1/*
2   +----------------------------------------------------------------------+
3   | Zend Engine                                                          |
4   +----------------------------------------------------------------------+
5   | Copyright (c) 1998-2015 Zend Technologies Ltd. (http://www.zend.com) |
6   +----------------------------------------------------------------------+
7   | This source file is subject to version 2.00 of the Zend license,     |
8   | that is bundled with this package in the file LICENSE, and is        |
9   | available through the world-wide-web at the following url:           |
10   | http://www.zend.com/license/2_00.txt.                                |
11   | If you did not receive a copy of the Zend license and are unable to  |
12   | obtain it through the world-wide-web, please send a note to          |
13   | license@zend.com so we can mail you a copy immediately.              |
14   +----------------------------------------------------------------------+
15   | Authors: Andi Gutmans <andi@zend.com>                                |
16   |          Zeev Suraski <zeev@zend.com>                                |
17   |          Dmitry Stogov <dmitry@zend.com>                             |
18   +----------------------------------------------------------------------+
19*/
20
21/* $Id$ */
22
23/* If you change this file, please regenerate the zend_vm_execute.h and
24 * zend_vm_opcodes.h files by running:
25 * php zend_vm_gen.php
26 */
27
28ZEND_VM_HANDLER(1, ZEND_ADD, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
29{
30    USE_OPLINE
31    zend_free_op free_op1, free_op2;
32
33    SAVE_OPLINE();
34    fast_add_function(EX_VAR(opline->result.var),
35        GET_OP1_ZVAL_PTR(BP_VAR_R),
36        GET_OP2_ZVAL_PTR(BP_VAR_R));
37    FREE_OP1();
38    FREE_OP2();
39    CHECK_EXCEPTION();
40    ZEND_VM_NEXT_OPCODE();
41}
42
43ZEND_VM_HANDLER(2, ZEND_SUB, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
44{
45    USE_OPLINE
46    zend_free_op free_op1, free_op2;
47
48    SAVE_OPLINE();
49    fast_sub_function(EX_VAR(opline->result.var),
50        GET_OP1_ZVAL_PTR(BP_VAR_R),
51        GET_OP2_ZVAL_PTR(BP_VAR_R));
52    FREE_OP1();
53    FREE_OP2();
54    CHECK_EXCEPTION();
55    ZEND_VM_NEXT_OPCODE();
56}
57
58ZEND_VM_HANDLER(3, ZEND_MUL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
59{
60    USE_OPLINE
61    zend_free_op free_op1, free_op2;
62
63    SAVE_OPLINE();
64    fast_mul_function(EX_VAR(opline->result.var),
65        GET_OP1_ZVAL_PTR(BP_VAR_R),
66        GET_OP2_ZVAL_PTR(BP_VAR_R));
67    FREE_OP1();
68    FREE_OP2();
69    CHECK_EXCEPTION();
70    ZEND_VM_NEXT_OPCODE();
71}
72
73ZEND_VM_HANDLER(4, ZEND_DIV, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
74{
75    USE_OPLINE
76    zend_free_op free_op1, free_op2;
77
78    SAVE_OPLINE();
79    fast_div_function(EX_VAR(opline->result.var),
80        GET_OP1_ZVAL_PTR(BP_VAR_R),
81        GET_OP2_ZVAL_PTR(BP_VAR_R));
82    FREE_OP1();
83    FREE_OP2();
84    CHECK_EXCEPTION();
85    ZEND_VM_NEXT_OPCODE();
86}
87
88ZEND_VM_HANDLER(5, ZEND_MOD, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
89{
90    USE_OPLINE
91    zend_free_op free_op1, free_op2;
92
93    SAVE_OPLINE();
94    fast_mod_function(EX_VAR(opline->result.var),
95        GET_OP1_ZVAL_PTR(BP_VAR_R),
96        GET_OP2_ZVAL_PTR(BP_VAR_R));
97    FREE_OP1();
98    FREE_OP2();
99    CHECK_EXCEPTION();
100    ZEND_VM_NEXT_OPCODE();
101}
102
103ZEND_VM_HANDLER(6, ZEND_SL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
104{
105    USE_OPLINE
106    zend_free_op free_op1, free_op2;
107
108    SAVE_OPLINE();
109    shift_left_function(EX_VAR(opline->result.var),
110        GET_OP1_ZVAL_PTR(BP_VAR_R),
111        GET_OP2_ZVAL_PTR(BP_VAR_R));
112    FREE_OP1();
113    FREE_OP2();
114    CHECK_EXCEPTION();
115    ZEND_VM_NEXT_OPCODE();
116}
117
118ZEND_VM_HANDLER(7, ZEND_SR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
119{
120    USE_OPLINE
121    zend_free_op free_op1, free_op2;
122
123    SAVE_OPLINE();
124    shift_right_function(EX_VAR(opline->result.var),
125        GET_OP1_ZVAL_PTR(BP_VAR_R),
126        GET_OP2_ZVAL_PTR(BP_VAR_R));
127    FREE_OP1();
128    FREE_OP2();
129    CHECK_EXCEPTION();
130    ZEND_VM_NEXT_OPCODE();
131}
132
133ZEND_VM_HANDLER(8, ZEND_CONCAT, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
134{
135    USE_OPLINE
136    zend_free_op free_op1, free_op2;
137
138    SAVE_OPLINE();
139    concat_function(EX_VAR(opline->result.var),
140        GET_OP1_ZVAL_PTR(BP_VAR_R),
141        GET_OP2_ZVAL_PTR(BP_VAR_R));
142    FREE_OP1();
143    FREE_OP2();
144    CHECK_EXCEPTION();
145    ZEND_VM_NEXT_OPCODE();
146}
147
148ZEND_VM_HANDLER(15, ZEND_IS_IDENTICAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
149{
150    USE_OPLINE
151    zend_free_op free_op1, free_op2;
152
153    SAVE_OPLINE();
154    fast_is_identical_function(EX_VAR(opline->result.var),
155        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
156        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R));
157    FREE_OP1();
158    FREE_OP2();
159    CHECK_EXCEPTION();
160    ZEND_VM_NEXT_OPCODE();
161}
162
163ZEND_VM_HANDLER(16, ZEND_IS_NOT_IDENTICAL, CONST|TMP|VAR|CV, CONST|TMP|VAR|CV)
164{
165    USE_OPLINE
166    zend_free_op free_op1, free_op2;
167    zval *result = EX_VAR(opline->result.var);
168
169    SAVE_OPLINE();
170    fast_is_not_identical_function(result,
171        GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R),
172        GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R));
173    FREE_OP1();
174    FREE_OP2();
175    CHECK_EXCEPTION();
176    ZEND_VM_NEXT_OPCODE();
177}
178
179ZEND_VM_HANDLER(17, ZEND_IS_EQUAL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
180{
181    USE_OPLINE
182    zend_free_op free_op1, free_op2;
183    zval *result = EX_VAR(opline->result.var);
184
185    SAVE_OPLINE();
186    fast_equal_function(result,
187        GET_OP1_ZVAL_PTR(BP_VAR_R),
188        GET_OP2_ZVAL_PTR(BP_VAR_R));
189    FREE_OP1();
190    FREE_OP2();
191    CHECK_EXCEPTION();
192    ZEND_VM_NEXT_OPCODE();
193}
194
195ZEND_VM_HANDLER(18, ZEND_IS_NOT_EQUAL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
196{
197    USE_OPLINE
198    zend_free_op free_op1, free_op2;
199    zval *result = EX_VAR(opline->result.var);
200
201    SAVE_OPLINE();
202    fast_not_equal_function(result,
203        GET_OP1_ZVAL_PTR(BP_VAR_R),
204        GET_OP2_ZVAL_PTR(BP_VAR_R));
205    FREE_OP1();
206    FREE_OP2();
207    CHECK_EXCEPTION();
208    ZEND_VM_NEXT_OPCODE();
209}
210
211ZEND_VM_HANDLER(19, ZEND_IS_SMALLER, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
212{
213    USE_OPLINE
214    zend_free_op free_op1, free_op2;
215    zval *result = EX_VAR(opline->result.var);
216
217    SAVE_OPLINE();
218    fast_is_smaller_function(result,
219        GET_OP1_ZVAL_PTR(BP_VAR_R),
220        GET_OP2_ZVAL_PTR(BP_VAR_R));
221    FREE_OP1();
222    FREE_OP2();
223    CHECK_EXCEPTION();
224    ZEND_VM_NEXT_OPCODE();
225}
226
227ZEND_VM_HANDLER(20, ZEND_IS_SMALLER_OR_EQUAL, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
228{
229    USE_OPLINE
230    zend_free_op free_op1, free_op2;
231    zval *result = EX_VAR(opline->result.var);
232
233    SAVE_OPLINE();
234    fast_is_smaller_or_equal_function(result,
235        GET_OP1_ZVAL_PTR(BP_VAR_R),
236        GET_OP2_ZVAL_PTR(BP_VAR_R));
237    FREE_OP1();
238    FREE_OP2();
239    CHECK_EXCEPTION();
240    ZEND_VM_NEXT_OPCODE();
241}
242
243ZEND_VM_HANDLER(9, ZEND_BW_OR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
244{
245    USE_OPLINE
246    zend_free_op free_op1, free_op2;
247
248    SAVE_OPLINE();
249    bitwise_or_function(EX_VAR(opline->result.var),
250        GET_OP1_ZVAL_PTR(BP_VAR_R),
251        GET_OP2_ZVAL_PTR(BP_VAR_R));
252    FREE_OP1();
253    FREE_OP2();
254    CHECK_EXCEPTION();
255    ZEND_VM_NEXT_OPCODE();
256}
257
258ZEND_VM_HANDLER(10, ZEND_BW_AND, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
259{
260    USE_OPLINE
261    zend_free_op free_op1, free_op2;
262
263    SAVE_OPLINE();
264    bitwise_and_function(EX_VAR(opline->result.var),
265        GET_OP1_ZVAL_PTR(BP_VAR_R),
266        GET_OP2_ZVAL_PTR(BP_VAR_R));
267    FREE_OP1();
268    FREE_OP2();
269    CHECK_EXCEPTION();
270    ZEND_VM_NEXT_OPCODE();
271}
272
273ZEND_VM_HANDLER(11, ZEND_BW_XOR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
274{
275    USE_OPLINE
276    zend_free_op free_op1, free_op2;
277
278    SAVE_OPLINE();
279    bitwise_xor_function(EX_VAR(opline->result.var),
280        GET_OP1_ZVAL_PTR(BP_VAR_R),
281        GET_OP2_ZVAL_PTR(BP_VAR_R));
282    FREE_OP1();
283    FREE_OP2();
284    CHECK_EXCEPTION();
285    ZEND_VM_NEXT_OPCODE();
286}
287
288ZEND_VM_HANDLER(14, ZEND_BOOL_XOR, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
289{
290    USE_OPLINE
291    zend_free_op free_op1, free_op2;
292
293    SAVE_OPLINE();
294    boolean_xor_function(EX_VAR(opline->result.var),
295        GET_OP1_ZVAL_PTR(BP_VAR_R),
296        GET_OP2_ZVAL_PTR(BP_VAR_R));
297    FREE_OP1();
298    FREE_OP2();
299    CHECK_EXCEPTION();
300    ZEND_VM_NEXT_OPCODE();
301}
302
303ZEND_VM_HANDLER(12, ZEND_BW_NOT, CONST|TMPVAR|CV, ANY)
304{
305    USE_OPLINE
306    zend_free_op free_op1;
307
308    SAVE_OPLINE();
309    bitwise_not_function(EX_VAR(opline->result.var),
310        GET_OP1_ZVAL_PTR(BP_VAR_R));
311    FREE_OP1();
312    CHECK_EXCEPTION();
313    ZEND_VM_NEXT_OPCODE();
314}
315
316ZEND_VM_HANDLER(13, ZEND_BOOL_NOT, CONST|TMPVAR|CV, ANY)
317{
318    USE_OPLINE
319    zval *val;
320    zend_free_op free_op1;
321
322    SAVE_OPLINE();
323    val = GET_OP1_ZVAL_PTR(BP_VAR_R);
324    if (Z_TYPE_P(val) == IS_TRUE) {
325        ZVAL_FALSE(EX_VAR(opline->result.var));
326    } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
327        ZVAL_TRUE(EX_VAR(opline->result.var));
328    } else {
329        ZVAL_BOOL(EX_VAR(opline->result.var), !i_zend_is_true(val));
330        FREE_OP1();
331        CHECK_EXCEPTION();
332    }
333    ZEND_VM_NEXT_OPCODE();
334}
335
336ZEND_VM_HELPER_EX(zend_binary_assign_op_obj_helper, VAR|UNUSED|CV, CONST|TMPVAR|CV, int (*binary_op)(zval *result, zval *op1, zval *op2))
337{
338    USE_OPLINE
339    zend_free_op free_op1, free_op2, free_op_data1;
340    zval *object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
341    zval *property = GET_OP2_ZVAL_PTR(BP_VAR_R);
342    zval *value;
343    zval *zptr;
344
345    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
346        zend_error_noreturn(E_ERROR, "Cannot use string offset as an object");
347    }
348
349    do {
350        value = get_zval_ptr((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
351
352        if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
353            if (UNEXPECTED(!make_real_object(&object))) {
354                zend_error(E_WARNING, "Attempt to assign property of non-object");
355                if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
356                    ZVAL_NULL(EX_VAR(opline->result.var));
357                }
358                break;
359            }
360        }
361
362        /* here we are sure we are dealing with an object */
363        if (EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
364            && EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL))) != NULL)) {
365
366            ZVAL_DEREF(zptr);
367            SEPARATE_ZVAL_NOREF(zptr);
368
369            binary_op(zptr, zptr, value);
370            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
371                ZVAL_COPY(EX_VAR(opline->result.var), zptr);
372            }
373        } else {
374            zval *z;
375            zval rv;
376
377            if (Z_OBJ_HT_P(object)->read_property &&
378                (z = Z_OBJ_HT_P(object)->read_property(object, property, BP_VAR_R, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL), &rv)) != NULL) {
379                if (Z_TYPE_P(z) == IS_OBJECT && Z_OBJ_HT_P(z)->get) {
380                    zval rv;
381                    zval *value = Z_OBJ_HT_P(z)->get(z, &rv);
382
383                    if (Z_REFCOUNT_P(z) == 0) {
384                        zend_objects_store_del(Z_OBJ_P(z));
385                    }
386                    ZVAL_COPY_VALUE(z, value);
387                }
388                ZVAL_DEREF(z);
389                SEPARATE_ZVAL_NOREF(z);
390                binary_op(z, z, value);
391                Z_OBJ_HT_P(object)->write_property(object, property, z, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL));
392                if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
393                    ZVAL_COPY(EX_VAR(opline->result.var), z);
394                }
395                zval_ptr_dtor(z);
396            } else {
397                zend_error(E_WARNING, "Attempt to assign property of non-object");
398                if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
399                    ZVAL_NULL(EX_VAR(opline->result.var));
400                }
401            }
402        }
403    } while (0);
404
405    FREE_OP(free_op_data1);
406    FREE_OP2();
407    FREE_OP1_VAR_PTR();
408    /* assign_obj has two opcodes! */
409    CHECK_EXCEPTION();
410    ZEND_VM_INC_OPCODE();
411    ZEND_VM_NEXT_OPCODE();
412}
413
414ZEND_VM_HELPER_EX(zend_binary_assign_op_dim_helper, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV, int (*binary_op)(zval *result, zval *op1, zval *op2))
415{
416    USE_OPLINE
417    zend_free_op free_op1, free_op2, free_op_data1;
418    zval *var_ptr, rv;
419    zval *value, *container, *dim;
420
421    SAVE_OPLINE();
422    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
423    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
424        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
425    }
426
427    dim = GET_OP2_ZVAL_PTR(BP_VAR_R);
428
429    do {
430        if (OP1_TYPE == IS_UNUSED || UNEXPECTED(Z_TYPE_P(container) != IS_ARRAY)) {
431            if (OP1_TYPE != IS_UNUSED) {
432                ZVAL_DEREF(container);
433            }
434#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
435            if (OP1_TYPE == IS_UNUSED || EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
436                value = get_zval_ptr((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
437                zend_binary_assign_op_obj_dim(container, dim, value, UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL, binary_op);
438                break;
439            }
440#endif
441        }
442
443        zend_fetch_dimension_address_RW(&rv, container, dim, OP2_TYPE);
444        value = get_zval_ptr((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
445        ZEND_ASSERT(Z_TYPE(rv) == IS_INDIRECT);
446        var_ptr = Z_INDIRECT(rv);
447
448        if (UNEXPECTED(var_ptr == NULL)) {
449            zend_error_noreturn(E_ERROR, "Cannot use assign-op operators with overloaded objects nor string offsets");
450        }
451
452        if (UNEXPECTED(var_ptr == &EG(error_zval))) {
453            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
454                ZVAL_NULL(EX_VAR(opline->result.var));
455            }
456        } else {
457            ZVAL_DEREF(var_ptr);
458            SEPARATE_ZVAL_NOREF(var_ptr);
459
460            binary_op(var_ptr, var_ptr, value);
461
462            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
463                ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
464            }
465        }
466    } while (0);
467
468    FREE_OP2();
469    FREE_OP(free_op_data1);
470    FREE_OP1_VAR_PTR();
471    CHECK_EXCEPTION();
472    ZEND_VM_INC_OPCODE();
473    ZEND_VM_NEXT_OPCODE();
474}
475
476ZEND_VM_HELPER_EX(zend_binary_assign_op_helper, VAR|CV, CONST|TMPVAR|CV, int (*binary_op)(zval *result, zval *op1, zval *op2))
477{
478    USE_OPLINE
479    zend_free_op free_op1, free_op2;
480    zval *var_ptr;
481    zval *value;
482
483    SAVE_OPLINE();
484    value = GET_OP2_ZVAL_PTR(BP_VAR_R);
485    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
486
487    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
488        zend_error_noreturn(E_ERROR, "Cannot use assign-op operators with overloaded objects nor string offsets");
489    }
490
491    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
492        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
493            ZVAL_NULL(EX_VAR(opline->result.var));
494        }
495    } else {
496        ZVAL_DEREF(var_ptr);
497        SEPARATE_ZVAL_NOREF(var_ptr);
498
499        binary_op(var_ptr, var_ptr, value);
500
501        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
502            ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
503        }
504    }
505
506    FREE_OP2();
507    FREE_OP1_VAR_PTR();
508    CHECK_EXCEPTION();
509    ZEND_VM_NEXT_OPCODE();
510}
511
512ZEND_VM_HANDLER(23, ZEND_ASSIGN_ADD, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
513{
514#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
515    USE_OPLINE
516
517# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
518    if (EXPECTED(opline->extended_value == 0)) {
519        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, add_function);
520    }
521# endif
522    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
523        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, add_function);
524    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
525        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, add_function);
526    }
527#else
528    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, add_function);
529#endif
530}
531
532ZEND_VM_HANDLER(24, ZEND_ASSIGN_SUB, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
533{
534#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
535    USE_OPLINE
536
537# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
538    if (EXPECTED(opline->extended_value == 0)) {
539        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, sub_function);
540    }
541# endif
542    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
543        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, sub_function);
544    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
545        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, sub_function);
546    }
547#else
548    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, sub_function);
549#endif
550}
551
552ZEND_VM_HANDLER(25, ZEND_ASSIGN_MUL, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
553{
554#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
555    USE_OPLINE
556
557# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
558    if (EXPECTED(opline->extended_value == 0)) {
559        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, mul_function);
560    }
561# endif
562    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
563        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, mul_function);
564    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
565        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, mul_function);
566    }
567#else
568    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, mul_function);
569#endif
570}
571
572ZEND_VM_HANDLER(26, ZEND_ASSIGN_DIV, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
573{
574#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
575    USE_OPLINE
576
577# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
578    if (EXPECTED(opline->extended_value == 0)) {
579        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, div_function);
580    }
581# endif
582    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
583        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, div_function);
584    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
585        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, div_function);
586    }
587#else
588    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, div_function);
589#endif
590}
591
592ZEND_VM_HANDLER(27, ZEND_ASSIGN_MOD, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
593{
594#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
595    USE_OPLINE
596
597# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
598    if (EXPECTED(opline->extended_value == 0)) {
599        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, mod_function);
600    }
601# endif
602    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
603        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, mod_function);
604    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
605        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, mod_function);
606    }
607#else
608    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, mod_function);
609#endif
610}
611
612ZEND_VM_HANDLER(28, ZEND_ASSIGN_SL, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
613{
614#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
615    USE_OPLINE
616
617# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
618    if (EXPECTED(opline->extended_value == 0)) {
619        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, shift_left_function);
620    }
621# endif
622    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
623        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, shift_left_function);
624    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
625        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, shift_left_function);
626    }
627#else
628    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, shift_left_function);
629#endif
630}
631
632ZEND_VM_HANDLER(29, ZEND_ASSIGN_SR, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
633{
634#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
635    USE_OPLINE
636
637# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
638    if (EXPECTED(opline->extended_value == 0)) {
639        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, shift_right_function);
640    }
641# endif
642    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
643        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, shift_right_function);
644    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
645        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, shift_right_function);
646    }
647#else
648    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, shift_right_function);
649#endif
650}
651
652ZEND_VM_HANDLER(30, ZEND_ASSIGN_CONCAT, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
653{
654#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
655    USE_OPLINE
656
657# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
658    if (EXPECTED(opline->extended_value == 0)) {
659        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, concat_function);
660    }
661# endif
662    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
663        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, concat_function);
664    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
665        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, concat_function);
666    }
667#else
668    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, concat_function);
669#endif
670}
671
672ZEND_VM_HANDLER(31, ZEND_ASSIGN_BW_OR, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
673{
674#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
675    USE_OPLINE
676
677# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
678    if (EXPECTED(opline->extended_value == 0)) {
679        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, bitwise_or_function);
680    }
681# endif
682    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
683        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_or_function);
684    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
685        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, bitwise_or_function);
686    }
687#else
688    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_or_function);
689#endif
690}
691
692ZEND_VM_HANDLER(32, ZEND_ASSIGN_BW_AND, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
693{
694#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
695    USE_OPLINE
696
697# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
698    if (EXPECTED(opline->extended_value == 0)) {
699        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, bitwise_and_function);
700    }
701# endif
702    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
703        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_and_function);
704    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
705        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, bitwise_and_function);
706    }
707#else
708    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_and_function);
709#endif
710}
711
712ZEND_VM_HANDLER(33, ZEND_ASSIGN_BW_XOR, VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
713{
714#if !defined(ZEND_VM_SPEC) || (OP2_TYPE != IS_UNUSED)
715    USE_OPLINE
716
717# if !defined(ZEND_VM_SPEC) || (OP1_TYPE != IS_UNUSED)
718    if (EXPECTED(opline->extended_value == 0)) {
719        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_helper, binary_op, bitwise_xor_function);
720    }
721# endif
722    if (EXPECTED(opline->extended_value == ZEND_ASSIGN_DIM)) {
723        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_xor_function);
724    } else /* if (EXPECTED(opline->extended_value == ZEND_ASSIGN_OBJ)) */ {
725        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_obj_helper, binary_op, bitwise_xor_function);
726    }
727#else
728    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_binary_assign_op_dim_helper, binary_op, bitwise_xor_function);
729#endif
730}
731
732ZEND_VM_HELPER_EX(zend_pre_incdec_property_helper, VAR|UNUSED|CV, CONST|TMPVAR|CV, incdec_t incdec_op)
733{
734    USE_OPLINE
735    zend_free_op free_op1, free_op2;
736    zval *object;
737    zval *property;
738    zval *retval;
739    zval *zptr;
740
741    SAVE_OPLINE();
742    object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
743    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
744    retval = EX_VAR(opline->result.var);
745
746    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
747        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
748    }
749
750    do {
751        if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
752            if (UNEXPECTED(!make_real_object(&object))) {
753                zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
754                if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
755                    ZVAL_NULL(retval);
756                }
757                break;
758            }
759        }
760
761        /* here we are sure we are dealing with an object */
762
763        if (EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
764            && EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL))) != NULL)) {
765
766            ZVAL_DEREF(zptr);
767            SEPARATE_ZVAL_NOREF(zptr);
768
769            incdec_op(zptr);
770            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
771                ZVAL_COPY(retval, zptr);
772            }
773        } else {
774            zval rv;
775
776            if (Z_OBJ_HT_P(object)->read_property && Z_OBJ_HT_P(object)->write_property) {
777                zval *z = Z_OBJ_HT_P(object)->read_property(object, property, BP_VAR_R, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL), &rv);
778
779                if (UNEXPECTED(Z_TYPE_P(z) == IS_OBJECT) && Z_OBJ_HT_P(z)->get) {
780                    zval rv;
781                    zval *value = Z_OBJ_HT_P(z)->get(z, &rv);
782
783                    if (Z_REFCOUNT_P(z) == 0) {
784                        zend_objects_store_del(Z_OBJ_P(z));
785                    }
786                    ZVAL_COPY_VALUE(z, value);
787                }
788                ZVAL_DEREF(z);
789                SEPARATE_ZVAL_NOREF(z);
790                incdec_op(z);
791                if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
792                    ZVAL_COPY(retval, z);
793                }
794                Z_OBJ_HT_P(object)->write_property(object, property, z, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL));
795                zval_ptr_dtor(z);
796            } else {
797                zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
798                if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
799                    ZVAL_NULL(retval);
800                }
801            }
802        }
803    } while (0);
804
805    FREE_OP2();
806    FREE_OP1_VAR_PTR();
807    CHECK_EXCEPTION();
808    ZEND_VM_NEXT_OPCODE();
809}
810
811ZEND_VM_HANDLER(132, ZEND_PRE_INC_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
812{
813    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_pre_incdec_property_helper, incdec_op, increment_function);
814}
815
816ZEND_VM_HANDLER(133, ZEND_PRE_DEC_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
817{
818    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_pre_incdec_property_helper, incdec_op, decrement_function);
819}
820
821ZEND_VM_HELPER_EX(zend_post_incdec_property_helper, VAR|UNUSED|CV, CONST|TMPVAR|CV, incdec_t incdec_op)
822{
823    USE_OPLINE
824    zend_free_op free_op1, free_op2;
825    zval *object;
826    zval *property;
827    zval *retval;
828    zval *zptr;
829
830    SAVE_OPLINE();
831    object = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
832    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
833    retval = EX_VAR(opline->result.var);
834
835    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
836        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
837    }
838
839    do {
840        if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
841            if (UNEXPECTED(!make_real_object(&object))) {
842                zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
843                ZVAL_NULL(retval);
844                break;
845            }
846        }
847
848        /* here we are sure we are dealing with an object */
849
850        if (EXPECTED(Z_OBJ_HT_P(object)->get_property_ptr_ptr)
851            && EXPECTED((zptr = Z_OBJ_HT_P(object)->get_property_ptr_ptr(object, property, BP_VAR_RW, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL))) != NULL)) {
852
853            ZVAL_DEREF(zptr);
854            ZVAL_COPY_VALUE(retval, zptr);
855            zval_opt_copy_ctor(zptr);
856
857            incdec_op(zptr);
858        } else {
859            if (Z_OBJ_HT_P(object)->read_property && Z_OBJ_HT_P(object)->write_property) {
860                zval rv;
861                zval *z = Z_OBJ_HT_P(object)->read_property(object, property, BP_VAR_R, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL), &rv);
862                zval z_copy;
863
864                if (UNEXPECTED(Z_TYPE_P(z) == IS_OBJECT) && Z_OBJ_HT_P(z)->get) {
865                    zval rv;
866                    zval *value = Z_OBJ_HT_P(z)->get(z, &rv);
867
868                    if (Z_REFCOUNT_P(z) == 0) {
869                        zend_objects_store_del(Z_OBJ_P(z));
870                    }
871                    ZVAL_COPY_VALUE(z, value);
872                }
873                ZVAL_DUP(retval, z);
874                ZVAL_DUP(&z_copy, z);
875                incdec_op(&z_copy);
876                if (Z_REFCOUNTED_P(z)) Z_ADDREF_P(z);
877                Z_OBJ_HT_P(object)->write_property(object, property, &z_copy, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL));
878                zval_ptr_dtor(&z_copy);
879                zval_ptr_dtor(z);
880            } else {
881                zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
882                ZVAL_NULL(retval);
883            }
884        }
885    } while (0);
886
887    FREE_OP2();
888    FREE_OP1_VAR_PTR();
889    CHECK_EXCEPTION();
890    ZEND_VM_NEXT_OPCODE();
891}
892
893ZEND_VM_HANDLER(134, ZEND_POST_INC_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
894{
895    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_post_incdec_property_helper, incdec_op, increment_function);
896}
897
898ZEND_VM_HANDLER(135, ZEND_POST_DEC_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
899{
900    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_post_incdec_property_helper, incdec_op, decrement_function);
901}
902
903ZEND_VM_HANDLER(34, ZEND_PRE_INC, VAR|CV, ANY)
904{
905    USE_OPLINE
906    zend_free_op free_op1;
907    zval *var_ptr;
908
909    SAVE_OPLINE();
910    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
911
912    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
913        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
914    }
915
916    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
917        fast_increment_function(var_ptr);
918        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
919            ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
920        }
921        ZEND_VM_NEXT_OPCODE();
922    }
923
924    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
925        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
926            ZVAL_NULL(EX_VAR(opline->result.var));
927        }
928        CHECK_EXCEPTION();
929        ZEND_VM_NEXT_OPCODE();
930    }
931
932    ZVAL_DEREF(var_ptr);
933    SEPARATE_ZVAL_NOREF(var_ptr);
934
935    increment_function(var_ptr);
936
937    if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
938        ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
939    }
940
941    FREE_OP1_VAR_PTR();
942    CHECK_EXCEPTION();
943    ZEND_VM_NEXT_OPCODE();
944}
945
946ZEND_VM_HANDLER(35, ZEND_PRE_DEC, VAR|CV, ANY)
947{
948    USE_OPLINE
949    zend_free_op free_op1;
950    zval *var_ptr;
951
952    SAVE_OPLINE();
953    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
954
955    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
956        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
957    }
958
959    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
960        fast_decrement_function(var_ptr);
961        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
962            ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
963        }
964        ZEND_VM_NEXT_OPCODE();
965    }
966
967    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
968        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
969            ZVAL_NULL(EX_VAR(opline->result.var));
970        }
971        CHECK_EXCEPTION();
972        ZEND_VM_NEXT_OPCODE();
973    }
974
975    ZVAL_DEREF(var_ptr);
976    SEPARATE_ZVAL_NOREF(var_ptr);
977
978    decrement_function(var_ptr);
979
980    if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
981        ZVAL_COPY(EX_VAR(opline->result.var), var_ptr);
982    }
983
984    FREE_OP1_VAR_PTR();
985    CHECK_EXCEPTION();
986    ZEND_VM_NEXT_OPCODE();
987}
988
989ZEND_VM_HANDLER(36, ZEND_POST_INC, VAR|CV, ANY)
990{
991    USE_OPLINE
992    zend_free_op free_op1;
993    zval *var_ptr;
994
995    SAVE_OPLINE();
996    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
997
998    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
999        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
1000    }
1001
1002    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1003        ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1004        fast_increment_function(var_ptr);
1005        ZEND_VM_NEXT_OPCODE();
1006    }
1007
1008    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
1009        ZVAL_NULL(EX_VAR(opline->result.var));
1010        CHECK_EXCEPTION();
1011        ZEND_VM_NEXT_OPCODE();
1012    }
1013
1014    ZVAL_DEREF(var_ptr);
1015    ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1016    zval_opt_copy_ctor(var_ptr);
1017
1018    increment_function(var_ptr);
1019
1020    FREE_OP1_VAR_PTR();
1021    CHECK_EXCEPTION();
1022    ZEND_VM_NEXT_OPCODE();
1023}
1024
1025ZEND_VM_HANDLER(37, ZEND_POST_DEC, VAR|CV, ANY)
1026{
1027    USE_OPLINE
1028    zend_free_op free_op1;
1029    zval *var_ptr;
1030
1031    SAVE_OPLINE();
1032    var_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
1033
1034    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == NULL)) {
1035        zend_error_noreturn(E_ERROR, "Cannot increment/decrement overloaded objects nor string offsets");
1036    }
1037
1038    if (EXPECTED(Z_TYPE_P(var_ptr) == IS_LONG)) {
1039        ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1040        fast_decrement_function(var_ptr);
1041        ZEND_VM_NEXT_OPCODE();
1042    }
1043
1044    if (OP1_TYPE == IS_VAR && UNEXPECTED(var_ptr == &EG(error_zval))) {
1045        ZVAL_NULL(EX_VAR(opline->result.var));
1046        CHECK_EXCEPTION();
1047        ZEND_VM_NEXT_OPCODE();
1048    }
1049
1050    ZVAL_DEREF(var_ptr);
1051    ZVAL_COPY_VALUE(EX_VAR(opline->result.var), var_ptr);
1052    zval_opt_copy_ctor(var_ptr);
1053
1054    decrement_function(var_ptr);
1055
1056    FREE_OP1_VAR_PTR();
1057    CHECK_EXCEPTION();
1058    ZEND_VM_NEXT_OPCODE();
1059}
1060
1061ZEND_VM_HANDLER(40, ZEND_ECHO, CONST|TMPVAR|CV, ANY)
1062{
1063    USE_OPLINE
1064    zend_free_op free_op1;
1065    zval *z;
1066
1067    SAVE_OPLINE();
1068    z = GET_OP1_ZVAL_PTR(BP_VAR_R);
1069
1070    if (Z_TYPE_P(z) == IS_STRING) {
1071        zend_string *str = Z_STR_P(z);
1072
1073        if (str->len != 0) {
1074            zend_write(str->val, str->len);
1075        }
1076    } else {
1077        zend_string *str = _zval_get_string_func(z);
1078
1079        if (str->len != 0) {
1080            zend_write(str->val, str->len);
1081        }
1082        zend_string_release(str);
1083    }
1084
1085    FREE_OP1();
1086    CHECK_EXCEPTION();
1087    ZEND_VM_NEXT_OPCODE();
1088}
1089
1090ZEND_VM_HELPER_EX(zend_fetch_var_address_helper, CONST|TMPVAR|CV, UNUSED|CONST|VAR, int type)
1091{
1092    USE_OPLINE
1093    zend_free_op free_op1;
1094    zval *varname;
1095    zval *retval;
1096    zend_string *name;
1097    HashTable *target_symbol_table;
1098
1099    SAVE_OPLINE();
1100    varname = GET_OP1_ZVAL_PTR(BP_VAR_R);
1101
1102    if (OP1_TYPE == IS_CONST) {
1103        name = Z_STR_P(varname);
1104    } else if (EXPECTED(Z_TYPE_P(varname) == IS_STRING)) {
1105        name = Z_STR_P(varname);
1106        zend_string_addref(name);
1107    } else {
1108        name = zval_get_string(varname);
1109    }
1110
1111    if (OP2_TYPE != IS_UNUSED) {
1112        zend_class_entry *ce;
1113
1114        if (OP2_TYPE == IS_CONST) {
1115            if (OP1_TYPE == IS_CONST && CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)))) {
1116
1117                ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
1118                retval = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)) + 1);
1119
1120                /* check if static properties were destoyed */
1121                if (UNEXPECTED(CE_STATIC_MEMBERS(ce) == NULL)) {
1122                    zend_error_noreturn(E_ERROR, "Access to undeclared static property: %s::$%s", ce->name->val, name->val);
1123                }
1124
1125                ZEND_VM_C_GOTO(fetch_var_return);
1126            } else if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) {
1127                ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
1128            } else {
1129                ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op2)), EX_CONSTANT(opline->op2) + 1, 0);
1130                if (UNEXPECTED(ce == NULL)) {
1131                    if (OP1_TYPE != IS_CONST) {
1132                        zend_string_release(name);
1133                    }
1134                    FREE_OP1();
1135                    CHECK_EXCEPTION();
1136                    ZEND_VM_NEXT_OPCODE();
1137                }
1138                CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce);
1139            }
1140        } else {
1141            ce = Z_CE_P(EX_VAR(opline->op2.var));
1142            if (OP1_TYPE == IS_CONST &&
1143                (retval = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce)) != NULL) {
1144
1145                /* check if static properties were destoyed */
1146                if (UNEXPECTED(CE_STATIC_MEMBERS(ce) == NULL)) {
1147                    zend_error_noreturn(E_ERROR, "Access to undeclared static property: %s::$%s", ce->name->val, name->val);
1148                }
1149
1150                ZEND_VM_C_GOTO(fetch_var_return);
1151            }
1152        }
1153        retval = zend_std_get_static_property(ce, name, 0);
1154        if (OP1_TYPE == IS_CONST && retval) {
1155            CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce, retval);
1156        }
1157
1158        FREE_OP1();
1159    } else {
1160        target_symbol_table = zend_get_target_symbol_table(execute_data, opline->extended_value & ZEND_FETCH_TYPE_MASK);
1161        retval = zend_hash_find(target_symbol_table, name);
1162        if (retval == NULL) {
1163            switch (type) {
1164                case BP_VAR_R:
1165                case BP_VAR_UNSET:
1166                    zend_error(E_NOTICE,"Undefined variable: %s", name->val);
1167                    /* break missing intentionally */
1168                case BP_VAR_IS:
1169                    retval = &EG(uninitialized_zval);
1170                    break;
1171                case BP_VAR_RW:
1172                    zend_error(E_NOTICE,"Undefined variable: %s", name->val);
1173                    /* break missing intentionally */
1174                case BP_VAR_W:
1175                    retval = zend_hash_add_new(target_symbol_table, name, &EG(uninitialized_zval));
1176                    break;
1177                EMPTY_SWITCH_DEFAULT_CASE()
1178            }
1179        /* GLOBAL or $$name variable may be an INDIRECT pointer to CV */
1180        } else if (Z_TYPE_P(retval) == IS_INDIRECT) {
1181            retval = Z_INDIRECT_P(retval);
1182            if (Z_TYPE_P(retval) == IS_UNDEF) {
1183                switch (type) {
1184                    case BP_VAR_R:
1185                    case BP_VAR_UNSET:
1186                        zend_error(E_NOTICE,"Undefined variable: %s", name->val);
1187                        /* break missing intentionally */
1188                    case BP_VAR_IS:
1189                        retval = &EG(uninitialized_zval);
1190                        break;
1191                    case BP_VAR_RW:
1192                        zend_error(E_NOTICE,"Undefined variable: %s", name->val);
1193                        /* break missing intentionally */
1194                    case BP_VAR_W:
1195                        ZVAL_NULL(retval);
1196                        break;
1197                    EMPTY_SWITCH_DEFAULT_CASE()
1198                }
1199            }
1200        }
1201        if ((opline->extended_value & ZEND_FETCH_TYPE_MASK) == ZEND_FETCH_STATIC) {
1202            if (Z_CONSTANT_P(retval)) {
1203                zval_update_constant(retval, 1);
1204            }
1205        } else if ((opline->extended_value & ZEND_FETCH_TYPE_MASK) != ZEND_FETCH_GLOBAL_LOCK) {
1206            FREE_OP1();
1207        }
1208    }
1209
1210    if (OP1_TYPE != IS_CONST) {
1211        zend_string_release(name);
1212    }
1213
1214ZEND_VM_C_LABEL(fetch_var_return):
1215    ZEND_ASSERT(retval != NULL);
1216    if (type == BP_VAR_R || type == BP_VAR_IS) {
1217        if (/*type == BP_VAR_R &&*/ Z_ISREF_P(retval) && Z_REFCOUNT_P(retval) == 1) {
1218            ZVAL_UNREF(retval);
1219        }
1220        ZVAL_COPY(EX_VAR(opline->result.var), retval);
1221    } else {
1222        ZVAL_INDIRECT(EX_VAR(opline->result.var), retval);
1223    }
1224    CHECK_EXCEPTION();
1225    ZEND_VM_NEXT_OPCODE();
1226}
1227
1228ZEND_VM_HANDLER(80, ZEND_FETCH_R, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1229{
1230    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_R);
1231}
1232
1233ZEND_VM_HANDLER(83, ZEND_FETCH_W, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1234{
1235    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_W);
1236}
1237
1238ZEND_VM_HANDLER(86, ZEND_FETCH_RW, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1239{
1240    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_RW);
1241}
1242
1243ZEND_VM_HANDLER(92, ZEND_FETCH_FUNC_ARG, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1244{
1245    USE_OPLINE
1246
1247    if (zend_is_by_ref_func_arg_fetch(opline, EX(call))) {
1248        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_W);
1249    } else {
1250        ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_R);
1251    }
1252}
1253
1254ZEND_VM_HANDLER(95, ZEND_FETCH_UNSET, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1255{
1256    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_UNSET);
1257}
1258
1259ZEND_VM_HANDLER(89, ZEND_FETCH_IS, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
1260{
1261    ZEND_VM_DISPATCH_TO_HELPER_EX(zend_fetch_var_address_helper, type, BP_VAR_IS);
1262}
1263
1264ZEND_VM_HANDLER(81, ZEND_FETCH_DIM_R, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
1265{
1266    USE_OPLINE
1267    zend_free_op free_op1, free_op2;
1268    zval *container;
1269
1270    SAVE_OPLINE();
1271    container = GET_OP1_ZVAL_PTR(BP_VAR_R);
1272    zend_fetch_dimension_address_read_R(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1273    FREE_OP2();
1274    FREE_OP1();
1275    CHECK_EXCEPTION();
1276    ZEND_VM_NEXT_OPCODE();
1277}
1278
1279ZEND_VM_HANDLER(84, ZEND_FETCH_DIM_W, VAR|CV, CONST|TMPVAR|UNUSED|CV)
1280{
1281    USE_OPLINE
1282    zend_free_op free_op1, free_op2;
1283    zval *container;
1284
1285    SAVE_OPLINE();
1286    container = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1287
1288    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1289        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1290    }
1291    zend_fetch_dimension_address_W(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1292    FREE_OP2();
1293    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1294        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1295    }
1296    FREE_OP1_VAR_PTR();
1297    CHECK_EXCEPTION();
1298    ZEND_VM_NEXT_OPCODE();
1299}
1300
1301ZEND_VM_HANDLER(87, ZEND_FETCH_DIM_RW, VAR|CV, CONST|TMPVAR|UNUSED|CV)
1302{
1303    USE_OPLINE
1304    zend_free_op free_op1, free_op2;
1305    zval *container;
1306
1307    SAVE_OPLINE();
1308    container = GET_OP1_ZVAL_PTR_PTR(BP_VAR_RW);
1309
1310    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1311        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1312    }
1313    zend_fetch_dimension_address_RW(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1314    FREE_OP2();
1315    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1316        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1317    }
1318    FREE_OP1_VAR_PTR();
1319    CHECK_EXCEPTION();
1320    ZEND_VM_NEXT_OPCODE();
1321}
1322
1323ZEND_VM_HANDLER(90, ZEND_FETCH_DIM_IS, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
1324{
1325    USE_OPLINE
1326    zend_free_op free_op1, free_op2;
1327    zval *container;
1328
1329    SAVE_OPLINE();
1330    container = GET_OP1_ZVAL_PTR(BP_VAR_IS);
1331    zend_fetch_dimension_address_read_IS(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1332    FREE_OP2();
1333    FREE_OP1();
1334    CHECK_EXCEPTION();
1335    ZEND_VM_NEXT_OPCODE();
1336}
1337
1338ZEND_VM_HANDLER(93, ZEND_FETCH_DIM_FUNC_ARG, CONST|TMP|VAR|CV, CONST|TMPVAR|UNUSED|CV)
1339{
1340    USE_OPLINE
1341    zval *container;
1342    zend_free_op free_op1, free_op2;
1343
1344    SAVE_OPLINE();
1345
1346    if (zend_is_by_ref_func_arg_fetch(opline, EX(call))) {
1347        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
1348            zend_error_noreturn(E_ERROR, "Cannot use temporary expression in write context");
1349        }
1350        container = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1351        if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1352            zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1353        }
1354        zend_fetch_dimension_address_W(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1355        if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1356            EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1357        }
1358        FREE_OP2();
1359        FREE_OP1_VAR_PTR();
1360    } else {
1361        if (OP2_TYPE == IS_UNUSED) {
1362            zend_error_noreturn(E_ERROR, "Cannot use [] for reading");
1363        }
1364        container = GET_OP1_ZVAL_PTR(BP_VAR_R);
1365        zend_fetch_dimension_address_read_R(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1366        FREE_OP2();
1367        FREE_OP1();
1368    }
1369    CHECK_EXCEPTION();
1370    ZEND_VM_NEXT_OPCODE();
1371}
1372
1373ZEND_VM_HANDLER(96, ZEND_FETCH_DIM_UNSET, VAR|CV, CONST|TMPVAR|CV)
1374{
1375    USE_OPLINE
1376    zend_free_op free_op1, free_op2;
1377    zval *container;
1378
1379    SAVE_OPLINE();
1380    container = GET_OP1_ZVAL_PTR_PTR(BP_VAR_UNSET);
1381
1382    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1383        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1384    }
1385    zend_fetch_dimension_address_UNSET(EX_VAR(opline->result.var), container, GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE);
1386    FREE_OP2();
1387    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1388        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1389    }
1390    FREE_OP1_VAR_PTR();
1391    CHECK_EXCEPTION();
1392    ZEND_VM_NEXT_OPCODE();
1393}
1394
1395ZEND_VM_HANDLER(82, ZEND_FETCH_OBJ_R, CONST|TMP|VAR|UNUSED|CV, CONST|TMPVAR|CV)
1396{
1397    USE_OPLINE
1398    zend_free_op free_op1;
1399    zval *container;
1400    zend_free_op free_op2;
1401    zval *offset;
1402
1403    SAVE_OPLINE();
1404    container = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_R);
1405    offset  = GET_OP2_ZVAL_PTR(BP_VAR_R);
1406
1407    if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
1408        if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(container)) {
1409            container = Z_REFVAL_P(container);
1410            if (UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
1411                ZEND_VM_C_GOTO(fetch_obj_r_no_object);
1412            }
1413        } else {
1414            ZEND_VM_C_GOTO(fetch_obj_r_no_object);
1415        }
1416    }
1417
1418    /* here we are sure we are dealing with an object */
1419    do {
1420        zend_object *zobj = Z_OBJ_P(container);
1421        zval *retval;
1422
1423        if (OP2_TYPE == IS_CONST &&
1424            EXPECTED(zobj->ce == CACHED_PTR(Z_CACHE_SLOT_P(offset)))) {
1425            uint32_t prop_offset = (uint32_t)(intptr_t)CACHED_PTR(Z_CACHE_SLOT_P(offset) + 1);
1426
1427            if (EXPECTED(prop_offset != ZEND_DYNAMIC_PROPERTY_OFFSET)) {
1428                retval = OBJ_PROP(zobj, prop_offset);
1429                if (EXPECTED(Z_TYPE_P(retval) != IS_UNDEF)) {
1430                    ZVAL_COPY(EX_VAR(opline->result.var), retval);
1431                    break;
1432                }
1433            } else if (EXPECTED(zobj->properties != NULL)) {
1434                retval = zend_hash_find(zobj->properties, Z_STR_P(offset));
1435                if (EXPECTED(retval)) {
1436                    ZVAL_COPY(EX_VAR(opline->result.var), retval);
1437                    break;
1438                }
1439            }
1440        }
1441
1442        if (UNEXPECTED(zobj->handlers->read_property == NULL)) {
1443ZEND_VM_C_LABEL(fetch_obj_r_no_object):
1444            zend_error(E_NOTICE, "Trying to get property of non-object");
1445            ZVAL_NULL(EX_VAR(opline->result.var));
1446        } else {
1447            retval = zobj->handlers->read_property(container, offset, BP_VAR_R, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(offset)) : NULL), EX_VAR(opline->result.var));
1448
1449            if (retval != EX_VAR(opline->result.var)) {
1450                ZVAL_COPY(EX_VAR(opline->result.var), retval);
1451            }
1452        }
1453    } while (0);
1454
1455    FREE_OP2();
1456    FREE_OP1();
1457    CHECK_EXCEPTION();
1458    ZEND_VM_NEXT_OPCODE();
1459}
1460
1461ZEND_VM_HANDLER(85, ZEND_FETCH_OBJ_W, VAR|UNUSED|CV, CONST|TMPVAR|CV)
1462{
1463    USE_OPLINE
1464    zend_free_op free_op1, free_op2;
1465    zval *property;
1466    zval *container;
1467
1468    SAVE_OPLINE();
1469    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1470
1471    container = GET_OP1_OBJ_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1472    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1473        zend_error_noreturn(E_ERROR, "Cannot use string offset as an object");
1474    }
1475
1476    zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_W);
1477    FREE_OP2();
1478    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1479        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1480    }
1481    FREE_OP1_VAR_PTR();
1482    CHECK_EXCEPTION();
1483    ZEND_VM_NEXT_OPCODE();
1484}
1485
1486ZEND_VM_HANDLER(88, ZEND_FETCH_OBJ_RW, VAR|UNUSED|CV, CONST|TMPVAR|CV)
1487{
1488    USE_OPLINE
1489    zend_free_op free_op1, free_op2;
1490    zval *property;
1491    zval *container;
1492
1493    SAVE_OPLINE();
1494    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1495    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_RW);
1496
1497    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1498        zend_error_noreturn(E_ERROR, "Cannot use string offset as an object");
1499    }
1500    zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_RW);
1501    FREE_OP2();
1502    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1503        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1504    }
1505    FREE_OP1_VAR_PTR();
1506    CHECK_EXCEPTION();
1507    ZEND_VM_NEXT_OPCODE();
1508}
1509
1510ZEND_VM_HANDLER(91, ZEND_FETCH_OBJ_IS, CONST|TMPVAR|UNUSED|CV, CONST|TMPVAR|CV)
1511{
1512    USE_OPLINE
1513    zend_free_op free_op1;
1514    zval *container;
1515    zend_free_op free_op2;
1516    zval *offset;
1517
1518    SAVE_OPLINE();
1519    container = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_IS);
1520    offset  = GET_OP2_ZVAL_PTR(BP_VAR_R);
1521
1522    if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
1523        if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(container)) {
1524            container = Z_REFVAL_P(container);
1525            if (UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
1526                ZEND_VM_C_GOTO(fetch_obj_is_no_object);
1527            }
1528        } else {
1529            ZEND_VM_C_GOTO(fetch_obj_is_no_object);
1530        }
1531    }
1532
1533    /* here we are sure we are dealing with an object */
1534    do {
1535        zend_object *zobj = Z_OBJ_P(container);
1536        zval *retval;
1537
1538        if (OP2_TYPE == IS_CONST &&
1539            EXPECTED(zobj->ce == CACHED_PTR(Z_CACHE_SLOT_P(offset)))) {
1540            uint32_t prop_offset = (uint32_t)(intptr_t)CACHED_PTR(Z_CACHE_SLOT_P(offset) + 1);
1541
1542            if (EXPECTED(prop_offset != ZEND_DYNAMIC_PROPERTY_OFFSET)) {
1543                retval = OBJ_PROP(zobj, prop_offset);
1544                if (EXPECTED(Z_TYPE_P(retval) != IS_UNDEF)) {
1545                    ZVAL_COPY(EX_VAR(opline->result.var), retval);
1546                    break;
1547                }
1548            } else if (EXPECTED(zobj->properties != NULL)) {
1549                retval = zend_hash_find(zobj->properties, Z_STR_P(offset));
1550                if (EXPECTED(retval)) {
1551                    ZVAL_COPY(EX_VAR(opline->result.var), retval);
1552                    break;
1553                }
1554            }
1555        }
1556
1557        if (UNEXPECTED(zobj->handlers->read_property == NULL)) {
1558ZEND_VM_C_LABEL(fetch_obj_is_no_object):
1559            ZVAL_NULL(EX_VAR(opline->result.var));
1560        } else {
1561
1562            retval = zobj->handlers->read_property(container, offset, BP_VAR_IS, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(offset)) : NULL), EX_VAR(opline->result.var));
1563
1564            if (retval != EX_VAR(opline->result.var)) {
1565                ZVAL_COPY(EX_VAR(opline->result.var), retval);
1566            }
1567        }
1568    } while (0);
1569
1570    FREE_OP2();
1571    FREE_OP1();
1572    CHECK_EXCEPTION();
1573    ZEND_VM_NEXT_OPCODE();
1574}
1575
1576ZEND_VM_HANDLER(94, ZEND_FETCH_OBJ_FUNC_ARG, CONST|TMP|VAR|UNUSED|CV, CONST|TMPVAR|CV)
1577{
1578    USE_OPLINE
1579    zval *container;
1580
1581    if (zend_is_by_ref_func_arg_fetch(opline, EX(call))) {
1582        /* Behave like FETCH_OBJ_W */
1583        zend_free_op free_op1, free_op2;
1584        zval *property;
1585
1586        SAVE_OPLINE();
1587        property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1588        container = GET_OP1_OBJ_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1589
1590        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
1591            zend_error_noreturn(E_ERROR, "Cannot use temporary expression in write context");
1592        }
1593        if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1594            zend_error_noreturn(E_ERROR, "Cannot use string offset as an object");
1595        }
1596        zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_W);
1597        FREE_OP2();
1598        if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1599            EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1600        }
1601        FREE_OP1_VAR_PTR();
1602        CHECK_EXCEPTION();
1603        ZEND_VM_NEXT_OPCODE();
1604    } else {
1605        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_FETCH_OBJ_R);
1606    }
1607}
1608
1609ZEND_VM_HANDLER(97, ZEND_FETCH_OBJ_UNSET, VAR|UNUSED|CV, CONST|TMPVAR|CV)
1610{
1611    USE_OPLINE
1612    zend_free_op free_op1, free_op2;
1613    zval *container, *property;
1614
1615    SAVE_OPLINE();
1616    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_UNSET);
1617    property = GET_OP2_ZVAL_PTR(BP_VAR_R);
1618
1619    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
1620        zend_error_noreturn(E_ERROR, "Cannot use string offset as an object");
1621    }
1622    zend_fetch_property_address(EX_VAR(opline->result.var), container, OP1_TYPE, property, OP2_TYPE, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property)) : NULL), BP_VAR_UNSET);
1623    FREE_OP2();
1624    if (OP1_TYPE == IS_VAR && READY_TO_DESTROY(free_op1)) {
1625        EXTRACT_ZVAL_PTR(EX_VAR(opline->result.var));
1626    }
1627    FREE_OP1_VAR_PTR();
1628    CHECK_EXCEPTION();
1629    ZEND_VM_NEXT_OPCODE();
1630}
1631
1632ZEND_VM_HANDLER(98, ZEND_FETCH_LIST, CONST|TMPVAR|CV, CONST)
1633{
1634    USE_OPLINE
1635    zend_free_op free_op1;
1636    zval *container;
1637
1638    SAVE_OPLINE();
1639    container = GET_OP1_ZVAL_PTR(BP_VAR_R);
1640
1641ZEND_VM_C_LABEL(try_fetch_list):
1642    if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
1643        zend_free_op free_op2;
1644        zval *value = zend_fetch_dimension_address_inner(Z_ARRVAL_P(container), GET_OP2_ZVAL_PTR(BP_VAR_R), OP2_TYPE, BP_VAR_R);
1645
1646        ZVAL_COPY(EX_VAR(opline->result.var), value);
1647    } else if (UNEXPECTED(Z_TYPE_P(container) == IS_OBJECT) &&
1648               EXPECTED(Z_OBJ_HT_P(container)->read_dimension)) {
1649        zval *result = EX_VAR(opline->result.var);
1650        zval *retval = Z_OBJ_HT_P(container)->read_dimension(container, GET_OP2_ZVAL_PTR(BP_VAR_R), BP_VAR_R, result);
1651
1652        if (retval) {
1653            if (result != retval) {
1654                ZVAL_COPY(result, retval);
1655            }
1656        } else {
1657            ZVAL_NULL(result);
1658        }
1659    } else if (Z_TYPE_P(container) == IS_REFERENCE) {
1660        container = Z_REFVAL_P(container);
1661        ZEND_VM_C_GOTO(try_fetch_list);
1662    } else {
1663        ZVAL_NULL(EX_VAR(opline->result.var));
1664    }
1665    CHECK_EXCEPTION();
1666    ZEND_VM_NEXT_OPCODE();
1667}
1668
1669ZEND_VM_HANDLER(136, ZEND_ASSIGN_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
1670{
1671    USE_OPLINE
1672    zend_free_op free_op1, free_op2;
1673    zval *object;
1674    zval *property_name;
1675
1676    SAVE_OPLINE();
1677    object = GET_OP1_OBJ_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1678    property_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
1679
1680    if (OP1_TYPE == IS_VAR && UNEXPECTED(object == NULL)) {
1681        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1682    }
1683    zend_assign_to_object(UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL, object, OP1_TYPE, property_name, OP2_TYPE, (opline+1)->op1_type, (opline+1)->op1, execute_data, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(property_name)) : NULL));
1684    FREE_OP2();
1685    FREE_OP1_VAR_PTR();
1686    /* assign_obj has two opcodes! */
1687    CHECK_EXCEPTION();
1688    ZEND_VM_INC_OPCODE();
1689    ZEND_VM_NEXT_OPCODE();
1690}
1691
1692ZEND_VM_HANDLER(147, ZEND_ASSIGN_DIM, VAR|CV, CONST|TMPVAR|UNUSED|CV)
1693{
1694    USE_OPLINE
1695    zend_free_op free_op1;
1696    zval *object_ptr;
1697    zend_free_op free_op2, free_op_data1;
1698    zval  rv;
1699    zval *value;
1700    zval *variable_ptr;
1701    zval *dim;
1702
1703    SAVE_OPLINE();
1704    object_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1705
1706    if (OP1_TYPE == IS_VAR && UNEXPECTED(object_ptr == NULL)) {
1707        zend_error_noreturn(E_ERROR, "Cannot use string offset as an array");
1708    }
1709
1710ZEND_VM_C_LABEL(try_assign_dim):
1711    if (EXPECTED(Z_TYPE_P(object_ptr) == IS_ARRAY)) {
1712ZEND_VM_C_LABEL(try_assign_dim_array):
1713        dim = GET_OP2_ZVAL_PTR(BP_VAR_R);
1714        zend_fetch_dimension_address_W(&rv, object_ptr, dim, OP2_TYPE);
1715        FREE_OP2();
1716        value = get_zval_ptr_deref((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
1717        ZEND_ASSERT(Z_TYPE(rv) == IS_INDIRECT);
1718        variable_ptr = Z_INDIRECT(rv);
1719        if (UNEXPECTED(variable_ptr == &EG(error_zval))) {
1720            FREE_OP(free_op_data1);
1721            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1722                ZVAL_NULL(EX_VAR(opline->result.var));
1723            }
1724        } else {
1725            value = zend_assign_to_variable(variable_ptr, value, (opline+1)->op1_type);
1726            if ((opline+1)->op1_type == IS_VAR) {
1727                FREE_OP(free_op_data1);
1728            }
1729            if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1730                ZVAL_COPY(EX_VAR(opline->result.var), value);
1731            }
1732        }
1733    } else if (EXPECTED(Z_TYPE_P(object_ptr) == IS_OBJECT)) {
1734        zend_free_op free_op2;
1735        zval *property_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
1736
1737        zend_assign_to_object_dim(UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL, object_ptr, property_name, (opline+1)->op1_type, (opline+1)->op1, execute_data);
1738        FREE_OP2();
1739    } else if (EXPECTED(Z_TYPE_P(object_ptr) == IS_STRING) &&
1740        EXPECTED(Z_STRLEN_P(object_ptr) != 0)) {
1741        zend_long offset;
1742
1743        dim = GET_OP2_ZVAL_PTR(BP_VAR_R);
1744        offset = zend_fetch_string_offset(object_ptr, dim, BP_VAR_W);
1745        FREE_OP2();
1746        value = get_zval_ptr_deref((opline+1)->op1_type, (opline+1)->op1, execute_data, &free_op_data1, BP_VAR_R);
1747        zend_assign_to_string_offset(object_ptr, offset, value, (UNEXPECTED(RETURN_VALUE_USED(opline)) ? EX_VAR(opline->result.var) : NULL));
1748        FREE_OP(free_op_data1);
1749    } else if (EXPECTED(Z_ISREF_P(object_ptr))) {
1750        object_ptr = Z_REFVAL_P(object_ptr);
1751        ZEND_VM_C_GOTO(try_assign_dim);
1752    } else {
1753        ZEND_VM_C_GOTO(try_assign_dim_array);
1754    }
1755    FREE_OP1_VAR_PTR();
1756    /* assign_dim has two opcodes! */
1757    CHECK_EXCEPTION();
1758    ZEND_VM_INC_OPCODE();
1759    ZEND_VM_NEXT_OPCODE();
1760}
1761
1762ZEND_VM_HANDLER(38, ZEND_ASSIGN, VAR|CV, CONST|TMP|VAR|CV)
1763{
1764    USE_OPLINE
1765    zend_free_op free_op1, free_op2;
1766    zval *value;
1767    zval *variable_ptr;
1768
1769    SAVE_OPLINE();
1770    value = GET_OP2_ZVAL_PTR_DEREF(BP_VAR_R);
1771    variable_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1772
1773    if (OP1_TYPE == IS_VAR && UNEXPECTED(variable_ptr == &EG(error_zval))) {
1774        if (OP2_TYPE == IS_TMP_VAR) {
1775            FREE_OP2();
1776        }
1777        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1778            ZVAL_NULL(EX_VAR(opline->result.var));
1779        }
1780    } else {
1781        value = zend_assign_to_variable(variable_ptr, value, OP2_TYPE);
1782        if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1783            ZVAL_COPY(EX_VAR(opline->result.var), value);
1784        }
1785        FREE_OP1_VAR_PTR();
1786    }
1787
1788    /* zend_assign_to_variable() always takes care of op2, never free it! */
1789    FREE_OP2_IF_VAR();
1790
1791    CHECK_EXCEPTION();
1792    ZEND_VM_NEXT_OPCODE();
1793}
1794
1795ZEND_VM_HANDLER(39, ZEND_ASSIGN_REF, VAR|CV, VAR|CV)
1796{
1797    USE_OPLINE
1798    zend_free_op free_op1, free_op2;
1799    zval *variable_ptr;
1800    zval *value_ptr;
1801
1802    SAVE_OPLINE();
1803    value_ptr = GET_OP2_ZVAL_PTR_PTR(BP_VAR_W);
1804
1805    if (OP2_TYPE == IS_VAR && UNEXPECTED(value_ptr == NULL)) {
1806        zend_error_noreturn(E_ERROR, "Cannot create references to/from string offsets nor overloaded objects");
1807    }
1808    if (OP2_TYPE == IS_VAR &&
1809        (value_ptr == &EG(uninitialized_zval) ||
1810         (opline->extended_value == ZEND_RETURNS_FUNCTION &&
1811          !(Z_VAR_FLAGS_P(value_ptr) & IS_VAR_RET_REF)))) {
1812        if (!OP2_FREE) {
1813            PZVAL_LOCK(value_ptr); /* undo the effect of get_zval_ptr_ptr() */
1814        }
1815        zend_error(E_STRICT, "Only variables should be assigned by reference");
1816        if (UNEXPECTED(EG(exception) != NULL)) {
1817            FREE_OP2_VAR_PTR();
1818            HANDLE_EXCEPTION();
1819        }
1820        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_ASSIGN);
1821    }
1822
1823    variable_ptr = GET_OP1_ZVAL_PTR_PTR_UNDEF(BP_VAR_W);
1824    if (OP1_TYPE == IS_VAR && UNEXPECTED(variable_ptr == NULL)) {
1825        zend_error_noreturn(E_ERROR, "Cannot create references to/from string offsets nor overloaded objects");
1826    }
1827    if (OP1_TYPE == IS_VAR &&
1828        UNEXPECTED(Z_TYPE_P(EX_VAR(opline->op1.var)) != IS_INDIRECT) &&
1829        UNEXPECTED(!Z_ISREF_P(variable_ptr))) {
1830        zend_error_noreturn(E_ERROR, "Cannot assign by reference to overloaded object");
1831    }
1832    if ((OP1_TYPE == IS_VAR && UNEXPECTED(variable_ptr == &EG(error_zval))) ||
1833        (OP2_TYPE == IS_VAR && UNEXPECTED(value_ptr == &EG(error_zval)))) {
1834        variable_ptr = &EG(uninitialized_zval);
1835    } else {
1836        zend_assign_to_variable_reference(variable_ptr, value_ptr);
1837    }
1838
1839    if (UNEXPECTED(RETURN_VALUE_USED(opline))) {
1840        ZVAL_COPY(EX_VAR(opline->result.var), variable_ptr);
1841    }
1842
1843    FREE_OP1_VAR_PTR();
1844    FREE_OP2_VAR_PTR();
1845
1846    CHECK_EXCEPTION();
1847    ZEND_VM_NEXT_OPCODE();
1848}
1849
1850ZEND_VM_HELPER(zend_leave_helper, ANY, ANY)
1851{
1852    zend_call_kind call_kind = EX_CALL_KIND();
1853
1854    if (call_kind == ZEND_CALL_NESTED_FUNCTION) {
1855        zend_object *object;
1856
1857        i_free_compiled_variables(execute_data);
1858        if (UNEXPECTED(EX(symbol_table) != NULL)) {
1859            zend_clean_and_cache_symbol_table(EX(symbol_table));
1860        }
1861        zend_vm_stack_free_extra_args(execute_data);
1862        EG(current_execute_data) = EX(prev_execute_data);
1863        if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_CLOSURE) != 0) && EX(func)->op_array.prototype) {
1864            OBJ_RELEASE((zend_object*)EX(func)->op_array.prototype);
1865        }
1866        object = Z_OBJ(EX(This));
1867        zend_vm_stack_free_call_frame(execute_data);
1868
1869        execute_data = EG(current_execute_data);
1870
1871        if (object) {
1872            if (UNEXPECTED(EG(exception) != NULL) && (EX(opline)->op1.num & ZEND_CALL_CTOR)) {
1873                if (!(EX(opline)->op1.num & ZEND_CALL_CTOR_RESULT_UNUSED)) {
1874                    GC_REFCOUNT(object)--;
1875                }
1876                if (GC_REFCOUNT(object) == 1) {
1877                    zend_object_store_ctor_failed(object);
1878                }
1879            }
1880            OBJ_RELEASE(object);
1881        }
1882        EG(scope) = EX(func)->op_array.scope;
1883
1884        if (UNEXPECTED(EG(exception) != NULL)) {
1885            const zend_op *opline = EX(opline);
1886            zend_throw_exception_internal(NULL);
1887            if (RETURN_VALUE_USED(opline)) {
1888                zval_ptr_dtor(EX_VAR(opline->result.var));
1889            }
1890            HANDLE_EXCEPTION_LEAVE();
1891        }
1892
1893        LOAD_OPLINE();
1894        ZEND_VM_INC_OPCODE();
1895        ZEND_VM_LEAVE();
1896    } else if (call_kind == ZEND_CALL_NESTED_CODE) {
1897        zend_detach_symbol_table(execute_data);
1898        destroy_op_array(&EX(func)->op_array);
1899        efree_size(EX(func), sizeof(zend_op_array));
1900        EG(current_execute_data) = EX(prev_execute_data);
1901        zend_vm_stack_free_call_frame(execute_data);
1902
1903        execute_data = EG(current_execute_data);
1904        zend_attach_symbol_table(execute_data);
1905        if (UNEXPECTED(EG(exception) != NULL)) {
1906            zend_throw_exception_internal(NULL);
1907            HANDLE_EXCEPTION_LEAVE();
1908        }
1909
1910        LOAD_OPLINE();
1911        ZEND_VM_INC_OPCODE();
1912        ZEND_VM_LEAVE();
1913    } else {
1914        if (call_kind == ZEND_CALL_TOP_FUNCTION) {
1915            i_free_compiled_variables(execute_data);
1916            if (UNEXPECTED(EX(symbol_table) != NULL)) {
1917                zend_clean_and_cache_symbol_table(EX(symbol_table));
1918            }
1919            zend_vm_stack_free_extra_args(execute_data);
1920            EG(current_execute_data) = EX(prev_execute_data);
1921            if ((EX(func)->op_array.fn_flags & ZEND_ACC_CLOSURE) && EX(func)->op_array.prototype) {
1922                OBJ_RELEASE((zend_object*)EX(func)->op_array.prototype);
1923            }
1924        } else /* if (call_kind == ZEND_CALL_TOP_CODE) */ {
1925            zend_array *symbol_table = EX(symbol_table);
1926            zend_execute_data *old_execute_data;
1927
1928            zend_detach_symbol_table(execute_data);
1929            old_execute_data = EX(prev_execute_data);
1930            while (old_execute_data) {
1931                if (old_execute_data->func && ZEND_USER_CODE(old_execute_data->func->op_array.type)) {
1932                    if (old_execute_data->symbol_table == symbol_table) {
1933                        zend_attach_symbol_table(old_execute_data);
1934                    }
1935                    break;
1936                }
1937                old_execute_data = old_execute_data->prev_execute_data;
1938            }
1939            EG(current_execute_data) = EX(prev_execute_data);
1940        }
1941        zend_vm_stack_free_call_frame(execute_data);
1942
1943        ZEND_VM_RETURN();
1944    }
1945}
1946
1947ZEND_VM_HANDLER(42, ZEND_JMP, ANY, ANY)
1948{
1949    USE_OPLINE
1950
1951    ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op1));
1952    ZEND_VM_CONTINUE();
1953}
1954
1955ZEND_VM_HANDLER(43, ZEND_JMPZ, CONST|TMPVAR|CV, ANY)
1956{
1957    USE_OPLINE
1958    zend_free_op free_op1;
1959    zval *val;
1960
1961    SAVE_OPLINE();
1962    val = GET_OP1_ZVAL_PTR(BP_VAR_R);
1963
1964    if (Z_TYPE_P(val) == IS_TRUE) {
1965        ZEND_VM_SET_OPCODE(opline + 1);
1966        ZEND_VM_CONTINUE();
1967    } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
1968        if (OP1_TYPE == IS_CV) {
1969            ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
1970        } else {
1971            ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
1972            ZEND_VM_CONTINUE();
1973        }
1974    }
1975
1976    if (i_zend_is_true(val)) {
1977        opline++;
1978    } else {
1979        opline = OP_JMP_ADDR(opline, opline->op2);
1980    }
1981    FREE_OP1();
1982    if (UNEXPECTED(EG(exception) != NULL)) {
1983        HANDLE_EXCEPTION();
1984    }
1985    ZEND_VM_JMP(opline);
1986}
1987
1988ZEND_VM_HANDLER(44, ZEND_JMPNZ, CONST|TMPVAR|CV, ANY)
1989{
1990    USE_OPLINE
1991    zend_free_op free_op1;
1992    zval *val;
1993
1994    SAVE_OPLINE();
1995    val = GET_OP1_ZVAL_PTR(BP_VAR_R);
1996
1997    if (Z_TYPE_P(val) == IS_TRUE) {
1998        ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
1999        ZEND_VM_CONTINUE();
2000    } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
2001        if (OP1_TYPE == IS_CV) {
2002            ZEND_VM_NEXT_OPCODE();
2003        } else {
2004            ZEND_VM_SET_OPCODE(opline + 1);
2005            ZEND_VM_CONTINUE();
2006        }
2007    }
2008
2009    if (i_zend_is_true(val)) {
2010        opline = OP_JMP_ADDR(opline, opline->op2);
2011    } else {
2012        opline++;
2013    }
2014    FREE_OP1();
2015    if (UNEXPECTED(EG(exception) != NULL)) {
2016        HANDLE_EXCEPTION();
2017    }
2018    ZEND_VM_JMP(opline);
2019}
2020
2021ZEND_VM_HANDLER(45, ZEND_JMPZNZ, CONST|TMPVAR|CV, ANY)
2022{
2023    USE_OPLINE
2024    zend_free_op free_op1;
2025    zval *val;
2026
2027    SAVE_OPLINE();
2028    val = GET_OP1_ZVAL_PTR(BP_VAR_R);
2029
2030    if (EXPECTED(Z_TYPE_P(val) == IS_TRUE)) {
2031        ZEND_VM_SET_RELATIVE_OPCODE(opline, opline->extended_value);
2032        ZEND_VM_CONTINUE();
2033    } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
2034        if (OP1_TYPE == IS_CV) {
2035            ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
2036        } else {
2037            ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2038            ZEND_VM_CONTINUE();
2039        }
2040    }
2041
2042    if (i_zend_is_true(val)) {
2043        opline = ZEND_OFFSET_TO_OPLINE(opline, opline->extended_value);
2044    } else {
2045        opline = OP_JMP_ADDR(opline, opline->op2);
2046    }
2047    FREE_OP1();
2048    if (UNEXPECTED(EG(exception) != NULL)) {
2049        HANDLE_EXCEPTION();
2050    }
2051    ZEND_VM_JMP(opline);
2052}
2053
2054ZEND_VM_HANDLER(46, ZEND_JMPZ_EX, CONST|TMPVAR|CV, ANY)
2055{
2056    USE_OPLINE
2057    zend_free_op free_op1;
2058    zval *val;
2059    int ret;
2060
2061    SAVE_OPLINE();
2062    val = GET_OP1_ZVAL_PTR(BP_VAR_R);
2063
2064    if (Z_TYPE_P(val) == IS_TRUE) {
2065        ZVAL_TRUE(EX_VAR(opline->result.var));
2066        ZEND_VM_SET_OPCODE(opline + 1);
2067        ZEND_VM_CONTINUE();
2068    } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
2069        ZVAL_FALSE(EX_VAR(opline->result.var));
2070        if (OP1_TYPE == IS_CV) {
2071            ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
2072        } else {
2073            ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2074            ZEND_VM_CONTINUE();
2075        }
2076    }
2077
2078    ret = i_zend_is_true(val);
2079    FREE_OP1();
2080    if (ret) {
2081        ZVAL_TRUE(EX_VAR(opline->result.var));
2082        opline++;
2083    } else {
2084        ZVAL_FALSE(EX_VAR(opline->result.var));
2085        opline = OP_JMP_ADDR(opline, opline->op2);
2086    }
2087    if (UNEXPECTED(EG(exception) != NULL)) {
2088        HANDLE_EXCEPTION();
2089    }
2090    ZEND_VM_JMP(opline);
2091}
2092
2093ZEND_VM_HANDLER(47, ZEND_JMPNZ_EX, CONST|TMPVAR|CV, ANY)
2094{
2095    USE_OPLINE
2096    zend_free_op free_op1;
2097    zval *val;
2098    int ret;
2099
2100    SAVE_OPLINE();
2101    val = GET_OP1_ZVAL_PTR(BP_VAR_R);
2102
2103    if (Z_TYPE_P(val) == IS_TRUE) {
2104        ZVAL_TRUE(EX_VAR(opline->result.var));
2105        ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline, opline->op2));
2106        ZEND_VM_CONTINUE();
2107    } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
2108        ZVAL_FALSE(EX_VAR(opline->result.var));
2109        if (OP1_TYPE == IS_CV) {
2110            ZEND_VM_NEXT_OPCODE();
2111        } else {
2112            ZEND_VM_SET_OPCODE(opline + 1);
2113            ZEND_VM_CONTINUE();
2114        }
2115    }
2116    ret = i_zend_is_true(val);
2117    FREE_OP1();
2118    if (ret) {
2119        ZVAL_TRUE(EX_VAR(opline->result.var));
2120        opline = OP_JMP_ADDR(opline, opline->op2);
2121    } else {
2122        ZVAL_FALSE(EX_VAR(opline->result.var));
2123        opline++;
2124    }
2125    if (UNEXPECTED(EG(exception) != NULL)) {
2126        HANDLE_EXCEPTION();
2127    }
2128    ZEND_VM_JMP(opline);
2129}
2130
2131ZEND_VM_HANDLER(70, ZEND_FREE, TMPVAR, ANY)
2132{
2133    USE_OPLINE
2134
2135    SAVE_OPLINE();
2136    zval_ptr_dtor_nogc(EX_VAR(opline->op1.var));
2137    CHECK_EXCEPTION();
2138    ZEND_VM_NEXT_OPCODE();
2139}
2140
2141ZEND_VM_HANDLER(54, ZEND_ADD_CHAR, TMP|UNUSED, CONST)
2142{
2143    USE_OPLINE
2144    zval *str = EX_VAR(opline->result.var);
2145
2146    SAVE_OPLINE();
2147
2148    if (OP1_TYPE == IS_UNUSED) {
2149        /* Initialize for erealloc in add_char_to_string */
2150        ZVAL_EMPTY_STRING(str);
2151    }
2152
2153    add_char_to_string(str, str, EX_CONSTANT(opline->op2));
2154
2155    /* FREE_OP is missing intentionally here - we're always working on the same temporary variable */
2156    /*CHECK_EXCEPTION();*/
2157    ZEND_VM_NEXT_OPCODE();
2158}
2159
2160ZEND_VM_HANDLER(55, ZEND_ADD_STRING, TMP|UNUSED, CONST)
2161{
2162    USE_OPLINE
2163    zval *str = EX_VAR(opline->result.var);
2164
2165    SAVE_OPLINE();
2166
2167    if (OP1_TYPE == IS_UNUSED) {
2168        /* Initialize for erealloc in add_string_to_string */
2169        ZVAL_EMPTY_STRING(str);
2170    }
2171
2172    add_string_to_string(str, str, EX_CONSTANT(opline->op2));
2173
2174    /* FREE_OP is missing intentionally here - we're always working on the same temporary variable */
2175    /*CHECK_EXCEPTION();*/
2176    ZEND_VM_NEXT_OPCODE();
2177}
2178
2179ZEND_VM_HANDLER(56, ZEND_ADD_VAR, TMP|UNUSED, TMPVAR|CV)
2180{
2181    USE_OPLINE
2182    zend_free_op free_op2;
2183    zval *str = EX_VAR(opline->result.var);
2184    zval *var;
2185    zval var_copy;
2186    int use_copy = 0;
2187
2188    SAVE_OPLINE();
2189    var = GET_OP2_ZVAL_PTR(BP_VAR_R);
2190
2191    if (OP1_TYPE == IS_UNUSED) {
2192        /* Initialize for erealloc in add_string_to_string */
2193        ZVAL_EMPTY_STRING(str);
2194    }
2195
2196    if (Z_TYPE_P(var) != IS_STRING) {
2197        use_copy = zend_make_printable_zval(var, &var_copy);
2198
2199        if (use_copy) {
2200            var = &var_copy;
2201        }
2202    }
2203    add_string_to_string(str, str, var);
2204
2205    if (use_copy) {
2206        zend_string_release(Z_STR_P(var));
2207    }
2208    /* original comment, possibly problematic:
2209     * FREE_OP is missing intentionally here - we're always working on the same temporary variable
2210     * (Zeev):  I don't think it's problematic, we only use variables
2211     * which aren't affected by FREE_OP(Ts, )'s anyway, unless they're
2212     * string offsets or overloaded objects
2213     */
2214    FREE_OP2();
2215
2216    CHECK_EXCEPTION();
2217    ZEND_VM_NEXT_OPCODE();
2218}
2219
2220ZEND_VM_HANDLER(109, ZEND_FETCH_CLASS, ANY, CONST|TMPVAR|UNUSED|CV)
2221{
2222    USE_OPLINE
2223
2224    SAVE_OPLINE();
2225    if (EG(exception)) {
2226        zend_exception_save();
2227    }
2228    if (OP2_TYPE == IS_UNUSED) {
2229        Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class(NULL, opline->extended_value);
2230        CHECK_EXCEPTION();
2231        ZEND_VM_NEXT_OPCODE();
2232    } else {
2233        zend_free_op free_op2;
2234        zval *class_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2235
2236ZEND_VM_C_LABEL(try_class_name):
2237        if (OP2_TYPE == IS_CONST) {
2238            if (CACHED_PTR(Z_CACHE_SLOT_P(class_name))) {
2239                Z_CE_P(EX_VAR(opline->result.var)) = CACHED_PTR(Z_CACHE_SLOT_P(class_name));
2240            } else {
2241                Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class_by_name(Z_STR_P(class_name), EX_CONSTANT(opline->op2) + 1, opline->extended_value);
2242                CACHE_PTR(Z_CACHE_SLOT_P(class_name), Z_CE_P(EX_VAR(opline->result.var)));
2243            }
2244        } else if (Z_TYPE_P(class_name) == IS_OBJECT) {
2245            Z_CE_P(EX_VAR(opline->result.var)) = Z_OBJCE_P(class_name);
2246        } else if (Z_TYPE_P(class_name) == IS_STRING) {
2247            Z_CE_P(EX_VAR(opline->result.var)) = zend_fetch_class(Z_STR_P(class_name), opline->extended_value);
2248        } else if ((OP2_TYPE & (IS_VAR|IS_CV)) && Z_TYPE_P(class_name) == IS_REFERENCE) {
2249            class_name = Z_REFVAL_P(class_name);
2250            ZEND_VM_C_GOTO(try_class_name);
2251        } else {
2252            if (UNEXPECTED(EG(exception) != NULL)) {
2253                HANDLE_EXCEPTION();
2254            }
2255            zend_error_noreturn(E_ERROR, "Class name must be a valid object or a string");
2256        }
2257
2258        FREE_OP2();
2259        CHECK_EXCEPTION();
2260        ZEND_VM_NEXT_OPCODE();
2261    }
2262}
2263
2264ZEND_VM_HANDLER(112, ZEND_INIT_METHOD_CALL, TMPVAR|UNUSED|CV, CONST|TMPVAR|CV)
2265{
2266    USE_OPLINE
2267    zval *function_name;
2268    zend_free_op free_op1, free_op2;
2269    zval *object;
2270    zend_function *fbc;
2271    zend_class_entry *called_scope;
2272    zend_object *obj;
2273
2274    SAVE_OPLINE();
2275
2276    function_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2277
2278    if (OP2_TYPE != IS_CONST &&
2279        UNEXPECTED(Z_TYPE_P(function_name) != IS_STRING)) {
2280        if (UNEXPECTED(EG(exception) != NULL)) {
2281            HANDLE_EXCEPTION();
2282        }
2283        zend_error_noreturn(E_ERROR, "Method name must be a string");
2284    }
2285
2286    object = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_R);
2287
2288    do {
2289        if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
2290            uint32_t nesting = 1;
2291
2292            if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(object)) {
2293                object = Z_REFVAL_P(object);
2294                if (EXPECTED(Z_TYPE_P(object) == IS_OBJECT)) {
2295                    break;
2296                }
2297            }
2298
2299            if (UNEXPECTED(EG(exception) != NULL)) {
2300                FREE_OP2();
2301                HANDLE_EXCEPTION();
2302            }
2303
2304            zend_error(E_RECOVERABLE_ERROR, "Call to a member function %s() on %s",  Z_STRVAL_P(function_name), zend_get_type_by_const(Z_TYPE_P(object)));
2305            FREE_OP2();
2306            FREE_OP1();
2307
2308            if (EG(exception) != NULL) {
2309                HANDLE_EXCEPTION();
2310            }
2311
2312            /* No exception raised: Skip over arguments until fcall opcode with correct
2313             * nesting level. Return NULL (except when return value unused) */
2314            do {
2315                opline++;
2316                if (opline->opcode == ZEND_INIT_FCALL ||
2317                    opline->opcode == ZEND_INIT_FCALL_BY_NAME ||
2318                    opline->opcode == ZEND_INIT_NS_FCALL_BY_NAME ||
2319                    opline->opcode == ZEND_INIT_METHOD_CALL ||
2320                    opline->opcode == ZEND_INIT_STATIC_METHOD_CALL ||
2321                    opline->opcode == ZEND_INIT_USER_CALL ||
2322                    opline->opcode == ZEND_NEW
2323                ) {
2324                    nesting++;
2325                } else if (opline->opcode == ZEND_DO_FCALL) {
2326                    nesting--;
2327                }
2328            } while (nesting);
2329
2330            if (RETURN_VALUE_USED(opline)) {
2331                ZVAL_NULL(EX_VAR(opline->result.var));
2332            }
2333
2334            /* We've skipped EXT_FCALL_BEGIND, so also skip the ending opcode */
2335            if ((opline + 1)->opcode == ZEND_EXT_FCALL_END) {
2336                opline++;
2337            }
2338            ZEND_VM_JMP(++opline);
2339        }
2340    } while (0);
2341
2342    obj = Z_OBJ_P(object);
2343    called_scope = obj->ce;
2344
2345    if (OP2_TYPE != IS_CONST ||
2346        UNEXPECTED((fbc = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), called_scope)) == NULL)) {
2347        zend_object *orig_obj = obj;
2348
2349        if (UNEXPECTED(obj->handlers->get_method == NULL)) {
2350            zend_error_noreturn(E_ERROR, "Object does not support method calls");
2351        }
2352
2353        /* First, locate the function. */
2354        fbc = obj->handlers->get_method(&obj, Z_STR_P(function_name), ((OP2_TYPE == IS_CONST) ? (EX_CONSTANT(opline->op2) + 1) : NULL));
2355        if (UNEXPECTED(fbc == NULL)) {
2356            zend_error_noreturn(E_ERROR, "Call to undefined method %s::%s()", obj->ce->name->val, Z_STRVAL_P(function_name));
2357        }
2358        if (OP2_TYPE == IS_CONST &&
2359            EXPECTED(fbc->type <= ZEND_USER_FUNCTION) &&
2360            EXPECTED((fbc->common.fn_flags & (ZEND_ACC_CALL_VIA_HANDLER|ZEND_ACC_NEVER_CACHE)) == 0) &&
2361            EXPECTED(obj == orig_obj)) {
2362            CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), called_scope, fbc);
2363        }
2364    }
2365
2366    if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_STATIC) != 0)) {
2367        obj = NULL;
2368    } else {
2369        GC_REFCOUNT(obj)++; /* For $this pointer */
2370    }
2371
2372    EX(call) = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
2373        fbc, opline->extended_value, called_scope, obj, EX(call));
2374
2375    FREE_OP2();
2376    FREE_OP1();
2377
2378    CHECK_EXCEPTION();
2379    ZEND_VM_NEXT_OPCODE();
2380}
2381
2382ZEND_VM_HANDLER(113, ZEND_INIT_STATIC_METHOD_CALL, CONST|VAR, CONST|TMPVAR|UNUSED|CV)
2383{
2384    USE_OPLINE
2385    zval *function_name;
2386    zend_class_entry *ce;
2387    zend_object *object;
2388    zend_function *fbc;
2389
2390    SAVE_OPLINE();
2391
2392    if (OP1_TYPE == IS_CONST) {
2393        /* no function found. try a static method in class */
2394        if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)))) {
2395            ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
2396        } else {
2397            ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, ZEND_FETCH_CLASS_DEFAULT);
2398            if (UNEXPECTED(EG(exception) != NULL)) {
2399                HANDLE_EXCEPTION();
2400            }
2401            if (UNEXPECTED(ce == NULL)) {
2402                zend_error_noreturn(E_ERROR, "Class '%s' not found", Z_STRVAL_P(EX_CONSTANT(opline->op1)));
2403            }
2404            CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce);
2405        }
2406    } else {
2407        ce = Z_CE_P(EX_VAR(opline->op1.var));
2408    }
2409
2410    if (OP1_TYPE == IS_CONST &&
2411        OP2_TYPE == IS_CONST &&
2412        CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) {
2413        fbc = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
2414    } else if (OP1_TYPE != IS_CONST &&
2415               OP2_TYPE == IS_CONST &&
2416               (fbc = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce))) {
2417        /* do nothing */
2418    } else if (OP2_TYPE != IS_UNUSED) {
2419        zend_free_op free_op2;
2420
2421        function_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2422        if (OP2_TYPE != IS_CONST) {
2423            if (UNEXPECTED(Z_TYPE_P(function_name) != IS_STRING)) {
2424                if (UNEXPECTED(EG(exception) != NULL)) {
2425                    HANDLE_EXCEPTION();
2426                }
2427                zend_error_noreturn(E_ERROR, "Function name must be a string");
2428            }
2429        }
2430
2431        if (ce->get_static_method) {
2432            fbc = ce->get_static_method(ce, Z_STR_P(function_name));
2433        } else {
2434            fbc = zend_std_get_static_method(ce, Z_STR_P(function_name), ((OP2_TYPE == IS_CONST) ? (EX_CONSTANT(opline->op2) + 1) : NULL));
2435        }
2436        if (UNEXPECTED(fbc == NULL)) {
2437            zend_error_noreturn(E_ERROR, "Call to undefined method %s::%s()", ce->name->val, Z_STRVAL_P(function_name));
2438        }
2439        if (OP2_TYPE == IS_CONST &&
2440            EXPECTED(fbc->type <= ZEND_USER_FUNCTION) &&
2441            EXPECTED((fbc->common.fn_flags & (ZEND_ACC_CALL_VIA_HANDLER|ZEND_ACC_NEVER_CACHE)) == 0)) {
2442            if (OP1_TYPE == IS_CONST) {
2443                CACHE_PTR(Z_CACHE_SLOT_P(function_name), fbc);
2444            } else {
2445                CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(function_name), ce, fbc);
2446            }
2447        }
2448        if (OP2_TYPE != IS_CONST) {
2449            FREE_OP2();
2450        }
2451    } else {
2452        if (UNEXPECTED(ce->constructor == NULL)) {
2453            zend_error_noreturn(E_ERROR, "Cannot call constructor");
2454        }
2455        if (Z_OBJ(EX(This)) && Z_OBJ(EX(This))->ce != ce->constructor->common.scope && (ce->constructor->common.fn_flags & ZEND_ACC_PRIVATE)) {
2456            zend_error_noreturn(E_ERROR, "Cannot call private %s::__construct()", ce->name->val);
2457        }
2458        fbc = ce->constructor;
2459    }
2460
2461    object = NULL;
2462    if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
2463        if (Z_OBJ(EX(This))) {
2464            object = Z_OBJ(EX(This));
2465            GC_REFCOUNT(object)++;
2466        }
2467        if (!object ||
2468            !instanceof_function(object->ce, ce)) {
2469            /* We are calling method of the other (incompatible) class,
2470               but passing $this. This is done for compatibility with php-4. */
2471            if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
2472                zend_error(
2473                    object ? E_DEPRECATED : E_STRICT,
2474                    "Non-static method %s::%s() should not be called statically%s",
2475                    fbc->common.scope->name->val, fbc->common.function_name->val,
2476                    object ? ", assuming $this from incompatible context" : "");
2477            } else {
2478                /* An internal function assumes $this is present and won't check that. So PHP would crash by allowing the call. */
2479                zend_error_noreturn(
2480                    E_ERROR,
2481                    "Non-static method %s::%s() cannot be called statically%s",
2482                    fbc->common.scope->name->val, fbc->common.function_name->val,
2483                    object ? ", assuming $this from incompatible context" : "");
2484            }
2485        }
2486    }
2487
2488    if (OP1_TYPE != IS_CONST) {
2489        /* previous opcode is ZEND_FETCH_CLASS */
2490        if ((opline-1)->extended_value == ZEND_FETCH_CLASS_PARENT || (opline-1)->extended_value == ZEND_FETCH_CLASS_SELF) {
2491            ce = EX(called_scope);
2492        }
2493    }
2494
2495    EX(call) = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
2496        fbc, opline->extended_value, ce, object, EX(call));
2497
2498    if (OP2_TYPE == IS_UNUSED) {
2499        EX(call)->return_value = NULL;
2500    }
2501
2502    CHECK_EXCEPTION();
2503    ZEND_VM_NEXT_OPCODE();
2504}
2505
2506ZEND_VM_HANDLER(59, ZEND_INIT_FCALL_BY_NAME, ANY, CONST|TMPVAR|CV)
2507{
2508    USE_OPLINE
2509    zend_function *fbc;
2510    zval *function_name, *func;
2511
2512    if (OP2_TYPE == IS_CONST && Z_TYPE_P(EX_CONSTANT(opline->op2)) == IS_STRING) {
2513        function_name = (zval*)(EX_CONSTANT(opline->op2)+1);
2514        if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) {
2515            fbc = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
2516        } else if (UNEXPECTED((func = zend_hash_find(EG(function_table), Z_STR_P(function_name))) == NULL)) {
2517            SAVE_OPLINE();
2518            zend_error_noreturn(E_ERROR, "Call to undefined function %s()", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
2519        } else {
2520            fbc = Z_FUNC_P(func);
2521            CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), fbc);
2522        }
2523
2524        EX(call) = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
2525            fbc, opline->extended_value, NULL, NULL, EX(call));
2526
2527        /*CHECK_EXCEPTION();*/
2528        ZEND_VM_NEXT_OPCODE();
2529    } else {
2530        zend_string *lcname;
2531        zend_free_op free_op2;
2532        zend_class_entry *called_scope;
2533        zend_object *object;
2534
2535        SAVE_OPLINE();
2536        function_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2537
2538ZEND_VM_C_LABEL(try_function_name):
2539        if (OP2_TYPE != IS_CONST && EXPECTED(Z_TYPE_P(function_name) == IS_STRING)) {
2540            if (Z_STRVAL_P(function_name)[0] == '\\') {
2541                lcname = zend_string_alloc(Z_STRLEN_P(function_name) - 1, 0);
2542                zend_str_tolower_copy(lcname->val, Z_STRVAL_P(function_name) + 1, Z_STRLEN_P(function_name) - 1);
2543            } else {
2544                lcname = zend_string_tolower(Z_STR_P(function_name));
2545            }
2546            if (UNEXPECTED((func = zend_hash_find(EG(function_table), lcname)) == NULL)) {
2547                zend_error_noreturn(E_ERROR, "Call to undefined function %s()", Z_STRVAL_P(function_name));
2548            }
2549            zend_string_release(lcname);
2550            FREE_OP2();
2551
2552            fbc = Z_FUNC_P(func);
2553            called_scope = NULL;
2554            object = NULL;
2555        } else if (OP2_TYPE != IS_CONST &&
2556            EXPECTED(Z_TYPE_P(function_name) == IS_OBJECT) &&
2557            Z_OBJ_HANDLER_P(function_name, get_closure) &&
2558            Z_OBJ_HANDLER_P(function_name, get_closure)(function_name, &called_scope, &fbc, &object) == SUCCESS) {
2559            if (object) {
2560                GC_REFCOUNT(object)++;
2561            }
2562            if (OP2_TYPE == IS_VAR && (fbc->common.fn_flags & ZEND_ACC_CLOSURE)) {
2563                /* Delay closure destruction until its invocation */
2564                fbc->common.prototype = (zend_function*)Z_OBJ_P(free_op2);
2565            } else if (OP2_TYPE == IS_CV) {
2566                FREE_OP2();
2567            }
2568        } else if (EXPECTED(Z_TYPE_P(function_name) == IS_ARRAY) &&
2569                zend_hash_num_elements(Z_ARRVAL_P(function_name)) == 2) {
2570            zval *obj;
2571            zval *method;
2572
2573            obj = zend_hash_index_find(Z_ARRVAL_P(function_name), 0);
2574            method = zend_hash_index_find(Z_ARRVAL_P(function_name), 1);
2575
2576            if (!obj || !method) {
2577                zend_error_noreturn(E_ERROR, "Array callback has to contain indices 0 and 1");
2578            }
2579
2580            ZVAL_DEREF(obj);
2581            if (Z_TYPE_P(obj) != IS_STRING && Z_TYPE_P(obj) != IS_OBJECT) {
2582                zend_error_noreturn(E_ERROR, "First array member is not a valid class name or object");
2583            }
2584
2585            ZVAL_DEREF(method);
2586            if (Z_TYPE_P(method) != IS_STRING) {
2587                zend_error_noreturn(E_ERROR, "Second array member is not a valid method");
2588            }
2589
2590            if (Z_TYPE_P(obj) == IS_STRING) {
2591                object = NULL;
2592                called_scope = zend_fetch_class_by_name(Z_STR_P(obj), NULL, 0);
2593                if (UNEXPECTED(called_scope == NULL)) {
2594                    CHECK_EXCEPTION();
2595                    ZEND_VM_NEXT_OPCODE();
2596                }
2597
2598                if (called_scope->get_static_method) {
2599                    fbc = called_scope->get_static_method(called_scope, Z_STR_P(method));
2600                } else {
2601                    fbc = zend_std_get_static_method(called_scope, Z_STR_P(method), NULL);
2602                }
2603                if (UNEXPECTED(fbc == NULL)) {
2604                    zend_error_noreturn(E_ERROR, "Call to undefined method %s::%s()", called_scope->name->val, Z_STRVAL_P(method));
2605                }
2606                if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
2607                    if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
2608                        zend_error(E_STRICT,
2609                        "Non-static method %s::%s() should not be called statically",
2610                        fbc->common.scope->name->val, fbc->common.function_name->val);
2611                    } else {
2612                        zend_error_noreturn(
2613                            E_ERROR,
2614                            "Non-static method %s::%s() cannot be called statically",
2615                            fbc->common.scope->name->val, fbc->common.function_name->val);
2616                    }
2617                }
2618            } else {
2619                called_scope = Z_OBJCE_P(obj);
2620                object = Z_OBJ_P(obj);
2621
2622                fbc = Z_OBJ_HT_P(obj)->get_method(&object, Z_STR_P(method), NULL);
2623                if (UNEXPECTED(fbc == NULL)) {
2624                    zend_error_noreturn(E_ERROR, "Call to undefined method %s::%s()", object->ce->name->val, Z_STRVAL_P(method));
2625                }
2626
2627                if ((fbc->common.fn_flags & ZEND_ACC_STATIC) != 0) {
2628                    object = NULL;
2629                } else {
2630                    GC_REFCOUNT(object)++; /* For $this pointer */
2631                }
2632            }
2633            FREE_OP2();
2634        } else if ((OP2_TYPE & (IS_VAR|IS_CV)) && Z_TYPE_P(function_name) == IS_REFERENCE) {
2635            function_name = Z_REFVAL_P(function_name);
2636            ZEND_VM_C_GOTO(try_function_name);
2637        } else {
2638            if (UNEXPECTED(EG(exception) != NULL)) {
2639                HANDLE_EXCEPTION();
2640            }
2641            zend_error_noreturn(E_ERROR, "Function name must be a string");
2642            ZEND_VM_CONTINUE(); /* Never reached */
2643        }
2644        EX(call) = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
2645            fbc, opline->extended_value, called_scope, object, EX(call));
2646
2647        CHECK_EXCEPTION();
2648        ZEND_VM_NEXT_OPCODE();
2649    }
2650}
2651
2652ZEND_VM_HANDLER(118, ZEND_INIT_USER_CALL, CONST, CONST|TMPVAR|CV)
2653{
2654    USE_OPLINE
2655    zend_free_op free_op2;
2656    zval *function_name = GET_OP2_ZVAL_PTR(BP_VAR_R);
2657    zend_fcall_info_cache fcc;
2658    char *error = NULL;
2659    zend_function *func;
2660    zend_class_entry *called_scope;
2661    zend_object *object;
2662
2663    if (zend_is_callable_ex(function_name, NULL, 0, NULL, &fcc, &error)) {
2664        if (error) {
2665            efree(error);
2666        }
2667        func = fcc.function_handler;
2668        if (func->common.fn_flags & ZEND_ACC_CLOSURE) {
2669            /* Delay closure destruction until its invocation */
2670            func->common.prototype = (zend_function*)Z_OBJ_P(function_name);
2671            Z_ADDREF_P(function_name);
2672        }
2673        called_scope = fcc.called_scope;
2674        object = fcc.object;
2675        if (object) {
2676            GC_REFCOUNT(object)++; /* For $this pointer */
2677        } else if (func->common.scope &&
2678                   !(func->common.fn_flags & ZEND_ACC_STATIC)) {
2679            if (func->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
2680                zend_error(E_STRICT,
2681                "Non-static method %s::%s() should not be called statically",
2682                func->common.scope->name->val, func->common.function_name->val);
2683            } else {
2684                zend_error_noreturn(
2685                    E_ERROR,
2686                    "Non-static method %s::%s() cannot be called statically",
2687                    func->common.scope->name->val, func->common.function_name->val);
2688            }
2689        }
2690    } else {
2691        zend_error(E_WARNING, "%s() expects parameter 1 to be a valid callback, %s", Z_STRVAL_P(EX_CONSTANT(opline->op1)), error);
2692        efree(error);
2693        func = (zend_function*)&zend_pass_function;
2694        called_scope = NULL;
2695        object = NULL;
2696    }
2697
2698    EX(call) = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
2699        func, opline->extended_value, called_scope, object, EX(call));
2700
2701    FREE_OP2();
2702    CHECK_EXCEPTION();
2703    ZEND_VM_NEXT_OPCODE();
2704}
2705
2706ZEND_VM_HANDLER(69, ZEND_INIT_NS_FCALL_BY_NAME, ANY, CONST)
2707{
2708    USE_OPLINE
2709    zval *func_name;
2710    zval *func;
2711    zend_function *fbc;
2712
2713    func_name = EX_CONSTANT(opline->op2) + 1;
2714    if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) {
2715        fbc = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
2716    } else if ((func = zend_hash_find(EG(function_table), Z_STR_P(func_name))) == NULL) {
2717        func_name++;
2718        if (UNEXPECTED((func = zend_hash_find(EG(function_table), Z_STR_P(func_name))) == NULL)) {
2719            SAVE_OPLINE();
2720            zend_error_noreturn(E_ERROR, "Call to undefined function %s()", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
2721        } else {
2722            fbc = Z_FUNC_P(func);
2723            CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), fbc);
2724        }
2725    } else {
2726        fbc = Z_FUNC_P(func);
2727        CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), fbc);
2728    }
2729
2730    EX(call) = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION,
2731        fbc, opline->extended_value, NULL, NULL, EX(call));
2732
2733    ZEND_VM_NEXT_OPCODE();
2734}
2735
2736ZEND_VM_HANDLER(61, ZEND_INIT_FCALL, ANY, CONST)
2737{
2738    USE_OPLINE
2739    zend_free_op free_op2;
2740    zval *fname = GET_OP2_ZVAL_PTR(BP_VAR_R);
2741    zval *func;
2742    zend_function *fbc;
2743
2744    if (CACHED_PTR(Z_CACHE_SLOT_P(fname))) {
2745        fbc = CACHED_PTR(Z_CACHE_SLOT_P(fname));
2746    } else if (UNEXPECTED((func = zend_hash_find(EG(function_table), Z_STR_P(fname))) == NULL)) {
2747        SAVE_OPLINE();
2748        zend_error_noreturn(E_ERROR, "Call to undefined function %s()", Z_STRVAL_P(fname));
2749    } else {
2750        fbc = Z_FUNC_P(func);
2751        CACHE_PTR(Z_CACHE_SLOT_P(fname), fbc);
2752    }
2753
2754    EX(call) = zend_vm_stack_push_call_frame_ex(
2755        opline->op1.num, ZEND_CALL_NESTED_FUNCTION,
2756        fbc, opline->extended_value, NULL, NULL, EX(call));
2757
2758    FREE_OP2();
2759
2760    ZEND_VM_NEXT_OPCODE();
2761}
2762
2763ZEND_VM_HANDLER(60, ZEND_DO_FCALL, ANY, ANY)
2764{
2765    USE_OPLINE
2766    zend_execute_data *call = EX(call);
2767    zend_function *fbc = call->func;
2768    zend_object *object = Z_OBJ(call->This);
2769    zval *ret;
2770
2771    SAVE_OPLINE();
2772    EX(call) = call->prev_execute_data;
2773    if (UNEXPECTED((fbc->common.fn_flags & (ZEND_ACC_ABSTRACT|ZEND_ACC_DEPRECATED)) != 0)) {
2774        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_ABSTRACT) != 0)) {
2775            zend_error_noreturn(E_ERROR, "Cannot call abstract method %s::%s()", fbc->common.scope->name->val, fbc->common.function_name->val);
2776        }
2777        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_DEPRECATED) != 0)) {
2778            zend_error(E_DEPRECATED, "Function %s%s%s() is deprecated",
2779                fbc->common.scope ? fbc->common.scope->name->val : "",
2780                fbc->common.scope ? "::" : "",
2781                fbc->common.function_name->val);
2782            if (UNEXPECTED(EG(exception) != NULL)) {
2783                HANDLE_EXCEPTION();
2784            }
2785        }
2786    }
2787
2788    LOAD_OPLINE();
2789
2790    if (EXPECTED(fbc->type == ZEND_USER_FUNCTION)) {
2791        EG(scope) = fbc->common.scope;
2792        if (UNEXPECTED((fbc->common.fn_flags & ZEND_ACC_GENERATOR) != 0)) {
2793            if (RETURN_VALUE_USED(opline)) {
2794                zend_generator_create_zval(call, &fbc->op_array, EX_VAR(opline->result.var));
2795            } else {
2796                zend_vm_stack_free_args(call);
2797            }
2798
2799            zend_vm_stack_free_call_frame(call);
2800        } else {
2801            ret = NULL;
2802            call->symbol_table = NULL;
2803            if (RETURN_VALUE_USED(opline)) {
2804                ret = EX_VAR(opline->result.var);
2805                ZVAL_NULL(ret);
2806                Z_VAR_FLAGS_P(ret) = 0;
2807            }
2808
2809            call->prev_execute_data = execute_data;
2810            i_init_func_execute_data(call, &fbc->op_array, ret);
2811
2812            if (EXPECTED(zend_execute_ex == execute_ex)) {
2813                ZEND_VM_ENTER();
2814            } else {
2815                ZEND_ADD_CALL_FLAG(call, ZEND_CALL_TOP);
2816                zend_execute_ex(call);
2817            }
2818        }
2819    } else if (EXPECTED(fbc->type < ZEND_USER_FUNCTION)) {
2820        int should_change_scope = 0;
2821        zval *ret;
2822
2823        if (fbc->common.scope) {
2824            should_change_scope = 1;
2825            /* TODO: we don't set scope if we call an object method ??? */
2826            /* See: ext/pdo_sqlite/tests/pdo_fetch_func_001.phpt */
2827#if 1
2828            EG(scope) = object ? NULL : fbc->common.scope;
2829#else
2830            EG(scope) = fbc->common.scope;
2831#endif
2832        } else {
2833            call->called_scope = EX(called_scope);
2834            Z_OBJ(call->This) = Z_OBJ(EX(This));
2835        }
2836
2837        call->prev_execute_data = execute_data;
2838        EG(current_execute_data) = call;
2839
2840        if (fbc->common.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) {
2841            uint32_t i;
2842            uint32_t num_args = ZEND_CALL_NUM_ARGS(call);
2843            zval *p = ZEND_CALL_ARG(call, 1);
2844
2845            for (i = 0; i < num_args; ++i) {
2846                zend_verify_internal_arg_type(fbc, i + 1, p);
2847                p++;
2848            }
2849            if (UNEXPECTED(EG(exception) != NULL)) {
2850                EG(current_execute_data) = call->prev_execute_data;
2851                zend_vm_stack_free_args(call);
2852                zend_vm_stack_free_call_frame(call);
2853                if (RETURN_VALUE_USED(opline)) {
2854                    ZVAL_UNDEF(EX_VAR(opline->result.var));
2855                }
2856                if (UNEXPECTED(should_change_scope)) {
2857                    ZEND_VM_C_GOTO(fcall_end_change_scope);
2858                } else {
2859                    ZEND_VM_C_GOTO(fcall_end);
2860                }
2861            }
2862        }
2863
2864        ret = EX_VAR(opline->result.var);
2865        ZVAL_NULL(ret);
2866        Z_VAR_FLAGS_P(ret) = (fbc->common.fn_flags & ZEND_ACC_RETURN_REFERENCE) != 0 ? IS_VAR_RET_REF : 0;
2867
2868        if (!zend_execute_internal) {
2869            /* saves one function call if zend_execute_internal is not used */
2870            fbc->internal_function.handler(call, ret);
2871        } else {
2872            zend_execute_internal(call, ret);
2873        }
2874        EG(current_execute_data) = call->prev_execute_data;
2875        zend_vm_stack_free_args(call);
2876        zend_vm_stack_free_call_frame(call);
2877
2878        if (!RETURN_VALUE_USED(opline)) {
2879            zval_ptr_dtor(EX_VAR(opline->result.var));
2880        }
2881
2882        if (UNEXPECTED(should_change_scope)) {
2883            ZEND_VM_C_GOTO(fcall_end_change_scope);
2884        } else {
2885            ZEND_VM_C_GOTO(fcall_end);
2886        }
2887    } else { /* ZEND_OVERLOADED_FUNCTION */
2888        EG(scope) = fbc->common.scope;
2889
2890        ZVAL_NULL(EX_VAR(opline->result.var));
2891
2892        /* Not sure what should be done here if it's a static method */
2893        if (EXPECTED(object != NULL)) {
2894            call->prev_execute_data = execute_data;
2895            EG(current_execute_data) = call;
2896            object->handlers->call_method(fbc->common.function_name, object, call, EX_VAR(opline->result.var));
2897            EG(current_execute_data) = call->prev_execute_data;
2898        } else {
2899            zend_error_noreturn(E_ERROR, "Cannot call overloaded function for non-object");
2900        }
2901
2902        zend_vm_stack_free_args(call);
2903
2904        zend_vm_stack_free_call_frame(call);
2905
2906        if (fbc->type == ZEND_OVERLOADED_FUNCTION_TEMPORARY) {
2907            zend_string_release(fbc->common.function_name);
2908        }
2909        efree(fbc);
2910
2911        if (!RETURN_VALUE_USED(opline)) {
2912            zval_ptr_dtor(EX_VAR(opline->result.var));
2913        } else {
2914//???           Z_UNSET_ISREF_P(EX_T(opline->result.var).var.ptr);
2915//???           Z_SET_REFCOUNT_P(EX_T(opline->result.var).var.ptr, 1);
2916            Z_VAR_FLAGS_P(EX_VAR(opline->result.var)) = 0;
2917        }
2918    }
2919
2920ZEND_VM_C_LABEL(fcall_end_change_scope):
2921    if (object) {
2922        if (UNEXPECTED(EG(exception) != NULL) && (opline->op1.num & ZEND_CALL_CTOR)) {
2923            if (!(opline->op1.num & ZEND_CALL_CTOR_RESULT_UNUSED)) {
2924                GC_REFCOUNT(object)--;
2925            }
2926            if (GC_REFCOUNT(object) == 1) {
2927                zend_object_store_ctor_failed(object);
2928            }
2929        }
2930        OBJ_RELEASE(object);
2931    }
2932    EG(scope) = EX(func)->op_array.scope;
2933
2934ZEND_VM_C_LABEL(fcall_end):
2935    if (UNEXPECTED(EG(exception) != NULL)) {
2936        zend_throw_exception_internal(NULL);
2937        if (RETURN_VALUE_USED(opline)) {
2938            zval_ptr_dtor(EX_VAR(opline->result.var));
2939        }
2940        HANDLE_EXCEPTION();
2941    }
2942
2943    ZEND_VM_NEXT_OPCODE();
2944}
2945
2946ZEND_VM_HANDLER(124, ZEND_VERIFY_RETURN_TYPE, CONST|TMP|VAR|UNUSED|CV, UNUSED)
2947{
2948#if OP1_TYPE != IS_UNUSED
2949    USE_OPLINE
2950#endif
2951    SAVE_OPLINE();
2952    if (OP1_TYPE == IS_UNUSED) {
2953        zend_verify_missing_return_type(EX(func));
2954    } else {
2955        zval *retval_ptr;
2956        zend_free_op free_op1;
2957
2958        retval_ptr = GET_OP1_ZVAL_PTR_DEREF(BP_VAR_R);
2959        zend_verify_return_type(EX(func), retval_ptr);
2960    }
2961    CHECK_EXCEPTION();
2962    ZEND_VM_NEXT_OPCODE();
2963}
2964
2965ZEND_VM_HANDLER(62, ZEND_RETURN, CONST|TMP|VAR|CV, ANY)
2966{
2967    USE_OPLINE
2968    zval *retval_ptr;
2969    zend_free_op free_op1;
2970
2971    SAVE_OPLINE();
2972    retval_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
2973
2974    if (!EX(return_value)) {
2975        FREE_OP1();
2976    } else {
2977        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR) {
2978            ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
2979            if (OP1_TYPE == IS_CONST) {
2980                if (UNEXPECTED(Z_OPT_COPYABLE_P(EX(return_value)))) {
2981                    zval_copy_ctor_func(EX(return_value));
2982                }
2983            }
2984        } else if ((OP1_TYPE == IS_CV || OP1_TYPE == IS_VAR) && Z_ISREF_P(retval_ptr)) {
2985            ZVAL_COPY(EX(return_value), Z_REFVAL_P(retval_ptr));
2986            FREE_OP1_IF_VAR();
2987        } else {
2988            ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
2989            if (OP1_TYPE == IS_CV) {
2990                if (Z_OPT_REFCOUNTED_P(retval_ptr)) Z_ADDREF_P(retval_ptr);
2991            }
2992        }
2993    }
2994    ZEND_VM_DISPATCH_TO_HELPER(zend_leave_helper);
2995}
2996
2997ZEND_VM_HANDLER(111, ZEND_RETURN_BY_REF, CONST|TMP|VAR|CV, ANY)
2998{
2999    USE_OPLINE
3000    zval *retval_ptr;
3001    zend_free_op free_op1;
3002
3003    SAVE_OPLINE();
3004
3005    do {
3006        if (OP1_TYPE == IS_CONST || OP1_TYPE == IS_TMP_VAR ||
3007            (OP1_TYPE == IS_VAR && opline->extended_value == ZEND_RETURNS_VALUE)) {
3008            /* Not supposed to happen, but we'll allow it */
3009            zend_error(E_NOTICE, "Only variable references should be returned by reference");
3010
3011            retval_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
3012            if (!EX(return_value)) {
3013                if (OP1_TYPE == IS_TMP_VAR) {
3014                    FREE_OP1();
3015                }
3016            } else {
3017                ZVAL_COPY_VALUE(EX(return_value), retval_ptr);
3018                Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
3019                if (OP1_TYPE != IS_TMP_VAR) {
3020                    zval_opt_copy_ctor_no_imm(EX(return_value));
3021                }
3022            }
3023            break;
3024        }
3025
3026        retval_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
3027
3028        if (OP1_TYPE == IS_VAR && UNEXPECTED(retval_ptr == NULL)) {
3029            zend_error_noreturn(E_ERROR, "Cannot return string offsets by reference");
3030        }
3031
3032        if (OP1_TYPE == IS_VAR) {
3033            if (retval_ptr == &EG(uninitialized_zval) ||
3034                (opline->extended_value == ZEND_RETURNS_FUNCTION &&
3035                 !(Z_VAR_FLAGS_P(retval_ptr) & IS_VAR_RET_REF))) {
3036                zend_error(E_NOTICE, "Only variable references should be returned by reference");
3037                if (EX(return_value)) {
3038                    ZVAL_NEW_REF(EX(return_value), retval_ptr);
3039                    Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
3040                    if (Z_REFCOUNTED_P(retval_ptr)) Z_ADDREF_P(retval_ptr);
3041                }
3042                break;
3043            }
3044        }
3045
3046        if (EX(return_value)) {
3047            ZVAL_MAKE_REF(retval_ptr);
3048            Z_ADDREF_P(retval_ptr);
3049            ZVAL_REF(EX(return_value), Z_REF_P(retval_ptr));
3050            Z_VAR_FLAGS_P(EX(return_value)) = IS_VAR_RET_REF;
3051        }
3052    } while (0);
3053
3054    FREE_OP1_VAR_PTR();
3055    ZEND_VM_DISPATCH_TO_HELPER(zend_leave_helper);
3056}
3057
3058ZEND_VM_HANDLER(161, ZEND_GENERATOR_RETURN, ANY, ANY)
3059{
3060    /* The generator object is stored in EX(return_value) */
3061    zend_generator *generator = (zend_generator *) EX(return_value);
3062
3063    /* Close the generator to free up resources */
3064    zend_generator_close(generator, 1);
3065
3066    /* Pass execution back to handling code */
3067    ZEND_VM_RETURN();
3068}
3069
3070ZEND_VM_HANDLER(108, ZEND_THROW, CONST|TMP|VAR|CV, ANY)
3071{
3072    USE_OPLINE
3073    zval *value;
3074    zend_free_op free_op1;
3075
3076    SAVE_OPLINE();
3077    value = GET_OP1_ZVAL_PTR(BP_VAR_R);
3078
3079    do {
3080        if (OP1_TYPE == IS_CONST || UNEXPECTED(Z_TYPE_P(value) != IS_OBJECT)) {
3081            if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(value)) {
3082                value = Z_REFVAL_P(value);
3083                if (EXPECTED(Z_TYPE_P(value) == IS_OBJECT)) {
3084                    break;
3085                }
3086            }
3087            if (UNEXPECTED(EG(exception) != NULL)) {
3088                HANDLE_EXCEPTION();
3089            }
3090            zend_error_noreturn(E_ERROR, "Can only throw objects");
3091        }
3092    } while (0);
3093
3094    zend_exception_save();
3095    if (OP1_TYPE != IS_TMP_VAR) {
3096        if (Z_REFCOUNTED_P(value)) Z_ADDREF_P(value);
3097    }
3098
3099    zend_throw_exception_object(value);
3100    zend_exception_restore();
3101    FREE_OP1_IF_VAR();
3102    HANDLE_EXCEPTION();
3103}
3104
3105ZEND_VM_HANDLER(107, ZEND_CATCH, CONST, CV)
3106{
3107    USE_OPLINE
3108    zend_class_entry *ce, *catch_ce;
3109    zend_object *exception;
3110
3111    SAVE_OPLINE();
3112    /* Check whether an exception has been thrown, if not, jump over code */
3113    zend_exception_restore();
3114    if (EG(exception) == NULL) {
3115        ZEND_VM_SET_OPCODE(&EX(func)->op_array.opcodes[opline->extended_value]);
3116        ZEND_VM_CONTINUE(); /* CHECK_ME */
3117    }
3118    if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)))) {
3119        catch_ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
3120    } else {
3121        catch_ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, ZEND_FETCH_CLASS_NO_AUTOLOAD);
3122
3123        CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), catch_ce);
3124    }
3125    ce = EG(exception)->ce;
3126
3127#ifdef HAVE_DTRACE
3128    if (DTRACE_EXCEPTION_CAUGHT_ENABLED()) {
3129        DTRACE_EXCEPTION_CAUGHT((char *)ce->name);
3130    }
3131#endif /* HAVE_DTRACE */
3132
3133    if (ce != catch_ce) {
3134        if (!catch_ce || !instanceof_function(ce, catch_ce)) {
3135            if (opline->result.num) {
3136                zend_throw_exception_internal(NULL);
3137                HANDLE_EXCEPTION();
3138            }
3139            ZEND_VM_SET_OPCODE(&EX(func)->op_array.opcodes[opline->extended_value]);
3140            ZEND_VM_CONTINUE(); /* CHECK_ME */
3141        }
3142    }
3143
3144    exception = EG(exception);
3145    zval_ptr_dtor(EX_VAR(opline->op2.var));
3146    ZVAL_OBJ(EX_VAR(opline->op2.var), EG(exception));
3147    if (UNEXPECTED(EG(exception) != exception)) {
3148        GC_REFCOUNT(EG(exception))++;
3149        HANDLE_EXCEPTION();
3150    } else {
3151        EG(exception) = NULL;
3152        ZEND_VM_NEXT_OPCODE();
3153    }
3154}
3155
3156ZEND_VM_HANDLER(65, ZEND_SEND_VAL, CONST|TMP, ANY)
3157{
3158    USE_OPLINE
3159    zval *value, *arg;
3160    zend_free_op free_op1;
3161
3162    SAVE_OPLINE();
3163    value = GET_OP1_ZVAL_PTR(BP_VAR_R);
3164    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
3165    ZVAL_COPY_VALUE(arg, value);
3166    if (OP1_TYPE == IS_CONST) {
3167        if (UNEXPECTED(Z_OPT_COPYABLE_P(arg))) {
3168            zval_copy_ctor_func(arg);
3169        }
3170    }
3171    ZEND_VM_NEXT_OPCODE();
3172}
3173
3174ZEND_VM_HANDLER(116, ZEND_SEND_VAL_EX, CONST|TMP, ANY)
3175{
3176    USE_OPLINE
3177    zval *value, *arg;
3178    zend_free_op free_op1;
3179
3180    SAVE_OPLINE();
3181    if (ARG_MUST_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3182        zend_error_noreturn(E_ERROR, "Cannot pass parameter %d by reference", opline->op2.num);
3183    }
3184    value = GET_OP1_ZVAL_PTR(BP_VAR_R);
3185    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
3186    ZVAL_COPY_VALUE(arg, value);
3187    if (OP1_TYPE == IS_CONST) {
3188        if (UNEXPECTED(Z_OPT_COPYABLE_P(arg))) {
3189            zval_copy_ctor_func(arg);
3190        }
3191    }
3192    ZEND_VM_NEXT_OPCODE();
3193}
3194
3195ZEND_VM_HANDLER(117, ZEND_SEND_VAR, VAR|CV, ANY)
3196{
3197    USE_OPLINE
3198    zval *varptr, *arg;
3199    zend_free_op free_op1;
3200
3201    varptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
3202    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
3203    if (Z_ISREF_P(varptr)) {
3204        ZVAL_COPY(arg, Z_REFVAL_P(varptr));
3205        FREE_OP1();
3206    } else {
3207        ZVAL_COPY_VALUE(arg, varptr);
3208        if (OP1_TYPE == IS_CV) {
3209            if (Z_OPT_REFCOUNTED_P(arg)) Z_ADDREF_P(arg);
3210        }
3211    }
3212    ZEND_VM_NEXT_OPCODE();
3213}
3214
3215ZEND_VM_HANDLER(106, ZEND_SEND_VAR_NO_REF, VAR|CV, ANY)
3216{
3217    USE_OPLINE
3218    zend_free_op free_op1;
3219    zval *varptr, *arg;
3220
3221    SAVE_OPLINE();
3222
3223    if (!(opline->extended_value & ZEND_ARG_COMPILE_TIME_BOUND)) {
3224        if (!ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3225            ZEND_VM_DISPATCH_TO_HANDLER(ZEND_SEND_VAR);
3226        }
3227    }
3228
3229    varptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
3230    if ((!(opline->extended_value & ZEND_ARG_SEND_FUNCTION) ||
3231         (Z_VAR_FLAGS_P(varptr) & IS_VAR_RET_REF)) &&
3232        (Z_ISREF_P(varptr) || Z_TYPE_P(varptr) == IS_OBJECT)) {
3233
3234        ZVAL_MAKE_REF(varptr);
3235        if (OP1_TYPE == IS_CV) {
3236            Z_ADDREF_P(varptr);
3237        }
3238    } else {
3239        if ((opline->extended_value & ZEND_ARG_COMPILE_TIME_BOUND) ?
3240            !(opline->extended_value & ZEND_ARG_SEND_SILENT) :
3241            !ARG_MAY_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3242            zend_error(E_STRICT, "Only variables should be passed by reference");
3243        }
3244    }
3245
3246    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
3247    ZVAL_COPY_VALUE(arg, varptr);
3248
3249    CHECK_EXCEPTION();
3250    ZEND_VM_NEXT_OPCODE();
3251}
3252
3253ZEND_VM_HANDLER(67, ZEND_SEND_REF, VAR|CV, ANY)
3254{
3255    USE_OPLINE
3256    zend_free_op free_op1;
3257    zval *varptr, *arg;
3258
3259    SAVE_OPLINE();
3260    varptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
3261
3262    if (OP1_TYPE == IS_VAR && UNEXPECTED(varptr == NULL)) {
3263        zend_error_noreturn(E_ERROR, "Only variables can be passed by reference");
3264    }
3265
3266    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
3267    if (OP1_TYPE == IS_VAR && UNEXPECTED(varptr == &EG(error_zval))) {
3268        ZVAL_NEW_REF(arg, &EG(uninitialized_zval));
3269        ZEND_VM_NEXT_OPCODE();
3270    }
3271
3272    if (Z_ISREF_P(varptr)) {
3273        Z_ADDREF_P(varptr);
3274        ZVAL_COPY_VALUE(arg, varptr);
3275    } else if (OP1_TYPE == IS_VAR &&
3276        UNEXPECTED(Z_TYPE_P(EX_VAR(opline->op1.var)) != IS_INDIRECT)) {
3277        ZVAL_NEW_REF(arg, varptr);
3278    } else {
3279        ZVAL_NEW_REF(arg, varptr);
3280        Z_ADDREF_P(arg);
3281        ZVAL_REF(varptr, Z_REF_P(arg));
3282    }
3283
3284    FREE_OP1_VAR_PTR();
3285    ZEND_VM_NEXT_OPCODE();
3286}
3287
3288ZEND_VM_HANDLER(66, ZEND_SEND_VAR_EX, VAR|CV, ANY)
3289{
3290    USE_OPLINE
3291    zval *varptr, *arg;
3292    zend_free_op free_op1;
3293
3294    if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3295        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_SEND_REF);
3296    }
3297    varptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
3298    arg = ZEND_CALL_VAR(EX(call), opline->result.var);
3299    if (Z_ISREF_P(varptr)) {
3300        ZVAL_COPY(arg, Z_REFVAL_P(varptr));
3301        FREE_OP1();
3302    } else {
3303        ZVAL_COPY_VALUE(arg, varptr);
3304        if (OP1_TYPE == IS_CV) {
3305            if (Z_OPT_REFCOUNTED_P(arg)) Z_ADDREF_P(arg);
3306        }
3307    }
3308    ZEND_VM_NEXT_OPCODE();
3309}
3310
3311ZEND_VM_HANDLER(165, ZEND_SEND_UNPACK, ANY, ANY)
3312{
3313    USE_OPLINE
3314    zend_free_op free_op1;
3315    zval *args;
3316    int arg_num;
3317    SAVE_OPLINE();
3318
3319    args = GET_OP1_ZVAL_PTR(BP_VAR_R);
3320    arg_num = ZEND_CALL_NUM_ARGS(EX(call)) + 1;
3321
3322ZEND_VM_C_LABEL(send_again):
3323    switch (Z_TYPE_P(args)) {
3324        case IS_ARRAY: {
3325            HashTable *ht = Z_ARRVAL_P(args);
3326            zval *arg, *top;
3327            zend_string *name;
3328
3329            zend_vm_stack_extend_call_frame(&EX(call), arg_num - 1, zend_hash_num_elements(ht));
3330
3331            if (OP1_TYPE != IS_CONST && OP1_TYPE != IS_TMP_VAR && Z_IMMUTABLE_P(args)) {
3332                uint32_t i;
3333                int separate = 0;
3334
3335                /* check if any of arguments are going to be passed by reference */
3336                for (i = 0; i < zend_hash_num_elements(ht); i++) {
3337                    if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num + i)) {
3338                        separate = 1;
3339                        break;
3340                    }
3341                }
3342                if (separate) {
3343                    zval_copy_ctor(args);
3344                    ht = Z_ARRVAL_P(args);
3345                }
3346            }
3347
3348            ZEND_HASH_FOREACH_STR_KEY_VAL(ht, name, arg) {
3349                if (name) {
3350                    zend_error(E_RECOVERABLE_ERROR, "Cannot unpack array with string keys");
3351                    FREE_OP1();
3352                    CHECK_EXCEPTION();
3353                    ZEND_VM_NEXT_OPCODE();
3354                }
3355
3356                top = ZEND_CALL_ARG(EX(call), arg_num);
3357                if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
3358                    if (!Z_IMMUTABLE_P(args)) {
3359                        ZVAL_MAKE_REF(arg);
3360                        Z_ADDREF_P(arg);
3361                        ZVAL_REF(top, Z_REF_P(arg));
3362                    } else {
3363                        ZVAL_DUP(top, arg);
3364                    }
3365                } else if (Z_ISREF_P(arg)) {
3366                    ZVAL_COPY(top, Z_REFVAL_P(arg));
3367                } else {
3368                    ZVAL_COPY(top, arg);
3369                }
3370
3371                ZEND_CALL_NUM_ARGS(EX(call))++;
3372                arg_num++;
3373            } ZEND_HASH_FOREACH_END();
3374
3375            break;
3376        }
3377        case IS_OBJECT: {
3378            zend_class_entry *ce = Z_OBJCE_P(args);
3379            zend_object_iterator *iter;
3380
3381            if (!ce || !ce->get_iterator) {
3382                zend_error(E_WARNING, "Only arrays and Traversables can be unpacked");
3383                break;
3384            }
3385
3386            iter = ce->get_iterator(ce, args, 0);
3387            if (UNEXPECTED(!iter)) {
3388                FREE_OP1();
3389                if (!EG(exception)) {
3390                    zend_throw_exception_ex(
3391                        NULL, 0, "Object of type %s did not create an Iterator", ce->name->val
3392                    );
3393                }
3394                HANDLE_EXCEPTION();
3395            }
3396
3397            if (iter->funcs->rewind) {
3398                iter->funcs->rewind(iter);
3399                if (UNEXPECTED(EG(exception) != NULL)) {
3400                    ZEND_VM_C_GOTO(unpack_iter_dtor);
3401                }
3402            }
3403
3404            for (; iter->funcs->valid(iter) == SUCCESS; ++arg_num) {
3405                zval *arg, *top;
3406
3407                if (UNEXPECTED(EG(exception) != NULL)) {
3408                    ZEND_VM_C_GOTO(unpack_iter_dtor);
3409                }
3410
3411                arg = iter->funcs->get_current_data(iter);
3412                if (UNEXPECTED(EG(exception) != NULL)) {
3413                    ZEND_VM_C_GOTO(unpack_iter_dtor);
3414                }
3415
3416                if (iter->funcs->get_current_key) {
3417                    zval key;
3418                    iter->funcs->get_current_key(iter, &key);
3419                    if (UNEXPECTED(EG(exception) != NULL)) {
3420                        ZEND_VM_C_GOTO(unpack_iter_dtor);
3421                    }
3422
3423                    if (Z_TYPE(key) == IS_STRING) {
3424                        zend_error(E_RECOVERABLE_ERROR,
3425                            "Cannot unpack Traversable with string keys");
3426                        zend_string_release(Z_STR(key));
3427                        ZEND_VM_C_GOTO(unpack_iter_dtor);
3428                    }
3429
3430                    zval_dtor(&key);
3431                }
3432
3433                if (ARG_MUST_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
3434                    zend_error(
3435                        E_WARNING, "Cannot pass by-reference argument %d of %s%s%s()"
3436                        " by unpacking a Traversable, passing by-value instead", arg_num,
3437                        EX(call)->func->common.scope ? EX(call)->func->common.scope->name->val : "",
3438                        EX(call)->func->common.scope ? "::" : "",
3439                        EX(call)->func->common.function_name->val
3440                    );
3441                }
3442
3443                if (Z_ISREF_P(arg)) {
3444                    ZVAL_DUP(arg, Z_REFVAL_P(arg));
3445                } else {
3446                    if (Z_REFCOUNTED_P(arg)) Z_ADDREF_P(arg);
3447                }
3448
3449                zend_vm_stack_extend_call_frame(&EX(call), arg_num - 1, 1);
3450                top = ZEND_CALL_ARG(EX(call), arg_num);
3451                ZVAL_COPY_VALUE(top, arg);
3452                ZEND_CALL_NUM_ARGS(EX(call))++;
3453
3454                iter->funcs->move_forward(iter);
3455                if (UNEXPECTED(EG(exception) != NULL)) {
3456                    ZEND_VM_C_GOTO(unpack_iter_dtor);
3457                }
3458            }
3459
3460ZEND_VM_C_LABEL(unpack_iter_dtor):
3461            zend_iterator_dtor(iter);
3462            break;
3463        }
3464        case IS_REFERENCE:
3465            args = Z_REFVAL_P(args);
3466            ZEND_VM_C_GOTO(send_again);
3467            break;
3468        default:
3469            zend_error(E_WARNING, "Only arrays and Traversables can be unpacked");
3470    }
3471
3472    FREE_OP1();
3473    CHECK_EXCEPTION();
3474    ZEND_VM_NEXT_OPCODE();
3475}
3476
3477ZEND_VM_HANDLER(119, ZEND_SEND_ARRAY, ANY, ANY)
3478{
3479    USE_OPLINE
3480    zend_free_op free_op1;
3481    zval *args;
3482    SAVE_OPLINE();
3483
3484    args = GET_OP1_ZVAL_PTR(BP_VAR_R);
3485
3486    if (UNEXPECTED(Z_TYPE_P(args) != IS_ARRAY)) {
3487        if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(args)) {
3488            args = Z_REFVAL_P(args);
3489            if (EXPECTED(Z_TYPE_P(args) == IS_ARRAY)) {
3490                ZEND_VM_C_GOTO(send_array);
3491            }
3492        }
3493        zend_error(E_WARNING, "call_user_func_array() expects parameter 2 to be array, %s given", zend_get_type_by_const(Z_TYPE_P(args)));
3494        if (EX(call)->func->common.fn_flags & ZEND_ACC_CLOSURE) {
3495            OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
3496        }
3497        if (Z_OBJ(EX(call)->This)) {
3498            OBJ_RELEASE(Z_OBJ(EX(call)->This));
3499        }
3500        EX(call)->func = (zend_function*)&zend_pass_function;
3501        EX(call)->called_scope = NULL;
3502        Z_OBJ(EX(call)->This) = NULL;
3503    } else {
3504        uint32_t arg_num;
3505        HashTable *ht;
3506        zval *arg, *param, tmp;
3507
3508ZEND_VM_C_LABEL(send_array):
3509        ht = Z_ARRVAL_P(args);
3510        zend_vm_stack_extend_call_frame(&EX(call), 0, zend_hash_num_elements(ht));
3511
3512        if (OP1_TYPE != IS_CONST && OP1_TYPE != IS_TMP_VAR && Z_IMMUTABLE_P(args)) {
3513            int separate = 0;
3514
3515            /* check if any of arguments are going to be passed by reference */
3516            for (arg_num = 0; arg_num < zend_hash_num_elements(ht); arg_num++) {
3517                if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num + 1)) {
3518                    separate = 1;
3519                    break;
3520                }
3521            }
3522            if (separate) {
3523                zval_copy_ctor(args);
3524                ht = Z_ARRVAL_P(args);
3525            }
3526        }
3527
3528        arg_num = 1;
3529        param = ZEND_CALL_ARG(EX(call), 1);
3530        ZEND_HASH_FOREACH_VAL(ht, arg) {
3531            if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
3532                // TODO: Scalar values don't have reference counters anymore.
3533                // They are assumed to be 1, and they may be easily passed by
3534                // reference now. However, previously scalars with refcount==1
3535                // might be passed and with refcount>1 might not. We can support
3536                // only single behavior ???
3537#if 0
3538                if (Z_REFCOUNTED_P(arg) &&
3539                    // This solution breaks the following test (omit warning message) ???
3540                    // Zend/tests/bug61273.phpt
3541                    // ext/reflection/tests/bug42976.phpt
3542                    // ext/standard/tests/general_functions/call_user_func_array_variation_001.phpt
3543#else
3544                if (!Z_REFCOUNTED_P(arg) ||
3545                    // This solution breaks the following test (emit warning message) ???
3546                    // ext/pdo_sqlite/tests/pdo_005.phpt
3547#endif
3548                    (!Z_ISREF_P(arg) && Z_REFCOUNT_P(arg) > 1)) {
3549
3550                    if (!ARG_MAY_BE_SENT_BY_REF(EX(call)->func, arg_num)) {
3551
3552                        zend_error(E_WARNING, "Parameter %d to %s%s%s() expected to be a reference, value given",
3553                            arg_num,
3554                            EX(call)->func->common.scope ? EX(call)->func->common.scope->name->val : "",
3555                            EX(call)->func->common.scope ? "::" : "",
3556                            EX(call)->func->common.function_name->val);
3557
3558                        if (EX(call)->func->common.fn_flags & ZEND_ACC_CLOSURE) {
3559                            OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
3560                        }
3561                        if (Z_OBJ(EX(call)->This)) {
3562                            OBJ_RELEASE(Z_OBJ(EX(call)->This));
3563                        }
3564                        EX(call)->func = (zend_function*)&zend_pass_function;
3565                        EX(call)->called_scope = NULL;
3566                        Z_OBJ(EX(call)->This) = NULL;
3567
3568                        break;
3569                    }
3570
3571                    if (Z_REFCOUNTED_P(arg)) {
3572                        Z_DELREF_P(arg);
3573                    }
3574                    ZVAL_DUP(&tmp, arg);
3575                    ZVAL_NEW_REF(arg, &tmp);
3576                    Z_ADDREF_P(arg);
3577                } else if (!Z_ISREF_P(arg)) {
3578                    ZVAL_NEW_REF(arg, arg);
3579                    Z_ADDREF_P(arg);
3580                } else if (Z_REFCOUNTED_P(arg)) {
3581                    Z_ADDREF_P(arg);
3582                }
3583                ZVAL_COPY_VALUE(param, arg);
3584            } else if (Z_ISREF_P(arg) &&
3585                   /* don't separate references for __call */
3586                   (EX(call)->func->common.fn_flags & ZEND_ACC_CALL_VIA_HANDLER) == 0) {
3587                ZVAL_DUP(param, Z_REFVAL_P(arg));
3588            } else {
3589                ZVAL_COPY(param, arg);
3590            }
3591            ZEND_CALL_NUM_ARGS(EX(call))++;
3592            arg_num++;
3593            param++;
3594        } ZEND_HASH_FOREACH_END();
3595    }
3596    FREE_OP1();
3597    CHECK_EXCEPTION();
3598    ZEND_VM_NEXT_OPCODE();
3599}
3600
3601ZEND_VM_HANDLER(120, ZEND_SEND_USER, VAR|CV, ANY)
3602{
3603    USE_OPLINE
3604    zval *arg, *param, tmp;
3605    zend_free_op free_op1;
3606
3607    arg = GET_OP1_ZVAL_PTR(BP_VAR_R);
3608    param = ZEND_CALL_VAR(EX(call), opline->result.var);
3609
3610    if (ARG_SHOULD_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3611        // TODO: Scalar values don't have reference counters anymore.
3612        // They are assumed to be 1, and they may be easily passed by
3613        // reference now. However, previously scalars with refcount==1
3614        // might be passed and with refcount>1 might not. We can support
3615        // only single behavior ???
3616#if 0
3617        if (Z_REFCOUNTED_P(arg) &&
3618            // This solution breaks the following test (omit warning message) ???
3619            // Zend/tests/bug61273.phpt
3620            // ext/reflection/tests/bug42976.phpt
3621            // ext/standard/tests/general_functions/call_user_func_array_variation_001.phpt
3622#else
3623        if (!Z_REFCOUNTED_P(arg) ||
3624            // This solution breaks the following test (emit warning message) ???
3625            // ext/pdo_sqlite/tests/pdo_005.phpt
3626#endif
3627            (!Z_ISREF_P(arg) /*&& Z_REFCOUNT_P(arg) > 1???*/)) {
3628
3629            if (!ARG_MAY_BE_SENT_BY_REF(EX(call)->func, opline->op2.num)) {
3630
3631                zend_error(E_WARNING, "Parameter %d to %s%s%s() expected to be a reference, value given",
3632                    opline->op2.num,
3633                    EX(call)->func->common.scope ? EX(call)->func->common.scope->name->val : "",
3634                    EX(call)->func->common.scope ? "::" : "",
3635                    EX(call)->func->common.function_name->val);
3636
3637                if (EX(call)->func->common.fn_flags & ZEND_ACC_CLOSURE) {
3638                    OBJ_RELEASE((zend_object*)EX(call)->func->common.prototype);
3639                }
3640                if (Z_OBJ(EX(call)->This)) {
3641                    OBJ_RELEASE(Z_OBJ(EX(call)->This));
3642                }
3643                ZVAL_UNDEF(param);
3644                EX(call)->func = (zend_function*)&zend_pass_function;
3645                EX(call)->called_scope = NULL;
3646                Z_OBJ(EX(call)->This) = NULL;
3647
3648                FREE_OP1();
3649                CHECK_EXCEPTION();
3650                ZEND_VM_NEXT_OPCODE();
3651            }
3652
3653            if (Z_REFCOUNTED_P(arg)) {
3654                Z_DELREF_P(arg);
3655            }
3656            ZVAL_DUP(&tmp, arg);
3657            ZVAL_NEW_REF(arg, &tmp);
3658            Z_ADDREF_P(arg);
3659        } else if (!Z_ISREF_P(arg)) {
3660            ZVAL_NEW_REF(arg, arg);
3661            Z_ADDREF_P(arg);
3662        } else if (Z_REFCOUNTED_P(arg)) {
3663            Z_ADDREF_P(arg);
3664        }
3665        ZVAL_COPY_VALUE(param, arg);
3666    } else if (Z_ISREF_P(arg) &&
3667               /* don't separate references for __call */
3668               (EX(call)->func->common.fn_flags & ZEND_ACC_CALL_VIA_HANDLER) == 0) {
3669        ZVAL_DUP(param, Z_REFVAL_P(arg));
3670    } else {
3671        ZVAL_COPY(param, arg);
3672    }
3673
3674    FREE_OP1();
3675    CHECK_EXCEPTION();
3676    ZEND_VM_NEXT_OPCODE();
3677}
3678
3679ZEND_VM_HANDLER(63, ZEND_RECV, ANY, ANY)
3680{
3681    USE_OPLINE
3682    uint32_t arg_num = opline->op1.num;
3683
3684    SAVE_OPLINE();
3685    if (UNEXPECTED(arg_num > EX_NUM_ARGS())) {
3686        zend_verify_missing_arg(execute_data, arg_num);
3687        CHECK_EXCEPTION();
3688    } else if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
3689        zval *param = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var);
3690
3691        zend_verify_arg_type(EX(func), arg_num, param, NULL);
3692        CHECK_EXCEPTION();
3693    }
3694
3695    ZEND_VM_NEXT_OPCODE();
3696}
3697
3698ZEND_VM_HANDLER(64, ZEND_RECV_INIT, ANY, CONST)
3699{
3700    USE_OPLINE
3701    uint32_t arg_num = opline->op1.num;
3702    zval *param;
3703
3704    SAVE_OPLINE();
3705    param = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var);
3706    if (arg_num > EX_NUM_ARGS()) {
3707        ZVAL_COPY_VALUE(param, EX_CONSTANT(opline->op2));
3708        if (Z_OPT_CONSTANT_P(param)) {
3709            zval_update_constant(param, 0);
3710        } else {
3711            /* IS_CONST can't be IS_OBJECT, IS_RESOURCE or IS_REFERENCE */
3712            if (UNEXPECTED(Z_OPT_COPYABLE_P(param))) {
3713                zval_copy_ctor_func(param);
3714            }
3715        }
3716    }
3717
3718    if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
3719        zend_verify_arg_type(EX(func), arg_num, param, EX_CONSTANT(opline->op2));
3720    }
3721
3722    CHECK_EXCEPTION();
3723    ZEND_VM_NEXT_OPCODE();
3724}
3725
3726ZEND_VM_HANDLER(164, ZEND_RECV_VARIADIC, ANY, ANY)
3727{
3728    USE_OPLINE
3729    uint32_t arg_num = opline->op1.num;
3730    uint32_t arg_count = EX_NUM_ARGS();
3731    zval *params;
3732
3733    SAVE_OPLINE();
3734
3735    params = _get_zval_ptr_cv_undef_BP_VAR_W(execute_data, opline->result.var);
3736
3737    if (arg_num <= arg_count) {
3738        zval *param;
3739
3740        array_init_size(params, arg_count - arg_num + 1);
3741        zend_hash_real_init(Z_ARRVAL_P(params), 1);
3742        ZEND_HASH_FILL_PACKED(Z_ARRVAL_P(params)) {
3743            param = EX_VAR_NUM(EX(func)->op_array.last_var + EX(func)->op_array.T);
3744            if (UNEXPECTED((EX(func)->op_array.fn_flags & ZEND_ACC_HAS_TYPE_HINTS) != 0)) {
3745                do {
3746                    zend_verify_arg_type(EX(func), arg_num, param, NULL);
3747                    if (Z_OPT_REFCOUNTED_P(param)) Z_ADDREF_P(param);
3748                    ZEND_HASH_FILL_ADD(param);
3749                    param++;
3750                } while (++arg_num <= arg_count);
3751            } else {
3752                do {
3753                    if (Z_OPT_REFCOUNTED_P(param)) Z_ADDREF_P(param);
3754                    ZEND_HASH_FILL_ADD(param);
3755                    param++;
3756                } while (++arg_num <= arg_count);
3757            }
3758        } ZEND_HASH_FILL_END();
3759    } else {
3760        array_init(params);
3761    }
3762
3763    CHECK_EXCEPTION();
3764    ZEND_VM_NEXT_OPCODE();
3765}
3766
3767ZEND_VM_HANDLER(52, ZEND_BOOL, CONST|TMPVAR|CV, ANY)
3768{
3769    USE_OPLINE
3770    zval *val;
3771    zend_free_op free_op1;
3772
3773    SAVE_OPLINE();
3774    val = GET_OP1_ZVAL_PTR(BP_VAR_R);
3775    if (Z_TYPE_P(val) == IS_TRUE) {
3776        ZVAL_TRUE(EX_VAR(opline->result.var));
3777    } else if (EXPECTED(Z_TYPE_P(val) <= IS_TRUE)) {
3778        ZVAL_FALSE(EX_VAR(opline->result.var));
3779    } else {
3780        ZVAL_BOOL(EX_VAR(opline->result.var), i_zend_is_true(val));
3781        FREE_OP1();
3782        CHECK_EXCEPTION();
3783    }
3784    ZEND_VM_NEXT_OPCODE();
3785}
3786
3787ZEND_VM_HANDLER(50, ZEND_BRK, ANY, CONST)
3788{
3789    USE_OPLINE
3790    zend_brk_cont_element *el;
3791
3792    SAVE_OPLINE();
3793    el = zend_brk_cont(Z_LVAL_P(EX_CONSTANT(opline->op2)), opline->op1.opline_num,
3794                       &EX(func)->op_array, execute_data);
3795    ZEND_VM_JMP(EX(func)->op_array.opcodes + el->brk);
3796}
3797
3798ZEND_VM_HANDLER(51, ZEND_CONT, ANY, CONST)
3799{
3800    USE_OPLINE
3801    zend_brk_cont_element *el;
3802
3803    SAVE_OPLINE();
3804    el = zend_brk_cont(Z_LVAL_P(EX_CONSTANT(opline->op2)), opline->op1.opline_num,
3805                       &EX(func)->op_array, execute_data);
3806    ZEND_VM_JMP(EX(func)->op_array.opcodes + el->cont);
3807}
3808
3809ZEND_VM_HANDLER(100, ZEND_GOTO, ANY, CONST)
3810{
3811    zend_op *brk_opline;
3812    USE_OPLINE
3813    zend_brk_cont_element *el;
3814
3815    SAVE_OPLINE();
3816    el = zend_brk_cont(Z_LVAL_P(EX_CONSTANT(opline->op2)), opline->extended_value,
3817                       &EX(func)->op_array, execute_data);
3818
3819    brk_opline = EX(func)->op_array.opcodes + el->brk;
3820
3821    if (brk_opline->opcode == ZEND_FREE) {
3822        if (!(brk_opline->extended_value & EXT_TYPE_FREE_ON_RETURN)) {
3823            zval_ptr_dtor_nogc(EX_VAR(brk_opline->op1.var));
3824        }
3825    }
3826    ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op1));
3827}
3828
3829ZEND_VM_HANDLER(48, ZEND_CASE, CONST|TMPVAR|CV, CONST|TMPVAR|CV)
3830{
3831    USE_OPLINE
3832    zend_free_op free_op1, free_op2;
3833    zval *result = EX_VAR(opline->result.var);
3834
3835    SAVE_OPLINE();
3836    fast_equal_function(result,
3837         GET_OP1_ZVAL_PTR(BP_VAR_R),
3838         GET_OP2_ZVAL_PTR(BP_VAR_R));
3839
3840    FREE_OP2();
3841    CHECK_EXCEPTION();
3842    ZEND_VM_NEXT_OPCODE();
3843}
3844
3845ZEND_VM_HANDLER(68, ZEND_NEW, CONST|VAR, ANY)
3846{
3847    USE_OPLINE
3848    zval object_zval;
3849    zend_function *constructor;
3850    zend_class_entry *ce;
3851
3852    SAVE_OPLINE();
3853    if (OP1_TYPE == IS_CONST) {
3854        if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)))) {
3855            ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
3856        } else {
3857            ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, 0);
3858            if (UNEXPECTED(ce == NULL)) {
3859                CHECK_EXCEPTION();
3860                ZEND_VM_NEXT_OPCODE();
3861            }
3862            CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce);
3863        }
3864    } else {
3865        ce = Z_CE_P(EX_VAR(opline->op1.var));
3866    }
3867    if (UNEXPECTED((ce->ce_flags & (ZEND_ACC_INTERFACE|ZEND_ACC_IMPLICIT_ABSTRACT_CLASS|ZEND_ACC_EXPLICIT_ABSTRACT_CLASS)) != 0)) {
3868        if (ce->ce_flags & ZEND_ACC_INTERFACE) {
3869            zend_error_noreturn(E_ERROR, "Cannot instantiate interface %s", ce->name->val);
3870        } else if ((ce->ce_flags & ZEND_ACC_TRAIT) == ZEND_ACC_TRAIT) {
3871            zend_error_noreturn(E_ERROR, "Cannot instantiate trait %s", ce->name->val);
3872        } else {
3873            zend_error_noreturn(E_ERROR, "Cannot instantiate abstract class %s", ce->name->val);
3874        }
3875    }
3876    object_init_ex(&object_zval, ce);
3877    constructor = Z_OBJ_HT(object_zval)->get_constructor(Z_OBJ(object_zval));
3878
3879    if (constructor == NULL) {
3880        if (EXPECTED(RETURN_VALUE_USED(opline))) {
3881            ZVAL_COPY_VALUE(EX_VAR(opline->result.var), &object_zval);
3882        } else {
3883            OBJ_RELEASE(Z_OBJ(object_zval));
3884        }
3885        ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
3886    } else {
3887        /* We are not handling overloaded classes right now */
3888        EX(call) = zend_vm_stack_push_call_frame(
3889                ZEND_CALL_FUNCTION | ZEND_CALL_CTOR |
3890                (EXPECTED(RETURN_VALUE_USED(opline)) ? 0 : ZEND_CALL_CTOR_RESULT_UNUSED),
3891            constructor,
3892            opline->extended_value,
3893            ce,
3894            Z_OBJ(object_zval),
3895            EX(call));
3896
3897        if (EXPECTED(RETURN_VALUE_USED(opline))) {
3898            ZVAL_COPY(EX_VAR(opline->result.var), &object_zval);
3899            EX(call)->return_value = EX_VAR(opline->result.var);
3900        } else {
3901            EX(call)->return_value = NULL;
3902        }
3903
3904        CHECK_EXCEPTION();
3905        ZEND_VM_NEXT_OPCODE();
3906    }
3907}
3908
3909ZEND_VM_HANDLER(110, ZEND_CLONE, CONST|TMPVAR|UNUSED|CV, ANY)
3910{
3911    USE_OPLINE
3912    zend_free_op free_op1;
3913    zval *obj;
3914    zend_class_entry *ce;
3915    zend_function *clone;
3916    zend_object_clone_obj_t clone_call;
3917
3918    SAVE_OPLINE();
3919    obj = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_R);
3920
3921    do {
3922        if (OP1_TYPE == IS_CONST ||
3923            (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(obj) != IS_OBJECT))) {
3924            if ((OP1_TYPE & (IS_VAR|IS_CV)) && Z_ISREF_P(obj)) {
3925                obj = Z_REFVAL_P(obj);
3926                if (EXPECTED(Z_TYPE_P(obj) == IS_OBJECT)) {
3927                    break;
3928                }
3929            }
3930            if (UNEXPECTED(EG(exception) != NULL)) {
3931                HANDLE_EXCEPTION();
3932            }
3933            zend_error_noreturn(E_ERROR, "__clone method called on non-object");
3934        }
3935    } while (0);
3936
3937    ce = Z_OBJCE_P(obj);
3938    clone = ce ? ce->clone : NULL;
3939    clone_call =  Z_OBJ_HT_P(obj)->clone_obj;
3940    if (UNEXPECTED(clone_call == NULL)) {
3941        if (ce) {
3942            zend_error_noreturn(E_ERROR, "Trying to clone an uncloneable object of class %s", ce->name->val);
3943        } else {
3944            zend_error_noreturn(E_ERROR, "Trying to clone an uncloneable object");
3945        }
3946    }
3947
3948    if (ce && clone) {
3949        if (clone->op_array.fn_flags & ZEND_ACC_PRIVATE) {
3950            /* Ensure that if we're calling a private function, we're allowed to do so.
3951             */
3952            if (UNEXPECTED(ce != EG(scope))) {
3953                zend_error_noreturn(E_ERROR, "Call to private %s::__clone() from context '%s'", ce->name->val, EG(scope) ? EG(scope)->name->val : "");
3954            }
3955        } else if ((clone->common.fn_flags & ZEND_ACC_PROTECTED)) {
3956            /* Ensure that if we're calling a protected function, we're allowed to do so.
3957             */
3958            if (UNEXPECTED(!zend_check_protected(zend_get_function_root_class(clone), EG(scope)))) {
3959                zend_error_noreturn(E_ERROR, "Call to protected %s::__clone() from context '%s'", ce->name->val, EG(scope) ? EG(scope)->name->val : "");
3960            }
3961        }
3962    }
3963
3964    if (EXPECTED(EG(exception) == NULL)) {
3965        ZVAL_OBJ(EX_VAR(opline->result.var), clone_call(obj));
3966        if (UNEXPECTED(!RETURN_VALUE_USED(opline)) || UNEXPECTED(EG(exception) != NULL)) {
3967            OBJ_RELEASE(Z_OBJ_P(EX_VAR(opline->result.var)));
3968        }
3969    }
3970    FREE_OP1();
3971    CHECK_EXCEPTION();
3972    ZEND_VM_NEXT_OPCODE();
3973}
3974
3975ZEND_VM_HANDLER(99, ZEND_FETCH_CONSTANT, VAR|CONST|UNUSED, CONST)
3976{
3977    USE_OPLINE
3978
3979    SAVE_OPLINE();
3980    if (OP1_TYPE == IS_UNUSED) {
3981        zend_constant *c;
3982        zval *retval;
3983
3984        if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) {
3985            c = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
3986        } else if ((c = zend_quick_get_constant(EX_CONSTANT(opline->op2) + 1, opline->extended_value)) == NULL) {
3987            if ((opline->extended_value & IS_CONSTANT_UNQUALIFIED) != 0) {
3988                char *actual = (char *)zend_memrchr(Z_STRVAL_P(EX_CONSTANT(opline->op2)), '\\', Z_STRLEN_P(EX_CONSTANT(opline->op2)));
3989                if (!actual) {
3990                    ZVAL_STR(EX_VAR(opline->result.var), zend_string_copy(Z_STR_P(EX_CONSTANT(opline->op2))));
3991                } else {
3992                    actual++;
3993                    ZVAL_STRINGL(EX_VAR(opline->result.var),
3994                            actual, Z_STRLEN_P(EX_CONSTANT(opline->op2)) - (actual - Z_STRVAL_P(EX_CONSTANT(opline->op2))));
3995                }
3996                /* non-qualified constant - allow text substitution */
3997                zend_error(E_NOTICE, "Use of undefined constant %s - assumed '%s'",
3998                        Z_STRVAL_P(EX_VAR(opline->result.var)), Z_STRVAL_P(EX_VAR(opline->result.var)));
3999                CHECK_EXCEPTION();
4000                ZEND_VM_NEXT_OPCODE();
4001            } else {
4002                zend_error_noreturn(E_ERROR, "Undefined constant '%s'", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
4003            }
4004        } else {
4005            CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), c);
4006        }
4007        retval = EX_VAR(opline->result.var);
4008        ZVAL_COPY_VALUE(retval, &c->value);
4009        if (Z_OPT_COPYABLE_P(retval) || Z_OPT_REFCOUNTED_P(retval)) {
4010            if (Z_OPT_COPYABLE_P(retval)) {
4011                zval_copy_ctor_func(retval);
4012            } else {
4013                Z_ADDREF_P(retval);
4014            }
4015        }
4016    } else {
4017        /* class constant */
4018        zend_class_entry *ce;
4019        zval *value;
4020
4021        if (OP1_TYPE == IS_CONST) {
4022            if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) {
4023                value = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
4024                ZVAL_DEREF(value);
4025                ZVAL_DUP(EX_VAR(opline->result.var), value);
4026                ZEND_VM_C_GOTO(constant_fetch_end);
4027            } else if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)))) {
4028                ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
4029            } else {
4030                ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op1)), EX_CONSTANT(opline->op1) + 1, 0);
4031                if (UNEXPECTED(EG(exception) != NULL)) {
4032                    HANDLE_EXCEPTION();
4033                }
4034                if (UNEXPECTED(ce == NULL)) {
4035                    zend_error_noreturn(E_ERROR, "Class '%s' not found", Z_STRVAL_P(EX_CONSTANT(opline->op1)));
4036                }
4037                CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce);
4038            }
4039        } else {
4040            ce = Z_CE_P(EX_VAR(opline->op1.var));
4041            if ((value = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce)) != NULL) {
4042                ZVAL_DEREF(value);
4043                ZVAL_DUP(EX_VAR(opline->result.var), value);
4044                ZEND_VM_C_GOTO(constant_fetch_end);
4045            }
4046        }
4047
4048        if (EXPECTED((value = zend_hash_find(&ce->constants_table, Z_STR_P(EX_CONSTANT(opline->op2)))) != NULL)) {
4049            ZVAL_DEREF(value);
4050            if (Z_CONSTANT_P(value)) {
4051                EG(scope) = ce;
4052                zval_update_constant(value, 1);
4053                EG(scope) = EX(func)->op_array.scope;
4054            }
4055            if (OP1_TYPE == IS_CONST) {
4056                CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), value);
4057            } else {
4058                CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce, value);
4059            }
4060            ZVAL_DUP(EX_VAR(opline->result.var), value);
4061        } else if (Z_STRLEN_P(EX_CONSTANT(opline->op2)) == sizeof("class")-1 && memcmp(Z_STRVAL_P(EX_CONSTANT(opline->op2)), "class", sizeof("class") - 1) == 0) {
4062            /* "class" is assigned as a case-sensitive keyword from zend_do_resolve_class_name */
4063            ZVAL_STR_COPY(EX_VAR(opline->result.var), ce->name);
4064        } else {
4065            zend_error_noreturn(E_ERROR, "Undefined class constant '%s'", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
4066        }
4067    }
4068ZEND_VM_C_LABEL(constant_fetch_end):
4069    CHECK_EXCEPTION();
4070    ZEND_VM_NEXT_OPCODE();
4071}
4072
4073ZEND_VM_HANDLER(72, ZEND_ADD_ARRAY_ELEMENT, CONST|TMP|VAR|CV, CONST|TMPVAR|UNUSED|CV)
4074{
4075    USE_OPLINE
4076    zend_free_op free_op1;
4077    zval *expr_ptr, new_expr;
4078
4079    SAVE_OPLINE();
4080    if ((OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) &&
4081        (opline->extended_value & ZEND_ARRAY_ELEMENT_REF)) {
4082        expr_ptr = GET_OP1_ZVAL_PTR_PTR(BP_VAR_W);
4083        if (OP1_TYPE == IS_VAR && UNEXPECTED(expr_ptr == NULL)) {
4084            zend_error_noreturn(E_ERROR, "Cannot create references to/from string offsets");
4085        }
4086        ZVAL_MAKE_REF(expr_ptr);
4087        Z_ADDREF_P(expr_ptr);
4088        FREE_OP1_VAR_PTR();
4089    } else {
4090        expr_ptr = GET_OP1_ZVAL_PTR(BP_VAR_R);
4091        if (OP1_TYPE == IS_TMP_VAR) {
4092            ZVAL_COPY_VALUE(&new_expr, expr_ptr);
4093            expr_ptr = &new_expr;
4094        } else if (OP1_TYPE == IS_CONST) {
4095            if (!Z_IMMUTABLE_P(expr_ptr)) {
4096                ZVAL_DUP(&new_expr, expr_ptr);
4097                expr_ptr = &new_expr;
4098            }
4099        } else if ((OP1_TYPE == IS_CV || OP1_TYPE == IS_VAR) && Z_ISREF_P(expr_ptr)) {
4100            expr_ptr = Z_REFVAL_P(expr_ptr);
4101            if (Z_REFCOUNTED_P(expr_ptr)) Z_ADDREF_P(expr_ptr);
4102            FREE_OP1_IF_VAR();
4103        } else if (OP1_TYPE == IS_CV && Z_REFCOUNTED_P(expr_ptr)) {
4104            Z_ADDREF_P(expr_ptr);
4105        }
4106    }
4107
4108    if (OP2_TYPE != IS_UNUSED) {
4109        zend_free_op free_op2;
4110        zval *offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
4111        zend_string *str;
4112        zend_ulong hval;
4113
4114ZEND_VM_C_LABEL(add_again):
4115        switch (Z_TYPE_P(offset)) {
4116            case IS_DOUBLE:
4117                hval = zend_dval_to_lval(Z_DVAL_P(offset));
4118                ZEND_VM_C_GOTO(num_index);
4119            case IS_LONG:
4120                hval = Z_LVAL_P(offset);
4121ZEND_VM_C_LABEL(num_index):
4122                zend_hash_index_update(Z_ARRVAL_P(EX_VAR(opline->result.var)), hval, expr_ptr);
4123                break;
4124            case IS_STRING:
4125                str = Z_STR_P(offset);
4126                if (OP2_TYPE != IS_CONST) {
4127                    if (ZEND_HANDLE_NUMERIC(str, hval)) {
4128                        ZEND_VM_C_GOTO(num_index);
4129                    }
4130                }
4131ZEND_VM_C_LABEL(str_index):
4132                zend_hash_update(Z_ARRVAL_P(EX_VAR(opline->result.var)), str, expr_ptr);
4133                break;
4134            case IS_NULL:
4135                str = STR_EMPTY_ALLOC();
4136                ZEND_VM_C_GOTO(str_index);
4137            case IS_FALSE:
4138                hval = 0;
4139                ZEND_VM_C_GOTO(num_index);
4140            case IS_TRUE:
4141                hval = 1;
4142                ZEND_VM_C_GOTO(num_index);
4143            case IS_REFERENCE:
4144                offset = Z_REFVAL_P(offset);
4145                ZEND_VM_C_GOTO(add_again);
4146                break;
4147            default:
4148                zend_error(E_WARNING, "Illegal offset type");
4149                zval_ptr_dtor(expr_ptr);
4150                /* do nothing */
4151                break;
4152        }
4153        FREE_OP2();
4154    } else {
4155        zend_hash_next_index_insert(Z_ARRVAL_P(EX_VAR(opline->result.var)), expr_ptr);
4156    }
4157    CHECK_EXCEPTION();
4158    ZEND_VM_NEXT_OPCODE();
4159}
4160
4161ZEND_VM_HANDLER(71, ZEND_INIT_ARRAY, CONST|TMP|VAR|UNUSED|CV, CONST|TMPVAR|UNUSED|CV)
4162{
4163    zval *array;
4164    uint32_t size;
4165    USE_OPLINE
4166
4167    array = EX_VAR(opline->result.var);
4168    if (OP1_TYPE != IS_UNUSED) {
4169        size = opline->extended_value >> ZEND_ARRAY_SIZE_SHIFT;
4170    } else {
4171        size = 0;
4172    }
4173    ZVAL_NEW_ARR(array);
4174    zend_hash_init(Z_ARRVAL_P(array), size, NULL, ZVAL_PTR_DTOR, 0);
4175
4176    if (OP1_TYPE != IS_UNUSED) {
4177        /* Explicitly initialize array as not-packed if flag is set */
4178        if (opline->extended_value & ZEND_ARRAY_NOT_PACKED) {
4179            zend_hash_real_init(Z_ARRVAL_P(array), 0);
4180        }
4181    }
4182
4183    if (OP1_TYPE == IS_UNUSED) {
4184        ZEND_VM_NEXT_OPCODE();
4185#if !defined(ZEND_VM_SPEC) || OP1_TYPE != IS_UNUSED
4186    } else {
4187        ZEND_VM_DISPATCH_TO_HANDLER(ZEND_ADD_ARRAY_ELEMENT);
4188#endif
4189    }
4190}
4191
4192ZEND_VM_HANDLER(21, ZEND_CAST, CONST|TMP|VAR|CV, ANY)
4193{
4194    USE_OPLINE
4195    zend_free_op free_op1;
4196    zval *expr;
4197    zval *result = EX_VAR(opline->result.var);
4198
4199    SAVE_OPLINE();
4200    expr = GET_OP1_ZVAL_PTR(BP_VAR_R);
4201
4202    switch (opline->extended_value) {
4203        case IS_NULL:
4204            /* This code is taken from convert_to_null. However, it does not seems very useful,
4205             * because a conversion to null always results in the same value. This could only
4206             * be relevant if a cast_object handler for IS_NULL has some kind of side-effect. */
4207#if 0
4208            if (OP1_TYPE == IS_VAR || OP1_TYPE == IS_CV) {
4209                ZVAL_DEREF(expr);
4210            }
4211            if (Z_TYPE_P(expr) == IS_OBJECT && Z_OBJ_HT_P(expr)->cast_object) {
4212                if (Z_OBJ_HT_P(expr)->cast_object(expr, result, IS_NULL) == SUCCESS) {
4213                    break;
4214                }
4215            }
4216#endif
4217
4218            ZVAL_NULL(result);
4219            break;
4220        case _IS_BOOL:
4221            ZVAL_BOOL(result, zend_is_true(expr));
4222            break;
4223        case IS_LONG:
4224            ZVAL_LONG(result, zval_get_long(expr));
4225            break;
4226        case IS_DOUBLE:
4227            ZVAL_DOUBLE(result, zval_get_double(expr));
4228            break;
4229        case IS_STRING:
4230            ZVAL_STR(result, zval_get_string(expr));
4231            break;
4232        default:
4233            if (OP1_TYPE & (IS_VAR|IS_CV)) {
4234                ZVAL_DEREF(expr);
4235            }
4236            /* If value is already of correct type, return it directly */
4237            if (Z_TYPE_P(expr) == opline->extended_value) {
4238                ZVAL_COPY_VALUE(result, expr);
4239                if (OP1_TYPE == IS_CONST) {
4240                    if (UNEXPECTED(Z_OPT_COPYABLE_P(result))) {
4241                        zval_copy_ctor_func(result);
4242                    }
4243                } else if (OP1_TYPE != IS_TMP_VAR) {
4244                    if (Z_OPT_REFCOUNTED_P(expr)) Z_ADDREF_P(expr);
4245                }
4246
4247                FREE_OP1_IF_VAR();
4248                CHECK_EXCEPTION();
4249                ZEND_VM_NEXT_OPCODE();
4250            }
4251
4252            if (opline->extended_value == IS_ARRAY) {
4253                if (Z_TYPE_P(expr) != IS_OBJECT) {
4254                    ZVAL_NEW_ARR(result);
4255                    zend_hash_init(Z_ARRVAL_P(result), 8, NULL, ZVAL_PTR_DTOR, 0);
4256                    if (Z_TYPE_P(expr) != IS_NULL) {
4257                        expr = zend_hash_index_add_new(Z_ARRVAL_P(result), 0, expr);
4258                        if (OP1_TYPE == IS_CONST) {
4259                            if (UNEXPECTED(Z_OPT_COPYABLE_P(expr))) {
4260                                zval_copy_ctor_func(expr);
4261                            }
4262                        } else {
4263                            if (Z_OPT_REFCOUNTED_P(expr)) Z_ADDREF_P(expr);
4264                        }
4265                    }
4266                } else {
4267                    ZVAL_COPY_VALUE(result, expr);
4268                    Z_ADDREF_P(result);
4269                    convert_to_array(result);
4270                }
4271            } else {
4272                if (Z_TYPE_P(expr) != IS_ARRAY) {
4273                    object_init(result);
4274                    if (Z_TYPE_P(expr) != IS_NULL) {
4275                        expr = zend_hash_str_add_new(Z_OBJPROP_P(result), "scalar", sizeof("scalar")-1, expr);
4276                        if (OP1_TYPE == IS_CONST) {
4277                            if (UNEXPECTED(Z_OPT_COPYABLE_P(expr))) {
4278                                zval_copy_ctor_func(expr);
4279                            }
4280                        } else {
4281                            if (Z_OPT_REFCOUNTED_P(expr)) Z_ADDREF_P(expr);
4282                        }
4283                    }
4284                } else {
4285                    ZVAL_COPY_VALUE(result, expr);
4286                    zval_opt_copy_ctor(result);
4287                    convert_to_object(result);
4288                }
4289            }
4290    }
4291
4292    FREE_OP1();
4293    CHECK_EXCEPTION();
4294    ZEND_VM_NEXT_OPCODE();
4295}
4296
4297ZEND_VM_HANDLER(73, ZEND_INCLUDE_OR_EVAL, CONST|TMPVAR|CV, ANY)
4298{
4299    USE_OPLINE
4300    zend_op_array *new_op_array=NULL;
4301    zend_free_op free_op1;
4302    zval *inc_filename;
4303    zval tmp_inc_filename;
4304    zend_bool failure_retval=0;
4305
4306    SAVE_OPLINE();
4307    inc_filename = GET_OP1_ZVAL_PTR(BP_VAR_R);
4308
4309    ZVAL_UNDEF(&tmp_inc_filename);
4310    if (Z_TYPE_P(inc_filename) != IS_STRING) {
4311        ZVAL_STR(&tmp_inc_filename, zval_get_string(inc_filename));
4312        inc_filename = &tmp_inc_filename;
4313    }
4314
4315    if (opline->extended_value != ZEND_EVAL && strlen(Z_STRVAL_P(inc_filename)) != Z_STRLEN_P(inc_filename)) {
4316        if (opline->extended_value == ZEND_INCLUDE_ONCE || opline->extended_value == ZEND_INCLUDE) {
4317            zend_message_dispatcher(ZMSG_FAILED_INCLUDE_FOPEN, Z_STRVAL_P(inc_filename));
4318        } else {
4319            zend_message_dispatcher(ZMSG_FAILED_REQUIRE_FOPEN, Z_STRVAL_P(inc_filename));
4320        }
4321    } else {
4322        switch (opline->extended_value) {
4323            case ZEND_INCLUDE_ONCE:
4324            case ZEND_REQUIRE_ONCE: {
4325                    zend_file_handle file_handle;
4326                    char *resolved_path;
4327
4328                    resolved_path = zend_resolve_path(Z_STRVAL_P(inc_filename), (int)Z_STRLEN_P(inc_filename));
4329                    if (resolved_path) {
4330                        failure_retval = zend_hash_str_exists(&EG(included_files), resolved_path, (int)strlen(resolved_path));
4331                    } else {
4332                        resolved_path = Z_STRVAL_P(inc_filename);
4333                    }
4334
4335                    if (failure_retval) {
4336                        /* do nothing, file already included */
4337                    } else if (SUCCESS == zend_stream_open(resolved_path, &file_handle)) {
4338
4339                        if (!file_handle.opened_path) {
4340                            file_handle.opened_path = estrdup(resolved_path);
4341                        }
4342
4343                        if (zend_hash_str_add_empty_element(&EG(included_files), file_handle.opened_path, (int)strlen(file_handle.opened_path))) {
4344                            new_op_array = zend_compile_file(&file_handle, (opline->extended_value==ZEND_INCLUDE_ONCE?ZEND_INCLUDE:ZEND_REQUIRE));
4345                            zend_destroy_file_handle(&file_handle);
4346                        } else {
4347                            zend_file_handle_dtor(&file_handle);
4348                            failure_retval=1;
4349                        }
4350                    } else {
4351                        if (opline->extended_value == ZEND_INCLUDE_ONCE) {
4352                            zend_message_dispatcher(ZMSG_FAILED_INCLUDE_FOPEN, Z_STRVAL_P(inc_filename));
4353                        } else {
4354                            zend_message_dispatcher(ZMSG_FAILED_REQUIRE_FOPEN, Z_STRVAL_P(inc_filename));
4355                        }
4356                    }
4357                    if (resolved_path != Z_STRVAL_P(inc_filename)) {
4358                        efree(resolved_path);
4359                    }
4360                }
4361                break;
4362            case ZEND_INCLUDE:
4363            case ZEND_REQUIRE:
4364                new_op_array = compile_filename(opline->extended_value, inc_filename);
4365                break;
4366            case ZEND_EVAL: {
4367                    char *eval_desc = zend_make_compiled_string_description("eval()'d code");
4368
4369                    new_op_array = zend_compile_string(inc_filename, eval_desc);
4370                    efree(eval_desc);
4371                }
4372                break;
4373            EMPTY_SWITCH_DEFAULT_CASE()
4374        }
4375    }
4376    if (Z_TYPE(tmp_inc_filename) != IS_UNDEF) {
4377        zend_string_release(Z_STR(tmp_inc_filename));
4378    }
4379    FREE_OP1();
4380    if (UNEXPECTED(EG(exception) != NULL)) {
4381        HANDLE_EXCEPTION();
4382    } else if (EXPECTED(new_op_array != NULL)) {
4383        zval *return_value = NULL;
4384        zend_execute_data *call;
4385
4386        if (RETURN_VALUE_USED(opline)) {
4387            return_value = EX_VAR(opline->result.var);
4388        }
4389
4390        new_op_array->scope = EG(scope); /* ??? */
4391
4392        call = zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_CODE,
4393            (zend_function*)new_op_array, 0, EX(called_scope), Z_OBJ(EX(This)), NULL);
4394
4395        if (EX(symbol_table)) {
4396            call->symbol_table = EX(symbol_table);
4397        } else {
4398            call->symbol_table = zend_rebuild_symbol_table();
4399        }
4400
4401        call->prev_execute_data = execute_data;
4402        i_init_code_execute_data(call, new_op_array, return_value);
4403        if (EXPECTED(zend_execute_ex == execute_ex)) {
4404            ZEND_VM_ENTER();
4405        } else {
4406            ZEND_ADD_CALL_FLAG(call, ZEND_CALL_TOP);
4407            zend_execute_ex(call);
4408        }
4409
4410        destroy_op_array(new_op_array);
4411        efree_size(new_op_array, sizeof(zend_op_array));
4412        if (UNEXPECTED(EG(exception) != NULL)) {
4413            zend_throw_exception_internal(NULL);
4414            HANDLE_EXCEPTION();
4415        }
4416
4417    } else if (RETURN_VALUE_USED(opline)) {
4418        ZVAL_BOOL(EX_VAR(opline->result.var), failure_retval);
4419    }
4420    ZEND_VM_NEXT_OPCODE();
4421}
4422
4423ZEND_VM_HANDLER(74, ZEND_UNSET_VAR, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
4424{
4425    USE_OPLINE
4426    zval tmp, *varname;
4427    HashTable *target_symbol_table;
4428    zend_free_op free_op1;
4429
4430    SAVE_OPLINE();
4431    if (OP1_TYPE == IS_CV &&
4432        OP2_TYPE == IS_UNUSED &&
4433        (opline->extended_value & ZEND_QUICK_SET)) {
4434        zval *var = EX_VAR(opline->op1.var);
4435
4436        if (Z_REFCOUNTED_P(var)) {
4437            zend_refcounted *garbage = Z_COUNTED_P(var);
4438
4439            if (!--GC_REFCOUNT(garbage)) {
4440                ZVAL_UNDEF(var);
4441                _zval_dtor_func_for_ptr(garbage ZEND_FILE_LINE_CC);
4442            } else {
4443                GC_ZVAL_CHECK_POSSIBLE_ROOT(var);
4444                ZVAL_UNDEF(var);
4445            }
4446        } else {
4447            ZVAL_UNDEF(var);
4448        }
4449        CHECK_EXCEPTION();
4450        ZEND_VM_NEXT_OPCODE();
4451    }
4452
4453    varname = GET_OP1_ZVAL_PTR(BP_VAR_R);
4454
4455    ZVAL_UNDEF(&tmp);
4456    if (OP1_TYPE != IS_CONST && Z_TYPE_P(varname) != IS_STRING) {
4457        ZVAL_STR(&tmp, zval_get_string(varname));
4458        varname = &tmp;
4459    }
4460
4461    if (OP2_TYPE != IS_UNUSED) {
4462        zend_class_entry *ce;
4463
4464        if (OP2_TYPE == IS_CONST) {
4465            if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) {
4466                ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
4467            } else {
4468                ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op2)), EX_CONSTANT(opline->op2) + 1, 0);
4469                if (UNEXPECTED(EG(exception) != NULL)) {
4470                    if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
4471                        zend_string_release(Z_STR(tmp));
4472                    }
4473                    FREE_OP1();
4474                    HANDLE_EXCEPTION();
4475                }
4476                if (UNEXPECTED(ce == NULL)) {
4477                    zend_error_noreturn(E_ERROR, "Class '%s' not found", Z_STRVAL_P(EX_CONSTANT(opline->op2)));
4478                }
4479                CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce);
4480            }
4481        } else {
4482            ce = Z_CE_P(EX_VAR(opline->op2.var));
4483        }
4484        zend_std_unset_static_property(ce, Z_STR_P(varname));
4485    } else {
4486        target_symbol_table = zend_get_target_symbol_table(execute_data, opline->extended_value & ZEND_FETCH_TYPE_MASK);
4487        zend_hash_del_ind(target_symbol_table, Z_STR_P(varname));
4488    }
4489
4490    if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
4491        zend_string_release(Z_STR(tmp));
4492    }
4493    FREE_OP1();
4494    CHECK_EXCEPTION();
4495    ZEND_VM_NEXT_OPCODE();
4496}
4497
4498ZEND_VM_HANDLER(75, ZEND_UNSET_DIM, VAR|UNUSED|CV, CONST|TMPVAR|CV)
4499{
4500    USE_OPLINE
4501    zend_free_op free_op1, free_op2;
4502    zval *container;
4503    zval *offset;
4504    zend_ulong hval;
4505
4506    SAVE_OPLINE();
4507    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_UNSET);
4508    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
4509        zend_error_noreturn(E_ERROR, "Cannot unset string offsets");
4510    }
4511    offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
4512
4513ZEND_VM_C_LABEL(unset_dim_again):
4514    if (OP1_TYPE != IS_UNUSED && EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
4515        HashTable *ht;
4516
4517ZEND_VM_C_LABEL(offset_again):
4518        SEPARATE_ARRAY(container);
4519        ht = Z_ARRVAL_P(container);
4520        switch (Z_TYPE_P(offset)) {
4521            case IS_DOUBLE:
4522                hval = zend_dval_to_lval(Z_DVAL_P(offset));
4523                zend_hash_index_del(ht, hval);
4524                break;
4525            case IS_LONG:
4526                hval = Z_LVAL_P(offset);
4527ZEND_VM_C_LABEL(num_index_dim):
4528                zend_hash_index_del(ht, hval);
4529                break;
4530            case IS_STRING:
4531                if (OP2_TYPE != IS_CONST) {
4532                    if (ZEND_HANDLE_NUMERIC(Z_STR_P(offset), hval)) {
4533                        ZEND_VM_C_GOTO(num_index_dim);
4534                    }
4535                }
4536                if (ht == &EG(symbol_table).ht) {
4537                    zend_delete_global_variable(Z_STR_P(offset));
4538                } else {
4539                    zend_hash_del(ht, Z_STR_P(offset));
4540                }
4541                break;
4542            case IS_NULL:
4543                zend_hash_del(ht, STR_EMPTY_ALLOC());
4544                break;
4545            case IS_FALSE:
4546                hval = 0;
4547                ZEND_VM_C_GOTO(num_index_dim);
4548            case IS_TRUE:
4549                hval = 1;
4550                ZEND_VM_C_GOTO(num_index_dim);
4551            case IS_RESOURCE:
4552                hval = Z_RES_HANDLE_P(offset);
4553                ZEND_VM_C_GOTO(num_index_dim);
4554            case IS_REFERENCE:
4555                offset = Z_REFVAL_P(offset);
4556                ZEND_VM_C_GOTO(offset_again);
4557                break;
4558            default:
4559                zend_error(E_WARNING, "Illegal offset type in unset");
4560                break;
4561        }
4562        FREE_OP2();
4563    } else if (OP1_TYPE == IS_UNUSED || EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
4564        if (UNEXPECTED(Z_OBJ_HT_P(container)->unset_dimension == NULL)) {
4565            zend_error_noreturn(E_ERROR, "Cannot use object as array");
4566        }
4567//???       if (OP2_TYPE == IS_CONST) {
4568//???           zval_copy_ctor(offset);
4569//???       }
4570        Z_OBJ_HT_P(container)->unset_dimension(container, offset);
4571        FREE_OP2();
4572    } else if (OP1_TYPE != IS_UNUSED && Z_ISREF_P(container)) {
4573        container = Z_REFVAL_P(container);
4574        ZEND_VM_C_GOTO(unset_dim_again);
4575    } else if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) == IS_STRING)) {
4576        zend_error_noreturn(E_ERROR, "Cannot unset string offsets");
4577        ZEND_VM_CONTINUE(); /* bailed out before */
4578    } else {
4579        FREE_OP2();
4580    }
4581    FREE_OP1_VAR_PTR();
4582    CHECK_EXCEPTION();
4583    ZEND_VM_NEXT_OPCODE();
4584}
4585
4586ZEND_VM_HANDLER(76, ZEND_UNSET_OBJ, VAR|UNUSED|CV, CONST|TMPVAR|CV)
4587{
4588    USE_OPLINE
4589    zend_free_op free_op1, free_op2;
4590    zval *container;
4591    zval *offset;
4592
4593    SAVE_OPLINE();
4594    container = GET_OP1_OBJ_ZVAL_PTR_PTR(BP_VAR_UNSET);
4595    if (OP1_TYPE == IS_VAR && UNEXPECTED(container == NULL)) {
4596        zend_error_noreturn(E_ERROR, "Cannot unset string offsets");
4597    }
4598    offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
4599
4600    do {
4601        if (OP1_TYPE != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
4602            if (Z_ISREF_P(container)) {
4603                container = Z_REFVAL_P(container);
4604                if (Z_TYPE_P(container) != IS_OBJECT) {
4605                    break;
4606                }
4607            } else {
4608                break;
4609            }
4610        }
4611        if (Z_OBJ_HT_P(container)->unset_property) {
4612            Z_OBJ_HT_P(container)->unset_property(container, offset, ((OP2_TYPE == IS_CONST) ? (EX_RUN_TIME_CACHE() + Z_CACHE_SLOT_P(offset)) : NULL));
4613        } else {
4614            zend_error(E_NOTICE, "Trying to unset property of non-object");
4615        }
4616    } while (0);
4617
4618    FREE_OP2();
4619    FREE_OP1_VAR_PTR();
4620    CHECK_EXCEPTION();
4621    ZEND_VM_NEXT_OPCODE();
4622}
4623
4624ZEND_VM_HANDLER(77, ZEND_FE_RESET, CONST|TMP|VAR|CV, ANY)
4625{
4626    USE_OPLINE
4627    zend_free_op free_op1;
4628    zval *array_ptr, *array_ref, iterator, tmp;
4629    HashTable *fe_ht;
4630    zend_object_iterator *iter = NULL;
4631    zend_class_entry *ce = NULL;
4632    zend_bool is_empty = 0;
4633
4634    SAVE_OPLINE();
4635
4636    if ((OP1_TYPE == IS_CV || OP1_TYPE == IS_VAR) &&
4637        (opline->extended_value & ZEND_FE_FETCH_BYREF)) {
4638        array_ptr = array_ref = GET_OP1_ZVAL_PTR_PTR(BP_VAR_R);
4639        ZVAL_DEREF(array_ptr);
4640        if (Z_TYPE_P(array_ptr) == IS_ARRAY) {
4641            SEPARATE_ARRAY(array_ptr);
4642            if (!Z_ISREF_P(array_ref)) {
4643                ZVAL_NEW_REF(array_ref, array_ref);
4644                array_ptr = Z_REFVAL_P(array_ref);
4645            }
4646            if (Z_REFCOUNTED_P(array_ref)) Z_ADDREF_P(array_ref);
4647        } else if (Z_TYPE_P(array_ptr) == IS_OBJECT) {
4648            ce = Z_OBJCE_P(array_ptr);
4649            if (ce->get_iterator == NULL) {
4650                Z_ADDREF_P(array_ptr);
4651            }
4652            array_ref = array_ptr;
4653        } else {
4654            if (Z_REFCOUNTED_P(array_ref)) Z_ADDREF_P(array_ref);
4655        }
4656    } else {
4657        array_ptr = array_ref = GET_OP1_ZVAL_PTR(BP_VAR_R);
4658        if (OP1_TYPE & (IS_VAR|IS_CV)) {
4659            ZVAL_DEREF(array_ptr);
4660        }
4661        if (OP1_TYPE == IS_TMP_VAR) {
4662            ZVAL_COPY_VALUE(&tmp, array_ptr);
4663            if (Z_OPT_IMMUTABLE_P(&tmp)) {
4664                zval_copy_ctor_func(&tmp);
4665            }
4666            array_ref = array_ptr = &tmp;
4667            if (Z_TYPE_P(array_ptr) == IS_OBJECT) {
4668                ce = Z_OBJCE_P(array_ptr);
4669                if (ce && ce->get_iterator) {
4670                    Z_DELREF_P(array_ref);
4671                }
4672            }
4673        } else if (Z_TYPE_P(array_ptr) == IS_OBJECT) {
4674            ce = Z_OBJCE_P(array_ptr);
4675            if (!ce->get_iterator) {
4676                if (OP1_TYPE == IS_CV) {
4677                    Z_ADDREF_P(array_ref);
4678                }
4679            }
4680        } else if (Z_IMMUTABLE_P(array_ref)) {
4681            if (OP1_TYPE == IS_CV) {
4682                zval_copy_ctor_func(array_ref);
4683                Z_ADDREF_P(array_ref);
4684            } else {
4685                ZVAL_COPY_VALUE(&tmp, array_ref);
4686                zval_copy_ctor_func(&tmp);
4687                array_ptr = array_ref = &tmp;
4688            }
4689        } else if (Z_REFCOUNTED_P(array_ref)) {
4690            if (OP1_TYPE == IS_CONST ||
4691                       (OP1_TYPE == IS_CV &&
4692                        !Z_ISREF_P(array_ref) &&
4693                        Z_REFCOUNT_P(array_ref) > 1) ||
4694                       (OP1_TYPE == IS_VAR &&
4695                        !Z_ISREF_P(array_ref) &&
4696                        Z_REFCOUNT_P(array_ref) > 2)) {
4697                if (OP1_TYPE == IS_VAR) {
4698                    Z_DELREF_P(array_ref);
4699                }
4700                ZVAL_DUP(&tmp, array_ref);
4701                array_ptr = array_ref = &tmp;
4702            } else if (OP1_TYPE == IS_CV || OP1_TYPE == IS_VAR) {
4703                if (Z_ISREF_P(array_ref) && Z_REFCOUNT_P(array_ref) == 1) {
4704                    ZVAL_UNREF(array_ref);
4705                    array_ptr = array_ref;
4706                }
4707                if (Z_IMMUTABLE_P(array_ptr)) {
4708                    zval_copy_ctor_func(array_ptr);
4709                } else if (Z_ISREF_P(array_ref) &&
4710                           Z_COPYABLE_P(array_ptr) &&
4711                           Z_REFCOUNT_P(array_ptr) > 1) {
4712                    Z_DELREF_P(array_ptr);
4713                    zval_copy_ctor_func(array_ptr);
4714                }
4715                if (OP1_TYPE == IS_CV) {
4716                    Z_ADDREF_P(array_ref);
4717                }
4718            }
4719        }
4720    }
4721
4722    if (ce && ce->get_iterator) {
4723        iter = ce->get_iterator(ce, array_ptr, opline->extended_value & ZEND_FE_FETCH_BYREF);
4724
4725        if (OP1_TYPE == IS_VAR && !(opline->extended_value & ZEND_FE_FETCH_BYREF)) {
4726            FREE_OP1_IF_VAR();
4727        }
4728        if (iter && EXPECTED(EG(exception) == NULL)) {
4729            ZVAL_OBJ(&iterator, &iter->std);
4730            array_ptr = array_ref = &iterator;
4731        } else {
4732            if (OP1_TYPE == IS_VAR && opline->extended_value & ZEND_FE_FETCH_BYREF) {
4733                FREE_OP1_VAR_PTR();
4734            }
4735            if (!EG(exception)) {
4736                zend_throw_exception_ex(NULL, 0, "Object of type %s did not create an Iterator", ce->name->val);
4737            }
4738            zend_throw_exception_internal(NULL);
4739            HANDLE_EXCEPTION();
4740        }
4741    }
4742
4743    ZVAL_COPY_VALUE(EX_VAR(opline->result.var), array_ref);
4744
4745    if (iter) {
4746        iter->index = 0;
4747        if (iter->funcs->rewind) {
4748            iter->funcs->rewind(iter);
4749            if (UNEXPECTED(EG(exception) != NULL)) {
4750                zval_ptr_dtor(array_ref);
4751                if (OP1_TYPE == IS_VAR && opline->extended_value & ZEND_FE_FETCH_BYREF) {
4752                    FREE_OP1_VAR_PTR();
4753                }
4754                HANDLE_EXCEPTION();
4755            }
4756        }
4757        is_empty = iter->funcs->valid(iter) != SUCCESS;
4758        if (UNEXPECTED(EG(exception) != NULL)) {
4759            zval_ptr_dtor(array_ref);
4760            if (OP1_TYPE == IS_VAR && opline->extended_value & ZEND_FE_FETCH_BYREF) {
4761                FREE_OP1_VAR_PTR();
4762            }
4763            HANDLE_EXCEPTION();
4764        }
4765        iter->index = -1; /* will be set to 0 before using next handler */
4766    } else if ((fe_ht = HASH_OF(array_ptr)) != NULL) {
4767        HashPointer *ptr = (HashPointer*)EX_VAR((opline+2)->op1.var);
4768        HashPosition pos = 0;
4769        Bucket *p;
4770
4771        while (1) {
4772            if (pos >= fe_ht->nNumUsed) {
4773                is_empty = 1;
4774                if (OP1_TYPE == IS_VAR && opline->extended_value & ZEND_FE_FETCH_BYREF) {
4775                    FREE_OP1_VAR_PTR();
4776                }
4777                ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
4778            }
4779            p = fe_ht->arData + pos;
4780            if (Z_TYPE(p->val) == IS_UNDEF ||
4781                (Z_TYPE(p->val) == IS_INDIRECT &&
4782                 Z_TYPE_P(Z_INDIRECT(p->val)) == IS_UNDEF)) {
4783                pos++;
4784                continue;
4785            }
4786            if (!ce ||
4787                !p->key ||
4788                zend_check_property_access(Z_OBJ_P(array_ptr), p->key) == SUCCESS) {
4789                break;
4790            }
4791            pos++;
4792        }
4793        fe_ht->nInternalPointer = pos;
4794        ptr->pos = pos;
4795        ptr->ht = fe_ht;
4796        ptr->h = fe_ht->arData[pos].h;
4797        ptr->key = fe_ht->arData[pos].key;
4798        is_empty = 0;
4799    } else {
4800        zend_error(E_WARNING, "Invalid argument supplied for foreach()");
4801        is_empty = 1;
4802    }
4803
4804    if (OP1_TYPE == IS_VAR && opline->extended_value & ZEND_FE_FETCH_BYREF) {
4805        FREE_OP1_VAR_PTR();
4806    }
4807    if (is_empty) {
4808        ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
4809    } else {
4810        CHECK_EXCEPTION();
4811        ZEND_VM_NEXT_OPCODE();
4812    }
4813}
4814
4815ZEND_VM_HANDLER(78, ZEND_FE_FETCH, VAR, ANY)
4816{
4817    USE_OPLINE
4818    zend_free_op free_op1;
4819    zval *array, *array_ref;
4820    zval *value;
4821    HashTable *fe_ht;
4822    HashPointer *ptr;
4823    HashPosition pos;
4824    Bucket *p;
4825
4826    array = array_ref = EX_VAR(opline->op1.var);
4827    if (Z_ISREF_P(array)) {
4828        array = Z_REFVAL_P(array);
4829        // TODO: referenced value might be changed to different array ???
4830        if (Z_IMMUTABLE_P(array)) {
4831            zval_copy_ctor_func(array);
4832        }
4833    }
4834
4835    SAVE_OPLINE();
4836
4837    if (EXPECTED(Z_TYPE_P(array) == IS_ARRAY)) {
4838        fe_ht = Z_ARRVAL_P(array);
4839        ptr = (HashPointer*)EX_VAR((opline+1)->op1.var);
4840        pos = ptr->pos;
4841        if (UNEXPECTED(pos == INVALID_IDX)) {
4842            /* reached end of iteration */
4843            ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
4844        } else if (UNEXPECTED(ptr->ht != fe_ht)) {
4845            ptr->ht = fe_ht;
4846            pos = 0;
4847        } else if (UNEXPECTED(fe_ht->nInternalPointer != ptr->pos)) {
4848            if (fe_ht->u.flags & HASH_FLAG_PACKED) {
4849                pos = ptr->h;
4850            } else {
4851                pos = fe_ht->arHash[ptr->h & fe_ht->nTableMask];
4852                while (1) {
4853                    if (pos == INVALID_IDX) {
4854                        pos = fe_ht->nInternalPointer;
4855                        break;
4856                    } else if (fe_ht->arData[pos].h == ptr->h && fe_ht->arData[pos].key == ptr->key) {
4857                        break;
4858                    }
4859                    pos = Z_NEXT(fe_ht->arData[pos].val);
4860                }
4861            }
4862        }
4863        while (1) {
4864            if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
4865                /* reached end of iteration */
4866                ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
4867            }
4868            p = fe_ht->arData + pos;
4869            value = &p->val;
4870            if (UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
4871                pos++;
4872                continue;
4873            } else if (UNEXPECTED(Z_TYPE_P(value) == IS_INDIRECT)) {
4874                value = Z_INDIRECT_P(value);
4875                if (UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
4876                    pos++;
4877                    continue;
4878                }
4879            }
4880            if (opline->extended_value & ZEND_FE_FETCH_BYREF) {
4881                ZVAL_MAKE_REF(value);
4882                Z_ADDREF_P(value);
4883                ZVAL_REF(EX_VAR(opline->result.var), Z_REF_P(value));
4884            } else {
4885                ZVAL_COPY(EX_VAR(opline->result.var), value);
4886            }
4887            if (opline->extended_value & ZEND_FE_FETCH_WITH_KEY) {
4888                if (!p->key) {
4889                    ZVAL_LONG(EX_VAR((opline+1)->result.var), p->h);
4890                } else {
4891                    ZVAL_STR_COPY(EX_VAR((opline+1)->result.var), p->key);
4892                }
4893            }
4894            break;
4895        }
4896        do {
4897            pos++;
4898            if (pos >= fe_ht->nNumUsed) {
4899                fe_ht->nInternalPointer = ptr->pos = INVALID_IDX;
4900                ZEND_VM_INC_OPCODE();
4901                ZEND_VM_NEXT_OPCODE();
4902            }
4903            p = fe_ht->arData + pos;
4904        } while (Z_TYPE(p->val) == IS_UNDEF ||
4905                 (Z_TYPE(p->val) == IS_INDIRECT &&
4906                  Z_TYPE_P(Z_INDIRECT(p->val)) == IS_UNDEF));
4907        fe_ht->nInternalPointer = ptr->pos = pos;
4908        ptr->h = fe_ht->arData[pos].h;
4909        ptr->key = fe_ht->arData[pos].key;
4910        ZEND_VM_INC_OPCODE();
4911        ZEND_VM_NEXT_OPCODE();
4912    } else if (EXPECTED(Z_TYPE_P(array) == IS_OBJECT)) {
4913        zend_object_iterator *iter;
4914
4915        if ((iter = zend_iterator_unwrap(array)) == NULL) {
4916            /* plain object */
4917            zend_object *zobj = Z_OBJ_P(array);
4918
4919            fe_ht = Z_OBJPROP_P(array);
4920            ptr = (HashPointer*)EX_VAR((opline+1)->op1.var);
4921            pos = ptr->pos;
4922            if (pos == INVALID_IDX) {
4923                /* reached end of iteration */
4924                ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
4925            } else if (UNEXPECTED(ptr->ht != fe_ht)) {
4926                ptr->ht = fe_ht;
4927                pos = 0;
4928            } else if (UNEXPECTED(fe_ht->nInternalPointer != ptr->pos)) {
4929                if (fe_ht->u.flags & HASH_FLAG_PACKED) {
4930                    pos = ptr->h;
4931                } else {
4932                    pos = fe_ht->arHash[ptr->h & fe_ht->nTableMask];
4933                    while (1) {
4934                        if (pos == INVALID_IDX) {
4935                            pos = fe_ht->nInternalPointer;
4936                            break;
4937                        } else if (fe_ht->arData[pos].h == ptr->h && fe_ht->arData[pos].key == ptr->key) {
4938                            break;
4939                        }
4940                        pos = Z_NEXT(fe_ht->arData[pos].val);
4941                    }
4942                }
4943            }
4944            while (1) {
4945                if (UNEXPECTED(pos >= fe_ht->nNumUsed)) {
4946                    /* reached end of iteration */
4947                    ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
4948                }
4949
4950                p = fe_ht->arData + pos;
4951                value = &p->val;
4952                if (UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
4953                    pos++;
4954                    continue;
4955                } else if (UNEXPECTED(Z_TYPE_P(value) == IS_INDIRECT)) {
4956                    value = Z_INDIRECT_P(value);
4957                    if (UNEXPECTED(Z_TYPE_P(value) == IS_UNDEF)) {
4958                        pos++;
4959                        continue;
4960                    }
4961                }
4962
4963                if (UNEXPECTED(!p->key)) {
4964                    if (opline->extended_value & ZEND_FE_FETCH_WITH_KEY) {
4965                        ZVAL_LONG(EX_VAR((opline+1)->result.var), p->h);
4966                    }
4967                    break;
4968                } else if (zend_check_property_access(zobj, p->key) == SUCCESS) {
4969                    if (opline->extended_value & ZEND_FE_FETCH_WITH_KEY) {
4970                        if (p->key->val[0]) {
4971                            ZVAL_STR_COPY(EX_VAR((opline+1)->result.var), p->key);
4972                        } else {
4973                            const char *class_name, *prop_name;
4974                            size_t prop_name_len;
4975                            zend_unmangle_property_name_ex(
4976                                p->key, &class_name, &prop_name, &prop_name_len);
4977                            ZVAL_STRINGL(EX_VAR((opline+1)->result.var), prop_name, prop_name_len);
4978                        }
4979                    }
4980                    break;
4981                }
4982                pos++;
4983            }
4984            if (opline->extended_value & ZEND_FE_FETCH_BYREF) {
4985                ZVAL_MAKE_REF(value);
4986                Z_ADDREF_P(value);
4987                ZVAL_REF(EX_VAR(opline->result.var), Z_REF_P(value));
4988            } else {
4989                ZVAL_COPY(EX_VAR(opline->result.var), value);
4990            }
4991            do {
4992                pos++;
4993                if (pos >= fe_ht->nNumUsed) {
4994                    fe_ht->nInternalPointer = ptr->pos = INVALID_IDX;
4995                    ZEND_VM_INC_OPCODE();
4996                    ZEND_VM_NEXT_OPCODE();
4997                }
4998                p = fe_ht->arData + pos;
4999            } while (Z_TYPE(p->val) == IS_UNDEF ||
5000                     (Z_TYPE(p->val) == IS_INDIRECT &&
5001                      Z_TYPE_P(Z_INDIRECT(p->val)) == IS_UNDEF) ||
5002                     (EXPECTED(p->key != NULL) &&
5003                      zend_check_property_access(zobj, p->key) == FAILURE));
5004            fe_ht->nInternalPointer = ptr->pos = pos;
5005            ptr->h = fe_ht->arData[pos].h;
5006            ptr->key = fe_ht->arData[pos].key;
5007            ZEND_VM_INC_OPCODE();
5008            ZEND_VM_NEXT_OPCODE();
5009        } else {
5010            /* !iter happens from exception */
5011            if (iter && ++iter->index > 0) {
5012                /* This could cause an endless loop if index becomes zero again.
5013                 * In case that ever happens we need an additional flag. */
5014                iter->funcs->move_forward(iter);
5015                if (UNEXPECTED(EG(exception) != NULL)) {
5016                    zval_ptr_dtor(array_ref);
5017                    HANDLE_EXCEPTION();
5018                }
5019            }
5020            /* If index is zero we come from FE_RESET and checked valid() already. */
5021            if (!iter || (iter->index > 0 && iter->funcs->valid(iter) == FAILURE)) {
5022                /* reached end of iteration */
5023                if (UNEXPECTED(EG(exception) != NULL)) {
5024                    zval_ptr_dtor(array_ref);
5025                    HANDLE_EXCEPTION();
5026                }
5027                ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
5028            }
5029            value = iter->funcs->get_current_data(iter);
5030            if (UNEXPECTED(EG(exception) != NULL)) {
5031                zval_ptr_dtor(array_ref);
5032                HANDLE_EXCEPTION();
5033            }
5034            if (!value) {
5035                /* failure in get_current_data */
5036                ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
5037            }
5038            if (opline->extended_value & ZEND_FE_FETCH_BYREF) {
5039                ZVAL_MAKE_REF(value);
5040                Z_ADDREF_P(value);
5041                ZVAL_REF(EX_VAR(opline->result.var), Z_REF_P(value));
5042            } else {
5043                ZVAL_COPY(EX_VAR(opline->result.var), value);
5044            }
5045            if (opline->extended_value & ZEND_FE_FETCH_WITH_KEY) {
5046                if (iter->funcs->get_current_key) {
5047                    iter->funcs->get_current_key(iter, EX_VAR((opline+1)->result.var));
5048                    if (UNEXPECTED(EG(exception) != NULL)) {
5049                        zval_ptr_dtor(array_ref);
5050                        HANDLE_EXCEPTION();
5051                    }
5052                } else {
5053                    ZVAL_LONG(EX_VAR((opline+1)->result.var), iter->index);
5054                }
5055            }
5056            ZEND_VM_INC_OPCODE();
5057            ZEND_VM_NEXT_OPCODE();
5058        }
5059    } else {
5060        zend_error(E_WARNING, "Invalid argument supplied for foreach()");
5061        ZEND_VM_JMP(OP_JMP_ADDR(opline, opline->op2));
5062    }
5063}
5064
5065ZEND_VM_HANDLER(114, ZEND_ISSET_ISEMPTY_VAR, CONST|TMPVAR|CV, UNUSED|CONST|VAR)
5066{
5067    USE_OPLINE
5068    zval *value;
5069
5070    SAVE_OPLINE();
5071    if (OP1_TYPE == IS_CV &&
5072        OP2_TYPE == IS_UNUSED &&
5073        (opline->extended_value & ZEND_QUICK_SET)) {
5074        value = EX_VAR(opline->op1.var);
5075        if (opline->extended_value & ZEND_ISSET) {
5076            ZVAL_BOOL(EX_VAR(opline->result.var),
5077                Z_TYPE_P(value) > IS_NULL &&
5078                (!Z_ISREF_P(value) || Z_TYPE_P(Z_REFVAL_P(value)) != IS_NULL));
5079        } else /* if (opline->extended_value & ZEND_ISEMPTY) */ {
5080            ZVAL_BOOL(EX_VAR(opline->result.var),
5081                !i_zend_is_true(value));
5082            CHECK_EXCEPTION();
5083        }
5084        ZEND_VM_NEXT_OPCODE();
5085    } else {
5086        zend_free_op free_op1;
5087        zval tmp, *varname = GET_OP1_ZVAL_PTR(BP_VAR_IS);
5088
5089        ZVAL_UNDEF(&tmp);
5090        if (OP1_TYPE != IS_CONST && Z_TYPE_P(varname) != IS_STRING) {
5091            ZVAL_STR(&tmp, zval_get_string(varname));
5092            varname = &tmp;
5093        }
5094
5095        if (OP2_TYPE != IS_UNUSED) {
5096            zend_class_entry *ce;
5097
5098            if (OP2_TYPE == IS_CONST) {
5099                if (OP1_TYPE == IS_CONST && CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)))) {
5100
5101                    ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)));
5102                    value = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)) + 1);
5103
5104                    /* check if static properties were destoyed */
5105                    if (UNEXPECTED(CE_STATIC_MEMBERS(ce) == NULL)) {
5106                        zend_error_noreturn(E_ERROR, "Access to undeclared static property: %s::$%s", ce->name->val, Z_STR_P(varname));
5107                    }
5108
5109                    ZEND_VM_C_GOTO(is_var_return);
5110                } else if (CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)))) {
5111                    ce = CACHED_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)));
5112                } else {
5113                    ce = zend_fetch_class_by_name(Z_STR_P(EX_CONSTANT(opline->op2)), EX_CONSTANT(opline->op2) + 1, 0);
5114                    if (UNEXPECTED(ce == NULL)) {
5115                        CHECK_EXCEPTION();
5116                        ZEND_VM_NEXT_OPCODE();
5117                    }
5118                    CACHE_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op2)), ce);
5119                }
5120            } else {
5121                ce = Z_CE_P(EX_VAR(opline->op2.var));
5122                if (OP1_TYPE == IS_CONST &&
5123                    (value = CACHED_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce)) != NULL) {
5124
5125                    /* check if static properties were destoyed */
5126                    if (UNEXPECTED(CE_STATIC_MEMBERS(ce) == NULL)) {
5127                        zend_error_noreturn(E_ERROR, "Access to undeclared static property: %s::$%s", ce->name->val, Z_STR_P(varname));
5128                    }
5129
5130                    ZEND_VM_C_GOTO(is_var_return);
5131                }
5132            }
5133
5134            value = zend_std_get_static_property(ce, Z_STR_P(varname), 1);
5135
5136            if (OP1_TYPE == IS_CONST && value) {
5137                CACHE_POLYMORPHIC_PTR(Z_CACHE_SLOT_P(EX_CONSTANT(opline->op1)), ce, value);
5138            }
5139        } else {
5140            HashTable *target_symbol_table = zend_get_target_symbol_table(execute_data, opline->extended_value & ZEND_FETCH_TYPE_MASK);
5141            value = zend_hash_find_ind(target_symbol_table, Z_STR_P(varname));
5142        }
5143
5144        if (OP1_TYPE != IS_CONST && Z_TYPE(tmp) != IS_UNDEF) {
5145            zend_string_release(Z_STR(tmp));
5146        }
5147        FREE_OP1();
5148
5149ZEND_VM_C_LABEL(is_var_return):
5150        if (opline->extended_value & ZEND_ISSET) {
5151            ZVAL_BOOL(EX_VAR(opline->result.var),
5152                value && Z_TYPE_P(value) > IS_NULL &&
5153                (!Z_ISREF_P(value) || Z_TYPE_P(Z_REFVAL_P(value)) != IS_NULL));
5154        } else /* if (opline->extended_value & ZEND_ISEMPTY) */ {
5155            ZVAL_BOOL(EX_VAR(opline->result.var),
5156                !value || !i_zend_is_true(value));
5157        }
5158
5159        CHECK_EXCEPTION();
5160        ZEND_VM_NEXT_OPCODE();
5161    }
5162}
5163
5164ZEND_VM_HANDLER(115, ZEND_ISSET_ISEMPTY_DIM_OBJ, CONST|TMPVAR|UNUSED|CV, CONST|TMPVAR|CV)
5165{
5166    USE_OPLINE
5167    zend_free_op free_op1, free_op2;
5168    zval *container;
5169    int result;
5170    zend_ulong hval;
5171    zval *offset;
5172
5173    SAVE_OPLINE();
5174    container = GET_OP1_OBJ_ZVAL_PTR(BP_VAR_IS);
5175    offset = GET_OP2_ZVAL_PTR(BP_VAR_R);
5176
5177ZEND_VM_C_LABEL(isset_dim_obj_again):
5178    if (OP1_TYPE != IS_UNUSED && EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
5179        HashTable *ht = Z_ARRVAL_P(container);
5180        zval *value;
5181        zend_string *str;
5182
5183ZEND_VM_C_LABEL(isset_again):
5184        if (EXPECTED(Z_TYPE_P(offset) == IS_STRING)) {
5185            str = Z_STR_P(offset);
5186            if (OP2_TYPE != IS_CONST) {
5187                if (ZEND_HANDLE_NUMERIC(str, hval)) {
5188                    ZEND_VM_C_GOTO(num_index_prop);
5189                }
5190            }
5191ZEND_VM_C_LABEL(str_index_prop):
5192            value = zend_hash_find_ind(ht, str);
5193        } else if (EXPECTED(Z_TYPE_P(offset) == IS_LONG)) {
5194            hval = Z_LVAL_P(offset);
5195ZEND_VM_C_LABEL(num_index_prop):
5196            value = zend_hash_index_find(ht, hval);
5197        } else {
5198            switch (Z_TYPE_P(offset)) {
5199                case IS_DOUBLE:
5200                    hval = zend_dval_to_lval(Z_DVAL_P(offset));
5201                    ZEND_VM_C_GOTO(num_index_prop);
5202                case IS_NULL:
5203                    str = STR_EMPTY_ALLOC();
5204                    ZEND_VM_C_GOTO(str_index_prop);
5205                case IS_FALSE:
5206                    hval = 0;
5207                    ZEND_VM_C_GOTO(num_index_prop);
5208                case IS_TRUE:
5209                    hval = 1;
5210