GET_OP1_ZVAL_PTR(BP_VAR_R),
281        GET_OP2_ZVAL_PTR(BP_VAR_R));
282    FREE_OP1();
283    FREE_OP2();
284    CHECK_EXCEPTION();
285    ZEND_VM_NEXT_OPCODE();
286}
287
288ZEND_VM_HANDLER(14, ZEND_BOOL_XOR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
289{
290    USE_OPLINE
291    zend_free_op free_op1, free_op2;
292
293    SAVE_OPLINE();
294    boolean_xor_function(EX_VAR(opline->result.var),
295        GET_OP1_ZVAL_PTR(BP_VAR_R),
296        GET_OP2_ZVAL_PTR(BP_VAR_R));
297    FREE_OP1();
298    FREE_OP2();
299    CHECK_EXCEPTION();
300    ZEND_VM_NEXT_OPCODE();
301}
302
303ZEND_VM_HANDLER(12, ZEND_BW_NOT, CONST|TMPVAR|CV, ANY)
304{
305    USE_OPLINE
306    zend_free_op free_op1;
307
308    SAVE_OPLINE();
309    bitwise_not_function(EX_VAR(opline->result.var),
310        GET_OP1_ZVAL_PTR(BP_VAR_R));
311    FREE_OP1();
312    CHECK_EXCEPTION();
313    ZEND_VM_NEXT_OPCODE();
314}
315
316ZEND_VM_HANDLER(13, ZEND_BOOL_NOT, CONST|TMPVAR|CV, ANY)
317{
318    USE_OPLINE
319    zval *val;
320    zend_free_op free_op1;
321
322    SAVE_OPLINE();
323    val = GET_OP1_ZVAL_PTR(BP_VAR_R);
324    if (Z_TYPE_P(val) == IS_TRUE) {
325        ZVAL_FALSE(EX_VAR(opline->result.var));
326    } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
327        ZVAL_TRUE(EX_VAR(opline->result.var));
328    } else {
329        ZVAL_BOOL(EX_VAR(opline->result.var), !i_zend_is_true(val));
330        FREE_OP1();
331        CHECK_EXCEPTION();
332    }
333    ZEND_VM_NEXT_OPCODE();
334}
335
336ZEND_VM_HELPER_EX(zend_binary_assign_op_obj_helper, VAR|UNUSED|CV, CONST|TMPVAR|CV, int (*binary_op)(zval *result, zval *op1, zval *op2))
337{
338    USE_OPLINE
339    zend_free_op free_op1, free_op2, free_op_data1;
340    zval *object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
341    zval *property = GET_OP2_ZVAL_PTR(BP_VAR_R);
342    zval *value;
343    zval *zptr;
344
345    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
346        zend_error_noreturn(E_ERROR, "Cannot use string offset as an object");
347    }
348
349    do {
350        value = get_zval_ptr((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
351
352        if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
353            if (UNEXPECTED(!make_real_object(&object))) {
354                zend_error(E_WARNING, "Attempt to assign property of non-object");
355                if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
356                    ZVAL_NULL(EX_VAR(opline->result.var));
357                }
358                break;
359            }
360        }
361
362        /* here we are sure we are dealing with an object */
363        if (EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
364            && EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL))) != NULL)) {
365
366            ZVAL_DEREF(zptr);
367            SEPARATE_ZVAL_NOREF(zptr);
368
369            binary_op(zptr, zptr, value);
370            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
371                ZVAL_COPY(EX_VAR(opline->result.var), zptr);
372            }
373        } else {
374            zval *z;
375            zval rv;
376
377            if (Z_OBJ_HT_P(object)->read_property &&
378                (z = Z_OBJ_HT_P(object)->read_property(object, property, BP_VAR_R, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL), &rv)) != NULL) {
379                if (Z_TYPE_P(z) == IS_OBJECT && Z_OBJ_HT_P(z)->get) {
380                    zval rv;
381                    zval *value = Z_OBJ_HT_P(z)->get(z, &rv);
382
383                    if (Z_REFCOUNT_P(z) == 0) {
384                        zend_objects_store_del(Z_OBJ_P(z));
385                    }
386                    ZVAL_COPY_VALUE(z, value);
387                }
388                ZVAL_DEREF(z);
389                SEPARATE_ZVAL_NOREF(z);
390                binary_op(z, z, value);
391                Z_OBJ_HT_P(object)->write_property(object, property, z, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL));
392                if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
393                    ZVAL_COPY(EX_VAR(opline->result.var), z);
394                }
395                zval_ptr_dtor(z);
396            } else {
397                zend_error(E_WARNING, "Attempt to assign property of non-object");
398                if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
399                    ZVAL_NULL(EX_VAR(opline->result.var));
400                }
401            }
402        }
403    } while (0);
404
405    FREE_OP(free_op_data1);
406    FREE_OP2();
407    FREE_OP1_VAR_PTR();
408    /* assign_obj has two opcodes! */
409    CHECK_EXCEPTION();
410    ZEND_VM_INC_OPCODE();
411    ZEND_VM_NEXT_OPCODE();
412}
413
414ZEND_VM_HELPER_EX(zend_binary_assign_op_dim_helper, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV, int (*binary_op)(zval *result, zval *op1, zval *op2))
415{
416    USE_OPLINE
417    zend_free_op free_op1, free_op2, free_op_data1;
418    zval *var_ptr, rv;
419    zval *value, *container, *dim;
420
421    SAVE_OPLINE();
422    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
423    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
424        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
425    }
426
427    dim = GET_OP2_ZVAL_PTR(BP_VAR_R);
428
429    do {
430        if (OP1_TYPE == IS_UNUSED || UNEXPECTED(Z_TYPE_P(container) != IS_ARRAY)) {
431            if (OP1_TYPE != IS_UNUSED) {
432                ZVAL_DEREF(container);
433            }
434#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
435            if (OP1_TYPE == IS_UNUSED || EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
436                value = get_zval_ptr((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
437                zend_binary_assign_op_obj_dim(container, dim, value, UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL, binary_op);
438                break;
439            }
440#endif
441        }
442
443        zend_fetch_dimension_address_RW(&rv, container, dim, OP2_TYPE);
444        value = get_zval_ptr((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
445        ZEND_ASSERT(Z_TYPE(rv) == IS_INDIRECT);
446        var_ptr = Z_INDIRECT(rv);
447
448        if (UNEXPECTED(var_ptr == NULL)) {
449            zend_error_noreturn(E_ERROR, "Cannot use assign-op operators with overloaded objects nor string offsets");
450        }
451
452        if (UNEXPECTED(var_ptr == &EG(error_zval))) {
453            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
454                ZVAL_NULL(EX_VAR(opline->result.var));
455            }
456        } else {
457            ZVAL_DEREF(var_ptr);
458            SEPARATE_ZVAL_NOREF(var_ptr);
459
460            binary_op(var_ptr, var_ptr, value);
461
462            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
463                ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
464            }
465        }
466    } while (0);
467
468    FREE_OP2();
469    FREE_OP(free_op_data1);
470    FREE_OP1_VAR_PTR();
471    CHECK_EXCEPTION();
472    ZEND_VM_INC_OPCODE();
473    ZEND_VM_NEXT_OPCODE();
474}
475
476ZEND_VM_HELPER_EX(zend_binary_assign_op_helper, VAR|CV, CONST|TMPVAR|CV, int (*binary_op)(zval *result, zval *op1, zval *op2))
477{
478    USE_OPLINE
479    zend_free_op free_op1, free_op2;
480    zval *var_ptr;
481    zval *value;
482
483    SAVE_OPLINE();
484    value = GET_OP2_ZVAL_PTR(BP_VAR_R);
485    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
486
487    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
488        zend_error_noreturn(E_ERROR, "Cannot use assign-op operators with overloaded objects nor string offsets");
489    }
490
491    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
492        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
493            ZVAL_NULL(EX_VAR(opline->result.var));
494        }
495    } else {
496        ZVAL_DEREF(var_ptr);
497        SEPARATE_ZVAL_NOREF(var_ptr);
498
499        binary_op(var_ptr, var_ptr, value);
500
501        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
502            ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
503        }
504    }
505
506    FREE_OP2();
507    FREE_OP1_VAR_PTR();
508    CHECK_EXCEPTION();
509    ZEND_VM_NEXT_OPCODE();
510}
511
512ZEND_VM_HANDLER(23, ZEND_ASSIGN_ADD, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
513{
514#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
515    USE_OPLINE
516
517# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
518    if (EXPECTED(opline->extended_value == 0)) {
519        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, add_function);
520    }
521# endif
522    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
523        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, add_function);
524    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
525        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, add_function);
526    }
527#else
528    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, add_function);
529#endif
530}
531
532ZEND_VM_HANDLER(24, ZEND_ASSIGN_SUB, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
533{
534#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
535    USE_OPLINE
536
537# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
538    if (EXPECTED(opline->extended_value == 0)) {
539        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, sub_function);
540    }
541# endif
542    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
543        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, sub_function);
544    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
545        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, sub_function);
546    }
547#else
548    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, sub_function);
549#endif
550}
551
552ZEND_VM_HANDLER(25, ZEND_ASSIGN_MUL, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
553{
554#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
555    USE_OPLINE
556
557# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
558    if (EXPECTED(opline->extended_value == 0)) {
559        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, mul_function);
560    }
561# endif
562    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
563        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, mul_function);
564    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
565        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, mul_function);
566    }
567#else
568    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, mul_function);
569#endif
570}
571
572ZEND_VM_HANDLER(26, ZEND_ASSIGN_DIV, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
573{
574#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
575    USE_OPLINE
576
577# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
578    if (EXPECTED(opline->extended_value == 0)) {
579        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, div_function);
580    }
581# endif
582    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
583        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, div_function);
584    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
585        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, div_function);
586    }
587#else
588    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, div_function);
589#endif
590}
591
592ZEND_VM_HANDLER(27, ZEND_ASSIGN_MOD, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
593{
594#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
595    USE_OPLINE
596
597# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
598    if (EXPECTED(opline->extended_value == 0)) {
599        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, mod_function);
600    }
601# endif
602    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
603        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, mod_function);
604    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
605        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, mod_function);
606    }
607#else
608    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, mod_function);
609#endif
610}
611
612ZEND_VM_HANDLER(28, ZEND_ASSIGN_SL, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
613{
614#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
615    USE_OPLINE
616
617# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
618    if (EXPECTED(opline->extended_value == 0)) {
619        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, shift_left_function);
620    }
621# endif
622    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
623        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, shift_left_function);
624    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
625        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, shift_left_function);
626    }
627#else
628    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, shift_left_function);
629#endif
630}
631
632ZEND_VM_HANDLER(29, ZEND_ASSIGN_SR, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
633{
634#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
635    USE_OPLINE
636
637# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
638    if (EXPECTED(opline->extended_value == 0)) {
639        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, shift_right_function);
640    }
641# endif
642    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
643        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, shift_right_function);
644    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
645        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, shift_right_function);
646    }
647#else
648    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, shift_right_function);
649#endif
650}
651
652ZEND_VM_HANDLER(30, ZEND_ASSIGN_CONCAT, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
653{
654#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
655    USE_OPLINE
656
657# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
658    if (EXPECTED(opline->extended_value == 0)) {
659        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, concat_function);
660    }
661# endif
662    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
663        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, concat_function);
664    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
665        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, concat_function);
666    }
667#else
668    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, concat_function);
669#endif
670}
671
672ZEND_VM_HANDLER(31, ZEND_ASSIGN_BW_OR, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
673{
674#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
675    USE_OPLINE
676
677# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
678    if (EXPECTED(opline->extended_value == 0)) {
679        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, bitwise_or_function);
680    }
681# endif
682    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
683        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_or_function);
684    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
685        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, bitwise_or_function);
686    }
687#else
688    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_or_function);
689#endif
690}
691
692ZEND_VM_HANDLER(32, ZEND_ASSIGN_BW_AND, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
693{
694#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
695    USE_OPLINE
696
697# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
698    if (EXPECTED(opline->extended_value == 0)) {
699        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, bitwise_and_function);
700    }
701# endif
702    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
703        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_and_function);
704    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
705        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, bitwise_and_function);
706    }
707#else
708    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_and_function);
709#endif
710}
711
712ZEND_VM_HANDLER(33, ZEND_ASSIGN_BW_XOR, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
713{
714#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
715    USE_OPLINE
716
717# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
718    if (EXPECTED(opline->extended_value == 0)) {
719        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, bitwise_xor_function);
720    }
721# endif
722    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
723        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_xor_function);
724    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
725        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, bitwise_xor_function);
726    }
727#else
728    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_xor_function);
729#endif
730}
731
732ZEND_VM_HELPER_EX(zend_pre_incdec_property_helper, VAR|UNUSED|CV, CONST|TMPVAR|CV, incdec_t incdec_op)
733{
734    USE_OPLINE
735    zend_free_op free_op1, free_op2;
736    zval *object;
737    zval *property;
738    zval *retval;
739    zval *zptr;
740
741    SAVE_OPLINE();
742    object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
743    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
744    retval = EX_VAR(opline->result.var);
745
746    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
747        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
748    }
749
750    do {
751        if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
752            if (UNEXPECTED(!make_real_object(&object))) {
753                zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
754                if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
755                    ZVAL_NULL(retval);
756                }
757                break;
758            }
759        }
760
761        /* here we are sure we are dealing with an object */
762
763        if (EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
764            && EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL))) != NULL)) {
765
766            ZVAL_DEREF(zptr);
767            SEPARATE_ZVAL_NOREF(zptr);
768
769            incdec_op(zptr);
770            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
771                ZVAL_COPY(retval, zptr);
772            }
773        } else {
774            zval rv;
775
776            if (Z_OBJ_HT_P(object)->read_property && Z_OBJ_HT_P(object)->write_property) {
777                zval *z = Z_OBJ_HT_P(object)->read_property(object, property, BP_VAR_R, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL), &rv);
778
779                if (UNEXPECTED(Z_TYPE_P(z) == IS_OBJECT) && Z_OBJ_HT_P(z)->get) {
780                    zval rv;
781                    zval *value = Z_OBJ_HT_P(z)->get(z, &rv);
782
783                    if (Z_REFCOUNT_P(z) == 0) {
784                        zend_objects_store_del(Z_OBJ_P(z));
785                    }
786                    ZVAL_COPY_VALUE(z, value);
787                }
788                ZVAL_DEREF(z);
789                SEPARATE_ZVAL_NOREF(z);
790                incdec_op(z);
791                if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
792                    ZVAL_COPY(retval, z);
793                }
794                Z_OBJ_HT_P(object)->write_property(object, property, z, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL));
795                zval_ptr_dtor(z);
796            } else {
797                zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
798                if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
799                    ZVAL_NULL(retval);
800                }
801            }
802        }
803    } while (0);
804
805    FREE_OP2();
806    FREE_OP1_VAR_PTR();
807    CHECK_EXCEPTION();
808    ZEND_VM_NEXT_OPCODE();
809}
810
811ZEND_VM_HANDLER(132, ZEND_PRE_INC_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
812{
813    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_pre_incdec_property_helper, incdec_op, increment_function);
814}
815
816ZEND_VM_HANDLER(133, ZEND_PRE_DEC_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
817{
818    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_pre_incdec_property_helper, incdec_op, decrement_function);
819}
820
821ZEND_VM_HELPER_EX(zend_post_incdec_property_helper, VAR|UNUSED|CV, CONST|TMPVAR|CV, incdec_t incdec_op)
822{
823    USE_OPLINE
824    zend_free_op free_op1, free_op2;
825    zval *object;
826    zval *property;
827    zval *retval;
828    zval *zptr;
829
830    SAVE_OPLINE();
831    object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
832    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
833    retval = EX_VAR(opline->result.var);
834
835    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
836        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
837    }
838
839    do {
840        if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
841            if (UNEXPECTED(!make_real_object(&object))) {
842                zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
843                ZVAL_NULL(retval);
844                break;
845            }
846        }
847
848        /* here we are sure we are dealing with an object */
849
850        if (EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
851            && EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL))) != NULL)) {
852
853            ZVAL_DEREF(zptr);
854            ZVAL_COPY_VALUE(retval, zptr);
855            zval_opt_copy_ctor(zptr);
856
857            incdec_op(zptr);
858        } else {
859            if (Z_OBJ_HT_P(object)->read_property && Z_OBJ_HT_P(object)->write_property) {
860                zval rv;
861                zval *z = Z_OBJ_HT_P(object)->read_property(object, property, BP_VAR_R, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL), &rv);
862                zval z_copy;
863
864                if (UNEXPECTED(Z_TYPE_P(z) == IS_OBJECT) && Z_OBJ_HT_P(z)->get) {
865                    zval rv;
866                    zval *value = Z_OBJ_HT_P(z)->get(z, &rv);
867
868                    if (Z_REFCOUNT_P(z) == 0) {
869                        zend_objects_store_del(Z_OBJ_P(z));
870                    }
871                    ZVAL_COPY_VALUE(z, value);
872                }
873                ZVAL_DUP(retval, z);
874                ZVAL_DUP(&z_copy, z);
875                incdec_op(&z_copy);
876                if (Z_REFCOUNTED_P(z)) Z_ADDREF_P(z);
877                Z_OBJ_HT_P(object)->write_property(object, property, &z_copy, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL));
878                zval_ptr_dtor(&z_copy);
879                zval_ptr_dtor(z);
880            } else {
881                zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
882                ZVAL_NULL(retval);
883            }
884        }
885    } while (0);
886
887    FREE_OP2();
888    FREE_OP1_VAR_PTR();
889    CHECK_EXCEPTION();
890    ZEND_VM_NEXT_OPCODE();
891}
892
893ZEND_VM_HANDLER(134, ZEND_POST_INC_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
894{
895    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_post_incdec_property_helper, incdec_op, increment_function);
896}
897
898ZEND_VM_HANDLER(135, ZEND_POST_DEC_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
899{
900    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_post_incdec_property_helper, incdec_op, decrement_function);
901}
902
903ZEND_VM_HANDLER(34, ZEND_PRE_INC, VAR|CV, ANY)
904{
905    USE_OPLINE
906    zend_free_op free_op1;
907    zval *var_ptr;
908
909    SAVE_OPLINE();
910    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
911
912    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
913        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
914    }
915
916    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
917        fast_increment_function(var_ptr);
918        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
919            ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
920        }
921        ZEND_VM_NEXT_OPCODE();
922    }
923
924    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
925        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
926            ZVAL_NULL(EX_VAR(opline->result.var));
927        }
928        CHECK_EXCEPTION();
929        ZEND_VM_NEXT_OPCODE();
930    }
931
932    ZVAL_DEREF(var_ptr);
933    SEPARATE_ZVAL_NOREF(var_ptr);
934
935    increment_function(var_ptr);
936
937    if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
938        ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
939    }
940
941    FREE_OP1_VAR_PTR();
942    CHECK_EXCEPTION();
943    ZEND_VM_NEXT_OPCODE();
944}
945
946ZEND_VM_HANDLER(35, ZEND_PRE_DEC, VAR|CV, ANY)
947{
948    USE_OPLINE
949    zend_free_op free_op1;
950    zval *var_ptr;
951
952    SAVE_OPLINE();
953    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
954
955    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
956        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
957    }
958
959    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
960        fast_decrement_function(var_ptr);
961        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
962            ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
963        }
964        ZEND_VM_NEXT_OPCODE();
965    }
966
967    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
968        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
969            ZVAL_NULL(EX_VAR(opline->result.var));
970        }
971        CHECK_EXCEPTION();
972        ZEND_VM_NEXT_OPCODE();
973    }
974
975    ZVAL_DEREF(var_ptr);
976    SEPARATE_ZVAL_NOREF(var_ptr);
977
978    decrement_function(var_ptr);
979
980    if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
981        ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
982    }
983
984    FREE_OP1_VAR_PTR();
985    CHECK_EXCEPTION();
986    ZEND_VM_NEXT_OPCODE();
987}
988
989ZEND_VM_HANDLER(36, ZEND_POST_INC, VAR|CV, ANY)
990{
991    USE_OPLINE
992    zend_free_op free_op1;
993    zval *var_ptr;
994
995    SAVE_OPLINE();
996    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
997
998    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
999        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
1000    }
1001
1002    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1003        ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1004        fast_increment_function(var_ptr);
1005        ZEND_VM_NEXT_OPCODE();
1006    }
1007
1008    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
1009        ZVAL_NULL(EX_VAR(opline->result.var));
1010        CHECK_EXCEPTION();
1011        ZEND_VM_NEXT_OPCODE();
1012    }
1013
1014    ZVAL_DEREF(var_ptr);
1015    ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1016    zval_opt_copy_ctor(var_ptr);
1017
1018    increment_function(var_ptr);
1019
1020    FREE_OP1_VAR_PTR();
1021    CHECK_EXCEPTION();
1022    ZEND_VM_NEXT_OPCODE();
1023}
1024
1025ZEND_VM_HANDLER(37, ZEND_POST_DEC, VAR|CV, ANY)
1026{
1027    USE_OPLINE
1028    zend_free_op free_op1;
1029    zval *var_ptr;
1030
1031    SAVE_OPLINE();
1032    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
1033
1034    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
1035        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
1036    }
1037
1038    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1039        ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1040        fast_decrement_function(var_ptr);
1041        ZEND_VM_NEXT_OPCODE();
1042    }
1043
1044    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
1045        ZVAL_NULL(EX_VAR(opline->result.var));
1046        CHECK_EXCEPTION();
1047        ZEND_VM_NEXT_OPCODE();
1048    }
1049
1050    ZVAL_DEREF(var_ptr);
1051    ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1052    zval_opt_copy_ctor(var_ptr);
1053
1054    decrement_function(var_ptr);
1055
1056    FREE_OP1_VAR_PTR();
1057    CHECK_EXCEPTION();
1058    ZEND_VM_NEXT_OPCODE();
1059}
1060
1061ZEND_VM_HANDLER(40, ZEND_ECHO, CONST|TMPVAR|CV, ANY)
1062{
1063    USE_OPLINE
1064    zend_free_op free_op1;
1065    zval *z;
1066
1067    SAVE_OPLINE();
1068    z = GET_OP1_ZVAL_PTR(BP_VAR_R);
1069
1070    if (Z_TYPE_P(z) == IS_STRING) {
1071        zend_string *str = Z_STR_P(z);
1072
1073        if (str->len != 0) {
1074            zend_write(str->val, str->len);
1075        }
1076    } else {
1077        zend_string *str = _zval_get_string_func(z);
1078
1079        if (str->len != 0) {
1080            zend_write(str->val, str->len);
1081        }
1082        zend_string_release(str);
1083    }
1084
1085    FREE_OP1();
1086    CHECK_EXCEPTION();
1087    ZEND_VM_NEXT_OPCODE();
1088}
1089
1090ZEND_VM_HELPER_EX(zend_fetch_var_address_helper, CONST|TMPVAR|CV, UNUSED|CONST|VAR, int type)
1091{
1092    USE_OPLINE
1093    zend_free_op free_op1;
1094    zval *varname;
1095    zval *retval;
1096    zend_string *name;
1097    HashTable *target_symbol_table;
1098
1099    SAVE_OPLINE();
1100    varname = GET_OP1_ZVAL_PTR(BP_VAR_R);
1101
1102    if (OP1_TYPE == IS_CONST) {
1103        name = Z_STR_P(varname);
1104    } else if (EXPECTED(Z_TYPE_P(varname) == IS_STRING)) {
1105        name = Z_STR_P(varname);
1106        zend_string_addref(name);
1107    } else {
1108        name = zval_get_string(varname);
1109    }
1110
1111    if (OP2_TYPE != IS_UNUSED) {
1112        zend_class_entry *ce;
1113
1114        if (OP2_TYPE == IS_CONST) {
1115            if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) {
1116                ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
1117            } else {
1118                ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op2)), EX_CONSTANT(opline->op2) + 1, 0);
1119                if (UNEXPECTED(ce == NULL)) {
1120                    if (OP1_TYPE != IS_CONST) {
1121                        zend_string_release(name);
1122                    }
1123                    FREE_OP1();
1124                    CHECK_EXCEPTION();
1125                    ZEND_VM_NEXT_OPCODE();
1126                }
1127                CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce);
1128            }
1129        } else {
1130            ce = Z_CE_P(EX_VAR(opline->op2.var));
1131        }
1132        retval = zend_std_get_static_property(ce, name, 0, ((OP1_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(varname)) : NULL));
1133        FREE_OP1();
1134    } else {
1135        target_symbol_table = zend_get_target_symbol_table(execute_data, opline->extended_value & ZEND_FETCH_TYPE_MASK);
1136        retval = zend_hash_find(target_symbol_table, name);
1137        if (retval == NULL) {
1138            switch (type) {
1139                case BP_VAR_R:
1140                case BP_VAR_UNSET:
1141                    zend_error(E_NOTICE,"Undefined variable: %s", name->val);
1142                    /* break missing intentionally */
1143                case BP_VAR_IS:
1144                    retval = &EG(uninitialized_zval);
1145                    break;
1146                case BP_VAR_RW:
1147                    zend_error(E_NOTICE,"Undefined variable: %s", name->val);
1148                    /* break missing intentionally */
1149                case BP_VAR_W:
1150                    retval = zend_hash_add_new(target_symbol_table, name, &EG(uninitialized_zval));
1151                    break;
1152                EMPTY_SWITCH_DEFAULT_CASE()
1153            }
1154        /* GLOBAL or $$name variable may be an INDIRECT pointer to CV */
1155        } else if (Z_TYPE_P(retval) == IS_INDIRECT) {
1156            retval = Z_INDIRECT_P(retval);
1157            if (Z_TYPE_P(retval) == IS_UNDEF) {
1158                switch (type) {
1159                    case BP_VAR_R:
1160                    case BP_VAR_UNSET:
1161                        zend_error(E_NOTICE,"Undefined variable: %s", name->val);
1162                        /* break missing intentionally */
1163                    case BP_VAR_IS:
1164                        retval = &EG(uninitialized_zval);
1165                        break;
1166                    case BP_VAR_RW:
1167                        zend_error(E_NOTICE,"Undefined variable: %s", name->val);
1168                        /* break missing intentionally */
1169                    case BP_VAR_W:
1170                        ZVAL_NULL(retval);
1171                        break;
1172                    EMPTY_SWITCH_DEFAULT_CASE()
1173                }
1174            }
1175        }
1176        if ((opline->extended_value & ZEND_FETCH_TYPE_MASK) == ZEND_FETCH_STATIC) {
1177            if (Z_CONSTANT_P(retval)) {
1178                zval_update_constant(retval, 1);
1179            }
1180        } else if ((opline->extended_value & ZEND_FETCH_TYPE_MASK) != ZEND_FETCH_GLOBAL_LOCK) {
1181            FREE_OP1();
1182        }
1183    }
1184
1185    if (OP1_TYPE != IS_CONST) {
1186        zend_string_release(name);
1187    }
1188
1189    ZEND_ASSERT(retval != NULL);
1190    if (type == BP_VAR_R || type == BP_VAR_IS) {
1191        if (/*type == BP_VAR_R &&*/ Z_ISREF_P(retval) && Z_REFCOUNT_P(retval) == 1) {
1192            ZVAL_UNREF(retval);
1193        }
1194        ZVAL_COPY(EX_VAR(opline->result.var), retval);
1195    } else {
1196        ZVAL_INDIRECT(EX_VAR(opline->result.var), retval);
1197    }
1198    CHECK_EXCEPTION();
1199    ZEND_VM_NEXT_OPCODE();
1200}
1201
1202ZEND_VM_HANDLER(80, ZEND_FETCH_R, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1203{
1204    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_R);
1205}
1206
1207ZEND_VM_HANDLER(83, ZEND_FETCH_W, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1208{
1209    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_W);
1210}
1211
1212ZEND_VM_HANDLER(86, ZEND_FETCH_RW, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1213{
1214    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_RW);
1215}
1216
1217ZEND_VM_HANDLER(92, ZEND_FETCH_FUNC_ARG, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1218{
1219    USE_OPLINE
1220
1221    if (zend_is_by_ref_func_arg_fetch(opline, EX(call))) {
1222        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_W);
1223    } else {
1224        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_R);
1225    }
1226}
1227
1228ZEND_VM_HANDLER(95, ZEND_FETCH_UNSET, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1229{
1230    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_UNSET);
1231}
1232
1233ZEND_VM_HANDLER(89, ZEND_FETCH_IS, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1234{
1235    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_IS);
1236}
1237
1238ZEND_VM_HANDLER(81, ZEND_FETCH_DIM_R, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
1239{
1240    USE_OPLINE
1241    zend_free_op free_op1, free_op2;
1242    zval *container;
1243
1244    SAVE_OPLINE();
1245    container = GET_OP1_ZVAL_PTR(BP_VAR_R);
1246    zend_fetch_dimension_address_read_R(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1247    FREE_OP2();
1248    FREE_OP1();
1249    CHECK_EXCEPTION();
1250    ZEND_VM_NEXT_OPCODE();
1251}
1252
1253ZEND_VM_HANDLER(84, ZEND_FETCH_DIM_W, VAR|CV, CONST|TMPVAR|UNUSED|CV)
1254{
1255    USE_OPLINE
1256    zend_free_op free_op1, free_op2;
1257    zval *container;
1258
1259    SAVE_OPLINE();
1260    container = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1261
1262    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1263        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1264    }
1265    zend_fetch_dimension_address_W(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1266    FREE_OP2();
1267    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1268        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1269    }
1270    FREE_OP1_VAR_PTR();
1271    CHECK_EXCEPTION();
1272    ZEND_VM_NEXT_OPCODE();
1273}
1274
1275ZEND_VM_HANDLER(87, ZEND_FETCH_DIM_RW, VAR|CV, CONST|TMPVAR|UNUSED|CV)
1276{
1277    USE_OPLINE
1278    zend_free_op free_op1, free_op2;
1279    zval *container;
1280
1281    SAVE_OPLINE();
1282    container = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
1283
1284    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1285        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1286    }
1287    zend_fetch_dimension_address_RW(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1288    FREE_OP2();
1289    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1290        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1291    }
1292    FREE_OP1_VAR_PTR();
1293    CHECK_EXCEPTION();
1294    ZEND_VM_NEXT_OPCODE();
1295}
1296
1297ZEND_VM_HANDLER(90, ZEND_FETCH_DIM_IS, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
1298{
1299    USE_OPLINE
1300    zend_free_op free_op1, free_op2;
1301    zval *container;
1302
1303    SAVE_OPLINE();
1304    container = GET_OP1_ZVAL_PTR(BP_VAR_IS);
1305    zend_fetch_dimension_address_read_IS(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1306    FREE_OP2();
1307    FREE_OP1();
1308    CHECK_EXCEPTION();
1309    ZEND_VM_NEXT_OPCODE();
1310}
1311
1312ZEND_VM_HANDLER(93, ZEND_FETCH_DIM_FUNC_ARG, CONST|TMP|VAR|CV, CONST|TMPVAR|UNUSED|CV)
1313{
1314    USE_OPLINE
1315    zval *container;
1316    zend_free_op free_op1, free_op2;
1317
1318    SAVE_OPLINE();
1319
1320    if (zend_is_by_ref_func_arg_fetch(opline, EX(call))) {
1321        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
1322            zend_error_noreturn(E_ERROR, "Cannot use temporary expression in write context");
1323        }
1324        container = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1325        if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1326            zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1327        }
1328        zend_fetch_dimension_address_W(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1329        if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1330            EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1331        }
1332        FREE_OP2();
1333        FREE_OP1_VAR_PTR();
1334    } else {
1335        if (OP2_TYPE == IS_UNUSED) {
1336            zend_error_noreturn(E_ERROR, "Cannot use [] for reading");
1337        }
1338        container = GET_OP1_ZVAL_PTR(BP_VAR_R);
1339        zend_fetch_dimension_address_read_R(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1340        FREE_OP2();
1341        FREE_OP1();
1342    }
1343    CHECK_EXCEPTION();
1344    ZEND_VM_NEXT_OPCODE();
1345}
1346
1347ZEND_VM_HANDLER(96, ZEND_FETCH_DIM_UNSET, VAR|CV, CONST|TMPVAR|CV)
1348{
1349    USE_OPLINE
1350    zend_free_op free_op1, free_op2;
1351    zval *container;
1352
1353    SAVE_OPLINE();
1354    container = GET_OP1_ZVAL_PTR_PTR(BP_VAR_UNSET);
1355
1356    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1357        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1358    }
1359    zend_fetch_dimension_address_UNSET(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1360    FREE_OP2();
1361    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1362        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1363    }
1364    FREE_OP1_VAR_PTR();
1365    CHECK_EXCEPTION();
1366    ZEND_VM_NEXT_OPCODE();
1367}
1368
1369ZEND_VM_HANDLER(82, ZEND_FETCH_OBJ_R, CONST|TMP|VAR|UNUSED|CV, CONST|TMPVAR|CV)
1370{
1371    USE_OPLINE
1372    zend_free_op free_op1;
1373    zval *container;
1374    zend_free_op free_op2;
1375    zval *offset;
1376
1377    SAVE_OPLINE();
1378    container = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_R);
1379    offset  = GET_OP2_ZVAL_PTR(BP_VAR_R);
1380
1381    if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
1382        if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(container)) {
1383            container = Z_REFVAL_P(container);
1384            if (UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
1385                ZEND_VM_C_GOTO(fetch_obj_r_no_object);
1386            }
1387        } else {
1388            ZEND_VM_C_GOTO(fetch_obj_r_no_object);
1389        }
1390    }
1391    if (UNEXPECTED(Z_OBJ_HT_P(container)->read_property == NULL)) {
1392ZEND_VM_C_LABEL(fetch_obj_r_no_object):
1393        zend_error(E_NOTICE, "Trying to get property of non-object");
1394        ZVAL_NULL(EX_VAR(opline->result.var));
1395    } else {
1396        zval *retval;
1397
1398        /* here we are sure we are dealing with an object */
1399        do {
1400            if (OP2_TYPE == IS_CONST &&
1401                EXPECTED(Z_OBJCE_P(container) == CACHED_PTR(Z_CACHE_SLOT_P(offset)))) {
1402                zend_property_info *prop_info = CACHED_PTR(Z_CACHE_SLOT_P(offset) + 1);
1403                zend_object *zobj = Z_OBJ_P(container);
1404
1405                if (EXPECTED(prop_info)) {
1406                    retval = OBJ_PROP(zobj, prop_info->offset);
1407                    if (EXPECTED(Z_TYPE_P(retval) != IS_UNDEF)) {
1408                        ZVAL_COPY(EX_VAR(opline->result.var), retval);
1409                        break;
1410                    }
1411                } else if (EXPECTED(zobj->properties != NULL)) {
1412                    retval = zend_hash_find(zobj->properties, Z_STR_P(offset));
1413                    if (EXPECTED(retval)) {
1414                        ZVAL_COPY(EX_VAR(opline->result.var), retval);
1415                        break;
1416                    }
1417                }
1418            }
1419
1420            retval = Z_OBJ_HT_P(container)->read_property(container, offset, BP_VAR_R, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(offset)) : NULL), EX_VAR(opline->result.var));
1421
1422            if (retval != EX_VAR(opline->result.var)) {
1423                ZVAL_COPY(EX_VAR(opline->result.var), retval);
1424            }
1425        } while (0);
1426    }
1427
1428    FREE_OP2();
1429    FREE_OP1();
1430    CHECK_EXCEPTION();
1431    ZEND_VM_NEXT_OPCODE();
1432}
1433
1434ZEND_VM_HANDLER(85, ZEND_FETCH_OBJ_W, VAR|UNUSED|CV, CONST|TMPVAR|CV)
1435{
1436    USE_OPLINE
1437    zend_free_op free_op1, free_op2;
1438    zval *property;
1439    zval *container;
1440
1441    SAVE_OPLINE();
1442    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1443
1444    container = GET_OP1_OBJ_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1445    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1446        zend_error_noreturn(E_ERROR, "Cannot use string offset as an object");
1447    }
1448
1449    zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_W);
1450    FREE_OP2();
1451    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1452        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1453    }
1454    FREE_OP1_VAR_PTR();
1455    CHECK_EXCEPTION();
1456    ZEND_VM_NEXT_OPCODE();
1457}
1458
1459ZEND_VM_HANDLER(88, ZEND_FETCH_OBJ_RW, VAR|UNUSED|CV, CONST|TMPVAR|CV)
1460{
1461    USE_OPLINE
1462    zend_free_op free_op1, free_op2;
1463    zval *property;
1464    zval *container;
1465
1466    SAVE_OPLINE();
1467    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1468    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
1469
1470    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1471        zend_error_noreturn(E_ERROR, "Cannot use string offset as an object");
1472    }
1473    zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_RW);
1474    FREE_OP2();
1475    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1476        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1477    }
1478    FREE_OP1_VAR_PTR();
1479    CHECK_EXCEPTION();
1480    ZEND_VM_NEXT_OPCODE();
1481}
1482
1483ZEND_VM_HANDLER(91, ZEND_FETCH_OBJ_IS, CONST|TMPVAR|UNUSED|CV, CONST|TMPVAR|CV)
1484{
1485    USE_OPLINE
1486    zend_free_op free_op1;
1487    zval *container;
1488    zend_free_op free_op2;
1489    zval *offset;
1490
1491    SAVE_OPLINE();
1492    container = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_IS);
1493    offset  = GET_OP2_ZVAL_PTR(BP_VAR_R);
1494
1495    if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
1496        if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(container)) {
1497            container = Z_REFVAL_P(container);
1498            if (UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
1499                ZEND_VM_C_GOTO(fetch_obj_is_no_object);
1500            }
1501        } else {
1502            ZEND_VM_C_GOTO(fetch_obj_is_no_object);
1503        }
1504    }
1505    if (UNEXPECTED(Z_OBJ_HT_P(container)->read_property == NULL)) {
1506ZEND_VM_C_LABEL(fetch_obj_is_no_object):
1507        ZVAL_NULL(EX_VAR(opline->result.var));
1508    } else {
1509        zval *retval;
1510
1511        /* here we are sure we are dealing with an object */
1512        do {
1513            if (OP2_TYPE == IS_CONST &&
1514                EXPECTED(Z_OBJCE_P(container) == CACHED_PTR(Z_CACHE_SLOT_P(offset)))) {
1515                zend_property_info *prop_info = CACHED_PTR(Z_CACHE_SLOT_P(offset) + 1);
1516                zend_object *zobj = Z_OBJ_P(container);
1517
1518                if (EXPECTED(prop_info)) {
1519                    retval = OBJ_PROP(zobj, prop_info->offset);
1520                    if (EXPECTED(Z_TYPE_P(retval) != IS_UNDEF)) {
1521                        ZVAL_COPY(EX_VAR(opline->result.var), retval);
1522                        break;
1523                    }
1524                } else if (EXPECTED(zobj->properties != NULL)) {
1525                    retval = zend_hash_find(zobj->properties, Z_STR_P(offset));
1526                    if (EXPECTED(retval)) {
1527                        ZVAL_COPY(EX_VAR(opline->result.var), retval);
1528                        break;
1529                    }
1530                }
1531            }
1532
1533            retval = Z_OBJ_HT_P(container)->read_property(container, offset, BP_VAR_IS, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(offset)) : NULL), EX_VAR(opline->result.var));
1534
1535            if (retval != EX_VAR(opline->result.var)) {
1536                ZVAL_COPY(EX_VAR(opline->result.var), retval);
1537            }
1538        } while (0);
1539    }
1540
1541    FREE_OP2();
1542    FREE_OP1();
1543    CHECK_EXCEPTION();
1544    ZEND_VM_NEXT_OPCODE();
1545}
1546
1547ZEND_VM_HANDLER(94, ZEND_FETCH_OBJ_FUNC_ARG, CONST|TMP|VAR|UNUSED|CV, CONST|TMPVAR|CV)
1548{
1549    USE_OPLINE
1550    zval *container;
1551
1552    if (zend_is_by_ref_func_arg_fetch(opline, EX(call))) {
1553        /* Behave like FETCH_OBJ_W */
1554        zend_free_op free_op1, free_op2;
1555        zval *property;
1556
1557        SAVE_OPLINE();
1558        property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1559        container = GET_OP1_OBJ_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1560
1561        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
1562            zend_error_noreturn(E_ERROR, "Cannot use temporary expression in write context");
1563        }
1564        if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1565            zend_error_noreturn(E_ERROR, "Cannot use string offset as an object");
1566        }
1567        zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_W);
1568        FREE_OP2();
1569        if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1570            EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1571        }
1572        FREE_OP1_VAR_PTR();
1573        CHECK_EXCEPTION();
1574        ZEND_VM_NEXT_OPCODE();
1575    } else {
1576        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_FETCH_OBJ_R);
1577    }
1578}
1579
1580ZEND_VM_HANDLER(97, ZEND_FETCH_OBJ_UNSET, VAR|UNUSED|CV, CONST|TMPVAR|CV)
1581{
1582    USE_OPLINE
1583    zend_free_op free_op1, free_op2;
1584    zval *container, *property;
1585
1586    SAVE_OPLINE();
1587    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_UNSET);
1588    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1589
1590    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1591        zend_error_noreturn(E_ERROR, "Cannot use string offset as an object");
1592    }
1593    zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_UNSET);
1594    FREE_OP2();
1595    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1596        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1597    }
1598    FREE_OP1_VAR_PTR();
1599    CHECK_EXCEPTION();
1600    ZEND_VM_NEXT_OPCODE();
1601}
1602
1603ZEND_VM_HANDLER(98, ZEND_FETCH_LIST, CONST|TMPVAR|CV, CONST)
1604{
1605    USE_OPLINE
1606    zend_free_op free_op1;
1607    zval *container;
1608
1609    SAVE_OPLINE();
1610    container = GET_OP1_ZVAL_PTR(BP_VAR_R);
1611
1612ZEND_VM_C_LABEL(try_fetch_list):
1613    if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
1614        zend_free_op free_op2;
1615        zval *value = zend_fetch_dimension_address_inner(Z_ARRVAL_P(container), GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE, BP_VAR_R);
1616
1617        ZVAL_COPY(EX_VAR(opline->result.var), value);
1618    } else if (UNEXPECTED(Z_TYPE_P(container) == IS_OBJECT) &&
1619               EXPECTED(Z_OBJ_HT_P(container)->read_dimension)) {
1620        zval *result = EX_VAR(opline->result.var);
1621        zval *retval = Z_OBJ_HT_P(container)->read_dimension(container, GET_OP2_ZVAL_PTR(BP_VAR_R), BP_VAR_R, result);
1622
1623        if (retval) {
1624            if (result != retval) {
1625                ZVAL_COPY(result, retval);
1626            }
1627        } else {
1628            ZVAL_NULL(result);
1629        }
1630    } else if (Z_TYPE_P(container) == IS_REFERENCE) {
1631        container = Z_REFVAL_P(container);
1632        ZEND_VM_C_GOTO(try_fetch_list);
1633    } else {
1634        ZVAL_NULL(EX_VAR(opline->result.var));
1635    }
1636    CHECK_EXCEPTION();
1637    ZEND_VM_NEXT_OPCODE();
1638}
1639
1640ZEND_VM_HANDLER(136, ZEND_ASSIGN_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
1641{
1642    USE_OPLINE
1643    zend_free_op free_op1, free_op2;
1644    zval *object;
1645    zval *property_name;
1646
1647    SAVE_OPLINE();
1648    object = GET_OP1_OBJ_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1649    property_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
1650
1651    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
1652        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1653    }
1654    zend_assign_to_object(UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL, object, OP1_TYPE, property_name, OP2_TYPE, (opline+1)->op1_type, (opline+1)->op1, execute_data, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property_name)) : NULL));
1655    FREE_OP2();
1656    FREE_OP1_VAR_PTR();
1657    /* assign_obj has two opcodes! */
1658    CHECK_EXCEPTION();
1659    ZEND_VM_INC_OPCODE();
1660    ZEND_VM_NEXT_OPCODE();
1661}
1662
1663ZEND_VM_HANDLER(147, ZEND_ASSIGN_DIM, VAR|CV, CONST|TMPVAR|UNUSED|CV)
1664{
1665    USE_OPLINE
1666    zend_free_op free_op1;
1667    zval *object_ptr;
1668    zend_free_op free_op2, free_op_data1;
1669    zval  rv;
1670    zval *value;
1671    zval *variable_ptr;
1672    zval *dim;
1673
1674    SAVE_OPLINE();
1675    object_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1676
1677    if (OP1_TYPE == IS_VAR && UNEXPECTED(object_ptr == NULL)) {
1678        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1679    }
1680
1681ZEND_VM_C_LABEL(try_assign_dim):
1682    if (EXPECTED(Z_TYPE_P(object_ptr) == IS_ARRAY)) {
1683ZEND_VM_C_LABEL(try_assign_dim_array):
1684        dim = GET_OP2_ZVAL_PTR(BP_VAR_R);
1685        zend_fetch_dimension_address_W(&rv, object_ptr, dim, OP2_TYPE);
1686        FREE_OP2();
1687        value = get_zval_ptr_deref((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
1688        ZEND_ASSERT(Z_TYPE(rv) == IS_INDIRECT);
1689        variable_ptr = Z_INDIRECT(rv);
1690        if (UNEXPECTED(variable_ptr == &EG(error_zval))) {
1691            FREE_OP(free_op_data1);
1692            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1693                ZVAL_NULL(EX_VAR(opline->result.var));
1694            }
1695        } else {
1696            value = zend_assign_to_variable(variable_ptr, value, (opline+1)->op1_type);
1697            if ((opline+1)->op1_type == IS_VAR) {
1698                FREE_OP(free_op_data1);
1699            }
1700            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1701                ZVAL_COPY(EX_VAR(opline->result.var), value);
1702            }
1703        }
1704    } else if (EXPECTED(Z_TYPE_P(object_ptr) == IS_OBJECT)) {
1705        zend_free_op free_op2;
1706        zval *property_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
1707
1708        zend_assign_to_object_dim(UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL, object_ptr, property_name, (opline+1)->op1_type, (opline+1)->op1, execute_data);
1709        FREE_OP2();
1710    } else if (EXPECTED(Z_TYPE_P(object_ptr) == IS_STRING) &&
1711        EXPECTED(Z_STRLEN_P(object_ptr) != 0)) {
1712        zend_long offset;
1713
1714        dim = GET_OP2_ZVAL_PTR(BP_VAR_R);
1715        offset = zend_fetch_string_offset(object_ptr, dim, BP_VAR_W);
1716        FREE_OP2();
1717        value = get_zval_ptr_deref((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
1718        zend_assign_to_string_offset(object_ptr, offset, value, (UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL));
1719        FREE_OP(free_op_data1);
1720    } else if (EXPECTED(Z_ISREF_P(object_ptr))) {
1721        object_ptr = Z_REFVAL_P(object_ptr);
1722        ZEND_VM_C_GOTO(try_assign_dim);
1723    } else {
1724        ZEND_VM_C_GOTO(try_assign_dim_array);
1725    }
1726    FREE_OP1_VAR_PTR();
1727    /* assign_dim has two opcodes! */
1728    CHECK_EXCEPTION();
1729    ZEND_VM_INC_OPCODE();
1730    ZEND_VM_NEXT_OPCODE();
1731}
1732
1733ZEND_VM_HANDLER(38, ZEND_ASSIGN, VAR|CV, CONST|TMP|VAR|CV)
1734{
1735    USE_OPLINE
1736    zend_free_op free_op1, free_op2;
1737    zval *value;
1738    zval *variable_ptr;
1739
1740    SAVE_OPLINE();
1741    value = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
1742    variable_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1743
1744    if (OP1_TYPE == IS_VAR && UNEXPECTED(variable_ptr == &EG(error_zval))) {
1745        if (OP2_TYPE == IS_TMP_VAR) {
1746            FREE_OP2();
1747        }
1748        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1749            ZVAL_NULL(EX_VAR(opline->result.var));
1750        }
1751    } else {
1752        value = zend_assign_to_variable(variable_ptr, value, OP2_TYPE);
1753        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1754            ZVAL_COPY(EX_VAR(opline->result.var), value);
1755        }
1756        FREE_OP1_VAR_PTR();
1757    }
1758
1759    /* zend_assign_to_variable() always takes care of op2, never free it! */
1760    FREE_OP2_IF_VAR();
1761
1762    CHECK_EXCEPTION();
1763    ZEND_VM_NEXT_OPCODE();
1764}
1765
1766ZEND_VM_HANDLER(39, ZEND_ASSIGN_REF, VAR|CV, VAR|CV)
1767{
1768    USE_OPLINE
1769    zend_free_op free_op1, free_op2;
1770    zval *variable_ptr;
1771    zval *value_ptr;
1772
1773    SAVE_OPLINE();
1774    value_ptr = GET_OP2_ZVAL_PTR_PTR(BP_VAR_W);
1775
1776    if (OP2_TYPE == IS_VAR && UNEXPECTED(value_ptr == NULL)) {
1777        zend_error_noreturn(E_ERROR, "Cannot create references to/from string offsets nor overloaded objects");
1778    }
1779    if (OP2_TYPE == IS_VAR &&
1780        (value_ptr == &EG(uninitialized_zval) ||
1781         (opline->extended_value == ZEND_RETURNS_FUNCTION &&
1782          !(Z_VAR_FLAGS_P(value_ptr) & IS_VAR_RET_REF)))) {
1783        if (!OP2_FREE) {
1784            PZVAL_LOCK(value_ptr); /* undo the effect of get_zval_ptr_ptr() */
1785        }
1786        zend_error(E_STRICT, "Only variables should be assigned by reference");
1787        if (UNEXPECTED(EG(exception) != NULL)) {
1788            FREE_OP2_VAR_PTR();
1789            HANDLE_EXCEPTION();
1790        }
1791        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_ASSIGN);
1792    } else if (OP2_TYPE == IS_VAR && opline->extended_value == ZEND_RETURNS_NEW) {
1793        if (!OP2_FREE) {
1794            PZVAL_LOCK(value_ptr);
1795        }
1796    }
1797
1798    variable_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1799    if (OP1_TYPE == IS_VAR && UNEXPECTED(variable_ptr == NULL)) {
1800        zend_error_noreturn(E_ERROR, "Cannot create references to/from string offsets nor overloaded objects");
1801    }
1802    if (OP1_TYPE == IS_VAR &&
1803        UNEXPECTED(Z_TYPE_P(EX_VAR(opline->op1.var)) != IS_INDIRECT) &&
1804        UNEXPECTED(!Z_ISREF_P(variable_ptr))) {
1805        zend_error_noreturn(E_ERROR, "Cannot assign by reference to overloaded object");
1806    }
1807    if ((OP1_TYPE == IS_VAR && UNEXPECTED(variable_ptr == &EG(error_zval))) ||
1808        (OP2_TYPE == IS_VAR && UNEXPECTED(value_ptr == &EG(error_zval)))) {
1809        variable_ptr = &EG(uninitialized_zval);
1810    } else {
1811        zend_assign_to_variable_reference(variable_ptr, value_ptr);
1812    }
1813
1814    if (OP2_TYPE == IS_VAR && opline->extended_value == ZEND_RETURNS_NEW) {
1815        if (!OP2_FREE) {
1816            Z_DELREF_P(variable_ptr);
1817        }
1818    }
1819
1820    if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1821        ZVAL_COPY(EX_VAR(opline->result.var), variable_ptr);
1822    }
1823
1824    FREE_OP1_VAR_PTR();
1825    FREE_OP2_VAR_PTR();
1826
1827    CHECK_EXCEPTION();
1828    ZEND_VM_NEXT_OPCODE();
1829}
1830
1831ZEND_VM_HELPER(zend_leave_helper, ANY, ANY)
1832{
1833    zend_call_kind call_kind = EX_CALL_KIND();
1834
1835    if (call_kind == ZEND_CALL_NESTED_FUNCTION) {
1836        zend_object *object;
1837
1838        i_free_compiled_variables(execute_data);
1839        if (UNEXPECTED(EX(symbol_table) != NULL)) {
1840            zend_clean_and_cache_symbol_table(EX(symbol_table));
1841        }
1842        zend_vm_stack_free_extra_args(execute_data);
1843        EG(current_execute_data) = EX(prev_execute_data);
1844        if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_CLOSURE) != 0) && EX(func)->op_array.prototype) {
1845            OBJ_RELEASE((zend_object*)EX(func)->op_array.prototype);
1846        }
1847        object = Z_OBJ(EX(This));
1848        zend_vm_stack_free_call_frame(execute_data);
1849
1850        execute_data = EG(current_execute_data);
1851
1852        if (object) {
1853            if (UNEXPECTED(EG(exception) != NULL) && (EX(opline)->op1.num & ZEND_CALL_CTOR)) {
1854                if (!(EX(opline)->op1.num & ZEND_CALL_CTOR_RESULT_UNUSED)) {
1855                    GC_REFCOUNT(object)--;
1856                }
1857                if (GC_REFCOUNT(object) == 1) {
1858                    zend_object_store_ctor_failed(object);
1859                }
1860            }
1861            OBJ_RELEASE(object);
1862        }
1863        EG(scope) = EX(func)->op_array.scope;
1864
1865        if (UNEXPECTED(EG(exception) != NULL)) {
1866            const zend_op *opline = EX(opline);
1867            zend_throw_exception_internal(NULL);
1868            if (RETURN_VALUE_USED(opline)) {
1869                zval_ptr_dtor(EX_VAR(opline->result.var));
1870            }
1871            HANDLE_EXCEPTION_LEAVE();
1872        }
1873
1874        LOAD_OPLINE();
1875        ZEND_VM_INC_OPCODE();
1876        ZEND_VM_LEAVE();
1877    } else if (call_kind == ZEND_CALL_NESTED_CODE) {
1878        zend_detach_symbol_table(execute_data);
1879        destroy_op_array(&EX(func)->op_array);
1880        efree_size(EX(func), sizeof(zend_op_array));
1881        EG(current_execute_data) = EX(prev_execute_data);
1882        zend_vm_stack_free_call_frame(execute_data);
1883
1884        execute_data = EG(current_execute_data);
1885        zend_attach_symbol_table(execute_data);
1886        if (UNEXPECTED(EG(exception) != NULL)) {
1887            zend_throw_exception_internal(NULL);
1888            HANDLE_EXCEPTION_LEAVE();
1889        }
1890
1891        LOAD_OPLINE();
1892        ZEND_VM_INC_OPCODE();
1893        ZEND_VM_LEAVE();
1894    } else {
1895        if (call_kind == ZEND_CALL_TOP_FUNCTION) {
1896            i_free_compiled_variables(execute_data);
1897            if (UNEXPECTED(EX(symbol_table) != NULL)) {
1898                zend_clean_and_cache_symbol_table(EX(symbol_table));
1899            }
1900            zend_vm_stack_free_extra_args(execute_data);
1901            EG(current_execute_data) = EX(prev_execute_data);
1902            if ((EX(func)->op_array.fn_flags & ZEND_ACC_CLOSURE) && EX(func)->op_array.prototype) {
1903                OBJ_RELEASE((zend_object*)EX(func)->op_array.prototype);
1904            }
1905        } else /* if (call_kind == ZEND_CALL_TOP_CODE) */ {
1906            zend_array *symbol_table = EX(symbol_table);
1907            zend_execute_data *old_execute_data;
1908
1909            zend_detach_symbol_table(execute_data);
1910            old_execute_data = EX(prev_execute_data);
1911            while (old_execute_data) {
1912                if (old_execute_data->func && ZEND_USER_CODE(old_execute_data->func->op_array.type)) {
1913                    if (old_execute_data->symbol_table == symbol_table) {
1914                        zend_attach_symbol_table(old_execute_data);
1915                    }
1916                    break;
1917                }
1918                old_execute_data = old_execute_data->prev_execute_data;
1919            }
1920            EG(current_execute_data) = EX(prev_execute_data);
1921        }
1922        zend_vm_stack_free_call_frame(execute_data);
1923
1924        ZEND_VM_RETURN();
1925    }
1926}
1927
1928ZEND_VM_HANDLER(42, ZEND_JMP, ANY, ANY)
1929{
1930    USE_OPLINE
1931
1932    ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op1));
1933    ZEND_VM_CONTINUE();
1934}
1935
1936ZEND_VM_HANDLER(43, ZEND_JMPZ, CONST|TMPVAR|CV, ANY)
1937{
1938    USE_OPLINE
1939    zend_free_op free_op1;
1940    zval *val;
1941
1942    SAVE_OPLINE();
1943    val = GET_OP1_ZVAL_PTR(BP_VAR_R);
1944
1945    if (Z_TYPE_P(val) == IS_TRUE) {
1946        ZEND_VM_SET_OPCODE(opline + 1);
1947        ZEND_VM_CONTINUE();
1948    } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
1949        if (OP1_TYPE == IS_CV) {
1950            ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
1951        } else {
1952            ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
1953            ZEND_VM_CONTINUE();
1954        }
1955    }
1956
1957    if (i_zend_is_true(val)) {
1958        opline++;
1959    } else {
1960        opline = OP_JMP_ADDR(opline, opline->op2);
1961    }
1962    FREE_OP1();
1963    if (UNEXPECTED(EG(exception) != NULL)) {
1964        HANDLE_EXCEPTION();
1965    }
1966    ZEND_VM_JMP(opline);
1967}
1968
1969ZEND_VM_HANDLER(44, ZEND_JMPNZ, CONST|TMPVAR|CV, ANY)
1970{
1971    USE_OPLINE
1972    zend_free_op free_op1;
1973    zval *val;
1974
1975    SAVE_OPLINE();
1976    val = GET_OP1_ZVAL_PTR(BP_VAR_R);
1977
1978    if (Z_TYPE_P(val) == IS_TRUE) {
1979        ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
1980        ZEND_VM_CONTINUE();
1981    } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
1982        if (OP1_TYPE == IS_CV) {
1983            ZEND_VM_NEXT_OPCODE();
1984        } else {
1985            ZEND_VM_SET_OPCODE(opline + 1);
1986            ZEND_VM_CONTINUE();
1987        }
1988    }
1989
1990    if (i_zend_is_true(val)) {
1991        opline = OP_JMP_ADDR(opline, opline->op2);
1992    } else {
1993        opline++;
1994    }
1995    FREE_OP1();
1996    if (UNEXPECTED(EG(exception) != NULL)) {
1997        HANDLE_EXCEPTION();
1998    }
1999    ZEND_VM_JMP(opline);
2000}
2001
2002ZEND_VM_HANDLER(45, ZEND_JMPZNZ, CONST|TMPVAR|CV, ANY)
2003{
2004    USE_OPLINE
2005    zend_free_op free_op1;
2006    zval *val;
2007
2008    SAVE_OPLINE();
2009    val = GET_OP1_ZVAL_PTR(BP_VAR_R);
2010
2011    if (EXPECTED(Z_TYPE_P(val) == IS_TRUE)) {
2012        ZEND_VM_SET_RELATIVE_OPCODE(opline, opline->extended_value);
2013        ZEND_VM_CONTINUE();
2014    } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
2015        if (OP1_TYPE == IS_CV) {
2016            ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
2017        } else {
2018            ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2019            ZEND_VM_CONTINUE();
2020        }
2021    }
2022
2023    if (i_zend_is_true(val)) {
2024        opline = ZEND_OFFSET_TO_OPLINE(opline, opline->extended_value);
2025    } else {
2026        opline = OP_JMP_ADDR(opline, opline->op2);
2027    }
2028    FREE_OP1();
2029    if (UNEXPECTED(EG(exception) != NULL)) {
2030        HANDLE_EXCEPTION();
2031    }
2032    ZEND_VM_JMP(opline);
2033}
2034
2035ZEND_VM_HANDLER(46, ZEND_JMPZ_EX, CONST|TMPVAR|CV, ANY)
2036{
2037    USE_OPLINE
2038    zend_free_op free_op1;
2039    zval *val;
2040
2041    SAVE_OPLINE();
2042    val = GET_OP1_ZVAL_PTR(BP_VAR_R);
2043
2044    if (Z_TYPE_P(val) == IS_TRUE) {
2045        ZVAL_TRUE(EX_VAR(opline->result.var));
2046        ZEND_VM_SET_OPCODE(opline + 1);
2047        ZEND_VM_CONTINUE();
2048    } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
2049        ZVAL_FALSE(EX_VAR(opline->result.var));
2050        if (OP1_TYPE == IS_CV) {
2051            ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
2052        } else {
2053            ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2054            ZEND_VM_CONTINUE();
2055        }
2056    }
2057
2058    if (i_zend_is_true(val)) {
2059        FREE_OP1();
2060        ZVAL_TRUE(EX_VAR(opline->result.var));
2061        opline++;
2062    } else {
2063        FREE_OP1();
2064        ZVAL_FALSE(EX_VAR(opline->result.var));
2065        opline = OP_JMP_ADDR(opline, opline->op2);
2066    }
2067    if (UNEXPECTED(EG(exception) != NULL)) {
2068        HANDLE_EXCEPTION();
2069    }
2070    ZEND_VM_JMP(opline);
2071}
2072
2073ZEND_VM_HANDLER(47, ZEND_JMPNZ_EX, CONST|TMPVAR|CV, ANY)
2074{
2075    USE_OPLINE
2076    zend_free_op free_op1;
2077    zval *val;
2078
2079    SAVE_OPLINE();
2080    val = GET_OP1_ZVAL_PTR(BP_VAR_R);
2081
2082    if (Z_TYPE_P(val) == IS_TRUE) {
2083        ZVAL_TRUE(EX_VAR(opline->result.var));
2084        ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2085        ZEND_VM_CONTINUE();
2086    } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
2087        ZVAL_FALSE(EX_VAR(opline->result.var));
2088        if (OP1_TYPE == IS_CV) {
2089            ZEND_VM_NEXT_OPCODE();
2090        } else {
2091            ZEND_VM_SET_OPCODE(opline + 1);
2092            ZEND_VM_CONTINUE();
2093        }
2094    }
2095    if (i_zend_is_true(val)) {
2096        ZVAL_TRUE(EX_VAR(opline->result.var));
2097        opline = OP_JMP_ADDR(opline, opline->op2);
2098    } else {
2099        ZVAL_FALSE(EX_VAR(opline->result.var));
2100        opline++;
2101    }
2102    FREE_OP1();
2103    if (UNEXPECTED(EG(exception) != NULL)) {
2104        HANDLE_EXCEPTION();
2105    }
2106    ZEND_VM_JMP(opline);
2107}
2108
2109ZEND_VM_HANDLER(70, ZEND_FREE, TMPVAR, ANY)
2110{
2111    USE_OPLINE
2112
2113    SAVE_OPLINE();
2114    zval_ptr_dtor_nogc(EX_VAR(opline->op1.var));
2115    CHECK_EXCEPTION();
2116    ZEND_VM_NEXT_OPCODE();
2117}
2118
2119ZEND_VM_HANDLER(54, ZEND_ADD_CHAR, TMP|UNUSED, CONST)
2120{
2121    USE_OPLINE
2122    zval *str = EX_VAR(opline->result.var);
2123
2124    SAVE_OPLINE();
2125
2126    if (OP1_TYPE == IS_UNUSED) {
2127        /* Initialize for erealloc in add_char_to_string */
2128        ZVAL_EMPTY_STRING(str);
2129    }
2130
2131    add_char_to_string(str, str, EX_CONSTANT(opline->op2));
2132
2133    /* FREE_OP is missing intentionally here - we're always working on the same temporary variable */
2134    /*CHECK_EXCEPTION();*/
2135    ZEND_VM_NEXT_OPCODE();
2136}
2137
2138ZEND_VM_HANDLER(55, ZEND_ADD_STRING, TMP|UNUSED, CONST)
2139{
2140    USE_OPLINE
2141    zval *str = EX_VAR(opline->result.var);
2142
2143    SAVE_OPLINE();
2144
2145    if (OP1_TYPE == IS_UNUSED) {
2146        /* Initialize for erealloc in add_string_to_string */
2147        ZVAL_EMPTY_STRING(str);
2148    }
2149
2150    add_string_to_string(str, str, EX_CONSTANT(opline->op2));
2151
2152    /* FREE_OP is missing intentionally here - we're always working on the same temporary variable */
2153    /*CHECK_EXCEPTION();*/
2154    ZEND_VM_NEXT_OPCODE();
2155}
2156
2157ZEND_VM_HANDLER(56, ZEND_ADD_VAR, TMP|UNUSED, TMPVAR|CV)
2158{
2159    USE_OPLINE
2160    zend_free_op free_op2;
2161    zval *str = EX_VAR(opline->result.var);
2162    zval *var;
2163    zval var_copy;
2164    int use_copy = 0;
2165
2166    SAVE_OPLINE();
2167    var = GET_OP2_ZVAL_PTR(BP_VAR_R);
2168
2169    if (OP1_TYPE == IS_UNUSED) {
2170        /* Initialize for erealloc in add_string_to_string */
2171        ZVAL_EMPTY_STRING(str);
2172    }
2173
2174    if (Z_TYPE_P(var) != IS_STRING) {
2175        use_copy = zend_make_printable_zval(var, &var_copy);
2176
2177        if (use_copy) {
2178            var = &var_copy;
2179        }
2180    }
2181    add_string_to_string(str, str, var);
2182
2183    if (use_copy) {
2184        zend_string_release(Z_STR_P(var));
2185    }
2186    /* original comment, possibly problematic:
2187     * FREE_OP is missing intentionally here - we're always working on the same temporary variable
2188     * (Zeev):  I don't think it's problematic, we only use variables
2189     * which aren't affected by FREE_OP(Ts, )'s anyway, unless they're
2190     * string offsets or overloaded objects
2191     */
2192    FREE_OP2();
2193
2194    CHECK_EXCEPTION();
2195    ZEND_VM_NEXT_OPCODE();
2196}
2197
2198ZEND_VM_HANDLER(109, ZEND_FETCH_CLASS, ANY, CONST|TMPVAR|UNUSED|CV)
2199{
2200    USE_OPLINE
2201
2202    SAVE_OPLINE();
2203    if (EG(exception)) {
2204        zend_exception_save();
2205    }
2206    if (OP2_TYPE == IS_UNUSED) {
2207        Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class(NULL, opline->extended_value);
2208        CHECK_EXCEPTION();
2209        ZEND_VM_NEXT_OPCODE();
2210    } else {
2211        zend_free_op free_op2;
2212        zval *class_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2213
2214ZEND_VM_C_LABEL(try_class_name):
2215        if (OP2_TYPE == IS_CONST) {
2216            if (CACHED_PTR(Z_CACHE_SLOT_P(class_name))) {
2217                Z_CE_P(EX_VAR(opline->result.var)) = CACHED_PTR(Z_CACHE_SLOT_P(class_name));
2218            } else {
2219                Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class_by_name(Z_STR_P(class_name), EX_CONSTANT(opline->op2) + 1, opline->extended_value);
2220                CACHE_PTR(Z_CACHE_SLOT_P(class_name), Z_CE_P(EX_VAR(opline->result.var)));
2221            }
2222        } else if (Z_TYPE_P(class_name) == IS_OBJECT) {
2223            Z_CE_P(EX_VAR(opline->result.var)) = Z_OBJCE_P(class_name);
2224        } else if (Z_TYPE_P(class_name) == IS_STRING) {
2225            Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class(Z_STR_P(class_name), opline->extended_value);
2226        } else if ((OP2_TYPE & (IS_VAR|IS_CV)) && Z_TYPE_P(class_name) == IS_REFERENCE) {
2227            class_name = Z_REFVAL_P(class_name);
2228            ZEND_VM_C_GOTO(try_class_name);
2229        } else {
2230            if (UNEXPECTED(EG(exception) != NULL)) {
2231                HANDLE_EXCEPTION();
2232            }
2233            zend_error_noreturn(E_ERROR, "Class name must be a valid object or a string");
2234        }
2235
2236        FREE_OP2();
2237        CHECK_EXCEPTION();
2238        ZEND_VM_NEXT_OPCODE();
2239    }
2240}
2241
2242ZEND_VM_HANDLER(112, ZEND_INIT_METHOD_CALL, TMPVAR|UNUSED|CV, CONST|TMPVAR|CV)
2243{
2244    USE_OPLINE
2245    zval *function_name;
2246    zend_free_op free_op1, free_op2;
2247    zval *object;
2248    zend_function *fbc;
2249    zend_class_entry *called_scope;
2250    zend_object *obj;
2251
2252    SAVE_OPLINE();
2253
2254    function_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2255
2256    if (OP2_TYPE != IS_CONST &&
2257        UNEXPECTED(Z_TYPE_P(function_name) != IS_STRING)) {
2258        if (UNEXPECTED(EG(exception) != NULL)) {
2259            HANDLE_EXCEPTION();
2260        }
2261        zend_error_noreturn(E_ERROR, "Method name must be a string");
2262    }
2263
2264    object = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_R);
2265
2266    do {
2267        if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
2268            uint32_t nesting = 1;
2269
2270            if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(object)) {
2271                object = Z_REFVAL_P(object);
2272                if (EXPECTED(Z_TYPE_P(object) == IS_OBJECT)) {
2273                    break;
2274                }
2275            }
2276
2277            if (UNEXPECTED(EG(exception) != NULL)) {
2278                FREE_OP2();
2279                HANDLE_EXCEPTION();
2280            }
2281
2282            zend_error(E_RECOVERABLE_ERROR, "Call to a member function %s() on %s",  Z_STRVAL_P(function_name), zend_get_type_by_const(Z_TYPE_P(object)));
2283            FREE_OP2();
2284            FREE_OP1();
2285
2286            if (EG(exception) != NULL) {
2287                HANDLE_EXCEPTION();
2288            }
2289
2290            /* No exception raised: Skip over arguments until fcall opcode with correct
2291             * nesting level. Return NULL (except when return value unused) */
2292            do {
2293                opline++;
2294                if (opline->opcode == ZEND_INIT_FCALL ||
2295                    opline->opcode == ZEND_INIT_FCALL_BY_NAME ||
2296                    opline->opcode == ZEND_INIT_NS_FCALL_BY_NAME ||
2297                    opline->opcode == ZEND_INIT_METHOD_CALL ||
2298                    opline->opcode == ZEND_INIT_STATIC_METHOD_CALL ||
2299                    opline->opcode == ZEND_INIT_USER_CALL ||
2300                    opline->opcode == ZEND_NEW
2301                ) {
2302                    nesting++;
2303                } else if (opline->opcode == ZEND_DO_FCALL) {
2304                    nesting--;
2305                }
2306            } while (nesting);
2307
2308            if (RETURN_VALUE_USED(opline)) {
2309                ZVAL_NULL(EX_VAR(opline->result.var));
2310            }
2311
2312            /* We've skipped EXT_FCALL_BEGIND, so also skip the ending opcode */
2313            if ((opline + 1)->opcode == ZEND_EXT_FCALL_END) {
2314                opline++;
2315            }
2316            ZEND_VM_JMP(++opline);
2317        }
2318    } while (0);
2319
2320    obj = Z_OBJ_P(object);
2321    called_scope = obj->ce;
2322
2323    if (OP2_TYPE != IS_CONST ||
2324        EXPECTED((fbc = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), called_scope)) == NULL)) {
2325        zend_object *orig_obj = obj;
2326
2327        if (UNEXPECTED(obj->handlers->get_method == NULL)) {
2328            zend_error_noreturn(E_ERROR, "Object does not support method calls");
2329        }
2330
2331        /* First, locate the function. */
2332        fbc = obj->handlers->get_method(&obj, Z_STR_P(function_name), ((OP2_TYPE == IS_CONST) ? (EX_CONSTANT(opline->op2) + 1) : NULL));
2333        if (UNEXPECTED(fbc == NULL)) {
2334            zend_error_noreturn(E_ERROR, "Call to undefined method %s::%s()", obj->ce->name->val, Z_STRVAL_P(function_name));
2335        }
2336        if (OP2_TYPE == IS_CONST &&
2337            EXPECTED(fbc->type <= ZEND_USER_FUNCTION) &&
2338            EXPECTED((fbc->common.fn_flags & (ZEND_ACC_CALL_VIA_HANDLER|ZEND_ACC_NEVER_CACHE)) == 0) &&
2339            EXPECTED(obj == orig_obj)) {
2340            CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), called_scope, fbc);
2341        }
2342    }
2343
2344    if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_STATIC) != 0)) {
2345        obj = NULL;
2346    } else {
2347        GC_REFCOUNT(obj)++; /* For $this pointer */
2348    }
2349
2350    EX(call) = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
2351        fbc, opline->extended_value, called_scope, obj, EX(call));
2352
2353    FREE_OP2();
2354    FREE_OP1();
2355
2356    CHECK_EXCEPTION();
2357    ZEND_VM_NEXT_OPCODE();
2358}
2359
2360ZEND_VM_HANDLER(113, ZEND_INIT_STATIC_METHOD_CALL, CONST|VAR, CONST|TMPVAR|UNUSED|CV)
2361{
2362    USE_OPLINE
2363    zval *function_name;
2364    zend_class_entry *ce;
2365    zend_object *object;
2366    zend_function *fbc;
2367
2368    SAVE_OPLINE();
2369
2370    if (OP1_TYPE == IS_CONST) {
2371        /* no function found. try a static method in class */
2372        if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)))) {
2373            ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
2374        } else {
2375            ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, ZEND_FETCH_CLASS_DEFAULT);
2376            if (UNEXPECTED(EG(exception) != NULL)) {
2377                HANDLE_EXCEPTION();
2378            }
2379            if (UNEXPECTED(ce == NULL)) {
2380                zend_error_noreturn(E_ERROR, "Class '%s' not found", Z_STRVAL_P(EX_CONSTANT(opline->op1)));
2381            }
2382            CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce);
2383        }
2384    } else {
2385        ce = Z_CE_P(EX_VAR(opline->op1.var));
2386    }
2387
2388    if (OP1_TYPE == IS_CONST &&
2389        OP2_TYPE == IS_CONST &&
2390        CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) {
2391        fbc = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
2392    } else if (OP1_TYPE != IS_CONST &&
2393               OP2_TYPE == IS_CONST &&
2394               (fbc = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce))) {
2395        /* do nothing */
2396    } else if (OP2_TYPE != IS_UNUSED) {
2397        zend_free_op free_op2;
2398
2399        function_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2400        if (OP2_TYPE != IS_CONST) {
2401            if (UNEXPECTED(Z_TYPE_P(function_name) != IS_STRING)) {
2402                if (UNEXPECTED(EG(exception) != NULL)) {
2403                    HANDLE_EXCEPTION();
2404                }
2405                zend_error_noreturn(E_ERROR, "Function name must be a string");
2406            }
2407        }
2408
2409        if (ce->get_static_method) {
2410            fbc = ce->get_static_method(ce, Z_STR_P(function_name));
2411        } else {
2412            fbc = zend_std_get_static_method(ce, Z_STR_P(function_name), ((OP2_TYPE == IS_CONST) ? (EX_CONSTANT(opline->op2) + 1) : NULL));
2413        }
2414        if (UNEXPECTED(fbc == NULL)) {
2415            zend_error_noreturn(E_ERROR, "Call to undefined method %s::%s()", ce->name->val, Z_STRVAL_P(function_name));
2416        }
2417        if (OP2_TYPE == IS_CONST &&
2418            EXPECTED(fbc->type <= ZEND_USER_FUNCTION) &&
2419            EXPECTED((fbc->common.fn_flags & (ZEND_ACC_CALL_VIA_HANDLER|ZEND_ACC_NEVER_CACHE)) == 0)) {
2420            if (OP1_TYPE == IS_CONST) {
2421                CACHE_PTR(Z_CACHE_SLOT_P(function_name), fbc);
2422            } else {
2423                CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), ce, fbc);
2424            }
2425        }
2426        if (OP2_TYPE != IS_CONST) {
2427            FREE_OP2();
2428        }
2429    } else {
2430        if (UNEXPECTED(ce->constructor == NULL)) {
2431            zend_error_noreturn(E_ERROR, "Cannot call constructor");
2432        }
2433        if (Z_OBJ(EX(This)) && Z_OBJ(EX(This))->ce != ce->constructor->common.scope && (ce->constructor->common.fn_flags & ZEND_ACC_PRIVATE)) {
2434            zend_error_noreturn(E_ERROR, "Cannot call private %s::__construct()", ce->name->val);
2435        }
2436        fbc = ce->constructor;
2437    }
2438
2439    object = NULL;
2440    if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
2441        if (Z_OBJ(EX(This))) {
2442            object = Z_OBJ(EX(This));
2443            GC_REFCOUNT(object)++;
2444        }
2445        if (!object ||
2446            !instanceof_function(object->ce, ce)) {
2447            /* We are calling method of the other (incompatible) class,
2448               but passing $this. This is done for compatibility with php-4. */
2449            if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
2450                zend_error(
2451                    object ? E_DEPRECATED : E_STRICT,
2452                    "Non-static method %s::%s() should not be called statically%s",
2453                    fbc->common.scope->name->val, fbc->common.function_name->val,
2454                    object ? ", assuming $this from incompatible context" : "");
2455            } else {
2456                /* An internal function assumes $this is present and won't check that. So PHP would crash by allowing the call. */
2457                zend_error_noreturn(
2458                    E_ERROR,
2459                    "Non-static method %s::%s() cannot be called statically%s",
2460                    fbc->common.scope->name->val, fbc->common.function_name->val,
2461                    object ? ", assuming $this from incompatible context" : "");
2462            }
2463        }
2464    }
2465
2466    if (OP1_TYPE != IS_CONST) {
2467        /* previous opcode is ZEND_FETCH_CLASS */
2468        if ((opline-1)->extended_value == ZEND_FETCH_CLASS_PARENT || (opline-1)->extended_value == ZEND_FETCH_CLASS_SELF) {
2469            ce = EX(called_scope);
2470        }
2471    }
2472
2473    EX(call) = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
2474        fbc, opline->extended_value, ce, object, EX(call));
2475
2476    if (OP2_TYPE == IS_UNUSED) {
2477        EX(call)->return_value = NULL;
2478    }
2479
2480    CHECK_EXCEPTION();
2481    ZEND_VM_NEXT_OPCODE();
2482}
2483
2484ZEND_VM_HANDLER(59, ZEND_INIT_FCALL_BY_NAME, ANY, CONST|TMPVAR|CV)
2485{
2486    USE_OPLINE
2487    zend_function *fbc;
2488    zval *function_name, *func;
2489
2490    if (OP2_TYPE == IS_CONST && Z_TYPE_P(EX_CONSTANT(opline->op2)) == IS_STRING) {
2491        function_name = (zval*)(EX_CONSTANT(opline->op2)+1);
2492        if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) {
2493            fbc = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
2494        } else if (UNEXPECTED((func = zend_hash_find(EG(function_table), Z_STR_P(function_name))) == NULL)) {
2495            SAVE_OPLINE();
2496            zend_error_noreturn(E_ERROR, "Call to undefined function %s()", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
2497        } else {
2498            fbc = Z_FUNC_P(func);
2499            CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), fbc);
2500        }
2501
2502        EX(call) = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
2503            fbc, opline->extended_value, NULL, NULL, EX(call));
2504
2505        /*CHECK_EXCEPTION();*/
2506        ZEND_VM_NEXT_OPCODE();
2507    } else {
2508        zend_string *lcname;
2509        zend_free_op free_op2;
2510        zend_class_entry *called_scope;
2511        zend_object *object;
2512
2513        SAVE_OPLINE();
2514        function_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2515
2516ZEND_VM_C_LABEL(try_function_name):
2517        if (OP2_TYPE != IS_CONST && EXPECTED(Z_TYPE_P(function_name) == IS_STRING)) {
2518            if (Z_STRVAL_P(function_name)[0] == '\\') {
2519                lcname = zend_string_alloc(Z_STRLEN_P(function_name) - 1, 0);
2520                zend_str_tolower_copy(lcname->val, Z_STRVAL_P(function_name) + 1, Z_STRLEN_P(function_name) - 1);
2521            } else {
2522                lcname = zend_string_tolower(Z_STR_P(function_name));
2523            }
2524            if (UNEXPECTED((func = zend_hash_find(EG(function_table), lcname)) == NULL)) {
2525                zend_error_noreturn(E_ERROR, "Call to undefined function %s()", Z_STRVAL_P(function_name));
2526            }
2527            zend_string_release(lcname);
2528            FREE_OP2();
2529
2530            fbc = Z_FUNC_P(func);
2531            called_scope = NULL;
2532            object = NULL;
2533        } else if (OP2_TYPE != IS_CONST &&
2534            EXPECTED(Z_TYPE_P(function_name) == IS_OBJECT) &&
2535            Z_OBJ_HANDLER_P(function_name, get_closure) &&
2536            Z_OBJ_HANDLER_P(function_name, get_closure)(function_name, &called_scope, &fbc, &object) == SUCCESS) {
2537            if (object) {
2538                GC_REFCOUNT(object)++;
2539            }
2540            if (OP2_TYPE == IS_VAR && (fbc->common.fn_flags & ZEND_ACC_CLOSURE)) {
2541                /* Delay closure destruction until its invocation */
2542                fbc->common.prototype = (zend_function*)Z_OBJ_P(free_op2);
2543            } else if (OP2_TYPE == IS_CV) {
2544                FREE_OP2();
2545            }
2546        } else if (EXPECTED(Z_TYPE_P(function_name) == IS_ARRAY) &&
2547                zend_hash_num_elements(Z_ARRVAL_P(function_name)) == 2) {
2548            zval *obj;
2549            zval *method;
2550
2551            obj = zend_hash_index_find(Z_ARRVAL_P(function_name), 0);
2552            method = zend_hash_index_find(Z_ARRVAL_P(function_name), 1);
2553
2554            if (!obj || !method) {
2555                zend_error_noreturn(E_ERROR, "Array callback has to contain indices 0 and 1");
2556            }
2557
2558            ZVAL_DEREF(obj);
2559            if (Z_TYPE_P(obj) != IS_STRING && Z_TYPE_P(obj) != IS_OBJECT) {
2560                zend_error_noreturn(E_ERROR, "First array member is not a valid class name or object");
2561            }
2562
2563            ZVAL_DEREF(method);
2564            if (Z_TYPE_P(method) != IS_STRING) {
2565                zend_error_noreturn(E_ERROR, "Second array member is not a valid method");
2566            }
2567
2568            if (Z_TYPE_P(obj) == IS_STRING) {
2569                object = NULL;
2570                called_scope = zend_fetch_class_by_name(Z_STR_P(obj), NULL, 0);
2571                if (UNEXPECTED(called_scope == NULL)) {
2572                    CHECK_EXCEPTION();
2573                    ZEND_VM_NEXT_OPCODE();
2574                }
2575
2576                if (called_scope->get_static_method) {
2577                    fbc = called_scope->get_static_method(called_scope, Z_STR_P(method));
2578                } else {
2579                    fbc = zend_std_get_static_method(called_scope, Z_STR_P(method), NULL);
2580                }
2581                if (UNEXPECTED(fbc == NULL)) {
2582                    zend_error_noreturn(E_ERROR, "Call to undefined method %s::%s()", called_scope->name->val, Z_STRVAL_P(method));
2583                }
2584                if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
2585                    if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
2586                        zend_error(E_STRICT,
2587                        "Non-static method %s::%s() should not be called statically",
2588                        fbc->common.scope->name->val, fbc->common.function_name->val);
2589                    } else {
2590                        zend_error_noreturn(
2591                            E_ERROR,
2592                            "Non-static method %s::%s() cannot be called statically",
2593                            fbc->common.scope->name->val, fbc->common.function_name->val);
2594                    }
2595                }
2596            } else {
2597                called_scope = Z_OBJCE_P(obj);
2598                object = Z_OBJ_P(obj);
2599
2600                fbc = Z_OBJ_HT_P(obj)->get_method(&object, Z_STR_P(method), NULL);
2601                if (UNEXPECTED(fbc == NULL)) {
2602                    zend_error_noreturn(E_ERROR, "Call to undefined method %s::%s()", object->ce->name->val, Z_STRVAL_P(method));
2603                }
2604
2605                if ((fbc->common.fn_flags & ZEND_ACC_STATIC) != 0) {
2606                    object = NULL;
2607                } else {
2608                    GC_REFCOUNT(object)++; /* For $this pointer */
2609                }
2610            }
2611            FREE_OP2();
2612        } else if ((OP2_TYPE & (IS_VAR|IS_CV)) && Z_TYPE_P(function_name) == IS_REFERENCE) {
2613            function_name = Z_REFVAL_P(function_name);
2614            ZEND_VM_C_GOTO(try_function_name);
2615        } else {
2616            if (UNEXPECTED(EG(exception) != NULL)) {
2617                HANDLE_EXCEPTION();
2618            }
2619            zend_error_noreturn(E_ERROR, "Function name must be a string");
2620            ZEND_VM_CONTINUE(); /* Never reached */
2621        }
2622        EX(call) = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
2623            fbc, opline->extended_value, called_scope, object, EX(call));
2624
2625        CHECK_EXCEPTION();
2626        ZEND_VM_NEXT_OPCODE();
2627    }
2628}
2629
2630ZEND_VM_HANDLER(118, ZEND_INIT_USER_CALL, CONST, CONST|TMPVAR|CV)
2631{
2632    USE_OPLINE
2633    zend_free_op free_op2;
2634    zval *function_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2635    zend_fcall_info_cache fcc;
2636    char *error = NULL;
2637    zend_function *func;
2638    zend_class_entry *called_scope;
2639    zend_object *object;
2640
2641    if (zend_is_callable_ex(function_name, NULL, 0, NULL, &fcc, &error)) {
2642        if (error) {
2643            efree(error);
2644        }
2645        func = fcc.function_handler;
2646        if (func->common.fn_flags & ZEND_ACC_CLOSURE) {
2647            /* Delay closure destruction until its invocation */
2648            func->common.prototype = (zend_function*)Z_OBJ_P(function_name);
2649            Z_ADDREF_P(function_name);
2650        }
2651        called_scope = fcc.called_scope;
2652        object = fcc.object;
2653        if (object) {
2654            GC_REFCOUNT(object)++; /* For $this pointer */
2655        } else if (func->common.scope &&
2656                   !(func->common.fn_flags & ZEND_ACC_STATIC)) {
2657            if (func->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
2658                zend_error(E_STRICT,
2659                "Non-static method %s::%s() should not be called statically",
2660                func->common.scope->name->val, func->common.function_name->val);
2661            } else {
2662                zend_error_noreturn(
2663                    E_ERROR,
2664                    "Non-static method %s::%s() cannot be called statically",
2665                    func->common.scope->name->val, func->common.function_name->val);
2666            }
2667        }
2668    } else {
2669        zend_error(E_WARNING, "%s() expects parameter 1 to be a valid callback, %s", Z_STRVAL_P(EX_CONSTANT(opline->op1)), error);
2670        efree(error);
2671        func = (zend_function*)&zend_pass_function;
2672        called_scope = NULL;
2673        object = NULL;
2674    }
2675
2676    EX(call) = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
2677        func, opline->extended_value, called_scope, object, EX(call));
2678
2679    FREE_OP2();
2680    CHECK_EXCEPTION();
2681    ZEND_VM_NEXT_OPCODE();
2682}
2683
2684ZEND_VM_HANDLER(69, ZEND_INIT_NS_FCALL_BY_NAME, ANY, CONST)
2685{
2686    USE_OPLINE
2687    zval *func_name;
2688    zval *func;
2689    zend_function *fbc;
2690
2691    func_name = EX_CONSTANT(opline->op2) + 1;
2692    if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) {
2693        fbc = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
2694    } else if ((func = zend_hash_find(EG(function_table), Z_STR_P(func_name))) == NULL) {
2695        func_name++;
2696        if (UNEXPECTED((func = zend_hash_find(EG(function_table), Z_STR_P(func_name))) == NULL)) {
2697            SAVE_OPLINE();
2698            zend_error_noreturn(E_ERROR, "Call to undefined function %s()", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
2699        } else {
2700            fbc = Z_FUNC_P(func);
2701            CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), fbc);
2702        }
2703    } else {
2704        fbc = Z_FUNC_P(func);
2705        CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), fbc);
2706    }
2707
2708    EX(call) = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
2709        fbc, opline->extended_value, NULL, NULL, EX(call));
2710
2711    ZEND_VM_NEXT_OPCODE();
2712}
2713
2714ZEND_VM_HANDLER(61, ZEND_INIT_FCALL, ANY, CONST)
2715{
2716    USE_OPLINE
2717    zend_free_op free_op2;
2718    zval *fname = GET_OP2_ZVAL_PTR(BP_VAR_R);
2719    zval *func;
2720    zend_function *fbc;
2721
2722    if (CACHED_PTR(Z_CACHE_SLOT_P(fname))) {
2723        fbc = CACHED_PTR(Z_CACHE_SLOT_P(fname));
2724    } else if (UNEXPECTED((func = zend_hash_find(EG(function_table), Z_STR_P(fname))) == NULL)) {
2725        SAVE_OPLINE();
2726        zend_error_noreturn(E_ERROR, "Call to undefined function %s()", Z_STRVAL_P(fname));
2727    } else {
2728        fbc = Z_FUNC_P(func);
2729        CACHE_PTR(Z_CACHE_SLOT_P(fname), fbc);
2730    }
2731
2732    EX(call) = zend_vm_stack_push_call_frame_ex(
2733        opline->op1.num, ZEND_CALL_NESTED_FUNCTION,
2734        fbc, opline->extended_value, NULL, NULL, EX(call));
2735
2736    FREE_OP2();
2737
2738    ZEND_VM_NEXT_OPCODE();
2739}
2740
2741ZEND_VM_HANDLER(60, ZEND_DO_FCALL, ANY, ANY)
2742{
2743    USE_OPLINE
2744    zend_execute_data *call = EX(call);
2745    zend_function *fbc = call->func;
2746    zend_object *object = Z_OBJ(call->This);
2747
2748    SAVE_OPLINE();
2749    EX(call) = call->prev_execute_data;
2750    if (UNEXPECTED((fbc->common.fn_flags & (ZEND_ACC_ABSTRACT|ZEND_ACC_DEPRECATED)) != 0)) {
2751        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_ABSTRACT) != 0)) {
2752            zend_error_noreturn(E_ERROR, "Cannot call abstract method %s::%s()", fbc->common.scope->name->val, fbc->common.function_name->val);
2753        }
2754        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_DEPRECATED) != 0)) {
2755            zend_error(E_DEPRECATED, "Function %s%s%s() is deprecated",
2756                fbc->common.scope ? fbc->common.scope->name->val : "",
2757                fbc->common.scope ? "::" : "",
2758                fbc->common.function_name->val);
2759            if (UNEXPECTED(EG(exception) != NULL)) {
2760                HANDLE_EXCEPTION();
2761            }
2762        }
2763    }
2764
2765    LOAD_OPLINE();
2766
2767    if (UNEXPECTED(fbc->type == ZEND_INTERNAL_FUNCTION)) {
2768        int should_change_scope = 0;
2769        zval *ret;
2770
2771        if (fbc->common.scope) {
2772            should_change_scope = 1;
2773            /* TODO: we don't set scope if we call an object method ??? */
2774            /* See: ext/pdo_sqlite/tests/pdo_fetch_func_001.phpt */
2775#if 1
2776            EG(scope) = object ? NULL : fbc->common.scope;
2777#else
2778            EG(scope) = fbc->common.scope;
2779#endif
2780        } else {
2781            call->called_scope = EX(called_scope);
2782            Z_OBJ(call->This) = Z_OBJ(EX(This));
2783        }
2784
2785        call->prev_execute_data = execute_data;
2786        EG(current_execute_data) = call;
2787
2788        if (fbc->common.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) {
2789            uint32_t i;
2790            uint32_t num_args = ZEND_CALL_NUM_ARGS(call);
2791            zval *p = ZEND_CALL_ARG(call, 1);
2792
2793            for (i = 0; i < num_args; ++i) {
2794                zend_verify_internal_arg_type(fbc, i + 1, p);
2795                p++;
2796            }
2797            if (UNEXPECTED(EG(exception) != NULL)) {
2798                EG(current_execute_data) = call->prev_execute_data;
2799                zend_vm_stack_free_args(call);
2800                zend_vm_stack_free_call_frame(call);
2801                if (RETURN_VALUE_USED(opline)) {
2802                    ZVAL_UNDEF(EX_VAR(opline->result.var));
2803                }
2804                if (UNEXPECTED(should_change_scope)) {
2805                    ZEND_VM_C_GOTO(fcall_end_change_scope);
2806                } else {
2807                    ZEND_VM_C_GOTO(fcall_end);
2808                }
2809            }
2810        }
2811
2812        ret = EX_VAR(opline->result.var);
2813        ZVAL_NULL(ret);
2814        Z_VAR_FLAGS_P(ret) = (fbc->common.fn_flags & ZEND_ACC_RETURN_REFERENCE) != 0 ? IS_VAR_RET_REF : 0;
2815
2816        if (!zend_execute_internal) {
2817            /* saves one function call if zend_execute_internal is not used */
2818            fbc->internal_function.handler(call, ret);
2819        } else {
2820            zend_execute_internal(call, ret);
2821        }
2822        EG(current_execute_data) = call->prev_execute_data;
2823        zend_vm_stack_free_args(call);
2824        zend_vm_stack_free_call_frame(call);
2825
2826        if (!RETURN_VALUE_USED(opline)) {
2827            zval_ptr_dtor(ret);
2828        }
2829
2830        if (UNEXPECTED(should_change_scope)) {
2831            ZEND_VM_C_GOTO(fcall_end_change_scope);
2832        } else {
2833            ZEND_VM_C_GOTO(fcall_end);
2834        }
2835    } else if (EXPECTED(fbc->type == ZEND_USER_FUNCTION)) {
2836        EG(scope) = fbc->common.scope;
2837        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_GENERATOR) != 0)) {
2838            if (RETURN_VALUE_USED(opline)) {
2839                zend_generator_create_zval(call, &fbc->op_array, EX_VAR(opline->result.var));
2840            } else {
2841                zend_vm_stack_free_args(call);
2842            }
2843
2844            zend_vm_stack_free_call_frame(call);
2845        } else {
2846            zval *return_value = NULL;
2847
2848            call->symbol_table = NULL;
2849            if (RETURN_VALUE_USED(opline)) {
2850                return_value = EX_VAR(opline->result.var);
2851
2852                ZVAL_NULL(return_value);
2853                Z_VAR_FLAGS_P(return_value) = 0;
2854            }
2855
2856            call->prev_execute_data = execute_data;
2857            i_init_func_execute_data(call, &fbc->op_array, return_value);
2858
2859            if (EXPECTED(zend_execute_ex == execute_ex)) {
2860                ZEND_VM_ENTER();
2861            } else {
2862                ZEND_ADD_CALL_FLAG(call, ZEND_CALL_TOP);
2863                zend_execute_ex(call);
2864            }
2865        }
2866    } else { /* ZEND_OVERLOADED_FUNCTION */
2867        EG(scope) = fbc->common.scope;
2868
2869        ZVAL_NULL(EX_VAR(opline->result.var));
2870
2871        /* Not sure what should be done here if it's a static method */
2872        if (EXPECTED(object != NULL)) {
2873            call->prev_execute_data = execute_data;
2874            EG(current_execute_data) = call;
2875            object->handlers->call_method(fbc->common.function_name, object, call, EX_VAR(opline->result.var));
2876            EG(current_execute_data) = call->prev_execute_data;
2877        } else {
2878            zend_error_noreturn(E_ERROR, "Cannot call overloaded function for non-object");
2879        }
2880
2881        zend_vm_stack_free_args(call);
2882
2883        zend_vm_stack_free_call_frame(call);
2884
2885        if (fbc->type == ZEND_OVERLOADED_FUNCTION_TEMPORARY) {
2886            zend_string_release(fbc->common.function_name);
2887        }
2888        efree(fbc);
2889
2890        if (!RETURN_VALUE_USED(opline)) {
2891            zval_ptr_dtor(EX_VAR(opline->result.var));
2892        } else {
2893//???           Z_UNSET_ISREF_P(EX_T(opline->result.var).var.ptr);
2894//???           Z_SET_REFCOUNT_P(EX_T(opline->result.var).var.ptr, 1);
2895            Z_VAR_FLAGS_P(EX_VAR(opline->result.var)) = 0;
2896        }
2897    }
2898
2899ZEND_VM_C_LABEL(fcall_end_change_scope):
2900    if (object) {
2901        if (UNEXPECTED(EG(exception) != NULL) && (opline->op1.num & ZEND_CALL_CTOR)) {
2902            if (!(opline->op1.num & ZEND_CALL_CTOR_RESULT_UNUSED)) {
2903                GC_REFCOUNT(object)--;
2904            }
2905            if (GC_REFCOUNT(object) == 1) {
2906                zend_object_store_ctor_failed(object);
2907            }
2908        }
2909        OBJ_RELEASE(object);
2910    }
2911    EG(scope) = EX(func)->op_array.scope;
2912
2913ZEND_VM_C_LABEL(fcall_end):
2914    if (UNEXPECTED(EG(exception) != NULL)) {
2915        zend_throw_exception_internal(NULL);
2916        if (RETURN_VALUE_USED(opline)) {
2917            zval_ptr_dtor(EX_VAR(opline->result.var));
2918        }
2919        HANDLE_EXCEPTION();
2920    }
2921
2922    ZEND_VM_NEXT_OPCODE();
2923}
2924
2925ZEND_VM_HANDLER(62, ZEND_RETURN, CONST|TMP|VAR|CV, ANY)
2926{
2927    USE_OPLINE
2928    zval *retval_ptr;
2929    zend_free_op free_op1;
2930
2931    SAVE_OPLINE();
2932    retval_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
2933
2934    if (!EX(return_value)) {
2935        FREE_OP1();
2936    } else {
2937        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
2938            ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
2939            if (OP1_TYPE == IS_CONST) {
2940                if (UNEXPECTED(Z_OPT_COPYABLE_P(EX(return_value)))) {
2941                    zval_copy_ctor_func(EX(return_value));
2942                }
2943            }
2944        } else if ((OP1_TYPE == IS_CV || OP1_TYPE == IS_VAR) && Z_ISREF_P(retval_ptr)) {
2945            ZVAL_COPY(EX(return_value), Z_REFVAL_P(retval_ptr));
2946            FREE_OP1_IF_VAR();
2947        } else {
2948            ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
2949            if (OP1_TYPE == IS_CV) {
2950                if (Z_OPT_REFCOUNTED_P(retval_ptr)) Z_ADDREF_P(retval_ptr);
2951            }
2952        }
2953    }
2954    ZEND_VM_DISPATCH_TO_HELPER(zend_leave_helper);
2955}
2956
2957ZEND_VM_HANDLER(111, ZEND_RETURN_BY_REF, CONST|TMP|VAR|CV, ANY)
2958{
2959    USE_OPLINE
2960    zval *retval_ptr;
2961    zend_free_op free_op1;
2962
2963    SAVE_OPLINE();
2964
2965    do {
2966        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR ||
2967            (OP1_TYPE == IS_VAR && opline->extended_value == ZEND_RETURNS_VALUE)) {
2968            /* Not supposed to happen, but we'll allow it */
2969            zend_error(E_NOTICE, "Only variable references should be returned by reference");
2970
2971            retval_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
2972            if (!EX(return_value)) {
2973                if (OP1_TYPE == IS_TMP_VAR) {
2974                    FREE_OP1();
2975                }
2976            } else {
2977                ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
2978                Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
2979                if (OP1_TYPE != IS_TMP_VAR) {
2980                    zval_opt_copy_ctor_no_imm(EX(return_value));
2981                }
2982            }
2983            break;
2984        }
2985
2986        retval_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
2987
2988        if (OP1_TYPE == IS_VAR && UNEXPECTED(retval_ptr == NULL)) {
2989            zend_error_noreturn(E_ERROR, "Cannot return string offsets by reference");
2990        }
2991
2992        if (OP1_TYPE == IS_VAR) {
2993            if (retval_ptr == &EG(uninitialized_zval) ||
2994                (opline->extended_value == ZEND_RETURNS_FUNCTION &&
2995                 !(Z_VAR_FLAGS_P(retval_ptr) & IS_VAR_RET_REF))) {
2996                zend_error(E_NOTICE, "Only variable references should be returned by reference");
2997                if (EX(return_value)) {
2998                    ZVAL_NEW_REF(EX(return_value), retval_ptr);
2999                    Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
3000                    if (Z_REFCOUNTED_P(retval_ptr)) Z_ADDREF_P(retval_ptr);
3001                }
3002                break;
3003            }
3004        }
3005
3006        if (EX(return_value)) {
3007            ZVAL_MAKE_REF(retval_ptr);
3008            Z_ADDREF_P(retval_ptr);
3009            ZVAL_REF(EX(return_value), Z_REF_P(retval_ptr));
3010            Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
3011        }
3012    } while (0);
3013
3014    FREE_OP1_VAR_PTR();
3015    ZEND_VM_DISPATCH_TO_HELPER(zend_leave_helper);
3016}
3017
3018ZEND_VM_HANDLER(161, ZEND_GENERATOR_RETURN, ANY, ANY)
3019{
3020    /* The generator object is stored in EX(return_value) */
3021    zend_generator *generator = (zend_generator *) EX(return_value);
3022
3023    /* Close the generator to free up resources */
3024    zend_generator_close(generator, 1);
3025
3026    /* Pass execution back to handling code */
3027    ZEND_VM_RETURN();
3028}
3029
3030ZEND_VM_HANDLER(108, ZEND_THROW, CONST|TMP|VAR|CV, ANY)
3031{
3032    USE_OPLINE
3033    zval *value;
3034    zend_free_op free_op1;
3035
3036    SAVE_OPLINE();
3037    value = GET_OP1_ZVAL_PTR(BP_VAR_R);
3038
3039    do {
3040        if (OP1_TYPE == IS_CONST || UNEXPECTED(Z_TYPE_P(value) != IS_OBJECT)) {
3041            if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(value)) {
3042                value = Z_REFVAL_P(value);
3043                if (EXPECTED(Z_TYPE_P(value) == IS_OBJECT)) {
3044                    break;
3045                }
3046            }
3047            if (UNEXPECTED(EG(exception) != NULL)) {
3048                HANDLE_EXCEPTION();
3049            }
3050            zend_error_noreturn(E_ERROR, "Can only throw objects");
3051        }
3052    } while (0);
3053
3054    zend_exception_save();
3055    if (OP1_TYPE != IS_TMP_VAR) {
3056        if (Z_REFCOUNTED_P(value)) Z_ADDREF_P(value);
3057    }
3058
3059    zend_throw_exception_object(value);
3060    zend_exception_restore();
3061    FREE_OP1_IF_VAR();
3062    HANDLE_EXCEPTION();
3063}
3064
3065ZEND_VM_HANDLER(107, ZEND_CATCH, CONST, CV)
3066{
3067    USE_OPLINE
3068    zend_class_entry *ce, *catch_ce;
3069    zend_object *exception;
3070
3071    SAVE_OPLINE();
3072    /* Check whether an exception has been thrown, if not, jump over code */
3073    zend_exception_restore();
3074    if (EG(exception) == NULL) {
3075        ZEND_VM_SET_OPCODE(&EX(func)->op_array.opcodes[opline->extended_value]);
3076        ZEND_VM_CONTINUE(); /* CHECK_ME */
3077    }
3078    if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)))) {
3079        catch_ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
3080    } else {
3081        catch_ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, ZEND_FETCH_CLASS_NO_AUTOLOAD);
3082
3083        CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), catch_ce);
3084    }
3085    ce = EG(exception)->ce;
3086
3087#ifdef HAVE_DTRACE
3088    if (DTRACE_EXCEPTION_CAUGHT_ENABLED()) {
3089        DTRACE_EXCEPTION_CAUGHT((char *)ce->name);
3090    }
3091#endif /* HAVE_DTRACE */
3092
3093    if (ce != catch_ce) {
3094        if (!instanceof_function(ce, catch_ce)) {
3095            if (opline->result.num) {
3096                zend_throw_exception_internal(NULL);
3097                HANDLE_EXCEPTION();
3098            }
3099            ZEND_VM_SET_OPCODE(&EX(func)->op_array.opcodes[opline->extended_value]);
3100            ZEND_VM_CONTINUE(); /* CHECK_ME */
3101        }
3102    }
3103
3104    exception = EG(exception);
3105    zval_ptr_dtor(EX_VAR(opline->op2.var));
3106    ZVAL_OBJ(EX_VAR(opline->op2.var), EG(exception));
3107    if (UNEXPECTED(EG(exception) != exception)) {
3108        GC_REFCOUNT(EG(exception))++;
3109        HANDLE_EXCEPTION();
3110    } else {
3111        EG(exception) = NULL;
3112        ZEND_VM_NEXT_OPCODE();
3113    }
3114}
3115
3116ZEND_VM_HANDLER(65, ZEND_SEND_VAL, CONST|TMP, ANY)
3117{
3118    USE_OPLINE
3119    zval *value, *arg;
3120    zend_free_op free_op1;
3121
3122    SAVE_OPLINE();
3123    value = GET_OP1_ZVAL_PTR(BP_VAR_R);
3124    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
3125    ZVAL_COPY_VALUE(arg, value);
3126    if (OP1_TYPE == IS_CONST) {
3127        if (UNEXPECTED(Z_OPT_COPYABLE_P(arg))) {
3128            zval_copy_ctor_func(arg);
3129        }
3130    }
3131    ZEND_VM_NEXT_OPCODE();
3132}
3133
3134ZEND_VM_HANDLER(116, ZEND_SEND_VAL_EX, CONST|TMP, ANY)
3135{
3136    USE_OPLINE
3137    zval *value, *arg;
3138    zend_free_op free_op1;
3139
3140    SAVE_OPLINE();
3141    if (ARG_MUST_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3142        zend_error_noreturn(E_ERROR, "Cannot pass parameter %d by reference", opline->op2.num);
3143    }
3144    value = GET_OP1_ZVAL_PTR(BP_VAR_R);
3145    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
3146    ZVAL_COPY_VALUE(arg, value);
3147    if (OP1_TYPE == IS_CONST) {
3148        if (UNEXPECTED(Z_OPT_COPYABLE_P(arg))) {
3149            zval_copy_ctor_func(arg);
3150        }
3151    }
3152    ZEND_VM_NEXT_OPCODE();
3153}
3154
3155ZEND_VM_HANDLER(117, ZEND_SEND_VAR, VAR|CV, ANY)
3156{
3157    USE_OPLINE
3158    zval *varptr, *arg;
3159    zend_free_op free_op1;
3160
3161    varptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
3162    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
3163    if (Z_ISREF_P(varptr)) {
3164        ZVAL_COPY(arg, Z_REFVAL_P(varptr));
3165        FREE_OP1();
3166    } else {
3167        ZVAL_COPY_VALUE(arg, varptr);
3168        if (OP1_TYPE == IS_CV) {
3169            if (Z_OPT_REFCOUNTED_P(arg)) Z_ADDREF_P(arg);
3170        }
3171    }
3172    ZEND_VM_NEXT_OPCODE();
3173}
3174
3175ZEND_VM_HANDLER(106, ZEND_SEND_VAR_NO_REF, VAR|CV, ANY)
3176{
3177    USE_OPLINE
3178    zend_free_op free_op1;
3179    zval *varptr, *arg;
3180
3181    SAVE_OPLINE();
3182
3183    if (!(opline->extended_value & ZEND_ARG_COMPILE_TIME_BOUND)) {
3184        if (!ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3185            ZEND_VM_DISPATCH_TO_HANDLER(ZEND_SEND_VAR);
3186        }
3187    }
3188
3189    varptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
3190    if ((!(opline->extended_value & ZEND_ARG_SEND_FUNCTION) ||
3191         (Z_VAR_FLAGS_P(varptr) & IS_VAR_RET_REF)) &&
3192        (Z_ISREF_P(varptr) || Z_TYPE_P(varptr) == IS_OBJECT)) {
3193
3194        ZVAL_MAKE_REF(varptr);
3195        if (OP1_TYPE == IS_CV) {
3196            Z_ADDREF_P(varptr);
3197        }
3198    } else {
3199        if ((opline->extended_value & ZEND_ARG_COMPILE_TIME_BOUND) ?
3200            !(opline->extended_value & ZEND_ARG_SEND_SILENT) :
3201            !ARG_MAY_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3202            zend_error(E_STRICT, "Only variables should be passed by reference");
3203        }
3204    }
3205
3206    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
3207    ZVAL_COPY_VALUE(arg, varptr);
3208
3209    CHECK_EXCEPTION();
3210    ZEND_VM_NEXT_OPCODE();
3211}
3212
3213ZEND_VM_HANDLER(67, ZEND_SEND_REF, VAR|CV, ANY)
3214{
3215    USE_OPLINE
3216    zend_free_op free_op1;
3217    zval *varptr, *arg;
3218
3219    SAVE_OPLINE();
3220    varptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
3221
3222    if (OP1_TYPE == IS_VAR && UNEXPECTED(varptr == NULL)) {
3223        zend_error_noreturn(E_ERROR, "Only variables can be passed by reference");
3224    }
3225
3226    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
3227    if (OP1_TYPE == IS_VAR && UNEXPECTED(varptr == &EG(error_zval))) {
3228        ZVAL_NEW_REF(arg, &EG(uninitialized_zval));
3229        ZEND_VM_NEXT_OPCODE();
3230    }
3231
3232    if (Z_ISREF_P(varptr)) {
3233        Z_ADDREF_P(varptr);
3234        ZVAL_COPY_VALUE(arg, varptr);
3235    } else if (OP1_TYPE == IS_VAR &&
3236        UNEXPECTED(Z_TYPE_P(EX_VAR(opline->op1.var)) != IS_INDIRECT)) {
3237        ZVAL_NEW_REF(arg, varptr);
3238    } else {
3239        ZVAL_NEW_REF(arg, varptr);
3240        Z_ADDREF_P(arg);
3241        ZVAL_REF(varptr, Z_REF_P(arg));
3242    }
3243
3244    FREE_OP1_VAR_PTR();
3245    ZEND_VM_NEXT_OPCODE();
3246}
3247
3248ZEND_VM_HANDLER(66, ZEND_SEND_VAR_EX, VAR|CV, ANY)
3249{
3250    USE_OPLINE
3251    zval *varptr, *arg;
3252    zend_free_op free_op1;
3253
3254    if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3255        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_SEND_REF);
3256    }
3257    varptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
3258    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
3259    if (Z_ISREF_P(varptr)) {
3260        ZVAL_COPY(arg, Z_REFVAL_P(varptr));
3261        FREE_OP1();
3262    } else {
3263        ZVAL_COPY_VALUE(arg, varptr);
3264        if (OP1_TYPE == IS_CV) {
3265            if (Z_OPT_REFCOUNTED_P(arg)) Z_ADDREF_P(arg);
3266        }
3267    }
3268    ZEND_VM_NEXT_OPCODE();
3269}
3270
3271ZEND_VM_HANDLER(165, ZEND_SEND_UNPACK, ANY, ANY)
3272{
3273    USE_OPLINE
3274    zend_free_op free_op1;
3275    zval *args;
3276    int arg_num;
3277    SAVE_OPLINE();
3278
3279    args = GET_OP1_ZVAL_PTR(BP_VAR_R);
3280    arg_num = ZEND_CALL_NUM_ARGS(EX(call)) + 1;
3281
3282ZEND_VM_C_LABEL(send_again):
3283    switch (Z_TYPE_P(args)) {
3284        case IS_ARRAY: {
3285            HashTable *ht = Z_ARRVAL_P(args);
3286            zval *arg, *top;
3287            zend_string *name;
3288
3289            zend_vm_stack_extend_call_frame(&EX(call), arg_num - 1, zend_hash_num_elements(ht));
3290
3291            if (OP1_TYPE != IS_CONST && OP1_TYPE != IS_TMP_VAR && Z_IMMUTABLE_P(args)) {
3292                uint32_t i;
3293                int separate = 0;
3294
3295                /* check if any of arguments are going to be passed by reference */
3296                for (i = 0; i < zend_hash_num_elements(ht); i++) {
3297                    if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num + i)) {
3298                        separate = 1;
3299                        break;
3300                    }
3301                }
3302                if (separate) {
3303                    zval_copy_ctor(args);
3304                    ht = Z_ARRVAL_P(args);
3305                }
3306            }
3307
3308            ZEND_HASH_FOREACH_STR_KEY_VAL(ht, name, arg) {
3309                if (name) {
3310                    zend_error(E_RECOVERABLE_ERROR, "Cannot unpack array with string keys");
3311                    FREE_OP1();
3312                    CHECK_EXCEPTION();
3313                    ZEND_VM_NEXT_OPCODE();
3314                }
3315
3316                top = ZEND_CALL_ARG(EX(call), arg_num);
3317                if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
3318                    if (!Z_IMMUTABLE_P(args)) {
3319                        ZVAL_MAKE_REF(arg);
3320                        Z_ADDREF_P(arg);
3321                        ZVAL_REF(top, Z_REF_P(arg));
3322                    } else {
3323                        ZVAL_DUP(top, arg);
3324                    }
3325                } else if (Z_ISREF_P(arg)) {
3326                    ZVAL_COPY(top, Z_REFVAL_P(arg));
3327                } else {
3328                    ZVAL_COPY(top, arg);
3329                }
3330
3331                ZEND_CALL_NUM_ARGS(EX(call))++;
3332                arg_num++;
3333            } ZEND_HASH_FOREACH_END();
3334
3335            break;
3336        }
3337        case IS_OBJECT: {
3338            zend_class_entry *ce = Z_OBJCE_P(args);
3339            zend_object_iterator *iter;
3340
3341            if (!ce || !ce->get_iterator) {
3342                zend_error(E_WARNING, "Only arrays and Traversables can be unpacked");
3343                break;
3344            }
3345
3346            iter = ce->get_iterator(ce, args, 0);
3347            if (UNEXPECTED(!iter)) {
3348                FREE_OP1();
3349                if (!EG(exception)) {
3350                    zend_throw_exception_ex(
3351                        NULL, 0, "Object of type %s did not create an Iterator", ce->name->val
3352                    );
3353                }
3354                HANDLE_EXCEPTION();
3355            }
3356
3357            if (iter->funcs->rewind) {
3358                iter->funcs->rewind(iter);
3359                if (UNEXPECTED(EG(exception) != NULL)) {
3360                    ZEND_VM_C_GOTO(unpack_iter_dtor);
3361                }
3362            }
3363
3364            for (; iter->funcs->valid(iter) == SUCCESS; ++arg_num) {
3365                zval *arg, *top;
3366
3367                if (UNEXPECTED(EG(exception) != NULL)) {
3368                    ZEND_VM_C_GOTO(unpack_iter_dtor);
3369                }
3370
3371                arg = iter->funcs->get_current_data(iter);
3372                if (UNEXPECTED(EG(exception) != NULL)) {
3373                    ZEND_VM_C_GOTO(unpack_iter_dtor);
3374                }
3375
3376                if (iter->funcs->get_current_key) {
3377                    zval key;
3378                    iter->funcs->get_current_key(iter, &key);
3379                    if (UNEXPECTED(EG(exception) != NULL)) {
3380                        ZEND_VM_C_GOTO(unpack_iter_dtor);
3381                    }
3382
3383                    if (Z_TYPE(key) == IS_STRING) {
3384                        zend_error(E_RECOVERABLE_ERROR,
3385                            "Cannot unpack Traversable with string keys");
3386                        zend_string_release(Z_STR(key));
3387                        ZEND_VM_C_GOTO(unpack_iter_dtor);
3388                    }
3389
3390                    zval_dtor(&key);
3391                }
3392
3393                if (ARG_MUST_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
3394                    zend_error(
3395                        E_WARNING, "Cannot pass by-reference argument %d of %s%s%s()"
3396                        " by unpacking a Traversable, passing by-value instead", arg_num,
3397                        EX(call)->func->common.scope ? EX(call)->func->common.scope->name->val : "",
3398                        EX(call)->func->common.scope ? "::" : "",
3399                        EX(call)->func->common.function_name->val
3400                    );
3401                }
3402
3403                if (Z_ISREF_P(arg)) {
3404                    ZVAL_DUP(arg, Z_REFVAL_P(arg));
3405                } else {
3406                    if (Z_REFCOUNTED_P(arg)) Z_ADDREF_P(arg);
3407                }
3408
3409                zend_vm_stack_extend_call_frame(&EX(call), arg_num - 1, 1);
3410                top = ZEND_CALL_ARG(EX(call), arg_num);
3411                ZVAL_COPY_VALUE(top, arg);
3412                ZEND_CALL_NUM_ARGS(EX(call))++;
3413
3414                iter->funcs->move_forward(iter);
3415                if (UNEXPECTED(EG(exception) != NULL)) {
3416                    ZEND_VM_C_GOTO(unpack_iter_dtor);
3417                }
3418            }
3419
3420ZEND_VM_C_LABEL(unpack_iter_dtor):
3421            zend_iterator_dtor(iter);
3422            break;
3423        }
3424        case IS_REFERENCE:
3425            args = Z_REFVAL_P(args);
3426            ZEND_VM_C_GOTO(send_again);
3427            break;
3428        default:
3429            zend_error(E_WARNING, "Only arrays and Traversables can be unpacked");
3430    }
3431
3432    FREE_OP1();
3433    CHECK_EXCEPTION();
3434    ZEND_VM_NEXT_OPCODE();
3435}
3436
3437ZEND_VM_HANDLER(119, ZEND_SEND_ARRAY, ANY, ANY)
3438{
3439    USE_OPLINE
3440    zend_free_op free_op1;
3441    zval *args;
3442    SAVE_OPLINE();
3443
3444    args = GET_OP1_ZVAL_PTR(BP_VAR_R);
3445
3446    if (UNEXPECTED(Z_TYPE_P(args) != IS_ARRAY)) {
3447        if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(args)) {
3448            args = Z_REFVAL_P(args);
3449            if (EXPECTED(Z_TYPE_P(args) == IS_ARRAY)) {
3450                ZEND_VM_C_GOTO(send_array);
3451            }
3452        }
3453        zend_error(E_WARNING, "call_user_func_array() expects parameter 2 to be array, %s given", zend_get_type_by_const(Z_TYPE_P(args)));
3454        if (EX(call)->func->common.fn_flags & ZEND_ACC_CLOSURE) {
3455            OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
3456        }
3457        if (Z_OBJ(EX(call)->This)) {
3458            OBJ_RELEASE(Z_OBJ(EX(call)->This));
3459        }
3460        EX(call)->func = (zend_function*)&zend_pass_function;
3461        EX(call)->called_scope = NULL;
3462        Z_OBJ(EX(call)->This) = NULL;
3463    } else {
3464        uint32_t arg_num;
3465        HashTable *ht;
3466        zval *arg, *param, tmp;
3467
3468ZEND_VM_C_LABEL(send_array):
3469        ht = Z_ARRVAL_P(args);
3470        zend_vm_stack_extend_call_frame(&EX(call), 0, zend_hash_num_elements(ht));
3471
3472        if (OP1_TYPE != IS_CONST && OP1_TYPE != IS_TMP_VAR && Z_IMMUTABLE_P(args)) {
3473            int separate = 0;
3474
3475            /* check if any of arguments are going to be passed by reference */
3476            for (arg_num = 0; arg_num < zend_hash_num_elements(ht); arg_num++) {
3477                if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num + 1)) {
3478                    separate = 1;
3479                    break;
3480                }
3481            }
3482            if (separate) {
3483                zval_copy_ctor(args);
3484                ht = Z_ARRVAL_P(args);
3485            }
3486        }
3487
3488        arg_num = 1;
3489        param = ZEND_CALL_ARG(EX(call), 1);
3490        ZEND_HASH_FOREACH_VAL(ht, arg) {
3491            if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
3492                // TODO: Scalar values don't have reference counters anymore.
3493                // They are assumed to be 1, and they may be easily passed by
3494                // reference now. However, previously scalars with refcount==1
3495                // might be passed and with refcount>1 might not. We can support
3496                // only single behavior ???
3497#if 0
3498                if (Z_REFCOUNTED_P(arg) &&
3499                    // This solution breaks the following test (omit warning message) ???
3500                    // Zend/tests/bug61273.phpt
3501                    // ext/reflection/tests/bug42976.phpt
3502                    // ext/standard/tests/general_functions/call_user_func_array_variation_001.phpt
3503#else
3504                if (!Z_REFCOUNTED_P(arg) ||
3505                    // This solution breaks the following test (emit warning message) ???
3506                    // ext/pdo_sqlite/tests/pdo_005.phpt
3507#endif
3508                    (!Z_ISREF_P(arg) && Z_REFCOUNT_P(arg) > 1)) {
3509
3510                    if (!ARG_MAY_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
3511
3512                        zend_error(E_WARNING, "Parameter %d to %s%s%s() expected to be a reference, value given",
3513                            arg_num,
3514                            EX(call)->func->common.scope ? EX(call)->func->common.scope->name->val : "",
3515                            EX(call)->func->common.scope ? "::" : "",
3516                            EX(call)->func->common.function_name->val);
3517
3518                        if (EX(call)->func->common.fn_flags & ZEND_ACC_CLOSURE) {
3519                            OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
3520                        }
3521                        if (Z_OBJ(EX(call)->This)) {
3522                            OBJ_RELEASE(Z_OBJ(EX(call)->This));
3523                        }
3524                        EX(call)->func = (zend_function*)&zend_pass_function;
3525                        EX(call)->called_scope = NULL;
3526                        Z_OBJ(EX(call)->This) = NULL;
3527
3528                        break;
3529                    }
3530
3531                    if (Z_REFCOUNTED_P(arg)) {
3532                        Z_DELREF_P(arg);
3533                    }
3534                    ZVAL_DUP(&tmp, arg);
3535                    ZVAL_NEW_REF(arg, &tmp);
3536                    Z_ADDREF_P(arg);
3537                } else if (!Z_ISREF_P(arg)) {
3538                    ZVAL_NEW_REF(arg, arg);
3539                    Z_ADDREF_P(arg);
3540                } else if (Z_REFCOUNTED_P(arg)) {
3541                    Z_ADDREF_P(arg);
3542                }
3543                ZVAL_COPY_VALUE(param, arg);
3544            } else if (Z_ISREF_P(arg) &&
3545                   /* don't separate references for __call */
3546                   (EX(call)->func->common.fn_flags & ZEND_ACC_CALL_VIA_HANDLER) == 0) {
3547                ZVAL_DUP(param, Z_REFVAL_P(arg));
3548            } else {
3549                ZVAL_COPY(param, arg);
3550            }
3551            ZEND_CALL_NUM_ARGS(EX(call))++;
3552            arg_num++;
3553            param++;
3554        } ZEND_HASH_FOREACH_END();
3555    }
3556    FREE_OP1();
3557    CHECK_EXCEPTION();
3558    ZEND_VM_NEXT_OPCODE();
3559}
3560
3561ZEND_VM_HANDLER(120, ZEND_SEND_USER, VAR|CV, ANY)
3562{
3563    USE_OPLINE
3564    zval *arg, *param, tmp;
3565    zend_free_op free_op1;
3566
3567    arg = GET_OP1_ZVAL_PTR(BP_VAR_R);
3568    param = ZEND_CALL_VAR(EX(call), opline->result.var);
3569
3570    if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3571        // TODO: Scalar values don't have reference counters anymore.
3572        // They are assumed to be 1, and they may be easily passed by
3573        // reference now. However, previously scalars with refcount==1
3574        // might be passed and with refcount>1 might not. We can support
3575        // only single behavior ???
3576#if 0
3577        if (Z_REFCOUNTED_P(arg) &&
3578            // This solution breaks the following test (omit warning message) ???
3579            // Zend/tests/bug61273.phpt
3580            // ext/reflection/tests/bug42976.phpt
3581            // ext/standard/tests/general_functions/call_user_func_array_variation_001.phpt
3582#else
3583        if (!Z_REFCOUNTED_P(arg) ||
3584            // This solution breaks the following test (emit warning message) ???
3585            // ext/pdo_sqlite/tests/pdo_005.phpt
3586#endif
3587            (!Z_ISREF_P(arg) /*&& Z_REFCOUNT_P(arg) > 1???*/)) {
3588
3589            if (!ARG_MAY_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3590
3591                zend_error(E_WARNING, "Parameter %d to %s%s%s() expected to be a reference, value given",
3592                    opline->op2.num,
3593                    EX(call)->func->common.scope ? EX(call)->func->common.scope->name->val : "",
3594                    EX(call)->func->common.scope ? "::" : "",
3595                    EX(call)->func->common.function_name->val);
3596
3597                if (EX(call)->func->common.fn_flags & ZEND_ACC_CLOSURE) {
3598                    OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
3599                }
3600                if (Z_OBJ(EX(call)->This)) {
3601                    OBJ_RELEASE(Z_OBJ(EX(call)->This));
3602                }
3603                EX(call)->func = (zend_function*)&zend_pass_function;
3604                EX(call)->called_scope = NULL;
3605                Z_OBJ(EX(call)->This) = NULL;
3606
3607                FREE_OP1();
3608                CHECK_EXCEPTION();
3609                ZEND_VM_NEXT_OPCODE();
3610            }
3611
3612            if (Z_REFCOUNTED_P(arg)) {
3613                Z_DELREF_P(arg);
3614            }
3615            ZVAL_DUP(&tmp, arg);
3616            ZVAL_NEW_REF(arg, &tmp);
3617            Z_ADDREF_P(arg);
3618        } else if (!Z_ISREF_P(arg)) {
3619            ZVAL_NEW_REF(arg, arg);
3620            Z_ADDREF_P(arg);
3621        } else if (Z_REFCOUNTED_P(arg)) {
3622            Z_ADDREF_P(arg);
3623        }
3624        ZVAL_COPY_VALUE(param, arg);
3625    } else if (Z_ISREF_P(arg) &&
3626               /* don't separate references for __call */
3627               (EX(call)->func->common.fn_flags & ZEND_ACC_CALL_VIA_HANDLER) == 0) {
3628        ZVAL_DUP(param, Z_REFVAL_P(arg));
3629    } else {
3630        ZVAL_COPY(param, arg);
3631    }
3632
3633    FREE_OP1();
3634    CHECK_EXCEPTION();
3635    ZEND_VM_NEXT_OPCODE();
3636}
3637
3638ZEND_VM_HANDLER(63, ZEND_RECV, ANY, ANY)
3639{
3640    USE_OPLINE
3641    uint32_t arg_num = opline->op1.num;
3642
3643    SAVE_OPLINE();
3644    if (UNEXPECTED(arg_num > EX_NUM_ARGS())) {
3645        zend_verify_missing_arg(execute_data, arg_num);
3646        CHECK_EXCEPTION();
3647    } else if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
3648        zval *param = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var);
3649
3650        zend_verify_arg_type(EX(func), arg_num, param, NULL);
3651        CHECK_EXCEPTION();
3652    }
3653
3654    ZEND_VM_NEXT_OPCODE();
3655}
3656
3657ZEND_VM_HANDLER(64, ZEND_RECV_INIT, ANY, CONST)
3658{
3659    USE_OPLINE
3660    uint32_t arg_num = opline->op1.num;
3661    zval *param;
3662
3663    SAVE_OPLINE();
3664    param = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var);
3665    if (arg_num > EX_NUM_ARGS()) {
3666        ZVAL_COPY_VALUE(param, EX_CONSTANT(opline->op2));
3667        if (Z_OPT_CONSTANT_P(param)) {
3668            zval_update_constant(param, 0);
3669        } else {
3670            /* IS_CONST can't be IS_OBJECT, IS_RESOURCE or IS_REFERENCE */
3671            if (UNEXPECTED(Z_OPT_COPYABLE_P(param))) {
3672                zval_copy_ctor_func(param);
3673            }
3674        }
3675    }
3676
3677    if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
3678        zend_verify_arg_type(EX(func), arg_num, param, EX_CONSTANT(opline->op2));
3679    }
3680
3681    CHECK_EXCEPTION();
3682    ZEND_VM_NEXT_OPCODE();
3683}
3684
3685ZEND_VM_HANDLER(164, ZEND_RECV_VARIADIC, ANY, ANY)
3686{
3687    USE_OPLINE
3688    uint32_t arg_num = opline->op1.num;
3689    uint32_t arg_count = EX_NUM_ARGS();
3690    zval *params;
3691
3692    SAVE_OPLINE();
3693
3694    params = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var);
3695
3696    if (arg_num <= arg_count) {
3697        zval *param;
3698
3699        array_init_size(params, arg_count - arg_num + 1);
3700        zend_hash_real_init(Z_ARRVAL_P(params), 1);
3701        ZEND_HASH_FILL_PACKED(Z_ARRVAL_P(params)) {
3702            param = EX_VAR_NUM(EX(func)->op_array.last_var + EX(func)->op_array.T);
3703            if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
3704                do {
3705                    zend_verify_arg_type(EX(func), arg_num, param, NULL);
3706                    if (Z_OPT_REFCOUNTED_P(param)) Z_ADDREF_P(param);
3707                    ZEND_HASH_FILL_ADD(param);
3708                    param++;
3709                } while (++arg_num <= arg_count);
3710            } else {
3711                do {
3712                    if (Z_OPT_REFCOUNTED_P(param)) Z_ADDREF_P(param);
3713                    ZEND_HASH_FILL_ADD(param);
3714                    param++;
3715                } while (++arg_num <= arg_count);
3716            }
3717        } ZEND_HASH_FILL_END();
3718    } else {
3719        array_init(params);
3720    }
3721
3722    CHECK_EXCEPTION();
3723    ZEND_VM_NEXT_OPCODE();
3724}
3725
3726ZEND_VM_HANDLER(52, ZEND_BOOL, CONST|TMPVAR|CV, ANY)
3727{
3728    USE_OPLINE
3729    zval *val;
3730    zend_free_op free_op1;
3731
3732    SAVE_OPLINE();
3733    val = GET_OP1_ZVAL_PTR(BP_VAR_R);
3734    if (Z_TYPE_P(val) == IS_TRUE) {
3735        ZVAL_TRUE(EX_VAR(opline->result.var));
3736    } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
3737        ZVAL_FALSE(EX_VAR(opline->result.var));
3738    } else {
3739        ZVAL_BOOL(EX_VAR(opline->result.var), i_zend_is_true(val));
3740        FREE_OP1();
3741        CHECK_EXCEPTION();
3742    }
3743    ZEND_VM_NEXT_OPCODE();
3744}
3745
3746ZEND_VM_HANDLER(50, ZEND_BRK, ANY, CONST)
3747{
3748    USE_OPLINE
3749    zend_brk_cont_element *el;
3750
3751    SAVE_OPLINE();
3752    el = zend_brk_cont(Z_LVAL_P(EX_CONSTANT(opline->op2)), opline->op1.opline_num,
3753                       &EX(func)->op_array, execute_data);
3754    ZEND_VM_JMP(EX(func)->op_array.opcodes + el->brk);
3755}
3756
3757ZEND_VM_HANDLER(51, ZEND_CONT, ANY, CONST)
3758{
3759    USE_OPLINE
3760    zend_brk_cont_element *el;
3761
3762    SAVE_OPLINE();
3763    el = zend_brk_cont(Z_LVAL_P(EX_CONSTANT(opline->op2)), opline->op1.opline_num,
3764                       &EX(func)->op_array, execute_data);
3765    ZEND_VM_JMP(EX(func)->op_array.opcodes + el->cont);
3766}
3767
3768ZEND_VM_HANDLER(100, ZEND_GOTO, ANY, CONST)
3769{
3770    zend_op *brk_opline;
3771    USE_OPLINE
3772    zend_brk_cont_element *el;
3773
3774    SAVE_OPLINE();
3775    el = zend_brk_cont(Z_LVAL_P(EX_CONSTANT(opline->op2)), opline->extended_value,
3776                       &EX(func)->op_array, execute_data);
3777
3778    brk_opline = EX(func)->op_array.opcodes + el->brk;
3779
3780    if (brk_opline->opcode == ZEND_FREE) {
3781        if (!(brk_opline->extended_value & EXT_TYPE_FREE_ON_RETURN)) {
3782            zval_ptr_dtor_nogc(EX_VAR(brk_opline->op1.var));
3783        }
3784    }
3785    ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op1));
3786}
3787
3788ZEND_VM_HANDLER(48, ZEND_CASE, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
3789{
3790    USE_OPLINE
3791    zend_free_op free_op1, free_op2;
3792    zval *result = EX_VAR(opline->result.var);
3793
3794    SAVE_OPLINE();
3795    fast_equal_function(result,
3796         GET_OP1_ZVAL_PTR(BP_VAR_R),
3797         GET_OP2_ZVAL_PTR(BP_VAR_R));
3798
3799    FREE_OP2();
3800    CHECK_EXCEPTION();
3801    ZEND_VM_NEXT_OPCODE();
3802}
3803
3804ZEND_VM_HANDLER(68, ZEND_NEW, CONST|VAR, ANY)
3805{
3806    USE_OPLINE
3807    zval object_zval;
3808    zend_function *constructor;
3809    zend_class_entry *ce;
3810
3811    SAVE_OPLINE();
3812    if (OP1_TYPE == IS_CONST) {
3813        if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)))) {
3814            ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
3815        } else {
3816            ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, 0);
3817            if (UNEXPECTED(ce == NULL)) {
3818                CHECK_EXCEPTION();
3819                ZEND_VM_NEXT_OPCODE();
3820            }
3821            CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce);
3822        }
3823    } else {
3824        ce = Z_CE_P(EX_VAR(opline->op1.var));
3825    }
3826    if (UNEXPECTED((ce->ce_flags & (ZEND_ACC_INTERFACE|ZEND_ACC_IMPLICIT_ABSTRACT_CLASS|ZEND_ACC_EXPLICIT_ABSTRACT_CLASS)) != 0)) {
3827        if (ce->ce_flags & ZEND_ACC_INTERFACE) {
3828            zend_error_noreturn(E_ERROR, "Cannot instantiate interface %s", ce->name->val);
3829        } else if ((ce->ce_flags & ZEND_ACC_TRAIT) == ZEND_ACC_TRAIT) {
3830            zend_error_noreturn(E_ERROR, "Cannot instantiate trait %s", ce->name->val);
3831        } else {
3832            zend_error_noreturn(E_ERROR, "Cannot instantiate abstract class %s", ce->name->val);
3833        }
3834    }
3835    object_init_ex(&object_zval, ce);
3836    constructor = Z_OBJ_HT(object_zval)->get_constructor(Z_OBJ(object_zval));
3837
3838    if (constructor == NULL) {
3839        if (EXPECTED(RETURN_VALUE_USED(opline))) {
3840            ZVAL_COPY_VALUE(EX_VAR(opline->result.var), &object_zval);
3841        } else {
3842            OBJ_RELEASE(Z_OBJ(object_zval));
3843        }
3844        ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
3845    } else {
3846        /* We are not handling overloaded classes right now */
3847        EX(call) = zend_vm_stack_push_call_frame(
3848                ZEND_CALL_FUNCTION | ZEND_CALL_CTOR |
3849                (EXPECTED(RETURN_VALUE_USED(opline)) ? 0 : ZEND_CALL_CTOR_RESULT_UNUSED),
3850            constructor,
3851            opline->extended_value,
3852            ce,
3853            Z_OBJ(object_zval),
3854            EX(call));
3855
3856        if (EXPECTED(RETURN_VALUE_USED(opline))) {
3857            ZVAL_COPY(EX_VAR(opline->result.var), &object_zval);
3858            EX(call)->return_value = EX_VAR(opline->result.var);
3859        } else {
3860            EX(call)->return_value = NULL;
3861        }
3862
3863        CHECK_EXCEPTION();
3864        ZEND_VM_NEXT_OPCODE();
3865    }
3866}
3867
3868ZEND_VM_HANDLER(110, ZEND_CLONE, CONST|TMPVAR|UNUSED|CV, ANY)
3869{
3870    USE_OPLINE
3871    zend_free_op free_op1;
3872    zval *obj;
3873    zend_class_entry *ce;
3874    zend_function *clone;
3875    zend_object_clone_obj_t clone_call;
3876
3877    SAVE_OPLINE();
3878    obj = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_R);
3879
3880    do {
3881        if (OP1_TYPE == IS_CONST ||
3882            (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(obj) != IS_OBJECT))) {
3883            if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(obj)) {
3884                obj = Z_REFVAL_P(obj);
3885                if (EXPECTED(Z_TYPE_P(obj) == IS_OBJECT)) {
3886                    break;
3887                }
3888            }
3889            if (UNEXPECTED(EG(exception) != NULL)) {
3890                HANDLE_EXCEPTION();
3891            }
3892            zend_error_noreturn(E_ERROR, "__clone method called on non-object");
3893        }
3894    } while (0);
3895
3896    ce = Z_OBJCE_P(obj);
3897    clone = ce ? ce->clone : NULL;
3898    clone_call =  Z_OBJ_HT_P(obj)->clone_obj;
3899    if (UNEXPECTED(clone_call == NULL)) {
3900        if (ce) {
3901            zend_error_noreturn(E_ERROR, "Trying to clone an uncloneable object of class %s", ce->name->val);
3902        } else {
3903            zend_error_noreturn(E_ERROR, "Trying to clone an uncloneable object");
3904        }
3905    }
3906
3907    if (ce && clone) {
3908        if (clone->op_array.fn_flags & ZEND_ACC_PRIVATE) {
3909            /* Ensure that if we're calling a private function, we're allowed to do so.
3910             */
3911            if (UNEXPECTED(ce != EG(scope))) {
3912                zend_error_noreturn(E_ERROR, "Call to private %s::__clone() from context '%s'", ce->name->val, EG(scope) ? EG(scope)->name->val : "");
3913            }
3914        } else if ((clone->common.fn_flags & ZEND_ACC_PROTECTED)) {
3915            /* Ensure that if we're calling a protected function, we're allowed to do so.
3916             */
3917            if (UNEXPECTED(!zend_check_protected(zend_get_function_root_class(clone), EG(scope)))) {
3918                zend_error_noreturn(E_ERROR, "Call to protected %s::__clone() from context '%s'", ce->name->val, EG(scope) ? EG(scope)->name->val : "");
3919            }
3920        }
3921    }
3922
3923    if (EXPECTED(EG(exception) == NULL)) {
3924        ZVAL_OBJ(EX_VAR(opline->result.var), clone_call(obj));
3925        if (UNEXPECTED(!RETURN_VALUE_USED(opline)) || UNEXPECTED(EG(exception) != NULL)) {
3926            OBJ_RELEASE(Z_OBJ_P(EX_VAR(opline->result.var)));
3927        }
3928    }
3929    FREE_OP1();
3930    CHECK_EXCEPTION();
3931    ZEND_VM_NEXT_OPCODE();
3932}
3933
3934ZEND_VM_HANDLER(99, ZEND_FETCH_CONSTANT, VAR|CONST|UNUSED, CONST)
3935{
3936    USE_OPLINE
3937
3938    SAVE_OPLINE();
3939    if (OP1_TYPE == IS_UNUSED) {
3940        zend_constant *c;
3941        zval *retval;
3942
3943        if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) {
3944            c = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
3945        } else if ((c = zend_quick_get_constant(EX_CONSTANT(opline->op2) + 1, opline->extended_value)) == NULL) {
3946            if ((opline->extended_value & IS_CONSTANT_UNQUALIFIED) != 0) {
3947                char *actual = (char *)zend_memrchr(Z_STRVAL_P(EX_CONSTANT(opline->op2)), '\\', Z_STRLEN_P(EX_CONSTANT(opline->op2)));
3948                if (!actual) {
3949                    ZVAL_STR(EX_VAR(opline->result.var), zend_string_copy(Z_STR_P(EX_CONSTANT(opline->op2))));
3950                } else {
3951                    actual++;
3952                    ZVAL_STRINGL(EX_VAR(opline->result.var),
3953                            actual, Z_STRLEN_P(EX_CONSTANT(opline->op2)) - (actual - Z_STRVAL_P(EX_CONSTANT(opline->op2))));
3954                }
3955                /* non-qualified constant - allow text substitution */
3956                zend_error(E_NOTICE, "Use of undefined constant %s - assumed '%s'",
3957                        Z_STRVAL_P(EX_VAR(opline->result.var)), Z_STRVAL_P(EX_VAR(opline->result.var)));
3958                CHECK_EXCEPTION();
3959                ZEND_VM_NEXT_OPCODE();
3960            } else {
3961                zend_error_noreturn(E_ERROR, "Undefined constant '%s'", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
3962            }
3963        } else {
3964            CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), c);
3965        }
3966        retval = EX_VAR(opline->result.var);
3967        ZVAL_COPY_VALUE(retval, &c->value);
3968        if (Z_OPT_COPYABLE_P(retval) || Z_OPT_REFCOUNTED_P(retval)) {
3969            if (Z_OPT_COPYABLE_P(retval)) {
3970                zval_copy_ctor_func(retval);
3971            } else {
3972                Z_ADDREF_P(retval);
3973            }
3974        }
3975    } else {
3976        /* class constant */
3977        zend_class_entry *ce;
3978        zval *value;
3979
3980        if (OP1_TYPE == IS_CONST) {
3981            if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) {
3982                value = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
3983                ZVAL_DEREF(value);
3984                ZVAL_DUP(EX_VAR(opline->result.var), value);
3985                ZEND_VM_C_GOTO(constant_fetch_end);
3986            } else if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)))) {
3987                ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
3988            } else {
3989                ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, 0);
3990                if (UNEXPECTED(EG(exception) != NULL)) {
3991                    HANDLE_EXCEPTION();
3992                }
3993                if (UNEXPECTED(ce == NULL)) {
3994                    zend_error_noreturn(E_ERROR, "Class '%s' not found", Z_STRVAL_P(EX_CONSTANT(opline->op1)));
3995                }
3996                CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce);
3997            }
3998        } else {
3999            ce = Z_CE_P(EX_VAR(opline->op1.var));
4000            if ((value = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce)) != NULL) {
4001                ZVAL_DEREF(value);
4002                ZVAL_DUP(EX_VAR(opline->result.var), value);
4003                ZEND_VM_C_GOTO(constant_fetch_end);
4004            }
4005        }
4006
4007        if (EXPECTED((value = zend_hash_find(&ce->constants_table, Z_STR_P(EX_CONSTANT(opline->op2)))) != NULL)) {
4008            ZVAL_DEREF(value);
4009            if (Z_CONSTANT_P(value)) {
4010                EG(scope) = ce;
4011                zval_update_constant(value, 1);
4012                EG(scope) = EX(func)->op_array.scope;
4013            }
4014            if (OP1_TYPE == IS_CONST) {
4015                CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), value);
4016            } else {
4017                CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce, value);
4018            }
4019            ZVAL_DUP(EX_VAR(opline->result.var), value);
4020        } else if (Z_STRLEN_P(EX_CONSTANT(opline->op2)) == sizeof("class")-1 && memcmp(Z_STRVAL_P(EX_CONSTANT(opline->op2)), "class", sizeof("class") - 1) == 0) {
4021            /* "class" is assigned as a case-sensitive keyword from zend_do_resolve_class_name */
4022            ZVAL_STR_COPY(EX_VAR(opline->result.var), ce->name);
4023        } else {
4024            zend_error_noreturn(E_ERROR, "Undefined class constant '%s'", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
4025        }
4026    }
4027ZEND_VM_C_LABEL(constant_fetch_end):
4028    CHECK_EXCEPTION();
4029    ZEND_VM_NEXT_OPCODE();
4030}
4031
4032ZEND_VM_HANDLER(72, ZEND_ADD_ARRAY_ELEMENT, CONST|TMP|VAR|CV, CONST|TMPVAR|UNUSED|CV)
4033{
4034    USE_OPLINE
4035    zend_free_op free_op1;
4036    zval *expr_ptr, new_expr;
4037
4038    SAVE_OPLINE();
4039    if ((OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) &&
4040        (opline->extended_value & ZEND_ARRAY_ELEMENT_REF)) {
4041        expr_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
4042        if (OP1_TYPE == IS_VAR && UNEXPECTED(expr_ptr == NULL)) {
4043            zend_error_noreturn(E_ERROR, "Cannot create references to/from string offsets");
4044        }
4045        ZVAL_MAKE_REF(expr_ptr);
4046        Z_ADDREF_P(expr_ptr);
4047        FREE_OP1_VAR_PTR();
4048    } else {
4049        expr_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
4050        if (OP1_TYPE == IS_TMP_VAR) {
4051            ZVAL_COPY_VALUE(&new_expr, expr_ptr);
4052            expr_ptr = &new_expr;
4053        } else if (OP1_TYPE == IS_CONST) {
4054            if (!Z_IMMUTABLE_P(expr_ptr)) {
4055                ZVAL_DUP(&new_expr, expr_ptr);
4056                expr_ptr = &new_expr;
4057            }
4058        } else if ((OP1_TYPE == IS_CV || OP1_TYPE == IS_VAR) && Z_ISREF_P(expr_ptr)) {
4059            expr_ptr = Z_REFVAL_P(expr_ptr);
4060            if (Z_REFCOUNTED_P(expr_ptr)) Z_ADDREF_P(expr_ptr);
4061            FREE_OP1_IF_VAR();
4062        } else if (OP1_TYPE == IS_CV && Z_REFCOUNTED_P(expr_ptr)) {
4063            Z_ADDREF_P(expr_ptr);
4064        }
4065    }
4066
4067    if (OP2_TYPE != IS_UNUSED) {
4068        zend_free_op free_op2;
4069        zval *offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
4070        zend_string *str;
4071        zend_ulong hval;
4072
4073ZEND_VM_C_LABEL(add_again):
4074        switch (Z_TYPE_P(offset)) {
4075            case IS_DOUBLE:
4076                hval = zend_dval_to_lval(Z_DVAL_P(offset));
4077                ZEND_VM_C_GOTO(num_index);
4078            case IS_LONG:
4079                hval = Z_LVAL_P(offset);
4080ZEND_VM_C_LABEL(num_index):
4081                zend_hash_index_update(Z_ARRVAL_P(EX_VAR(opline->result.var)), hval, expr_ptr);
4082                break;
4083            case IS_STRING:
4084                str = Z_STR_P(offset);
4085                if (OP2_TYPE != IS_CONST) {
4086                    if (ZEND_HANDLE_NUMERIC(str, hval)) {
4087                        ZEND_VM_C_GOTO(num_index);
4088                    }
4089                }
4090ZEND_VM_C_LABEL(str_index):
4091                zend_hash_update(Z_ARRVAL_P(EX_VAR(opline->result.var)), str, expr_ptr);
4092                break;
4093            case IS_NULL:
4094                str = STR_EMPTY_ALLOC();
4095                ZEND_VM_C_GOTO(str_index);
4096            case IS_FALSE:
4097                hval = 0;
4098                ZEND_VM_C_GOTO(num_index);
4099            case IS_TRUE:
4100                hval = 1;
4101                ZEND_VM_C_GOTO(num_index);
4102            case IS_REFERENCE:
4103                offset = Z_REFVAL_P(offset);
4104                ZEND_VM_C_GOTO(add_again);
4105                break;
4106            default:
4107                zend_error(E_WARNING, "Illegal offset type");
4108                zval_ptr_dtor(expr_ptr);
4109                /* do nothing */
4110                break;
4111        }
4112        FREE_OP2();
4113    } else {
4114        zend_hash_next_index_insert(Z_ARRVAL_P(EX_VAR(opline->result.var)), expr_ptr);
4115    }
4116    CHECK_EXCEPTION();
4117    ZEND_VM_NEXT_OPCODE();
4118}
4119
4120ZEND_VM_HANDLER(71, ZEND_INIT_ARRAY, CONST|TMP|VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
4121{
4122    zval *array;
4123    uint32_t size;
4124    USE_OPLINE
4125
4126    array = EX_VAR(opline->result.var);
4127    if (OP1_TYPE != IS_UNUSED) {
4128        size = opline->extended_value >> ZEND_ARRAY_SIZE_SHIFT;
4129    } else {
4130        size = 0;
4131    }
4132    ZVAL_NEW_ARR(array);
4133    zend_hash_init(Z_ARRVAL_P(array), size, NULL, ZVAL_PTR_DTOR, 0);
4134
4135    if (OP1_TYPE != IS_UNUSED) {
4136        /* Explicitly initialize array as not-packed if flag is set */
4137        if (opline->extended_value & ZEND_ARRAY_NOT_PACKED) {
4138            zend_hash_real_init(Z_ARRVAL_P(array), 0);
4139        }
4140    }
4141
4142    if (OP1_TYPE == IS_UNUSED) {
4143        ZEND_VM_NEXT_OPCODE();
4144#if !defined(ZEND_VM_SPEC) || OP1_TYPE != IS_UNUSED
4145    } else {
4146        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_ADD_ARRAY_ELEMENT);
4147#endif
4148    }
4149}
4150
4151ZEND_VM_HANDLER(21, ZEND_CAST, CONST|TMP|VAR|CV, ANY)
4152{
4153    USE_OPLINE
4154    zend_free_op free_op1;
4155    zval *expr;
4156    zval *result = EX_VAR(opline->result.var);
4157
4158    SAVE_OPLINE();
4159    expr = GET_OP1_ZVAL_PTR(BP_VAR_R);
4160
4161    switch (opline->extended_value) {
4162        case IS_NULL:
4163            /* This code is taken from convert_to_null. However, it does not seems very useful,
4164             * because a conversion to null always results in the same value. This could only
4165             * be relevant if a cast_object handler for IS_NULL has some kind of side-effect. */
4166#if 0
4167            if (OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) {
4168                ZVAL_DEREF(expr);
4169            }
4170            if (Z_TYPE_P(expr) == IS_OBJECT && Z_OBJ_HT_P(expr)->cast_object) {
4171                if (Z_OBJ_HT_P(expr)->cast_object(expr, result, IS_NULL) == SUCCESS) {
4172                    break;
4173                }
4174            }
4175#endif
4176
4177            ZVAL_NULL(result);
4178            break;
4179        case _IS_BOOL:
4180            ZVAL_BOOL(result, zend_is_true(expr));
4181            break;
4182        case IS_LONG:
4183            ZVAL_LONG(result, zval_get_long(expr));
4184            break;
4185        case IS_DOUBLE:
4186            ZVAL_DOUBLE(result, zval_get_double(expr));
4187            break;
4188        case IS_STRING:
4189            ZVAL_STR(result, zval_get_string(expr));
4190            break;
4191        default:
4192            if (OP1_TYPE & (IS_VAR|IS_CV)) {
4193                ZVAL_DEREF(expr);
4194            }
4195            /* If value is already of correct type, return it directly */
4196            if (Z_TYPE_P(expr) == opline->extended_value) {
4197                ZVAL_COPY_VALUE(result, expr);
4198                if (OP1_TYPE == IS_CONST) {
4199                    if (UNEXPECTED(Z_OPT_COPYABLE_P(result))) {
4200                        zval_copy_ctor_func(result);
4201                    }
4202                } else if (OP1_TYPE != IS_TMP_VAR) {
4203                    if (Z_OPT_REFCOUNTED_P(expr)) Z_ADDREF_P(expr);
4204                }
4205
4206                FREE_OP1_IF_VAR();
4207                CHECK_EXCEPTION();
4208                ZEND_VM_NEXT_OPCODE();
4209            }
4210
4211            if (opline->extended_value == IS_ARRAY) {
4212                if (Z_TYPE_P(expr) != IS_OBJECT) {
4213                    ZVAL_NEW_ARR(result);
4214                    zend_hash_init(Z_ARRVAL_P(result), 8, NULL, ZVAL_PTR_DTOR, 0);
4215                    if (Z_TYPE_P(expr) != IS_NULL) {
4216                        expr = zend_hash_index_add_new(Z_ARRVAL_P(result), 0, expr);
4217                        if (OP1_TYPE == IS_CONST) {
4218                            if (UNEXPECTED(Z_OPT_COPYABLE_P(expr))) {
4219                                zval_copy_ctor_func(expr);
4220                            }
4221                        } else {
4222                            if (Z_OPT_REFCOUNTED_P(expr)) Z_ADDREF_P(expr);
4223                        }
4224                    }
4225                } else {
4226                    ZVAL_COPY_VALUE(result, expr);
4227                    Z_ADDREF_P(result);
4228                    convert_to_array(result);
4229                }
4230            } else {
4231                if (Z_TYPE_P(expr) != IS_ARRAY) {
4232                    object_init(result);
4233                    if (Z_TYPE_P(expr) != IS_NULL) {
4234                        expr = zend_hash_str_add_new(Z_OBJPROP_P(result), "scalar", sizeof("scalar")-1, expr);
4235                        if (OP1_TYPE == IS_CONST) {
4236                            if (UNEXPECTED(Z_OPT_COPYABLE_P(expr))) {
4237                                zval_copy_ctor_func(expr);
4238                            }
4239                        } else {
4240                            if (Z_OPT_REFCOUNTED_P(expr)) Z_ADDREF_P(expr);
4241                        }
4242                    }
4243                } else {
4244                    ZVAL_COPY_VALUE(result, expr);
4245                    zval_opt_copy_ctor(result);
4246                    convert_to_object(result);
4247                }
4248            }
4249    }
4250
4251    FREE_OP1();
4252    CHECK_EXCEPTION();
4253    ZEND_VM_NEXT_OPCODE();
4254}
4255
4256ZEND_VM_HANDLER(73, ZEND_INCLUDE_OR_EVAL, CONST|TMPVAR|CV, ANY)
4257{
4258    USE_OPLINE
4259    zend_op_array *new_op_array=NULL;
4260    zend_free_op free_op1;
4261    zval *inc_filename;
4262    zval tmp_inc_filename;
4263    zend_bool failure_retval=0;
4264
4265    SAVE_OPLINE();
4266    inc_filename = GET_OP1_ZVAL_PTR(BP_VAR_R);
4267
4268    ZVAL_UNDEF(&tmp_inc_filename);
4269    if (Z_TYPE_P(inc_filename) != IS_STRING) {
4270        ZVAL_STR(&tmp_inc_filename, zval_get_string(inc_filename));
4271        inc_filename = &tmp_inc_filename;
4272    }
4273
4274    if (opline->extended_value != ZEND_EVAL && strlen(Z_STRVAL_P(inc_filename)) != Z_STRLEN_P(inc_filename)) {
4275        if (opline->extended_value == ZEND_INCLUDE_ONCE || opline->extended_value == ZEND_INCLUDE) {
4276            zend_message_dispatcher(ZMSG_FAILED_INCLUDE_FOPEN, Z_STRVAL_P(inc_filename));
4277        } else {
4278            zend_message_dispatcher(ZMSG_FAILED_REQUIRE_FOPEN, Z_STRVAL_P(inc_filename));
4279        }
4280    } else {
4281        switch (opline->extended_value) {
4282            case ZEND_INCLUDE_ONCE:
4283            case ZEND_REQUIRE_ONCE: {
4284                    zend_file_handle file_handle;
4285                    char *resolved_path;
4286
4287                    resolved_path = zend_resolve_path(Z_STRVAL_P(inc_filename), (int)Z_STRLEN_P(inc_filename));
4288                    if (resolved_path) {
4289                        failure_retval = zend_hash_str_exists(&EG(included_files), resolved_path, (int)strlen(resolved_path));
4290                    } else {
4291                        resolved_path = Z_STRVAL_P(inc_filename);
4292                    }
4293
4294                    if (failure_retval) {
4295                        /* do nothing, file already included */
4296                    } else if (SUCCESS == zend_stream_open(resolved_path, &file_handle)) {
4297
4298                        if (!file_handle.opened_path) {
4299                            file_handle.opened_path = estrdup(resolved_path);
4300                        }
4301
4302                        if (zend_hash_str_add_empty_element(&EG(included_files), file_handle.opened_path, (int)strlen(file_handle.opened_path))) {
4303                            new_op_array = zend_compile_file(&file_handle, (opline->extended_value==ZEND_INCLUDE_ONCE?ZEND_INCLUDE:ZEND_REQUIRE));
4304                            zend_destroy_file_handle(&file_handle);
4305                        } else {
4306                            zend_file_handle_dtor(&file_handle);
4307                            failure_retval=1;
4308                        }
4309                    } else {
4310                        if (opline->extended_value == ZEND_INCLUDE_ONCE) {
4311                            zend_message_dispatcher(ZMSG_FAILED_INCLUDE_FOPEN, Z_STRVAL_P(inc_filename));
4312                        } else {
4313                            zend_message_dispatcher(ZMSG_FAILED_REQUIRE_FOPEN, Z_STRVAL_P(inc_filename));
4314                        }
4315                    }
4316                    if (resolved_path != Z_STRVAL_P(inc_filename)) {
4317                        efree(resolved_path);
4318                    }
4319                }
4320                break;
4321            case ZEND_INCLUDE:
4322            case ZEND_REQUIRE:
4323                new_op_array = compile_filename(opline->extended_value, inc_filename);
4324                break;
4325            case ZEND_EVAL: {
4326                    char *eval_desc = zend_make_compiled_string_description("eval()'d code");
4327
4328                    new_op_array = zend_compile_string(inc_filename, eval_desc);
4329                    efree(eval_desc);
4330                }
4331                break;
4332            EMPTY_SWITCH_DEFAULT_CASE()
4333        }
4334    }
4335    if (Z_TYPE(tmp_inc_filename) != IS_UNDEF) {
4336        zend_string_release(Z_STR(tmp_inc_filename));
4337    }
4338    FREE_OP1();
4339    if (UNEXPECTED(EG(exception) != NULL)) {
4340        HANDLE_EXCEPTION();
4341    } else if (EXPECTED(new_op_array != NULL)) {
4342        zval *return_value = NULL;
4343        zend_execute_data *call;
4344
4345        if (RETURN_VALUE_USED(opline)) {
4346            return_value = EX_VAR(opline->result.var);
4347        }
4348
4349        new_op_array->scope = EG(scope); /* ??? */
4350
4351        call = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_CODE,
4352            (zend_function*)new_op_array, 0, EX(called_scope), Z_OBJ(EX(This)), NULL);
4353
4354        if (EX(symbol_table)) {
4355            call->symbol_table = EX(symbol_table);
4356        } else {
4357            call->symbol_table = zend_rebuild_symbol_table();
4358        }
4359
4360        call->prev_execute_data = execute_data;
4361        i_init_code_execute_data(call, new_op_array, return_value);
4362        if (EXPECTED(zend_execute_ex == execute_ex)) {
4363            ZEND_VM_ENTER();
4364        } else {
4365            ZEND_ADD_CALL_FLAG(call, ZEND_CALL_TOP);
4366            zend_execute_ex(call);
4367        }
4368
4369        destroy_op_array(new_op_array);
4370        efree_size(new_op_array, sizeof(zend_op_array));
4371        if (UNEXPECTED(EG(exception) != NULL)) {
4372            zend_throw_exception_internal(NULL);
4373            HANDLE_EXCEPTION();
4374        }
4375
4376    } else if (RETURN_VALUE_USED(opline)) {
4377        ZVAL_BOOL(EX_VAR(opline->result.var), failure_retval);
4378    }
4379    ZEND_VM_NEXT_OPCODE();
4380}
4381
4382ZEND_VM_HANDLER(74, ZEND_UNSET_VAR, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
4383{
4384    USE_OPLINE
4385    zval tmp, *varname;
4386    HashTable *target_symbol_table;
4387    zend_free_op free_op1;
4388
4389    SAVE_OPLINE();
4390    if (OP1_TYPE == IS_CV &&
4391        OP2_TYPE == IS_UNUSED &&
4392        (opline->extended_value & ZEND_QUICK_SET)) {
4393        zval *var = EX_VAR(opline->op1.var);
4394
4395        if (Z_REFCOUNTED_P(var)) {
4396            zend_refcounted *garbage = Z_COUNTED_P(var);
4397
4398            if (!--GC_REFCOUNT(garbage)) {
4399                ZVAL_UNDEF(var);
4400                _zval_dtor_func_for_ptr(garbage ZEND_FILE_LINE_CC);
4401            } else {
4402                GC_ZVAL_CHECK_POSSIBLE_ROOT(var);
4403                ZVAL_UNDEF(var);
4404            }
4405        } else {
4406            ZVAL_UNDEF(var);
4407        }
4408        CHECK_EXCEPTION();
4409        ZEND_VM_NEXT_OPCODE();
4410    }
4411
4412    varname = GET_OP1_ZVAL_PTR(BP_VAR_R);
4413
4414    ZVAL_UNDEF(&tmp);
4415    if (OP1_TYPE != IS_CONST && Z_TYPE_P(varname) != IS_STRING) {
4416        ZVAL_STR(&tmp, zval_get_string(varname));
4417        varname = &tmp;
4418    }
4419
4420    if (OP2_TYPE != IS_UNUSED) {
4421        zend_class_entry *ce;
4422
4423        if (OP2_TYPE == IS_CONST) {
4424            if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) {
4425                ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
4426            } else {
4427                ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op2)), EX_CONSTANT(opline->op2) + 1, 0);
4428                if (UNEXPECTED(EG(exception) != NULL)) {
4429                    if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
4430                        zend_string_release(Z_STR(tmp));
4431                    }
4432                    FREE_OP1();
4433                    HANDLE_EXCEPTION();
4434                }
4435                if (UNEXPECTED(ce == NULL)) {
4436                    zend_error_noreturn(E_ERROR, "Class '%s' not found", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
4437                }
4438                CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce);
4439            }
4440        } else {
4441            ce = Z_CE_P(EX_VAR(opline->op2.var));
4442        }
4443        zend_std_unset_static_property(ce, Z_STR_P(varname), ((OP1_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(varname)) : NULL));
4444    } else {
4445        target_symbol_table = zend_get_target_symbol_table(execute_data, opline->extended_value & ZEND_FETCH_TYPE_MASK);
4446        zend_hash_del_ind(target_symbol_table, Z_STR_P(varname));
4447    }
4448
4449    if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
4450        zend_string_release(Z_STR(tmp));
4451    }
4452    FREE_OP1();
4453    CHECK_EXCEPTION();
4454    ZEND_VM_NEXT_OPCODE();
4455}
4456
4457ZEND_VM_HANDLER(75, ZEND_UNSET_DIM, VAR|UNUSED|CV, CONST|TMPVAR|CV)
4458{
4459    USE_OPLINE
4460    zend_free_op free_op1, free_op2;
4461    zval *container;
4462    zval *offset;
4463    zend_ulong hval;
4464
4465    SAVE_OPLINE();
4466    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_UNSET);
4467    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
4468        zend_error_noreturn(E_ERROR, "Cannot unset string offsets");
4469    }
4470    offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
4471
4472ZEND_VM_C_LABEL(unset_dim_again):
4473    if (OP1_TYPE != IS_UNUSED && EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
4474        HashTable *ht;
4475
4476ZEND_VM_C_LABEL(offset_again):
4477        SEPARATE_ARRAY(container);
4478        ht = Z_ARRVAL_P(container);
4479        switch (Z_TYPE_P(offset)) {
4480            case IS_DOUBLE:
4481                hval = zend_dval_to_lval(Z_DVAL_P(offset));
4482                zend_hash_index_del(ht, hval);
4483                break;
4484            case IS_LONG:
4485                hval = Z_LVAL_P(offset);
4486ZEND_VM_C_LABEL(num_index_dim):
4487                zend_hash_index_del(ht, hval);
4488                break;
4489            case IS_STRING:
4490                if (OP2_TYPE != IS_CONST) {
4491                    if (ZEND_HANDLE_NUMERIC(Z_STR_P(offset), hval)) {
4492                        ZEND_VM_C_GOTO(num_index_dim);
4493                    }
4494                }
4495                if (ht == &EG(symbol_table).ht) {
4496                    zend_delete_global_variable(Z_STR_P(offset));
4497                } else {
4498                    zend_hash_del(ht, Z_STR_P(offset));
4499                }
4500                break;
4501            case IS_NULL:
4502                zend_hash_del(ht, STR_EMPTY_ALLOC());
4503                break;
4504            case IS_FALSE:
4505                hval = 0;
4506                ZEND_VM_C_GOTO(num_index_dim);
4507            case IS_TRUE:
4508                hval = 1;
4509                ZEND_VM_C_GOTO(num_index_dim);
4510            case IS_RESOURCE:
4511                hval = Z_RES_HANDLE_P(offset);
4512                ZEND_VM_C_GOTO(num_index_dim);
4513            case IS_REFERENCE:
4514                offset = Z_REFVAL_P(offset);
4515                ZEND_VM_C_GOTO(offset_again);
4516                break;
4517            default:
4518                zend_error(E_WARNING, "Illegal offset type in unset");
4519                break;
4520        }
4521        FREE_OP2();
4522    } else if (OP1_TYPE == IS_UNUSED || EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
4523        if (UNEXPECTED(Z_OBJ_HT_P(container)->unset_dimension == NULL)) {
4524            zend_error_noreturn(E_ERROR, "Cannot use object as array");
4525        }
4526//???       if (OP2_TYPE == IS_CONST) {
4527//???           zval_copy_ctor(offset);
4528//???       }
4529        Z_OBJ_HT_P(container)->unset_dimension(container, offset);
4530        FREE_OP2();
4531    } else if (OP1_TYPE != IS_UNUSED && Z_ISREF_P(container)) {
4532        container = Z_REFVAL_P(container);
4533        ZEND_VM_C_GOTO(unset_dim_again);
4534    } else if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) == IS_STRING)) {
4535        zend_error_noreturn(E_ERROR, "Cannot unset string offsets");
4536        ZEND_VM_CONTINUE(); /* bailed out before */
4537    } else {
4538        FREE_OP2();
4539    }
4540    FREE_OP1_VAR_PTR();
4541    CHECK_EXCEPTION();
4542    ZEND_VM_NEXT_OPCODE();
4543}
4544
4545ZEND_VM_HANDLER(76, ZEND_UNSET_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
4546{
4547    USE_OPLINE
4548    zend_free_op free_op1, free_op2;
4549    zval *container;
4550    zval *offset;
4551
4552    SAVE_OPLINE();
4553    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_UNSET);
4554    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
4555        zend_error_noreturn(E_ERROR, "Cannot unset string offsets");
4556    }
4557    offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
4558
4559    do {
4560        if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
4561            if (Z_ISREF_P(container)) {
4562                container = Z_REFVAL_P(container);
4563                if (Z_TYPE_P(container) != IS_OBJECT) {
4564                    break;
4565                }
4566            } else {
4567                break;
4568            }
4569        }
4570        if (Z_OBJ_HT_P(container)->unset_property) {
4571            Z_OBJ_HT_P(container)->unset_property(container, offset, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(offset)) : NULL));
4572        } else {
4573            zend_error(E_NOTICE, "Trying to unset property of non-object");
4574        }
4575    } while (0);
4576
4577    FREE_OP2();
4578    FREE_OP1_VAR_PTR();
4579    CHECK_EXCEPTION();
4580    ZEND_VM_NEXT_OPCODE();
4581}
4582
4583ZEND_VM_HANDLER(77, ZEND_FE_RESET, CONST|TMP|VAR|CV, ANY)
4584{
4585    USE_OPLINE
4586    zend_free_op free_op1;
4587    zval *array_ptr, *array_ref, iterator, tmp;
4588    HashTable *fe_ht;
4589    zend_object_iterator *iter = NULL;
4590    zend_class_entry *ce = NULL;
4591    zend_bool is_empty = 0;
4592
4593    SAVE_OPLINE();
4594
4595    if ((OP1_TYPE == IS_CV || OP1_TYPE == IS_VAR) &&
4596        (opline->extended_value & ZEND_FE_FETCH_BYREF)) {
4597        array_ptr = array_ref = GET_OP1_ZVAL_PTR_PTR(BP_VAR_R);
4598        ZVAL_DEREF(array_ptr);
4599        if (Z_TYPE_P(array_ptr) == IS_ARRAY) {
4600            SEPARATE_ARRAY(array_ptr);
4601            if (!Z_ISREF_P(array_ref)) {
4602                ZVAL_NEW_REF(array_ref, array_ref);
4603                array_ptr = Z_REFVAL_P(array_ref);
4604            }
4605            if (Z_REFCOUNTED_P(array_ref)) Z_ADDREF_P(array_ref);
4606        } else if (Z_TYPE_P(array_ptr) == IS_OBJECT) {
4607            ce = Z_OBJCE_P(array_ptr);
4608            if (ce->get_iterator == NULL) {
4609                Z_ADDREF_P(array_ptr);
4610            }
4611            array_ref = array_ptr;
4612        } else {
4613            if (Z_REFCOUNTED_P(array_ref)) Z_ADDREF_P(array_ref);
4614        }
4615    } else {
4616        array_ptr = array_ref = GET_OP1_ZVAL_PTR(BP_VAR_R);
4617        if (OP1_TYPE & (IS_VAR|IS_CV)) {
4618            ZVAL_DEREF(array_ptr);
4619        }
4620        if (OP1_TYPE == IS_TMP_VAR) {
4621            ZVAL_COPY_VALUE(&tmp, array_ptr);
4622            if (Z_OPT_IMMUTABLE_P(&tmp)) {
4623                zval_copy_ctor_func(&tmp);
4624            }
4625            array_ref = array_ptr = &tmp;
4626            if (Z_TYPE_P(array_ptr) == IS_OBJECT) {
4627                ce = Z_OBJCE_P(array_ptr);
4628                if (ce && ce->get_iterator) {
4629                    Z_DELREF_P(array_ref);
4630                }
4631            }
4632        } else if (Z_TYPE_P(array_ptr) == IS_OBJECT) {
4633            ce = Z_OBJCE_P(array_ptr);
4634            if (!ce->get_iterator) {
4635                if (OP1_TYPE == IS_CV) {
4636                    Z_ADDREF_P(array_ref);
4637                }
4638            }
4639        } else if (Z_IMMUTABLE_P(array_ref)) {
4640            if (OP1_TYPE == IS_CV) {
4641                zval_copy_ctor_func(array_ref);
4642                Z_ADDREF_P(array_ref);
4643            } else {
4644                ZVAL_COPY_VALUE(&tmp, array_ref);
4645                zval_copy_ctor_func(&tmp);
4646                array_ptr = array_ref = &tmp;
4647            }
4648        } else if (Z_REFCOUNTED_P(array_ref)) {
4649            if (OP1_TYPE == IS_CONST ||
4650                       (OP1_TYPE == IS_CV &&
4651                        !Z_ISREF_P(array_ref) &&
4652                        Z_REFCOUNT_P(array_ref) > 1) ||
4653                       (OP1_TYPE == IS_VAR &&
4654                        !Z_ISREF_P(array_ref) &&
4655                        Z_REFCOUNT_P(array_ref) > 2)) {
4656                if (OP1_TYPE == IS_VAR) {
4657                    Z_DELREF_P(array_ref);
4658                }
4659                ZVAL_DUP(&tmp, array_ref);
4660                array_ptr = array_ref = &tmp;
4661            } else if (OP1_TYPE == IS_CV || OP1_TYPE == IS_VAR) {
4662                if (Z_ISREF_P(array_ref) && Z_REFCOUNT_P(array_ref) == 1) {
4663                    ZVAL_UNREF(array_ref);
4664                    array_ptr = array_ref;
4665                }
4666                if (Z_IMMUTABLE_P(array_ptr)) {
4667                    zval_copy_ctor_func(array_ptr);
4668                } else if (Z_ISREF_P(array_ref) &&
4669                           Z_COPYABLE_P(array_ptr) &&
4670                           Z_REFCOUNT_P(array_ptr) > 1) {
4671                    Z_DELREF_P(array_ptr);
4672                    zval_copy_ctor_func(array_ptr);
4673                }
4674                if (OP1_TYPE == IS_CV) {
4675                    Z_ADDREF_P(array_ref);
4676                }
4677            }
4678        }
4679    }
4680
4681    if (ce && ce->get_iterator) {
4682        iter = ce->get_iterator(ce, array_ptr, opline->extended_value & ZEND_FE_FETCH_BYREF);
4683
4684        if (OP1_TYPE == IS_VAR && !(opline->extended_value & ZEND_FE_FETCH_BYREF)) {
4685            FREE_OP1_IF_VAR();
4686        }
4687        if (iter && EXPECTED(EG(exception) == NULL)) {
4688            ZVAL_OBJ(&iterator, &iter->std);
4689            array_ptr = array_ref = &iterator;
4690        } else {
4691            if (OP1_TYPE == IS_VAR && opline->extended_value & ZEND_FE_FETCH_BYREF) {
4692                FREE_OP1_VAR_PTR();
4693            }
4694            if (!EG(exception)) {
4695                zend_throw_exception_ex(NULL, 0, "Object of type %s did not create an Iterator", ce->name->val);
4696            }
4697            zend_throw_exception_internal(NULL);
4698            HANDLE_EXCEPTION();
4699        }
4700    }
4701
4702    ZVAL_COPY_VALUE(EX_VAR(opline->result.var), array_ref);
4703
4704    if (iter) {
4705        iter->index = 0;
4706        if (iter->funcs->rewind) {
4707            iter->funcs->rewind(iter);
4708            if (UNEXPECTED(EG(exception) != NULL)) {
4709                zval_ptr_dtor(array_ref);
4710                if (OP1_TYPE == IS_VAR && opline->extended_value & ZEND_FE_FETCH_BYREF) {
4711                    FREE_OP1_VAR_PTR();
4712                }
4713                HANDLE_EXCEPTION();
4714            }
4715        }
4716        is_empty = iter->funcs->valid(iter) != SUCCESS;
4717        if (UNEXPECTED(EG(exception) != NULL)) {
4718            zval_ptr_dtor(array_ref);
4719            if (OP1_TYPE == IS_VAR && opline->extended_value & ZEND_FE_FETCH_BYREF) {
4720                FREE_OP1_VAR_PTR();
4721            }
4722            HANDLE_EXCEPTION();
4723        }
4724        iter->index = -1; /* will be set to 0 before using next handler */
4725    } else if ((fe_ht = HASH_OF(array_ptr)) != NULL) {
4726        HashPointer *ptr = (HashPointer*)EX_VAR((opline+2)->op1.var);
4727        HashPosition pos = 0;
4728        Bucket *p;
4729
4730        while (1) {
4731            if (pos >= fe_ht->nNumUsed) {
4732                is_empty = 1;
4733                if (OP1_TYPE == IS_VAR && opline->extended_value & ZEND_FE_FETCH_BYREF) {
4734                    FREE_OP1_VAR_PTR();
4735                }
4736                ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
4737            }
4738            p = fe_ht->arData + pos;
4739            if (Z_TYPE(p->val) == IS_UNDEF ||
4740                (Z_TYPE(p->val) == IS_INDIRECT &&
4741                 Z_TYPE_P(Z_INDIRECT(p->val)) == IS_UNDEF)) {
4742                pos++;
4743                continue;
4744            }
4745            if (!ce ||
4746                !p->key ||
4747                zend_check_property_access(Z_OBJ_P(array_ptr), p->key) == SUCCESS) {
4748                break;
4749            }
4750            pos++;
4751        }
4752        fe_ht->nInternalPointer = pos;
4753        ptr->pos = pos;
4754        ptr->ht = fe_ht;
4755        ptr->h = fe_ht->arData[pos].h;
4756        ptr->key = fe_ht->arData[pos].key;
4757        is_empty = 0;
4758    } else {
4759        zend_error(E_WARNING, "Invalid argument supplied for foreach()");
4760        is_empty = 1;
4761    }
4762
4763    if (OP1_TYPE == IS_VAR && opline->extended_value & ZEND_FE_FETCH_BYREF) {
4764        FREE_OP1_VAR_PTR();
4765    }
4766    if (is_empty) {
4767        ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
4768    } else {
4769        CHECK_EXCEPTION();
4770        ZEND_VM_NEXT_OPCODE();
4771    }
4772}
4773
4774ZEND_VM_HANDLER(78, ZEND_FE_FETCH, VAR, ANY)
4775{
4776    USE_OPLINE
4777    zend_free_op free_op1;
4778    zval *array, *array_ref;
4779    zval *value;
4780    HashTable *fe_ht;
4781    HashPointer *ptr;
4782    HashPosition pos;
4783    Bucket *p;
4784
4785    array = array_ref = EX_VAR(opline->op1.var);
4786    if (Z_ISREF_P(array)) {
4787        array = Z_REFVAL_P(array);
4788        // TODO: referenced value might be changed to different array ???
4789        if (Z_IMMUTABLE_P(array)) {
4790            zval_copy_ctor_func(array);
4791        }
4792    }
4793
4794    SAVE_OPLINE();
4795
4796    if (EXPECTED(Z_TYPE_P(array) == IS_ARRAY)) {
4797        fe_ht = Z_ARRVAL_P(array);
4798        ptr = (HashPointer*)EX_VAR((opline+1)->op1.var);
4799        pos = ptr->pos;
4800        if (UNEXPECTED(pos == INVALID_IDX)) {
4801            /* reached end of iteration */
4802            ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
4803        } else if (UNEXPECTED(ptr->ht != fe_ht)) {
4804            ptr->ht = fe_ht;
4805            pos = 0;
4806        } else if (UNEXPECTED(fe_ht->nInternalPointer != ptr->pos)) {
4807            if (fe_ht->u.flags & HASH_FLAG_PACKED) {
4808                pos = ptr->h;
4809            } else {
4810                pos = fe_ht->arHash[ptr->h & fe_ht->nTableMask];
4811                while (1) {
4812                    if (pos == INVALID_IDX) {
4813                        pos = fe_ht->nInternalPointer;
4814                        break;
4815                    } else if (fe_ht->arData[pos].h == ptr->h && fe_ht->arData[pos].key == ptr->key) {
4816                        break;
4817                    }
4818                    pos = Z_NEXT(fe_ht->arData[pos].val);
4819                }
4820            }
4821        }
4822        while (1) {
4823            if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
4824                /* reached end of iteration */
4825                ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
4826            }
4827            p = fe_ht->arData + pos;
4828            value = &p->val;
4829            if (UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
4830                pos++;
4831                continue;
4832            } else if (UNEXPECTED(Z_TYPE_P(value) == IS_INDIRECT)) {
4833                value = Z_INDIRECT_P(value);
4834                if (UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
4835                    pos++;
4836                    continue;
4837                }
4838            }
4839            if (opline->extended_value & ZEND_FE_FETCH_BYREF) {
4840                ZVAL_MAKE_REF(value);
4841                Z_ADDREF_P(value);
4842                ZVAL_REF(EX_VAR(opline->result.var), Z_REF_P(value));
4843            } else {
4844                ZVAL_COPY(EX_VAR(opline->result.var), value);
4845            }
4846            if (opline->extended_value & ZEND_FE_FETCH_WITH_KEY) {
4847                if (!p->key) {
4848                    ZVAL_LONG(EX_VAR((opline+1)->result.var), p->h);
4849                } else {
4850                    ZVAL_STR_COPY(EX_VAR((opline+1)->result.var), p->key);
4851                }
4852            }
4853            break;
4854        }
4855        do {
4856            pos++;
4857            if (pos >= fe_ht->nNumUsed) {
4858                fe_ht->nInternalPointer = ptr->pos = INVALID_IDX;
4859                ZEND_VM_INC_OPCODE();
4860                ZEND_VM_NEXT_OPCODE();
4861            }
4862            p = fe_ht->arData + pos;
4863        } while (Z_TYPE(p->val) == IS_UNDEF ||
4864                 (Z_TYPE(p->val) == IS_INDIRECT &&
4865                  Z_TYPE_P(Z_INDIRECT(p->val)) == IS_UNDEF));
4866        fe_ht->nInternalPointer = ptr->pos = pos;
4867        ptr->h = fe_ht->arData[pos].h;
4868        ptr->key = fe_ht->arData[pos].key;
4869        ZEND_VM_INC_OPCODE();
4870        ZEND_VM_NEXT_OPCODE();
4871    } else if (EXPECTED(Z_TYPE_P(array) == IS_OBJECT)) {
4872        zend_object_iterator *iter;
4873
4874        if ((iter = zend_iterator_unwrap(array)) == NULL) {
4875            /* plain object */
4876            zend_object *zobj = Z_OBJ_P(array);
4877
4878            fe_ht = Z_OBJPROP_P(array);
4879            ptr = (HashPointer*)EX_VAR((opline+1)->op1.var);
4880            pos = ptr->pos;
4881            if (pos == INVALID_IDX) {
4882                /* reached end of iteration */
4883                ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
4884            } else if (UNEXPECTED(ptr->ht != fe_ht)) {
4885                ptr->ht = fe_ht;
4886                pos = 0;
4887            } else if (UNEXPECTED(fe_ht->nInternalPointer != ptr->pos)) {
4888                if (fe_ht->u.flags & HASH_FLAG_PACKED) {
4889                    pos = ptr->h;
4890                } else {
4891                    pos = fe_ht->arHash[ptr->h & fe_ht->nTableMask];
4892                    while (1) {
4893                        if (pos == INVALID_IDX) {
4894                            pos = fe_ht->nInternalPointer;
4895                            break;
4896                        } else if (fe_ht->arData[pos].h == ptr->h && fe_ht->arData[pos].key == ptr->key) {
4897                            break;
4898                        }
4899                        pos = Z_NEXT(fe_ht->arData[pos].val);
4900                    }
4901                }
4902            }
4903            while (1) {
4904                if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
4905                    /* reached end of iteration */
4906                    ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
4907                }
4908
4909                p = fe_ht->arData + pos;
4910                value = &p->val;
4911                if (UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
4912                    pos++;
4913                    continue;
4914                } else if (UNEXPECTED(Z_TYPE_P(value) == IS_INDIRECT)) {
4915                    value = Z_INDIRECT_P(value);
4916                    if (UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
4917                        pos++;
4918                        continue;
4919                    }
4920                }
4921
4922                if (UNEXPECTED(!p->key)) {
4923                    if (opline->extended_value & ZEND_FE_FETCH_WITH_KEY) {
4924                        ZVAL_LONG(EX_VAR((opline+1)->result.var), p->h);
4925                    }
4926                    break;
4927                } else if (zend_check_property_access(zobj, p->key) == SUCCESS) {
4928                    if (opline->extended_value & ZEND_FE_FETCH_WITH_KEY) {
4929                        if (p->key->val[0]) {
4930                            ZVAL_STR_COPY(EX_VAR((opline+1)->result.var), p->key);
4931                        } else {
4932                            const char *class_name, *prop_name;
4933                            size_t prop_name_len;
4934                            zend_unmangle_property_name_ex(
4935                                p->key, &class_name, &prop_name, &prop_name_len);
4936                            ZVAL_STRINGL(EX_VAR((opline+1)->result.var), prop_name, prop_name_len);
4937                        }
4938                    }
4939                    break;
4940                }
4941                pos++;
4942            }
4943            if (opline->extended_value & ZEND_FE_FETCH_BYREF) {
4944                ZVAL_MAKE_REF(value);
4945                Z_ADDREF_P(value);
4946                ZVAL_REF(EX_VAR(opline->result.var), Z_REF_P(value));
4947            } else {
4948                ZVAL_COPY(EX_VAR(opline->result.var), value);
4949            }
4950            do {
4951                pos++;
4952                if (pos >= fe_ht->nNumUsed) {
4953                    fe_ht->nInternalPointer = ptr->pos = INVALID_IDX;
4954                    ZEND_VM_INC_OPCODE();
4955                    ZEND_VM_NEXT_OPCODE();
4956                }
4957                p = fe_ht->arData + pos;
4958            } while (Z_TYPE(p->val) == IS_UNDEF ||
4959                     (Z_TYPE(p->val) == IS_INDIRECT &&
4960                      Z_TYPE_P(Z_INDIRECT(p->val)) == IS_UNDEF) ||
4961                     (EXPECTED(p->key != NULL) &&
4962                      zend_check_property_access(zobj, p->key) == FAILURE));
4963            fe_ht->nInternalPointer = ptr->pos = pos;
4964            ptr->h = fe_ht->arData[pos].h;
4965            ptr->key = fe_ht->arData[pos].key;
4966            ZEND_VM_INC_OPCODE();
4967            ZEND_VM_NEXT_OPCODE();
4968        } else {
4969            /* !iter happens from exception */
4970            if (iter && ++iter->index > 0) {
4971                /* This could cause an endless loop if index becomes zero again.
4972                 * In case that ever happens we need an additional flag. */
4973                iter->funcs->move_forward(iter);
4974                if (UNEXPECTED(EG(exception) != NULL)) {
4975                    zval_ptr_dtor(array_ref);
4976                    HANDLE_EXCEPTION();
4977                }
4978            }
4979            /* If index is zero we come from FE_RESET and checked valid() already. */
4980            if (!iter || (iter->index > 0 && iter->funcs->valid(iter) == FAILURE)) {
4981                /* reached end of iteration */
4982                if (UNEXPECTED(EG(exception) != NULL)) {
4983                    zval_ptr_dtor(array_ref);
4984                    HANDLE_EXCEPTION();
4985                }
4986                ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
4987            }
4988            value = iter->funcs->get_current_data(iter);
4989            if (UNEXPECTED(EG(exception) != NULL)) {
4990                zval_ptr_dtor(array_ref);
4991                HANDLE_EXCEPTION();
4992            }
4993            if (!value) {
4994                /* failure in get_current_data */
4995                ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
4996            }
4997            if (opline->extended_value & ZEND_FE_FETCH_BYREF) {
4998                ZVAL_MAKE_REF(value);
4999                Z_ADDREF_P(value);
5000                ZVAL_REF(EX_VAR(opline->result.var), Z_REF_P(value));
5001            } else {
5002                ZVAL_COPY(EX_VAR(opline->result.var), value);
5003            }
5004            if (opline->extended_value & ZEND_FE_FETCH_WITH_KEY) {
5005                if (iter->funcs->get_current_key) {
5006                    iter->funcs->get_current_key(iter, EX_VAR((opline+1)->result.var));
5007                    if (UNEXPECTED(EG(exception) != NULL)) {
5008                        zval_ptr_dtor(array_ref);
5009                        HANDLE_EXCEPTION();
5010                    }
5011                } else {
5012                    ZVAL_LONG(EX_VAR((opline+1)->result.var), iter->index);
5013                }
5014            }
5015            ZEND_VM_INC_OPCODE();
5016            ZEND_VM_NEXT_OPCODE();
5017        }
5018    } else {
5019        zend_error(E_WARNING, "Invalid argument supplied for foreach()");
5020        ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
5021    }
5022}
5023
5024ZEND_VM_HANDLER(114, ZEND_ISSET_ISEMPTY_VAR, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
5025{
5026    USE_OPLINE
5027    zval *value;
5028
5029    SAVE_OPLINE();
5030    if (OP1_TYPE == IS_CV &&
5031        OP2_TYPE == IS_UNUSED &&
5032        (opline->extended_value & ZEND_QUICK_SET)) {
5033        value = EX_VAR(opline->op1.var);
5034        if (opline->extended_value & ZEND_ISSET) {
5035            ZVAL_BOOL(EX_VAR(opline->result.var),
5036                Z_TYPE_P(value) > IS_NULL &&
5037                (!Z_ISREF_P(value) || Z_TYPE_P(Z_REFVAL_P(value)) != IS_NULL));
5038        } else /* if (opline->extended_value & ZEND_ISEMPTY) */ {
5039            ZVAL_BOOL(EX_VAR(opline->result.var),
5040                !i_zend_is_true(value));
5041            CHECK_EXCEPTION();
5042        }
5043        ZEND_VM_NEXT_OPCODE();
5044    } else {
5045        zend_free_op free_op1;
5046        zval tmp, *varname = GET_OP1_ZVAL_PTR(BP_VAR_IS);
5047
5048        ZVAL_UNDEF(&tmp);
5049        if (OP1_TYPE != IS_CONST && Z_TYPE_P(varname) != IS_STRING) {
5050            ZVAL_STR(&tmp, zval_get_string(varname));
5051            varname = &tmp;
5052        }
5053
5054        if (OP2_TYPE != IS_UNUSED) {
5055            zend_class_entry *ce;
5056
5057            if (OP2_TYPE == IS_CONST) {
5058                if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) {
5059                    ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
5060                } else {
5061                    ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op2)), EX_CONSTANT(opline->op2) + 1, 0);
5062                    if (UNEXPECTED(ce == NULL)) {
5063                        CHECK_EXCEPTION();
5064                        ZEND_VM_NEXT_OPCODE();
5065                    }
5066                    CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce);
5067                }
5068            } else {
5069                ce = Z_CE_P(EX_VAR(opline->op2.var));
5070            }
5071            value = zend_std_get_static_property(ce, Z_STR_P(varname), 1, ((OP1_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(varname)) : NULL));
5072        } else {
5073            HashTable *target_symbol_table = zend_get_target_symbol_table(execute_data, opline->extended_value & ZEND_FETCH_TYPE_MASK);
5074            value = zend_hash_find_ind(target_symbol_table, Z_STR_P(varname));
5075        }
5076
5077        if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
5078            zend_string_release(Z_STR(tmp));
5079        }
5080        FREE_OP1();
5081
5082        if (opline->extended_value & ZEND_ISSET) {
5083            ZVAL_BOOL(EX_VAR(opline->result.var),
5084                value && Z_TYPE_P(value) > IS_NULL &&
5085                (!Z_ISREF_P(value) || Z_TYPE_P(Z_REFVAL_P(value)) != IS_NULL));
5086        } else /* if (opline->extended_value & ZEND_ISEMPTY) */ {
5087            ZVAL_BOOL(EX_VAR(opline->result.var),
5088                !value || !i_zend_is_true(value));
5089        }
5090
5091        CHECK_EXCEPTION();
5092        ZEND_VM_NEXT_OPCODE();
5093    }
5094}
5095
5096ZEND_VM_HANDLER(115, ZEND_ISSET_ISEMPTY_DIM_OBJ, CONST|TMPVAR|UNUSED|CV, CONST|TMPVAR|CV)
5097{
5098    USE_OPLINE
5099    zend_free_op free_op1, free_op2;
5100    zval *container;
5101    int result;
5102    zend_ulong hval;
5103    zval *offset;
5104
5105    SAVE_OPLINE();
5106    container = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_IS);
5107    offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
5108
5109ZEND_VM_C_LABEL(isset_dim_obj_again):
5110    if (OP1_TYPE != IS_UNUSED && EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
5111        HashTable *ht = Z_ARRVAL_P(container);
5112        zval *value;
5113        zend_string *str;
5114
5115ZEND_VM_C_LABEL(isset_again):
5116        if (EXPECTED(Z_TYPE_P(offset) == IS_STRING)) {
5117            str = Z_STR_P(offset);
5118            if (OP2_TYPE != IS_CONST) {
5119                if (ZEND_HANDLE_NUMERIC(str, hval)) {
5120                    ZEND_VM_C_GOTO(num_index_prop);
5121                }
5122            }
5123ZEND_VM_C_LABEL(str_index_prop):
5124            value = zend_hash_find_ind(ht, str);
5125        } else if (EXPECTED(Z_TYPE_P(offset) == IS_LONG)) {
5126            hval = Z_LVAL_P(offset);
5127ZEND_VM_C_LABEL(num_index_prop):
5128            value = zend_hash_index_find(ht, hval);
5129        } else {
5130            switch (Z_TYPE_P(offset)) {
5131                case IS_DOUBLE:
5132                    hval = zend_dval_to_lval(Z_DVAL_P(offset));
5133                    ZEND_VM_C_GOTO(num_index_prop);
5134                case IS_NULL:
5135                    str = STR_EMPTY_ALLOC();
5136                    ZEND_VM_C_GOTO(str_index_prop);
5137                case IS_FALSE:
5138                    hval = 0;
5139                    ZEND_VM_C_GOTO(num_index_prop);
5140                case IS_TRUE:
5141                    hval = 1;
5142                    ZEND_VM_C_GOTO(num_index_prop);
5143                case IS_RESOURCE:
5144                    hval = Z_RES_HANDLE_P(offset);
5145                    ZEND_VM_C_GOTO(num_index_prop);
5146                case IS_REFERENCE:
5147                    offset = Z_REFVAL_P(offset);
5148                    ZEND_VM_C_GOTO(isset_again);
5149                default:
5150                    zend_error(E_WARNING, "Illegal offset type in isset or empty");
5151                    value = NULL;
5152                    break;
5153            }
5154        }
5155
5156        if (opline->extended_value & ZEND_ISSET) {
5157            /* > IS_NULL means not IS_UNDEF and not IS_NULL */
5158            result = value != NULL && Z_TYPE_P(value) > IS_NULL &&
5159                (!Z_ISREF_P(value) || Z_TYPE_P(Z_REFVAL_P(value)) != IS_NULL);
5160        } else /* if (opline->extended_value & ZEND_ISEMPTY) */ {
5161            result = (value == NULL || !i_zend_is_true(value));
5162        }
5163    } else if (OP1_TYPE == IS_UNUSED || EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
5164        if (EXPECTED(Z_OBJ_HT_P(container)->has_dimension)) {
5165            result = Z_OBJ_HT_P(container)->has_dimension(container, offset, (opline->extended_value & ZEND_ISSET) == 0);
5166        } else {
5167            zend_error(E_NOTICE, "Trying to check element of non-array");
5168            result = 0;
5169        }
5170        if ((opline->extended_value & ZEND_ISSET) == 0) {
5171            result = !result;
5172        }
5173    } else if (EXPECTED(Z_TYPE_P(container) == IS_STRING)) { /* string offsets */
5174        zval tmp;
5175
5176        result = 0;
5177        if (UNEXPECTED(Z_TYPE_P(offset) != IS_LONG)) {
5178            if (OP2_TYPE & (IS_CV|IS_VAR)) {
5179                ZVAL_DEREF(offset);
5180            }
5181            if (Z_TYPE_P(offset) < IS_STRING /* simple scalar types */
5182                    || (Z_TYPE_P(offset) == IS_STRING /* or numeric string */
5183                        && IS_LONG == is_numeric_string(Z_STRVAL_P(offset), Z_STRLEN_P(offset), NULL, NULL, 0))) {
5184                ZVAL_DUP(&tmp, offset);
5185                convert_to_long(&tmp);
5186                offset = &tmp;
5187            }
5188        }
5189        if (EXPECTED(Z_TYPE_P(offset) == IS_LONG)) {
5190            if (offset->value.lval >= 0 && (size_t)offset->value.lval < Z_STRLEN_P(container)) {
5191                if ((opline->extended_value & ZEND_ISSET) ||
5192                    Z_STRVAL_P(container)[offset->value.lval] != '0') {
5193                    result = 1;
5194                }
5195            }
5196        }
5197        if ((opline->extended_value & ZEND_ISSET) == 0) {
5198            result = !result;
5199        }
5200    } else if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(container)) {
5201        container = Z_REFVAL_P(container);
5202        ZEND_VM_C_GOTO(isset_dim_obj_again);
5203    } else {
5204