1/*
2   +----------------------------------------------------------------------+
3   | Zend Engine                                                          |
4   +----------------------------------------------------------------------+
5   | Copyright (c) 1998-2016 Zend Technologies Ltd. (http://www.zend.com) |
6   +----------------------------------------------------------------------+
7   | This source file is subject to version 2.00 of the Zend license,     |
8   | that is bundled with this package in the file LICENSE, and is        |
9   | available through the world-wide-web at the following url:           |
10   | http://www.zend.com/license/2_00.txt.                                |
11   | If you did not receive a copy of the Zend license and are unable to  |
12   | obtain it through the world-wide-web, please send a note to          |
13   | license@zend.com so we can mail you a copy immediately.              |
14   +----------------------------------------------------------------------+
15   | Authors: Andi Gutmans <andi@zend.com>                                |
16   |          Zeev Suraski <zeev@zend.com>                                |
17   |          Dmitry Stogov <dmitry@zend.com>                             |
18   +----------------------------------------------------------------------+
19*/
20
21/* $Id$ */
22
23/* If you change this file, please regenerate the zend_vm_execute.h and
24 * zend_vm_opcodes.h files by running:
25 * php zend_vm_gen.php
26 */
27
28ZEND_VM_HANDLER(1, ZEND_ADD, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
29{
30	USE_OPLINE
31	zend_free_op free_op1, free_op2;
32	zval *op1, *op2, *result;
33
34	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
35	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
36	if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
37		if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
38			result = EX_VAR(opline->result.var);
39			fast_long_add_function(result, op1, op2);
40			ZEND_VM_NEXT_OPCODE();
41		} else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
42			result = EX_VAR(opline->result.var);
43			ZVAL_DOUBLE(result, ((double)Z_LVAL_P(op1)) + Z_DVAL_P(op2));
44			ZEND_VM_NEXT_OPCODE();
45		}
46	} else if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_DOUBLE)) {
47		if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
48			result = EX_VAR(opline->result.var);
49			ZVAL_DOUBLE(result, Z_DVAL_P(op1) + Z_DVAL_P(op2));
50			ZEND_VM_NEXT_OPCODE();
51		} else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
52			result = EX_VAR(opline->result.var);
53			ZVAL_DOUBLE(result, Z_DVAL_P(op1) + ((double)Z_LVAL_P(op2)));
54			ZEND_VM_NEXT_OPCODE();
55		}
56	}
57
58	SAVE_OPLINE();
59	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
60		op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
61	}
62	if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
63		op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
64	}
65	add_function(EX_VAR(opline->result.var), op1, op2);
66	FREE_OP1();
67	FREE_OP2();
68	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
69}
70
71ZEND_VM_HANDLER(2, ZEND_SUB, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
72{
73	USE_OPLINE
74	zend_free_op free_op1, free_op2;
75	zval *op1, *op2, *result;
76
77	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
78	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
79	if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
80		if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
81			result = EX_VAR(opline->result.var);
82			fast_long_sub_function(result, op1, op2);
83			ZEND_VM_NEXT_OPCODE();
84		} else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
85			result = EX_VAR(opline->result.var);
86			ZVAL_DOUBLE(result, ((double)Z_LVAL_P(op1)) - Z_DVAL_P(op2));
87			ZEND_VM_NEXT_OPCODE();
88		}
89	} else if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_DOUBLE)) {
90		if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
91			result = EX_VAR(opline->result.var);
92			ZVAL_DOUBLE(result, Z_DVAL_P(op1) - Z_DVAL_P(op2));
93			ZEND_VM_NEXT_OPCODE();
94		} else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
95			result = EX_VAR(opline->result.var);
96			ZVAL_DOUBLE(result, Z_DVAL_P(op1) - ((double)Z_LVAL_P(op2)));
97			ZEND_VM_NEXT_OPCODE();
98		}
99	}
100
101	SAVE_OPLINE();
102	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
103		op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
104	}
105	if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
106		op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
107	}
108	sub_function(EX_VAR(opline->result.var), op1, op2);
109	FREE_OP1();
110	FREE_OP2();
111	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
112}
113
114ZEND_VM_HANDLER(3, ZEND_MUL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
115{
116	USE_OPLINE
117	zend_free_op free_op1, free_op2;
118	zval *op1, *op2, *result;
119
120	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
121	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
122	if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
123		if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
124			zend_long overflow;
125
126			result = EX_VAR(opline->result.var);
127			ZEND_SIGNED_MULTIPLY_LONG(Z_LVAL_P(op1), Z_LVAL_P(op2), Z_LVAL_P(result), Z_DVAL_P(result), overflow);
128			Z_TYPE_INFO_P(result) = overflow ? IS_DOUBLE : IS_LONG;
129			ZEND_VM_NEXT_OPCODE();
130		} else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
131			result = EX_VAR(opline->result.var);
132			ZVAL_DOUBLE(result, ((double)Z_LVAL_P(op1)) * Z_DVAL_P(op2));
133			ZEND_VM_NEXT_OPCODE();
134		}
135	} else if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_DOUBLE)) {
136		if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
137			result = EX_VAR(opline->result.var);
138			ZVAL_DOUBLE(result, Z_DVAL_P(op1) * Z_DVAL_P(op2));
139			ZEND_VM_NEXT_OPCODE();
140		} else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
141			result = EX_VAR(opline->result.var);
142			ZVAL_DOUBLE(result, Z_DVAL_P(op1) * ((double)Z_LVAL_P(op2)));
143			ZEND_VM_NEXT_OPCODE();
144		}
145	}
146
147	SAVE_OPLINE();
148	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
149		op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
150	}
151	if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
152		op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
153	}
154	mul_function(EX_VAR(opline->result.var), op1, op2);
155	FREE_OP1();
156	FREE_OP2();
157	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
158}
159
160ZEND_VM_HANDLER(4, ZEND_DIV, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
161{
162	USE_OPLINE
163	zend_free_op free_op1, free_op2;
164	zval *op1, *op2;
165
166	SAVE_OPLINE();
167	op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
168	op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
169	fast_div_function(EX_VAR(opline->result.var), op1, op2);
170	FREE_OP1();
171	FREE_OP2();
172	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
173}
174
175ZEND_VM_HANDLER(5, ZEND_MOD, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
176{
177	USE_OPLINE
178	zend_free_op free_op1, free_op2;
179	zval *op1, *op2, *result;
180
181	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
182	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
183	if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
184		if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
185			result = EX_VAR(opline->result.var);
186			if (UNEXPECTED(Z_LVAL_P(op2) == 0)) {
187				SAVE_OPLINE();
188				zend_throw_exception_ex(zend_ce_division_by_zero_error, 0, "Modulo by zero");
189				HANDLE_EXCEPTION();
190			} else if (UNEXPECTED(Z_LVAL_P(op2) == -1)) {
191				/* Prevent overflow error/crash if op1==ZEND_LONG_MIN */
192				ZVAL_LONG(result, 0);
193			} else {
194				ZVAL_LONG(result, Z_LVAL_P(op1) % Z_LVAL_P(op2));
195			}
196			ZEND_VM_NEXT_OPCODE();
197		}
198	}
199
200	SAVE_OPLINE();
201	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
202		op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
203	}
204	if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
205		op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
206	}
207	mod_function(EX_VAR(opline->result.var), op1, op2);
208	FREE_OP1();
209	FREE_OP2();
210	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
211}
212
213ZEND_VM_HANDLER(6, ZEND_SL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
214{
215	USE_OPLINE
216	zend_free_op free_op1, free_op2;
217	zval *op1, *op2;
218
219	SAVE_OPLINE();
220	op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
221	op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
222	shift_left_function(EX_VAR(opline->result.var), op1, op2);
223	FREE_OP1();
224	FREE_OP2();
225	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
226}
227
228ZEND_VM_HANDLER(7, ZEND_SR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
229{
230	USE_OPLINE
231	zend_free_op free_op1, free_op2;
232	zval *op1, *op2;
233
234	SAVE_OPLINE();
235	op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
236	op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
237	shift_right_function(EX_VAR(opline->result.var), op1, op2);
238	FREE_OP1();
239	FREE_OP2();
240	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
241}
242
243ZEND_VM_HANDLER(166, ZEND_POW, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
244{
245	USE_OPLINE
246	zend_free_op free_op1, free_op2;
247	zval *op1, *op2;
248
249	SAVE_OPLINE();
250	op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
251	op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
252	pow_function(EX_VAR(opline->result.var), op1, op2);
253	FREE_OP1();
254	FREE_OP2();
255	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
256}
257
258ZEND_VM_HANDLER(8, ZEND_CONCAT, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
259{
260	USE_OPLINE
261	zend_free_op free_op1, free_op2;
262	zval *op1, *op2;
263
264	SAVE_OPLINE();
265	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
266	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
267
268	do {
269		if ((OP1_TYPE == IS_CONST || EXPECTED(Z_TYPE_P(op1) == IS_STRING)) &&
270		    (OP2_TYPE == IS_CONST || EXPECTED(Z_TYPE_P(op2) == IS_STRING))) {
271			zend_string *op1_str = Z_STR_P(op1);
272			zend_string *op2_str = Z_STR_P(op2);
273			zend_string *str;
274
275			if (OP1_TYPE != IS_CONST) {
276				if (UNEXPECTED(ZSTR_LEN(op1_str) == 0)) {
277					ZVAL_STR_COPY(EX_VAR(opline->result.var), op2_str);
278					FREE_OP1();
279					break;
280				}
281			}
282			if (OP2_TYPE != IS_CONST) {
283				if (UNEXPECTED(ZSTR_LEN(op2_str) == 0)) {
284					ZVAL_STR_COPY(EX_VAR(opline->result.var), op1_str);
285					FREE_OP1();
286					break;
287				}
288			}
289			if (OP1_TYPE != IS_CONST && OP1_TYPE != IS_CV &&
290			    !ZSTR_IS_INTERNED(op1_str) && GC_REFCOUNT(op1_str) == 1) {
291			    size_t len = ZSTR_LEN(op1_str);
292
293				str = zend_string_realloc(op1_str, len + ZSTR_LEN(op2_str), 0);
294				memcpy(ZSTR_VAL(str) + len, ZSTR_VAL(op2_str), ZSTR_LEN(op2_str)+1);
295				ZVAL_NEW_STR(EX_VAR(opline->result.var), str);
296				break;
297			} else {
298				str = zend_string_alloc(ZSTR_LEN(op1_str) + ZSTR_LEN(op2_str), 0);
299				memcpy(ZSTR_VAL(str), ZSTR_VAL(op1_str), ZSTR_LEN(op1_str));
300				memcpy(ZSTR_VAL(str) + ZSTR_LEN(op1_str), ZSTR_VAL(op2_str), ZSTR_LEN(op2_str)+1);
301				ZVAL_NEW_STR(EX_VAR(opline->result.var), str);
302			}
303		} else {
304			if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op1) == IS_UNDEF)) {
305				op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
306			}
307			if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op2) == IS_UNDEF)) {
308				op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
309			}
310			concat_function(EX_VAR(opline->result.var), op1, op2);
311		}
312		FREE_OP1();
313	} while (0);
314	FREE_OP2();
315	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
316}
317
318ZEND_VM_HANDLER(15, ZEND_IS_IDENTICAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
319{
320	USE_OPLINE
321	zend_free_op free_op1, free_op2;
322	zval *op1, *op2;
323	int result;
324
325	SAVE_OPLINE();
326	op1 = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
327	op2 = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
328	result = fast_is_identical_function(op1, op2);
329	FREE_OP1();
330	FREE_OP2();
331	ZEND_VM_SMART_BRANCH(result, 1);
332	ZVAL_BOOL(EX_VAR(opline->result.var), result);
333	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
334}
335
336ZEND_VM_HANDLER(16, ZEND_IS_NOT_IDENTICAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
337{
338	USE_OPLINE
339	zend_free_op free_op1, free_op2;
340	zval *op1, *op2;
341	int result;
342
343	SAVE_OPLINE();
344	op1 = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
345	op2 = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
346	result = fast_is_not_identical_function(op1, op2);
347	FREE_OP1();
348	FREE_OP2();
349	ZEND_VM_SMART_BRANCH(result, 1);
350	ZVAL_BOOL(EX_VAR(opline->result.var), result);
351	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
352}
353
354ZEND_VM_HANDLER(17, ZEND_IS_EQUAL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
355{
356	USE_OPLINE
357	zend_free_op free_op1, free_op2;
358	zval *op1, *op2, *result;
359
360	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
361	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
362	do {
363		int result;
364
365		if (EXPECTED(Z_TYPE_P(op1) == IS_LONG)) {
366			if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
367				result = (Z_LVAL_P(op1) == Z_LVAL_P(op2));
368			} else if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
369				result = ((double)Z_LVAL_P(op1) == Z_DVAL_P(op2));
370			} else {
371				break;
372			}
373		} else if (EXPECTED(Z_TYPE_P(op1) == IS_DOUBLE)) {
374			if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
375				result = (Z_DVAL_P(op1) == Z_DVAL_P(op2));
376			} else if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
377				result = (Z_DVAL_P(op1) == ((double)Z_LVAL_P(op2)));
378			} else {
379				break;
380			}
381		} else if (EXPECTED(Z_TYPE_P(op1) == IS_STRING)) {
382			if (EXPECTED(Z_TYPE_P(op2) == IS_STRING)) {
383				if (Z_STR_P(op1) == Z_STR_P(op2)) {
384					result = 1;
385				} else if (Z_STRVAL_P(op1)[0] > '9' || Z_STRVAL_P(op2)[0] > '9') {
386					if (Z_STRLEN_P(op1) != Z_STRLEN_P(op2)) {
387						result = 0;
388					} else {
389						result = (memcmp(Z_STRVAL_P(op1), Z_STRVAL_P(op2), Z_STRLEN_P(op1)) == 0);
390					}
391				} else {
392					result = (zendi_smart_strcmp(Z_STR_P(op1), Z_STR_P(op2)) == 0);
393				}
394				FREE_OP1();
395				FREE_OP2();
396			} else {
397				break;
398			}
399		} else {
400			break;
401		}
402		ZEND_VM_SMART_BRANCH(result, 0);
403		ZVAL_BOOL(EX_VAR(opline->result.var), result);
404		ZEND_VM_NEXT_OPCODE();
405	} while (0);
406
407	SAVE_OPLINE();
408	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op1) == IS_UNDEF)) {
409		op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
410	}
411	if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op2) == IS_UNDEF)) {
412		op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
413	}
414	result = EX_VAR(opline->result.var);
415	compare_function(result, op1, op2);
416	ZVAL_BOOL(result, Z_LVAL_P(result) == 0);
417	FREE_OP1();
418	FREE_OP2();
419	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
420}
421
422ZEND_VM_HANDLER(18, ZEND_IS_NOT_EQUAL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
423{
424	USE_OPLINE
425	zend_free_op free_op1, free_op2;
426	zval *op1, *op2, *result;
427
428	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
429	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
430	do {
431		int result;
432
433		if (EXPECTED(Z_TYPE_P(op1) == IS_LONG)) {
434			if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
435				result = (Z_LVAL_P(op1) != Z_LVAL_P(op2));
436			} else if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
437				result = ((double)Z_LVAL_P(op1) != Z_DVAL_P(op2));
438			} else {
439				break;
440			}
441		} else if (EXPECTED(Z_TYPE_P(op1) == IS_DOUBLE)) {
442			if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
443				result = (Z_DVAL_P(op1) != Z_DVAL_P(op2));
444			} else if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
445				result = (Z_DVAL_P(op1) != ((double)Z_LVAL_P(op2)));
446			} else {
447				break;
448			}
449		} else if (EXPECTED(Z_TYPE_P(op1) == IS_STRING)) {
450			if (EXPECTED(Z_TYPE_P(op2) == IS_STRING)) {
451				if (Z_STR_P(op1) == Z_STR_P(op2)) {
452					result = 0;
453				} else if (Z_STRVAL_P(op1)[0] > '9' || Z_STRVAL_P(op2)[0] > '9') {
454					if (Z_STRLEN_P(op1) != Z_STRLEN_P(op2)) {
455						result = 1;
456					} else {
457						result = (memcmp(Z_STRVAL_P(op1), Z_STRVAL_P(op2), Z_STRLEN_P(op1)) != 0);
458					}
459				} else {
460					result = (zendi_smart_strcmp(Z_STR_P(op1), Z_STR_P(op2)) != 0);
461				}
462				FREE_OP1();
463				FREE_OP2();
464			} else {
465				break;
466			}
467		} else {
468			break;
469		}
470		ZEND_VM_SMART_BRANCH(result, 0);
471		ZVAL_BOOL(EX_VAR(opline->result.var), result);
472		ZEND_VM_NEXT_OPCODE();
473	} while (0);
474
475	SAVE_OPLINE();
476	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op1) == IS_UNDEF)) {
477		op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
478	}
479	if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op2) == IS_UNDEF)) {
480		op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
481	}
482	result = EX_VAR(opline->result.var);
483	compare_function(result, op1, op2);
484	ZVAL_BOOL(result, Z_LVAL_P(result) != 0);
485	FREE_OP1();
486	FREE_OP2();
487	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
488}
489
490ZEND_VM_HANDLER(19, ZEND_IS_SMALLER, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
491{
492	USE_OPLINE
493	zend_free_op free_op1, free_op2;
494	zval *op1, *op2, *result;
495
496	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
497	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
498	do {
499		int result;
500
501		if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
502			if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
503				result = (Z_LVAL_P(op1) < Z_LVAL_P(op2));
504			} else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
505				result = ((double)Z_LVAL_P(op1) < Z_DVAL_P(op2));
506			} else {
507				break;
508			}
509		} else if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_DOUBLE)) {
510			if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
511				result = (Z_DVAL_P(op1) < Z_DVAL_P(op2));
512			} else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
513				result = (Z_DVAL_P(op1) < ((double)Z_LVAL_P(op2)));
514			} else {
515				break;
516			}
517		} else {
518			break;
519		}
520		ZEND_VM_SMART_BRANCH(result, 0);
521		ZVAL_BOOL(EX_VAR(opline->result.var), result);
522		ZEND_VM_NEXT_OPCODE();
523	} while (0);
524
525	SAVE_OPLINE();
526	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
527		op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
528	}
529	if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
530		op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
531	}
532	result = EX_VAR(opline->result.var);
533	compare_function(result, op1, op2);
534	ZVAL_BOOL(result, Z_LVAL_P(result) < 0);
535	FREE_OP1();
536	FREE_OP2();
537	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
538}
539
540ZEND_VM_HANDLER(20, ZEND_IS_SMALLER_OR_EQUAL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
541{
542	USE_OPLINE
543	zend_free_op free_op1, free_op2;
544	zval *op1, *op2, *result;
545
546	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
547	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
548	do {
549		int result;
550
551		if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_LONG)) {
552			if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
553				result = (Z_LVAL_P(op1) <= Z_LVAL_P(op2));
554			} else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
555				result = ((double)Z_LVAL_P(op1) <= Z_DVAL_P(op2));
556			} else {
557				break;
558			}
559		} else if (EXPECTED(Z_TYPE_INFO_P(op1) == IS_DOUBLE)) {
560			if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_DOUBLE)) {
561				result = (Z_DVAL_P(op1) <= Z_DVAL_P(op2));
562			} else if (EXPECTED(Z_TYPE_INFO_P(op2) == IS_LONG)) {
563				result = (Z_DVAL_P(op1) <= ((double)Z_LVAL_P(op2)));
564			} else {
565				break;
566			}
567		} else {
568			break;
569		}
570		ZEND_VM_SMART_BRANCH(result, 0);
571		ZVAL_BOOL(EX_VAR(opline->result.var), result);
572		ZEND_VM_NEXT_OPCODE();
573	} while (0);
574
575	SAVE_OPLINE();
576	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op1) == IS_UNDEF)) {
577		op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
578	}
579	if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(op2) == IS_UNDEF)) {
580		op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
581	}
582	result = EX_VAR(opline->result.var);
583	compare_function(result, op1, op2);
584	ZVAL_BOOL(result, Z_LVAL_P(result) <= 0);
585	FREE_OP1();
586	FREE_OP2();
587	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
588}
589
590ZEND_VM_HANDLER(170, ZEND_SPACESHIP, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
591{
592	USE_OPLINE
593	zend_free_op free_op1, free_op2;
594	zval *op1, *op2;
595
596	SAVE_OPLINE();
597	op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
598	op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
599	compare_function(EX_VAR(opline->result.var), op1, op2);
600	FREE_OP1();
601	FREE_OP2();
602	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
603}
604
605ZEND_VM_HANDLER(9, ZEND_BW_OR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
606{
607	USE_OPLINE
608	zend_free_op free_op1, free_op2;
609	zval *op1, *op2;
610
611	SAVE_OPLINE();
612	op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
613	op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
614	bitwise_or_function(EX_VAR(opline->result.var), op1, op2);
615	FREE_OP1();
616	FREE_OP2();
617	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
618}
619
620ZEND_VM_HANDLER(10, ZEND_BW_AND, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
621{
622	USE_OPLINE
623	zend_free_op free_op1, free_op2;
624	zval *op1, *op2;
625
626	SAVE_OPLINE();
627	op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
628	op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
629	bitwise_and_function(EX_VAR(opline->result.var), op1, op2);
630	FREE_OP1();
631	FREE_OP2();
632	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
633}
634
635ZEND_VM_HANDLER(11, ZEND_BW_XOR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
636{
637	USE_OPLINE
638	zend_free_op free_op1, free_op2;
639	zval *op1, *op2;
640
641	SAVE_OPLINE();
642	op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
643	op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
644	bitwise_xor_function(EX_VAR(opline->result.var), op1, op2);
645	FREE_OP1();
646	FREE_OP2();
647	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
648}
649
650ZEND_VM_HANDLER(14, ZEND_BOOL_XOR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
651{
652	USE_OPLINE
653	zend_free_op free_op1, free_op2;
654	zval *op1, *op2;
655
656	SAVE_OPLINE();
657	op1 = GET_OP1_ZVAL_PTR(BP_VAR_R);
658	op2 = GET_OP2_ZVAL_PTR(BP_VAR_R);
659	boolean_xor_function(EX_VAR(opline->result.var), op1, op2);
660	FREE_OP1();
661	FREE_OP2();
662	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
663}
664
665ZEND_VM_HANDLER(12, ZEND_BW_NOT, CONST|TMPVAR|CV, ANY)
666{
667	USE_OPLINE
668	zend_free_op free_op1;
669
670	SAVE_OPLINE();
671	bitwise_not_function(EX_VAR(opline->result.var),
672		GET_OP1_ZVAL_PTR(BP_VAR_R));
673	FREE_OP1();
674	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
675}
676
677ZEND_VM_HANDLER(13, ZEND_BOOL_NOT, CONST|TMPVAR|CV, ANY)
678{
679	USE_OPLINE
680	zval *val;
681	zend_free_op free_op1;
682
683	val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
684	if (Z_TYPE_INFO_P(val) == IS_TRUE) {
685		ZVAL_FALSE(EX_VAR(opline->result.var));
686	} else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
687		ZVAL_TRUE(EX_VAR(opline->result.var));
688		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
689			SAVE_OPLINE();
690			GET_OP1_UNDEF_CV(val, BP_VAR_R);
691			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
692		}
693	} else {
694		SAVE_OPLINE();
695		ZVAL_BOOL(EX_VAR(opline->result.var), !i_zend_is_true(val));
696		FREE_OP1();
697		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
698	}
699	ZEND_VM_NEXT_OPCODE();
700}
701
702ZEND_VM_HELPER(zend_binary_assign_op_obj_helper, VAR|UNUSED|CV, CONST|TMPVAR|CV, binary_op_type binary_op)
703{
704	USE_OPLINE
705	zend_free_op free_op1, free_op2, free_op_data1;
706	zval *object;
707	zval *property;
708	zval *value;
709	zval *zptr;
710
711	SAVE_OPLINE();
712	object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
713
714	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(object) == NULL)) {
715		zend_throw_error(NULL, "Using $this when not in object context");
716		FREE_UNFETCHED_OP((opline+1)->op1_type, (opline+1)->op1.var);
717		FREE_UNFETCHED_OP2();
718		HANDLE_EXCEPTION();
719	}
720
721	property = GET_OP2_ZVAL_PTR(BP_VAR_R);
722
723	do {
724		value = get_zval_ptr_r((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1);
725
726		if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
727			ZVAL_DEREF(object);
728			if (UNEXPECTED(!make_real_object(object))) {
729				zend_error(E_WARNING, "Attempt to assign property of non-object");
730				if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
731					ZVAL_NULL(EX_VAR(opline->result.var));
732				}
733				break;
734			}
735		}
736
737		/* here we are sure we are dealing with an object */
738		if (EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
739			&& EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL))) != NULL)) {
740
741			ZVAL_DEREF(zptr);
742			SEPARATE_ZVAL_NOREF(zptr);
743
744			binary_op(zptr, zptr, value);
745			if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
746				ZVAL_COPY(EX_VAR(opline->result.var), zptr);
747			}
748		} else {
749			zend_assign_op_overloaded_property(object, property, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), value, binary_op, (UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL));
750		}
751	} while (0);
752
753	FREE_OP(free_op_data1);
754	FREE_OP2();
755	FREE_OP1_VAR_PTR();
756	/* assign_obj has two opcodes! */
757	ZEND_VM_NEXT_OPCODE_EX(1, 2);
758}
759
760ZEND_VM_HELPER(zend_binary_assign_op_dim_helper, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV, binary_op_type binary_op)
761{
762	USE_OPLINE
763	zend_free_op free_op1, free_op2, free_op_data1;
764	zval *var_ptr, rv;
765	zval *value, *container, *dim;
766
767	SAVE_OPLINE();
768	container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
769	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
770		zend_throw_error(NULL, "Using $this when not in object context");
771		FREE_UNFETCHED_OP((opline+1)->op1_type, (opline+1)->op1.var);
772		FREE_UNFETCHED_OP2();
773		HANDLE_EXCEPTION();
774	}
775
776	dim = GET_OP2_ZVAL_PTR(BP_VAR_R);
777
778	do {
779		if (OP1_TYPE == IS_UNUSED || UNEXPECTED(Z_TYPE_P(container) != IS_ARRAY)) {
780			if (OP1_TYPE != IS_UNUSED) {
781				ZVAL_DEREF(container);
782			}
783			if (OP1_TYPE == IS_UNUSED || EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
784				value = get_zval_ptr_r((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1);
785				zend_binary_assign_op_obj_dim(container, dim, value, UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL, binary_op);
786				break;
787			}
788		}
789
790		zend_fetch_dimension_address_RW(&rv, container, dim, OP2_TYPE);
791		value = get_zval_ptr_r((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1);
792
793		if (UNEXPECTED(Z_ISERROR(rv))) {
794			if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
795				ZVAL_NULL(EX_VAR(opline->result.var));
796			}
797		} else {
798			ZEND_ASSERT(Z_TYPE(rv) == IS_INDIRECT);
799			var_ptr = Z_INDIRECT(rv);
800			ZVAL_DEREF(var_ptr);
801			SEPARATE_ZVAL_NOREF(var_ptr);
802
803			binary_op(var_ptr, var_ptr, value);
804
805			if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
806				ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
807			}
808		}
809	} while (0);
810
811	FREE_OP2();
812	FREE_OP(free_op_data1);
813	FREE_OP1_VAR_PTR();
814	ZEND_VM_NEXT_OPCODE_EX(1, 2);
815}
816
817ZEND_VM_HELPER(zend_binary_assign_op_helper, VAR|CV, CONST|TMPVAR|CV, binary_op_type binary_op)
818{
819	USE_OPLINE
820	zend_free_op free_op1, free_op2;
821	zval *var_ptr;
822	zval *value;
823
824	SAVE_OPLINE();
825	value = GET_OP2_ZVAL_PTR(BP_VAR_R);
826	var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
827
828	if (OP1_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(var_ptr))) {
829		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
830			ZVAL_NULL(EX_VAR(opline->result.var));
831		}
832	} else {
833		ZVAL_DEREF(var_ptr);
834		SEPARATE_ZVAL_NOREF(var_ptr);
835
836		binary_op(var_ptr, var_ptr, value);
837
838		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
839			ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
840		}
841	}
842
843	FREE_OP2();
844	FREE_OP1_VAR_PTR();
845	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
846}
847
848ZEND_VM_HANDLER(23, ZEND_ASSIGN_ADD, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
849{
850#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
851	USE_OPLINE
852
853# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
854	if (EXPECTED(opline->extended_value == 0)) {
855		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, add_function);
856	}
857# endif
858	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
859		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, add_function);
860	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
861		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, add_function);
862	}
863#else
864	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, add_function);
865#endif
866}
867
868ZEND_VM_HANDLER(24, ZEND_ASSIGN_SUB, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
869{
870#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
871	USE_OPLINE
872
873# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
874	if (EXPECTED(opline->extended_value == 0)) {
875		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, sub_function);
876	}
877# endif
878	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
879		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, sub_function);
880	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
881		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, sub_function);
882	}
883#else
884	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, sub_function);
885#endif
886}
887
888ZEND_VM_HANDLER(25, ZEND_ASSIGN_MUL, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
889{
890#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
891	USE_OPLINE
892
893# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
894	if (EXPECTED(opline->extended_value == 0)) {
895		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, mul_function);
896	}
897# endif
898	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
899		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, mul_function);
900	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
901		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, mul_function);
902	}
903#else
904	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, mul_function);
905#endif
906}
907
908ZEND_VM_HANDLER(26, ZEND_ASSIGN_DIV, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
909{
910#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
911	USE_OPLINE
912
913# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
914	if (EXPECTED(opline->extended_value == 0)) {
915		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, div_function);
916	}
917# endif
918	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
919		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, div_function);
920	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
921		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, div_function);
922	}
923#else
924	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, div_function);
925#endif
926}
927
928ZEND_VM_HANDLER(27, ZEND_ASSIGN_MOD, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
929{
930#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
931	USE_OPLINE
932
933# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
934	if (EXPECTED(opline->extended_value == 0)) {
935		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, mod_function);
936	}
937# endif
938	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
939		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, mod_function);
940	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
941		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, mod_function);
942	}
943#else
944	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, mod_function);
945#endif
946}
947
948ZEND_VM_HANDLER(28, ZEND_ASSIGN_SL, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
949{
950#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
951	USE_OPLINE
952
953# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
954	if (EXPECTED(opline->extended_value == 0)) {
955		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, shift_left_function);
956	}
957# endif
958	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
959		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, shift_left_function);
960	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
961		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, shift_left_function);
962	}
963#else
964	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, shift_left_function);
965#endif
966}
967
968ZEND_VM_HANDLER(29, ZEND_ASSIGN_SR, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
969{
970#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
971	USE_OPLINE
972
973# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
974	if (EXPECTED(opline->extended_value == 0)) {
975		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, shift_right_function);
976	}
977# endif
978	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
979		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, shift_right_function);
980	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
981		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, shift_right_function);
982	}
983#else
984	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, shift_right_function);
985#endif
986}
987
988ZEND_VM_HANDLER(30, ZEND_ASSIGN_CONCAT, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
989{
990#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
991	USE_OPLINE
992
993# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
994	if (EXPECTED(opline->extended_value == 0)) {
995		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, concat_function);
996	}
997# endif
998	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
999		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, concat_function);
1000	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
1001		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, concat_function);
1002	}
1003#else
1004	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, concat_function);
1005#endif
1006}
1007
1008ZEND_VM_HANDLER(31, ZEND_ASSIGN_BW_OR, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
1009{
1010#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
1011	USE_OPLINE
1012
1013# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
1014	if (EXPECTED(opline->extended_value == 0)) {
1015		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, bitwise_or_function);
1016	}
1017# endif
1018	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
1019		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, bitwise_or_function);
1020	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
1021		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, bitwise_or_function);
1022	}
1023#else
1024	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, bitwise_or_function);
1025#endif
1026}
1027
1028ZEND_VM_HANDLER(32, ZEND_ASSIGN_BW_AND, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
1029{
1030#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
1031	USE_OPLINE
1032
1033# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
1034	if (EXPECTED(opline->extended_value == 0)) {
1035		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, bitwise_and_function);
1036	}
1037# endif
1038	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
1039		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, bitwise_and_function);
1040	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
1041		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, bitwise_and_function);
1042	}
1043#else
1044	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, bitwise_and_function);
1045#endif
1046}
1047
1048ZEND_VM_HANDLER(33, ZEND_ASSIGN_BW_XOR, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
1049{
1050#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
1051	USE_OPLINE
1052
1053# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
1054	if (EXPECTED(opline->extended_value == 0)) {
1055		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, bitwise_xor_function);
1056	}
1057# endif
1058	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
1059		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, bitwise_xor_function);
1060	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
1061		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, bitwise_xor_function);
1062	}
1063#else
1064	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, bitwise_xor_function);
1065#endif
1066}
1067
1068ZEND_VM_HANDLER(167, ZEND_ASSIGN_POW, VAR|UNUSED|THIS|CV, CONST|TMPVAR|UNUSED|NEXT|CV, DIM_OBJ)
1069{
1070#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
1071	USE_OPLINE
1072
1073# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
1074	if (EXPECTED(opline->extended_value == 0)) {
1075		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_helper, binary_op, pow_function);
1076	}
1077# endif
1078	if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
1079		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, pow_function);
1080	} else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
1081		ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_obj_helper, binary_op, pow_function);
1082	}
1083#else
1084	ZEND_VM_DISPATCH_TO_HELPER(zend_binary_assign_op_dim_helper, binary_op, pow_function);
1085#endif
1086}
1087
1088ZEND_VM_HELPER(zend_pre_incdec_property_helper, VAR|UNUSED|CV, CONST|TMPVAR|CV, int inc)
1089{
1090	USE_OPLINE
1091	zend_free_op free_op1, free_op2;
1092	zval *object;
1093	zval *property;
1094	zval *zptr;
1095
1096	SAVE_OPLINE();
1097	object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
1098
1099	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(object) == NULL)) {
1100		zend_throw_error(NULL, "Using $this when not in object context");
1101		FREE_UNFETCHED_OP2();
1102		HANDLE_EXCEPTION();
1103	}
1104
1105	property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1106
1107	do {
1108		if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
1109			ZVAL_DEREF(object);
1110			if (UNEXPECTED(!make_real_object(object))) {
1111				zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
1112				if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1113					ZVAL_NULL(EX_VAR(opline->result.var));
1114				}
1115				break;
1116			}
1117		}
1118
1119		/* here we are sure we are dealing with an object */
1120
1121		if (EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
1122			&& EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL))) != NULL)) {
1123
1124			if (EXPECTED(Z_TYPE_P(zptr) == IS_LONG)) {
1125				if (inc) {
1126					fast_long_increment_function(zptr);
1127				} else {
1128					fast_long_decrement_function(zptr);
1129				}
1130			} else {
1131				ZVAL_DEREF(zptr);
1132				SEPARATE_ZVAL_NOREF(zptr);
1133
1134				if (inc) {
1135					increment_function(zptr);
1136				} else {
1137					decrement_function(zptr);
1138				}
1139			}
1140			if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1141				ZVAL_COPY(EX_VAR(opline->result.var), zptr);
1142			}
1143		} else {
1144			zend_pre_incdec_overloaded_property(object, property, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), inc, (UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL));
1145		}
1146	} while (0);
1147
1148	FREE_OP2();
1149	FREE_OP1_VAR_PTR();
1150	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1151}
1152
1153ZEND_VM_HANDLER(132, ZEND_PRE_INC_OBJ, VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
1154{
1155	ZEND_VM_DISPATCH_TO_HELPER(zend_pre_incdec_property_helper, inc, 1);
1156}
1157
1158ZEND_VM_HANDLER(133, ZEND_PRE_DEC_OBJ, VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
1159{
1160	ZEND_VM_DISPATCH_TO_HELPER(zend_pre_incdec_property_helper, inc, 0);
1161}
1162
1163ZEND_VM_HELPER(zend_post_incdec_property_helper, VAR|UNUSED|CV, CONST|TMPVAR|CV, int inc)
1164{
1165	USE_OPLINE
1166	zend_free_op free_op1, free_op2;
1167	zval *object;
1168	zval *property;
1169	zval *zptr;
1170
1171	SAVE_OPLINE();
1172	object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
1173
1174	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(object) == NULL)) {
1175		zend_throw_error(NULL, "Using $this when not in object context");
1176		FREE_UNFETCHED_OP2();
1177		HANDLE_EXCEPTION();
1178	}
1179
1180	property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1181
1182	do {
1183		if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
1184			ZVAL_DEREF(object);
1185			if (UNEXPECTED(!make_real_object(object))) {
1186				zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
1187				ZVAL_NULL(EX_VAR(opline->result.var));
1188				break;
1189			}
1190		}
1191
1192		/* here we are sure we are dealing with an object */
1193
1194		if (EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
1195			&& EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL))) != NULL)) {
1196
1197			if (EXPECTED(Z_TYPE_P(zptr) == IS_LONG)) {
1198				ZVAL_COPY_VALUE(EX_VAR(opline->result.var), zptr);
1199				if (inc) {
1200					fast_long_increment_function(zptr);
1201				} else {
1202					fast_long_decrement_function(zptr);
1203				}
1204			} else {
1205				ZVAL_DEREF(zptr);
1206				ZVAL_COPY_VALUE(EX_VAR(opline->result.var), zptr);
1207				zval_opt_copy_ctor(zptr);
1208				if (inc) {
1209					increment_function(zptr);
1210				} else {
1211					decrement_function(zptr);
1212				}
1213			}
1214		} else {
1215			zend_post_incdec_overloaded_property(object, property, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), inc, EX_VAR(opline->result.var));
1216		}
1217	} while (0);
1218
1219	FREE_OP2();
1220	FREE_OP1_VAR_PTR();
1221	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1222}
1223
1224ZEND_VM_HANDLER(134, ZEND_POST_INC_OBJ, VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
1225{
1226	ZEND_VM_DISPATCH_TO_HELPER(zend_post_incdec_property_helper, inc, 1);
1227}
1228
1229ZEND_VM_HANDLER(135, ZEND_POST_DEC_OBJ, VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
1230{
1231	ZEND_VM_DISPATCH_TO_HELPER(zend_post_incdec_property_helper, inc, 0);
1232}
1233
1234ZEND_VM_HANDLER(34, ZEND_PRE_INC, VAR|CV, ANY, SPEC(RETVAL))
1235{
1236	USE_OPLINE
1237	zend_free_op free_op1;
1238	zval *var_ptr;
1239
1240	var_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_RW);
1241
1242	if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1243		fast_long_increment_function(var_ptr);
1244		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1245			ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1246		}
1247		ZEND_VM_NEXT_OPCODE();
1248	}
1249
1250	if (OP1_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(var_ptr))) {
1251		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1252			ZVAL_NULL(EX_VAR(opline->result.var));
1253		}
1254		ZEND_VM_NEXT_OPCODE();
1255	}
1256
1257	SAVE_OPLINE();
1258	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var_ptr) == IS_UNDEF)) {
1259		var_ptr = GET_OP1_UNDEF_CV(var_ptr, BP_VAR_RW);
1260	}
1261	ZVAL_DEREF(var_ptr);
1262	SEPARATE_ZVAL_NOREF(var_ptr);
1263
1264	increment_function(var_ptr);
1265
1266	if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1267		ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
1268	}
1269
1270	FREE_OP1_VAR_PTR();
1271	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1272}
1273
1274ZEND_VM_HANDLER(35, ZEND_PRE_DEC, VAR|CV, ANY, SPEC(RETVAL))
1275{
1276	USE_OPLINE
1277	zend_free_op free_op1;
1278	zval *var_ptr;
1279
1280	var_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_RW);
1281
1282	if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1283		fast_long_decrement_function(var_ptr);
1284		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1285			ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1286		}
1287		ZEND_VM_NEXT_OPCODE();
1288	}
1289
1290	if (OP1_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(var_ptr))) {
1291		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1292			ZVAL_NULL(EX_VAR(opline->result.var));
1293		}
1294		ZEND_VM_NEXT_OPCODE();
1295	}
1296
1297	SAVE_OPLINE();
1298	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var_ptr) == IS_UNDEF)) {
1299		var_ptr = GET_OP1_UNDEF_CV(var_ptr, BP_VAR_RW);
1300	}
1301	ZVAL_DEREF(var_ptr);
1302	SEPARATE_ZVAL_NOREF(var_ptr);
1303
1304	decrement_function(var_ptr);
1305
1306	if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1307		ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
1308	}
1309
1310	FREE_OP1_VAR_PTR();
1311	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1312}
1313
1314ZEND_VM_HANDLER(36, ZEND_POST_INC, VAR|CV, ANY)
1315{
1316	USE_OPLINE
1317	zend_free_op free_op1;
1318	zval *var_ptr;
1319
1320	var_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_RW);
1321
1322	if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1323		ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1324		fast_long_increment_function(var_ptr);
1325		ZEND_VM_NEXT_OPCODE();
1326	}
1327
1328	if (OP1_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(var_ptr))) {
1329		ZVAL_NULL(EX_VAR(opline->result.var));
1330		ZEND_VM_NEXT_OPCODE();
1331	}
1332
1333	SAVE_OPLINE();
1334	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var_ptr) == IS_UNDEF)) {
1335		var_ptr = GET_OP1_UNDEF_CV(var_ptr, BP_VAR_RW);
1336	}
1337	ZVAL_DEREF(var_ptr);
1338	ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1339	zval_opt_copy_ctor(var_ptr);
1340
1341	increment_function(var_ptr);
1342
1343	FREE_OP1_VAR_PTR();
1344	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1345}
1346
1347ZEND_VM_HANDLER(37, ZEND_POST_DEC, VAR|CV, ANY)
1348{
1349	USE_OPLINE
1350	zend_free_op free_op1;
1351	zval *var_ptr;
1352
1353	var_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_RW);
1354
1355	if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1356		ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1357		fast_long_decrement_function(var_ptr);
1358		ZEND_VM_NEXT_OPCODE();
1359	}
1360
1361	if (OP1_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(var_ptr))) {
1362		ZVAL_NULL(EX_VAR(opline->result.var));
1363		ZEND_VM_NEXT_OPCODE();
1364	}
1365
1366	SAVE_OPLINE();
1367	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var_ptr) == IS_UNDEF)) {
1368		var_ptr = GET_OP1_UNDEF_CV(var_ptr, BP_VAR_RW);
1369	}
1370	ZVAL_DEREF(var_ptr);
1371	ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1372	zval_opt_copy_ctor(var_ptr);
1373
1374	decrement_function(var_ptr);
1375
1376	FREE_OP1_VAR_PTR();
1377	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1378}
1379
1380ZEND_VM_HANDLER(40, ZEND_ECHO, CONST|TMPVAR|CV, ANY)
1381{
1382	USE_OPLINE
1383	zend_free_op free_op1;
1384	zval *z;
1385
1386	SAVE_OPLINE();
1387	z = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
1388
1389	if (Z_TYPE_P(z) == IS_STRING) {
1390		zend_string *str = Z_STR_P(z);
1391
1392		if (ZSTR_LEN(str) != 0) {
1393			zend_write(ZSTR_VAL(str), ZSTR_LEN(str));
1394		}
1395	} else {
1396		zend_string *str = _zval_get_string_func(z);
1397
1398		if (ZSTR_LEN(str) != 0) {
1399			zend_write(ZSTR_VAL(str), ZSTR_LEN(str));
1400		} else if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(z) == IS_UNDEF)) {
1401			GET_OP1_UNDEF_CV(z, BP_VAR_R);
1402		}
1403		zend_string_release(str);
1404	}
1405
1406	FREE_OP1();
1407	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1408}
1409
1410ZEND_VM_HELPER(zend_fetch_var_address_helper, CONST|TMPVAR|CV, UNUSED, int type)
1411{
1412	USE_OPLINE
1413	zend_free_op free_op1;
1414	zval *varname;
1415	zval *retval;
1416	zend_string *name;
1417	HashTable *target_symbol_table;
1418
1419	SAVE_OPLINE();
1420	varname = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
1421
1422 	if (OP1_TYPE == IS_CONST) {
1423		name = Z_STR_P(varname);
1424	} else if (EXPECTED(Z_TYPE_P(varname) == IS_STRING)) {
1425		name = Z_STR_P(varname);
1426		zend_string_addref(name);
1427	} else {
1428		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(varname) == IS_UNDEF)) {
1429			GET_OP1_UNDEF_CV(varname, BP_VAR_R);
1430		}
1431		name = zval_get_string(varname);
1432	}
1433
1434	target_symbol_table = zend_get_target_symbol_table(execute_data, opline->extended_value & ZEND_FETCH_TYPE_MASK);
1435	retval = zend_hash_find(target_symbol_table, name);
1436	if (retval == NULL) {
1437		switch (type) {
1438			case BP_VAR_R:
1439			case BP_VAR_UNSET:
1440				zend_error(E_NOTICE,"Undefined variable: %s", ZSTR_VAL(name));
1441				/* break missing intentionally */
1442			case BP_VAR_IS:
1443				retval = &EG(uninitialized_zval);
1444				break;
1445			case BP_VAR_RW:
1446				zend_error(E_NOTICE,"Undefined variable: %s", ZSTR_VAL(name));
1447				retval = zend_hash_update(target_symbol_table, name, &EG(uninitialized_zval));
1448				break;
1449			case BP_VAR_W:
1450				retval = zend_hash_add_new(target_symbol_table, name, &EG(uninitialized_zval));
1451				break;
1452			EMPTY_SWITCH_DEFAULT_CASE()
1453		}
1454	/* GLOBAL or $$name variable may be an INDIRECT pointer to CV */
1455	} else if (Z_TYPE_P(retval) == IS_INDIRECT) {
1456		retval = Z_INDIRECT_P(retval);
1457		if (Z_TYPE_P(retval) == IS_UNDEF) {
1458			switch (type) {
1459				case BP_VAR_R:
1460				case BP_VAR_UNSET:
1461					zend_error(E_NOTICE,"Undefined variable: %s", ZSTR_VAL(name));
1462					/* break missing intentionally */
1463				case BP_VAR_IS:
1464					retval = &EG(uninitialized_zval);
1465					break;
1466				case BP_VAR_RW:
1467					zend_error(E_NOTICE,"Undefined variable: %s", ZSTR_VAL(name));
1468					/* break missing intentionally */
1469				case BP_VAR_W:
1470					ZVAL_NULL(retval);
1471					break;
1472				EMPTY_SWITCH_DEFAULT_CASE()
1473			}
1474		}
1475	}
1476
1477	if ((opline->extended_value & ZEND_FETCH_TYPE_MASK) != ZEND_FETCH_GLOBAL_LOCK) {
1478		FREE_OP1();
1479	}
1480
1481	if (OP1_TYPE != IS_CONST) {
1482		zend_string_release(name);
1483	}
1484
1485	ZEND_ASSERT(retval != NULL);
1486	if (type == BP_VAR_R || type == BP_VAR_IS) {
1487		if (/*type == BP_VAR_R &&*/ Z_ISREF_P(retval) && Z_REFCOUNT_P(retval) == 1) {
1488			ZVAL_UNREF(retval);
1489		}
1490		ZVAL_COPY(EX_VAR(opline->result.var), retval);
1491	} else {
1492		ZVAL_INDIRECT(EX_VAR(opline->result.var), retval);
1493	}
1494	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1495}
1496
1497ZEND_VM_HANDLER(80, ZEND_FETCH_R, CONST|TMPVAR|CV, UNUSED, VAR_FETCH)
1498{
1499	ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_var_address_helper, type, BP_VAR_R);
1500}
1501
1502ZEND_VM_HANDLER(83, ZEND_FETCH_W, CONST|TMPVAR|CV, UNUSED, VAR_FETCH)
1503{
1504	ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_var_address_helper, type, BP_VAR_W);
1505}
1506
1507ZEND_VM_HANDLER(86, ZEND_FETCH_RW, CONST|TMPVAR|CV, UNUSED, VAR_FETCH)
1508{
1509	ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_var_address_helper, type, BP_VAR_RW);
1510}
1511
1512ZEND_VM_HANDLER(92, ZEND_FETCH_FUNC_ARG, CONST|TMPVAR|CV, UNUSED, VAR_FETCH|ARG_NUM)
1513{
1514	USE_OPLINE
1515
1516	if (zend_is_by_ref_func_arg_fetch(opline, EX(call))) {
1517		ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_var_address_helper, type, BP_VAR_W);
1518	} else {
1519		ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_var_address_helper, type, BP_VAR_R);
1520	}
1521}
1522
1523ZEND_VM_HANDLER(95, ZEND_FETCH_UNSET, CONST|TMPVAR|CV, UNUSED, VAR_FETCH)
1524{
1525	ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_var_address_helper, type, BP_VAR_UNSET);
1526}
1527
1528ZEND_VM_HANDLER(89, ZEND_FETCH_IS, CONST|TMPVAR|CV, UNUSED, VAR_FETCH)
1529{
1530	ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_var_address_helper, type, BP_VAR_IS);
1531}
1532
1533ZEND_VM_HELPER(zend_fetch_static_prop_helper, CONST|TMPVAR|CV, UNUSED|CONST|VAR, int type)
1534{
1535	USE_OPLINE
1536	zend_free_op free_op1;
1537	zval *varname;
1538	zval *retval;
1539	zend_string *name;
1540	zend_class_entry *ce;
1541
1542	SAVE_OPLINE();
1543	varname = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
1544
1545 	if (OP1_TYPE == IS_CONST) {
1546		name = Z_STR_P(varname);
1547	} else if (EXPECTED(Z_TYPE_P(varname) == IS_STRING)) {
1548		name = Z_STR_P(varname);
1549		zend_string_addref(name);
1550	} else {
1551		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(varname) == IS_UNDEF)) {
1552			GET_OP1_UNDEF_CV(varname, BP_VAR_R);
1553		}
1554		name = zval_get_string(varname);
1555	}
1556
1557	if (OP2_TYPE == IS_CONST) {
1558		if (OP1_TYPE == IS_CONST && EXPECTED((ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)))) != NULL)) {
1559			retval = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)) + sizeof(void*));
1560
1561			/* check if static properties were destoyed */
1562			if (UNEXPECTED(CE_STATIC_MEMBERS(ce) == NULL)) {
1563				zend_throw_error(NULL, "Access to undeclared static property: %s::$%s", ZSTR_VAL(ce->name), ZSTR_VAL(name));
1564				FREE_OP1();
1565				HANDLE_EXCEPTION();
1566			}
1567
1568			ZEND_VM_C_GOTO(fetch_static_prop_return);
1569		} else if (UNEXPECTED((ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) == NULL)) {
1570			ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op2)), EX_CONSTANT(opline->op2) + 1, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
1571			if (UNEXPECTED(ce == NULL)) {
1572				if (OP1_TYPE != IS_CONST) {
1573					zend_string_release(name);
1574				}
1575				FREE_OP1();
1576				ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1577			}
1578			CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce);
1579		}
1580	} else {
1581		if (OP2_TYPE == IS_UNUSED) {
1582			ce = zend_fetch_class(NULL, opline->op2.num);
1583			if (UNEXPECTED(ce == NULL)) {
1584				ZEND_ASSERT(EG(exception));
1585				if (OP1_TYPE != IS_CONST) {
1586					zend_string_release(name);
1587				}
1588				FREE_OP1();
1589				HANDLE_EXCEPTION();
1590			}
1591		} else {
1592			ce = Z_CE_P(EX_VAR(opline->op2.var));
1593		}
1594		if (OP1_TYPE == IS_CONST &&
1595		    (retval = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce)) != NULL) {
1596
1597			/* check if static properties were destoyed */
1598			if (UNEXPECTED(CE_STATIC_MEMBERS(ce) == NULL)) {
1599				zend_throw_error(NULL, "Access to undeclared static property: %s::$%s", ZSTR_VAL(ce->name), ZSTR_VAL(name));
1600				FREE_OP1();
1601				HANDLE_EXCEPTION();
1602			}
1603
1604			ZEND_VM_C_GOTO(fetch_static_prop_return);
1605		}
1606	}
1607	retval = zend_std_get_static_property(ce, name, 0);
1608	if (UNEXPECTED(EG(exception))) {
1609		if (OP1_TYPE != IS_CONST) {
1610			zend_string_release(name);
1611		}
1612		FREE_OP1();
1613		HANDLE_EXCEPTION();
1614	}
1615	if (OP1_TYPE == IS_CONST && retval) {
1616		CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce, retval);
1617	}
1618
1619	FREE_OP1();
1620
1621	if (OP1_TYPE != IS_CONST) {
1622		zend_string_release(name);
1623	}
1624
1625ZEND_VM_C_LABEL(fetch_static_prop_return):
1626	ZEND_ASSERT(retval != NULL);
1627	if (type == BP_VAR_R || type == BP_VAR_IS) {
1628		if (/*type == BP_VAR_R &&*/ Z_ISREF_P(retval) && Z_REFCOUNT_P(retval) == 1) {
1629			ZVAL_UNREF(retval);
1630		}
1631		ZVAL_COPY(EX_VAR(opline->result.var), retval);
1632	} else {
1633		ZVAL_INDIRECT(EX_VAR(opline->result.var), retval);
1634	}
1635	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1636}
1637
1638ZEND_VM_HANDLER(173, ZEND_FETCH_STATIC_PROP_R, CONST|TMPVAR|CV, UNUSED|CLASS_FETCH|CONST|VAR)
1639{
1640	ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_static_prop_helper, type, BP_VAR_R);
1641}
1642
1643ZEND_VM_HANDLER(174, ZEND_FETCH_STATIC_PROP_W, CONST|TMPVAR|CV, UNUSED|CLASS_FETCH|CONST|VAR)
1644{
1645	ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_static_prop_helper, type, BP_VAR_W);
1646}
1647
1648ZEND_VM_HANDLER(175, ZEND_FETCH_STATIC_PROP_RW, CONST|TMPVAR|CV, UNUSED|CLASS_FETCH|CONST|VAR)
1649{
1650	ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_static_prop_helper, type, BP_VAR_RW);
1651}
1652
1653ZEND_VM_HANDLER(177, ZEND_FETCH_STATIC_PROP_FUNC_ARG, CONST|TMPVAR|CV, UNUSED|CLASS_FETCH|CONST|VAR, NUM)
1654{
1655	USE_OPLINE
1656
1657	if (zend_is_by_ref_func_arg_fetch(opline, EX(call))) {
1658		ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_static_prop_helper, type, BP_VAR_W);
1659	} else {
1660		ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_static_prop_helper, type, BP_VAR_R);
1661	}
1662}
1663
1664ZEND_VM_HANDLER(178, ZEND_FETCH_STATIC_PROP_UNSET, CONST|TMPVAR|CV, UNUSED|CLASS_FETCH|CONST|VAR)
1665{
1666	ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_static_prop_helper, type, BP_VAR_UNSET);
1667}
1668
1669ZEND_VM_HANDLER(176, ZEND_FETCH_STATIC_PROP_IS, CONST|TMPVAR|CV, UNUSED|CLASS_FETCH|CONST|VAR)
1670{
1671	ZEND_VM_DISPATCH_TO_HELPER(zend_fetch_static_prop_helper, type, BP_VAR_IS);
1672}
1673
1674ZEND_VM_HANDLER(81, ZEND_FETCH_DIM_R, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
1675{
1676	USE_OPLINE
1677	zend_free_op free_op1, free_op2;
1678	zval *container;
1679
1680	SAVE_OPLINE();
1681	container = GET_OP1_ZVAL_PTR(BP_VAR_R);
1682	zend_fetch_dimension_address_read_R(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1683	FREE_OP2();
1684	FREE_OP1();
1685	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1686}
1687
1688ZEND_VM_HANDLER(84, ZEND_FETCH_DIM_W, VAR|CV, CONST|TMPVAR|UNUSED|NEXT|CV)
1689{
1690	USE_OPLINE
1691	zend_free_op free_op1, free_op2;
1692	zval *container;
1693
1694	SAVE_OPLINE();
1695	container = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1696
1697	zend_fetch_dimension_address_W(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1698	FREE_OP2();
1699	if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1700		EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1701	}
1702	FREE_OP1_VAR_PTR();
1703	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1704}
1705
1706ZEND_VM_HANDLER(87, ZEND_FETCH_DIM_RW, VAR|CV, CONST|TMPVAR|UNUSED|NEXT|CV)
1707{
1708	USE_OPLINE
1709	zend_free_op free_op1, free_op2;
1710	zval *container;
1711
1712	SAVE_OPLINE();
1713	container = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
1714
1715	zend_fetch_dimension_address_RW(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1716	FREE_OP2();
1717	if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1718		EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1719	}
1720	FREE_OP1_VAR_PTR();
1721	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1722}
1723
1724ZEND_VM_HANDLER(90, ZEND_FETCH_DIM_IS, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
1725{
1726	USE_OPLINE
1727	zend_free_op free_op1, free_op2;
1728	zval *container;
1729
1730	SAVE_OPLINE();
1731	container = GET_OP1_ZVAL_PTR(BP_VAR_IS);
1732	zend_fetch_dimension_address_read_IS(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1733	FREE_OP2();
1734	FREE_OP1();
1735	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1736}
1737
1738ZEND_VM_HANDLER(93, ZEND_FETCH_DIM_FUNC_ARG, CONST|TMP|VAR|CV, CONST|TMPVAR|UNUSED|NEXT|CV, NUM)
1739{
1740	USE_OPLINE
1741	zval *container;
1742	zend_free_op free_op1, free_op2;
1743
1744	SAVE_OPLINE();
1745
1746	if (zend_is_by_ref_func_arg_fetch(opline, EX(call))) {
1747        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
1748            zend_throw_error(NULL, "Cannot use temporary expression in write context");
1749			FREE_UNFETCHED_OP2();
1750			FREE_UNFETCHED_OP1();
1751			HANDLE_EXCEPTION();
1752        }
1753		container = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1754		zend_fetch_dimension_address_W(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1755		if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1756			EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1757		}
1758		FREE_OP2();
1759		FREE_OP1_VAR_PTR();
1760	} else {
1761		if (OP2_TYPE == IS_UNUSED) {
1762			zend_throw_error(NULL, "Cannot use [] for reading");
1763			FREE_UNFETCHED_OP2();
1764			FREE_UNFETCHED_OP1();
1765			HANDLE_EXCEPTION();
1766		}
1767		container = GET_OP1_ZVAL_PTR(BP_VAR_R);
1768		zend_fetch_dimension_address_read_R(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1769		FREE_OP2();
1770		FREE_OP1();
1771	}
1772	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1773}
1774
1775ZEND_VM_HANDLER(96, ZEND_FETCH_DIM_UNSET, VAR|CV, CONST|TMPVAR|CV)
1776{
1777	USE_OPLINE
1778	zend_free_op free_op1, free_op2;
1779	zval *container;
1780
1781	SAVE_OPLINE();
1782	container = GET_OP1_ZVAL_PTR_PTR(BP_VAR_UNSET);
1783
1784	zend_fetch_dimension_address_UNSET(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1785	FREE_OP2();
1786	if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1787		EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1788	}
1789	FREE_OP1_VAR_PTR();
1790	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1791}
1792
1793ZEND_VM_HANDLER(82, ZEND_FETCH_OBJ_R, CONST|TMP|VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
1794{
1795	USE_OPLINE
1796	zend_free_op free_op1;
1797	zval *container;
1798	zend_free_op free_op2;
1799	zval *offset;
1800
1801	SAVE_OPLINE();
1802	container = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_R);
1803
1804	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
1805		zend_throw_error(NULL, "Using $this when not in object context");
1806		FREE_UNFETCHED_OP2();
1807		HANDLE_EXCEPTION();
1808	}
1809
1810	offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
1811
1812	if (OP1_TYPE == IS_CONST ||
1813	    (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT))) {
1814		if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(container)) {
1815			container = Z_REFVAL_P(container);
1816			if (UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
1817				ZEND_VM_C_GOTO(fetch_obj_r_no_object);
1818			}
1819		} else {
1820			ZEND_VM_C_GOTO(fetch_obj_r_no_object);
1821		}
1822	}
1823
1824	/* here we are sure we are dealing with an object */
1825	do {
1826		zend_object *zobj = Z_OBJ_P(container);
1827		zval *retval;
1828
1829		if (OP2_TYPE == IS_CONST &&
1830			EXPECTED(zobj->ce == CACHED_PTR(Z_CACHE_SLOT_P(offset)))) {
1831			uint32_t prop_offset = (uint32_t)(intptr_t)CACHED_PTR(Z_CACHE_SLOT_P(offset) + sizeof(void*));
1832
1833			if (EXPECTED(prop_offset != (uint32_t)ZEND_DYNAMIC_PROPERTY_OFFSET)) {
1834				retval = OBJ_PROP(zobj, prop_offset);
1835				if (EXPECTED(Z_TYPE_P(retval) != IS_UNDEF)) {
1836					ZVAL_COPY(EX_VAR(opline->result.var), retval);
1837					break;
1838				}
1839			} else if (EXPECTED(zobj->properties != NULL)) {
1840				retval = zend_hash_find(zobj->properties, Z_STR_P(offset));
1841				if (EXPECTED(retval)) {
1842					ZVAL_COPY(EX_VAR(opline->result.var), retval);
1843					break;
1844				}
1845			}
1846		}
1847
1848		if (UNEXPECTED(zobj->handlers->read_property == NULL)) {
1849ZEND_VM_C_LABEL(fetch_obj_r_no_object):
1850			zend_error(E_NOTICE, "Trying to get property of non-object");
1851			ZVAL_NULL(EX_VAR(opline->result.var));
1852		} else {
1853			retval = zobj->handlers->read_property(container, offset, BP_VAR_R, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(offset)) : NULL), EX_VAR(opline->result.var));
1854
1855			if (retval != EX_VAR(opline->result.var)) {
1856				ZVAL_COPY(EX_VAR(opline->result.var), retval);
1857			}
1858		}
1859	} while (0);
1860
1861	FREE_OP2();
1862	FREE_OP1();
1863	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1864}
1865
1866ZEND_VM_HANDLER(85, ZEND_FETCH_OBJ_W, VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
1867{
1868	USE_OPLINE
1869	zend_free_op free_op1, free_op2;
1870	zval *property;
1871	zval *container;
1872
1873	SAVE_OPLINE();
1874	property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1875
1876	container = GET_OP1_OBJ_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1877	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
1878		zend_throw_error(NULL, "Using $this when not in object context");
1879		FREE_OP2();
1880		HANDLE_EXCEPTION();
1881	}
1882
1883	zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_W);
1884	FREE_OP2();
1885	if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1886		EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1887	}
1888	FREE_OP1_VAR_PTR();
1889	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1890}
1891
1892ZEND_VM_HANDLER(88, ZEND_FETCH_OBJ_RW, VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
1893{
1894	USE_OPLINE
1895	zend_free_op free_op1, free_op2;
1896	zval *property;
1897	zval *container;
1898
1899	SAVE_OPLINE();
1900	property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1901	container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
1902
1903	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
1904		zend_throw_error(NULL, "Using $this when not in object context");
1905		FREE_OP2();
1906		HANDLE_EXCEPTION();
1907	}
1908	zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_RW);
1909	FREE_OP2();
1910	if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1911		EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1912	}
1913	FREE_OP1_VAR_PTR();
1914	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1915}
1916
1917ZEND_VM_HANDLER(91, ZEND_FETCH_OBJ_IS, CONST|TMPVAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
1918{
1919	USE_OPLINE
1920	zend_free_op free_op1;
1921	zval *container;
1922	zend_free_op free_op2;
1923	zval *offset;
1924
1925	SAVE_OPLINE();
1926	container = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_IS);
1927
1928	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
1929		zend_throw_error(NULL, "Using $this when not in object context");
1930		FREE_UNFETCHED_OP2();
1931		HANDLE_EXCEPTION();
1932	}
1933
1934	offset  = GET_OP2_ZVAL_PTR(BP_VAR_R);
1935
1936	if (OP1_TYPE == IS_CONST ||
1937	    (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT))) {
1938		if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(container)) {
1939			container = Z_REFVAL_P(container);
1940			if (UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
1941				ZEND_VM_C_GOTO(fetch_obj_is_no_object);
1942			}
1943		} else {
1944			ZEND_VM_C_GOTO(fetch_obj_is_no_object);
1945		}
1946	}
1947
1948	/* here we are sure we are dealing with an object */
1949	do {
1950		zend_object *zobj = Z_OBJ_P(container);
1951		zval *retval;
1952
1953		if (OP2_TYPE == IS_CONST &&
1954			EXPECTED(zobj->ce == CACHED_PTR(Z_CACHE_SLOT_P(offset)))) {
1955			uint32_t prop_offset = (uint32_t)(intptr_t)CACHED_PTR(Z_CACHE_SLOT_P(offset) + sizeof(void*));
1956
1957			if (EXPECTED(prop_offset != (uint32_t)ZEND_DYNAMIC_PROPERTY_OFFSET)) {
1958				retval = OBJ_PROP(zobj, prop_offset);
1959				if (EXPECTED(Z_TYPE_P(retval) != IS_UNDEF)) {
1960					ZVAL_COPY(EX_VAR(opline->result.var), retval);
1961					break;
1962				}
1963			} else if (EXPECTED(zobj->properties != NULL)) {
1964				retval = zend_hash_find(zobj->properties, Z_STR_P(offset));
1965				if (EXPECTED(retval)) {
1966					ZVAL_COPY(EX_VAR(opline->result.var), retval);
1967					break;
1968				}
1969			}
1970		}
1971
1972		if (UNEXPECTED(zobj->handlers->read_property == NULL)) {
1973ZEND_VM_C_LABEL(fetch_obj_is_no_object):
1974			ZVAL_NULL(EX_VAR(opline->result.var));
1975		} else {
1976
1977			retval = zobj->handlers->read_property(container, offset, BP_VAR_IS, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(offset)) : NULL), EX_VAR(opline->result.var));
1978
1979			if (retval != EX_VAR(opline->result.var)) {
1980				ZVAL_COPY(EX_VAR(opline->result.var), retval);
1981			}
1982		}
1983	} while (0);
1984
1985	FREE_OP2();
1986	FREE_OP1();
1987	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
1988}
1989
1990ZEND_VM_HANDLER(94, ZEND_FETCH_OBJ_FUNC_ARG, CONST|TMP|VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV, NUM)
1991{
1992	USE_OPLINE
1993	zval *container;
1994
1995	if (zend_is_by_ref_func_arg_fetch(opline, EX(call))) {
1996		/* Behave like FETCH_OBJ_W */
1997		zend_free_op free_op1, free_op2;
1998		zval *property;
1999
2000		SAVE_OPLINE();
2001		property = GET_OP2_ZVAL_PTR(BP_VAR_R);
2002		container = GET_OP1_OBJ_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
2003
2004		if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
2005			zend_throw_error(NULL, "Using $this when not in object context");
2006			FREE_OP2();
2007			HANDLE_EXCEPTION();
2008		}
2009		if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
2010			zend_throw_error(NULL, "Cannot use temporary expression in write context");
2011			FREE_OP2();
2012			FREE_OP1_VAR_PTR();
2013			HANDLE_EXCEPTION();
2014		}
2015		zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_W);
2016		FREE_OP2();
2017		if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
2018			EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
2019		}
2020		FREE_OP1_VAR_PTR();
2021		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2022	} else {
2023		ZEND_VM_DISPATCH_TO_HANDLER(ZEND_FETCH_OBJ_R);
2024	}
2025}
2026
2027ZEND_VM_HANDLER(97, ZEND_FETCH_OBJ_UNSET, VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
2028{
2029	USE_OPLINE
2030	zend_free_op free_op1, free_op2;
2031	zval *container, *property;
2032
2033	SAVE_OPLINE();
2034	container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_UNSET);
2035
2036	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
2037		zend_throw_error(NULL, "Using $this when not in object context");
2038		FREE_UNFETCHED_OP2();
2039		HANDLE_EXCEPTION();
2040	}
2041
2042	property = GET_OP2_ZVAL_PTR(BP_VAR_R);
2043
2044	zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_UNSET);
2045	FREE_OP2();
2046	if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
2047		EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
2048	}
2049	FREE_OP1_VAR_PTR();
2050	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2051}
2052
2053ZEND_VM_HANDLER(98, ZEND_FETCH_LIST, CONST|TMPVAR|CV, CONST)
2054{
2055	USE_OPLINE
2056	zend_free_op free_op1;
2057	zval *container;
2058
2059	SAVE_OPLINE();
2060	container = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2061
2062ZEND_VM_C_LABEL(try_fetch_list):
2063	if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
2064		zval *value = zend_hash_index_find(Z_ARRVAL_P(container), Z_LVAL_P(EX_CONSTANT(opline->op2)));
2065
2066		if (UNEXPECTED(value == NULL)) {
2067			zend_error(E_NOTICE,"Undefined offset: " ZEND_ULONG_FMT, Z_LVAL_P(EX_CONSTANT(opline->op2)));
2068			ZVAL_NULL(EX_VAR(opline->result.var));
2069		} else {
2070			ZVAL_COPY(EX_VAR(opline->result.var), value);
2071		}
2072	} else if (OP1_TYPE != IS_CONST &&
2073	           UNEXPECTED(Z_TYPE_P(container) == IS_OBJECT) &&
2074	           EXPECTED(Z_OBJ_HT_P(container)->read_dimension)) {
2075		zval *result = EX_VAR(opline->result.var);
2076		zval *retval = Z_OBJ_HT_P(container)->read_dimension(container, EX_CONSTANT(opline->op2), BP_VAR_R, result);
2077
2078		if (retval) {
2079			if (result != retval) {
2080				ZVAL_COPY(result, retval);
2081			}
2082		} else {
2083			ZVAL_NULL(result);
2084		}
2085	} else if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_TYPE_P(container) == IS_REFERENCE) {
2086		container = Z_REFVAL_P(container);
2087		ZEND_VM_C_GOTO(try_fetch_list);
2088	} else {
2089		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(container) == IS_UNDEF)) {
2090			GET_OP1_UNDEF_CV(container, BP_VAR_R);
2091		}
2092		ZVAL_NULL(EX_VAR(opline->result.var));
2093	}
2094	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2095}
2096
2097ZEND_VM_HANDLER(136, ZEND_ASSIGN_OBJ, VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV, SPEC(OP_DATA=CONST|TMP|VAR|CV))
2098{
2099	USE_OPLINE
2100	zend_free_op free_op1, free_op2, free_op_data;
2101	zval *object, *property_name, *value, tmp;
2102
2103	SAVE_OPLINE();
2104	object = GET_OP1_OBJ_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
2105
2106	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(object) == NULL)) {
2107		zend_throw_error(NULL, "Using $this when not in object context");
2108		FREE_UNFETCHED_OP2();
2109		HANDLE_EXCEPTION();
2110	}
2111
2112	property_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2113	value = GET_OP_DATA_ZVAL_PTR(BP_VAR_R);
2114
2115	if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
2116		do {
2117			if (OP1_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(object))) {
2118				if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2119					ZVAL_NULL(EX_VAR(opline->result.var));
2120				}
2121				FREE_OP_DATA();
2122				ZEND_VM_C_GOTO(exit_assign_obj);
2123			}
2124			if (Z_ISREF_P(object)) {
2125				object = Z_REFVAL_P(object);
2126				if (EXPECTED(Z_TYPE_P(object) == IS_OBJECT)) {
2127					break;
2128				}
2129			}
2130			if (EXPECTED(Z_TYPE_P(object) <= IS_FALSE ||
2131			    (Z_TYPE_P(object) == IS_STRING && Z_STRLEN_P(object) == 0))) {
2132				zend_object *obj;
2133
2134				zval_ptr_dtor(object);
2135				object_init(object);
2136				Z_ADDREF_P(object);
2137				obj = Z_OBJ_P(object);
2138				zend_error(E_WARNING, "Creating default object from empty value");
2139				if (GC_REFCOUNT(obj) == 1) {
2140					/* the enclosing container was deleted, obj is unreferenced */
2141					if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2142						ZVAL_NULL(EX_VAR(opline->result.var));
2143					}
2144					FREE_OP_DATA();
2145					OBJ_RELEASE(obj);
2146					ZEND_VM_C_GOTO(exit_assign_obj);
2147				}
2148				Z_DELREF_P(object);
2149			} else {
2150				zend_error(E_WARNING, "Attempt to assign property of non-object");
2151				if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2152					ZVAL_NULL(EX_VAR(opline->result.var));
2153				}
2154				FREE_OP_DATA();
2155				ZEND_VM_C_GOTO(exit_assign_obj);
2156			}
2157		} while (0);
2158	}
2159
2160	if (OP2_TYPE == IS_CONST &&
2161	    EXPECTED(Z_OBJCE_P(object) == CACHED_PTR(Z_CACHE_SLOT_P(property_name)))) {
2162		uint32_t prop_offset = (uint32_t)(intptr_t)CACHED_PTR(Z_CACHE_SLOT_P(property_name) + sizeof(void*));
2163		zend_object *zobj = Z_OBJ_P(object);
2164		zval *property;
2165
2166		if (EXPECTED(prop_offset != (uint32_t)ZEND_DYNAMIC_PROPERTY_OFFSET)) {
2167			property = OBJ_PROP(zobj, prop_offset);
2168			if (Z_TYPE_P(property) != IS_UNDEF) {
2169ZEND_VM_C_LABEL(fast_assign_obj):
2170				value = zend_assign_to_variable(property, value, OP_DATA_TYPE);
2171				if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2172					ZVAL_COPY(EX_VAR(opline->result.var), value);
2173				}
2174				ZEND_VM_C_GOTO(exit_assign_obj);
2175			}
2176		} else {
2177			if (EXPECTED(zobj->properties != NULL)) {
2178				if (UNEXPECTED(GC_REFCOUNT(zobj->properties) > 1)) {
2179					if (EXPECTED(!(GC_FLAGS(zobj->properties) & IS_ARRAY_IMMUTABLE))) {
2180						GC_REFCOUNT(zobj->properties)--;
2181					}
2182					zobj->properties = zend_array_dup(zobj->properties);
2183				}
2184				property = zend_hash_find(zobj->properties, Z_STR_P(property_name));
2185				if (property) {
2186					ZEND_VM_C_GOTO(fast_assign_obj);
2187				}
2188			}
2189
2190			if (!zobj->ce->__set) {
2191
2192				if (EXPECTED(zobj->properties == NULL)) {
2193					rebuild_object_properties(zobj);
2194				}
2195				/* separate our value if necessary */
2196				if (OP_DATA_TYPE == IS_CONST) {
2197					if (UNEXPECTED(Z_OPT_COPYABLE_P(value))) {
2198						ZVAL_COPY_VALUE(&tmp, value);
2199						zval_copy_ctor_func(&tmp);
2200						value = &tmp;
2201					}
2202				} else if (OP_DATA_TYPE != IS_TMP_VAR) {
2203					if (Z_ISREF_P(value)) {
2204						if (OP_DATA_TYPE == IS_VAR) {
2205							zend_reference *ref = Z_REF_P(value);
2206							if (--GC_REFCOUNT(ref) == 0) {
2207								ZVAL_COPY_VALUE(&tmp, Z_REFVAL_P(value));
2208								efree_size(ref, sizeof(zend_reference));
2209								value = &tmp;
2210							} else {
2211								value = Z_REFVAL_P(value);
2212								if (Z_REFCOUNTED_P(value)) {
2213									Z_ADDREF_P(value);
2214								}
2215							}
2216						} else {
2217							value = Z_REFVAL_P(value);
2218							if (Z_REFCOUNTED_P(value)) {
2219								Z_ADDREF_P(value);
2220							}
2221						}
2222					} else if (OP_DATA_TYPE == IS_CV && Z_REFCOUNTED_P(value)) {
2223						Z_ADDREF_P(value);
2224					}
2225				}
2226				zend_hash_add_new(zobj->properties, Z_STR_P(property_name), value);
2227				if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2228					ZVAL_COPY(EX_VAR(opline->result.var), value);
2229				}
2230				ZEND_VM_C_GOTO(exit_assign_obj);
2231			}
2232		}
2233	}
2234
2235	if (!Z_OBJ_HT_P(object)->write_property) {
2236		zend_error(E_WARNING, "Attempt to assign property of non-object");
2237		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2238			ZVAL_NULL(EX_VAR(opline->result.var));
2239		}
2240		FREE_OP_DATA();
2241		ZEND_VM_C_GOTO(exit_assign_obj);
2242	}
2243
2244	/* separate our value if necessary */
2245	if (OP_DATA_TYPE == IS_CONST) {
2246		if (UNEXPECTED(Z_OPT_COPYABLE_P(value))) {
2247			ZVAL_COPY_VALUE(&tmp, value);
2248			zval_copy_ctor_func(&tmp);
2249			value = &tmp;
2250		}
2251	} else if (OP_DATA_TYPE != IS_TMP_VAR) {
2252		ZVAL_DEREF(value);
2253	}
2254
2255	Z_OBJ_HT_P(object)->write_property(object, property_name, value, (OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(property_name)) : NULL);
2256
2257	if (UNEXPECTED(RETURN_VALUE_USED(opline)) && EXPECTED(!EG(exception))) {
2258		ZVAL_COPY(EX_VAR(opline->result.var), value);
2259	}
2260	if (OP_DATA_TYPE == IS_CONST) {
2261		zval_ptr_dtor_nogc(value);
2262	} else {
2263		FREE_OP_DATA();
2264	}
2265ZEND_VM_C_LABEL(exit_assign_obj):
2266	FREE_OP2();
2267	FREE_OP1_VAR_PTR();
2268	/* assign_obj has two opcodes! */
2269	ZEND_VM_NEXT_OPCODE_EX(1, 2);
2270}
2271
2272ZEND_VM_HANDLER(147, ZEND_ASSIGN_DIM, VAR|CV, CONST|TMPVAR|UNUSED|NEXT|CV, SPEC(OP_DATA=CONST|TMP|VAR|CV))
2273{
2274	USE_OPLINE
2275	zend_free_op free_op1;
2276	zval *object_ptr;
2277	zend_free_op free_op2, free_op_data;
2278	zval *value;
2279	zval *variable_ptr;
2280	zval *dim;
2281
2282	SAVE_OPLINE();
2283	object_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
2284
2285	if (EXPECTED(Z_TYPE_P(object_ptr) == IS_ARRAY)) {
2286ZEND_VM_C_LABEL(try_assign_dim_array):
2287		if (OP2_TYPE == IS_UNUSED) {
2288			SEPARATE_ARRAY(object_ptr);
2289			variable_ptr = zend_hash_next_index_insert(Z_ARRVAL_P(object_ptr), &EG(uninitialized_zval));
2290			if (UNEXPECTED(variable_ptr == NULL)) {
2291				zend_error(E_WARNING, "Cannot add element to the array as the next element is already occupied");
2292				variable_ptr = NULL;
2293			}
2294		} else {
2295			dim = GET_OP2_ZVAL_PTR(BP_VAR_R);
2296			SEPARATE_ARRAY(object_ptr);
2297			variable_ptr = zend_fetch_dimension_address_inner(Z_ARRVAL_P(object_ptr), dim, OP2_TYPE, BP_VAR_W);
2298			FREE_OP2();
2299		}
2300		if (UNEXPECTED(variable_ptr == NULL)) {
2301			FREE_UNFETCHED_OP_DATA();
2302			if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2303				ZVAL_NULL(EX_VAR(opline->result.var));
2304			}
2305		} else {
2306			value = GET_OP_DATA_ZVAL_PTR(BP_VAR_R);
2307			value = zend_assign_to_variable(variable_ptr, value, OP_DATA_TYPE);
2308			if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2309				ZVAL_COPY(EX_VAR(opline->result.var), value);
2310			}
2311		}
2312	} else {
2313		if (EXPECTED(Z_ISREF_P(object_ptr))) {
2314			object_ptr = Z_REFVAL_P(object_ptr);
2315			if (EXPECTED(Z_TYPE_P(object_ptr) == IS_ARRAY)) {
2316				ZEND_VM_C_GOTO(try_assign_dim_array);
2317			}
2318		}
2319		if (EXPECTED(Z_TYPE_P(object_ptr) == IS_OBJECT)) {
2320			zend_free_op free_op2;
2321			zval *property_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2322
2323			zend_assign_to_object_dim(UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL, object_ptr, property_name, OP_DATA_TYPE, (opline+1)->op1, execute_data);
2324			FREE_OP2();
2325		} else if (EXPECTED(Z_TYPE_P(object_ptr) == IS_STRING)) {
2326			if (EXPECTED(Z_STRLEN_P(object_ptr) != 0)) {
2327				if (OP2_TYPE == IS_UNUSED) {
2328					zend_throw_error(NULL, "[] operator not supported for strings");
2329					FREE_UNFETCHED_OP_DATA();
2330					FREE_OP1_VAR_PTR();
2331					HANDLE_EXCEPTION();
2332				} else {
2333					zend_long offset;
2334
2335					dim = GET_OP2_ZVAL_PTR(BP_VAR_R);
2336					offset = zend_fetch_string_offset(object_ptr, dim, BP_VAR_W);
2337					FREE_OP2();
2338					value = GET_OP_DATA_ZVAL_PTR_DEREF(BP_VAR_R);
2339					zend_assign_to_string_offset(object_ptr, offset, value, (UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL));
2340					FREE_OP_DATA();
2341				}
2342			} else {
2343				zval_ptr_dtor_nogc(object_ptr);
2344ZEND_VM_C_LABEL(assign_dim_convert_to_array):
2345				ZVAL_NEW_ARR(object_ptr);
2346				zend_hash_init(Z_ARRVAL_P(object_ptr), 8, NULL, ZVAL_PTR_DTOR, 0);
2347				ZEND_VM_C_GOTO(try_assign_dim_array);
2348			}
2349		} else if (EXPECTED(Z_TYPE_P(object_ptr) <= IS_FALSE)) {
2350			ZEND_VM_C_GOTO(assign_dim_convert_to_array);
2351		} else if (OP1_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(object_ptr))) {
2352			ZEND_VM_C_GOTO(assign_dim_clean);
2353		} else {
2354			zend_error(E_WARNING, "Cannot use a scalar value as an array");
2355ZEND_VM_C_LABEL(assign_dim_clean):
2356			FREE_UNFETCHED_OP2();
2357			FREE_UNFETCHED_OP_DATA();
2358			if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2359				ZVAL_NULL(EX_VAR(opline->result.var));
2360			}
2361		}
2362	}
2363	FREE_OP1_VAR_PTR();
2364	/* assign_dim has two opcodes! */
2365	ZEND_VM_NEXT_OPCODE_EX(1, 2);
2366}
2367
2368ZEND_VM_HANDLER(38, ZEND_ASSIGN, VAR|CV, CONST|TMP|VAR|CV, SPEC(RETVAL))
2369{
2370	USE_OPLINE
2371	zend_free_op free_op1, free_op2;
2372	zval *value;
2373	zval *variable_ptr;
2374
2375	SAVE_OPLINE();
2376	value = GET_OP2_ZVAL_PTR(BP_VAR_R);
2377	variable_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
2378
2379	if (OP1_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(variable_ptr))) {
2380		FREE_OP2();
2381		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2382			ZVAL_NULL(EX_VAR(opline->result.var));
2383		}
2384	} else {
2385		value = zend_assign_to_variable(variable_ptr, value, OP2_TYPE);
2386		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2387			ZVAL_COPY(EX_VAR(opline->result.var), value);
2388		}
2389		FREE_OP1_VAR_PTR();
2390		/* zend_assign_to_variable() always takes care of op2, never free it! */
2391	}
2392
2393	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2394}
2395
2396ZEND_VM_HANDLER(39, ZEND_ASSIGN_REF, VAR|CV, VAR|CV, SRC)
2397{
2398	USE_OPLINE
2399	zend_free_op free_op1, free_op2;
2400	zval *variable_ptr;
2401	zval *value_ptr;
2402
2403	SAVE_OPLINE();
2404	value_ptr = GET_OP2_ZVAL_PTR_PTR(BP_VAR_W);
2405	variable_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
2406
2407	if (OP1_TYPE == IS_VAR &&
2408	    UNEXPECTED(Z_TYPE_P(EX_VAR(opline->op1.var)) != IS_INDIRECT) &&
2409	    UNEXPECTED(!Z_ISREF_P(EX_VAR(opline->op1.var))) &&
2410	    UNEXPECTED(!Z_ISERROR_P(EX_VAR(opline->op1.var)))) {
2411
2412		zend_throw_error(NULL, "Cannot assign by reference to overloaded object");
2413		FREE_OP2_VAR_PTR();
2414		HANDLE_EXCEPTION();
2415
2416	} else if (OP2_TYPE == IS_VAR &&
2417	           opline->extended_value == ZEND_RETURNS_FUNCTION &&
2418	           UNEXPECTED(!(Z_VAR_FLAGS_P(value_ptr) & IS_VAR_RET_REF))) {
2419
2420		zend_error(E_NOTICE, "Only variables should be assigned by reference");
2421		if (UNEXPECTED(EG(exception) != NULL)) {
2422			FREE_OP2_VAR_PTR();
2423			HANDLE_EXCEPTION();
2424		}
2425
2426		value_ptr = zend_assign_to_variable(variable_ptr, value_ptr, OP2_TYPE);
2427		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2428			ZVAL_COPY(EX_VAR(opline->result.var), value_ptr);
2429		}
2430		/* zend_assign_to_variable() always takes care of op2, never free it! */
2431
2432	} else {
2433
2434		if ((OP1_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(variable_ptr))) ||
2435		    (OP2_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(value_ptr)))) {
2436			variable_ptr = &EG(uninitialized_zval);
2437		} else {
2438			zend_assign_to_variable_reference(variable_ptr, value_ptr);
2439		}
2440
2441		if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
2442			ZVAL_COPY(EX_VAR(opline->result.var), variable_ptr);
2443		}
2444
2445		FREE_OP2_VAR_PTR();
2446	}
2447
2448	FREE_OP1_VAR_PTR();
2449	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2450}
2451
2452ZEND_VM_HELPER(zend_leave_helper, ANY, ANY)
2453{
2454	zend_execute_data *old_execute_data;
2455	uint32_t call_info = EX_CALL_INFO();
2456
2457	if (EXPECTED(ZEND_CALL_KIND_EX(call_info) == ZEND_CALL_NESTED_FUNCTION)) {
2458		zend_object *object;
2459
2460		i_free_compiled_variables(execute_data);
2461		if (UNEXPECTED(EX(symbol_table) != NULL)) {
2462			zend_clean_and_cache_symbol_table(EX(symbol_table));
2463		}
2464		zend_vm_stack_free_extra_args_ex(call_info, execute_data);
2465		old_execute_data = execute_data;
2466		execute_data = EG(current_execute_data) = EX(prev_execute_data);
2467		if (UNEXPECTED(call_info & ZEND_CALL_CLOSURE)) {
2468			OBJ_RELEASE((zend_object*)old_execute_data->func->op_array.prototype);
2469		}
2470		if (UNEXPECTED(call_info & ZEND_CALL_RELEASE_THIS)) {
2471			object = Z_OBJ(old_execute_data->This);
2472#if 0
2473			if (UNEXPECTED(EG(exception) != NULL) && (EX(opline)->op1.num & ZEND_CALL_CTOR)) {
2474				if (!(EX(opline)->op1.num & ZEND_CALL_CTOR_RESULT_UNUSED)) {
2475#else
2476			if (UNEXPECTED(EG(exception) != NULL) && (call_info & ZEND_CALL_CTOR)) {
2477				if (!(call_info & ZEND_CALL_CTOR_RESULT_UNUSED)) {
2478#endif
2479					GC_REFCOUNT(object)--;
2480				}
2481				if (GC_REFCOUNT(object) == 1) {
2482					zend_object_store_ctor_failed(object);
2483				}
2484			}
2485			OBJ_RELEASE(object);
2486		}
2487		EG(scope) = EX(func)->op_array.scope;
2488
2489		zend_vm_stack_free_call_frame_ex(call_info, old_execute_data);
2490
2491		if (UNEXPECTED(EG(exception) != NULL)) {
2492			const zend_op *old_opline = EX(opline);
2493			zend_throw_exception_internal(NULL);
2494			if (old_opline->opcode != ZEND_HANDLE_EXCEPTION && RETURN_VALUE_USED(old_opline)) {
2495				zval_ptr_dtor(EX_VAR(old_opline->result.var));
2496			}
2497			HANDLE_EXCEPTION_LEAVE();
2498		}
2499
2500		LOAD_NEXT_OPLINE();
2501		ZEND_VM_LEAVE();
2502	}
2503	if (EXPECTED((ZEND_CALL_KIND_EX(call_info) & ZEND_CALL_TOP) == 0)) {
2504		zend_detach_symbol_table(execute_data);
2505		destroy_op_array(&EX(func)->op_array);
2506		efree_size(EX(func), sizeof(zend_op_array));
2507		old_execute_data = execute_data;
2508		execute_data = EG(current_execute_data) = EX(prev_execute_data);
2509		zend_vm_stack_free_call_frame_ex(call_info, old_execute_data);
2510
2511		zend_attach_symbol_table(execute_data);
2512		if (UNEXPECTED(EG(exception) != NULL)) {
2513			zend_throw_exception_internal(NULL);
2514			HANDLE_EXCEPTION_LEAVE();
2515		}
2516
2517		LOAD_NEXT_OPLINE();
2518		ZEND_VM_LEAVE();
2519	} else {
2520		if (ZEND_CALL_KIND_EX(call_info) == ZEND_CALL_TOP_FUNCTION) {
2521			i_free_compiled_variables(execute_data);
2522			if (UNEXPECTED(EX(symbol_table) != NULL)) {
2523				zend_clean_and_cache_symbol_table(EX(symbol_table));
2524			}
2525			zend_vm_stack_free_extra_args_ex(call_info, execute_data);
2526			EG(current_execute_data) = EX(prev_execute_data);
2527			if (UNEXPECTED(call_info & ZEND_CALL_CLOSURE)) {
2528				OBJ_RELEASE((zend_object*)EX(func)->op_array.prototype);
2529			}
2530		} else /* if (call_kind == ZEND_CALL_TOP_CODE) */ {
2531			zend_array *symbol_table = EX(symbol_table);
2532
2533			zend_detach_symbol_table(execute_data);
2534			old_execute_data = EX(prev_execute_data);
2535			while (old_execute_data) {
2536				if (old_execute_data->func && ZEND_USER_CODE(old_execute_data->func->op_array.type)) {
2537					if (old_execute_data->symbol_table == symbol_table) {
2538						zend_attach_symbol_table(old_execute_data);
2539					}
2540					break;
2541				}
2542				old_execute_data = old_execute_data->prev_execute_data;
2543			}
2544			EG(current_execute_data) = EX(prev_execute_data);
2545		}
2546
2547		ZEND_VM_RETURN();
2548	}
2549}
2550
2551ZEND_VM_HANDLER(42, ZEND_JMP, JMP_ADDR, ANY)
2552{
2553	USE_OPLINE
2554
2555	ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op1));
2556	ZEND_VM_CONTINUE();
2557}
2558
2559ZEND_VM_HANDLER(43, ZEND_JMPZ, CONST|TMPVAR|CV, JMP_ADDR)
2560{
2561	USE_OPLINE
2562	zend_free_op free_op1;
2563	zval *val;
2564
2565	val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2566
2567	if (Z_TYPE_INFO_P(val) == IS_TRUE) {
2568		ZEND_VM_SET_NEXT_OPCODE(opline + 1);
2569		ZEND_VM_CONTINUE();
2570	} else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
2571		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
2572			SAVE_OPLINE();
2573			GET_OP1_UNDEF_CV(val, BP_VAR_R);
2574			ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
2575		} else {
2576			ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2577			ZEND_VM_CONTINUE();
2578		}
2579	}
2580
2581	SAVE_OPLINE();
2582	if (i_zend_is_true(val)) {
2583		opline++;
2584	} else {
2585		opline = OP_JMP_ADDR(opline, opline->op2);
2586	}
2587	FREE_OP1();
2588	if (UNEXPECTED(EG(exception) != NULL)) {
2589		HANDLE_EXCEPTION();
2590	}
2591	ZEND_VM_JMP(opline);
2592}
2593
2594ZEND_VM_HANDLER(44, ZEND_JMPNZ, CONST|TMPVAR|CV, JMP_ADDR)
2595{
2596	USE_OPLINE
2597	zend_free_op free_op1;
2598	zval *val;
2599
2600	val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2601
2602	if (Z_TYPE_INFO_P(val) == IS_TRUE) {
2603		ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2604		ZEND_VM_CONTINUE();
2605	} else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
2606		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
2607			SAVE_OPLINE();
2608			GET_OP1_UNDEF_CV(val, BP_VAR_R);
2609			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2610		} else {
2611			ZEND_VM_NEXT_OPCODE();
2612		}
2613	}
2614
2615	SAVE_OPLINE();
2616	if (i_zend_is_true(val)) {
2617		opline = OP_JMP_ADDR(opline, opline->op2);
2618	} else {
2619		opline++;
2620	}
2621	FREE_OP1();
2622	if (UNEXPECTED(EG(exception) != NULL)) {
2623		HANDLE_EXCEPTION();
2624	}
2625	ZEND_VM_JMP(opline);
2626}
2627
2628ZEND_VM_HANDLER(45, ZEND_JMPZNZ, CONST|TMPVAR|CV, JMP_ADDR, JMP_ADDR)
2629{
2630	USE_OPLINE
2631	zend_free_op free_op1;
2632	zval *val;
2633
2634	val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2635
2636	if (EXPECTED(Z_TYPE_INFO_P(val) == IS_TRUE)) {
2637		ZEND_VM_SET_RELATIVE_OPCODE(opline, opline->extended_value);
2638		ZEND_VM_CONTINUE();
2639	} else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
2640		if (OP1_TYPE == IS_CV) {
2641			if (UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
2642				SAVE_OPLINE();
2643				GET_OP1_UNDEF_CV(val, BP_VAR_R);
2644			}
2645			ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
2646		} else {
2647			ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2648			ZEND_VM_CONTINUE();
2649		}
2650	}
2651
2652	SAVE_OPLINE();
2653	if (i_zend_is_true(val)) {
2654		opline = ZEND_OFFSET_TO_OPLINE(opline, opline->extended_value);
2655	} else {
2656		opline = OP_JMP_ADDR(opline, opline->op2);
2657	}
2658	FREE_OP1();
2659	if (UNEXPECTED(EG(exception) != NULL)) {
2660		HANDLE_EXCEPTION();
2661	}
2662	ZEND_VM_JMP(opline);
2663}
2664
2665ZEND_VM_HANDLER(46, ZEND_JMPZ_EX, CONST|TMPVAR|CV, JMP_ADDR)
2666{
2667	USE_OPLINE
2668	zend_free_op free_op1;
2669	zval *val;
2670	int ret;
2671
2672	val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2673
2674	if (Z_TYPE_INFO_P(val) == IS_TRUE) {
2675		ZVAL_TRUE(EX_VAR(opline->result.var));
2676		ZEND_VM_SET_NEXT_OPCODE(opline + 1);
2677		ZEND_VM_CONTINUE();
2678	} else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
2679		ZVAL_FALSE(EX_VAR(opline->result.var));
2680		if (OP1_TYPE == IS_CV) {
2681			if (UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
2682				SAVE_OPLINE();
2683				GET_OP1_UNDEF_CV(val, BP_VAR_R);
2684			}
2685			ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
2686		} else {
2687			ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2688			ZEND_VM_CONTINUE();
2689		}
2690	}
2691
2692	SAVE_OPLINE();
2693	ret = i_zend_is_true(val);
2694	FREE_OP1();
2695	if (ret) {
2696		ZVAL_TRUE(EX_VAR(opline->result.var));
2697		opline++;
2698	} else {
2699		ZVAL_FALSE(EX_VAR(opline->result.var));
2700		opline = OP_JMP_ADDR(opline, opline->op2);
2701	}
2702	if (UNEXPECTED(EG(exception) != NULL)) {
2703		HANDLE_EXCEPTION();
2704	}
2705	ZEND_VM_JMP(opline);
2706}
2707
2708ZEND_VM_HANDLER(47, ZEND_JMPNZ_EX, CONST|TMPVAR|CV, JMP_ADDR)
2709{
2710	USE_OPLINE
2711	zend_free_op free_op1;
2712	zval *val;
2713	int ret;
2714
2715	val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2716
2717	if (Z_TYPE_INFO_P(val) == IS_TRUE) {
2718		ZVAL_TRUE(EX_VAR(opline->result.var));
2719		ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2720		ZEND_VM_CONTINUE();
2721	} else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
2722		ZVAL_FALSE(EX_VAR(opline->result.var));
2723		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
2724			SAVE_OPLINE();
2725			GET_OP1_UNDEF_CV(val, BP_VAR_R);
2726			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2727		} else {
2728			ZEND_VM_NEXT_OPCODE();
2729		}
2730	}
2731
2732	SAVE_OPLINE();
2733	ret = i_zend_is_true(val);
2734	FREE_OP1();
2735	if (ret) {
2736		ZVAL_TRUE(EX_VAR(opline->result.var));
2737		opline = OP_JMP_ADDR(opline, opline->op2);
2738	} else {
2739		ZVAL_FALSE(EX_VAR(opline->result.var));
2740		opline++;
2741	}
2742	if (UNEXPECTED(EG(exception) != NULL)) {
2743		HANDLE_EXCEPTION();
2744	}
2745	ZEND_VM_JMP(opline);
2746}
2747
2748ZEND_VM_HANDLER(70, ZEND_FREE, TMPVAR, LIVE_RANGE)
2749{
2750	USE_OPLINE
2751
2752	SAVE_OPLINE();
2753	zval_ptr_dtor_nogc(EX_VAR(opline->op1.var));
2754	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2755}
2756
2757ZEND_VM_HANDLER(127, ZEND_FE_FREE, TMPVAR, LIVE_RANGE)
2758{
2759	zval *var;
2760	USE_OPLINE
2761
2762	SAVE_OPLINE();
2763	var = EX_VAR(opline->op1.var);
2764	if (Z_TYPE_P(var) != IS_ARRAY && Z_FE_ITER_P(var) != (uint32_t)-1) {
2765		zend_hash_iterator_del(Z_FE_ITER_P(var));
2766	}
2767	zval_ptr_dtor_nogc(var);
2768	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2769}
2770
2771ZEND_VM_HANDLER(53, ZEND_FAST_CONCAT, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
2772{
2773	USE_OPLINE
2774	zend_free_op free_op1, free_op2;
2775	zval *op1, *op2;
2776	zend_string *op1_str, *op2_str, *str;
2777
2778	SAVE_OPLINE();
2779	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
2780	if (OP1_TYPE == IS_CONST) {
2781		op1_str = Z_STR_P(op1);
2782	} else if (EXPECTED(Z_TYPE_P(op1) == IS_STRING)) {
2783		op1_str = zend_string_copy(Z_STR_P(op1));
2784	} else {
2785		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op1) == IS_UNDEF)) {
2786			GET_OP1_UNDEF_CV(op1, BP_VAR_R);
2787		}
2788		op1_str = _zval_get_string_func(op1);
2789	}
2790	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2791	if (OP2_TYPE == IS_CONST) {
2792		op2_str = Z_STR_P(op2);
2793	} else if (EXPECTED(Z_TYPE_P(op2) == IS_STRING)) {
2794		op2_str = zend_string_copy(Z_STR_P(op2));
2795	} else {
2796		if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op2) == IS_UNDEF)) {
2797			GET_OP2_UNDEF_CV(op2, BP_VAR_R);
2798		}
2799		op2_str = _zval_get_string_func(op2);
2800	}
2801	do {
2802		if (OP1_TYPE != IS_CONST) {
2803			if (UNEXPECTED(ZSTR_LEN(op1_str) == 0)) {
2804				if (OP2_TYPE == IS_CONST) {
2805					zend_string_addref(op2_str);
2806				}
2807				ZVAL_STR(EX_VAR(opline->result.var), op2_str);
2808				zend_string_release(op1_str);
2809				break;
2810			}
2811		}
2812		if (OP2_TYPE != IS_CONST) {
2813			if (UNEXPECTED(ZSTR_LEN(op2_str) == 0)) {
2814				if (OP1_TYPE == IS_CONST) {
2815					zend_string_addref(op1_str);
2816				}
2817				ZVAL_STR(EX_VAR(opline->result.var), op1_str);
2818				zend_string_release(op2_str);
2819				break;
2820			}
2821		}
2822		str = zend_string_alloc(ZSTR_LEN(op1_str) + ZSTR_LEN(op2_str), 0);
2823		memcpy(ZSTR_VAL(str), ZSTR_VAL(op1_str), ZSTR_LEN(op1_str));
2824		memcpy(ZSTR_VAL(str) + ZSTR_LEN(op1_str), ZSTR_VAL(op2_str), ZSTR_LEN(op2_str)+1);
2825		ZVAL_NEW_STR(EX_VAR(opline->result.var), str);
2826		if (OP1_TYPE != IS_CONST) {
2827			zend_string_release(op1_str);
2828		}
2829		if (OP2_TYPE != IS_CONST) {
2830			zend_string_release(op2_str);
2831		}
2832	} while (0);
2833	FREE_OP1();
2834	FREE_OP2();
2835	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2836}
2837
2838ZEND_VM_HANDLER(54, ZEND_ROPE_INIT, UNUSED, CONST|TMPVAR|CV, NUM)
2839{
2840	USE_OPLINE
2841	zend_free_op free_op2;
2842	zend_string **rope;
2843	zval *var;
2844
2845	/* Compiler allocates the necessary number of zval slots to keep the rope */
2846	rope = (zend_string**)EX_VAR(opline->result.var);
2847	if (OP2_TYPE == IS_CONST) {
2848		var = GET_OP2_ZVAL_PTR(BP_VAR_R);
2849		rope[0] = zend_string_copy(Z_STR_P(var));
2850	} else {
2851		var = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2852		if (EXPECTED(Z_TYPE_P(var) == IS_STRING)) {
2853			if (OP2_TYPE == IS_CV) {
2854				rope[0] = zend_string_copy(Z_STR_P(var));
2855			} else {
2856				rope[0] = Z_STR_P(var);
2857			}
2858		} else {
2859			SAVE_OPLINE();
2860			if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var) == IS_UNDEF)) {
2861				GET_OP2_UNDEF_CV(var, BP_VAR_R);
2862			}
2863			rope[0] = _zval_get_string_func(var);
2864			FREE_OP2();
2865			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2866		}
2867	}
2868	ZEND_VM_NEXT_OPCODE();
2869}
2870
2871ZEND_VM_HANDLER(55, ZEND_ROPE_ADD, TMP, CONST|TMPVAR|CV, NUM)
2872{
2873	USE_OPLINE
2874	zend_free_op free_op2;
2875	zend_string **rope;
2876	zval *var;
2877
2878	/* op1 and result are the same */
2879	rope = (zend_string**)EX_VAR(opline->op1.var);
2880	if (OP2_TYPE == IS_CONST) {
2881		var = GET_OP2_ZVAL_PTR(BP_VAR_R);
2882		rope[opline->extended_value] = zend_string_copy(Z_STR_P(var));
2883	} else {
2884		var = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2885		if (EXPECTED(Z_TYPE_P(var) == IS_STRING)) {
2886			if (OP2_TYPE == IS_CV) {
2887				rope[opline->extended_value] = zend_string_copy(Z_STR_P(var));
2888			} else {
2889				rope[opline->extended_value] = Z_STR_P(var);
2890			}
2891		} else {
2892			SAVE_OPLINE();
2893			if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var) == IS_UNDEF)) {
2894				GET_OP2_UNDEF_CV(var, BP_VAR_R);
2895			}
2896			rope[opline->extended_value] = _zval_get_string_func(var);
2897			FREE_OP2();
2898			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2899		}
2900	}
2901	ZEND_VM_NEXT_OPCODE();
2902}
2903
2904ZEND_VM_HANDLER(56, ZEND_ROPE_END, TMP, CONST|TMPVAR|CV, NUM)
2905{
2906	USE_OPLINE
2907	zend_free_op free_op2;
2908	zend_string **rope;
2909	zval *var, *ret;
2910	uint32_t i;
2911	size_t len = 0;
2912	char *target;
2913
2914	rope = (zend_string**)EX_VAR(opline->op1.var);
2915	if (OP2_TYPE == IS_CONST) {
2916		var = GET_OP2_ZVAL_PTR(BP_VAR_R);
2917		rope[opline->extended_value] = zend_string_copy(Z_STR_P(var));
2918	} else {
2919		var = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2920		if (EXPECTED(Z_TYPE_P(var) == IS_STRING)) {
2921			if (OP2_TYPE == IS_CV) {
2922				rope[opline->extended_value] = zend_string_copy(Z_STR_P(var));
2923			} else {
2924				rope[opline->extended_value] = Z_STR_P(var);
2925			}
2926		} else {
2927			SAVE_OPLINE();
2928			if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(var) == IS_UNDEF)) {
2929				GET_OP2_UNDEF_CV(var, BP_VAR_R);
2930			}
2931			rope[opline->extended_value] = _zval_get_string_func(var);
2932			FREE_OP2();
2933			if (UNEXPECTED(EG(exception))) {
2934				for (i = 0; i <= opline->extended_value; i++) {
2935					zend_string_release(rope[i]);
2936				}
2937				HANDLE_EXCEPTION();
2938			}
2939		}
2940	}
2941	for (i = 0; i <= opline->extended_value; i++) {
2942		len += ZSTR_LEN(rope[i]);
2943	}
2944	ret = EX_VAR(opline->result.var);
2945	ZVAL_STR(ret, zend_string_alloc(len, 0));
2946	target = Z_STRVAL_P(ret);
2947	for (i = 0; i <= opline->extended_value; i++) {
2948		memcpy(target, ZSTR_VAL(rope[i]), ZSTR_LEN(rope[i]));
2949		target += ZSTR_LEN(rope[i]);
2950		zend_string_release(rope[i]);
2951	}
2952	*target = '\0';
2953
2954	ZEND_VM_NEXT_OPCODE();
2955}
2956
2957ZEND_VM_HANDLER(109, ZEND_FETCH_CLASS, ANY, CONST|TMPVAR|UNUSED|CV, CLASS_FETCH)
2958{
2959	USE_OPLINE
2960
2961	SAVE_OPLINE();
2962	if (OP2_TYPE == IS_UNUSED) {
2963		Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class(NULL, opline->extended_value);
2964		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2965	} else {
2966		zend_free_op free_op2;
2967		zval *class_name = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
2968
2969ZEND_VM_C_LABEL(try_class_name):
2970		if (OP2_TYPE == IS_CONST) {
2971			zend_class_entry *ce = CACHED_PTR(Z_CACHE_SLOT_P(class_name));
2972
2973			if (UNEXPECTED(ce == NULL)) {
2974				ce = zend_fetch_class_by_name(Z_STR_P(class_name), EX_CONSTANT(opline->op2) + 1, opline->extended_value);
2975				CACHE_PTR(Z_CACHE_SLOT_P(class_name), ce);
2976			}
2977			Z_CE_P(EX_VAR(opline->result.var)) = ce;
2978		} else if (Z_TYPE_P(class_name) == IS_OBJECT) {
2979			Z_CE_P(EX_VAR(opline->result.var)) = Z_OBJCE_P(class_name);
2980		} else if (Z_TYPE_P(class_name) == IS_STRING) {
2981			Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class(Z_STR_P(class_name), opline->extended_value);
2982		} else if ((OP2_TYPE & (IS_VAR|IS_CV)) && Z_TYPE_P(class_name) == IS_REFERENCE) {
2983			class_name = Z_REFVAL_P(class_name);
2984			ZEND_VM_C_GOTO(try_class_name);
2985		} else {
2986			if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(class_name) == IS_UNDEF)) {
2987				GET_OP2_UNDEF_CV(class_name, BP_VAR_R);
2988				if (UNEXPECTED(EG(exception) != NULL)) {
2989					HANDLE_EXCEPTION();
2990				}
2991			}
2992			zend_throw_error(NULL, "Class name must be a valid object or a string");
2993		}
2994
2995		FREE_OP2();
2996		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
2997	}
2998}
2999
3000ZEND_VM_HANDLER(112, ZEND_INIT_METHOD_CALL, CONST|TMPVAR|UNUSED|THIS|CV, CONST|TMPVAR|CV, NUM)
3001{
3002	USE_OPLINE
3003	zval *function_name;
3004	zend_free_op free_op1, free_op2;
3005	zval *object;
3006	zend_function *fbc;
3007	zend_class_entry *called_scope;
3008	zend_object *obj;
3009	zend_execute_data *call;
3010	uint32_t call_info;
3011
3012	SAVE_OPLINE();
3013
3014	function_name = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
3015
3016	if (OP2_TYPE != IS_CONST &&
3017	    UNEXPECTED(Z_TYPE_P(function_name) != IS_STRING)) {
3018		do {
3019			if ((OP2_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(function_name)) {
3020				function_name = Z_REFVAL_P(function_name);
3021				if (EXPECTED(Z_TYPE_P(function_name) == IS_STRING)) {
3022					break;
3023				}
3024			} else if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(function_name) == IS_UNDEF)) {
3025				GET_OP2_UNDEF_CV(function_name, BP_VAR_R);
3026				if (UNEXPECTED(EG(exception) != NULL)) {
3027					HANDLE_EXCEPTION();
3028				}
3029			}
3030			zend_throw_error(NULL, "Method name must be a string");
3031			FREE_OP2();
3032			FREE_UNFETCHED_OP1();
3033			HANDLE_EXCEPTION();
3034		} while (0);
3035	}
3036
3037	object = GET_OP1_OBJ_ZVAL_PTR_UNDEF(BP_VAR_R);
3038
3039	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(object) == NULL)) {
3040		zend_throw_error(NULL, "Using $this when not in object context");
3041		FREE_OP2();
3042		HANDLE_EXCEPTION();
3043	}
3044
3045	if (OP1_TYPE != IS_UNUSED) {
3046		do {
3047			if (OP1_TYPE == IS_CONST || UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
3048				if ((OP1_TYPE & (IS_VAR|IS_CV)) && EXPECTED(Z_ISREF_P(object))) {
3049					object = Z_REFVAL_P(object);
3050					if (EXPECTED(Z_TYPE_P(object) == IS_OBJECT)) {
3051						break;
3052					}
3053				}
3054				if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(object) == IS_UNDEF)) {
3055					GET_OP1_UNDEF_CV(object, BP_VAR_R);
3056					if (UNEXPECTED(EG(exception) != NULL)) {
3057						FREE_OP2();
3058						HANDLE_EXCEPTION();
3059					}
3060				}
3061				zend_throw_error(NULL, "Call to a member function %s() on %s", Z_STRVAL_P(function_name), zend_get_type_by_const(Z_TYPE_P(object)));
3062				FREE_OP2();
3063				FREE_OP1();
3064				HANDLE_EXCEPTION();
3065			}
3066		} while (0);
3067	}
3068
3069	obj = Z_OBJ_P(object);
3070	called_scope = obj->ce;
3071
3072	if (OP2_TYPE != IS_CONST ||
3073	    UNEXPECTED((fbc = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), called_scope)) == NULL)) {
3074	    zend_object *orig_obj = obj;
3075
3076		if (UNEXPECTED(obj->handlers->get_method == NULL)) {
3077			zend_throw_error(NULL, "Object does not support method calls");
3078			FREE_OP2();
3079			FREE_OP1();
3080			HANDLE_EXCEPTION();
3081		}
3082
3083		/* First, locate the function. */
3084		fbc = obj->handlers->get_method(&obj, Z_STR_P(function_name), ((OP2_TYPE == IS_CONST) ? (EX_CONSTANT(opline->op2) + 1) : NULL));
3085		if (UNEXPECTED(fbc == NULL)) {
3086			if (EXPECTED(!EG(exception))) {
3087				zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(obj->ce->name), Z_STRVAL_P(function_name));
3088			}
3089			FREE_OP2();
3090			FREE_OP1();
3091			HANDLE_EXCEPTION();
3092		}
3093		if (OP2_TYPE == IS_CONST &&
3094		    EXPECTED(fbc->type <= ZEND_USER_FUNCTION) &&
3095		    EXPECTED(!(fbc->common.fn_flags & (ZEND_ACC_CALL_VIA_TRAMPOLINE|ZEND_ACC_NEVER_CACHE))) &&
3096		    EXPECTED(obj == orig_obj)) {
3097			CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), called_scope, fbc);
3098		}
3099	}
3100
3101	call_info = ZEND_CALL_NESTED_FUNCTION;
3102	if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_STATIC) != 0)) {
3103		obj = NULL;
3104	} else if (OP1_TYPE & (IS_VAR|IS_TMP_VAR|IS_CV)) {
3105		/* CV may be changed indirectly (e.g. when it's a reference) */
3106		call_info = ZEND_CALL_NESTED_FUNCTION | ZEND_CALL_RELEASE_THIS;
3107		GC_REFCOUNT(obj)++; /* For $this pointer */
3108	}
3109
3110	call = zend_vm_stack_push_call_frame(call_info,
3111		fbc, opline->extended_value, called_scope, obj);
3112	call->prev_execute_data = EX(call);
3113	EX(call) = call;
3114
3115	FREE_OP2();
3116	FREE_OP1();
3117
3118	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
3119}
3120
3121ZEND_VM_HANDLER(113, ZEND_INIT_STATIC_METHOD_CALL, UNUSED|CLASS_FETCH|CONST|VAR, CONST|TMPVAR|UNUSED|CONSTRUCTOR|CV, NUM)
3122{
3123	USE_OPLINE
3124	zval *function_name;
3125	zend_class_entry *ce;
3126	zend_object *object;
3127	zend_function *fbc;
3128	zend_execute_data *call;
3129
3130	SAVE_OPLINE();
3131
3132	if (OP1_TYPE == IS_CONST) {
3133		/* no function found. try a static method in class */
3134		ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
3135		if (UNEXPECTED(ce == NULL)) {
3136			ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, ZEND_FETCH_CLASS_DEFAULT |  ZEND_FETCH_CLASS_EXCEPTION);
3137			if (UNEXPECTED(ce == NULL)) {
3138				if (UNEXPECTED(EG(exception) != NULL)) {
3139					HANDLE_EXCEPTION();
3140				}
3141				zend_throw_error(NULL, "Class '%s' not found", Z_STRVAL_P(EX_CONSTANT(opline->op1)));
3142				HANDLE_EXCEPTION();
3143			}
3144			CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce);
3145		}
3146	} else if (OP1_TYPE == IS_UNUSED) {
3147		ce = zend_fetch_class(NULL, opline->op1.num);
3148		if (UNEXPECTED(ce == NULL)) {
3149			ZEND_ASSERT(EG(exception));
3150			FREE_UNFETCHED_OP2();
3151			HANDLE_EXCEPTION();
3152		}
3153	} else {
3154		ce = Z_CE_P(EX_VAR(opline->op1.var));
3155	}
3156
3157	if (OP1_TYPE == IS_CONST &&
3158	    OP2_TYPE == IS_CONST &&
3159	    EXPECTED((fbc = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) != NULL)) {
3160		/* nothing to do */
3161	} else if (OP1_TYPE != IS_CONST &&
3162	           OP2_TYPE == IS_CONST &&
3163	           (fbc = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce))) {
3164		/* do nothing */
3165	} else if (OP2_TYPE != IS_UNUSED) {
3166		zend_free_op free_op2;
3167
3168		function_name = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
3169		if (OP2_TYPE != IS_CONST) {
3170			if (UNEXPECTED(Z_TYPE_P(function_name) != IS_STRING)) {
3171				if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(function_name) == IS_UNDEF)) {
3172					GET_OP2_UNDEF_CV(function_name, BP_VAR_R);
3173					if (UNEXPECTED(EG(exception) != NULL)) {
3174						HANDLE_EXCEPTION();
3175					}
3176				}
3177				zend_throw_error(NULL, "Function name must be a string");
3178				FREE_OP2();
3179				HANDLE_EXCEPTION();
3180 			}
3181		}
3182
3183		if (ce->get_static_method) {
3184			fbc = ce->get_static_method(ce, Z_STR_P(function_name));
3185		} else {
3186			fbc = zend_std_get_static_method(ce, Z_STR_P(function_name), ((OP2_TYPE == IS_CONST) ? (EX_CONSTANT(opline->op2) + 1) : NULL));
3187		}
3188		if (UNEXPECTED(fbc == NULL)) {
3189			if (EXPECTED(!EG(exception))) {
3190				zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(ce->name), Z_STRVAL_P(function_name));
3191			}
3192			FREE_OP2();
3193			HANDLE_EXCEPTION();
3194		}
3195		if (OP2_TYPE == IS_CONST &&
3196		    EXPECTED(fbc->type <= ZEND_USER_FUNCTION) &&
3197		    EXPECTED(!(fbc->common.fn_flags & (ZEND_ACC_CALL_VIA_TRAMPOLINE|ZEND_ACC_NEVER_CACHE)))) {
3198			if (OP1_TYPE == IS_CONST) {
3199				CACHE_PTR(Z_CACHE_SLOT_P(function_name), fbc);
3200			} else {
3201				CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), ce, fbc);
3202			}
3203		}
3204		if (OP2_TYPE != IS_CONST) {
3205			FREE_OP2();
3206		}
3207	} else {
3208		if (UNEXPECTED(ce->constructor == NULL)) {
3209			zend_throw_error(NULL, "Cannot call constructor");
3210			HANDLE_EXCEPTION();
3211		}
3212		if (Z_OBJ(EX(This)) && Z_OBJ(EX(This))->ce != ce->constructor->common.scope && (ce->constructor->common.fn_flags & ZEND_ACC_PRIVATE)) {
3213			zend_throw_error(NULL, "Cannot call private %s::__construct()", ZSTR_VAL(ce->name));
3214			HANDLE_EXCEPTION();
3215		}
3216		fbc = ce->constructor;
3217	}
3218
3219	object = NULL;
3220	if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
3221		if (Z_OBJ(EX(This)) && instanceof_function(Z_OBJCE(EX(This)), ce)) {
3222			object = Z_OBJ(EX(This));
3223			ce = object->ce;
3224		} else {
3225			if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
3226				/* Allowed for PHP 4 compatibility. */
3227				zend_error(
3228					E_DEPRECATED,
3229					"Non-static method %s::%s() should not be called statically",
3230					ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3231				if (UNEXPECTED(EG(exception) != NULL)) {
3232					HANDLE_EXCEPTION();
3233				}
3234			} else {
3235				/* An internal function assumes $this is present and won't check that.
3236				 * So PHP would crash by allowing the call. */
3237				zend_throw_error(
3238					zend_ce_error,
3239					"Non-static method %s::%s() cannot be called statically",
3240					ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3241				HANDLE_EXCEPTION();
3242			}
3243		}
3244	}
3245
3246	if (OP1_TYPE == IS_UNUSED) {
3247		/* previous opcode is ZEND_FETCH_CLASS */
3248		if ((opline->op1.num & ZEND_FETCH_CLASS_MASK) == ZEND_FETCH_CLASS_PARENT ||
3249		    (opline->op1.num & ZEND_FETCH_CLASS_MASK) == ZEND_FETCH_CLASS_SELF) {
3250			ce = EX(called_scope);
3251		}
3252	}
3253
3254	call = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
3255		fbc, opline->extended_value, ce, object);
3256	call->prev_execute_data = EX(call);
3257	EX(call) = call;
3258
3259	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
3260}
3261
3262ZEND_VM_HANDLER(59, ZEND_INIT_FCALL_BY_NAME, ANY, CONST, NUM)
3263{
3264	USE_OPLINE
3265	zend_function *fbc;
3266	zval *function_name, *func;
3267	zend_execute_data *call;
3268
3269	fbc = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
3270	if (UNEXPECTED(fbc == NULL)) {
3271		function_name = (zval*)(EX_CONSTANT(opline->op2)+1);
3272		func = zend_hash_find(EG(function_table), Z_STR_P(function_name));
3273		if (UNEXPECTED(func == NULL)) {
3274			SAVE_OPLINE();
3275			zend_throw_error(NULL, "Call to undefined function %s()", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
3276			HANDLE_EXCEPTION();
3277		}
3278		fbc = Z_FUNC_P(func);
3279		CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), fbc);
3280	}
3281	call = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
3282		fbc, opline->extended_value, NULL, NULL);
3283	call->prev_execute_data = EX(call);
3284	EX(call) = call;
3285
3286	ZEND_VM_NEXT_OPCODE();
3287}
3288
3289ZEND_VM_HANDLER(128, ZEND_INIT_DYNAMIC_CALL, ANY, CONST|TMPVAR|CV, NUM)
3290{
3291	USE_OPLINE
3292	zend_function *fbc;
3293	zval *function_name, *func;
3294	zend_string *lcname;
3295	zend_free_op free_op2;
3296	zend_class_entry *called_scope;
3297	zend_object *object;
3298	zend_execute_data *call;
3299	uint32_t call_info = ZEND_CALL_NESTED_FUNCTION;
3300
3301	SAVE_OPLINE();
3302	function_name = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
3303
3304ZEND_VM_C_LABEL(try_function_name):
3305	if (OP2_TYPE != IS_CONST && EXPECTED(Z_TYPE_P(function_name) == IS_STRING)) {
3306		const char *colon;
3307
3308		if ((colon = zend_memrchr(Z_STRVAL_P(function_name), ':', Z_STRLEN_P(function_name))) != NULL &&
3309			colon > Z_STRVAL_P(function_name) &&
3310			*(colon-1) == ':'
3311		) {
3312			zend_string *mname;
3313			size_t cname_length = colon - Z_STRVAL_P(function_name) - 1;
3314			size_t mname_length = Z_STRLEN_P(function_name) - cname_length - (sizeof("::") - 1);
3315
3316			lcname = zend_string_init(Z_STRVAL_P(function_name), cname_length, 0);
3317
3318			object = NULL;
3319			called_scope = zend_fetch_class_by_name(lcname, NULL, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
3320			if (UNEXPECTED(called_scope == NULL)) {
3321				zend_string_release(lcname);
3322				ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
3323			}
3324
3325			mname = zend_string_init(Z_STRVAL_P(function_name) + (cname_length + sizeof("::") - 1), mname_length, 0);
3326
3327			if (called_scope->get_static_method) {
3328				fbc = called_scope->get_static_method(called_scope, mname);
3329			} else {
3330				fbc = zend_std_get_static_method(called_scope, mname, NULL);
3331			}
3332			if (UNEXPECTED(fbc == NULL)) {
3333				if (EXPECTED(!EG(exception))) {
3334					zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(called_scope->name), ZSTR_VAL(mname));
3335				}
3336				zend_string_release(lcname);
3337				zend_string_release(mname);
3338				FREE_OP2();
3339				HANDLE_EXCEPTION();
3340			}
3341
3342			zend_string_release(lcname);
3343			zend_string_release(mname);
3344
3345			if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
3346				if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
3347					zend_error(E_DEPRECATED,
3348						"Non-static method %s::%s() should not be called statically",
3349						ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3350					if (UNEXPECTED(EG(exception) != NULL)) {
3351						HANDLE_EXCEPTION();
3352					}
3353				} else {
3354					zend_throw_error(
3355						zend_ce_error,
3356						"Non-static method %s::%s() cannot be called statically",
3357						ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3358					FREE_OP2();
3359					HANDLE_EXCEPTION();
3360				}
3361			}
3362		} else {
3363			if (Z_STRVAL_P(function_name)[0] == '\\') {
3364				lcname = zend_string_alloc(Z_STRLEN_P(function_name) - 1, 0);
3365				zend_str_tolower_copy(ZSTR_VAL(lcname), Z_STRVAL_P(function_name) + 1, Z_STRLEN_P(function_name) - 1);
3366			} else {
3367				lcname = zend_string_tolower(Z_STR_P(function_name));
3368			}
3369			if (UNEXPECTED((func = zend_hash_find(EG(function_table), lcname)) == NULL)) {
3370				zend_throw_error(NULL, "Call to undefined function %s()", Z_STRVAL_P(function_name));
3371				zend_string_release(lcname);
3372				FREE_OP2();
3373				HANDLE_EXCEPTION();
3374			}
3375			zend_string_release(lcname);
3376
3377			fbc = Z_FUNC_P(func);
3378			called_scope = NULL;
3379			object = NULL;
3380		}
3381		FREE_OP2();
3382	} else if (OP2_TYPE != IS_CONST &&
3383	    EXPECTED(Z_TYPE_P(function_name) == IS_OBJECT) &&
3384		Z_OBJ_HANDLER_P(function_name, get_closure) &&
3385		Z_OBJ_HANDLER_P(function_name, get_closure)(function_name, &called_scope, &fbc, &object) == SUCCESS) {
3386		if (fbc->common.fn_flags & ZEND_ACC_CLOSURE) {
3387			/* Delay closure destruction until its invocation */
3388			ZEND_ASSERT(GC_TYPE((zend_object*)fbc->common.prototype) == IS_OBJECT);
3389			GC_REFCOUNT((zend_object*)fbc->common.prototype)++;
3390			call_info |= ZEND_CALL_CLOSURE;
3391		} else if (object) {
3392			call_info |= ZEND_CALL_RELEASE_THIS;
3393			GC_REFCOUNT(object)++; /* For $this pointer */
3394		}
3395		FREE_OP2();
3396	} else if (EXPECTED(Z_TYPE_P(function_name) == IS_ARRAY) &&
3397			zend_hash_num_elements(Z_ARRVAL_P(function_name)) == 2) {
3398		zval *obj;
3399		zval *method;
3400		obj = zend_hash_index_find(Z_ARRVAL_P(function_name), 0);
3401		method = zend_hash_index_find(Z_ARRVAL_P(function_name), 1);
3402
3403		if (!obj || !method) {
3404			zend_throw_error(NULL, "Array callback has to contain indices 0 and 1");
3405			FREE_OP2();
3406			HANDLE_EXCEPTION();
3407		}
3408
3409		ZVAL_DEREF(obj);
3410		if (Z_TYPE_P(obj) != IS_STRING && Z_TYPE_P(obj) != IS_OBJECT) {
3411			zend_throw_error(NULL, "First array member is not a valid class name or object");
3412			FREE_OP2();
3413			HANDLE_EXCEPTION();
3414		}
3415
3416		ZVAL_DEREF(method);
3417		if (Z_TYPE_P(method) != IS_STRING) {
3418			zend_throw_error(NULL, "Second array member is not a valid method");
3419			FREE_OP2();
3420			HANDLE_EXCEPTION();
3421		}
3422
3423		if (Z_TYPE_P(obj) == IS_STRING) {
3424			object = NULL;
3425			called_scope = zend_fetch_class_by_name(Z_STR_P(obj), NULL, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
3426			if (UNEXPECTED(called_scope == NULL)) {
3427				ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
3428			}
3429
3430			if (called_scope->get_static_method) {
3431				fbc = called_scope->get_static_method(called_scope, Z_STR_P(method));
3432			} else {
3433				fbc = zend_std_get_static_method(called_scope, Z_STR_P(method), NULL);
3434			}
3435			if (UNEXPECTED(fbc == NULL)) {
3436				if (EXPECTED(!EG(exception))) {
3437					zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(called_scope->name), Z_STRVAL_P(method));
3438				}
3439				FREE_OP2();
3440				HANDLE_EXCEPTION();
3441			}
3442			if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
3443				if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
3444					zend_error(E_DEPRECATED,
3445						"Non-static method %s::%s() should not be called statically",
3446						ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3447					if (UNEXPECTED(EG(exception) != NULL)) {
3448						HANDLE_EXCEPTION();
3449					}
3450				} else {
3451					zend_throw_error(
3452						zend_ce_error,
3453						"Non-static method %s::%s() cannot be called statically",
3454						ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3455					FREE_OP2();
3456					HANDLE_EXCEPTION();
3457				}
3458			}
3459		} else {
3460			called_scope = Z_OBJCE_P(obj);
3461			object = Z_OBJ_P(obj);
3462
3463			fbc = Z_OBJ_HT_P(obj)->get_method(&object, Z_STR_P(method), NULL);
3464			if (UNEXPECTED(fbc == NULL)) {
3465				if (EXPECTED(!EG(exception))) {
3466					zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(object->ce->name), Z_STRVAL_P(method));
3467				}
3468				FREE_OP2();
3469				HANDLE_EXCEPTION();
3470			}
3471
3472			if ((fbc->common.fn_flags & ZEND_ACC_STATIC) != 0) {
3473				object = NULL;
3474			} else {
3475				call_info |= ZEND_CALL_RELEASE_THIS;
3476				GC_REFCOUNT(object)++; /* For $this pointer */
3477			}
3478		}
3479		FREE_OP2();
3480	} else if ((OP2_TYPE & (IS_VAR|IS_CV)) && Z_TYPE_P(function_name) == IS_REFERENCE) {
3481		function_name = Z_REFVAL_P(function_name);
3482		ZEND_VM_C_GOTO(try_function_name);
3483	} else {
3484		if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(function_name) == IS_UNDEF)) {
3485			GET_OP2_UNDEF_CV(function_name, BP_VAR_R);
3486			if (UNEXPECTED(EG(exception) != NULL)) {
3487				HANDLE_EXCEPTION();
3488			}
3489		}
3490		zend_throw_error(NULL, "Function name must be a string");
3491		FREE_OP2();
3492		HANDLE_EXCEPTION();
3493	}
3494	call = zend_vm_stack_push_call_frame(call_info,
3495		fbc, opline->extended_value, called_scope, object);
3496	call->prev_execute_data = EX(call);
3497	EX(call) = call;
3498
3499	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
3500}
3501
3502ZEND_VM_HANDLER(118, ZEND_INIT_USER_CALL, CONST, CONST|TMPVAR|CV, NUM)
3503{
3504	USE_OPLINE
3505	zend_free_op free_op2;
3506	zval *function_name;
3507	zend_fcall_info_cache fcc;
3508	char *error = NULL;
3509	zend_function *func;
3510	zend_class_entry *called_scope;
3511	zend_object *object;
3512	zend_execute_data *call;
3513	uint32_t call_info = ZEND_CALL_NESTED_FUNCTION;
3514
3515	SAVE_OPLINE();
3516	function_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
3517	if (zend_is_callable_ex(function_name, NULL, 0, NULL, &fcc, &error)) {
3518		func = fcc.function_handler;
3519		if (func->common.fn_flags & ZEND_ACC_CLOSURE) {
3520			/* Delay closure destruction until its invocation */
3521			if (OP2_TYPE & (IS_VAR|IS_CV)) {
3522				ZVAL_DEREF(function_name);
3523			}
3524			ZEND_ASSERT(GC_TYPE((zend_object*)func->common.prototype) == IS_OBJECT);
3525			GC_REFCOUNT((zend_object*)func->common.prototype)++;
3526			call_info |= ZEND_CALL_CLOSURE;
3527		}
3528		called_scope = fcc.called_scope;
3529		object = fcc.object;
3530		if (object) {
3531			call_info |= ZEND_CALL_RELEASE_THIS;
3532			GC_REFCOUNT(object)++; /* For $this pointer */
3533		}
3534		if (error) {
3535			efree(error);
3536			/* This is the only soft error is_callable() can generate */
3537			zend_error(E_DEPRECATED,
3538				"Non-static method %s::%s() should not be called statically",
3539				ZSTR_VAL(func->common.scope->name), ZSTR_VAL(func->common.function_name));
3540			if (UNEXPECTED(EG(exception) != NULL)) {
3541				HANDLE_EXCEPTION();
3542			}
3543		}
3544	} else {
3545		zend_internal_type_error(EX_USES_STRICT_TYPES(), "%s() expects parameter 1 to be a valid callback, %s", Z_STRVAL_P(EX_CONSTANT(opline->op1)), error);
3546		efree(error);
3547		func = (zend_function*)&zend_pass_function;
3548		called_scope = NULL;
3549		object = NULL;
3550	}
3551
3552	call = zend_vm_stack_push_call_frame(call_info,
3553		func, opline->extended_value, called_scope, object);
3554	call->prev_execute_data = EX(call);
3555	EX(call) = call;
3556
3557	FREE_OP2();
3558	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
3559}
3560
3561ZEND_VM_HANDLER(69, ZEND_INIT_NS_FCALL_BY_NAME, ANY, CONST, NUM)
3562{
3563	USE_OPLINE
3564	zval *func_name;
3565	zval *func;
3566	zend_function *fbc;
3567	zend_execute_data *call;
3568
3569	func_name = EX_CONSTANT(opline->op2) + 1;
3570	fbc = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
3571	if (UNEXPECTED(fbc == NULL)) {
3572		func = zend_hash_find(EG(function_table), Z_STR_P(func_name));
3573		if (func == NULL) {
3574			func_name++;
3575			func = zend_hash_find(EG(function_table), Z_STR_P(func_name));
3576			if (UNEXPECTED(func == NULL)) {
3577				SAVE_OPLINE();
3578				zend_throw_error(NULL, "Call to undefined function %s()", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
3579				HANDLE_EXCEPTION();
3580			}
3581		}
3582		fbc = Z_FUNC_P(func);
3583		CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), fbc);
3584	}
3585
3586	call = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
3587		fbc, opline->extended_value, NULL, NULL);
3588	call->prev_execute_data = EX(call);
3589	EX(call) = call;
3590
3591	ZEND_VM_NEXT_OPCODE();
3592}
3593
3594ZEND_VM_HANDLER(61, ZEND_INIT_FCALL, NUM, CONST, NUM)
3595{
3596	USE_OPLINE
3597	zend_free_op free_op2;
3598	zval *fname = GET_OP2_ZVAL_PTR(BP_VAR_R);
3599	zval *func;
3600	zend_function *fbc;
3601	zend_execute_data *call;
3602
3603	fbc = CACHED_PTR(Z_CACHE_SLOT_P(fname));
3604	if (UNEXPECTED(fbc == NULL)) {
3605		func = zend_hash_find(EG(function_table), Z_STR_P(fname));
3606		if (UNEXPECTED(func == NULL)) {
3607		    SAVE_OPLINE();
3608			zend_throw_error(NULL, "Call to undefined function %s()", Z_STRVAL_P(fname));
3609			HANDLE_EXCEPTION();
3610		}
3611		fbc = Z_FUNC_P(func);
3612		CACHE_PTR(Z_CACHE_SLOT_P(fname), fbc);
3613	}
3614
3615	call = zend_vm_stack_push_call_frame_ex(
3616		opline->op1.num, ZEND_CALL_NESTED_FUNCTION,
3617		fbc, opline->extended_value, NULL, NULL);
3618	call->prev_execute_data = EX(call);
3619	EX(call) = call;
3620
3621	ZEND_VM_NEXT_OPCODE();
3622}
3623
3624ZEND_VM_HANDLER(129, ZEND_DO_ICALL, ANY, ANY, SPEC(RETVAL))
3625{
3626	USE_OPLINE
3627	zend_execute_data *call = EX(call);
3628	zend_function *fbc = call->func;
3629	zval *ret;
3630
3631	SAVE_OPLINE();
3632	EX(call) = call->prev_execute_data;
3633
3634	call->prev_execute_data = execute_data;
3635	EG(current_execute_data) = call;
3636
3637	ret = EX_VAR(opline->result.var);
3638	ZVAL_NULL(ret);
3639	Z_VAR_FLAGS_P(ret) = 0;
3640
3641	fbc->internal_function.handler(call, ret);
3642
3643#if ZEND_DEBUG
3644	ZEND_ASSERT(
3645		EG(exception) || !call->func ||
3646		!(call->func->common.fn_flags & ZEND_ACC_HAS_RETURN_TYPE) ||
3647		zend_verify_internal_return_type(call->func, EX_VAR(opline->result.var)));
3648#endif
3649
3650	EG(current_execute_data) = call->prev_execute_data;
3651	zend_vm_stack_free_args(call);
3652	zend_vm_stack_free_call_frame(call);
3653
3654	if (!RETURN_VALUE_USED(opline)) {
3655		zval_ptr_dtor(EX_VAR(opline->result.var));
3656	}
3657
3658	if (UNEXPECTED(EG(exception) != NULL)) {
3659		zend_throw_exception_internal(NULL);
3660		if (RETURN_VALUE_USED(opline)) {
3661			zval_ptr_dtor(EX_VAR(opline->result.var));
3662		}
3663		HANDLE_EXCEPTION();
3664	}
3665
3666	ZEND_VM_INTERRUPT_CHECK();
3667	ZEND_VM_NEXT_OPCODE();
3668}
3669
3670ZEND_VM_HANDLER(130, ZEND_DO_UCALL, ANY, ANY, SPEC(RETVAL))
3671{
3672	USE_OPLINE
3673	zend_execute_data *call = EX(call);
3674	zend_function *fbc = call->func;
3675	zval *ret;
3676
3677	SAVE_OPLINE();
3678	EX(call) = call->prev_execute_data;
3679
3680	EG(scope) = NULL;
3681	ret = NULL;
3682	call->symbol_table = NULL;
3683	if (RETURN_VALUE_USED(opline)) {
3684		ret = EX_VAR(opline->result.var);
3685		ZVAL_NULL(ret);
3686		Z_VAR_FLAGS_P(ret) = 0;
3687	}
3688
3689	call->prev_execute_data = execute_data;
3690	i_init_func_execute_data(call, &fbc->op_array, ret, 0);
3691
3692	ZEND_VM_ENTER();
3693}
3694
3695ZEND_VM_HANDLER(131, ZEND_DO_FCALL_BY_NAME, ANY, ANY, SPEC(RETVAL))
3696{
3697	USE_OPLINE
3698	zend_execute_data *call = EX(call);
3699	zend_function *fbc = call->func;
3700	zval *ret;
3701
3702	SAVE_OPLINE();
3703	EX(call) = call->prev_execute_data;
3704
3705	if (EXPECTED(fbc->type == ZEND_USER_FUNCTION)) {
3706		EG(scope) = NULL;
3707		if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_GENERATOR) != 0)) {
3708			if (EXPECTED(RETURN_VALUE_USED(opline))) {
3709				ret = EX_VAR(opline->result.var);
3710				zend_generator_create_zval(call, &fbc->op_array, ret);
3711				Z_VAR_FLAGS_P(ret) = 0;
3712			} else {
3713				zend_vm_stack_free_args(call);
3714			}
3715
3716			zend_vm_stack_free_call_frame(call);
3717		} else {
3718			ret = NULL;
3719			call->symbol_table = NULL;
3720			if (RETURN_VALUE_USED(opline)) {
3721				ret = EX_VAR(opline->result.var);
3722				ZVAL_NULL(ret);
3723				Z_VAR_FLAGS_P(ret) = 0;
3724			}
3725
3726			call->prev_execute_data = execute_data;
3727			i_init_func_execute_data(call, &fbc->op_array, ret, 0);
3728
3729			ZEND_VM_ENTER();
3730		}
3731		EG(scope) = EX(func)->op_array.scope;
3732	} else {
3733		ZEND_ASSERT(fbc->type == ZEND_INTERNAL_FUNCTION);
3734
3735		if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_DEPRECATED) != 0)) {
3736			zend_error(E_DEPRECATED, "Function %s%s%s() is deprecated",
3737				fbc->common.scope ? ZSTR_VAL(fbc->common.scope->name) : "",
3738				fbc->common.scope ? "::" : "",
3739				ZSTR_VAL(fbc->common.function_name));
3740			if (UNEXPECTED(EG(exception) != NULL)) {
3741				HANDLE_EXCEPTION();
3742			}
3743		}
3744
3745		call->prev_execute_data = execute_data;
3746		EG(current_execute_data) = call;
3747
3748		if (fbc->common.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) {
3749			uint32_t i;
3750			uint32_t num_args = ZEND_CALL_NUM_ARGS(call);
3751			zval *p = ZEND_CALL_ARG(call, 1);
3752
3753			for (i = 0; i < num_args; ++i) {
3754				if (UNEXPECTED(!zend_verify_internal_arg_type(fbc, i + 1, p))) {
3755					EG(current_execute_data) = call->prev_execute_data;
3756					zend_vm_stack_free_args(call);
3757					zend_vm_stack_free_call_frame(call);
3758					zend_throw_exception_internal(NULL);
3759					HANDLE_EXCEPTION();
3760				}
3761				p++;
3762			}
3763		}
3764
3765		ret = EX_VAR(opline->result.var);
3766		ZVAL_NULL(ret);
3767		Z_VAR_FLAGS_P(ret) = (fbc->common.fn_flags & ZEND_ACC_RETURN_REFERENCE) != 0 ? IS_VAR_RET_REF : 0;
3768
3769		fbc->internal_function.handler(call, ret);
3770
3771#if ZEND_DEBUG
3772		ZEND_ASSERT(
3773			EG(exception) || !call->func ||
3774			!(call->func->common.fn_flags & ZEND_ACC_HAS_RETURN_TYPE) ||
3775			zend_verify_internal_return_type(call->func, EX_VAR(opline->result.var)));
3776#endif
3777
3778		EG(current_execute_data) = call->prev_execute_data;
3779		zend_vm_stack_free_args(call);
3780		zend_vm_stack_free_call_frame(call);
3781
3782		if (!RETURN_VALUE_USED(opline)) {
3783			zval_ptr_dtor(EX_VAR(opline->result.var));
3784		}
3785	}
3786
3787	if (UNEXPECTED(EG(exception) != NULL)) {
3788		zend_throw_exception_internal(NULL);
3789		if (RETURN_VALUE_USED(opline)) {
3790			zval_ptr_dtor(EX_VAR(opline->result.var));
3791		}
3792		HANDLE_EXCEPTION();
3793	}
3794	ZEND_VM_INTERRUPT_CHECK();
3795	ZEND_VM_NEXT_OPCODE();
3796}
3797
3798ZEND_VM_HANDLER(60, ZEND_DO_FCALL, ANY, ANY, SPEC(RETVAL))
3799{
3800	USE_OPLINE
3801	zend_execute_data *call = EX(call);
3802	zend_function *fbc = call->func;
3803	zend_object *object;
3804	zval *ret;
3805
3806	SAVE_OPLINE();
3807	EX(call) = call->prev_execute_data;
3808	if (UNEXPECTED((fbc->common.fn_flags & (ZEND_ACC_ABSTRACT|ZEND_ACC_DEPRECATED)) != 0)) {
3809		if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_ABSTRACT) != 0)) {
3810			zend_throw_error(NULL, "Cannot call abstract method %s::%s()", ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
3811			HANDLE_EXCEPTION();
3812		}
3813		if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_DEPRECATED) != 0)) {
3814			zend_error(E_DEPRECATED, "Function %s%s%s() is deprecated",
3815				fbc->common.scope ? ZSTR_VAL(fbc->common.scope->name) : "",
3816				fbc->common.scope ? "::" : "",
3817				ZSTR_VAL(fbc->common.function_name));
3818			if (UNEXPECTED(EG(exception) != NULL)) {
3819				HANDLE_EXCEPTION();
3820			}
3821		}
3822	}
3823
3824	LOAD_OPLINE();
3825
3826	if (EXPECTED(fbc->type == ZEND_USER_FUNCTION)) {
3827		EG(scope) = fbc->common.scope;
3828		if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_GENERATOR) != 0)) {
3829			if (EXPECTED(RETURN_VALUE_USED(opline))) {
3830				ret = EX_VAR(opline->result.var);
3831				zend_generator_create_zval(call, &fbc->op_array, ret);
3832				Z_VAR_FLAGS_P(ret) = 0;
3833			} else {
3834				if (UNEXPECTED(ZEND_CALL_INFO(call) & ZEND_CALL_CLOSURE)) {
3835					OBJ_RELEASE((zend_object*)fbc->op_array.prototype);
3836				}
3837				zend_vm_stack_free_args(call);
3838			}
3839		} else {
3840			ret = NULL;
3841			call->symbol_table = NULL;
3842			if (RETURN_VALUE_USED(opline)) {
3843				ret = EX_VAR(opline->result.var);
3844				ZVAL_NULL(ret);
3845				Z_VAR_FLAGS_P(ret) = 0;
3846			}
3847
3848			call->prev_execute_data = execute_data;
3849			i_init_func_execute_data(call, &fbc->op_array, ret, 1);
3850
3851			if (EXPECTED(zend_execute_ex == execute_ex)) {
3852				ZEND_VM_ENTER();
3853			} else {
3854				ZEND_ADD_CALL_FLAG(call, ZEND_CALL_TOP);
3855				zend_execute_ex(call);
3856			}
3857		}
3858	} else if (EXPECTED(fbc->type < ZEND_USER_FUNCTION)) {
3859		int should_change_scope = 0;
3860
3861		if (fbc->common.scope) {
3862			should_change_scope = 1;
3863			EG(scope) = fbc->common.scope;
3864		}
3865
3866		call->prev_execute_data = execute_data;
3867		EG(current_execute_data) = call;
3868
3869		if (fbc->common.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) {
3870			uint32_t i;
3871			uint32_t num_args = ZEND_CALL_NUM_ARGS(call);
3872			zval *p = ZEND_CALL_ARG(call, 1);
3873
3874			for (i = 0; i < num_args; ++i) {
3875				if (UNEXPECTED(!zend_verify_internal_arg_type(fbc, i + 1, p))) {
3876					EG(current_execute_data) = call->prev_execute_data;
3877					zend_vm_stack_free_args(call);
3878					if (RETURN_VALUE_USED(opline)) {
3879						ZVAL_UNDEF(EX_VAR(opline->result.var));
3880					}
3881					if (UNEXPECTED(should_change_scope)) {
3882						ZEND_VM_C_GOTO(fcall_end_change_scope);
3883					} else {
3884						ZEND_VM_C_GOTO(fcall_end);
3885					}
3886				}
3887				p++;
3888			}
3889		}
3890
3891		ret = EX_VAR(opline->result.var);
3892		ZVAL_NULL(ret);
3893		Z_VAR_FLAGS_P(ret) = (fbc->common.fn_flags & ZEND_ACC_RETURN_REFERENCE) != 0 ? IS_VAR_RET_REF : 0;
3894
3895		if (!zend_execute_internal) {
3896			/* saves one function call if zend_execute_internal is not used */
3897			fbc->internal_function.handler(call, ret);
3898		} else {
3899			zend_execute_internal(call, ret);
3900		}
3901
3902#if ZEND_DEBUG
3903		ZEND_ASSERT(
3904			EG(exception) || !call->func ||
3905			!(call->func->common.fn_flags & ZEND_ACC_HAS_RETURN_TYPE) ||
3906			zend_verify_internal_return_type(call->func, EX_VAR(opline->result.var)));
3907#endif
3908
3909		EG(current_execute_data) = call->prev_execute_data;
3910		zend_vm_stack_free_args(call);
3911
3912		if (!RETURN_VALUE_USED(opline)) {
3913			zval_ptr_dtor(EX_VAR(opline->result.var));
3914		}
3915
3916		if (UNEXPECTED(should_change_scope)) {
3917			ZEND_VM_C_GOTO(fcall_end_change_scope);
3918		} else {
3919			ZEND_VM_C_GOTO(fcall_end);
3920		}
3921	} else { /* ZEND_OVERLOADED_FUNCTION */
3922		/* Not sure what should be done here if it's a static method */
3923		object = Z_OBJ(call->This);
3924		if (UNEXPECTED(object == NULL)) {
3925			zend_vm_stack_free_args(call);
3926			if (fbc->type == ZEND_OVERLOADED_FUNCTION_TEMPORARY) {
3927				zend_string_release(fbc->common.function_name);
3928			}
3929			efree(fbc);
3930			zend_vm_stack_free_call_frame(call);
3931
3932			zend_throw_error(NULL, "Cannot call overloaded function for non-object");
3933			HANDLE_EXCEPTION();
3934		}
3935
3936		EG(scope) = fbc->common.scope;
3937
3938		ZVAL_NULL(EX_VAR(opline->result.var));
3939
3940		call->prev_execute_data = execute_data;
3941		EG(current_execute_data) = call;
3942		object->handlers->call_method(fbc->common.function_name, object, call, EX_VAR(opline->result.var));
3943		EG(current_execute_data) = call->prev_execute_data;
3944
3945		zend_vm_stack_free_args(call);
3946
3947		if (fbc->type == ZEND_OVERLOADED_FUNCTION_TEMPORARY) {
3948			zend_string_release(fbc->common.function_name);
3949		}
3950		efree(fbc);
3951
3952		if (!RETURN_VALUE_USED(opline)) {
3953			zval_ptr_dtor(EX_VAR(opline->result.var));
3954		} else {
3955			Z_VAR_FLAGS_P(EX_VAR(opline->result.var)) = 0;
3956		}
3957	}
3958
3959ZEND_VM_C_LABEL(fcall_end_change_scope):
3960	if (UNEXPECTED(ZEND_CALL_INFO(call) & ZEND_CALL_RELEASE_THIS)) {
3961		object = Z_OBJ(call->This);
3962#if 0
3963		if (UNEXPECTED(EG(exception) != NULL) && (opline->op1.num & ZEND_CALL_CTOR)) {
3964			if (!(opline->op1.num & ZEND_CALL_CTOR_RESULT_UNUSED)) {
3965#else
3966		if (UNEXPECTED(EG(exception) != NULL) && (ZEND_CALL_INFO(call) & ZEND_CALL_CTOR)) {
3967			if (!(ZEND_CALL_INFO(call) & ZEND_CALL_CTOR_RESULT_UNUSED)) {
3968#endif
3969				GC_REFCOUNT(object)--;
3970			}
3971			if (GC_REFCOUNT(object) == 1) {
3972				zend_object_store_ctor_failed(object);
3973			}
3974		}
3975		OBJ_RELEASE(object);
3976	}
3977	EG(scope) = EX(func)->op_array.scope;
3978
3979ZEND_VM_C_LABEL(fcall_end):
3980	zend_vm_stack_free_call_frame(call);
3981	if (UNEXPECTED(EG(exception) != NULL)) {
3982		zend_throw_exception_internal(NULL);
3983		if (RETURN_VALUE_USED(opline)) {
3984			zval_ptr_dtor(EX_VAR(opline->result.var));
3985		}
3986		HANDLE_EXCEPTION();
3987	}
3988
3989	ZEND_VM_INTERRUPT_CHECK();
3990	ZEND_VM_NEXT_OPCODE();
3991}
3992
3993ZEND_VM_HANDLER(124, ZEND_VERIFY_RETURN_TYPE, CONST|TMP|VAR|UNUSED|CV, UNUSED)
3994{
3995	USE_OPLINE
3996
3997	SAVE_OPLINE();
3998	if (OP1_TYPE == IS_UNUSED) {
3999		zend_verify_missing_return_type(EX(func), CACHE_ADDR(opline->op2.num));
4000	} else {
4001/* prevents "undefined variable opline" errors */
4002#if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
4003		zval *retval_ref, *retval_ptr;
4004		zend_free_op free_op1;
4005		zend_arg_info *ret_info = EX(func)->common.arg_info - 1;
4006
4007		retval_ref = retval_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
4008
4009		if (OP1_TYPE == IS_CONST) {
4010			ZVAL_COPY(EX_VAR(opline->result.var), retval_ptr);
4011			retval_ref = retval_ptr = EX_VAR(opline->result.var);
4012		} else if (OP1_TYPE == IS_VAR) {
4013			if (UNEXPECTED(Z_TYPE_P(retval_ptr) == IS_INDIRECT)) {
4014				retval_ptr = Z_INDIRECT_P(retval_ptr);
4015			}
4016			ZVAL_DEREF(retval_ptr);
4017		} else if (OP1_TYPE == IS_CV) {
4018			ZVAL_DEREF(retval_ptr);
4019		}
4020
4021		if (UNEXPECTED(!ret_info->class_name
4022			&& ret_info->type_hint != IS_CALLABLE
4023			&& !ZEND_SAME_FAKE_TYPE(ret_info->type_hint, Z_TYPE_P(retval_ptr))
4024			&& !(EX(func)->op_array.fn_flags & ZEND_ACC_RETURN_REFERENCE)
4025			&& retval_ref != retval_ptr)
4026		) {
4027			/* A cast might happen - unwrap the reference if this is a by-value return */
4028			if (Z_REFCOUNT_P(retval_ref) == 1) {
4029				ZVAL_UNREF(retval_ref);
4030			} else {
4031				Z_DELREF_P(retval_ref);
4032				ZVAL_COPY(retval_ref, retval_ptr);
4033			}
4034			retval_ptr = retval_ref;
4035		}
4036		zend_verify_return_type(EX(func), retval_ptr, CACHE_ADDR(opline->op2.num));
4037
4038		if (UNEXPECTED(EG(exception) != NULL)) {
4039			if (OP1_TYPE == IS_CONST) {
4040				zval_ptr_dtor_nogc(retval_ptr);
4041			}
4042		}
4043#endif
4044	}
4045	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4046}
4047
4048ZEND_VM_HANDLER(62, ZEND_RETURN, CONST|TMP|VAR|CV, ANY)
4049{
4050	USE_OPLINE
4051	zval *retval_ptr;
4052	zend_free_op free_op1;
4053
4054	retval_ptr = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4055	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(retval_ptr) == IS_UNDEF)) {
4056		SAVE_OPLINE();
4057		retval_ptr = GET_OP1_UNDEF_CV(retval_ptr, BP_VAR_R);
4058		if (EX(return_value)) {
4059			ZVAL_NULL(EX(return_value));
4060		}
4061	} else if (!EX(return_value)) {
4062		if (OP1_TYPE == IS_VAR || OP1_TYPE == IS_TMP_VAR ) {
4063			if (Z_REFCOUNTED_P(free_op1) && !Z_DELREF_P(free_op1)) {
4064				SAVE_OPLINE();
4065				zval_dtor_func_for_ptr(Z_COUNTED_P(free_op1));
4066			}
4067		}
4068	} else {
4069		if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
4070			ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
4071			if (OP1_TYPE == IS_CONST) {
4072				if (UNEXPECTED(Z_OPT_COPYABLE_P(EX(return_value)))) {
4073					zval_copy_ctor_func(EX(return_value));
4074				}
4075			}
4076		} else if (OP1_TYPE == IS_CV) {
4077			ZVAL_DEREF(retval_ptr);
4078			ZVAL_COPY(EX(return_value), retval_ptr);
4079		} else /* if (OP1_TYPE == IS_VAR) */ {
4080			if (UNEXPECTED(Z_ISREF_P(retval_ptr))) {
4081				zend_refcounted *ref = Z_COUNTED_P(retval_ptr);
4082
4083				retval_ptr = Z_REFVAL_P(retval_ptr);
4084				ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
4085				if (UNEXPECTED(--GC_REFCOUNT(ref) == 0)) {
4086					efree_size(ref, sizeof(zend_reference));
4087				} else if (Z_OPT_REFCOUNTED_P(retval_ptr)) {
4088					Z_ADDREF_P(retval_ptr);
4089				}
4090			} else {
4091				ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
4092			}
4093		}
4094	}
4095	ZEND_VM_DISPATCH_TO_HELPER(zend_leave_helper);
4096}
4097
4098ZEND_VM_HANDLER(111, ZEND_RETURN_BY_REF, CONST|TMP|VAR|CV, ANY, SRC)
4099{
4100	USE_OPLINE
4101	zval *retval_ptr;
4102	zend_free_op free_op1;
4103
4104	SAVE_OPLINE();
4105
4106	do {
4107		if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR ||
4108		    (OP1_TYPE == IS_VAR && opline->extended_value == ZEND_RETURNS_VALUE)) {
4109			/* Not supposed to happen, but we'll allow it */
4110			zend_error(E_NOTICE, "Only variable references should be returned by reference");
4111
4112			retval_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
4113			if (!EX(return_value)) {
4114				if (OP1_TYPE == IS_TMP_VAR) {
4115					FREE_OP1();
4116				}
4117			} else {
4118				ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
4119				Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
4120				if (OP1_TYPE != IS_TMP_VAR) {
4121					zval_opt_copy_ctor_no_imm(EX(return_value));
4122				}
4123			}
4124			break;
4125		}
4126
4127		retval_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
4128
4129		if (OP1_TYPE == IS_VAR) {
4130			if (retval_ptr == &EG(uninitialized_zval) ||
4131			    (opline->extended_value == ZEND_RETURNS_FUNCTION &&
4132			     !(Z_VAR_FLAGS_P(retval_ptr) & IS_VAR_RET_REF))) {
4133				zend_error(E_NOTICE, "Only variable references should be returned by reference");
4134				if (EX(return_value)) {
4135					ZVAL_NEW_REF(EX(return_value), retval_ptr);
4136					Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
4137					if (Z_REFCOUNTED_P(retval_ptr)) Z_ADDREF_P(retval_ptr);
4138				}
4139				break;
4140			}
4141		}
4142
4143		if (EX(return_value)) {
4144			ZVAL_MAKE_REF(retval_ptr);
4145			Z_ADDREF_P(retval_ptr);
4146			ZVAL_REF(EX(return_value), Z_REF_P(retval_ptr));
4147			Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
4148		}
4149	} while (0);
4150
4151	FREE_OP1_VAR_PTR();
4152	ZEND_VM_DISPATCH_TO_HELPER(zend_leave_helper);
4153}
4154
4155ZEND_VM_HANDLER(161, ZEND_GENERATOR_RETURN, CONST|TMP|VAR|CV, ANY)
4156{
4157	USE_OPLINE
4158	zval *retval;
4159	zend_free_op free_op1;
4160
4161	zend_generator *generator = zend_get_running_generator(execute_data);
4162
4163	SAVE_OPLINE();
4164	retval = GET_OP1_ZVAL_PTR(BP_VAR_R);
4165
4166	/* Copy return value into generator->retval */
4167	if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
4168		ZVAL_COPY_VALUE(&generator->retval, retval);
4169		if (OP1_TYPE == IS_CONST) {
4170			if (UNEXPECTED(Z_OPT_COPYABLE(generator->retval))) {
4171				zval_copy_ctor_func(&generator->retval);
4172			}
4173		}
4174	} else if (OP1_TYPE == IS_CV) {
4175		ZVAL_DEREF(retval);
4176		ZVAL_COPY(&generator->retval, retval);
4177	} else /* if (OP1_TYPE == IS_VAR) */ {
4178		if (UNEXPECTED(Z_ISREF_P(retval))) {
4179			zend_refcounted *ref = Z_COUNTED_P(retval);
4180
4181			retval = Z_REFVAL_P(retval);
4182			ZVAL_COPY_VALUE(&generator->retval, retval);
4183			if (UNEXPECTED(--GC_REFCOUNT(ref) == 0)) {
4184				efree_size(ref, sizeof(zend_reference));
4185			} else if (Z_OPT_REFCOUNTED_P(retval)) {
4186				Z_ADDREF_P(retval);
4187			}
4188		} else {
4189			ZVAL_COPY_VALUE(&generator->retval, retval);
4190		}
4191	}
4192
4193	/* Close the generator to free up resources */
4194	zend_generator_close(generator, 1);
4195
4196	/* Pass execution back to handling code */
4197	ZEND_VM_RETURN();
4198}
4199
4200ZEND_VM_HANDLER(108, ZEND_THROW, CONST|TMP|VAR|CV, ANY)
4201{
4202	USE_OPLINE
4203	zval *value;
4204	zend_free_op free_op1;
4205
4206	SAVE_OPLINE();
4207	value = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4208
4209	do {
4210		if (OP1_TYPE == IS_CONST || UNEXPECTED(Z_TYPE_P(value) != IS_OBJECT)) {
4211			if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(value)) {
4212				value = Z_REFVAL_P(value);
4213				if (EXPECTED(Z_TYPE_P(value) == IS_OBJECT)) {
4214					break;
4215				}
4216			}
4217			if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
4218				GET_OP1_UNDEF_CV(value, BP_VAR_R);
4219				if (UNEXPECTED(EG(exception) != NULL)) {
4220					HANDLE_EXCEPTION();
4221				}
4222			}
4223			zend_throw_error(NULL, "Can only throw objects");
4224			FREE_OP1();
4225			HANDLE_EXCEPTION();
4226		}
4227	} while (0);
4228
4229	zend_exception_save();
4230	if (OP1_TYPE != IS_TMP_VAR) {
4231		if (Z_REFCOUNTED_P(value)) Z_ADDREF_P(value);
4232	}
4233
4234	zend_throw_exception_object(value);
4235	zend_exception_restore();
4236	FREE_OP1_IF_VAR();
4237	HANDLE_EXCEPTION();
4238}
4239
4240ZEND_VM_HANDLER(107, ZEND_CATCH, CONST, CV, JMP_ADDR)
4241{
4242	USE_OPLINE
4243	zend_class_entry *ce, *catch_ce;
4244	zend_object *exception;
4245
4246	SAVE_OPLINE();
4247	/* Check whether an exception has been thrown, if not, jump over code */
4248	zend_exception_restore();
4249	if (EG(exception) == NULL) {
4250		ZEND_VM_SET_RELATIVE_OPCODE(opline, opline->extended_value);
4251		ZEND_VM_CONTINUE();
4252	}
4253	catch_ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
4254	if (UNEXPECTED(catch_ce == NULL)) {
4255		catch_ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, ZEND_FETCH_CLASS_NO_AUTOLOAD);
4256
4257		CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), catch_ce);
4258	}
4259	ce = EG(exception)->ce;
4260
4261#ifdef HAVE_DTRACE
4262	if (DTRACE_EXCEPTION_CAUGHT_ENABLED()) {
4263		DTRACE_EXCEPTION_CAUGHT((char *)ce->name);
4264	}
4265#endif /* HAVE_DTRACE */
4266
4267	if (ce != catch_ce) {
4268		if (!catch_ce || !instanceof_function(ce, catch_ce)) {
4269			if (opline->result.num) {
4270				zend_throw_exception_internal(NULL);
4271				HANDLE_EXCEPTION();
4272			}
4273			ZEND_VM_SET_RELATIVE_OPCODE(opline, opline->extended_value);
4274			ZEND_VM_CONTINUE();
4275		}
4276	}
4277
4278	exception = EG(exception);
4279	zval_ptr_dtor(EX_VAR(opline->op2.var));
4280	ZVAL_OBJ(EX_VAR(opline->op2.var), EG(exception));
4281	if (UNEXPECTED(EG(exception) != exception)) {
4282		GC_REFCOUNT(EG(exception))++;
4283		HANDLE_EXCEPTION();
4284	} else {
4285		EG(exception) = NULL;
4286		ZEND_VM_NEXT_OPCODE();
4287	}
4288}
4289
4290ZEND_VM_HANDLER(65, ZEND_SEND_VAL, CONST|TMP, NUM)
4291{
4292	USE_OPLINE
4293	zval *value, *arg;
4294	zend_free_op free_op1;
4295
4296	value = GET_OP1_ZVAL_PTR(BP_VAR_R);
4297	arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4298	ZVAL_COPY_VALUE(arg, value);
4299	if (OP1_TYPE == IS_CONST) {
4300		if (UNEXPECTED(Z_OPT_COPYABLE_P(arg))) {
4301			zval_copy_ctor_func(arg);
4302		}
4303	}
4304	ZEND_VM_NEXT_OPCODE();
4305}
4306
4307ZEND_VM_HANDLER(116, ZEND_SEND_VAL_EX, CONST|TMP, NUM, SPEC(QUICK_ARG))
4308{
4309	USE_OPLINE
4310	zval *value, *arg;
4311	zend_free_op free_op1;
4312	uint32_t arg_num = opline->op2.num;
4313
4314	if (EXPECTED(arg_num <= MAX_ARG_FLAG_NUM)) {
4315		if (QUICK_ARG_MUST_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4316			ZEND_VM_C_GOTO(send_val_by_ref);
4317		}
4318	} else if (ARG_MUST_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4319ZEND_VM_C_LABEL(send_val_by_ref):
4320		SAVE_OPLINE();
4321		zend_throw_error(NULL, "Cannot pass parameter %d by reference", arg_num);
4322		FREE_UNFETCHED_OP1();
4323		arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4324		ZVAL_UNDEF(arg);
4325		HANDLE_EXCEPTION();
4326	}
4327	value = GET_OP1_ZVAL_PTR(BP_VAR_R);
4328	arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4329	ZVAL_COPY_VALUE(arg, value);
4330	if (OP1_TYPE == IS_CONST) {
4331		if (UNEXPECTED(Z_OPT_COPYABLE_P(arg))) {
4332			zval_copy_ctor_func(arg);
4333		}
4334	}
4335	ZEND_VM_NEXT_OPCODE();
4336}
4337
4338ZEND_VM_HANDLER(117, ZEND_SEND_VAR, VAR|CV, NUM)
4339{
4340	USE_OPLINE
4341	zval *varptr, *arg;
4342	zend_free_op free_op1;
4343
4344	varptr = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4345	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(varptr) == IS_UNDEF)) {
4346		SAVE_OPLINE();
4347		GET_OP1_UNDEF_CV(varptr, BP_VAR_R);
4348		arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4349		ZVAL_NULL(arg);
4350		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4351	}
4352
4353	arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4354
4355	if (OP1_TYPE == IS_CV) {
4356		ZVAL_OPT_DEREF(varptr);
4357		ZVAL_COPY(arg, varptr);
4358	} else /* if (OP1_TYPE == IS_VAR) */ {
4359		if (UNEXPECTED(Z_ISREF_P(varptr))) {
4360			zend_refcounted *ref = Z_COUNTED_P(varptr);
4361
4362			varptr = Z_REFVAL_P(varptr);
4363			ZVAL_COPY_VALUE(arg, varptr);
4364			if (UNEXPECTED(--GC_REFCOUNT(ref) == 0)) {
4365				efree_size(ref, sizeof(zend_reference));
4366			} else if (Z_OPT_REFCOUNTED_P(arg)) {
4367				Z_ADDREF_P(arg);
4368			}
4369		} else {
4370			ZVAL_COPY_VALUE(arg, varptr);
4371		}
4372	}
4373
4374	ZEND_VM_NEXT_OPCODE();
4375}
4376
4377ZEND_VM_HANDLER(106, ZEND_SEND_VAR_NO_REF, VAR, NUM, SEND)
4378{
4379	USE_OPLINE
4380	zend_free_op free_op1;
4381	zval *varptr, *arg;
4382
4383	if (!(opline->extended_value & ZEND_ARG_COMPILE_TIME_BOUND)) {
4384		if (!ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4385			ZEND_VM_DISPATCH_TO_HANDLER(ZEND_SEND_VAR);
4386		}
4387	}
4388
4389	varptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
4390
4391	if ((!(opline->extended_value & ZEND_ARG_SEND_FUNCTION) ||
4392	     (Z_VAR_FLAGS_P(varptr) & IS_VAR_RET_REF)) &&
4393	    (Z_ISREF_P(varptr) || Z_TYPE_P(varptr) == IS_OBJECT)) {
4394
4395		ZVAL_MAKE_REF(varptr);
4396	} else {
4397		if ((opline->extended_value & ZEND_ARG_COMPILE_TIME_BOUND) ?
4398			!(opline->extended_value & ZEND_ARG_SEND_SILENT) :
4399			!ARG_MAY_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4400			SAVE_OPLINE();
4401			zend_error(E_NOTICE, "Only variables should be passed by reference");
4402			arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4403			ZVAL_COPY_VALUE(arg, varptr);
4404			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4405		}
4406	}
4407
4408	arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4409	ZVAL_COPY_VALUE(arg, varptr);
4410
4411	ZEND_VM_NEXT_OPCODE();
4412}
4413
4414ZEND_VM_HANDLER(67, ZEND_SEND_REF, VAR|CV, NUM)
4415{
4416	USE_OPLINE
4417	zend_free_op free_op1;
4418	zval *varptr, *arg;
4419
4420	SAVE_OPLINE();
4421	varptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
4422
4423	arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4424	if (OP1_TYPE == IS_VAR && UNEXPECTED(Z_ISERROR_P(varptr))) {
4425		ZVAL_NEW_REF(arg, &EG(uninitialized_zval));
4426		ZEND_VM_NEXT_OPCODE();
4427	}
4428
4429	if (Z_ISREF_P(varptr)) {
4430		Z_ADDREF_P(varptr);
4431		ZVAL_COPY_VALUE(arg, varptr);
4432	} else {
4433		ZVAL_NEW_REF(arg, varptr);
4434		Z_ADDREF_P(arg);
4435		ZVAL_REF(varptr, Z_REF_P(arg));
4436	}
4437
4438	FREE_OP1_VAR_PTR();
4439	ZEND_VM_NEXT_OPCODE();
4440}
4441
4442ZEND_VM_HANDLER(66, ZEND_SEND_VAR_EX, VAR|CV, NUM, SPEC(QUICK_ARG))
4443{
4444	USE_OPLINE
4445	zval *varptr, *arg;
4446	zend_free_op free_op1;
4447	uint32_t arg_num = opline->op2.num;
4448
4449	if (EXPECTED(arg_num <= MAX_ARG_FLAG_NUM)) {
4450		if (QUICK_ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4451			ZEND_VM_C_GOTO(send_var_by_ref);
4452		}
4453	} else if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4454ZEND_VM_C_LABEL(send_var_by_ref):
4455		ZEND_VM_DISPATCH_TO_HANDLER(ZEND_SEND_REF);
4456	}
4457
4458	varptr = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4459	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(varptr) == IS_UNDEF)) {
4460		SAVE_OPLINE();
4461		GET_OP1_UNDEF_CV(varptr, BP_VAR_R);
4462		arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4463		ZVAL_NULL(arg);
4464		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4465	}
4466
4467	arg = ZEND_CALL_VAR(EX(call), opline->result.var);
4468
4469	if (OP1_TYPE == IS_CV) {
4470		ZVAL_OPT_DEREF(varptr);
4471		ZVAL_COPY(arg, varptr);
4472	} else /* if (OP1_TYPE == IS_VAR) */ {
4473		if (UNEXPECTED(Z_ISREF_P(varptr))) {
4474			zend_refcounted *ref = Z_COUNTED_P(varptr);
4475
4476			varptr = Z_REFVAL_P(varptr);
4477			ZVAL_COPY_VALUE(arg, varptr);
4478			if (UNEXPECTED(--GC_REFCOUNT(ref) == 0)) {
4479				efree_size(ref, sizeof(zend_reference));
4480			} else if (Z_OPT_REFCOUNTED_P(arg)) {
4481				Z_ADDREF_P(arg);
4482			}
4483		} else {
4484			ZVAL_COPY_VALUE(arg, varptr);
4485		}
4486	}
4487
4488	ZEND_VM_NEXT_OPCODE();
4489}
4490
4491ZEND_VM_HANDLER(165, ZEND_SEND_UNPACK, ANY, ANY)
4492{
4493	USE_OPLINE
4494	zend_free_op free_op1;
4495	zval *args;
4496	int arg_num;
4497
4498	SAVE_OPLINE();
4499	args = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4500	arg_num = ZEND_CALL_NUM_ARGS(EX(call)) + 1;
4501
4502ZEND_VM_C_LABEL(send_again):
4503	if (EXPECTED(Z_TYPE_P(args) == IS_ARRAY)) {
4504		HashTable *ht = Z_ARRVAL_P(args);
4505		zval *arg, *top;
4506		zend_string *name;
4507
4508		zend_vm_stack_extend_call_frame(&EX(call), arg_num - 1, zend_hash_num_elements(ht));
4509
4510		if (OP1_TYPE != IS_CONST && OP1_TYPE != IS_TMP_VAR && Z_IMMUTABLE_P(args)) {
4511			uint32_t i;
4512			int separate = 0;
4513
4514			/* check if any of arguments are going to be passed by reference */
4515			for (i = 0; i < zend_hash_num_elements(ht); i++) {
4516				if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num + i)) {
4517					separate = 1;
4518					break;
4519				}
4520			}
4521			if (separate) {
4522				zval_copy_ctor(args);
4523				ht = Z_ARRVAL_P(args);
4524			}
4525		}
4526
4527		ZEND_HASH_FOREACH_STR_KEY_VAL(ht, name, arg) {
4528			if (name) {
4529				zend_throw_error(NULL, "Cannot unpack array with string keys");
4530				FREE_OP1();
4531				HANDLE_EXCEPTION();
4532			}
4533
4534			top = ZEND_CALL_ARG(EX(call), arg_num);
4535			if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4536				if (!Z_IMMUTABLE_P(args)) {
4537					ZVAL_MAKE_REF(arg);
4538					Z_ADDREF_P(arg);
4539					ZVAL_REF(top, Z_REF_P(arg));
4540				} else {
4541					ZVAL_DUP(top, arg);
4542				}
4543			} else if (Z_ISREF_P(arg)) {
4544				ZVAL_COPY(top, Z_REFVAL_P(arg));
4545			} else {
4546				ZVAL_COPY(top, arg);
4547			}
4548
4549			ZEND_CALL_NUM_ARGS(EX(call))++;
4550			arg_num++;
4551		} ZEND_HASH_FOREACH_END();
4552
4553	} else if (EXPECTED(Z_TYPE_P(args) == IS_OBJECT)) {
4554		zend_class_entry *ce = Z_OBJCE_P(args);
4555		zend_object_iterator *iter;
4556
4557		if (!ce || !ce->get_iterator) {
4558			zend_error(E_WARNING, "Only arrays and Traversables can be unpacked");
4559		} else {
4560
4561			iter = ce->get_iterator(ce, args, 0);
4562			if (UNEXPECTED(!iter)) {
4563				FREE_OP1();
4564				if (!EG(exception)) {
4565					zend_throw_exception_ex(
4566						NULL, 0, "Object of type %s did not create an Iterator", ZSTR_VAL(ce->name)
4567					);
4568				}
4569				HANDLE_EXCEPTION();
4570			}
4571
4572			if (iter->funcs->rewind) {
4573				iter->funcs->rewind(iter);
4574				if (UNEXPECTED(EG(exception) != NULL)) {
4575					ZEND_VM_C_GOTO(unpack_iter_dtor);
4576				}
4577			}
4578
4579			for (; iter->funcs->valid(iter) == SUCCESS; ++arg_num) {
4580				zval *arg, *top;
4581
4582				if (UNEXPECTED(EG(exception) != NULL)) {
4583					ZEND_VM_C_GOTO(unpack_iter_dtor);
4584				}
4585
4586				arg = iter->funcs->get_current_data(iter);
4587				if (UNEXPECTED(EG(exception) != NULL)) {
4588					ZEND_VM_C_GOTO(unpack_iter_dtor);
4589				}
4590
4591				if (iter->funcs->get_current_key) {
4592					zval key;
4593					iter->funcs->get_current_key(iter, &key);
4594					if (UNEXPECTED(EG(exception) != NULL)) {
4595						ZEND_VM_C_GOTO(unpack_iter_dtor);
4596					}
4597
4598					if (Z_TYPE(key) == IS_STRING) {
4599						zend_throw_error(NULL,
4600							"Cannot unpack Traversable with string keys");
4601						zend_string_release(Z_STR(key));
4602						ZEND_VM_C_GOTO(unpack_iter_dtor);
4603					}
4604
4605					zval_dtor(&key);
4606				}
4607
4608				if (ARG_MUST_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4609					zend_error(
4610						E_WARNING, "Cannot pass by-reference argument %d of %s%s%s()"
4611						" by unpacking a Traversable, passing by-value instead", arg_num,
4612						EX(call)->func->common.scope ? ZSTR_VAL(EX(call)->func->common.scope->name) : "",
4613						EX(call)->func->common.scope ? "::" : "",
4614						ZSTR_VAL(EX(call)->func->common.function_name)
4615					);
4616				}
4617
4618				if (Z_ISREF_P(arg)) {
4619					ZVAL_DUP(arg, Z_REFVAL_P(arg));
4620				} else {
4621					if (Z_REFCOUNTED_P(arg)) Z_ADDREF_P(arg);
4622				}
4623
4624				zend_vm_stack_extend_call_frame(&EX(call), arg_num - 1, 1);
4625				top = ZEND_CALL_ARG(EX(call), arg_num);
4626				ZVAL_COPY_VALUE(top, arg);
4627				ZEND_CALL_NUM_ARGS(EX(call))++;
4628
4629				iter->funcs->move_forward(iter);
4630				if (UNEXPECTED(EG(exception) != NULL)) {
4631					ZEND_VM_C_GOTO(unpack_iter_dtor);
4632				}
4633			}
4634
4635ZEND_VM_C_LABEL(unpack_iter_dtor):
4636			zend_iterator_dtor(iter);
4637		}
4638	} else if (EXPECTED(Z_ISREF_P(args))) {
4639		args = Z_REFVAL_P(args);
4640		ZEND_VM_C_GOTO(send_again);
4641	} else {
4642		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(args) == IS_UNDEF)) {
4643			GET_OP1_UNDEF_CV(args, BP_VAR_R);
4644		}
4645		zend_error(E_WARNING, "Only arrays and Traversables can be unpacked");
4646	}
4647
4648	FREE_OP1();
4649	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4650}
4651
4652ZEND_VM_HANDLER(119, ZEND_SEND_ARRAY, ANY, ANY)
4653{
4654	USE_OPLINE
4655	zend_free_op free_op1;
4656	zval *args;
4657	SAVE_OPLINE();
4658
4659	SAVE_OPLINE();
4660	args = GET_OP1_ZVAL_PTR(BP_VAR_R);
4661
4662	if (UNEXPECTED(Z_TYPE_P(args) != IS_ARRAY)) {
4663		if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(args)) {
4664			args = Z_REFVAL_P(args);
4665			if (EXPECTED(Z_TYPE_P(args) == IS_ARRAY)) {
4666				ZEND_VM_C_GOTO(send_array);
4667			}
4668		}
4669		zend_internal_type_error(EX_USES_STRICT_TYPES(), "call_user_func_array() expects parameter 2 to be array, %s given", zend_get_type_by_const(Z_TYPE_P(args)));
4670		if (ZEND_CALL_INFO(EX(call)) & ZEND_CALL_CLOSURE) {
4671			OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
4672		}
4673		if (Z_OBJ(EX(call)->This)) {
4674			OBJ_RELEASE(Z_OBJ(EX(call)->This));
4675		}
4676		EX(call)->func = (zend_function*)&zend_pass_function;
4677		EX(call)->called_scope = NULL;
4678		Z_OBJ(EX(call)->This) = NULL;
4679	} else {
4680		uint32_t arg_num;
4681		HashTable *ht;
4682		zval *arg, *param;
4683
4684ZEND_VM_C_LABEL(send_array):
4685		ht = Z_ARRVAL_P(args);
4686		zend_vm_stack_extend_call_frame(&EX(call), 0, zend_hash_num_elements(ht));
4687
4688		if (OP1_TYPE != IS_CONST && OP1_TYPE != IS_TMP_VAR && Z_IMMUTABLE_P(args)) {
4689			int separate = 0;
4690
4691			/* check if any of arguments are going to be passed by reference */
4692			for (arg_num = 0; arg_num < zend_hash_num_elements(ht); arg_num++) {
4693				if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num + 1)) {
4694					separate = 1;
4695					break;
4696				}
4697			}
4698			if (separate) {
4699				zval_copy_ctor(args);
4700				ht = Z_ARRVAL_P(args);
4701			}
4702		}
4703
4704		arg_num = 1;
4705		param = ZEND_CALL_ARG(EX(call), 1);
4706		ZEND_HASH_FOREACH_VAL(ht, arg) {
4707			if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4708				if (UNEXPECTED(!Z_ISREF_P(arg))) {
4709					if (!ARG_MAY_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
4710
4711						zend_error(E_WARNING, "Parameter %d to %s%s%s() expected to be a reference, value given",
4712							arg_num,
4713							EX(call)->func->common.scope ? ZSTR_VAL(EX(call)->func->common.scope->name) : "",
4714							EX(call)->func->common.scope ? "::" : "",
4715							ZSTR_VAL(EX(call)->func->common.function_name));
4716
4717						if (ZEND_CALL_INFO(EX(call)) & ZEND_CALL_CLOSURE) {
4718							OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
4719						}
4720						if (Z_OBJ(EX(call)->This)) {
4721							OBJ_RELEASE(Z_OBJ(EX(call)->This));
4722						}
4723						EX(call)->func = (zend_function*)&zend_pass_function;
4724						EX(call)->called_scope = NULL;
4725						Z_OBJ(EX(call)->This) = NULL;
4726
4727						break;
4728					}
4729
4730					ZVAL_NEW_REF(arg, arg);
4731				}
4732				Z_ADDREF_P(arg);
4733			} else{
4734				if (Z_ISREF_P(arg) &&
4735				    !(EX(call)->func->common.fn_flags & ZEND_ACC_CALL_VIA_TRAMPOLINE)) {
4736					/* don't separate references for __call */
4737					arg = Z_REFVAL_P(arg);
4738				}
4739				if (Z_OPT_REFCOUNTED_P(arg)) {
4740					Z_ADDREF_P(arg);
4741				}
4742			}
4743			ZVAL_COPY_VALUE(param, arg);
4744			ZEND_CALL_NUM_ARGS(EX(call))++;
4745			arg_num++;
4746			param++;
4747		} ZEND_HASH_FOREACH_END();
4748	}
4749	FREE_OP1();
4750	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4751}
4752
4753ZEND_VM_HANDLER(120, ZEND_SEND_USER, VAR|CV, NUM)
4754{
4755	USE_OPLINE
4756	zval *arg, *param;
4757	zend_free_op free_op1;
4758
4759	SAVE_OPLINE();
4760	arg = GET_OP1_ZVAL_PTR(BP_VAR_R);
4761	param = ZEND_CALL_VAR(EX(call), opline->result.var);
4762
4763	if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4764		if (UNEXPECTED(!Z_ISREF_P(arg))) {
4765
4766			if (!ARG_MAY_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
4767
4768				zend_error(E_WARNING, "Parameter %d to %s%s%s() expected to be a reference, value given",
4769					opline->op2.num,
4770					EX(call)->func->common.scope ? ZSTR_VAL(EX(call)->func->common.scope->name) : "",
4771					EX(call)->func->common.scope ? "::" : "",
4772					ZSTR_VAL(EX(call)->func->common.function_name));
4773
4774				if (ZEND_CALL_INFO(EX(call)) & ZEND_CALL_CLOSURE) {
4775					OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
4776				}
4777				if (Z_OBJ(EX(call)->This)) {
4778					OBJ_RELEASE(Z_OBJ(EX(call)->This));
4779				}
4780				ZVAL_UNDEF(param);
4781				EX(call)->func = (zend_function*)&zend_pass_function;
4782				EX(call)->called_scope = NULL;
4783				Z_OBJ(EX(call)->This) = NULL;
4784
4785				FREE_OP1();
4786				ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4787			}
4788
4789			ZVAL_NEW_REF(arg, arg);
4790		}
4791		Z_ADDREF_P(arg);
4792	} else {
4793		if (Z_ISREF_P(arg) &&
4794		    !(EX(call)->func->common.fn_flags & ZEND_ACC_CALL_VIA_TRAMPOLINE)) {
4795			/* don't separate references for __call */
4796			arg = Z_REFVAL_P(arg);
4797		}
4798		if (Z_OPT_REFCOUNTED_P(arg)) {
4799			Z_ADDREF_P(arg);
4800		}
4801	}
4802	ZVAL_COPY_VALUE(param, arg);
4803
4804	FREE_OP1();
4805	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4806}
4807
4808ZEND_VM_HANDLER(63, ZEND_RECV, NUM, ANY)
4809{
4810	USE_OPLINE
4811	uint32_t arg_num = opline->op1.num;
4812
4813	if (UNEXPECTED(arg_num > EX_NUM_ARGS())) {
4814		SAVE_OPLINE();
4815		zend_verify_missing_arg(execute_data, arg_num, CACHE_ADDR(opline->op2.num));
4816		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4817	} else if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
4818		zval *param = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var);
4819
4820		SAVE_OPLINE();
4821		if (UNEXPECTED(!zend_verify_arg_type(EX(func), arg_num, param, NULL, CACHE_ADDR(opline->op2.num)))) {
4822			HANDLE_EXCEPTION();
4823		}
4824	}
4825
4826	ZEND_VM_NEXT_OPCODE();
4827}
4828
4829ZEND_VM_HANDLER(64, ZEND_RECV_INIT, NUM, CONST)
4830{
4831	USE_OPLINE
4832	uint32_t arg_num;
4833	zval *param;
4834
4835	ZEND_VM_REPEATABLE_OPCODE
4836
4837	arg_num = opline->op1.num;
4838	param = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var);
4839	if (arg_num > EX_NUM_ARGS()) {
4840		ZVAL_COPY_VALUE(param, EX_CONSTANT(opline->op2));
4841		if (Z_OPT_CONSTANT_P(param)) {
4842			SAVE_OPLINE();
4843			if (UNEXPECTED(zval_update_constant_ex(param, 0, NULL) != SUCCESS)) {
4844				ZVAL_UNDEF(param);
4845				HANDLE_EXCEPTION();
4846			}
4847		} else {
4848			/* IS_CONST can't be IS_OBJECT, IS_RESOURCE or IS_REFERENCE */
4849			if (UNEXPECTED(Z_OPT_COPYABLE_P(param))) {
4850				zval_copy_ctor_func(param);
4851			}
4852		}
4853	}
4854
4855	if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
4856		zval *default_value = EX_CONSTANT(opline->op2);
4857
4858		SAVE_OPLINE();
4859		if (UNEXPECTED(!zend_verify_arg_type(EX(func), arg_num, param, default_value, CACHE_ADDR(Z_CACHE_SLOT_P(default_value))))) {
4860			HANDLE_EXCEPTION();
4861		}
4862	}
4863
4864	ZEND_VM_REPEAT_OPCODE(ZEND_RECV_INIT);
4865	ZEND_VM_NEXT_OPCODE();
4866}
4867
4868ZEND_VM_HANDLER(164, ZEND_RECV_VARIADIC, NUM, ANY)
4869{
4870	USE_OPLINE
4871	uint32_t arg_num = opline->op1.num;
4872	uint32_t arg_count = EX_NUM_ARGS();
4873	zval *params;
4874
4875	SAVE_OPLINE();
4876
4877	params = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var);
4878
4879	if (arg_num <= arg_count) {
4880		zval *param;
4881
4882		array_init_size(params, arg_count - arg_num + 1);
4883		zend_hash_real_init(Z_ARRVAL_P(params), 1);
4884		ZEND_HASH_FILL_PACKED(Z_ARRVAL_P(params)) {
4885			param = EX_VAR_NUM(EX(func)->op_array.last_var + EX(func)->op_array.T);
4886			if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
4887				do {
4888					zend_verify_arg_type(EX(func), arg_num, param, NULL, CACHE_ADDR(opline->op2.num));
4889					if (Z_OPT_REFCOUNTED_P(param)) Z_ADDREF_P(param);
4890					ZEND_HASH_FILL_ADD(param);
4891					param++;
4892				} while (++arg_num <= arg_count);
4893			} else {
4894				do {
4895					if (Z_OPT_REFCOUNTED_P(param)) Z_ADDREF_P(param);
4896					ZEND_HASH_FILL_ADD(param);
4897					param++;
4898				} while (++arg_num <= arg_count);
4899			}
4900		} ZEND_HASH_FILL_END();
4901	} else {
4902		array_init(params);
4903	}
4904
4905	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4906}
4907
4908ZEND_VM_HANDLER(52, ZEND_BOOL, CONST|TMPVAR|CV, ANY)
4909{
4910	USE_OPLINE
4911	zval *val;
4912	zend_free_op free_op1;
4913
4914	val = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4915	if (Z_TYPE_INFO_P(val) == IS_TRUE) {
4916		ZVAL_TRUE(EX_VAR(opline->result.var));
4917	} else if (EXPECTED(Z_TYPE_INFO_P(val) <= IS_TRUE)) {
4918		ZVAL_FALSE(EX_VAR(opline->result.var));
4919		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_INFO_P(val) == IS_UNDEF)) {
4920			SAVE_OPLINE();
4921			GET_OP1_UNDEF_CV(val, BP_VAR_R);
4922			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4923		}
4924	} else {
4925		SAVE_OPLINE();
4926		ZVAL_BOOL(EX_VAR(opline->result.var), i_zend_is_true(val));
4927		FREE_OP1();
4928		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4929	}
4930	ZEND_VM_NEXT_OPCODE();
4931}
4932
4933ZEND_VM_HANDLER(48, ZEND_CASE, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
4934{
4935	USE_OPLINE
4936	zend_free_op free_op1, free_op2;
4937	zval *op1, *op2, *result;
4938
4939	op1 = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
4940	op2 = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
4941	do {
4942		int result;
4943
4944		if (EXPECTED(Z_TYPE_P(op1) == IS_LONG)) {
4945			if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
4946				result = (Z_LVAL_P(op1) == Z_LVAL_P(op2));
4947			} else if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
4948				result = ((double)Z_LVAL_P(op1) == Z_DVAL_P(op2));
4949			} else {
4950				break;
4951			}
4952		} else if (EXPECTED(Z_TYPE_P(op1) == IS_DOUBLE)) {
4953			if (EXPECTED(Z_TYPE_P(op2) == IS_DOUBLE)) {
4954				result = (Z_DVAL_P(op1) == Z_DVAL_P(op2));
4955			} else if (EXPECTED(Z_TYPE_P(op2) == IS_LONG)) {
4956				result = (Z_DVAL_P(op1) == ((double)Z_LVAL_P(op2)));
4957			} else {
4958				break;
4959			}
4960		} else if (EXPECTED(Z_TYPE_P(op1) == IS_STRING)) {
4961			if (EXPECTED(Z_TYPE_P(op2) == IS_STRING)) {
4962				if (Z_STR_P(op1) == Z_STR_P(op2)) {
4963					result = 1;
4964				} else if (Z_STRVAL_P(op1)[0] > '9' || Z_STRVAL_P(op2)[0] > '9') {
4965					if (Z_STRLEN_P(op1) != Z_STRLEN_P(op2)) {
4966						result = 0;
4967					} else {
4968						result = (memcmp(Z_STRVAL_P(op1), Z_STRVAL_P(op2), Z_STRLEN_P(op1)) == 0);
4969					}
4970				} else {
4971					result = (zendi_smart_strcmp(Z_STR_P(op1), Z_STR_P(op2)) == 0);
4972				}
4973				FREE_OP2();
4974			} else {
4975				break;
4976			}
4977		} else {
4978			break;
4979		}
4980		ZEND_VM_SMART_BRANCH(result, 0);
4981		ZVAL_BOOL(EX_VAR(opline->result.var), result);
4982		ZEND_VM_NEXT_OPCODE();
4983	} while (0);
4984
4985	SAVE_OPLINE();
4986	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op1) == IS_UNDEF)) {
4987		op1 = GET_OP1_UNDEF_CV(op1, BP_VAR_R);
4988	}
4989	if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(op2) == IS_UNDEF)) {
4990		op2 = GET_OP2_UNDEF_CV(op2, BP_VAR_R);
4991	}
4992	result = EX_VAR(opline->result.var);
4993	compare_function(result, op1, op2);
4994	ZVAL_BOOL(result, Z_LVAL_P(result) == 0);
4995	FREE_OP2();
4996	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
4997}
4998
4999ZEND_VM_HANDLER(68, ZEND_NEW, UNUSED|CLASS_FETCH|CONST|VAR, JMP_ADDR, NUM)
5000{
5001	USE_OPLINE
5002	zval object_zval;
5003	zend_function *constructor;
5004	zend_class_entry *ce;
5005
5006	SAVE_OPLINE();
5007	if (OP1_TYPE == IS_CONST) {
5008		ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
5009		if (UNEXPECTED(ce == NULL)) {
5010			ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
5011			if (UNEXPECTED(ce == NULL)) {
5012				ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5013			}
5014			CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce);
5015		}
5016	} else if (OP1_TYPE == IS_UNUSED) {
5017		ce = zend_fetch_class(NULL, opline->op1.num);
5018		if (UNEXPECTED(ce == NULL)) {
5019			ZEND_ASSERT(EG(exception));
5020			HANDLE_EXCEPTION();
5021		}
5022	} else {
5023		ce = Z_CE_P(EX_VAR(opline->op1.var));
5024	}
5025	if (UNEXPECTED(object_init_ex(&object_zval, ce) != SUCCESS)) {
5026		HANDLE_EXCEPTION();
5027	}
5028	constructor = Z_OBJ_HT(object_zval)->get_constructor(Z_OBJ(object_zval));
5029
5030	if (constructor == NULL) {
5031		if (EXPECTED(RETURN_VALUE_USED(opline))) {
5032			ZVAL_COPY_VALUE(EX_VAR(opline->result.var), &object_zval);
5033		} else {
5034			OBJ_RELEASE(Z_OBJ(object_zval));
5035		}
5036		ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
5037	} else {
5038		/* We are not handling overloaded classes right now */
5039		zend_execute_data *call = zend_vm_stack_push_call_frame(
5040				ZEND_CALL_FUNCTION | ZEND_CALL_RELEASE_THIS | ZEND_CALL_CTOR |
5041				(EXPECTED(RETURN_VALUE_USED(opline)) ? 0 : ZEND_CALL_CTOR_RESULT_UNUSED),
5042			constructor,
5043			opline->extended_value,
5044			ce,
5045			Z_OBJ(object_zval));
5046		call->prev_execute_data = EX(call);
5047		EX(call) = call;
5048
5049		if (EXPECTED(RETURN_VALUE_USED(opline))) {
5050			ZVAL_COPY(EX_VAR(opline->result.var), &object_zval);
5051		}
5052
5053		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5054	}
5055}
5056
5057ZEND_VM_HANDLER(110, ZEND_CLONE, CONST|TMPVAR|UNUSED|THIS|CV, ANY)
5058{
5059	USE_OPLINE
5060	zend_free_op free_op1;
5061	zval *obj;
5062	zend_class_entry *ce;
5063	zend_function *clone;
5064	zend_object_clone_obj_t clone_call;
5065
5066	SAVE_OPLINE();
5067	obj = GET_OP1_OBJ_ZVAL_PTR_UNDEF(BP_VAR_R);
5068
5069	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(obj) == NULL)) {
5070		zend_throw_error(NULL, "Using $this when not in object context");
5071		HANDLE_EXCEPTION();
5072	}
5073
5074	do {
5075		if (OP1_TYPE == IS_CONST ||
5076		    (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(obj) != IS_OBJECT))) {
5077		    if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(obj)) {
5078		    	obj = Z_REFVAL_P(obj);
5079		    	if (EXPECTED(Z_TYPE_P(obj) == IS_OBJECT)) {
5080		    		break;
5081				}
5082			}
5083			if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(obj) == IS_UNDEF)) {
5084				GET_OP1_UNDEF_CV(obj, BP_VAR_R);
5085				if (UNEXPECTED(EG(exception) != NULL)) {
5086					HANDLE_EXCEPTION();
5087				}
5088			}
5089			zend_throw_error(NULL, "__clone method called on non-object");
5090			FREE_OP1();
5091			HANDLE_EXCEPTION();
5092		}
5093	} while (0);
5094
5095	ce = Z_OBJCE_P(obj);
5096	clone = ce->clone;
5097	clone_call = Z_OBJ_HT_P(obj)->clone_obj;
5098	if (UNEXPECTED(clone_call == NULL)) {
5099		zend_throw_error(NULL, "Trying to clone an uncloneable object of class %s", ZSTR_VAL(ce->name));
5100		FREE_OP1();
5101		HANDLE_EXCEPTION();
5102	}
5103
5104	if (clone) {
5105		if (clone->op_array.fn_flags & ZEND_ACC_PRIVATE) {
5106			/* Ensure that if we're calling a private function, we're allowed to do so.
5107			 */
5108			if (UNEXPECTED(ce != EG(scope))) {
5109				zend_throw_error(NULL, "Call to private %s::__clone() from context '%s'", ZSTR_VAL(ce->name), EG(scope) ? ZSTR_VAL(EG(scope)->name) : "");
5110				FREE_OP1();
5111				HANDLE_EXCEPTION();
5112			}
5113		} else if ((clone->common.fn_flags & ZEND_ACC_PROTECTED)) {
5114			/* Ensure that if we're calling a protected function, we're allowed to do so.
5115			 */
5116			if (UNEXPECTED(!zend_check_protected(zend_get_function_root_class(clone), EG(scope)))) {
5117				zend_throw_error(NULL, "Call to protected %s::__clone() from context '%s'", ZSTR_VAL(ce->name), EG(scope) ? ZSTR_VAL(EG(scope)->name) : "");
5118				FREE_OP1();
5119				HANDLE_EXCEPTION();
5120			}
5121		}
5122	}
5123
5124	ZVAL_OBJ(EX_VAR(opline->result.var), clone_call(obj));
5125	if (UNEXPECTED(EG(exception) != NULL)) {
5126		OBJ_RELEASE(Z_OBJ_P(EX_VAR(opline->result.var)));
5127	}
5128
5129	FREE_OP1();
5130	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5131}
5132
5133ZEND_VM_HANDLER(99, ZEND_FETCH_CONSTANT, UNUSED, CONST, CONST_FETCH)
5134{
5135	USE_OPLINE
5136	zend_constant *c;
5137
5138	SAVE_OPLINE();
5139
5140	if (EXPECTED(CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2))))) {
5141		c = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
5142	} else if ((c = zend_quick_get_constant(EX_CONSTANT(opline->op2) + 1, opline->extended_value)) == NULL) {
5143		if ((opline->extended_value & IS_CONSTANT_UNQUALIFIED) != 0) {
5144			char *actual = (char *)zend_memrchr(Z_STRVAL_P(EX_CONSTANT(opline->op2)), '\\', Z_STRLEN_P(EX_CONSTANT(opline->op2)));
5145			if (!actual) {
5146				ZVAL_STR_COPY(EX_VAR(opline->result.var), Z_STR_P(EX_CONSTANT(opline->op2)));
5147			} else {
5148				actual++;
5149				ZVAL_STRINGL(EX_VAR(opline->result.var),
5150						actual, Z_STRLEN_P(EX_CONSTANT(opline->op2)) - (actual - Z_STRVAL_P(EX_CONSTANT(opline->op2))));
5151			}
5152			/* non-qualified constant - allow text substitution */
5153			zend_error(E_NOTICE, "Use of undefined constant %s - assumed '%s'",
5154					Z_STRVAL_P(EX_VAR(opline->result.var)), Z_STRVAL_P(EX_VAR(opline->result.var)));
5155			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5156		} else {
5157			zend_throw_error(NULL, "Undefined constant '%s'", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
5158			HANDLE_EXCEPTION();
5159		}
5160	} else {
5161		CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), c);
5162	}
5163
5164#ifdef ZTS
5165	if (c->flags & CONST_PERSISTENT) {
5166		ZVAL_DUP(EX_VAR(opline->result.var), &c->value);
5167	} else {
5168		ZVAL_COPY(EX_VAR(opline->result.var), &c->value);
5169	}
5170#else
5171	ZVAL_COPY(EX_VAR(opline->result.var), &c->value);
5172#endif
5173
5174	ZEND_VM_NEXT_OPCODE();
5175}
5176
5177ZEND_VM_HANDLER(181, ZEND_FETCH_CLASS_CONSTANT, VAR|CONST|UNUSED|CLASS_FETCH, CONST)
5178{
5179	zend_class_entry *ce;
5180	zend_class_constant *c;
5181	zval *value;
5182	USE_OPLINE
5183
5184	SAVE_OPLINE();
5185
5186	do {
5187		if (OP1_TYPE == IS_CONST) {
5188			if (EXPECTED(CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2))))) {
5189				value = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
5190#ifdef ZTS
5191				ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
5192#endif
5193				break;
5194			} else if (EXPECTED(CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1))))) {
5195				ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
5196			} else {
5197				ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
5198				if (UNEXPECTED(ce == NULL)) {
5199					if (EXPECTED(!EG(exception))) {
5200						zend_throw_error(NULL, "Class '%s' not found", Z_STRVAL_P(EX_CONSTANT(opline->op1)));
5201					}
5202					HANDLE_EXCEPTION();
5203				}
5204				CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce);
5205			}
5206		} else {
5207			if (OP1_TYPE == IS_UNUSED) {
5208				ce = zend_fetch_class(NULL, opline->op1.num);
5209				if (UNEXPECTED(ce == NULL)) {
5210					ZEND_ASSERT(EG(exception));
5211					HANDLE_EXCEPTION();
5212				}
5213			} else {
5214				ce = Z_CE_P(EX_VAR(opline->op1.var));
5215			}
5216			if ((value = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce)) != NULL) {
5217				break;
5218			}
5219		}
5220
5221		if (EXPECTED((c = zend_hash_find_ptr(&ce->constants_table, Z_STR_P(EX_CONSTANT(opline->op2)))) != NULL)) {
5222			if (!zend_verify_const_access(c, EG(scope))) {
5223				zend_throw_error(NULL, "Cannot access %s const %s::%s", zend_visibility_string(Z_ACCESS_FLAGS(c->value)), ZSTR_VAL(ce->name), Z_STRVAL_P(EX_CONSTANT(opline->op2)));
5224				HANDLE_EXCEPTION();
5225			}
5226			value = &c->value;
5227			if (Z_CONSTANT_P(value)) {
5228				EG(scope) = ce;
5229				zval_update_constant_ex(value, 1, NULL);
5230				EG(scope) = EX(func)->op_array.scope;
5231				if (UNEXPECTED(EG(exception) != NULL)) {
5232					HANDLE_EXCEPTION();
5233				}
5234			}
5235			if (OP1_TYPE == IS_CONST) {
5236				CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), value);
5237			} else {
5238				CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce, value);
5239			}
5240		} else {
5241			zend_throw_error(NULL, "Undefined class constant '%s'", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
5242			HANDLE_EXCEPTION();
5243		}
5244	} while (0);
5245
5246#ifdef ZTS
5247	if (ce->type == ZEND_INTERNAL_CLASS) {
5248		ZVAL_DUP(EX_VAR(opline->result.var), value);
5249	} else {
5250		ZVAL_COPY(EX_VAR(opline->result.var), value);
5251	}
5252#else
5253	ZVAL_COPY(EX_VAR(opline->result.var), value);
5254#endif
5255
5256	ZEND_VM_NEXT_OPCODE();
5257}
5258
5259ZEND_VM_HANDLER(72, ZEND_ADD_ARRAY_ELEMENT, CONST|TMP|VAR|CV, CONST|TMPVAR|UNUSED|NEXT|CV, REF)
5260{
5261	USE_OPLINE
5262	zend_free_op free_op1;
5263	zval *expr_ptr, new_expr;
5264
5265	SAVE_OPLINE();
5266	if ((OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) &&
5267	    UNEXPECTED(opline->extended_value & ZEND_ARRAY_ELEMENT_REF)) {
5268		expr_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
5269		ZVAL_MAKE_REF(expr_ptr);
5270		Z_ADDREF_P(expr_ptr);
5271		FREE_OP1_VAR_PTR();
5272	} else {
5273		expr_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
5274		if (OP1_TYPE == IS_TMP_VAR) {
5275			/* pass */
5276		} else if (OP1_TYPE == IS_CONST) {
5277			if (UNEXPECTED(Z_OPT_COPYABLE_P(expr_ptr))) {
5278				ZVAL_COPY_VALUE(&new_expr, expr_ptr);
5279				zval_copy_ctor_func(&new_expr);
5280				expr_ptr = &new_expr;
5281			}
5282		} else if (OP1_TYPE == IS_CV) {
5283			ZVAL_DEREF(expr_ptr);
5284			if (Z_REFCOUNTED_P(expr_ptr)) {
5285				Z_ADDREF_P(expr_ptr);
5286			}
5287		} else /* if (OP1_TYPE == IS_VAR) */ {
5288			if (UNEXPECTED(Z_ISREF_P(expr_ptr))) {
5289				zend_refcounted *ref = Z_COUNTED_P(expr_ptr);
5290
5291				expr_ptr = Z_REFVAL_P(expr_ptr);
5292				if (UNEXPECTED(--GC_REFCOUNT(ref) == 0)) {
5293					ZVAL_COPY_VALUE(&new_expr, expr_ptr);
5294					expr_ptr = &new_expr;
5295					efree_size(ref, sizeof(zend_reference));
5296				} else if (Z_OPT_REFCOUNTED_P(expr_ptr)) {
5297					Z_ADDREF_P(expr_ptr);
5298				}
5299			}
5300		}
5301	}
5302
5303	if (OP2_TYPE != IS_UNUSED) {
5304		zend_free_op free_op2;
5305		zval *offset = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
5306		zend_string *str;
5307		zend_ulong hval;
5308
5309ZEND_VM_C_LABEL(add_again):
5310		if (EXPECTED(Z_TYPE_P(offset) == IS_STRING)) {
5311			str = Z_STR_P(offset);
5312			if (OP2_TYPE != IS_CONST) {
5313				if (ZEND_HANDLE_NUMERIC(str, hval)) {
5314					ZEND_VM_C_GOTO(num_index);
5315				}
5316			}
5317ZEND_VM_C_LABEL(str_index):
5318			zend_hash_update(Z_ARRVAL_P(EX_VAR(opline->result.var)), str, expr_ptr);
5319		} else if (EXPECTED(Z_TYPE_P(offset) == IS_LONG)) {
5320			hval = Z_LVAL_P(offset);
5321ZEND_VM_C_LABEL(num_index):
5322			zend_hash_index_update(Z_ARRVAL_P(EX_VAR(opline->result.var)), hval, expr_ptr);
5323		} else if ((OP2_TYPE & (IS_VAR|IS_CV)) && EXPECTED(Z_TYPE_P(offset) == IS_REFERENCE)) {
5324			offset = Z_REFVAL_P(offset);
5325			ZEND_VM_C_GOTO(add_again);
5326		} else if (Z_TYPE_P(offset) == IS_NULL) {
5327			str = ZSTR_EMPTY_ALLOC();
5328			ZEND_VM_C_GOTO(str_index);
5329		} else if (Z_TYPE_P(offset) == IS_DOUBLE) {
5330			hval = zend_dval_to_lval(Z_DVAL_P(offset));
5331			ZEND_VM_C_GOTO(num_index);
5332		} else if (Z_TYPE_P(offset) == IS_FALSE) {
5333			hval = 0;
5334			ZEND_VM_C_GOTO(num_index);
5335		} else if (Z_TYPE_P(offset) == IS_TRUE) {
5336			hval = 1;
5337			ZEND_VM_C_GOTO(num_index);
5338		} else if (OP2_TYPE == IS_CV && Z_TYPE_P(offset) == IS_UNDEF) {
5339			GET_OP2_UNDEF_CV(offset, BP_VAR_R);
5340			str = ZSTR_EMPTY_ALLOC();
5341			ZEND_VM_C_GOTO(str_index);
5342		} else {
5343			zend_error(E_WARNING, "Illegal offset type");
5344			zval_ptr_dtor(expr_ptr);
5345		}
5346		FREE_OP2();
5347	} else {
5348		zend_hash_next_index_insert(Z_ARRVAL_P(EX_VAR(opline->result.var)), expr_ptr);
5349	}
5350	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5351}
5352
5353ZEND_VM_HANDLER(71, ZEND_INIT_ARRAY, CONST|TMP|VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|NEXT|CV, ARRAY_INIT|REF)
5354{
5355	zval *array;
5356	uint32_t size;
5357	USE_OPLINE
5358
5359	array = EX_VAR(opline->result.var);
5360	if (OP1_TYPE != IS_UNUSED) {
5361		size = opline->extended_value >> ZEND_ARRAY_SIZE_SHIFT;
5362	} else {
5363		size = 0;
5364	}
5365	ZVAL_NEW_ARR(array);
5366	zend_hash_init(Z_ARRVAL_P(array), size, NULL, ZVAL_PTR_DTOR, 0);
5367
5368	if (OP1_TYPE != IS_UNUSED) {
5369		/* Explicitly initialize array as not-packed if flag is set */
5370		if (opline->extended_value & ZEND_ARRAY_NOT_PACKED) {
5371			zend_hash_real_init(Z_ARRVAL_P(array), 0);
5372		}
5373	}
5374
5375	if (OP1_TYPE == IS_UNUSED) {
5376		ZEND_VM_NEXT_OPCODE();
5377#if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
5378	} else {
5379		ZEND_VM_DISPATCH_TO_HANDLER(ZEND_ADD_ARRAY_ELEMENT);
5380#endif
5381	}
5382}
5383
5384ZEND_VM_HANDLER(21, ZEND_CAST, CONST|TMP|VAR|CV, ANY, TYPE)
5385{
5386	USE_OPLINE
5387	zend_free_op free_op1;
5388	zval *expr;
5389	zval *result = EX_VAR(opline->result.var);
5390
5391	SAVE_OPLINE();
5392	expr = GET_OP1_ZVAL_PTR(BP_VAR_R);
5393
5394	switch (opline->extended_value) {
5395		case IS_NULL:
5396			/* This code is taken from convert_to_null. However, it does not seems very useful,
5397			 * because a conversion to null always results in the same value. This could only
5398			 * be relevant if a cast_object handler for IS_NULL has some kind of side-effect. */
5399#if 0
5400			if (OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) {
5401				ZVAL_DEREF(expr);
5402			}
5403			if (Z_TYPE_P(expr) == IS_OBJECT && Z_OBJ_HT_P(expr)->cast_object) {
5404				if (Z_OBJ_HT_P(expr)->cast_object(expr, result, IS_NULL) == SUCCESS) {
5405					break;
5406				}
5407			}
5408#endif
5409
5410			ZVAL_NULL(result);
5411			break;
5412		case _IS_BOOL:
5413			ZVAL_BOOL(result, zend_is_true(expr));
5414			break;
5415		case IS_LONG:
5416			ZVAL_LONG(result, zval_get_long(expr));
5417			break;
5418		case IS_DOUBLE:
5419			ZVAL_DOUBLE(result, zval_get_double(expr));
5420			break;
5421		case IS_STRING:
5422			ZVAL_STR(result, zval_get_string(expr));
5423			break;
5424		default:
5425			if (OP1_TYPE & (IS_VAR|IS_CV)) {
5426				ZVAL_DEREF(expr);
5427			}
5428			/* If value is already of correct type, return it directly */
5429			if (Z_TYPE_P(expr) == opline->extended_value) {
5430				ZVAL_COPY_VALUE(result, expr);
5431				if (OP1_TYPE == IS_CONST) {
5432					if (UNEXPECTED(Z_OPT_COPYABLE_P(result))) {
5433						zval_copy_ctor_func(result);
5434					}
5435				} else if (OP1_TYPE != IS_TMP_VAR) {
5436					if (Z_OPT_REFCOUNTED_P(expr)) Z_ADDREF_P(expr);
5437				}
5438
5439				FREE_OP1_IF_VAR();
5440				ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5441			}
5442
5443			if (opline->extended_value == IS_ARRAY) {
5444				if (Z_TYPE_P(expr) != IS_OBJECT) {
5445					ZVAL_NEW_ARR(result);
5446					zend_hash_init(Z_ARRVAL_P(result), 8, NULL, ZVAL_PTR_DTOR, 0);
5447					if (Z_TYPE_P(expr) != IS_NULL) {
5448						expr = zend_hash_index_add_new(Z_ARRVAL_P(result), 0, expr);
5449						if (OP1_TYPE == IS_CONST) {
5450							if (UNEXPECTED(Z_OPT_COPYABLE_P(expr))) {
5451								zval_copy_ctor_func(expr);
5452							}
5453						} else {
5454							if (Z_OPT_REFCOUNTED_P(expr)) Z_ADDREF_P(expr);
5455						}
5456					}
5457				} else {
5458					ZVAL_COPY_VALUE(result, expr);
5459					Z_ADDREF_P(result);
5460					convert_to_array(result);
5461				}
5462			} else {
5463				if (Z_TYPE_P(expr) != IS_ARRAY) {
5464					object_init(result);
5465					if (Z_TYPE_P(expr) != IS_NULL) {
5466						expr = zend_hash_str_add_new(Z_OBJPROP_P(result), "scalar", sizeof("scalar")-1, expr);
5467						if (OP1_TYPE == IS_CONST) {
5468							if (UNEXPECTED(Z_OPT_COPYABLE_P(expr))) {
5469								zval_copy_ctor_func(expr);
5470							}
5471						} else {
5472							if (Z_OPT_REFCOUNTED_P(expr)) Z_ADDREF_P(expr);
5473						}
5474					}
5475				} else {
5476					ZVAL_COPY(result, expr);
5477					convert_to_object(result);
5478				}
5479			}
5480	}
5481
5482	FREE_OP1();
5483	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5484}
5485
5486ZEND_VM_HANDLER(73, ZEND_INCLUDE_OR_EVAL, CONST|TMPVAR|CV, ANY, EVAL)
5487{
5488	USE_OPLINE
5489	zend_op_array *new_op_array=NULL;
5490	zend_free_op free_op1;
5491	zval *inc_filename;
5492	zval tmp_inc_filename;
5493	zend_bool failure_retval=0;
5494
5495	SAVE_OPLINE();
5496	inc_filename = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
5497
5498	ZVAL_UNDEF(&tmp_inc_filename);
5499	if (Z_TYPE_P(inc_filename) != IS_STRING) {
5500		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(inc_filename) == IS_UNDEF)) {
5501			inc_filename = GET_OP1_UNDEF_CV(inc_filename, BP_VAR_R);
5502		}
5503		ZVAL_STR(&tmp_inc_filename, zval_get_string(inc_filename));
5504		inc_filename = &tmp_inc_filename;
5505	}
5506
5507	if (opline->extended_value != ZEND_EVAL && strlen(Z_STRVAL_P(inc_filename)) != Z_STRLEN_P(inc_filename)) {
5508		if (opline->extended_value == ZEND_INCLUDE_ONCE || opline->extended_value == ZEND_INCLUDE) {
5509			zend_message_dispatcher(ZMSG_FAILED_INCLUDE_FOPEN, Z_STRVAL_P(inc_filename));
5510		} else {
5511			zend_message_dispatcher(ZMSG_FAILED_REQUIRE_FOPEN, Z_STRVAL_P(inc_filename));
5512		}
5513	} else {
5514		switch (opline->extended_value) {
5515			case ZEND_INCLUDE_ONCE:
5516			case ZEND_REQUIRE_ONCE: {
5517					zend_file_handle file_handle;
5518					zend_string *resolved_path;
5519
5520					resolved_path = zend_resolve_path(Z_STRVAL_P(inc_filename), (int)Z_STRLEN_P(inc_filename));
5521					if (resolved_path) {
5522						failure_retval = zend_hash_exists(&EG(included_files), resolved_path);
5523					} else {
5524						resolved_path = zend_string_copy(Z_STR_P(inc_filename));
5525					}
5526
5527					if (failure_retval) {
5528						/* do nothing, file already included */
5529					} else if (SUCCESS == zend_stream_open(ZSTR_VAL(resolved_path), &file_handle)) {
5530
5531						if (!file_handle.opened_path) {
5532							file_handle.opened_path = zend_string_copy(resolved_path);
5533						}
5534
5535						if (zend_hash_add_empty_element(&EG(included_files), file_handle.opened_path)) {
5536							new_op_array = zend_compile_file(&file_handle, (opline->extended_value==ZEND_INCLUDE_ONCE?ZEND_INCLUDE:ZEND_REQUIRE));
5537							zend_destroy_file_handle(&file_handle);
5538						} else {
5539							zend_file_handle_dtor(&file_handle);
5540							failure_retval=1;
5541						}
5542					} else {
5543						if (opline->extended_value == ZEND_INCLUDE_ONCE) {
5544							zend_message_dispatcher(ZMSG_FAILED_INCLUDE_FOPEN, Z_STRVAL_P(inc_filename));
5545						} else {
5546							zend_message_dispatcher(ZMSG_FAILED_REQUIRE_FOPEN, Z_STRVAL_P(inc_filename));
5547						}
5548					}
5549					zend_string_release(resolved_path);
5550				}
5551				break;
5552			case ZEND_INCLUDE:
5553			case ZEND_REQUIRE:
5554				new_op_array = compile_filename(opline->extended_value, inc_filename);
5555				break;
5556			case ZEND_EVAL: {
5557					char *eval_desc = zend_make_compiled_string_description("eval()'d code");
5558
5559					new_op_array = zend_compile_string(inc_filename, eval_desc);
5560					efree(eval_desc);
5561				}
5562				break;
5563			EMPTY_SWITCH_DEFAULT_CASE()
5564		}
5565	}
5566	if (Z_TYPE(tmp_inc_filename) != IS_UNDEF) {
5567		zend_string_release(Z_STR(tmp_inc_filename));
5568	}
5569	FREE_OP1();
5570	if (UNEXPECTED(EG(exception) != NULL)) {
5571		HANDLE_EXCEPTION();
5572	} else if (EXPECTED(new_op_array != NULL)) {
5573		zval *return_value = NULL;
5574		zend_execute_data *call;
5575
5576		if (RETURN_VALUE_USED(opline)) {
5577			return_value = EX_VAR(opline->result.var);
5578		}
5579
5580		new_op_array->scope = EG(scope);
5581
5582		call = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_CODE,
5583			(zend_function*)new_op_array, 0, EX(called_scope), Z_OBJ(EX(This)));
5584
5585		if (EX(symbol_table)) {
5586			call->symbol_table = EX(symbol_table);
5587		} else {
5588			call->symbol_table = zend_rebuild_symbol_table();
5589		}
5590
5591		call->prev_execute_data = execute_data;
5592	    i_init_code_execute_data(call, new_op_array, return_value);
5593		if (EXPECTED(zend_execute_ex == execute_ex)) {
5594			ZEND_VM_ENTER();
5595		} else {
5596			ZEND_ADD_CALL_FLAG(call, ZEND_CALL_TOP);
5597			zend_execute_ex(call);
5598			zend_vm_stack_free_call_frame(call);
5599		}
5600
5601		destroy_op_array(new_op_array);
5602		efree_size(new_op_array, sizeof(zend_op_array));
5603		if (UNEXPECTED(EG(exception) != NULL)) {
5604			zend_throw_exception_internal(NULL);
5605			HANDLE_EXCEPTION();
5606		}
5607
5608	} else if (RETURN_VALUE_USED(opline)) {
5609		ZVAL_BOOL(EX_VAR(opline->result.var), failure_retval);
5610	}
5611	ZEND_VM_INTERRUPT_CHECK();
5612	ZEND_VM_NEXT_OPCODE();
5613}
5614
5615ZEND_VM_HANDLER(74, ZEND_UNSET_VAR, CONST|TMPVAR|CV, UNUSED, VAR_FETCH|ISSET)
5616{
5617	USE_OPLINE
5618	zval tmp, *varname;
5619	HashTable *target_symbol_table;
5620	zend_free_op free_op1;
5621
5622	SAVE_OPLINE();
5623	if (OP1_TYPE == IS_CV &&
5624	    (opline->extended_value & ZEND_QUICK_SET)) {
5625		zval *var = EX_VAR(opline->op1.var);
5626
5627		if (Z_REFCOUNTED_P(var)) {
5628			zend_refcounted *garbage = Z_COUNTED_P(var);
5629
5630			if (!--GC_REFCOUNT(garbage)) {
5631				ZVAL_UNDEF(var);
5632				zval_dtor_func_for_ptr(garbage);
5633			} else {
5634				zval *z = var;
5635				ZVAL_DEREF(z);
5636				if (Z_COLLECTABLE_P(z) && UNEXPECTED(!Z_GC_INFO_P(z))) {
5637					ZVAL_UNDEF(var);
5638					gc_possible_root(Z_COUNTED_P(z));
5639				} else {
5640					ZVAL_UNDEF(var);
5641				}
5642			}
5643		} else {
5644			ZVAL_UNDEF(var);
5645		}
5646		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5647	}
5648
5649	varname = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
5650
5651	ZVAL_UNDEF(&tmp);
5652	if (OP1_TYPE != IS_CONST && Z_TYPE_P(varname) != IS_STRING) {
5653		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(varname) == IS_UNDEF)) {
5654			varname = GET_OP1_UNDEF_CV(varname, BP_VAR_R);
5655		}
5656		ZVAL_STR(&tmp, zval_get_string(varname));
5657		varname = &tmp;
5658	}
5659
5660	target_symbol_table = zend_get_target_symbol_table(execute_data, opline->extended_value & ZEND_FETCH_TYPE_MASK);
5661	zend_hash_del_ind(target_symbol_table, Z_STR_P(varname));
5662
5663	if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
5664		zend_string_release(Z_STR(tmp));
5665	}
5666	FREE_OP1();
5667	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5668}
5669
5670ZEND_VM_HANDLER(179, ZEND_UNSET_STATIC_PROP, CONST|TMPVAR|CV, UNUSED|CLASS_FETCH|CONST|VAR)
5671{
5672	USE_OPLINE
5673	zval tmp, *varname;
5674	zend_class_entry *ce;
5675	zend_free_op free_op1;
5676
5677	SAVE_OPLINE();
5678
5679	varname = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
5680
5681	ZVAL_UNDEF(&tmp);
5682	if (OP1_TYPE != IS_CONST && Z_TYPE_P(varname) != IS_STRING) {
5683		if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(varname) == IS_UNDEF)) {
5684			varname = GET_OP1_UNDEF_CV(varname, BP_VAR_R);
5685		}
5686		ZVAL_STR(&tmp, zval_get_string(varname));
5687		varname = &tmp;
5688	}
5689
5690	if (OP2_TYPE == IS_CONST) {
5691		ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
5692		if (UNEXPECTED(ce == NULL)) {
5693			ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op2)), EX_CONSTANT(opline->op2) + 1, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
5694			if (UNEXPECTED(ce == NULL)) {
5695				if (EXPECTED(!EG(exception))) {
5696					zend_throw_error(NULL, "Class '%s' not found", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
5697				}
5698				if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
5699					zend_string_release(Z_STR(tmp));
5700				}
5701				FREE_OP1();
5702				HANDLE_EXCEPTION();
5703			}
5704			CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce);
5705		}
5706	} else if (OP2_TYPE == IS_UNUSED) {
5707		ce = zend_fetch_class(NULL, opline->op2.num);
5708		if (UNEXPECTED(ce == NULL)) {
5709			ZEND_ASSERT(EG(exception));
5710			if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
5711				zend_string_release(Z_STR(tmp));
5712			}
5713			FREE_OP1();
5714			HANDLE_EXCEPTION();
5715		}
5716	} else {
5717		ce = Z_CE_P(EX_VAR(opline->op2.var));
5718	}
5719	zend_std_unset_static_property(ce, Z_STR_P(varname));
5720
5721	if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
5722		zend_string_release(Z_STR(tmp));
5723	}
5724	FREE_OP1();
5725	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5726}
5727
5728ZEND_VM_HANDLER(75, ZEND_UNSET_DIM, VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
5729{
5730	USE_OPLINE
5731	zend_free_op free_op1, free_op2;
5732	zval *container;
5733	zval *offset;
5734	zend_ulong hval;
5735	zend_string *key;
5736
5737	SAVE_OPLINE();
5738	container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_UNSET);
5739	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
5740		zend_throw_error(NULL, "Using $this when not in object context");
5741		FREE_UNFETCHED_OP2();
5742		HANDLE_EXCEPTION();
5743	}
5744	offset = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
5745
5746	do {
5747		if (OP1_TYPE != IS_UNUSED && EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
5748			HashTable *ht;
5749
5750ZEND_VM_C_LABEL(unset_dim_array):
5751			SEPARATE_ARRAY(container);
5752			ht = Z_ARRVAL_P(container);
5753ZEND_VM_C_LABEL(offset_again):
5754			if (EXPECTED(Z_TYPE_P(offset) == IS_STRING)) {
5755				key = Z_STR_P(offset);
5756				if (OP2_TYPE != IS_CONST) {
5757					if (ZEND_HANDLE_NUMERIC(key, hval)) {
5758						ZEND_VM_C_GOTO(num_index_dim);
5759					}
5760				}
5761ZEND_VM_C_LABEL(str_index_dim):
5762				if (ht == &EG(symbol_table)) {
5763					zend_delete_global_variable(key);
5764				} else {
5765					zend_hash_del(ht, key);
5766				}
5767			} else if (EXPECTED(Z_TYPE_P(offset) == IS_LONG)) {
5768				hval = Z_LVAL_P(offset);
5769ZEND_VM_C_LABEL(num_index_dim):
5770				zend_hash_index_del(ht, hval);
5771			} else if ((OP2_TYPE & (IS_VAR|IS_CV)) && EXPECTED(Z_TYPE_P(offset) == IS_REFERENCE)) {
5772				offset = Z_REFVAL_P(offset);
5773				ZEND_VM_C_GOTO(offset_again);
5774			} else if (Z_TYPE_P(offset) == IS_DOUBLE) {
5775				hval = zend_dval_to_lval(Z_DVAL_P(offset));
5776				ZEND_VM_C_GOTO(num_index_dim);
5777			} else if (Z_TYPE_P(offset) == IS_NULL) {
5778				key = ZSTR_EMPTY_ALLOC();
5779				ZEND_VM_C_GOTO(str_index_dim);
5780			} else if (Z_TYPE_P(offset) == IS_FALSE) {
5781				hval = 0;
5782				ZEND_VM_C_GOTO(num_index_dim);
5783			} else if (Z_TYPE_P(offset) == IS_TRUE) {
5784				hval = 1;
5785				ZEND_VM_C_GOTO(num_index_dim);
5786			} else if (Z_TYPE_P(offset) == IS_RESOURCE) {
5787				hval = Z_RES_HANDLE_P(offset);
5788				ZEND_VM_C_GOTO(num_index_dim);
5789			} else if (OP2_TYPE == IS_CV && Z_TYPE_P(offset) == IS_UNDEF) {
5790				GET_OP2_UNDEF_CV(offset, BP_VAR_R);
5791				key = ZSTR_EMPTY_ALLOC();
5792				ZEND_VM_C_GOTO(str_index_dim);
5793			} else {
5794				zend_error(E_WARNING, "Illegal offset type in unset");
5795			}
5796			break;
5797		} else if (OP1_TYPE != IS_UNUSED && Z_ISREF_P(container)) {
5798			container = Z_REFVAL_P(container);
5799			if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
5800				ZEND_VM_C_GOTO(unset_dim_array);
5801			}
5802		}
5803		if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(offset) == IS_UNDEF)) {
5804			offset = GET_OP2_UNDEF_CV(offset, BP_VAR_R);
5805		}
5806		if (OP1_TYPE == IS_UNUSED || EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
5807			if (UNEXPECTED(Z_OBJ_HT_P(container)->unset_dimension == NULL)) {
5808				zend_throw_error(NULL, "Cannot use object as array");
5809			} else {
5810				Z_OBJ_HT_P(container)->unset_dimension(container, offset);
5811			}
5812		} else if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) == IS_STRING)) {
5813			zend_throw_error(NULL, "Cannot unset string offsets");
5814		}
5815	} while (0);
5816
5817	FREE_OP2();
5818	FREE_OP1_VAR_PTR();
5819	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5820}
5821
5822ZEND_VM_HANDLER(76, ZEND_UNSET_OBJ, VAR|UNUSED|THIS|CV, CONST|TMPVAR|CV)
5823{
5824	USE_OPLINE
5825	zend_free_op free_op1, free_op2;
5826	zval *container;
5827	zval *offset;
5828
5829	SAVE_OPLINE();
5830	container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_UNSET);
5831	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
5832		zend_throw_error(NULL, "Using $this when not in object context");
5833		FREE_UNFETCHED_OP2();
5834		HANDLE_EXCEPTION();
5835	}
5836	offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
5837
5838	do {
5839		if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
5840			if (Z_ISREF_P(container)) {
5841				container = Z_REFVAL_P(container);
5842				if (Z_TYPE_P(container) != IS_OBJECT) {
5843					break;
5844				}
5845			} else {
5846				break;
5847			}
5848		}
5849		if (Z_OBJ_HT_P(container)->unset_property) {
5850			Z_OBJ_HT_P(container)->unset_property(container, offset, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(offset)) : NULL));
5851		} else {
5852			zend_error(E_NOTICE, "Trying to unset property of non-object");
5853		}
5854	} while (0);
5855
5856	FREE_OP2();
5857	FREE_OP1_VAR_PTR();
5858	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5859}
5860
5861ZEND_VM_HANDLER(77, ZEND_FE_RESET_R, CONST|TMP|VAR|CV, JMP_ADDR)
5862{
5863	USE_OPLINE
5864	zend_free_op free_op1;
5865	zval *array_ptr, *result;
5866	HashTable *fe_ht;
5867
5868	SAVE_OPLINE();
5869
5870	array_ptr = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
5871	if (EXPECTED(Z_TYPE_P(array_ptr) == IS_ARRAY)) {
5872		result = EX_VAR(opline->result.var);
5873		ZVAL_COPY_VALUE(result, array_ptr);
5874		if (OP1_TYPE != IS_TMP_VAR && Z_OPT_REFCOUNTED_P(result)) {
5875			Z_ADDREF_P(array_ptr);
5876		}
5877		Z_FE_POS_P(result) = 0;
5878
5879		FREE_OP1_IF_VAR();
5880		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5881	} else if (OP1_TYPE != IS_CONST && EXPECTED(Z_TYPE_P(array_ptr) == IS_OBJECT)) {
5882		if (!Z_OBJCE_P(array_ptr)->get_iterator) {
5883			HashPosition pos = 0;
5884			Bucket *p;
5885
5886			result = EX_VAR(opline->result.var);
5887			ZVAL_COPY_VALUE(result, array_ptr);
5888			if (OP1_TYPE != IS_TMP_VAR) {
5889				Z_ADDREF_P(array_ptr);
5890			}
5891			fe_ht = Z_OBJPROP_P(array_ptr);
5892			pos = 0;
5893			p = fe_ht->arData;
5894			while (1) {
5895				if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
5896					FREE_OP1_IF_VAR();
5897					Z_FE_ITER_P(EX_VAR(opline->result.var)) = (uint32_t)-1;
5898					ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
5899				}
5900				if ((EXPECTED(Z_TYPE(p->val) != IS_UNDEF) &&
5901				     (EXPECTED(Z_TYPE(p->val) != IS_INDIRECT) ||
5902				      EXPECTED(Z_TYPE_P(Z_INDIRECT(p->val)) != IS_UNDEF))) &&
5903				    (UNEXPECTED(!p->key) ||
5904				     EXPECTED(zend_check_property_access(Z_OBJ_P(array_ptr), p->key) == SUCCESS))) {
5905					break;
5906				}
5907				pos++;
5908				p++;
5909			}
5910			Z_FE_ITER_P(EX_VAR(opline->result.var)) = zend_hash_iterator_add(fe_ht, pos);
5911
5912			FREE_OP1_IF_VAR();
5913			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5914		} else {
5915			zend_class_entry *ce = Z_OBJCE_P(array_ptr);
5916			zend_object_iterator *iter = ce->get_iterator(ce, array_ptr, 0);
5917			zend_bool is_empty;
5918
5919			if (UNEXPECTED(!iter) || UNEXPECTED(EG(exception))) {
5920				FREE_OP1();
5921				if (!EG(exception)) {
5922					zend_throw_exception_ex(NULL, 0, "Object of type %s did not create an Iterator", ZSTR_VAL(ce->name));
5923				}
5924				zend_throw_exception_internal(NULL);
5925				HANDLE_EXCEPTION();
5926			}
5927
5928			iter->index = 0;
5929			if (iter->funcs->rewind) {
5930				iter->funcs->rewind(iter);
5931				if (UNEXPECTED(EG(exception) != NULL)) {
5932					OBJ_RELEASE(&iter->std);
5933					FREE_OP1();
5934					HANDLE_EXCEPTION();
5935				}
5936			}
5937
5938			is_empty = iter->funcs->valid(iter) != SUCCESS;
5939
5940			if (UNEXPECTED(EG(exception) != NULL)) {
5941				OBJ_RELEASE(&iter->std);
5942				FREE_OP1();
5943				HANDLE_EXCEPTION();
5944			}
5945			iter->index = -1; /* will be set to 0 before using next handler */
5946
5947			ZVAL_OBJ(EX_VAR(opline->result.var), &iter->std);
5948			Z_FE_ITER_P(EX_VAR(opline->result.var)) = (uint32_t)-1;
5949
5950			FREE_OP1();
5951			if (is_empty) {
5952				ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
5953			} else {
5954				ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
5955			}
5956		}
5957	} else {
5958		zend_error(E_WARNING, "Invalid argument supplied for foreach()");
5959		ZVAL_UNDEF(EX_VAR(opline->result.var));
5960		Z_FE_ITER_P(EX_VAR(opline->result.var)) = (uint32_t)-1;
5961		FREE_OP1();
5962		ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
5963	}
5964}
5965
5966ZEND_VM_HANDLER(125, ZEND_FE_RESET_RW, CONST|TMP|VAR|CV, JMP_ADDR)
5967{
5968	USE_OPLINE
5969	zend_free_op free_op1;
5970	zval *array_ptr, *array_ref;
5971	HashTable *fe_ht;
5972	HashPosition pos = 0;
5973	Bucket *p;
5974
5975	SAVE_OPLINE();
5976
5977	if (OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) {
5978		array_ref = array_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_R);
5979		if (Z_ISREF_P(array_ref)) {
5980			array_ptr = Z_REFVAL_P(array_ref);
5981		}
5982	} else {
5983		array_ref = array_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
5984	}
5985
5986	if (EXPECTED(Z_TYPE_P(array_ptr) == IS_ARRAY)) {
5987		if (OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) {
5988			if (array_ptr == array_ref) {
5989				ZVAL_NEW_REF(array_ref, array_ref);
5990				array_ptr = Z_REFVAL_P(array_ref);
5991			}
5992			Z_ADDREF_P(array_ref);
5993			ZVAL_COPY_VALUE(EX_VAR(opline->result.var), array_ref);
5994		} else {
5995			array_ref = EX_VAR(opline->result.var);
5996			ZVAL_NEW_REF(array_ref, array_ptr);
5997			array_ptr = Z_REFVAL_P(array_ref);
5998		}
5999		if (OP1_TYPE == IS_CONST) {
6000			zval_copy_ctor_func(array_ptr);
6001		} else {
6002			SEPARATE_ARRAY(array_ptr);
6003		}
6004		fe_ht = Z_ARRVAL_P(array_ptr);
6005		p = fe_ht->arData;
6006		while (1) {
6007			if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
6008				FREE_OP1_VAR_PTR();
6009				Z_FE_ITER_P(EX_VAR(opline->result.var)) = (uint32_t)-1;
6010				ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
6011			}
6012			if (EXPECTED(Z_TYPE(p->val) != IS_UNDEF) &&
6013			    (EXPECTED(Z_TYPE(p->val) != IS_INDIRECT) ||
6014			     EXPECTED(Z_TYPE_P(Z_INDIRECT(p->val)) != IS_UNDEF))) {
6015				break;
6016			}
6017			pos++;
6018			p++;
6019		}
6020		Z_FE_ITER_P(EX_VAR(opline->result.var)) = zend_hash_iterator_add(fe_ht, pos);
6021
6022		FREE_OP1_VAR_PTR();
6023		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6024	} else if (OP1_TYPE != IS_CONST && EXPECTED(Z_TYPE_P(array_ptr) == IS_OBJECT)) {
6025		if (!Z_OBJCE_P(array_ptr)->get_iterator) {
6026			if (OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) {
6027				if (array_ptr == array_ref) {
6028					ZVAL_NEW_REF(array_ref, array_ref);
6029					array_ptr = Z_REFVAL_P(array_ref);
6030				}
6031				Z_ADDREF_P(array_ref);
6032				ZVAL_COPY_VALUE(EX_VAR(opline->result.var), array_ref);
6033			} else {
6034				array_ptr = EX_VAR(opline->result.var);
6035				ZVAL_COPY_VALUE(array_ptr, array_ref);
6036			}
6037			fe_ht = Z_OBJPROP_P(array_ptr);
6038			p = fe_ht->arData;
6039			while (1) {
6040				if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
6041					FREE_OP1_VAR_PTR();
6042					Z_FE_ITER_P(EX_VAR(opline->result.var)) = (uint32_t)-1;
6043					ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
6044				}
6045				if ((EXPECTED(Z_TYPE(p->val) != IS_UNDEF) &&
6046				     (EXPECTED(Z_TYPE(p->val) != IS_INDIRECT) ||
6047				      EXPECTED(Z_TYPE_P(Z_INDIRECT(p->val)) != IS_UNDEF))) &&
6048				    (UNEXPECTED(!p->key) ||
6049				     EXPECTED(zend_check_property_access(Z_OBJ_P(array_ptr), p->key) == SUCCESS))) {
6050					break;
6051				}
6052				pos++;
6053				p++;
6054			}
6055			Z_FE_ITER_P(EX_VAR(opline->result.var)) = zend_hash_iterator_add(fe_ht, pos);
6056
6057			FREE_OP1_VAR_PTR();
6058			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6059		} else {
6060			zend_class_entry *ce = Z_OBJCE_P(array_ptr);
6061			zend_object_iterator *iter = ce->get_iterator(ce, array_ptr, 1);
6062			zend_bool is_empty;
6063
6064			if (UNEXPECTED(!iter) || UNEXPECTED(EG(exception))) {
6065				if (OP1_TYPE == IS_VAR) {
6066					FREE_OP1_VAR_PTR();
6067				} else {
6068					FREE_OP1();
6069				}
6070				if (!EG(exception)) {
6071					zend_throw_exception_ex(NULL, 0, "Object of type %s did not create an Iterator", ZSTR_VAL(ce->name));
6072				}
6073				zend_throw_exception_internal(NULL);
6074				HANDLE_EXCEPTION();
6075			}
6076
6077			iter->index = 0;
6078			if (iter->funcs->rewind) {
6079				iter->funcs->rewind(iter);
6080				if (UNEXPECTED(EG(exception) != NULL)) {
6081					OBJ_RELEASE(&iter->std);
6082					if (OP1_TYPE == IS_VAR) {
6083						FREE_OP1_VAR_PTR();
6084					} else {
6085						FREE_OP1();
6086					}
6087					HANDLE_EXCEPTION();
6088				}
6089			}
6090
6091			is_empty = iter->funcs->valid(iter) != SUCCESS;
6092
6093			if (UNEXPECTED(EG(exception) != NULL)) {
6094				OBJ_RELEASE(&iter->std);
6095				if (OP1_TYPE == IS_VAR) {
6096					FREE_OP1_VAR_PTR();
6097				} else {
6098					FREE_OP1();
6099				}
6100				HANDLE_EXCEPTION();
6101			}
6102			iter->index = -1; /* will be set to 0 before using next handler */
6103
6104			ZVAL_OBJ(EX_VAR(opline->result.var), &iter->std);
6105			Z_FE_ITER_P(EX_VAR(opline->result.var)) = (uint32_t)-1;
6106
6107			if (OP1_TYPE == IS_VAR) {
6108				FREE_OP1_VAR_PTR();
6109			} else {
6110				FREE_OP1();
6111			}
6112			if (is_empty) {
6113				ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
6114			} else {
6115				ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6116			}
6117		}
6118	} else {
6119		zend_error(E_WARNING, "Invalid argument supplied for foreach()");
6120		ZVAL_UNDEF(EX_VAR(opline->result.var));
6121		Z_FE_ITER_P(EX_VAR(opline->result.var)) = (uint32_t)-1;
6122		if (OP1_TYPE == IS_VAR) {
6123			FREE_OP1_VAR_PTR();
6124		} else {
6125			FREE_OP1();
6126		}
6127		ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
6128	}
6129}
6130
6131ZEND_VM_HANDLER(78, ZEND_FE_FETCH_R, VAR, ANY, JMP_ADDR)
6132{
6133	USE_OPLINE
6134	zval *array;
6135	zval *value;
6136	uint32_t value_type;
6137	HashTable *fe_ht;
6138	HashPosition pos;
6139	Bucket *p;
6140
6141	array = EX_VAR(opline->op1.var);
6142	SAVE_OPLINE();
6143	if (EXPECTED(Z_TYPE_P(array) == IS_ARRAY)) {
6144		fe_ht = Z_ARRVAL_P(array);
6145		pos = Z_FE_POS_P(array);
6146		p = fe_ht->arData + pos;
6147		while (1) {
6148			if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
6149				/* reached end of iteration */
6150				ZEND_VM_C_GOTO(fe_fetch_r_exit);
6151			}
6152			value = &p->val;
6153			value_type = Z_TYPE_INFO_P(value);
6154			if (value_type == IS_UNDEF) {
6155				pos++;
6156				p++;
6157				continue;
6158			} else if (UNEXPECTED(value_type == IS_INDIRECT)) {
6159				value = Z_INDIRECT_P(value);
6160				value_type = Z_TYPE_INFO_P(value);
6161				if (UNEXPECTED(value_type == IS_UNDEF)) {
6162					pos++;
6163					p++;
6164					continue;
6165				}
6166			}
6167			break;
6168		}
6169		Z_FE_POS_P(array) = pos + 1;
6170		if (opline->result_type & (IS_TMP_VAR|IS_CV)) {
6171			if (!p->key) {
6172				ZVAL_LONG(EX_VAR(opline->result.var), p->h);
6173			} else {
6174				ZVAL_STR_COPY(EX_VAR(opline->result.var), p->key);
6175			}
6176		}
6177	} else if (EXPECTED(Z_TYPE_P(array) == IS_OBJECT)) {
6178		zend_object_iterator *iter;
6179
6180		if ((iter = zend_iterator_unwrap(array)) == NULL) {
6181			/* plain object */
6182
6183 			fe_ht = Z_OBJPROP_P(array);
6184			pos = zend_hash_iterator_pos(Z_FE_ITER_P(array), fe_ht);
6185			p = fe_ht->arData + pos;
6186			while (1) {
6187				if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
6188					/* reached end of iteration */
6189					ZEND_VM_C_GOTO(fe_fetch_r_exit);
6190				}
6191
6192				value = &p->val;
6193				value_type = Z_TYPE_INFO_P(value);
6194				if (UNEXPECTED(value_type == IS_UNDEF)) {
6195					pos++;
6196					p++;
6197					continue;
6198				} else if (UNEXPECTED(value_type == IS_INDIRECT)) {
6199					value = Z_INDIRECT_P(value);
6200					value_type = Z_TYPE_INFO_P(value);
6201					if (UNEXPECTED(value_type == IS_UNDEF)) {
6202						pos++;
6203						p++;
6204						continue;
6205					}
6206				}
6207				if (UNEXPECTED(!p->key) ||
6208				    EXPECTED(zend_check_property_access(Z_OBJ_P(array), p->key) == SUCCESS)) {
6209					break;
6210				}
6211				pos++;
6212				p++;
6213			}
6214			if (opline->result_type & (IS_TMP_VAR|IS_CV)) {
6215				if (UNEXPECTED(!p->key)) {
6216					ZVAL_LONG(EX_VAR(opline->result.var), p->h);
6217				} else if (ZSTR_VAL(p->key)[0]) {
6218					ZVAL_STR_COPY(EX_VAR(opline->result.var), p->key);
6219				} else {
6220					const char *class_name, *prop_name;
6221					size_t prop_name_len;
6222					zend_unmangle_property_name_ex(
6223						p->key, &class_name, &prop_name, &prop_name_len);
6224					ZVAL_STRINGL(EX_VAR(opline->result.var), prop_name, prop_name_len);
6225				}
6226			}
6227			while (1) {
6228				pos++;
6229				if (pos >= fe_ht->nNumUsed) {
6230					pos = HT_INVALID_IDX;
6231					break;
6232				}
6233				p++;
6234				if ((EXPECTED(Z_TYPE(p->val) != IS_UNDEF) &&
6235				     (EXPECTED(Z_TYPE(p->val) != IS_INDIRECT) ||
6236				      EXPECTED(Z_TYPE_P(Z_INDIRECT(p->val)) != IS_UNDEF))) &&
6237				    (UNEXPECTED(!p->key) ||
6238				     EXPECTED(zend_check_property_access(Z_OBJ_P(array), p->key) == SUCCESS))) {
6239					break;
6240				}
6241			}
6242			EG(ht_iterators)[Z_FE_ITER_P(array)].pos = pos;
6243		} else {
6244			if (EXPECTED(++iter->index > 0)) {
6245				/* This could cause an endless loop if index becomes zero again.
6246				 * In case that ever happens we need an additional flag. */
6247				iter->funcs->move_forward(iter);
6248				if (UNEXPECTED(EG(exception) != NULL)) {
6249					HANDLE_EXCEPTION();
6250				}
6251				if (UNEXPECTED(iter->funcs->valid(iter) == FAILURE)) {
6252					/* reached end of iteration */
6253					if (UNEXPECTED(EG(exception) != NULL)) {
6254						HANDLE_EXCEPTION();
6255					}
6256					ZEND_VM_C_GOTO(fe_fetch_r_exit);
6257				}
6258			}
6259			value = iter->funcs->get_current_data(iter);
6260			if (UNEXPECTED(EG(exception) != NULL)) {
6261				HANDLE_EXCEPTION();
6262			}
6263			if (!value) {
6264				/* failure in get_current_data */
6265				ZEND_VM_C_GOTO(fe_fetch_r_exit);
6266			}
6267			if (opline->result_type & (IS_TMP_VAR|IS_CV)) {
6268				if (iter->funcs->get_current_key) {
6269					iter->funcs->get_current_key(iter, EX_VAR(opline->result.var));
6270					if (UNEXPECTED(EG(exception) != NULL)) {
6271						HANDLE_EXCEPTION();
6272					}
6273				} else {
6274					ZVAL_LONG(EX_VAR(opline->result.var), iter->index);
6275				}
6276			}
6277			value_type = Z_TYPE_INFO_P(value);
6278		}
6279	} else {
6280		zend_error(E_WARNING, "Invalid argument supplied for foreach()");
6281		if (UNEXPECTED(EG(exception))) {
6282			HANDLE_EXCEPTION();
6283		}
6284ZEND_VM_C_LABEL(fe_fetch_r_exit):
6285		ZEND_VM_SET_RELATIVE_OPCODE(opline, opline->extended_value);
6286		ZEND_VM_CONTINUE();
6287	}
6288
6289	if (EXPECTED(OP2_TYPE == IS_CV)) {
6290		zval *variable_ptr = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->op2.var);
6291		zend_assign_to_variable(variable_ptr, value, IS_CV);
6292	} else {
6293		zval *res = EX_VAR(opline->op2.var);
6294		zend_refcounted *gc = Z_COUNTED_P(value);
6295
6296		ZVAL_COPY_VALUE_EX(res, value, gc, value_type);
6297		if (EXPECTED((value_type & (IS_TYPE_REFCOUNTED << Z_TYPE_FLAGS_SHIFT)) != 0)) {
6298			GC_REFCOUNT(gc)++;
6299		}
6300	}
6301	ZEND_VM_NEXT_OPCODE();
6302}
6303
6304ZEND_VM_HANDLER(126, ZEND_FE_FETCH_RW, VAR, ANY, JMP_ADDR)
6305{
6306	USE_OPLINE
6307	zval *array;
6308	zval *value;
6309	uint32_t value_type;
6310	HashTable *fe_ht;
6311	HashPosition pos;
6312	Bucket *p;
6313
6314	array = EX_VAR(opline->op1.var);
6315	SAVE_OPLINE();
6316
6317	ZVAL_DEREF(array);
6318	if (EXPECTED(Z_TYPE_P(array) == IS_ARRAY)) {
6319		pos = zend_hash_iterator_pos_ex(Z_FE_ITER_P(EX_VAR(opline->op1.var)), array);
6320		fe_ht = Z_ARRVAL_P(array);
6321		p = fe_ht->arData + pos;
6322		while (1) {
6323			if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
6324				/* reached end of iteration */
6325				ZEND_VM_C_GOTO(fe_fetch_w_exit);
6326			}
6327			value = &p->val;
6328			value_type = Z_TYPE_INFO_P(value);
6329			if (UNEXPECTED(value_type == IS_UNDEF)) {
6330				pos++;
6331				p++;
6332				continue;
6333			} else if (UNEXPECTED(value_type == IS_INDIRECT)) {
6334				value = Z_INDIRECT_P(value);
6335				value_type = Z_TYPE_INFO_P(value);
6336				if (UNEXPECTED(value_type == IS_UNDEF)) {
6337					pos++;
6338					p++;
6339					continue;
6340				}
6341			}
6342			break;
6343		}
6344		if (opline->result_type & (IS_TMP_VAR|IS_CV)) {
6345			if (!p->key) {
6346				ZVAL_LONG(EX_VAR(opline->result.var), p->h);
6347			} else {
6348				ZVAL_STR_COPY(EX_VAR(opline->result.var), p->key);
6349			}
6350		}
6351		while (1) {
6352			pos++;
6353			if (pos >= fe_ht->nNumUsed) {
6354				pos = HT_INVALID_IDX;
6355				break;
6356			}
6357			p++;
6358			if (EXPECTED(Z_TYPE(p->val) != IS_UNDEF) &&
6359			    (EXPECTED(Z_TYPE(p->val) != IS_INDIRECT) ||
6360			     EXPECTED(Z_TYPE_P(Z_INDIRECT(p->val)) != IS_UNDEF))) {
6361				break;
6362			}
6363		}
6364		EG(ht_iterators)[Z_FE_ITER_P(EX_VAR(opline->op1.var))].pos = pos;
6365	} else if (EXPECTED(Z_TYPE_P(array) == IS_OBJECT)) {
6366		zend_object_iterator *iter;
6367
6368		if ((iter = zend_iterator_unwrap(array)) == NULL) {
6369			/* plain object */
6370
6371 			fe_ht = Z_OBJPROP_P(array);
6372			pos = zend_hash_iterator_pos(Z_FE_ITER_P(EX_VAR(opline->op1.var)), fe_ht);
6373			p = fe_ht->arData + pos;
6374			while (1) {
6375				if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
6376					/* reached end of iteration */
6377					ZEND_VM_C_GOTO(fe_fetch_w_exit);
6378				}
6379
6380				value = &p->val;
6381				value_type = Z_TYPE_INFO_P(value);
6382				if (UNEXPECTED(value_type == IS_UNDEF)) {
6383					pos++;
6384					p++;
6385					continue;
6386				} else if (UNEXPECTED(value_type == IS_INDIRECT)) {
6387					value = Z_INDIRECT_P(value);
6388					value_type = Z_TYPE_INFO_P(value);
6389					if (UNEXPECTED(value_type == IS_UNDEF)) {
6390						pos++;
6391						p++;
6392						continue;
6393					}
6394				}
6395				if (UNEXPECTED(!p->key) ||
6396				    EXPECTED(zend_check_property_access(Z_OBJ_P(array), p->key) == SUCCESS)) {
6397					break;
6398				}
6399				pos++;
6400				p++;
6401			}
6402			if (opline->result_type & (IS_TMP_VAR|IS_CV)) {
6403				if (UNEXPECTED(!p->key)) {
6404					ZVAL_LONG(EX_VAR(opline->result.var), p->h);
6405				} else if (ZSTR_VAL(p->key)[0]) {
6406					ZVAL_STR_COPY(EX_VAR(opline->result.var), p->key);
6407				} else {
6408					const char *class_name, *prop_name;
6409					size_t prop_name_len;
6410					zend_unmangle_property_name_ex(
6411						p->key, &class_name, &prop_name, &prop_name_len);
6412					ZVAL_STRINGL(EX_VAR(opline->result.var), prop_name, prop_name_len);
6413				}
6414			}
6415			while (1) {
6416				pos++;
6417				if (pos >= fe_ht->nNumUsed) {
6418					pos = HT_INVALID_IDX;
6419					break;
6420				}
6421				p++;
6422				if ((EXPECTED(Z_TYPE(p->val) != IS_UNDEF) &&
6423				     (EXPECTED(Z_TYPE(p->val) != IS_INDIRECT) ||
6424				      EXPECTED(Z_TYPE_P(Z_INDIRECT(p->val)) != IS_UNDEF))) &&
6425				    (UNEXPECTED(!p->key) ||
6426				     EXPECTED(zend_check_property_access(Z_OBJ_P(array), p->key) == SUCCESS))) {
6427					break;
6428				}
6429			}
6430			EG(ht_iterators)[Z_FE_ITER_P(EX_VAR(opline->op1.var))].pos = pos;
6431		} else {
6432			if (++iter->index > 0) {
6433				/* This could cause an endless loop if index becomes zero again.
6434				 * In case that ever happens we need an additional flag. */
6435				iter->funcs->move_forward(iter);
6436				if (UNEXPECTED(EG(exception) != NULL)) {
6437					HANDLE_EXCEPTION();
6438				}
6439				if (UNEXPECTED(iter->funcs->valid(iter) == FAILURE)) {
6440					/* reached end of iteration */
6441					if (UNEXPECTED(EG(exception) != NULL)) {
6442						HANDLE_EXCEPTION();
6443					}
6444					ZEND_VM_C_GOTO(fe_fetch_w_exit);
6445				}
6446			}
6447			value = iter->funcs->get_current_data(iter);
6448			if (UNEXPECTED(EG(exception) != NULL)) {
6449				HANDLE_EXCEPTION();
6450			}
6451			if (!value) {
6452				/* failure in get_current_data */
6453				ZEND_VM_C_GOTO(fe_fetch_w_exit);
6454			}
6455			if (opline->result_type & (IS_TMP_VAR|IS_CV)) {
6456				if (iter->funcs->get_current_key) {
6457					iter->funcs->get_current_key(iter, EX_VAR(opline->result.var));
6458					if (UNEXPECTED(EG(exception) != NULL)) {
6459						HANDLE_EXCEPTION();
6460					}
6461				} else {
6462					ZVAL_LONG(EX_VAR(opline->result.var), iter->index);
6463				}
6464			}
6465			value_type = Z_TYPE_INFO_P(value);
6466		}
6467	} else {
6468		zend_error(E_WARNING, "Invalid argument supplied for foreach()");
6469		if (UNEXPECTED(EG(exception))) {
6470			HANDLE_EXCEPTION();
6471		}
6472ZEND_VM_C_LABEL(fe_fetch_w_exit):
6473		ZEND_VM_SET_RELATIVE_OPCODE(opline, opline->extended_value);
6474		ZEND_VM_CONTINUE();
6475	}
6476
6477	if (EXPECTED((value_type & Z_TYPE_MASK) != IS_REFERENCE)) {
6478		zend_refcounted *gc = Z_COUNTED_P(value);
6479		zval *ref;
6480		ZVAL_NEW_EMPTY_REF(value);
6481		ref = Z_REFVAL_P(value);
6482		ZVAL_COPY_VALUE_EX(ref, value, gc, value_type);
6483	}
6484	if (EXPECTED(OP2_TYPE == IS_CV)) {
6485		zval *variable_ptr = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->op2.var);
6486		if (EXPECTED(variable_ptr != value)) {
6487			zend_reference *ref;
6488
6489			ref = Z_REF_P(value);
6490			GC_REFCOUNT(ref)++;
6491			zval_ptr_dtor(variable_ptr);
6492			ZVAL_REF(variable_ptr, ref);
6493		}
6494	} else {
6495		Z_ADDREF_P(value);
6496		ZVAL_REF(EX_VAR(opline->op2.var), Z_REF_P(value));
6497	}
6498	ZEND_VM_NEXT_OPCODE();
6499}
6500
6501ZEND_VM_HANDLER(114, ZEND_ISSET_ISEMPTY_VAR, CONST|TMPVAR|CV, UNUSED, VAR_FETCH|ISSET)
6502{
6503	USE_OPLINE
6504	zval *value;
6505	int result;
6506
6507	if (OP1_TYPE == IS_CV &&
6508	    (opline->extended_value & ZEND_QUICK_SET)) {
6509		value = EX_VAR(opline->op1.var);
6510		if (opline->extended_value & ZEND_ISSET) {
6511			result =
6512				Z_TYPE_P(value) > IS_NULL &&
6513			    (!Z_ISREF_P(value) || Z_TYPE_P(Z_REFVAL_P(value)) != IS_NULL);
6514		} else /* if (opline->extended_value & ZEND_ISEMPTY) */ {
6515			SAVE_OPLINE();
6516			result = !i_zend_is_true(value);
6517			if (UNEXPECTED(EG(exception))) {
6518				HANDLE_EXCEPTION();
6519			}
6520		}
6521		ZEND_VM_SMART_BRANCH(result, 0);
6522		ZVAL_BOOL(EX_VAR(opline->result.var), result);
6523		ZEND_VM_SET_NEXT_OPCODE(opline + 1);
6524		ZEND_VM_CONTINUE();
6525	} else {
6526		zend_free_op free_op1;
6527		zval tmp, *varname;
6528		HashTable *target_symbol_table;
6529
6530		SAVE_OPLINE();
6531		varname = GET_OP1_ZVAL_PTR(BP_VAR_IS);
6532		ZVAL_UNDEF(&tmp);
6533		if (OP1_TYPE != IS_CONST && Z_TYPE_P(varname) != IS_STRING) {
6534			ZVAL_STR(&tmp, zval_get_string(varname));
6535			varname = &tmp;
6536		}
6537
6538		target_symbol_table = zend_get_target_symbol_table(execute_data, opline->extended_value & ZEND_FETCH_TYPE_MASK);
6539		value = zend_hash_find_ind(target_symbol_table, Z_STR_P(varname));
6540
6541		if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
6542			zend_string_release(Z_STR(tmp));
6543		}
6544		FREE_OP1();
6545
6546		if (opline->extended_value & ZEND_ISSET) {
6547			result = value && Z_TYPE_P(value) > IS_NULL &&
6548			    (!Z_ISREF_P(value) || Z_TYPE_P(Z_REFVAL_P(value)) != IS_NULL);
6549		} else /* if (opline->extended_value & ZEND_ISEMPTY) */ {
6550			result = !value || !i_zend_is_true(value);
6551		}
6552
6553		ZEND_VM_SMART_BRANCH(result, 1);
6554		ZVAL_BOOL(EX_VAR(opline->result.var), result);
6555		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6556	}
6557}
6558
6559ZEND_VM_HANDLER(180, ZEND_ISSET_ISEMPTY_STATIC_PROP, CONST|TMPVAR|CV, UNUSED|CLASS_FETCH|CONST|VAR, ISSET)
6560{
6561	USE_OPLINE
6562	zval *value;
6563	int result;
6564	zend_free_op free_op1;
6565	zval tmp, *varname;
6566	zend_class_entry *ce;
6567
6568	SAVE_OPLINE();
6569	varname = GET_OP1_ZVAL_PTR(BP_VAR_IS);
6570	ZVAL_UNDEF(&tmp);
6571	if (OP1_TYPE != IS_CONST && Z_TYPE_P(varname) != IS_STRING) {
6572		ZVAL_STR(&tmp, zval_get_string(varname));
6573		varname = &tmp;
6574	}
6575
6576	if (OP2_TYPE == IS_CONST) {
6577		if (OP1_TYPE == IS_CONST && EXPECTED((ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)))) != NULL)) {
6578			value = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)) + sizeof(void*));
6579
6580			/* check if static properties were destoyed */
6581			if (UNEXPECTED(CE_STATIC_MEMBERS(ce) == NULL)) {
6582				value = NULL;
6583			}
6584
6585			ZEND_VM_C_GOTO(is_static_prop_return);
6586		} else if (UNEXPECTED((ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) == NULL)) {
6587			ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op2)), EX_CONSTANT(opline->op2) + 1, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
6588			if (UNEXPECTED(ce == NULL)) {
6589				ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6590			}
6591			CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce);
6592		}
6593	} else {
6594		if (OP2_TYPE == IS_UNUSED) {
6595			ce = zend_fetch_class(NULL, opline->op2.num);
6596			if (UNEXPECTED(ce == NULL)) {
6597				ZEND_ASSERT(EG(exception));
6598				if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
6599					zend_string_release(Z_STR(tmp));
6600				}
6601				FREE_OP1();
6602				HANDLE_EXCEPTION();
6603			}
6604		} else {
6605			ce = Z_CE_P(EX_VAR(opline->op2.var));
6606		}
6607		if (OP1_TYPE == IS_CONST &&
6608		    (value = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce)) != NULL) {
6609
6610			/* check if static properties were destoyed */
6611			if (UNEXPECTED(CE_STATIC_MEMBERS(ce) == NULL)) {
6612				value = NULL;
6613			}
6614
6615			ZEND_VM_C_GOTO(is_static_prop_return);
6616		}
6617	}
6618
6619	value = zend_std_get_static_property(ce, Z_STR_P(varname), 1);
6620
6621	if (OP1_TYPE == IS_CONST && value) {
6622		CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce, value);
6623	}
6624
6625	if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
6626		zend_string_release(Z_STR(tmp));
6627	}
6628	FREE_OP1();
6629
6630ZEND_VM_C_LABEL(is_static_prop_return):
6631	if (opline->extended_value & ZEND_ISSET) {
6632		result = value && Z_TYPE_P(value) > IS_NULL &&
6633		    (!Z_ISREF_P(value) || Z_TYPE_P(Z_REFVAL_P(value)) != IS_NULL);
6634	} else /* if (opline->extended_value & ZEND_ISEMPTY) */ {
6635		result = !value || !i_zend_is_true(value);
6636	}
6637
6638	ZEND_VM_SMART_BRANCH(result, 1);
6639	ZVAL_BOOL(EX_VAR(opline->result.var), result);
6640	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6641}
6642
6643ZEND_VM_HANDLER(115, ZEND_ISSET_ISEMPTY_DIM_OBJ, CONST|TMPVAR|UNUSED|THIS|CV, CONST|TMPVAR|CV, ISSET)
6644{
6645	USE_OPLINE
6646	zend_free_op free_op1, free_op2;
6647	zval *container;
6648	int result;
6649	zend_ulong hval;
6650	zval *offset;
6651
6652	SAVE_OPLINE();
6653	container = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_IS);
6654
6655	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
6656		zend_throw_error(NULL, "Using $this when not in object context");
6657		FREE_UNFETCHED_OP2();
6658		HANDLE_EXCEPTION();
6659	}
6660
6661	offset = GET_OP2_ZVAL_PTR_UNDEF(BP_VAR_R);
6662
6663	if (OP1_TYPE != IS_UNUSED && EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
6664		HashTable *ht;
6665		zval *value;
6666		zend_string *str;
6667
6668ZEND_VM_C_LABEL(isset_dim_obj_array):
6669		ht = Z_ARRVAL_P(container);
6670ZEND_VM_C_LABEL(isset_again):
6671		if (EXPECTED(Z_TYPE_P(offset) == IS_STRING)) {
6672			str = Z_STR_P(offset);
6673			if (OP2_TYPE != IS_CONST) {
6674				if (ZEND_HANDLE_NUMERIC(str, hval)) {
6675					ZEND_VM_C_GOTO(num_index_prop);
6676				}
6677			}
6678ZEND_VM_C_LABEL(str_index_prop):
6679			value = zend_hash_find_ind(ht, str);
6680		} else if (EXPECTED(Z_TYPE_P(offset) == IS_LONG)) {
6681			hval = Z_LVAL_P(offset);
6682ZEND_VM_C_LABEL(num_index_prop):
6683			value = zend_hash_index_find(ht, hval);
6684		} else if ((OP2_TYPE & (IS_VAR|IS_CV)) && EXPECTED(Z_ISREF_P(offset))) {
6685			offset = Z_REFVAL_P(offset);
6686			ZEND_VM_C_GOTO(isset_again);
6687		} else if (Z_TYPE_P(offset) == IS_DOUBLE) {
6688			hval = zend_dval_to_lval(Z_DVAL_P(offset));
6689			ZEND_VM_C_GOTO(num_index_prop);
6690		} else if (Z_TYPE_P(offset) == IS_NULL) {
6691			str = ZSTR_EMPTY_ALLOC();
6692			ZEND_VM_C_GOTO(str_index_prop);
6693		} else if (Z_TYPE_P(offset) == IS_FALSE) {
6694			hval = 0;
6695			ZEND_VM_C_GOTO(num_index_prop);
6696		} else if (Z_TYPE_P(offset) == IS_TRUE) {
6697			hval = 1;
6698			ZEND_VM_C_GOTO(num_index_prop);
6699		} else if (Z_TYPE_P(offset) == IS_RESOURCE) {
6700			hval = Z_RES_HANDLE_P(offset);
6701			ZEND_VM_C_GOTO(num_index_prop);
6702		} else if (OP2_TYPE == IS_CV && Z_TYPE_P(offset) == IS_UNDEF) {
6703			GET_OP2_UNDEF_CV(offset, BP_VAR_R);
6704			str = ZSTR_EMPTY_ALLOC();
6705			ZEND_VM_C_GOTO(str_index_prop);
6706		} else {
6707			zend_error(E_WARNING, "Illegal offset type in isset or empty");
6708			ZEND_VM_C_GOTO(isset_not_found);
6709		}
6710
6711		if (opline->extended_value & ZEND_ISSET) {
6712			/* > IS_NULL means not IS_UNDEF and not IS_NULL */
6713			result = value != NULL && Z_TYPE_P(value) > IS_NULL &&
6714			    (!Z_ISREF_P(value) || Z_TYPE_P(Z_REFVAL_P(value)) != IS_NULL);
6715		} else /* if (opline->extended_value & ZEND_ISEMPTY) */ {
6716			result = (value == NULL || !i_zend_is_true(value));
6717		}
6718		ZEND_VM_C_GOTO(isset_dim_obj_exit);
6719	} else if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(container)) {
6720		container = Z_REFVAL_P(container);
6721		if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
6722			ZEND_VM_C_GOTO(isset_dim_obj_array);
6723		}
6724	}
6725
6726	if (OP2_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(offset) == IS_UNDEF)) {
6727		offset = GET_OP2_UNDEF_CV(offset, BP_VAR_R);
6728	}
6729
6730	if (OP1_TYPE == IS_UNUSED ||
6731	    (OP1_TYPE != IS_CONST && EXPECTED(Z_TYPE_P(container) == IS_OBJECT))) {
6732		if (EXPECTED(Z_OBJ_HT_P(container)->has_dimension)) {
6733			result =
6734				((opline->extended_value & ZEND_ISSET) == 0) ^
6735				Z_OBJ_HT_P(container)->has_dimension(container, offset, (opline->extended_value & ZEND_ISSET) == 0);
6736		} else {
6737			zend_error(E_NOTICE, "Trying to check element of non-array");
6738			ZEND_VM_C_GOTO(isset_not_found);
6739		}
6740	} else if (EXPECTED(Z_TYPE_P(container) == IS_STRING)) { /* string offsets */
6741		zend_long lval;
6742
6743		if (EXPECTED(Z_TYPE_P(offset) == IS_LONG)) {
6744			lval = Z_LVAL_P(offset);
6745ZEND_VM_C_LABEL(isset_str_offset):
6746			if (EXPECTED(lval >= 0) && (size_t)lval < Z_STRLEN_P(container)) {
6747				if (opline->extended_value & ZEND_ISSET) {
6748					result = 1;
6749				} else {
6750					result = (Z_STRVAL_P(container)[lval] == '0');
6751				}
6752			} else {
6753				ZEND_VM_C_GOTO(isset_not_found);
6754			}
6755		} else {
6756			if (OP2_TYPE & (IS_CV|IS_VAR)) {
6757				ZVAL_DEREF(offset);
6758			}
6759			if (Z_TYPE_P(offset) < IS_STRING /* simple scalar types */
6760					|| (Z_TYPE_P(offset) == IS_STRING /* or numeric string */
6761						&& IS_LONG == is_numeric_string(Z_STRVAL_P(offset), Z_STRLEN_P(offset), NULL, NULL, 0))) {
6762				lval = zval_get_long(offset);
6763				ZEND_VM_C_GOTO(isset_str_offset);
6764			}
6765			ZEND_VM_C_GOTO(isset_not_found);
6766		}
6767	} else {
6768ZEND_VM_C_LABEL(isset_not_found):
6769		result = ((opline->extended_value & ZEND_ISSET) == 0);
6770	}
6771
6772ZEND_VM_C_LABEL(isset_dim_obj_exit):
6773	FREE_OP2();
6774	FREE_OP1();
6775	ZEND_VM_SMART_BRANCH(result, 1);
6776	ZVAL_BOOL(EX_VAR(opline->result.var), result);
6777	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6778}
6779
6780ZEND_VM_HANDLER(148, ZEND_ISSET_ISEMPTY_PROP_OBJ, CONST|TMPVAR|UNUSED|THIS|CV, CONST|TMPVAR|CV, ISSET)
6781{
6782	USE_OPLINE
6783	zend_free_op free_op1, free_op2;
6784	zval *container;
6785	int result;
6786	zval *offset;
6787
6788	SAVE_OPLINE();
6789	container = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_IS);
6790
6791	if (OP1_TYPE == IS_UNUSED && UNEXPECTED(Z_OBJ_P(container) == NULL)) {
6792		zend_throw_error(NULL, "Using $this when not in object context");
6793		FREE_UNFETCHED_OP2();
6794		HANDLE_EXCEPTION();
6795	}
6796
6797	offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
6798
6799	if (OP1_TYPE == IS_CONST ||
6800	    (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT))) {
6801		if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(container)) {
6802			container = Z_REFVAL_P(container);
6803			if (UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
6804				ZEND_VM_C_GOTO(isset_no_object);
6805			}
6806		} else {
6807			ZEND_VM_C_GOTO(isset_no_object);
6808		}
6809	}
6810	if (UNEXPECTED(!Z_OBJ_HT_P(container)->has_property)) {
6811		zend_error(E_NOTICE, "Trying to check property of non-object");
6812ZEND_VM_C_LABEL(isset_no_object):
6813		result = ((opline->extended_value & ZEND_ISSET) == 0);
6814	} else {
6815		result =
6816			((opline->extended_value & ZEND_ISSET) == 0) ^
6817			Z_OBJ_HT_P(container)->has_property(container, offset, (opline->extended_value & ZEND_ISSET) == 0, ((OP2_TYPE == IS_CONST) ? CACHE_ADDR(Z_CACHE_SLOT_P(offset)) : NULL));
6818	}
6819
6820	FREE_OP2();
6821	FREE_OP1();
6822	ZEND_VM_SMART_BRANCH(result, 1);
6823	ZVAL_BOOL(EX_VAR(opline->result.var), result);
6824	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6825}
6826
6827ZEND_VM_HANDLER(79, ZEND_EXIT, CONST|TMPVAR|UNUSED|CV, ANY)
6828{
6829	USE_OPLINE
6830
6831	SAVE_OPLINE();
6832	if (OP1_TYPE != IS_UNUSED) {
6833		zend_free_op free_op1;
6834		zval *ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
6835
6836		do {
6837			if (Z_TYPE_P(ptr) == IS_LONG) {
6838				EG(exit_status) = Z_LVAL_P(ptr);
6839			} else {
6840				if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(ptr)) {
6841					ptr = Z_REFVAL_P(ptr);
6842					if (Z_TYPE_P(ptr) == IS_LONG) {
6843						EG(exit_status) = Z_LVAL_P(ptr);
6844						break;
6845					}
6846				}
6847				zend_print_variable(ptr);
6848			}
6849		} while (0);
6850		FREE_OP1();
6851	}
6852	zend_bailout();
6853	ZEND_VM_NEXT_OPCODE(); /* Never reached */
6854}
6855
6856ZEND_VM_HANDLER(57, ZEND_BEGIN_SILENCE, ANY, ANY)
6857{
6858	USE_OPLINE
6859
6860	ZVAL_LONG(EX_VAR(opline->result.var), EG(error_reporting));
6861
6862	if (EG(error_reporting)) {
6863		do {
6864			EG(error_reporting) = 0;
6865			if (!EG(error_reporting_ini_entry)) {
6866				zend_ini_entry *p = zend_hash_str_find_ptr(EG(ini_directives), "error_reporting", sizeof("error_reporting")-1);
6867				if (p) {
6868					EG(error_reporting_ini_entry) = p;
6869				} else {
6870					break;
6871				}
6872			}
6873			if (!EG(error_reporting_ini_entry)->modified) {
6874				if (!EG(modified_ini_directives)) {
6875					ALLOC_HASHTABLE(EG(modified_ini_directives));
6876					zend_hash_init(EG(modified_ini_directives), 8, NULL, NULL, 0);
6877				}
6878				if (EXPECTED(zend_hash_str_add_ptr(EG(modified_ini_directives), "error_reporting", sizeof("error_reporting")-1, EG(error_reporting_ini_entry)) != NULL)) {
6879					EG(error_reporting_ini_entry)->orig_value = EG(error_reporting_ini_entry)->value;
6880					EG(error_reporting_ini_entry)->orig_modifiable = EG(error_reporting_ini_entry)->modifiable;
6881					EG(error_reporting_ini_entry)->modified = 1;
6882				}
6883			}
6884		} while (0);
6885	}
6886	ZEND_VM_NEXT_OPCODE();
6887}
6888
6889ZEND_VM_HANDLER(58, ZEND_END_SILENCE, TMP, ANY)
6890{
6891	USE_OPLINE
6892
6893	if (!EG(error_reporting) && Z_LVAL_P(EX_VAR(opline->op1.var)) != 0) {
6894		EG(error_reporting) = Z_LVAL_P(EX_VAR(opline->op1.var));
6895	}
6896	ZEND_VM_NEXT_OPCODE();
6897}
6898
6899ZEND_VM_HANDLER(152, ZEND_JMP_SET, CONST|TMP|VAR|CV, JMP_ADDR)
6900{
6901	USE_OPLINE
6902	zend_free_op free_op1;
6903	zval *value;
6904	zval *ref = NULL;
6905
6906	SAVE_OPLINE();
6907	value = GET_OP1_ZVAL_PTR(BP_VAR_R);
6908
6909	if ((OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) && Z_ISREF_P(value)) {
6910		if (OP1_TYPE == IS_VAR) {
6911			ref = value;
6912		}
6913		value = Z_REFVAL_P(value);
6914	}
6915	if (i_zend_is_true(value)) {
6916		ZVAL_COPY_VALUE(EX_VAR(opline->result.var), value);
6917		if (OP1_TYPE == IS_CONST) {
6918			if (UNEXPECTED(Z_OPT_COPYABLE_P(value))) {
6919				zval_copy_ctor_func(EX_VAR(opline->result.var));
6920			}
6921		} else if (OP1_TYPE == IS_CV) {
6922			if (Z_OPT_REFCOUNTED_P(value)) Z_ADDREF_P(value);
6923		} else if (OP1_TYPE == IS_VAR && ref) {
6924			zend_reference *r = Z_REF_P(ref);
6925
6926			if (Z_OPT_REFCOUNTED_P(value)) Z_ADDREF_P(value);
6927			if (UNEXPECTED(--GC_REFCOUNT(r) == 0)) {
6928				efree_size(r, sizeof(zend_reference));
6929			}
6930		}
6931		ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
6932	}
6933
6934	FREE_OP1();
6935	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6936}
6937
6938ZEND_VM_HANDLER(169, ZEND_COALESCE, CONST|TMP|VAR|CV, JMP_ADDR)
6939{
6940	USE_OPLINE
6941	zend_free_op free_op1;
6942	zval *value;
6943	zval *ref = NULL;
6944
6945	SAVE_OPLINE();
6946	value = GET_OP1_ZVAL_PTR(BP_VAR_IS);
6947
6948	if ((OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) && Z_ISREF_P(value)) {
6949		if (OP1_TYPE == IS_VAR) {
6950			ref = value;
6951		}
6952		value = Z_REFVAL_P(value);
6953	}
6954
6955	if (Z_TYPE_P(value) > IS_NULL) {
6956		ZVAL_COPY_VALUE(EX_VAR(opline->result.var), value);
6957		if (OP1_TYPE == IS_CONST) {
6958			if (UNEXPECTED(Z_OPT_COPYABLE_P(value))) {
6959				zval_copy_ctor_func(EX_VAR(opline->result.var));
6960			}
6961		} else if (OP1_TYPE == IS_CV) {
6962			if (Z_OPT_REFCOUNTED_P(value)) Z_ADDREF_P(value);
6963		} else if (OP1_TYPE == IS_VAR && ref) {
6964			zend_reference *r = Z_REF_P(ref);
6965
6966			if (Z_OPT_REFCOUNTED_P(value)) Z_ADDREF_P(value);
6967			if (UNEXPECTED(--GC_REFCOUNT(r) == 0)) {
6968				efree_size(r, sizeof(zend_reference));
6969			}
6970		}
6971		ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
6972	}
6973
6974	FREE_OP1();
6975	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6976}
6977
6978ZEND_VM_HANDLER(22, ZEND_QM_ASSIGN, CONST|TMP|VAR|CV, ANY)
6979{
6980	USE_OPLINE
6981	zend_free_op free_op1;
6982	zval *value;
6983
6984	value = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
6985	if (OP1_TYPE == IS_CV && UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
6986		SAVE_OPLINE();
6987		GET_OP1_UNDEF_CV(value, BP_VAR_R);
6988		ZVAL_NULL(EX_VAR(opline->result.var));
6989		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
6990	}
6991
6992	if ((OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) && Z_ISREF_P(value)) {
6993		ZVAL_COPY(EX_VAR(opline->result.var), Z_REFVAL_P(value));
6994		if (OP1_TYPE == IS_VAR) {
6995			if (UNEXPECTED(Z_DELREF_P(value) == 0)) {
6996				efree_size(Z_REF_P(value), sizeof(zend_reference));
6997			}
6998		}
6999	} else {
7000		ZVAL_COPY_VALUE(EX_VAR(opline->result.var), value);
7001		if (OP1_TYPE == IS_CONST) {
7002			if (UNEXPECTED(Z_OPT_COPYABLE_P(value))) {
7003				zval_copy_ctor_func(EX_VAR(opline->result.var));
7004			}
7005		} else if (OP1_TYPE == IS_CV) {
7006			if (Z_OPT_REFCOUNTED_P(value)) Z_ADDREF_P(value);
7007		}
7008	}
7009	ZEND_VM_NEXT_OPCODE();
7010}
7011
7012ZEND_VM_HANDLER(101, ZEND_EXT_STMT, ANY, ANY)
7013{
7014	USE_OPLINE
7015
7016	if (!EG(no_extensions)) {
7017		SAVE_OPLINE();
7018		zend_llist_apply_with_argument(&zend_extensions, (llist_apply_with_arg_func_t) zend_extension_statement_handler, EX(func));
7019		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7020	}
7021	ZEND_VM_NEXT_OPCODE();
7022}
7023
7024ZEND_VM_HANDLER(102, ZEND_EXT_FCALL_BEGIN, ANY, ANY)
7025{
7026	USE_OPLINE
7027
7028	if (!EG(no_extensions)) {
7029		SAVE_OPLINE();
7030		zend_llist_apply_with_argument(&zend_extensions, (llist_apply_with_arg_func_t) zend_extension_fcall_begin_handler, EX(func));
7031		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7032	}
7033	ZEND_VM_NEXT_OPCODE();
7034}
7035
7036ZEND_VM_HANDLER(103, ZEND_EXT_FCALL_END, ANY, ANY)
7037{
7038	USE_OPLINE
7039
7040	if (!EG(no_extensions)) {
7041		SAVE_OPLINE();
7042		zend_llist_apply_with_argument(&zend_extensions, (llist_apply_with_arg_func_t) zend_extension_fcall_end_handler, EX(func));
7043		ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7044	}
7045	ZEND_VM_NEXT_OPCODE();
7046}
7047
7048ZEND_VM_HANDLER(139, ZEND_DECLARE_CLASS, ANY, ANY)
7049{
7050	USE_OPLINE
7051
7052	SAVE_OPLINE();
7053	Z_CE_P(EX_VAR(opline->result.var)) = do_bind_class(&EX(func)->op_array, opline, EG(class_table), 0);
7054	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7055}
7056
7057ZEND_VM_HANDLER(140, ZEND_DECLARE_INHERITED_CLASS, ANY, VAR)
7058{
7059	USE_OPLINE
7060
7061	SAVE_OPLINE();
7062	Z_CE_P(EX_VAR(opline->result.var)) = do_bind_inherited_class(&EX(func)->op_array, opline, EG(class_table), Z_CE_P(EX_VAR(opline->op2.var)), 0);
7063	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7064}
7065
7066ZEND_VM_HANDLER(145, ZEND_DECLARE_INHERITED_CLASS_DELAYED, ANY, VAR)
7067{
7068	USE_OPLINE
7069	zval *zce, *orig_zce;
7070
7071	SAVE_OPLINE();
7072	if ((zce = zend_hash_find(EG(class_table), Z_STR_P(EX_CONSTANT(opline->op1)))) == NULL ||
7073	    ((orig_zce = zend_hash_find(EG(class_table), Z_STR_P(EX_CONSTANT(opline->op1)+1))) != NULL &&
7074	     Z_CE_P(zce) != Z_CE_P(orig_zce))) {
7075		do_bind_inherited_class(&EX(func)->op_array, opline, EG(class_table), Z_CE_P(EX_VAR(opline->op2.var)), 0);
7076	}
7077	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7078}
7079
7080ZEND_VM_HANDLER(171, ZEND_DECLARE_ANON_CLASS, ANY, ANY, JMP_ADDR)
7081{
7082	zend_class_entry *ce;
7083	USE_OPLINE
7084
7085	SAVE_OPLINE();
7086	ce = zend_hash_find_ptr(EG(class_table), Z_STR_P(EX_CONSTANT(opline->op1)));
7087	Z_CE_P(EX_VAR(opline->result.var)) = ce;
7088	ZEND_ASSERT(ce != NULL);
7089
7090	if (ce->ce_flags & ZEND_ACC_ANON_BOUND) {
7091		ZEND_VM_SET_RELATIVE_OPCODE(opline, opline->extended_value);
7092		ZEND_VM_CONTINUE();
7093	}
7094
7095	if (!(ce->ce_flags & (ZEND_ACC_INTERFACE|ZEND_ACC_IMPLEMENT_INTERFACES|ZEND_ACC_IMPLEMENT_TRAITS))) {
7096		zend_verify_abstract_class(ce);
7097	}
7098	ce->ce_flags |= ZEND_ACC_ANON_BOUND;
7099	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7100}
7101
7102ZEND_VM_HANDLER(172, ZEND_DECLARE_ANON_INHERITED_CLASS, ANY, VAR, JMP_ADDR)
7103{
7104	zend_class_entry *ce;
7105	USE_OPLINE
7106
7107	SAVE_OPLINE();
7108	ce = zend_hash_find_ptr(EG(class_table), Z_STR_P(EX_CONSTANT(opline->op1)));
7109	Z_CE_P(EX_VAR(opline->result.var)) = ce;
7110	ZEND_ASSERT(ce != NULL);
7111
7112	if (ce->ce_flags & ZEND_ACC_ANON_BOUND) {
7113		ZEND_VM_SET_RELATIVE_OPCODE(opline, opline->extended_value);
7114		ZEND_VM_CONTINUE();
7115	}
7116
7117	zend_do_inheritance(ce, Z_CE_P(EX_VAR(opline->op2.var)));
7118	ce->ce_flags |= ZEND_ACC_ANON_BOUND;
7119	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7120}
7121
7122ZEND_VM_HANDLER(141, ZEND_DECLARE_FUNCTION, ANY, ANY)
7123{
7124	USE_OPLINE
7125
7126	SAVE_OPLINE();
7127	do_bind_function(&EX(func)->op_array, opline, EG(function_table), 0);
7128	ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7129}
7130
7131ZEND_VM_HANDLER(105, ZEND_TICKS, ANY, ANY, NUM)
7132{
7133	USE_OPLINE
7134
7135	if ((uint32_t)++EG(ticks_count) >= opline->extended_value) {
7136		EG(ticks_count) = 0;
7137		if (zend_ticks_function) {
7138			SAVE_OPLINE();
7139			zend_ticks_function(opline->extended_value);
7140			ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7141		}
7142	}
7143	ZEND_VM_NEXT_OPCODE();
7144}
7145
7146ZEND_VM_HANDLER(138, ZEND_INSTANCEOF, TMPVAR|CV, UNUSED|CLASS_FETCH|CONST|VAR)
7147{
7148	USE_OPLINE
7149	zend_free_op free_op1;
7150	zval *expr;
7151	zend_bool result;
7152
7153	SAVE_OPLINE();
7154	expr = GET_OP1_ZVAL_PTR_UNDEF(BP_VAR_R);
7155
7156ZEND_VM_C_LABEL(try_instanceof):
7157	if (Z_TYPE_P(expr) == IS_OBJECT) {
7158		zend_class_entry *ce;
7159
7160		if (OP2_TYPE == IS_CONST) {
7161			ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
7162			if (UNEXPECTED(ce == NULL)) {
7163				ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op2)), EX_CONSTANT(opline->op2) + 1, ZEND_FETCH_CLASS_NO_AUTOLOAD);
7164				if (UNEXPECTED(ce == NULL)) {
7165					ZVAL_FALSE(EX_VAR(opline->result.var));
7166					FREE_OP1();
7167					ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION();
7168				}
7169				CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce);
7170			}
7171		} else if (OP2_TYPE == IS_UNUSED) {
7172			ce = zend_fetch_class(NULL, opline->op2.num);
7173			if (UNEXPECTED(ce == NULL)) {
7174				ZEND_ASSERT(EG(exception));
7175				FREE_OP1();
7176				HANDLE_EXCEPTION();
7177