PHP  
 PHP: Test and Code Coverage Analysis
downloads | QA | documentation | faq | getting help | mailing lists | reporting bugs | php.net sites | links | my php.net 
 

LCOV - code coverage report
Current view: top level - Zend - zend_execute.c (source / functions) Hit Total Coverage
Test: PHP Code Coverage Lines: 1030 1214 84.8 %
Date: 2016-08-28 Functions: 51 63 81.0 %
Legend: Lines: hit not hit

          Line data    Source code
       1             : /*
       2             :    +----------------------------------------------------------------------+
       3             :    | Zend Engine                                                          |
       4             :    +----------------------------------------------------------------------+
       5             :    | Copyright (c) 1998-2016 Zend Technologies Ltd. (http://www.zend.com) |
       6             :    +----------------------------------------------------------------------+
       7             :    | This source file is subject to version 2.00 of the Zend license,     |
       8             :    | that is bundled with this package in the file LICENSE, and is        |
       9             :    | available through the world-wide-web at the following url:           |
      10             :    | http://www.zend.com/license/2_00.txt.                                |
      11             :    | If you did not receive a copy of the Zend license and are unable to  |
      12             :    | obtain it through the world-wide-web, please send a note to          |
      13             :    | license@zend.com so we can mail you a copy immediately.              |
      14             :    +----------------------------------------------------------------------+
      15             :    | Authors: Andi Gutmans <andi@zend.com>                                |
      16             :    |          Zeev Suraski <zeev@zend.com>                                |
      17             :    |          Dmitry Stogov <dmitry@zend.com>                             |
      18             :    +----------------------------------------------------------------------+
      19             : */
      20             : 
      21             : /* $Id$ */
      22             : 
      23             : #define ZEND_INTENSIVE_DEBUGGING 0
      24             : 
      25             : #include <stdio.h>
      26             : #include <signal.h>
      27             : 
      28             : #include "zend.h"
      29             : #include "zend_compile.h"
      30             : #include "zend_execute.h"
      31             : #include "zend_API.h"
      32             : #include "zend_ptr_stack.h"
      33             : #include "zend_constants.h"
      34             : #include "zend_extensions.h"
      35             : #include "zend_ini.h"
      36             : #include "zend_exceptions.h"
      37             : #include "zend_interfaces.h"
      38             : #include "zend_closures.h"
      39             : #include "zend_generators.h"
      40             : #include "zend_vm.h"
      41             : #include "zend_dtrace.h"
      42             : #include "zend_inheritance.h"
      43             : #include "zend_type_info.h"
      44             : 
      45             : /* Virtual current working directory support */
      46             : #include "zend_virtual_cwd.h"
      47             : 
      48             : #define _CONST_CODE  0
      49             : #define _TMP_CODE    1
      50             : #define _VAR_CODE    2
      51             : #define _UNUSED_CODE 3
      52             : #define _CV_CODE     4
      53             : 
      54             : typedef int (ZEND_FASTCALL *incdec_t)(zval *);
      55             : 
      56             : #define get_zval_ptr(op_type, node, ex, should_free, type) _get_zval_ptr(op_type, node, ex, should_free, type)
      57             : #define get_zval_ptr_deref(op_type, node, ex, should_free, type) _get_zval_ptr_deref(op_type, node, ex, should_free, type)
      58             : #define get_zval_ptr_r(op_type, node, ex, should_free) _get_zval_ptr_r(op_type, node, ex, should_free)
      59             : #define get_zval_ptr_r_deref(op_type, node, ex, should_free) _get_zval_ptr_r_deref(op_type, node, ex, should_free)
      60             : #define get_zval_ptr_undef(op_type, node, ex, should_free, type) _get_zval_ptr_undef(op_type, node, ex, should_free, type)
      61             : #define get_zval_ptr_ptr(op_type, node, ex, should_free, type) _get_zval_ptr_ptr(op_type, node, ex, should_free, type)
      62             : #define get_zval_ptr_ptr_undef(op_type, node, ex, should_free, type) _get_zval_ptr_ptr(op_type, node, ex, should_free, type)
      63             : #define get_obj_zval_ptr(op_type, node, ex, should_free, type) _get_obj_zval_ptr(op_type, node, ex, should_free, type)
      64             : #define get_obj_zval_ptr_undef(op_type, node, ex, should_free, type) _get_obj_zval_ptr_undef(op_type, node, ex, should_free, type)
      65             : #define get_obj_zval_ptr_ptr(op_type, node, ex, should_free, type) _get_obj_zval_ptr_ptr(op_type, node, ex, should_free, type)
      66             : 
      67             : /* Prototypes */
      68             : static void zend_extension_statement_handler(const zend_extension *extension, zend_execute_data *frame);
      69             : static void zend_extension_fcall_begin_handler(const zend_extension *extension, zend_execute_data *frame);
      70             : static void zend_extension_fcall_end_handler(const zend_extension *extension, zend_execute_data *frame);
      71             : 
      72             : #define RETURN_VALUE_USED(opline) ((opline)->result_type != IS_UNUSED)
      73             : 
      74          92 : static ZEND_FUNCTION(pass)
      75             : {
      76          92 : }
      77             : 
      78             : ZEND_API const zend_internal_function zend_pass_function = {
      79             :         ZEND_INTERNAL_FUNCTION, /* type              */
      80             :         {0, 0, 0},              /* arg_flags         */
      81             :         0,                      /* fn_flags          */
      82             :         NULL,                   /* name              */
      83             :         NULL,                   /* scope             */
      84             :         NULL,                   /* prototype         */
      85             :         0,                      /* num_args          */
      86             :         0,                      /* required_num_args */
      87             :         NULL,                   /* arg_info          */
      88             :         ZEND_FN(pass),          /* handler           */
      89             :         NULL,                   /* module            */
      90             :         {NULL,NULL,NULL,NULL}   /* reserved          */
      91             : };
      92             : 
      93             : #undef zval_ptr_dtor
      94             : #define zval_ptr_dtor(zv) i_zval_ptr_dtor(zv ZEND_FILE_LINE_CC)
      95             : 
      96             : #define READY_TO_DESTROY(zv) \
      97             :         (UNEXPECTED(zv) && Z_REFCOUNTED_P(zv) && Z_REFCOUNT_P(zv) == 1)
      98             : 
      99             : #define EXTRACT_ZVAL_PTR(zv) do {               \
     100             :         zval *__zv = (zv);                                                              \
     101             :         if (EXPECTED(Z_TYPE_P(__zv) == IS_INDIRECT)) {  \
     102             :                 ZVAL_COPY(__zv, Z_INDIRECT_P(__zv));        \
     103             :         }                                                                                               \
     104             : } while (0)
     105             : 
     106             : #define FREE_OP(should_free) \
     107             :         if (should_free) { \
     108             :                 zval_ptr_dtor_nogc(should_free); \
     109             :         }
     110             : 
     111             : #define FREE_UNFETCHED_OP(type, var) \
     112             :         if ((type) & (IS_TMP_VAR|IS_VAR)) { \
     113             :                 zval_ptr_dtor_nogc(EX_VAR(var)); \
     114             :         }
     115             : 
     116             : #define FREE_OP_VAR_PTR(should_free) \
     117             :         if (should_free) { \
     118             :                 zval_ptr_dtor_nogc(should_free); \
     119             :         }
     120             : 
     121             : #define CV_DEF_OF(i) (EX(func)->op_array.vars[i])
     122             : 
     123             : #define ZEND_VM_MAIN_STACK_PAGE_SLOTS (16 * 1024) /* should be a power of 2 */
     124             : #define ZEND_VM_GENERATOR_STACK_PAGE_SLOTS (256)
     125             : 
     126             : #define ZEND_VM_STACK_PAGE_SLOTS(gen) ((gen) ? ZEND_VM_GENERATOR_STACK_PAGE_SLOTS : ZEND_VM_MAIN_STACK_PAGE_SLOTS)
     127             : 
     128             : #define ZEND_VM_STACK_PAGE_SIZE(gen)  (ZEND_VM_STACK_PAGE_SLOTS(gen) * sizeof(zval))
     129             : 
     130             : #define ZEND_VM_STACK_FREE_PAGE_SIZE(gen) \
     131             :         ((ZEND_VM_STACK_PAGE_SLOTS(gen) - ZEND_VM_STACK_HEADER_SLOTS) * sizeof(zval))
     132             : 
     133             : #define ZEND_VM_STACK_PAGE_ALIGNED_SIZE(gen, size) \
     134             :         (((size) + (ZEND_VM_STACK_FREE_PAGE_SIZE(gen) - 1)) & ~(ZEND_VM_STACK_PAGE_SIZE(gen) - 1))
     135             : 
     136             : static zend_always_inline zend_vm_stack zend_vm_stack_new_page(size_t size, zend_vm_stack prev) {
     137       23475 :         zend_vm_stack page = (zend_vm_stack)emalloc(size);
     138             : 
     139       23475 :         page->top = ZEND_VM_STACK_ELEMENTS(page);
     140       23475 :         page->end = (zval*)((char*)page + size);
     141       23475 :         page->prev = prev;
     142       23475 :         return page;
     143             : }
     144             : 
     145       23458 : ZEND_API void zend_vm_stack_init(void)
     146             : {
     147       23458 :         EG(vm_stack) = zend_vm_stack_new_page(ZEND_VM_STACK_PAGE_SIZE(0 /* main stack */), NULL);
     148       23458 :         EG(vm_stack)->top++;
     149       23458 :         EG(vm_stack_top) = EG(vm_stack)->top;
     150       23458 :         EG(vm_stack_end) = EG(vm_stack)->end;
     151       23458 : }
     152             : 
     153       23500 : ZEND_API void zend_vm_stack_destroy(void)
     154             : {
     155       23500 :         zend_vm_stack stack = EG(vm_stack);
     156             : 
     157       70500 :         while (stack != NULL) {
     158       23500 :                 zend_vm_stack p = stack->prev;
     159       23500 :                 efree(stack);
     160       23500 :                 stack = p;
     161             :         }
     162       23500 : }
     163             : 
     164          17 : ZEND_API void* zend_vm_stack_extend(size_t size)
     165             : {
     166             :         zend_vm_stack stack;
     167             :         void *ptr;
     168             : 
     169          17 :         stack = EG(vm_stack);
     170          17 :         stack->top = EG(vm_stack_top);
     171          44 :         EG(vm_stack) = stack = zend_vm_stack_new_page(
     172          17 :                 EXPECTED(size < ZEND_VM_STACK_FREE_PAGE_SIZE(0)) ?
     173          10 :                         ZEND_VM_STACK_PAGE_SIZE(0) : ZEND_VM_STACK_PAGE_ALIGNED_SIZE(0, size),
     174             :                 stack);
     175          17 :         ptr = stack->top;
     176          17 :         EG(vm_stack_top) = (void*)(((char*)ptr) + size);
     177          17 :         EG(vm_stack_end) = stack->end;
     178          17 :         return ptr;
     179             : }
     180             : 
     181           0 : ZEND_API zval* zend_get_compiled_variable_value(const zend_execute_data *execute_data, uint32_t var)
     182             : {
     183           0 :         return EX_VAR(var);
     184             : }
     185             : 
     186             : static zend_always_inline zval *_get_zval_ptr_tmp(uint32_t var, const zend_execute_data *execute_data, zend_free_op *should_free)
     187             : {
     188     9438266 :         zval *ret = EX_VAR(var);
     189     9438266 :         *should_free = ret;
     190             : 
     191             :         ZEND_ASSERT(Z_TYPE_P(ret) != IS_REFERENCE);
     192             : 
     193     9438266 :         return ret;
     194             : }
     195             : 
     196             : static zend_always_inline zval *_get_zval_ptr_var(uint32_t var, const zend_execute_data *execute_data, zend_free_op *should_free)
     197             : {
     198    68087337 :         zval *ret = EX_VAR(var);
     199             : 
     200    68087337 :         *should_free = ret;
     201    68087337 :         return ret;
     202             : }
     203             : 
     204             : static zend_always_inline zval *_get_zval_ptr_var_deref(uint32_t var, const zend_execute_data *execute_data, zend_free_op *should_free)
     205             : {
     206     1599974 :         zval *ret = EX_VAR(var);
     207             : 
     208     1599974 :         *should_free = ret;
     209     1599974 :         ZVAL_DEREF(ret);
     210     1599974 :         return ret;
     211             : }
     212             : 
     213         551 : static zend_never_inline ZEND_COLD void zval_undefined_cv(uint32_t var, const zend_execute_data *execute_data)
     214             : {
     215         551 :         zend_string *cv = CV_DEF_OF(EX_VAR_TO_NUM(var));
     216             : 
     217         551 :         zend_error(E_NOTICE, "Undefined variable: %s", ZSTR_VAL(cv));
     218         551 : }
     219             : 
     220           0 : static zend_never_inline zval *_get_zval_cv_lookup(zval *ptr, uint32_t var, int type, const zend_execute_data *execute_data)
     221             : {
     222           0 :         switch (type) {
     223             :                 case BP_VAR_R:
     224             :                 case BP_VAR_UNSET:
     225           0 :                         zval_undefined_cv(var, execute_data);
     226             :                         /* break missing intentionally */
     227             :                 case BP_VAR_IS:
     228           0 :                         ptr = &EG(uninitialized_zval);
     229           0 :                         break;
     230             :                 case BP_VAR_RW:
     231           0 :                         zval_undefined_cv(var, execute_data);
     232             :                         /* break missing intentionally */
     233             :                 case BP_VAR_W:
     234           0 :                         ZVAL_NULL(ptr);
     235             :                         break;
     236             :         }
     237           0 :         return ptr;
     238             : }
     239             : 
     240             : static zend_always_inline zval *_get_zval_cv_lookup_BP_VAR_R(zval *ptr, uint32_t var, const zend_execute_data *execute_data)
     241             : {
     242         525 :         zval_undefined_cv(var, execute_data);
     243         525 :         return &EG(uninitialized_zval);
     244             : }
     245             : 
     246             : static zend_always_inline zval *_get_zval_cv_lookup_BP_VAR_UNSET(zval *ptr, uint32_t var, const zend_execute_data *execute_data)
     247             : {
     248           0 :         zval_undefined_cv(var, execute_data);
     249           0 :         return &EG(uninitialized_zval);
     250             : }
     251             : 
     252             : static zend_always_inline zval *_get_zval_cv_lookup_BP_VAR_RW(zval *ptr, uint32_t var, const zend_execute_data *execute_data)
     253             : {
     254           6 :         ZVAL_NULL(ptr);
     255           6 :         zval_undefined_cv(var, execute_data);
     256           6 :         return ptr;
     257             : }
     258             : 
     259             : static zend_always_inline zval *_get_zval_cv_lookup_BP_VAR_W(zval *ptr, uint32_t var, const zend_execute_data *execute_data)
     260             : {
     261     5747453 :         ZVAL_NULL(ptr);
     262     5747453 :         return ptr;
     263             : }
     264             : 
     265             : static zend_always_inline zval *_get_zval_ptr_cv(const zend_execute_data *execute_data, uint32_t var, int type)
     266             : {
     267         121 :         zval *ret = EX_VAR(var);
     268             : 
     269         121 :         if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
     270           0 :                 return _get_zval_cv_lookup(ret, var, type, execute_data);
     271             :         }
     272         121 :         return ret;
     273             : }
     274             : 
     275             : static zend_always_inline zval *_get_zval_ptr_cv_undef(const zend_execute_data *execute_data, uint32_t var)
     276             : {
     277    86514960 :         return EX_VAR(var);
     278             : }
     279             : 
     280             : static zend_always_inline zval *_get_zval_ptr_cv_deref(const zend_execute_data *execute_data, uint32_t var, int type)
     281             : {
     282             :         zval *ret = EX_VAR(var);
     283             : 
     284             :         if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
     285             :                 return _get_zval_cv_lookup(ret, var, type, execute_data);
     286             :         }
     287             :         ZVAL_DEREF(ret);
     288             :         return ret;
     289             : }
     290             : 
     291             : static zend_always_inline zval *_get_zval_ptr_cv_BP_VAR_R(const zend_execute_data *execute_data, uint32_t var)
     292             : {
     293    16956966 :         zval *ret = EX_VAR(var);
     294             : 
     295    16956966 :         if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
     296         191 :                 return _get_zval_cv_lookup_BP_VAR_R(ret, var, execute_data);
     297             :         }
     298    16956775 :         return ret;
     299             : }
     300             : 
     301             : static zend_always_inline zval *_get_zval_ptr_cv_deref_BP_VAR_R(const zend_execute_data *execute_data, uint32_t var)
     302             : {
     303     4090203 :         zval *ret = EX_VAR(var);
     304             : 
     305     4090203 :         if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
     306           6 :                 return _get_zval_cv_lookup_BP_VAR_R(ret, var, execute_data);
     307             :         }
     308     4090197 :         ZVAL_DEREF(ret);
     309     4090197 :         return ret;
     310             : }
     311             : 
     312             : static zend_always_inline zval *_get_zval_ptr_cv_BP_VAR_UNSET(const zend_execute_data *execute_data, uint32_t var)
     313             : {
     314          91 :         zval *ret = EX_VAR(var);
     315             : 
     316          91 :         if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
     317           0 :                 return _get_zval_cv_lookup_BP_VAR_UNSET(ret, var, execute_data);
     318             :         }
     319          91 :         return ret;
     320             : }
     321             : 
     322             : static zend_always_inline zval *_get_zval_ptr_cv_deref_BP_VAR_UNSET(const zend_execute_data *execute_data, uint32_t var)
     323             : {
     324             :         zval *ret = EX_VAR(var);
     325             : 
     326             :         if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
     327             :                 return _get_zval_cv_lookup_BP_VAR_UNSET(ret, var, execute_data);
     328             :         }
     329             :         ZVAL_DEREF(ret);
     330             :         return ret;
     331             : }
     332             : 
     333             : static zend_always_inline zval *_get_zval_ptr_cv_BP_VAR_IS(const zend_execute_data *execute_data, uint32_t var)
     334             : {
     335         231 :         zval *ret = EX_VAR(var);
     336             : 
     337         231 :         return ret;
     338             : }
     339             : 
     340             : static zend_always_inline zval *_get_zval_ptr_cv_deref_BP_VAR_IS(const zend_execute_data *execute_data, uint32_t var)
     341             : {
     342             :         zval *ret = EX_VAR(var);
     343             : 
     344             :         ZVAL_DEREF(ret);
     345             :         return ret;
     346             : }
     347             : 
     348             : static zend_always_inline zval *_get_zval_ptr_cv_BP_VAR_RW(const zend_execute_data *execute_data, uint32_t var)
     349             : {
     350     8670881 :         zval *ret = EX_VAR(var);
     351             : 
     352     8670881 :         if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
     353           0 :                 return _get_zval_cv_lookup_BP_VAR_RW(ret, var, execute_data);
     354             :         }
     355     8670881 :         return ret;
     356             : }
     357             : 
     358             : static zend_always_inline zval *_get_zval_ptr_cv_deref_BP_VAR_RW(const zend_execute_data *execute_data, uint32_t var)
     359             : {
     360             :         zval *ret = EX_VAR(var);
     361             : 
     362             :         if (UNEXPECTED(Z_TYPE_P(ret) == IS_UNDEF)) {
     363             :                 return _get_zval_cv_lookup_BP_VAR_RW(ret, var, execute_data);
     364             :         }
     365             :         ZVAL_DEREF(ret);
     366             :         return ret;
     367             : }
     368             : 
     369             : static zend_always_inline zval *_get_zval_ptr_cv_BP_VAR_W(const zend_execute_data *execute_data, uint32_t var)
     370             : {
     371     9745781 :         zval *ret = EX_VAR(var);
     372             : 
     373     9745781 :         if (Z_TYPE_P(ret) == IS_UNDEF) {
     374     5747453 :                 return _get_zval_cv_lookup_BP_VAR_W(ret, var, execute_data);
     375             :         }
     376     3998328 :         return ret;
     377             : }
     378             : 
     379             : static zend_always_inline zval *_get_zval_ptr_cv_undef_BP_VAR_W(const zend_execute_data *execute_data, uint32_t var)
     380             : {
     381    36190214 :         return EX_VAR(var);
     382             : }
     383             : 
     384             : static zend_always_inline zval *_get_zval_ptr_cv_undef_BP_VAR_RW(const zend_execute_data *execute_data, uint32_t var)
     385             : {
     386    10665315 :         return EX_VAR(var);
     387             : }
     388             : 
     389             : static zend_always_inline zval *_get_zval_ptr_cv_undef_BP_VAR_UNSET(const zend_execute_data *execute_data, uint32_t var)
     390             : {
     391       24503 :         return EX_VAR(var);
     392             : }
     393             : 
     394             : static zend_always_inline zval *_get_zval_ptr_cv_deref_BP_VAR_W(const zend_execute_data *execute_data, uint32_t var)
     395             : {
     396             :         zval *ret = EX_VAR(var);
     397             : 
     398             :         if (Z_TYPE_P(ret) == IS_UNDEF) {
     399             :                 return _get_zval_cv_lookup_BP_VAR_W(ret, var, execute_data);
     400             :         }
     401             :         ZVAL_DEREF(ret);
     402             :         return ret;
     403             : }
     404             : 
     405             : static zend_always_inline zval *_get_zval_ptr(int op_type, znode_op node, const zend_execute_data *execute_data, zend_free_op *should_free, int type)
     406             : {
     407         168 :         if (op_type & (IS_TMP_VAR|IS_VAR)) {
     408          40 :                 if (op_type == IS_TMP_VAR) {
     409          46 :                         return _get_zval_ptr_tmp(node.var, execute_data, should_free);
     410             :                 } else {
     411             :                         ZEND_ASSERT(op_type == IS_VAR);
     412          34 :                         return _get_zval_ptr_var(node.var, execute_data, should_free);
     413             :                 }
     414             :         } else {
     415         128 :                 *should_free = NULL;
     416         128 :                 if (op_type == IS_CONST) {
     417           7 :                         return EX_CONSTANT(node);
     418         121 :                 } else if (op_type == IS_CV) {
     419         242 :                         return _get_zval_ptr_cv(execute_data, node.var, type);
     420             :                 } else {
     421           0 :                         return NULL;
     422             :                 }
     423             :         }
     424             : }
     425             : 
     426             : static zend_always_inline zval *_get_zval_ptr_r(int op_type, znode_op node, const zend_execute_data *execute_data, zend_free_op *should_free)
     427             : {
     428     1166591 :         if (op_type & (IS_TMP_VAR|IS_VAR)) {
     429        1106 :                 if (op_type == IS_TMP_VAR) {
     430        2188 :                         return _get_zval_ptr_tmp(node.var, execute_data, should_free);
     431             :                 } else {
     432             :                         ZEND_ASSERT(op_type == IS_VAR);
     433          24 :                         return _get_zval_ptr_var(node.var, execute_data, should_free);
     434             :                 }
     435             :         } else {
     436     1165485 :                 *should_free = NULL;
     437     1165485 :                 if (op_type == IS_CONST) {
     438          58 :                         return EX_CONSTANT(node);
     439     1165427 :                 } else if (op_type == IS_CV) {
     440     2330854 :                         return _get_zval_ptr_cv_BP_VAR_R(execute_data, node.var);
     441             :                 } else {
     442           0 :                         return NULL;
     443             :                 }
     444             :         }
     445             : }
     446             : 
     447             : static zend_always_inline zval *_get_zval_ptr_deref(int op_type, znode_op node, const zend_execute_data *execute_data, zend_free_op *should_free, int type)
     448             : {
     449             :         if (op_type & (IS_TMP_VAR|IS_VAR)) {
     450             :                 if (op_type == IS_TMP_VAR) {
     451             :                         return _get_zval_ptr_tmp(node.var, execute_data, should_free);
     452             :                 } else {
     453             :                         ZEND_ASSERT(op_type == IS_VAR);
     454             :                         return _get_zval_ptr_var_deref(node.var, execute_data, should_free);
     455             :                 }
     456             :         } else {
     457             :                 *should_free = NULL;
     458             :                 if (op_type == IS_CONST) {
     459             :                         return EX_CONSTANT(node);
     460             :                 } else if (op_type == IS_CV) {
     461             :                         return _get_zval_ptr_cv_deref(execute_data, node.var, type);
     462             :                 } else {
     463             :                         return NULL;
     464             :                 }
     465             :         }
     466             : }
     467             : 
     468             : static zend_always_inline zval *_get_zval_ptr_r_deref(int op_type, znode_op node, const zend_execute_data *execute_data, zend_free_op *should_free)
     469             : {
     470             :         if (op_type & (IS_TMP_VAR|IS_VAR)) {
     471             :                 if (op_type == IS_TMP_VAR) {
     472             :                         return _get_zval_ptr_tmp(node.var, execute_data, should_free);
     473             :                 } else {
     474             :                         ZEND_ASSERT(op_type == IS_VAR);
     475             :                         return _get_zval_ptr_var_deref(node.var, execute_data, should_free);
     476             :                 }
     477             :         } else {
     478             :                 *should_free = NULL;
     479             :                 if (op_type == IS_CONST) {
     480             :                         return EX_CONSTANT(node);
     481             :                 } else if (op_type == IS_CV) {
     482             :                         return _get_zval_ptr_cv_deref_BP_VAR_R(execute_data, node.var);
     483             :                 } else {
     484             :                         return NULL;
     485             :                 }
     486             :         }
     487             : }
     488             : 
     489             : static zend_always_inline zval *_get_zval_ptr_undef(int op_type, znode_op node, const zend_execute_data *execute_data, zend_free_op *should_free, int type)
     490             : {
     491          69 :         if (op_type & (IS_TMP_VAR|IS_VAR)) {
     492          17 :                 if (op_type == IS_TMP_VAR) {
     493           0 :                         return _get_zval_ptr_tmp(node.var, execute_data, should_free);
     494             :                 } else {
     495             :                         ZEND_ASSERT(op_type == IS_VAR);
     496          34 :                         return _get_zval_ptr_var(node.var, execute_data, should_free);
     497             :                 }
     498             :         } else {
     499          52 :                 *should_free = NULL;
     500          52 :                 if (op_type == IS_CONST) {
     501          34 :                         return EX_CONSTANT(node);
     502          18 :                 } else if (op_type == IS_CV) {
     503          36 :                         return _get_zval_ptr_cv_undef(execute_data, node.var);
     504             :                 } else {
     505           0 :                         return NULL;
     506             :                 }
     507             :         }
     508             : }
     509             : 
     510             : static zend_always_inline zval *_get_zval_ptr_ptr_var(uint32_t var, const zend_execute_data *execute_data, zend_free_op *should_free)
     511             : {
     512     1155454 :         zval *ret = EX_VAR(var);
     513             : 
     514     1155454 :         if (EXPECTED(Z_TYPE_P(ret) == IS_INDIRECT)) {
     515      968551 :                 *should_free = NULL;
     516      968551 :                 ret = Z_INDIRECT_P(ret);
     517             :         } else {
     518      186903 :                 *should_free = ret;
     519             :         }
     520     1155454 :         return ret;
     521             : }
     522             : 
     523             : static inline zval *_get_zval_ptr_ptr(int op_type, znode_op node, const zend_execute_data *execute_data, zend_free_op *should_free, int type)
     524             : {
     525             :         if (op_type == IS_CV) {
     526             :                 *should_free = NULL;
     527             :                 return _get_zval_ptr_cv(execute_data, node.var, type);
     528             :         } else /* if (op_type == IS_VAR) */ {
     529             :                 ZEND_ASSERT(op_type == IS_VAR);
     530             :                 return _get_zval_ptr_ptr_var(node.var, execute_data, should_free);
     531             :         }
     532             : }
     533             : 
     534             : static zend_always_inline zval *_get_obj_zval_ptr_unused(zend_execute_data *execute_data)
     535             : {       
     536      420355 :         return &EX(This);
     537             : }
     538             : 
     539             : static inline zval *_get_obj_zval_ptr(int op_type, znode_op op, zend_execute_data *execute_data, zend_free_op *should_free, int type)
     540             : {
     541             :         if (op_type == IS_UNUSED) {
     542             :                 *should_free = NULL;
     543             :                 return &EX(This);
     544             :         }
     545             :         return get_zval_ptr(op_type, op, execute_data, should_free, type);
     546             : }
     547             : 
     548             : static inline zval *_get_obj_zval_ptr_undef(int op_type, znode_op op, zend_execute_data *execute_data, zend_free_op *should_free, int type)
     549             : {
     550             :         if (op_type == IS_UNUSED) {
     551             :                 *should_free = NULL;
     552             :                 return &EX(This);
     553             :         }
     554             :         return get_zval_ptr_undef(op_type, op, execute_data, should_free, type);
     555             : }
     556             : 
     557             : static inline zval *_get_obj_zval_ptr_ptr(int op_type, znode_op node, zend_execute_data *execute_data, zend_free_op *should_free, int type)
     558             : {
     559             :         if (op_type == IS_UNUSED) {
     560             :                 *should_free = NULL;
     561             :                 return &EX(This);
     562             :         }
     563             :         return get_zval_ptr_ptr(op_type, node, execute_data, should_free, type);
     564             : }
     565             : 
     566      283073 : static inline void zend_assign_to_variable_reference(zval *variable_ptr, zval *value_ptr)
     567             : {
     568             :         zend_reference *ref;
     569             : 
     570      283073 :         if (EXPECTED(!Z_ISREF_P(value_ptr))) {
     571       63570 :                 ZVAL_NEW_REF(value_ptr, value_ptr);
     572      219503 :         } else if (UNEXPECTED(variable_ptr == value_ptr)) {
     573           1 :                 return;
     574             :         }
     575             : 
     576      283072 :         ref = Z_REF_P(value_ptr);
     577      283072 :         GC_REFCOUNT(ref)++;
     578             :         zval_ptr_dtor(variable_ptr);
     579      283072 :         ZVAL_REF(variable_ptr, ref);
     580             : }
     581             : 
     582             : /* this should modify object only if it's empty */
     583          25 : static inline int make_real_object(zval *object)
     584             : {
     585          25 :         if (UNEXPECTED(Z_TYPE_P(object) != IS_OBJECT)) {
     586          18 :                 if (EXPECTED(Z_TYPE_P(object) <= IS_FALSE)) {
     587             :                         /* nothing to destroy */
     588          11 :                 } else if (EXPECTED((Z_TYPE_P(object) == IS_STRING && Z_STRLEN_P(object) == 0))) {
     589             :                         zval_ptr_dtor_nogc(object);
     590             :                 } else {
     591           7 :                         return 0;
     592             :                 }
     593          11 :                 object_init(object);
     594          11 :                 zend_error(E_WARNING, "Creating default object from empty value");
     595             :         }
     596          18 :         return 1;
     597             : }
     598             : 
     599        1275 : static char * zend_verify_internal_arg_class_kind(const zend_internal_arg_info *cur_arg_info, char **class_name, zend_class_entry **pce)
     600             : {
     601             :         zend_string *key;
     602             :         ALLOCA_FLAG(use_heap);
     603             : 
     604        2550 :         ZSTR_ALLOCA_INIT(key, cur_arg_info->class_name, strlen(cur_arg_info->class_name), use_heap);
     605        1275 :         *pce = zend_fetch_class(key, (ZEND_FETCH_CLASS_AUTO | ZEND_FETCH_CLASS_NO_AUTOLOAD));
     606        1275 :         ZSTR_ALLOCA_FREE(key, use_heap);
     607             : 
     608        1275 :         *class_name = (*pce) ? ZSTR_VAL((*pce)->name) : (char*)cur_arg_info->class_name;
     609        1275 :         if (*pce && (*pce)->ce_flags & ZEND_ACC_INTERFACE) {
     610         591 :                 return "implement interface ";
     611             :         } else {
     612         684 :                 return "be an instance of ";
     613             :         }
     614             : }
     615             : 
     616             : static zend_always_inline zend_class_entry* zend_verify_arg_class_kind(const zend_arg_info *cur_arg_info)
     617             : {
     618         119 :         return zend_fetch_class(cur_arg_info->class_name, (ZEND_FETCH_CLASS_AUTO | ZEND_FETCH_CLASS_NO_AUTOLOAD));
     619             : }
     620             : 
     621         343 : static ZEND_COLD void zend_verify_arg_error(const zend_function *zf, uint32_t arg_num, const char *need_msg, const char *need_kind, const char *given_msg, const char *given_kind)
     622             : {
     623         343 :         zend_execute_data *ptr = EG(current_execute_data)->prev_execute_data;
     624         343 :         const char *fname = ZSTR_VAL(zf->common.function_name);
     625             :         const char *fsep;
     626             :         const char *fclass;
     627             : 
     628         343 :         if (zf->common.scope) {
     629          27 :                 fsep =  "::";
     630          27 :                 fclass = ZSTR_VAL(zf->common.scope->name);
     631             :         } else {
     632         316 :                 fsep =  "";
     633         316 :                 fclass = "";
     634             :         }
     635             : 
     636         343 :         if (zf->common.type == ZEND_USER_FUNCTION) {
     637         293 :                 if (ptr && ptr->func && ZEND_USER_CODE(ptr->func->common.type)) {
     638         290 :                         zend_type_error("Argument %d passed to %s%s%s() must %s%s, %s%s given, called in %s on line %d",
     639             :                                         arg_num, fclass, fsep, fname, need_msg, need_kind, given_msg, given_kind,
     640         290 :                                         ZSTR_VAL(ptr->func->op_array.filename), ptr->opline->lineno);
     641             :                 } else {
     642           3 :                         zend_type_error("Argument %d passed to %s%s%s() must %s%s, %s%s given", arg_num, fclass, fsep, fname, need_msg, need_kind, given_msg, given_kind);
     643             :                 }
     644             :         } else {
     645         195 :                 zend_type_error("Argument %d passed to %s%s%s() must %s%s, %s%s given", arg_num, fclass, fsep, fname, need_msg, need_kind, given_msg, given_kind);
     646             :         }
     647         343 : }
     648             : 
     649           5 : static int is_null_constant(zend_class_entry *scope, zval *default_value)
     650             : {
     651           5 :         if (Z_CONSTANT_P(default_value)) {
     652             :                 zval constant;
     653             : 
     654           5 :                 ZVAL_COPY(&constant, default_value);
     655           5 :                 if (UNEXPECTED(zval_update_constant_ex(&constant, scope) != SUCCESS)) {
     656           0 :                         return 0;
     657             :                 }
     658           5 :                 if (Z_TYPE(constant) == IS_NULL) {
     659           4 :                         return 1;
     660             :                 }
     661             :                 zval_ptr_dtor(&constant);
     662             :         }
     663           1 :         return 0;
     664             : }
     665             : 
     666         138 : static zend_bool zend_verify_weak_scalar_type_hint(zend_uchar type_hint, zval *arg)
     667             : {
     668         138 :         switch (type_hint) {
     669             :                 case _IS_BOOL: {
     670             :                         zend_bool dest;
     671             : 
     672          27 :                         if (!zend_parse_arg_bool_weak(arg, &dest)) {
     673           8 :                                 return 0;
     674             :                         }
     675             :                         zval_ptr_dtor(arg);
     676          19 :                         ZVAL_BOOL(arg, dest);
     677          19 :                         return 1;
     678             :                 }
     679             :                 case IS_LONG: {
     680             :                         zend_long dest;
     681             : 
     682          35 :                         if (!zend_parse_arg_long_weak(arg, &dest)) {
     683          16 :                                 return 0;
     684             :                         }
     685             :                         zval_ptr_dtor(arg);
     686          19 :                         ZVAL_LONG(arg, dest);
     687          19 :                         return 1;
     688             :                 }
     689             :                 case IS_DOUBLE: {
     690             :                         double dest;
     691             : 
     692          30 :                         if (!zend_parse_arg_double_weak(arg, &dest)) {
     693          12 :                                 return 0;
     694             :                         }
     695             :                         zval_ptr_dtor(arg);
     696          18 :                         ZVAL_DOUBLE(arg, dest);
     697          18 :                         return 1;
     698             :                 }
     699             :                 case IS_STRING: {
     700             :                         zend_string *dest;
     701             : 
     702             :                         /* on success "arg" is converted to IS_STRING */
     703          28 :                         if (!zend_parse_arg_str_weak(arg, &dest)) {
     704           6 :                                 return 0;
     705             :                         }
     706          22 :                         return 1;
     707             :                 }
     708             :                 default:
     709          18 :                         return 0;
     710             :         }
     711             : }
     712             : 
     713         242 : static zend_bool zend_verify_scalar_type_hint(zend_uchar type_hint, zval *arg, zend_bool strict)
     714             : {
     715         242 :         if (UNEXPECTED(strict)) {
     716             :                 /* SSTH Exception: IS_LONG may be accepted as IS_DOUBLE (converted) */
     717         111 :                 if (type_hint != IS_DOUBLE || Z_TYPE_P(arg) != IS_LONG) {
     718          85 :                         return 0;
     719             :                 }
     720         153 :         } else if (UNEXPECTED(Z_TYPE_P(arg) == IS_NULL)) {
     721             :                 /* NULL may be accepted only by nullable hints (this is already checked) */
     722          19 :                 return 0;
     723             :         }
     724         138 :         return zend_verify_weak_scalar_type_hint(type_hint, arg);
     725             : }
     726             : 
     727        2339 : static int zend_verify_internal_arg_type(zend_function *zf, uint32_t arg_num, zval *arg)
     728             : {
     729             :         zend_internal_arg_info *cur_arg_info;
     730             :         char *need_msg, *class_name;
     731             :         zend_class_entry *ce;
     732             : 
     733        2339 :         if (EXPECTED(arg_num <= zf->internal_function.num_args)) {
     734        2307 :                 cur_arg_info = &zf->internal_function.arg_info[arg_num-1];
     735          32 :         } else if (zf->internal_function.fn_flags & ZEND_ACC_VARIADIC) {
     736           0 :                 cur_arg_info = &zf->internal_function.arg_info[zf->internal_function.num_args];
     737             :         } else {
     738          32 :                 return 1;
     739             :         }
     740             : 
     741        2307 :         if (cur_arg_info->type_hint) {
     742        1603 :                 ZVAL_DEREF(arg);
     743        3206 :                 if (EXPECTED(cur_arg_info->type_hint == Z_TYPE_P(arg))) {
     744        1462 :                         if (cur_arg_info->class_name) {
     745        1157 :                                 need_msg = zend_verify_internal_arg_class_kind((zend_internal_arg_info*)cur_arg_info, &class_name, &ce);
     746        1157 :                                 if (!ce || !instanceof_function(Z_OBJCE_P(arg), ce)) {
     747          70 :                                         zend_verify_arg_error(zf, arg_num, need_msg, class_name, "instance of ", ZSTR_VAL(Z_OBJCE_P(arg)->name));
     748          70 :                                         return 0;
     749             :                                 }
     750             :                         }
     751         141 :                 } else if (Z_TYPE_P(arg) != IS_NULL || !cur_arg_info->allow_null) {
     752         125 :                         if (cur_arg_info->class_name) {
     753         118 :                                 need_msg = zend_verify_internal_arg_class_kind((zend_internal_arg_info*)cur_arg_info, &class_name, &ce);
     754         118 :                                 zend_verify_arg_error(zf, arg_num, need_msg, class_name, zend_zval_type_name(arg), "");
     755         118 :                                 return 0;
     756           7 :                         } else if (cur_arg_info->type_hint == IS_CALLABLE) {
     757           0 :                                 if (!zend_is_callable(arg, IS_CALLABLE_CHECK_SILENT, NULL)) {
     758           0 :                                         zend_verify_arg_error(zf, arg_num, "be callable", "", zend_zval_type_name(arg), "");
     759           0 :                                         return 0;
     760             :                                 }
     761           7 :                         } else if (cur_arg_info->type_hint == IS_ITERABLE) {
     762           0 :                                 if (!zend_is_iterable(arg)) {
     763           0 :                                         zend_verify_arg_error(zf, arg_num, "be iterable", "", zend_zval_type_name(arg), "");
     764           0 :                                         return 0;
     765             :                                 }
     766           7 :                         } else if (cur_arg_info->type_hint == _IS_BOOL &&
     767             :                                    EXPECTED(Z_TYPE_P(arg) == IS_FALSE || Z_TYPE_P(arg) == IS_TRUE)) {
     768             :                                 /* pass */
     769           7 :                         } else if (UNEXPECTED(!zend_verify_scalar_type_hint(cur_arg_info->type_hint, arg, ZEND_CALL_USES_STRICT_TYPES(EG(current_execute_data))))) {
     770           7 :                                 zend_verify_arg_error(zf, arg_num, "be of the type ", zend_get_type_by_const(cur_arg_info->type_hint), zend_zval_type_name(arg), "");
     771           7 :                                 return 0;
     772             :                         }
     773             :                 }
     774             :         }
     775        2112 :         return 1;
     776             : }
     777             : 
     778        1520 : static zend_never_inline int zend_verify_internal_arg_types(zend_function *fbc, zend_execute_data *call)
     779             : {
     780             :         uint32_t i;
     781        1520 :         uint32_t num_args = ZEND_CALL_NUM_ARGS(call);
     782        1520 :         zval *p = ZEND_CALL_ARG(call, 1);
     783             : 
     784        3664 :         for (i = 0; i < num_args; ++i) {
     785        2339 :                 if (UNEXPECTED(!zend_verify_internal_arg_type(fbc, i + 1, p))) {
     786         195 :                         EG(current_execute_data) = call->prev_execute_data;
     787             :                         zend_vm_stack_free_args(call);
     788         195 :                         return 0;
     789             :                 }
     790        2144 :                 p++;
     791             :         }
     792        1325 :         return 1;
     793             : }
     794             : 
     795             : static zend_always_inline int zend_verify_arg_type(zend_function *zf, uint32_t arg_num, zval *arg, zval *default_value, void **cache_slot)
     796             : {
     797             :         zend_arg_info *cur_arg_info;
     798             :         char *need_msg;
     799             :         zend_class_entry *ce;
     800             : 
     801       88658 :         if (EXPECTED(arg_num <= zf->common.num_args)) {
     802       88648 :                 cur_arg_info = &zf->common.arg_info[arg_num-1];
     803          10 :         } else if (UNEXPECTED(zf->common.fn_flags & ZEND_ACC_VARIADIC)) {
     804          10 :                 cur_arg_info = &zf->common.arg_info[zf->common.num_args];
     805             :         } else {
     806           0 :                 return 1;
     807             :         }
     808             : 
     809       88658 :         if (cur_arg_info->type_hint) {
     810       88420 :                 ZVAL_DEREF(arg);
     811      176840 :                 if (EXPECTED(cur_arg_info->type_hint == Z_TYPE_P(arg))) {
     812       88166 :                         if (cur_arg_info->class_name) {
     813       87932 :                                 if (EXPECTED(*cache_slot)) {
     814       87841 :                                         ce = (zend_class_entry*)*cache_slot;
     815             :                                 } else {
     816          91 :                                         ce = zend_verify_arg_class_kind(cur_arg_info);
     817          91 :                                         if (UNEXPECTED(!ce)) {
     818           4 :                                                 zend_verify_arg_error(zf, arg_num, "be an instance of ", ZSTR_VAL(cur_arg_info->class_name), "instance of ", ZSTR_VAL(Z_OBJCE_P(arg)->name));
     819           4 :                                                 return 0;
     820             :                                         }
     821          87 :                                         *cache_slot = (void*)ce;
     822             :                                 }
     823       87928 :                                 if (UNEXPECTED(!instanceof_function(Z_OBJCE_P(arg), ce))) {
     824          11 :                                         need_msg =
     825          11 :                                                 (ce->ce_flags & ZEND_ACC_INTERFACE) ?
     826             :                                                 "implement interface " : "be an instance of ";
     827          11 :                                         zend_verify_arg_error(zf, arg_num, need_msg, ZSTR_VAL(ce->name), "instance of ", ZSTR_VAL(Z_OBJCE_P(arg)->name));
     828          11 :                                         return 0;
     829             :                                 }
     830             :                         }
     831         254 :                 } else if (Z_TYPE_P(arg) != IS_NULL || !(cur_arg_info->allow_null || (default_value && is_null_constant(zf->common.scope, default_value)))) {
     832         196 :                         if (cur_arg_info->class_name) {
     833           8 :                                 if (EXPECTED(*cache_slot)) {
     834           1 :                                         ce = (zend_class_entry*)*cache_slot;
     835             :                                 } else {
     836           7 :                                         ce = zend_verify_arg_class_kind(cur_arg_info);
     837           7 :                                         if (UNEXPECTED(!ce)) {
     838           1 :                                                 if (Z_TYPE_P(arg) == IS_OBJECT) {
     839           0 :                                                         zend_verify_arg_error(zf, arg_num, "be an instance of ", ZSTR_VAL(cur_arg_info->class_name), "instance of ", ZSTR_VAL(Z_OBJCE_P(arg)->name));
     840             :                                                 } else {
     841           1 :                                                         zend_verify_arg_error(zf, arg_num, "be an instance of ", ZSTR_VAL(cur_arg_info->class_name), "", zend_zval_type_name(arg));
     842             :                                                 }
     843           1 :                                                 return 0;
     844             :                                         }
     845           6 :                                         *cache_slot = (void*)ce;
     846             :                                 }
     847           7 :                                 need_msg =
     848           7 :                                         (ce->ce_flags & ZEND_ACC_INTERFACE) ?
     849             :                                         "implement interface " : "be an instance of ";
     850           7 :                                 zend_verify_arg_error(zf, arg_num, need_msg, ZSTR_VAL(ce->name), zend_zval_type_name(arg), "");
     851           7 :                                 return 0;
     852         188 :                         } else if (cur_arg_info->type_hint == IS_CALLABLE) {
     853          10 :                                 if (!zend_is_callable(arg, IS_CALLABLE_CHECK_SILENT, NULL)) {
     854           1 :                                         zend_verify_arg_error(zf, arg_num, "be callable", "", zend_zval_type_name(arg), "");
     855           1 :                                         return 0;
     856             :                                 }
     857         178 :                         } else if (cur_arg_info->type_hint == IS_ITERABLE) {
     858           4 :                                 if (!zend_is_iterable(arg)) {
     859           1 :                                         zend_verify_arg_error(zf, arg_num, "be iterable", "", zend_zval_type_name(arg), "");
     860           1 :                                         return 0;
     861             :                                 }
     862         260 :                         } else if (cur_arg_info->type_hint == _IS_BOOL &&
     863             :                                    EXPECTED(Z_TYPE_P(arg) == IS_FALSE || Z_TYPE_P(arg) == IS_TRUE)) {
     864             :                                 /* pass */
     865         166 :                         } else if (UNEXPECTED(!zend_verify_scalar_type_hint(cur_arg_info->type_hint, arg, ZEND_ARG_USES_STRICT_TYPES()))) {
     866         123 :                                 zend_verify_arg_error(zf, arg_num, "be of the type ", zend_get_type_by_const(cur_arg_info->type_hint), zend_zval_type_name(arg), "");
     867         123 :                                 return 0;
     868             :                         }
     869             :                 }
     870             :         }
     871       88510 :         return 1;
     872             : }
     873             : 
     874          51 : ZEND_API ZEND_COLD void ZEND_FASTCALL zend_missing_arg_error(zend_execute_data *execute_data)
     875             : {
     876          51 :         zend_execute_data *ptr = EX(prev_execute_data);
     877             : 
     878          71 :         if (ptr && ptr->func && ZEND_USER_CODE(ptr->func->common.type)) {
     879         143 :                 zend_throw_error(NULL, "Too few arguments to function %s%s%s(), %d passed in %s on line %d and %s %d expected",
     880          23 :                         EX(func)->common.scope ? ZSTR_VAL(EX(func)->common.scope->name) : "",
     881          20 :                         EX(func)->common.scope ? "::" : "",
     882          20 :                         ZSTR_VAL(EX(func)->common.function_name),
     883             :                         EX_NUM_ARGS(),
     884          20 :                         ZSTR_VAL(ptr->func->op_array.filename),
     885          20 :                         ptr->opline->lineno,
     886          20 :                         EX(func)->common.required_num_args == EX(func)->common.num_args ? "exactly" : "at least",
     887          20 :                         EX(func)->common.required_num_args);
     888             :         } else {
     889         165 :                 zend_throw_error(NULL, "Too few arguments to function %s%s%s(), %d passed and %s %d expected",
     890          41 :                         EX(func)->common.scope ? ZSTR_VAL(EX(func)->common.scope->name) : "",
     891          31 :                         EX(func)->common.scope ? "::" : "",
     892          31 :                         ZSTR_VAL(EX(func)->common.function_name),
     893             :                         EX_NUM_ARGS(),
     894          31 :                         EX(func)->common.required_num_args == EX(func)->common.num_args ? "exactly" : "at least",
     895          31 :                         EX(func)->common.required_num_args);
     896             :         }
     897          51 : }
     898             : 
     899          39 : static ZEND_COLD void zend_verify_return_error(const zend_function *zf, const char *need_msg, const char *need_kind, const char *returned_msg, const char *returned_kind)
     900             : {
     901          39 :         const char *fname = ZSTR_VAL(zf->common.function_name);
     902             :         const char *fsep;
     903             :         const char *fclass;
     904             : 
     905          39 :         if (zf->common.scope) {
     906           2 :                 fsep =  "::";
     907           2 :                 fclass = ZSTR_VAL(zf->common.scope->name);
     908             :         } else {
     909          37 :                 fsep =  "";
     910          37 :                 fclass = "";
     911             :         }
     912             : 
     913          39 :         zend_type_error("Return value of %s%s%s() must %s%s, %s%s returned",
     914             :                 fclass, fsep, fname, need_msg, need_kind, returned_msg, returned_kind);
     915          39 : }
     916             : 
     917             : #if ZEND_DEBUG
     918             : static ZEND_COLD void zend_verify_internal_return_error(const zend_function *zf, const char *need_msg, const char *need_kind, const char *returned_msg, const char *returned_kind)
     919             : {
     920             :         const char *fname = ZSTR_VAL(zf->common.function_name);
     921             :         const char *fsep;
     922             :         const char *fclass;
     923             : 
     924             :         if (zf->common.scope) {
     925             :                 fsep =  "::";
     926             :                 fclass = ZSTR_VAL(zf->common.scope->name);
     927             :         } else {
     928             :                 fsep =  "";
     929             :                 fclass = "";
     930             :         }
     931             : 
     932             :         zend_error_noreturn(E_CORE_ERROR, "Return value of %s%s%s() must %s%s, %s%s returned",
     933             :                 fclass, fsep, fname, need_msg, need_kind, returned_msg, returned_kind);
     934             : }
     935             : 
     936             : static ZEND_COLD void zend_verify_void_return_error(const zend_function *zf, const char *returned_msg, const char *returned_kind)
     937             : {
     938             :         const char *fname = ZSTR_VAL(zf->common.function_name);
     939             :         const char *fsep;
     940             :         const char *fclass;
     941             : 
     942             :         if (zf->common.scope) {
     943             :                 fsep =  "::";
     944             :                 fclass = ZSTR_VAL(zf->common.scope->name);
     945             :         } else {
     946             :                 fsep =  "";
     947             :                 fclass = "";
     948             :         }
     949             : 
     950             :         zend_type_error("%s%s%s() must not return a value, %s%s returned",
     951             :                 fclass, fsep, fname, returned_msg, returned_kind);
     952             : }
     953             : 
     954             : static int zend_verify_internal_return_type(zend_function *zf, zval *ret)
     955             : {
     956             :         zend_arg_info *ret_info = zf->common.arg_info - 1;
     957             :         char *need_msg, *class_name;
     958             :         zend_class_entry *ce;
     959             : 
     960             : 
     961             :         if (ret_info->type_hint) {
     962             :                 if (EXPECTED(ret_info->type_hint == Z_TYPE_P(ret))) {
     963             :                         if (ret_info->class_name) {
     964             :                                 need_msg = zend_verify_internal_arg_class_kind((zend_internal_arg_info *)ret_info, &class_name, &ce);
     965             :                                 if (!ce || !instanceof_function(Z_OBJCE_P(ret), ce)) {
     966             :                                         zend_verify_internal_return_error(zf, need_msg, class_name, "instance of ", ZSTR_VAL(Z_OBJCE_P(ret)->name));
     967             :                                         return 0;
     968             :                                 }
     969             :                         }
     970             :                 } else if (Z_TYPE_P(ret) != IS_NULL || !ret_info->allow_null) {
     971             :                         if (ret_info->class_name) {
     972             :                                 need_msg = zend_verify_internal_arg_class_kind((zend_internal_arg_info *)ret_info, &class_name, &ce);
     973             :                                 zend_verify_internal_return_error(zf, need_msg, class_name, zend_zval_type_name(ret), "");
     974             :                         } else if (ret_info->type_hint == IS_CALLABLE) {
     975             :                                 if (!zend_is_callable(ret, IS_CALLABLE_CHECK_SILENT, NULL) && (Z_TYPE_P(ret) != IS_NULL || !ret_info->allow_null)) {
     976             :                                         zend_verify_internal_return_error(zf, "be callable", "", zend_zval_type_name(ret), "");
     977             :                                         return 0;
     978             :                                 }
     979             :                         } else if (ret_info->type_hint == IS_ITERABLE) {
     980             :                                 if (!zend_is_iterable(ret) && (Z_TYPE_P(ret) != IS_NULL || !ret_info->allow_null)) {
     981             :                                         zend_verify_internal_return_error(zf, "be iterable", "", zend_zval_type_name(ret), "");
     982             :                                         return 0;
     983             :                                 }
     984             :                         } else if (ret_info->type_hint == _IS_BOOL &&
     985             :                                    EXPECTED(Z_TYPE_P(ret) == IS_FALSE || Z_TYPE_P(ret) == IS_TRUE)) {
     986             :                                 /* pass */
     987             :                         } else if (ret_info->type_hint == IS_VOID) {
     988             :                                 zend_verify_void_return_error(zf, zend_zval_type_name(ret), "");
     989             :                         } else {
     990             :                                 /* Use strict check to verify return value of internal function */
     991             :                                 zend_verify_internal_return_error(zf, "be of the type ", zend_get_type_by_const(ret_info->type_hint), zend_zval_type_name(ret), "");
     992             :                                 return 0;
     993             :                         }
     994             :                 }
     995             :         }
     996             :         return 1;
     997             : }
     998             : #endif
     999             : 
    1000             : static zend_always_inline void zend_verify_return_type(zend_function *zf, zval *ret, void **cache_slot)
    1001             : {
    1002         136 :         zend_arg_info *ret_info = zf->common.arg_info - 1;
    1003             :         char *need_msg;
    1004             :         zend_class_entry *ce;
    1005             : 
    1006         136 :         if (ret_info->type_hint) {
    1007         272 :                 if (EXPECTED(ret_info->type_hint == Z_TYPE_P(ret))) {
    1008          51 :                         if (ret_info->class_name) {
    1009          20 :                                 if (EXPECTED(*cache_slot)) {
    1010           1 :                                         ce = (zend_class_entry*)*cache_slot;
    1011             :                                 } else {
    1012          19 :                                         ce = zend_verify_arg_class_kind(ret_info);
    1013          19 :                                         if (UNEXPECTED(!ce)) {
    1014           0 :                                                 zend_verify_return_error(zf, "be an instance of ", ZSTR_VAL(ret_info->class_name), "instance of ", ZSTR_VAL(Z_OBJCE_P(ret)->name));
    1015             :                                                 return;
    1016             :                                         }
    1017          19 :                                         *cache_slot = (void*)ce;
    1018             :                                 }
    1019          20 :                                 if (UNEXPECTED(!instanceof_function(Z_OBJCE_P(ret), ce))) {
    1020           1 :                                         need_msg =
    1021           1 :                                                 (ce->ce_flags & ZEND_ACC_INTERFACE) ?
    1022             :                                                 "implement interface " : "be an instance of ";
    1023           1 :                                         zend_verify_return_error(zf, need_msg, ZSTR_VAL(ce->name), "instance of ", ZSTR_VAL(Z_OBJCE_P(ret)->name));
    1024             :                                 }
    1025             :                         }
    1026          85 :                 } else if (Z_TYPE_P(ret) != IS_NULL || !ret_info->allow_null) {
    1027          79 :                         if (ret_info->class_name) {
    1028           2 :                                 if (EXPECTED(*cache_slot)) {
    1029           0 :                                         ce = (zend_class_entry*)*cache_slot;
    1030             :                                 } else {
    1031           2 :                                         ce = zend_verify_arg_class_kind(ret_info);
    1032           2 :                                         if (UNEXPECTED(!ce)) {
    1033           0 :                                                 zend_verify_return_error(zf, "be an instance of ", ZSTR_VAL(ret_info->class_name), zend_zval_type_name(ret), "");
    1034             :                                                 return;
    1035             :                                         }
    1036           2 :                                         *cache_slot = (void*)ce;
    1037             :                                 }
    1038           2 :                                 need_msg =
    1039           2 :                                         (ce->ce_flags & ZEND_ACC_INTERFACE) ?
    1040             :                                         "implement interface " : "be an instance of ";
    1041           2 :                                 zend_verify_return_error(zf, need_msg, ZSTR_VAL(ce->name), zend_zval_type_name(ret), "");
    1042          77 :                         } else if (ret_info->type_hint == IS_CALLABLE) {
    1043           3 :                                 if (!zend_is_callable(ret, IS_CALLABLE_CHECK_SILENT, NULL)) {
    1044           0 :                                         zend_verify_return_error(zf, "be callable", "", zend_zval_type_name(ret), "");
    1045             :                                 }
    1046          74 :                         } else if (ret_info->type_hint == IS_ITERABLE) {
    1047           3 :                                 if (!zend_is_iterable(ret)) {
    1048           1 :                                         zend_verify_return_error(zf, "be iterable", "", zend_zval_type_name(ret), "");
    1049             :                                 }
    1050         102 :                         } else if (ret_info->type_hint == _IS_BOOL &&
    1051             :                                    EXPECTED(Z_TYPE_P(ret) == IS_FALSE || Z_TYPE_P(ret) == IS_TRUE)) {
    1052             :                                 /* pass */
    1053             :                         /* There would be a check here for the IS_VOID type hint, which
    1054             :                          * would trigger an error because a value had been returned.
    1055             :                          * However, zend_compile.c already does a compile-time check
    1056             :                          * that bans `return ...;` within a void function. Thus we can skip
    1057             :                          * this part of the runtime check for non-internal functions.
    1058             :                          */
    1059          69 :                         } else if (UNEXPECTED(!zend_verify_scalar_type_hint(ret_info->type_hint, ret, ZEND_RET_USES_STRICT_TYPES()))) {
    1060          34 :                                 zend_verify_return_error(zf, "be of the type ", zend_get_type_by_const(ret_info->type_hint), zend_zval_type_name(ret), "");
    1061             :                         }
    1062             :                 }
    1063             :         }
    1064             : }
    1065             : 
    1066           1 : static ZEND_COLD int zend_verify_missing_return_type(zend_function *zf, void **cache_slot)
    1067             : {
    1068           1 :         zend_arg_info *ret_info = zf->common.arg_info - 1;
    1069             :         char *need_msg;
    1070             :         zend_class_entry *ce;
    1071             : 
    1072           1 :         if (ret_info->type_hint && EXPECTED(ret_info->type_hint != IS_VOID)) {
    1073           1 :                 if (ret_info->class_name) {
    1074           0 :                         if (EXPECTED(*cache_slot)) {
    1075           0 :                                 ce = (zend_class_entry*)*cache_slot;
    1076             :                         } else {
    1077           0 :                                 ce = zend_verify_arg_class_kind(ret_info);
    1078           0 :                                 if (UNEXPECTED(!ce)) {
    1079           0 :                                         zend_verify_return_error(zf, "be an instance of ", ZSTR_VAL(ret_info->class_name), "none", "");
    1080           0 :                                         return 0;
    1081             :                                 }
    1082           0 :                                 *cache_slot = (void*)ce;
    1083             :                         }
    1084           0 :                         need_msg =
    1085           0 :                                 (ce->ce_flags & ZEND_ACC_INTERFACE) ?
    1086             :                                 "implement interface " : "be an instance of ";
    1087           0 :                         zend_verify_return_error(zf, need_msg, ZSTR_VAL(ce->name), "none", "");
    1088           0 :                         return 0;
    1089           1 :                 } else if (ret_info->type_hint == IS_CALLABLE) {
    1090           0 :                         zend_verify_return_error(zf, "be callable", "", "none", "");
    1091           1 :                 } else if (ret_info->type_hint == IS_ITERABLE) {
    1092           0 :                         zend_verify_return_error(zf, "be iterable", "", "none", "");
    1093             :                 } else {
    1094           1 :                         zend_verify_return_error(zf, "be of the type ", zend_get_type_by_const(ret_info->type_hint), "none", "");
    1095             :                 }
    1096           1 :                 return 0;
    1097             :         }
    1098           0 :         return 1;
    1099             : }
    1100             : 
    1101        1577 : static zend_never_inline void zend_assign_to_object_dim(zval *object, zval *dim, zval *value)
    1102             : {
    1103        1577 :         if (UNEXPECTED(!Z_OBJ_HT_P(object)->write_dimension)) {
    1104           0 :                 zend_throw_error(NULL, "Cannot use object as array");
    1105           0 :                 return;
    1106             :         }
    1107             : 
    1108        1577 :         Z_OBJ_HT_P(object)->write_dimension(object, dim, value);
    1109             : }
    1110             : 
    1111          13 : static zend_never_inline void zend_binary_assign_op_obj_dim(zval *object, zval *property, zval *value, zval *retval, binary_op_type binary_op)
    1112             : {
    1113             :         zval *z;
    1114             :         zval rv, res;
    1115             : 
    1116          39 :         if (Z_OBJ_HT_P(object)->read_dimension &&
    1117          13 :                 (z = Z_OBJ_HT_P(object)->read_dimension(object, property, BP_VAR_R, &rv)) != NULL) {
    1118             : 
    1119          13 :                 if (Z_TYPE_P(z) == IS_OBJECT && Z_OBJ_HT_P(z)->get) {
    1120             :                         zval rv2;
    1121           4 :                         zval *value = Z_OBJ_HT_P(z)->get(z, &rv2);
    1122             : 
    1123           4 :                         if (z == &rv) {
    1124             :                                 zval_ptr_dtor(&rv);
    1125             :                         }
    1126           4 :                         ZVAL_COPY_VALUE(z, value);
    1127             :                 }
    1128          13 :                 binary_op(&res, Z_ISREF_P(z) ? Z_REFVAL_P(z) : z, value);
    1129          13 :                 Z_OBJ_HT_P(object)->write_dimension(object, property, &res);
    1130          13 :                 if (z == &rv) {
    1131             :                         zval_ptr_dtor(&rv);
    1132             :                 }
    1133          13 :                 if (retval) {
    1134           1 :                         ZVAL_COPY(retval, &res);
    1135             :                 }
    1136             :                 zval_ptr_dtor(&res);
    1137             :         } else {
    1138           0 :                 zend_error(E_WARNING, "Attempt to assign property of non-object");
    1139           0 :                 if (retval) {
    1140           0 :                         ZVAL_NULL(retval);
    1141             :                 }
    1142             :         }
    1143          13 : }
    1144             : 
    1145         183 : static zend_never_inline zend_long zend_check_string_offset(zval *dim, int type)
    1146             : {
    1147             :         zend_long offset;
    1148             : 
    1149             : try_again:
    1150         183 :         if (UNEXPECTED(Z_TYPE_P(dim) != IS_LONG)) {
    1151          17 :                 switch(Z_TYPE_P(dim)) {
    1152             :                         case IS_STRING:
    1153          34 :                                 if (IS_LONG == is_numeric_string(Z_STRVAL_P(dim), Z_STRLEN_P(dim), NULL, NULL, -1)) {
    1154           0 :                                         break;
    1155             :                                 }
    1156          17 :                                 if (type != BP_VAR_UNSET) {
    1157          16 :                                         zend_error(E_WARNING, "Illegal string offset '%s'", Z_STRVAL_P(dim));
    1158             :                                 }
    1159          17 :                                 break;
    1160             :                         case IS_UNDEF:
    1161           0 :                                 zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
    1162             :                         case IS_DOUBLE:
    1163             :                         case IS_NULL:
    1164             :                         case IS_FALSE:
    1165             :                         case IS_TRUE:
    1166           0 :                                 zend_error(E_NOTICE, "String offset cast occurred");
    1167           0 :                                 break;
    1168             :                         case IS_REFERENCE:
    1169           0 :                                 dim = Z_REFVAL_P(dim);
    1170           0 :                                 goto try_again;
    1171             :                         default:
    1172           0 :                                 zend_error(E_WARNING, "Illegal offset type");
    1173             :                                 break;
    1174             :                 }
    1175             : 
    1176          17 :                 offset = _zval_get_long_func(dim);
    1177             :         } else {
    1178         166 :                 offset = Z_LVAL_P(dim);
    1179             :         }
    1180             : 
    1181         183 :         return offset;
    1182             : }
    1183             : 
    1184          15 : static zend_never_inline ZEND_COLD void zend_wrong_string_offset(void)
    1185             : {
    1186          15 :         const char *msg = NULL;
    1187          15 :         const zend_op *opline = EG(current_execute_data)->opline;
    1188             :         const zend_op *end;
    1189             :         uint32_t var;
    1190             : 
    1191          15 :         switch (opline->opcode) {
    1192             :                 case ZEND_ASSIGN_ADD:
    1193             :                 case ZEND_ASSIGN_SUB:
    1194             :                 case ZEND_ASSIGN_MUL:
    1195             :                 case ZEND_ASSIGN_DIV:
    1196             :                 case ZEND_ASSIGN_MOD:
    1197             :                 case ZEND_ASSIGN_SL:
    1198             :                 case ZEND_ASSIGN_SR:
    1199             :                 case ZEND_ASSIGN_CONCAT:
    1200             :                 case ZEND_ASSIGN_BW_OR:
    1201             :                 case ZEND_ASSIGN_BW_AND:
    1202             :                 case ZEND_ASSIGN_BW_XOR:
    1203             :                 case ZEND_ASSIGN_POW:
    1204           1 :                         msg = "Cannot use assign-op operators with string offsets";
    1205           1 :                         break;
    1206             :                 case ZEND_FETCH_DIM_W:
    1207             :                 case ZEND_FETCH_DIM_RW:
    1208             :                 case ZEND_FETCH_DIM_FUNC_ARG:
    1209             :                 case ZEND_FETCH_DIM_UNSET:
    1210             :                         /* TODO: Encode the "reason" into opline->extended_value??? */
    1211          14 :                         var = opline->result.var;
    1212          14 :                         opline++;
    1213          42 :                         end = EG(current_execute_data)->func->op_array.opcodes +
    1214          28 :                                 EG(current_execute_data)->func->op_array.last;
    1215          28 :                         while (opline < end) {
    1216          14 :                                 if (opline->op1_type == IS_VAR && opline->op1.var == var) {
    1217          13 :                                         switch (opline->opcode) {
    1218             :                                                 case ZEND_ASSIGN_ADD:
    1219             :                                                 case ZEND_ASSIGN_SUB:
    1220             :                                                 case ZEND_ASSIGN_MUL:
    1221             :                                                 case ZEND_ASSIGN_DIV:
    1222             :                                                 case ZEND_ASSIGN_MOD:
    1223             :                                                 case ZEND_ASSIGN_SL:
    1224             :                                                 case ZEND_ASSIGN_SR:
    1225             :                                                 case ZEND_ASSIGN_CONCAT:
    1226             :                                                 case ZEND_ASSIGN_BW_OR:
    1227             :                                                 case ZEND_ASSIGN_BW_AND:
    1228             :                                                 case ZEND_ASSIGN_BW_XOR:
    1229             :                                                 case ZEND_ASSIGN_POW:
    1230           2 :                                                         if (opline->extended_value == ZEND_ASSIGN_OBJ) {
    1231           1 :                                                                 msg = "Cannot use string offset as an object";
    1232           1 :                                                         } else if (opline->extended_value == ZEND_ASSIGN_DIM) {
    1233           1 :                                                                 msg = "Cannot use string offset as an array";
    1234             :                                                         } else {
    1235           0 :                                                                 msg = "Cannot use assign-op operators with string offsets";
    1236             :                                                         }
    1237           2 :                                                         break;
    1238             :                                                 case ZEND_PRE_INC_OBJ:
    1239             :                                                 case ZEND_PRE_DEC_OBJ:
    1240             :                                                 case ZEND_POST_INC_OBJ:
    1241             :                                                 case ZEND_POST_DEC_OBJ:
    1242             :                                                 case ZEND_PRE_INC:
    1243             :                                                 case ZEND_PRE_DEC:
    1244             :                                                 case ZEND_POST_INC:
    1245             :                                                 case ZEND_POST_DEC:
    1246           1 :                                                         msg = "Cannot increment/decrement string offsets";
    1247           1 :                                                         break;
    1248             :                                                 case ZEND_FETCH_DIM_W:
    1249             :                                                 case ZEND_FETCH_DIM_RW:
    1250             :                                                 case ZEND_FETCH_DIM_FUNC_ARG:
    1251             :                                                 case ZEND_FETCH_DIM_UNSET:
    1252             :                                                 case ZEND_ASSIGN_DIM:
    1253           3 :                                                         msg = "Cannot use string offset as an array";
    1254           3 :                                                         break;
    1255             :                                                 case ZEND_FETCH_OBJ_W:
    1256             :                                                 case ZEND_FETCH_OBJ_RW:
    1257             :                                                 case ZEND_FETCH_OBJ_FUNC_ARG:
    1258             :                                                 case ZEND_FETCH_OBJ_UNSET:
    1259             :                                                 case ZEND_ASSIGN_OBJ:
    1260           2 :                                                         msg = "Cannot use string offset as an object";
    1261           2 :                                                         break;
    1262             :                                                 case ZEND_ASSIGN_REF:
    1263             :                                                 case ZEND_ADD_ARRAY_ELEMENT:
    1264             :                                                 case ZEND_INIT_ARRAY:
    1265             :                                                 case ZEND_MAKE_REF:
    1266           2 :                                                         msg = "Cannot create references to/from string offsets";
    1267           2 :                                                         break;
    1268             :                                                 case ZEND_RETURN_BY_REF:
    1269             :                                                 case ZEND_VERIFY_RETURN_TYPE:
    1270           1 :                                                         msg = "Cannot return string offsets by reference";
    1271           1 :                                                         break;
    1272             :                                                 case ZEND_UNSET_DIM:
    1273             :                                                 case ZEND_UNSET_OBJ:
    1274           1 :                                                         msg = "Cannot unset string offsets";
    1275           1 :                                                         break;
    1276             :                                                 case ZEND_YIELD:
    1277           0 :                                                         msg = "Cannot yield string offsets by reference";
    1278           0 :                                                         break;
    1279             :                                                 case ZEND_SEND_REF:
    1280             :                                                 case ZEND_SEND_VAR_EX:
    1281           1 :                                                         msg = "Only variables can be passed by reference";
    1282             :                                                         break;
    1283             :                                                 EMPTY_SWITCH_DEFAULT_CASE();
    1284             :                                         }
    1285          13 :                                         break;
    1286             :                                 }
    1287           1 :                                 if (opline->op2_type == IS_VAR && opline->op2.var == var) {
    1288             :                                         ZEND_ASSERT(opline->opcode == ZEND_ASSIGN_REF);
    1289           1 :                                         msg = "Cannot create references to/from string offsets";
    1290           1 :                                         break;
    1291             :                                 }
    1292             :                         }
    1293             :                         break;
    1294             :                 EMPTY_SWITCH_DEFAULT_CASE();
    1295             :         }
    1296             :         ZEND_ASSERT(msg != NULL);
    1297          15 :         zend_throw_error(NULL, msg);
    1298          15 : }
    1299             : 
    1300         168 : static zend_never_inline void zend_assign_to_string_offset(zval *str, zval *dim, zval *value, zval *result)
    1301             : {
    1302             :         zend_string *old_str;
    1303             :         zend_uchar c;
    1304             :         size_t string_len;
    1305             :         zend_long offset;
    1306             : 
    1307         168 :         offset = zend_check_string_offset(dim, BP_VAR_W);
    1308         168 :         if (offset < (zend_long)(-Z_STRLEN_P(str))) {
    1309             :                 /* Error on negative offset */
    1310           2 :                 zend_error(E_WARNING, "Illegal string offset:  " ZEND_LONG_FMT, offset);
    1311           2 :                 if (result) {
    1312           1 :                         ZVAL_NULL(result);
    1313             :                 }
    1314           2 :                 return;
    1315             :         }
    1316             : 
    1317         166 :         if (Z_TYPE_P(value) != IS_STRING) {
    1318             :                 /* Convert to string, just the time to pick the 1st byte */
    1319          12 :                 zend_string *tmp = zval_get_string(value);
    1320             : 
    1321          12 :                 string_len = ZSTR_LEN(tmp);
    1322          12 :                 c = (zend_uchar)ZSTR_VAL(tmp)[0];
    1323             :                 zend_string_release(tmp);
    1324             :         } else {
    1325         154 :                 string_len = Z_STRLEN_P(value);
    1326         154 :                 c = (zend_uchar)Z_STRVAL_P(value)[0];
    1327             :         }
    1328             : 
    1329         166 :         if (string_len == 0) {
    1330             :                 /* Error on empty input string */
    1331           4 :                 zend_error(E_WARNING, "Cannot assign an empty string to a string offset");
    1332           4 :                 if (result) {
    1333           4 :                         ZVAL_NULL(result);
    1334             :                 }
    1335           4 :                 return;
    1336             :         }
    1337             : 
    1338         162 :         if (offset < 0) { /* Handle negative offset */
    1339           7 :                 offset += (zend_long)Z_STRLEN_P(str);
    1340             :         }
    1341             : 
    1342         162 :         if ((size_t)offset >= Z_STRLEN_P(str)) {
    1343             :                 /* Extend string if needed */
    1344           8 :                 zend_long old_len = Z_STRLEN_P(str);
    1345          16 :                 Z_STR_P(str) = zend_string_extend(Z_STR_P(str), offset + 1, 0);
    1346           8 :                 Z_TYPE_INFO_P(str) = IS_STRING_EX;
    1347           8 :                 memset(Z_STRVAL_P(str) + old_len, ' ', offset - old_len);
    1348           8 :                 Z_STRVAL_P(str)[offset+1] = 0;
    1349         154 :         } else if (!Z_REFCOUNTED_P(str)) {
    1350           9 :                 old_str = Z_STR_P(str);
    1351          18 :                 Z_STR_P(str) = zend_string_init(Z_STRVAL_P(str), Z_STRLEN_P(str), 0);
    1352           9 :                 Z_TYPE_INFO_P(str) = IS_STRING_EX;
    1353             :                 zend_string_release(old_str);
    1354             :         } else {
    1355         296 :                 SEPARATE_STRING(str);
    1356             :         }
    1357             : 
    1358         162 :         Z_STRVAL_P(str)[offset] = c;
    1359             : 
    1360         162 :         if (result) {
    1361             :                 /* Return the new character */
    1362          17 :                 if (CG(one_char_string)[c]) {
    1363           0 :                         ZVAL_INTERNED_STR(result, CG(one_char_string)[c]);
    1364             :                 } else {
    1365          34 :                         ZVAL_NEW_STR(result, zend_string_init(Z_STRVAL_P(str) + offset, 1, 0));
    1366             :                 }
    1367             :         }
    1368             : }
    1369             : 
    1370           9 : static zend_never_inline void zend_post_incdec_overloaded_property(zval *object, zval *property, void **cache_slot, int inc, zval *result)
    1371             : {
    1372          17 :         if (Z_OBJ_HT_P(object)->read_property && Z_OBJ_HT_P(object)->write_property) {
    1373             :                 zval rv, obj;
    1374             :                 zval *z;
    1375             :                 zval z_copy;
    1376             : 
    1377           9 :                 ZVAL_OBJ(&obj, Z_OBJ_P(object));
    1378             :                 Z_ADDREF(obj);
    1379           9 :                 z = Z_OBJ_HT(obj)->read_property(&obj, property, BP_VAR_R, cache_slot, &rv);
    1380           9 :                 if (UNEXPECTED(EG(exception))) {
    1381           1 :                         OBJ_RELEASE(Z_OBJ(obj));
    1382           1 :                         return;
    1383             :                 }
    1384             : 
    1385           8 :                 if (UNEXPECTED(Z_TYPE_P(z) == IS_OBJECT) && Z_OBJ_HT_P(z)->get) {
    1386             :                         zval rv2;
    1387           0 :                         zval *value = Z_OBJ_HT_P(z)->get(z, &rv2);
    1388           0 :                         if (z == &rv) {
    1389             :                                 zval_ptr_dtor(&rv);
    1390             :                         }
    1391           0 :                         ZVAL_COPY_VALUE(z, value);
    1392             :                 }
    1393             : 
    1394           8 :                 if (UNEXPECTED(Z_TYPE_P(z) == IS_REFERENCE)) {
    1395           1 :                         ZVAL_COPY(result, Z_REFVAL_P(z));
    1396             :                 } else {
    1397           7 :                         ZVAL_COPY(result, z);
    1398             :                 }
    1399           8 :                 ZVAL_DUP(&z_copy, result);
    1400           8 :                 if (inc) {
    1401           8 :                         increment_function(&z_copy);
    1402             :                 } else {
    1403           0 :                         decrement_function(&z_copy);
    1404             :                 }
    1405           8 :                 Z_OBJ_HT(obj)->write_property(&obj, property, &z_copy, cache_slot);
    1406           8 :                 OBJ_RELEASE(Z_OBJ(obj));
    1407             :                 zval_ptr_dtor(&z_copy);
    1408             :                 zval_ptr_dtor(z);
    1409             :         } else {
    1410           0 :                 zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
    1411           0 :                 ZVAL_NULL(result);
    1412             :         }
    1413             : }
    1414             : 
    1415           5 : static zend_never_inline void zend_pre_incdec_overloaded_property(zval *object, zval *property, void **cache_slot, int inc, zval *result)
    1416             : {
    1417             :         zval rv;
    1418             : 
    1419           8 :         if (Z_OBJ_HT_P(object)->read_property && Z_OBJ_HT_P(object)->write_property) {
    1420             :                 zval *z, obj;
    1421             :                                 
    1422           5 :                 ZVAL_OBJ(&obj, Z_OBJ_P(object));
    1423             :                 Z_ADDREF(obj);
    1424           5 :                 z = Z_OBJ_HT(obj)->read_property(&obj, property, BP_VAR_R, cache_slot, &rv);
    1425           5 :                 if (UNEXPECTED(EG(exception))) {
    1426           2 :                         OBJ_RELEASE(Z_OBJ(obj));
    1427           2 :                         return;
    1428             :                 }
    1429             : 
    1430           3 :                 if (UNEXPECTED(Z_TYPE_P(z) == IS_OBJECT) && Z_OBJ_HT_P(z)->get) {
    1431             :                         zval rv2;
    1432           0 :                         zval *value = Z_OBJ_HT_P(z)->get(z, &rv2);
    1433             : 
    1434           0 :                         if (z == &rv) {
    1435             :                                 zval_ptr_dtor(&rv);
    1436             :                         }
    1437           0 :                         ZVAL_COPY_VALUE(z, value);
    1438             :                 }
    1439           3 :                 ZVAL_DEREF(z);
    1440           3 :                 SEPARATE_ZVAL_NOREF(z);
    1441           3 :                 if (inc) {
    1442           3 :                         increment_function(z);
    1443             :                 } else {
    1444           0 :                         decrement_function(z);
    1445             :                 }
    1446           3 :                 if (UNEXPECTED(result)) {
    1447           1 :                         ZVAL_COPY(result, z);
    1448             :                 }
    1449           3 :                 Z_OBJ_HT(obj)->write_property(&obj, property, z, cache_slot);
    1450           3 :                 OBJ_RELEASE(Z_OBJ(obj));
    1451             :                 zval_ptr_dtor(z);
    1452             :         } else {
    1453           0 :                 zend_error(E_WARNING, "Attempt to increment/decrement property of non-object");
    1454           0 :                 if (UNEXPECTED(result)) {
    1455           0 :                         ZVAL_NULL(result);
    1456             :                 }
    1457             :         }
    1458             : }
    1459             : 
    1460           9 : static zend_never_inline void zend_assign_op_overloaded_property(zval *object, zval *property, void **cache_slot, zval *value, binary_op_type binary_op, zval *result)
    1461             : {
    1462             :         zval *z;
    1463             :         zval rv, obj;
    1464             :         zval *zptr;
    1465             : 
    1466           9 :         ZVAL_OBJ(&obj, Z_OBJ_P(object));
    1467             :         Z_ADDREF(obj);
    1468           9 :         if (EXPECTED(Z_OBJ_HT(obj)->read_property)) {
    1469           9 :                 z = Z_OBJ_HT(obj)->read_property(&obj, property, BP_VAR_R, cache_slot, &rv);
    1470           9 :                 if (UNEXPECTED(EG(exception))) {
    1471           1 :                         OBJ_RELEASE(Z_OBJ(obj));
    1472           1 :                         return;
    1473             :                 }
    1474           8 :                 if (Z_TYPE_P(z) == IS_OBJECT && Z_OBJ_HT_P(z)->get) {
    1475             :                         zval rv2;
    1476           3 :                         zval *value = Z_OBJ_HT_P(z)->get(z, &rv2);
    1477             : 
    1478           3 :                         if (z == &rv) {
    1479             :                                 zval_ptr_dtor(&rv);
    1480             :                         }
    1481           3 :                         ZVAL_COPY_VALUE(z, value);
    1482             :                 }
    1483           8 :                 zptr = z;
    1484           8 :                 ZVAL_DEREF(z);
    1485          10 :                 SEPARATE_ZVAL_NOREF(z);
    1486           8 :                 binary_op(z, z, value);
    1487           8 :                 Z_OBJ_HT(obj)->write_property(&obj, property, z, cache_slot);
    1488           8 :                 if (UNEXPECTED(result)) {
    1489           0 :                         ZVAL_COPY(result, z);
    1490             :                 }
    1491             :                 zval_ptr_dtor(zptr);
    1492             :         } else {
    1493           0 :                 zend_error(E_WARNING, "Attempt to assign property of non-object");
    1494           0 :                 if (UNEXPECTED(result)) {
    1495           0 :                         ZVAL_NULL(result);
    1496             :                 }
    1497             :         }
    1498           8 :         OBJ_RELEASE(Z_OBJ(obj));
    1499             : }
    1500             : 
    1501             : /* Utility Functions for Extensions */
    1502           0 : static void zend_extension_statement_handler(const zend_extension *extension, zend_execute_data *frame)
    1503             : {
    1504           0 :         if (extension->statement_handler) {
    1505           0 :                 extension->statement_handler(frame);
    1506             :         }
    1507           0 : }
    1508             : 
    1509             : 
    1510           0 : static void zend_extension_fcall_begin_handler(const zend_extension *extension, zend_execute_data *frame)
    1511             : {
    1512           0 :         if (extension->fcall_begin_handler) {
    1513           0 :                 extension->fcall_begin_handler(frame);
    1514             :         }
    1515           0 : }
    1516             : 
    1517             : 
    1518           0 : static void zend_extension_fcall_end_handler(const zend_extension *extension, zend_execute_data *frame)
    1519             : {
    1520           0 :         if (extension->fcall_end_handler) {
    1521           0 :                 extension->fcall_end_handler(frame);
    1522             :         }
    1523           0 : }
    1524             : 
    1525             : 
    1526             : static zend_always_inline HashTable *zend_get_target_symbol_table(zend_execute_data *execute_data, int fetch_type)
    1527             : {
    1528             :         HashTable *ht;
    1529             : 
    1530      458275 :         if (EXPECTED(fetch_type == ZEND_FETCH_GLOBAL_LOCK) ||
    1531      229135 :             EXPECTED(fetch_type == ZEND_FETCH_GLOBAL)) {
    1532      123971 :                 ht = &EG(symbol_table);
    1533             :         } else {
    1534             :                 ZEND_ASSERT(fetch_type == ZEND_FETCH_LOCAL);
    1535      105169 :                 if (!(EX_CALL_INFO() & ZEND_CALL_HAS_SYMBOL_TABLE)) {
    1536          14 :                         zend_rebuild_symbol_table();
    1537             :                 }
    1538      105169 :                 ht = EX(symbol_table);
    1539             :         }
    1540      229140 :         return ht;
    1541             : }
    1542             : 
    1543             : static zend_always_inline zval *zend_fetch_dimension_address_inner(HashTable *ht, const zval *dim, int dim_type, int type)
    1544             : {
    1545             :         zval *retval;
    1546             :         zend_string *offset_key;
    1547             :         zend_ulong hval;
    1548             : 
    1549             : try_again:
    1550    10510911 :         if (EXPECTED(Z_TYPE_P(dim) == IS_LONG)) {
    1551     4809330 :                 hval = Z_LVAL_P(dim);
    1552             : num_index:
    1553     9048736 :                 ZEND_HASH_INDEX_FIND(ht, hval, retval, num_undef);
    1554     4593271 :                 return retval;
    1555             : num_undef:
    1556      396214 :                 switch (type) {
    1557             :                         case BP_VAR_R:
    1558          21 :                                 zend_error(E_NOTICE,"Undefined offset: " ZEND_LONG_FMT, hval);
    1559             :                                 /* break missing intentionally */
    1560             :                         case BP_VAR_UNSET:
    1561             :                         case BP_VAR_IS:
    1562          30 :                                 retval = &EG(uninitialized_zval);
    1563             :                                 break;
    1564             :                         case BP_VAR_RW:
    1565           6 :                                 zend_error(E_NOTICE,"Undefined offset: " ZEND_LONG_FMT, hval);
    1566           6 :                                 retval = zend_hash_index_update(ht, hval, &EG(uninitialized_zval));
    1567             :                                 break;
    1568             :                         case BP_VAR_W:
    1569      396178 :                                 retval = zend_hash_index_add_new(ht, hval, &EG(uninitialized_zval));
    1570             :                                 break;
    1571             :                 }
    1572     5701581 :         } else if (EXPECTED(Z_TYPE_P(dim) == IS_STRING)) {
    1573     4507126 :                 offset_key = Z_STR_P(dim);
    1574     4507126 :                 if (dim_type != IS_CONST) {
    1575     6857818 :                         if (ZEND_HANDLE_NUMERIC(offset_key, hval)) {
    1576             :                                 goto num_index;
    1577             :                         }
    1578             :                 }
    1579             : str_index:
    1580     4327055 :                 retval = zend_hash_find(ht, offset_key);
    1581     4327055 :                 if (retval) {
    1582             :                         /* support for $GLOBALS[...] */
    1583     2064563 :                         if (UNEXPECTED(Z_TYPE_P(retval) == IS_INDIRECT)) {
    1584        7911 :                                 retval = Z_INDIRECT_P(retval);
    1585        7911 :                                 if (UNEXPECTED(Z_TYPE_P(retval) == IS_UNDEF)) {
    1586          21 :                                         switch (type) {
    1587             :                                                 case BP_VAR_R:
    1588           1 :                                                         zend_error(E_NOTICE, "Undefined index: %s", ZSTR_VAL(offset_key));
    1589             :                                                         /* break missing intentionally */
    1590             :                                                 case BP_VAR_UNSET:
    1591             :                                                 case BP_VAR_IS:
    1592           1 :                                                         retval = &EG(uninitialized_zval);
    1593             :                                                         break;
    1594             :                                                 case BP_VAR_RW:
    1595           0 :                                                         zend_error(E_NOTICE,"Undefined index: %s", ZSTR_VAL(offset_key));
    1596             :                                                         /* break missing intentionally */
    1597             :                                                 case BP_VAR_W:
    1598          20 :                                                         ZVAL_NULL(retval);
    1599             :                                                         break;
    1600             :                                         }
    1601             :                                 }
    1602             :                         }
    1603             :                 } else {
    1604     2262492 :                         switch (type) {
    1605             :                                 case BP_VAR_R:
    1606      180768 :                                         zend_error(E_NOTICE, "Undefined index: %s", ZSTR_VAL(offset_key));
    1607             :                                         /* break missing intentionally */
    1608             :                                 case BP_VAR_UNSET:
    1609             :                                 case BP_VAR_IS:
    1610      180774 :                                         retval = &EG(uninitialized_zval);
    1611             :                                         break;
    1612             :                                 case BP_VAR_RW:
    1613           2 :                                         zend_error(E_NOTICE,"Undefined index: %s", ZSTR_VAL(offset_key));
    1614           2 :                                         retval = zend_hash_update(ht, offset_key, &EG(uninitialized_zval));
    1615             :                                         break;
    1616             :                                 case BP_VAR_W:
    1617     2081716 :                                         retval = zend_hash_add_new(ht, offset_key, &EG(uninitialized_zval));
    1618             :                                         break;
    1619             :                         }
    1620             :                 }
    1621             :         } else {
    1622     1194455 :                 switch (Z_TYPE_P(dim)) {
    1623             :                         case IS_UNDEF:
    1624           2 :                                 zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
    1625             :                                 /* break missing intentionally */                               
    1626             :                         case IS_NULL:
    1627          14 :                                 offset_key = ZSTR_EMPTY_ALLOC();
    1628             :                                 goto str_index;
    1629             :                         case IS_DOUBLE:
    1630         108 :                                 hval = zend_dval_to_lval(Z_DVAL_P(dim));
    1631             :                                 goto num_index;
    1632             :                         case IS_RESOURCE:
    1633           4 :                                 zend_error(E_NOTICE, "Resource ID#%d used as offset, casting to integer (%d)", Z_RES_HANDLE_P(dim), Z_RES_HANDLE_P(dim));
    1634           4 :                                 hval = Z_RES_HANDLE_P(dim);
    1635             :                                 goto num_index;
    1636             :                         case IS_FALSE:
    1637           7 :                                 hval = 0;
    1638             :                                 goto num_index;
    1639             :                         case IS_TRUE:
    1640           5 :                                 hval = 1;
    1641             :                                 goto num_index;
    1642             :                         case IS_REFERENCE:
    1643     1194365 :                                 dim = Z_REFVAL_P(dim);
    1644             :                                 goto try_again;
    1645             :                         default:
    1646           6 :                                 zend_error(E_WARNING, "Illegal offset type");
    1647           6 :                                 retval = (type == BP_VAR_W || type == BP_VAR_RW) ?
    1648             :                                         NULL : &EG(uninitialized_zval);
    1649             :                 }
    1650             :         }
    1651     4723275 :         return retval;
    1652             : }
    1653             : 
    1654     2400119 : static zend_never_inline zval* ZEND_FASTCALL zend_fetch_dimension_address_inner_W(HashTable *ht, const zval *dim)
    1655             : {
    1656     2400119 :         return zend_fetch_dimension_address_inner(ht, dim, IS_TMP_VAR, BP_VAR_W);
    1657             : }
    1658             : 
    1659      318152 : static zend_never_inline zval* ZEND_FASTCALL zend_fetch_dimension_address_inner_W_CONST(HashTable *ht, const zval *dim)
    1660             : {
    1661      318152 :         return zend_fetch_dimension_address_inner(ht, dim, IS_CONST, BP_VAR_W);
    1662             : }
    1663             : 
    1664     1165399 : static zend_never_inline zval* ZEND_FASTCALL zend_fetch_dimension_address_inner_RW(HashTable *ht, const zval *dim)
    1665             : {
    1666     1165399 :         return zend_fetch_dimension_address_inner(ht, dim, IS_TMP_VAR, BP_VAR_RW);
    1667             : }
    1668             : 
    1669          43 : static zend_never_inline zval* ZEND_FASTCALL zend_fetch_dimension_address_inner_RW_CONST(HashTable *ht, const zval *dim)
    1670             : {
    1671          43 :         return zend_fetch_dimension_address_inner(ht, dim, IS_CONST, BP_VAR_RW);
    1672             : }
    1673             : 
    1674             : static zend_always_inline void zend_fetch_dimension_address(zval *result, zval *container, zval *dim, int dim_type, int type)
    1675             : {
    1676             :     zval *retval;
    1677             : 
    1678      566531 :         if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
    1679             : try_array:
    1680      566099 :                 SEPARATE_ARRAY(container);
    1681             : fetch_from_array:
    1682      566452 :                 if (dim == NULL) {
    1683       96558 :                         retval = zend_hash_next_index_insert(Z_ARRVAL_P(container), &EG(uninitialized_zval));
    1684       96558 :                         if (UNEXPECTED(retval == NULL)) {
    1685           2 :                                 zend_error(E_WARNING, "Cannot add element to the array as the next element is already occupied");
    1686           2 :                                 ZVAL_ERROR(result);
    1687             :                                 return;
    1688             :                         }
    1689             :                 } else {
    1690      939788 :                         retval = zend_fetch_dimension_address_inner(Z_ARRVAL_P(container), dim, dim_type, type);
    1691      469894 :                         if (UNEXPECTED(!retval)) {
    1692           0 :                                 ZVAL_ERROR(result);
    1693             :                                 return;
    1694             :                         }
    1695             :                 }
    1696      566450 :                 ZVAL_INDIRECT(result, retval);
    1697             :                 return;
    1698       63557 :         } else if (EXPECTED(Z_TYPE_P(container) == IS_REFERENCE)) {
    1699       63126 :                 container = Z_REFVAL_P(container);
    1700       63126 :                 if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
    1701             :                         goto try_array;
    1702             :                 }
    1703             :         }
    1704         432 :         if (UNEXPECTED(Z_TYPE_P(container) == IS_STRING)) {
    1705          15 :                 if (dim == NULL) {
    1706           1 :                         zend_throw_error(NULL, "[] operator not supported for strings");
    1707             :                 } else {
    1708          14 :                         zend_check_string_offset(dim, type);
    1709          14 :                         zend_wrong_string_offset();
    1710             :                 }
    1711          15 :                 ZVAL_ERROR(result);
    1712         417 :         } else if (EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
    1713         104 :                 if (/*dim_type == IS_CV &&*/ dim && UNEXPECTED(Z_TYPE_P(dim) == IS_UNDEF)) {
    1714           0 :                         zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
    1715           0 :                         dim = &EG(uninitialized_zval);
    1716             :                 }
    1717          56 :                 if (!Z_OBJ_HT_P(container)->read_dimension) {
    1718           0 :                         zend_throw_error(NULL, "Cannot use object as array");
    1719           0 :                         ZVAL_ERROR(result);
    1720             :                 } else {
    1721          56 :                         retval = Z_OBJ_HT_P(container)->read_dimension(container, dim, type, result);
    1722             : 
    1723          56 :                         if (UNEXPECTED(retval == &EG(uninitialized_zval))) {
    1724           2 :                                 zend_class_entry *ce = Z_OBJCE_P(container);
    1725             : 
    1726           2 :                                 ZVAL_NULL(result);
    1727           2 :                                 zend_error(E_NOTICE, "Indirect modification of overloaded element of %s has no effect", ZSTR_VAL(ce->name));
    1728         104 :                         } else if (EXPECTED(retval && Z_TYPE_P(retval) != IS_UNDEF)) {
    1729          50 :                                 if (!Z_ISREF_P(retval)) {
    1730          76 :                                         if (Z_REFCOUNTED_P(retval) &&
    1731             :                                             Z_REFCOUNT_P(retval) > 1) {
    1732           7 :                                                 if (Z_TYPE_P(retval) != IS_OBJECT) {
    1733             :                                                         Z_DELREF_P(retval);
    1734           5 :                                                         ZVAL_DUP(result, retval);
    1735           5 :                                                         retval = result;
    1736             :                                                 } else {
    1737           2 :                                                         ZVAL_COPY_VALUE(result, retval);
    1738           2 :                                                         retval = result;
    1739             :                                                 }
    1740             :                                         }
    1741          40 :                                         if (Z_TYPE_P(retval) != IS_OBJECT) {
    1742           9 :                                                 zend_class_entry *ce = Z_OBJCE_P(container);
    1743           9 :                                                 zend_error(E_NOTICE, "Indirect modification of overloaded element of %s has no effect", ZSTR_VAL(ce->name));
    1744             :                                         }
    1745          10 :                                 } else if (UNEXPECTED(Z_REFCOUNT_P(retval) == 1)) {
    1746           6 :                                         ZVAL_UNREF(retval);
    1747             :                                 }
    1748          50 :                                 if (result != retval) {
    1749           5 :                                         ZVAL_INDIRECT(result, retval);
    1750             :                                 }
    1751             :                         } else {
    1752           4 :                                 ZVAL_ERROR(result);
    1753             :                         }
    1754             :                 }
    1755             :         } else {
    1756         365 :                 if (type != BP_VAR_W && UNEXPECTED(Z_TYPE_P(container) == IS_UNDEF)) {
    1757           0 :                         zval_undefined_cv(EG(current_execute_data)->opline->op1.var, EG(current_execute_data));
    1758             :                 }
    1759         711 :                 if (/*dim_type == IS_CV &&*/ dim && UNEXPECTED(Z_TYPE_P(dim) == IS_UNDEF)) {
    1760           0 :                         zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
    1761             :                 }
    1762         361 :                 if (EXPECTED(Z_TYPE_P(container) <= IS_FALSE)) {
    1763         353 :                         if (type != BP_VAR_UNSET) {
    1764         353 :                                 ZVAL_NEW_ARR(container);
    1765         353 :                                 zend_hash_init(Z_ARRVAL_P(container), 8, NULL, ZVAL_PTR_DTOR, 0);
    1766             :                                 goto fetch_from_array;
    1767             :                         } else {
    1768             :                                 /* for read-mode only */
    1769           0 :                                 ZVAL_NULL(result);
    1770             :                         }
    1771           8 :                 } else if (EXPECTED(Z_ISERROR_P(container))) {
    1772           0 :                         ZVAL_ERROR(result);
    1773             :                 } else {
    1774           8 :                         if (type == BP_VAR_UNSET) {
    1775           0 :                                 zend_error(E_WARNING, "Cannot unset offset in a non-array variable");
    1776           0 :                                 ZVAL_NULL(result);
    1777             :                         } else {
    1778           8 :                                 zend_error(E_WARNING, "Cannot use a scalar value as an array");
    1779           8 :                                 ZVAL_ERROR(result);
    1780             :                         }
    1781             :                 }
    1782             :         }
    1783             : }
    1784             : 
    1785      368710 : static zend_never_inline void zend_fetch_dimension_address_W(zval *result, zval *container_ptr, zval *dim, int dim_type)
    1786             : {
    1787             :         zend_fetch_dimension_address(result, container_ptr, dim, dim_type, BP_VAR_W);
    1788      368710 : }
    1789             : 
    1790      197798 : static zend_never_inline void zend_fetch_dimension_address_RW(zval *result, zval *container_ptr, zval *dim, int dim_type)
    1791             : {
    1792             :         zend_fetch_dimension_address(result, container_ptr, dim, dim_type, BP_VAR_RW);
    1793      197798 : }
    1794             : 
    1795          23 : static zend_never_inline void zend_fetch_dimension_address_UNSET(zval *result, zval *container_ptr, zval *dim, int dim_type)
    1796             : {
    1797             :         zend_fetch_dimension_address(result, container_ptr, dim, dim_type, BP_VAR_UNSET);
    1798          23 : }
    1799             : 
    1800             : static zend_always_inline void zend_fetch_dimension_address_read(zval *result, zval *container, zval *dim, int dim_type, int type, int support_strings, int slow)
    1801             : {
    1802             :         zval *retval;
    1803             : 
    1804     2612817 :         if (!slow) {
    1805     2559794 :                 if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
    1806             : try_array:
    1807      419530 :                         retval = zend_fetch_dimension_address_inner(Z_ARRVAL_P(container), dim, dim_type, type);
    1808      209765 :                         ZVAL_COPY(result, retval);
    1809             :                         return;
    1810     2350055 :                 } else if (EXPECTED(Z_TYPE_P(container) == IS_REFERENCE)) {
    1811          31 :                         container = Z_REFVAL_P(container);
    1812          31 :                         if (EXPECTED(Z_TYPE_P(container) == IS_ARRAY)) {
    1813             :                                 goto try_array;
    1814             :                         }
    1815             :                 }
    1816             :         }
    1817     4806006 :         if (support_strings && EXPECTED(Z_TYPE_P(container) == IS_STRING)) {
    1818             :                 zend_long offset;
    1819             : 
    1820             : try_string_offset:
    1821     2402037 :                 if (UNEXPECTED(Z_TYPE_P(dim) != IS_LONG)) {
    1822          46 :                         switch (Z_TYPE_P(dim)) {
    1823             :                                 /* case IS_LONG: */
    1824             :                                 case IS_STRING:
    1825          60 :                                         if (IS_LONG == is_numeric_string(Z_STRVAL_P(dim), Z_STRLEN_P(dim), NULL, NULL, -1)) {
    1826             :                                                 break;
    1827             :                                         }
    1828          29 :                                         if (type == BP_VAR_IS) {
    1829           8 :                                                 ZVAL_NULL(result);
    1830             :                                                 return;
    1831             :                                         }
    1832          21 :                                         zend_error(E_WARNING, "Illegal string offset '%s'", Z_STRVAL_P(dim));
    1833             :                                         break;
    1834             :                                 case IS_UNDEF:
    1835           0 :                                         zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
    1836             :                                 case IS_DOUBLE:
    1837             :                                 case IS_NULL:
    1838             :                                 case IS_FALSE:
    1839             :                                 case IS_TRUE:
    1840          13 :                                         if (type != BP_VAR_IS) {
    1841          11 :                                                 zend_error(E_NOTICE, "String offset cast occurred");
    1842             :                                         }
    1843             :                                         break;
    1844             :                                 case IS_REFERENCE:
    1845           0 :                                         dim = Z_REFVAL_P(dim);
    1846             :                                         goto try_string_offset;
    1847             :                                 default:
    1848           3 :                                         zend_error(E_WARNING, "Illegal offset type");
    1849             :                                         break;
    1850             :                         }
    1851             : 
    1852          38 :                         offset = _zval_get_long_func(dim);
    1853             :                 } else {
    1854     2401991 :                         offset = Z_LVAL_P(dim);
    1855             :                 }
    1856             : 
    1857     2402029 :                 if (UNEXPECTED(Z_STRLEN_P(container) < (size_t)((offset < 0) ? -offset : (offset + 1)))) {
    1858          37 :                         if (type != BP_VAR_IS) {
    1859          35 :                                 zend_error(E_NOTICE, "Uninitialized string offset: " ZEND_LONG_FMT, offset);
    1860          35 :                                 ZVAL_EMPTY_STRING(result);
    1861             :                         } else {
    1862           2 :                                 ZVAL_NULL(result);
    1863             :                         }
    1864             :                 } else {
    1865             :                         zend_uchar c;
    1866             :                         zend_long real_offset;
    1867             : 
    1868     2401997 :                         real_offset = (UNEXPECTED(offset < 0)) /* Handle negative offset */
    1869           5 :                                 ? (zend_long)Z_STRLEN_P(container) + offset : offset;
    1870     2401992 :                         c = (zend_uchar)Z_STRVAL_P(container)[real_offset];
    1871             : 
    1872     2401992 :                         if (CG(one_char_string)[c]) {
    1873           0 :                                 ZVAL_INTERNED_STR(result, CG(one_char_string)[c]);
    1874             :                         } else {
    1875     4803984 :                                 ZVAL_NEW_STR(result, zend_string_init(Z_STRVAL_P(container) + real_offset, 1, 0));
    1876             :                         }
    1877             :                 }
    1878        1015 :         } else if (EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
    1879         811 :                 if (/*dim_type == IS_CV &&*/ UNEXPECTED(Z_TYPE_P(dim) == IS_UNDEF)) {
    1880           0 :                         zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
    1881           0 :                         dim = &EG(uninitialized_zval);
    1882             :                 }
    1883         811 :                 if (!Z_OBJ_HT_P(container)->read_dimension) {
    1884           0 :                         zend_throw_error(NULL, "Cannot use object as array");
    1885           0 :                         ZVAL_NULL(result);
    1886             :                 } else {
    1887         811 :                         retval = Z_OBJ_HT_P(container)->read_dimension(container, dim, type, result);
    1888             : 
    1889             :                         ZEND_ASSERT(result != NULL);
    1890         811 :                         if (retval) {
    1891         800 :                                 if (result != retval) {
    1892         135 :                                         ZVAL_COPY(result, retval);
    1893             :                                 }
    1894             :                         } else {
    1895          11 :                                 ZVAL_NULL(result);
    1896             :                         }
    1897             :                 }
    1898             :         } else {
    1899         388 :                 if (type != BP_VAR_IS && UNEXPECTED(Z_TYPE_P(container) == IS_UNDEF)) {
    1900          15 :                         zval_undefined_cv(EG(current_execute_data)->opline->op1.var, EG(current_execute_data));
    1901             :                 }
    1902         204 :                 if (/*dim_type == IS_CV &&*/ UNEXPECTED(Z_TYPE_P(dim) == IS_UNDEF)) {
    1903           3 :                         zval_undefined_cv(EG(current_execute_data)->opline->op2.var, EG(current_execute_data));
    1904             :                 }
    1905         204 :                 ZVAL_NULL(result);
    1906             :         }
    1907             : }
    1908             : 
    1909     2351754 : static zend_never_inline void zend_fetch_dimension_address_read_R(zval *result, zval *container, zval *dim, int dim_type)
    1910             : {
    1911             :         zend_fetch_dimension_address_read(result, container, dim, dim_type, BP_VAR_R, 1, 0);
    1912     2351754 : }
    1913             : 
    1914       53023 : static zend_never_inline void zend_fetch_dimension_address_read_R_slow(zval *result, zval *container, zval *dim)
    1915             : {
    1916             :         zend_fetch_dimension_address_read(result, container, dim, IS_CV, BP_VAR_R, 1, 1);
    1917       53023 : }
    1918             : 
    1919         912 : static zend_never_inline void zend_fetch_dimension_address_read_IS(zval *result, zval *container, zval *dim, int dim_type)
    1920             : {
    1921             :         zend_fetch_dimension_address_read(result, container, dim, dim_type, BP_VAR_IS, 1, 0);
    1922         912 : }
    1923             : 
    1924      207095 : static zend_never_inline void zend_fetch_dimension_address_read_LIST(zval *result, zval *container, zval *dim)
    1925             : {
    1926             :         zend_fetch_dimension_address_read(result, container, dim, IS_TMP_VAR, BP_VAR_R, 0, 0);
    1927      207095 : }
    1928             : 
    1929           9 : ZEND_API void zend_fetch_dimension_by_zval(zval *result, zval *container, zval *dim)
    1930             : {
    1931           9 :         zend_fetch_dimension_address_read_R(result, container, dim, IS_TMP_VAR);
    1932           9 : }
    1933             : 
    1934          33 : ZEND_API void zend_fetch_dimension_by_zval_is(zval *result, zval *container, zval *dim, int dim_type)
    1935             : {
    1936             :         zend_fetch_dimension_address_read(result, container, dim, dim_type, BP_VAR_IS, 1, 0);
    1937          33 : }
    1938             : 
    1939             : 
    1940             : static zend_always_inline void zend_fetch_property_address(zval *result, zval *container, uint32_t container_op_type, zval *prop_ptr, uint32_t prop_op_type, void **cache_slot, int type)
    1941             : {
    1942      463793 :     if (container_op_type != IS_UNUSED && UNEXPECTED(Z_TYPE_P(container) != IS_OBJECT)) {
    1943             :                 do {
    1944          88 :                         if (Z_ISREF_P(container)) {
    1945          44 :                                 container = Z_REFVAL_P(container);
    1946          44 :                                 if (EXPECTED(Z_TYPE_P(container) == IS_OBJECT)) {
    1947             :                                         break;
    1948             :                                 }
    1949             :                         }
    1950             : 
    1951             :                         /* this should modify object only if it's empty */
    1952         100 :                         if (type != BP_VAR_UNSET &&
    1953           3 :                             EXPECTED(Z_TYPE_P(container) <= IS_FALSE ||
    1954             :                               (Z_TYPE_P(container) == IS_STRING && Z_STRLEN_P(container)==0))) {
    1955             :                                 zval_ptr_dtor_nogc(container);
    1956          38 :                                 object_init(container);
    1957             :                         } else {
    1958           8 :                                 if (container_op_type != IS_VAR || EXPECTED(!Z_ISERROR_P(container))) {
    1959           6 :                                         zend_error(E_WARNING, "Attempt to modify property of non-object");
    1960             :                                 }
    1961           7 :                                 ZVAL_ERROR(result);
    1962             :                                 return;
    1963             :                         }
    1964             :                 } while (0);
    1965             :         }
    1966      751788 :         if (prop_op_type == IS_CONST &&
    1967      375885 :             EXPECTED(Z_OBJCE_P(container) == CACHED_PTR_EX(cache_slot))) {
    1968      375429 :                 uint32_t prop_offset = (uint32_t)(intptr_t)CACHED_PTR_EX(cache_slot + 1);
    1969      375429 :                 zend_object *zobj = Z_OBJ_P(container);
    1970             :                 zval *retval;
    1971             : 
    1972      375429 :                 if (EXPECTED(prop_offset != (uint32_t)ZEND_DYNAMIC_PROPERTY_OFFSET)) {
    1973      375219 :                         retval = OBJ_PROP(zobj, prop_offset);
    1974      375219 :                         if (EXPECTED(Z_TYPE_P(retval) != IS_UNDEF)) {
    1975      375219 :                                 ZVAL_INDIRECT(result, retval);
    1976             :                                 return;
    1977             :                         }
    1978         210 :                 } else if (EXPECTED(zobj->properties != NULL)) {
    1979         204 :                         if (UNEXPECTED(GC_REFCOUNT(zobj->properties) > 1)) {
    1980           2 :                                 if (EXPECTED(!(GC_FLAGS(zobj->properties) & IS_ARRAY_IMMUTABLE))) {
    1981           2 :                                         GC_REFCOUNT(zobj->properties)--;
    1982             :                                 }
    1983           2 :                                 zobj->properties = zend_array_dup(zobj->properties);
    1984             :                         }
    1985         204 :                         retval = zend_hash_find(zobj->properties, Z_STR_P(prop_ptr));
    1986         204 :                         if (EXPECTED(retval)) {
    1987           5 :                                 ZVAL_INDIRECT(result, retval);
    1988             :                                 return;
    1989             :                         }
    1990             :                 }
    1991             :         }
    1992         679 :         if (EXPECTED(Z_OBJ_HT_P(container)->get_property_ptr_ptr)) {
    1993         679 :                 zval *ptr = Z_OBJ_HT_P(container)->get_property_ptr_ptr(container, prop_ptr, type, cache_slot);
    1994         679 :                 if (NULL == ptr) {
    1995          60 :                         if (EXPECTED(Z_OBJ_HT_P(container)->read_property)) {
    1996             : use_read_property:
    1997          60 :                                 ptr = Z_OBJ_HT_P(container)->read_property(container, prop_ptr, type, cache_slot, result);
    1998          60 :                                 if (ptr != result) {
    1999           2 :                                         ZVAL_INDIRECT(result, ptr);
    2000          66 :                                 } else if (UNEXPECTED(Z_ISREF_P(ptr) && Z_REFCOUNT_P(ptr) == 1)) {
    2001           1 :                                         ZVAL_UNREF(ptr);
    2002             :                                 }
    2003             :                         } else {
    2004           0 :                                 zend_throw_error(NULL, "Cannot access undefined property for object with overloaded property access");
    2005           0 :                                 ZVAL_ERROR(result);
    2006             :                         }
    2007             :                 } else {
    2008         619 :                         ZVAL_INDIRECT(result, ptr);
    2009             :                 }
    2010           0 :         } else if (EXPECTED(Z_OBJ_HT_P(container)->read_property)) {
    2011             :                 goto use_read_property; 
    2012             :         } else {
    2013           0 :                 zend_error(E_WARNING, "This object doesn't support property references");
    2014           0 :                 ZVAL_ERROR(result);
    2015             :         }
    2016             : }
    2017             : 
    2018             : #if ZEND_INTENSIVE_DEBUGGING
    2019             : 
    2020             : #define CHECK_SYMBOL_TABLES()                                                                                                   \
    2021             :         zend_hash_apply(&EG(symbol_table), zend_check_symbol);                      \
    2022             :         if (&EG(symbol_table)!=EX(symbol_table)) {                                                  \
    2023             :                 zend_hash_apply(EX(symbol_table), zend_check_symbol);   \
    2024             :         }
    2025             : 
    2026             : static int zend_check_symbol(zval *pz)
    2027             : {
    2028             :         if (Z_TYPE_P(pz) == IS_INDIRECT) {
    2029             :                 pz = Z_INDIRECT_P(pz);
    2030             :         }
    2031             :         if (Z_TYPE_P(pz) > 10) {
    2032             :                 fprintf(stderr, "Warning!  %x has invalid type!\n", *pz);
    2033             : /* See http://support.microsoft.com/kb/190351 */
    2034             : #ifdef ZEND_WIN32
    2035             :                 fflush(stderr);
    2036             : #endif
    2037             :         } else if (Z_TYPE_P(pz) == IS_ARRAY) {
    2038             :                 zend_hash_apply(Z_ARRVAL_P(pz), zend_check_symbol);
    2039             :         } else if (Z_TYPE_P(pz) == IS_OBJECT) {
    2040             :                 /* OBJ-TBI - doesn't support new object model! */
    2041             :                 zend_hash_apply(Z_OBJPROP_P(pz), zend_check_symbol);
    2042             :         }
    2043             : 
    2044             :         return 0;
    2045             : }
    2046             : 
    2047             : 
    2048             : #else
    2049             : #define CHECK_SYMBOL_TABLES()
    2050             : #endif
    2051             : 
    2052           0 : ZEND_API void execute_internal(zend_execute_data *execute_data, zval *return_value)
    2053             : {
    2054           0 :         execute_data->func->internal_function.handler(execute_data, return_value);
    2055           0 : }
    2056             : 
    2057         434 : ZEND_API void zend_clean_and_cache_symbol_table(zend_array *symbol_table) /* {{{ */
    2058             : {
    2059         434 :         if (EG(symtable_cache_ptr) >= EG(symtable_cache_limit)) {
    2060           4 :                 zend_array_destroy(symbol_table);
    2061             :         } else {
    2062             :                 /* clean before putting into the cache, since clean
    2063             :                    could call dtors, which could use cached hash */
    2064         430 :                 zend_symtable_clean(symbol_table);
    2065         430 :                 *(++EG(symtable_cache_ptr)) = symbol_table;
    2066             :         }
    2067         434 : }
    2068             : /* }}} */
    2069             : 
    2070             : static zend_always_inline void i_free_compiled_variables(zend_execute_data *execute_data) /* {{{ */
    2071             : {
    2072     4962967 :         zval *cv = EX_VAR_NUM(0);
    2073     4962967 :         zval *end = cv + EX(func)->op_array.last_var;
    2074    28929524 :         while (EXPECTED(cv != end)) {
    2075    23966557 :                 if (Z_REFCOUNTED_P(cv)) {
    2076    15142512 :                         if (!Z_DELREF_P(cv)) {
    2077     6538242 :                                 zend_refcounted *r = Z_COUNTED_P(cv);
    2078     6538242 :                                 ZVAL_NULL(cv);
    2079     6538242 :                                 zval_dtor_func(r);
    2080             :                         } else {
    2081             :                                 GC_ZVAL_CHECK_POSSIBLE_ROOT(cv);
    2082             :                         }
    2083             :                 }
    2084    23966557 :                 cv++;
    2085             :         }
    2086             : }
    2087             : /* }}} */
    2088             : 
    2089       50455 : void zend_free_compiled_variables(zend_execute_data *execute_data) /* {{{ */
    2090             : {
    2091             :         i_free_compiled_variables(execute_data);
    2092       50455 : }
    2093             : /* }}} */
    2094             : 
    2095             : #define ZEND_VM_INTERRUPT_CHECK() do { \
    2096             :                 if (UNEXPECTED(EG(vm_interrupt))) { \
    2097             :                         ZEND_VM_INTERRUPT(); \
    2098             :                 } \
    2099             :         } while (0)
    2100             : 
    2101             : #define ZEND_VM_LOOP_INTERRUPT_CHECK() do { \
    2102             :                 if (UNEXPECTED(EG(vm_interrupt))) { \
    2103             :                         ZEND_VM_LOOP_INTERRUPT(); \
    2104             :                 } \
    2105             :         } while (0)
    2106             : 
    2107             : /*
    2108             :  * Stack Frame Layout (the whole stack frame is allocated at once)
    2109             :  * ==================
    2110             :  *
    2111             :  *                             +========================================+
    2112             :  * EG(current_execute_data) -> | zend_execute_data                      |
    2113             :  *                             +----------------------------------------+
    2114             :  *     EX_CV_NUM(0) ---------> | VAR[0] = ARG[1]                        |
    2115             :  *                             | ...                                    |
    2116             :  *                             | VAR[op_array->num_args-1] = ARG[N]     |
    2117             :  *                             | ...                                    |
    2118             :  *                             | VAR[op_array->last_var-1]              |
    2119             :  *                             | VAR[op_array->last_var] = TMP[0]       |
    2120             :  *                             | ...                                    |
    2121             :  *                             | VAR[op_array->last_var+op_array->T-1]  |
    2122             :  *                             | ARG[N+1] (extra_args)                  |
    2123             :  *                             | ...                                    |
    2124             :  *                             +----------------------------------------+
    2125             :  */
    2126             : 
    2127             : static zend_always_inline void i_init_func_execute_data(zend_execute_data *execute_data, zend_op_array *op_array, zval *return_value) /* {{{ */
    2128             : {
    2129             :         uint32_t first_extra_arg, num_args;
    2130             :         ZEND_ASSERT(EX(func) == (zend_function*)op_array);
    2131             : 
    2132     4393145 :         EX(opline) = op_array->opcodes;
    2133     4393145 :         EX(call) = NULL;
    2134     4393145 :         EX(return_value) = return_value;
    2135             : 
    2136             :         /* Handle arguments */
    2137     4393145 :         first_extra_arg = op_array->num_args;
    2138     4393145 :         num_args = EX_NUM_ARGS();
    2139     4393145 :         if (UNEXPECTED(num_args > first_extra_arg)) {
    2140         485 :                 if (EXPECTED(!(op_array->fn_flags & ZEND_ACC_CALL_VIA_TRAMPOLINE))) {
    2141             :                         zval *end, *src, *dst;
    2142         150 :                         uint32_t type_flags = 0;
    2143             : 
    2144         150 :                         if (EXPECTED((op_array->fn_flags & ZEND_ACC_HAS_TYPE_HINTS) == 0)) {
    2145             :                                 /* Skip useless ZEND_RECV and ZEND_RECV_INIT opcodes */
    2146         146 :                                 EX(opline) += first_extra_arg;
    2147             :                         }
    2148             : 
    2149             :                         /* move extra args into separate array after all CV and TMP vars */
    2150         150 :                         end = EX_VAR_NUM(first_extra_arg - 1);
    2151         150 :                         src = end + (num_args - first_extra_arg);
    2152         150 :                         dst = src + (op_array->last_var + op_array->T - first_extra_arg);
    2153         150 :                         if (EXPECTED(src != dst)) {
    2154             :                                 do {
    2155       86782 :                                         type_flags |= Z_TYPE_INFO_P(src);
    2156       86782 :                                         ZVAL_COPY_VALUE(dst, src);
    2157       86782 :                                         ZVAL_UNDEF(src);
    2158       86782 :                                         src--;
    2159       86782 :                                         dst--;
    2160       86782 :                                 } while (src != end);
    2161             :                         } else {
    2162             :                                 do {
    2163         326 :                                         type_flags |= Z_TYPE_INFO_P(src);
    2164         326 :                                         src--;
    2165         326 :                                 } while (src != end);
    2166             :                         }
    2167         150 :                         ZEND_ADD_CALL_FLAG(execute_data, ((type_flags >> Z_TYPE_FLAGS_SHIFT) & IS_TYPE_REFCOUNTED));
    2168             :                 }
    2169     4392660 :         } else if (EXPECTED((op_array->fn_flags & ZEND_ACC_HAS_TYPE_HINTS) == 0)) {
    2170             :                 /* Skip useless ZEND_RECV and ZEND_RECV_INIT opcodes */
    2171     4304345 :                 EX(opline) += num_args;
    2172             :         }
    2173             : 
    2174             :         /* Initialize CV variables (skip arguments) */
    2175     4393145 :         if (EXPECTED((int)num_args < op_array->last_var)) {
    2176     1613564 :                 zval *var = EX_VAR_NUM(num_args);
    2177     1613564 :                 zval *end = EX_VAR_NUM(op_array->last_var);
    2178             : 
    2179             :                 do {
    2180     9885447 :                         ZVAL_UNDEF(var);
    2181     9885447 :                         var++;
    2182     9885447 :                 } while (var != end);
    2183             :         }
    2184             : 
    2185     4393145 :         EX_LOAD_RUN_TIME_CACHE(op_array);
    2186     4393145 :         EX_LOAD_LITERALS(op_array);
    2187             : 
    2188     4393145 :         EG(current_execute_data) = execute_data;
    2189             : }
    2190             : /* }}} */
    2191             : 
    2192        9716 : static zend_never_inline void ZEND_FASTCALL init_func_run_time_cache(zend_op_array *op_array) /* {{{ */
    2193             : {
    2194             :         ZEND_ASSERT(op_array->run_time_cache == NULL);
    2195       19432 :         op_array->run_time_cache = zend_arena_alloc(&CG(arena), op_array->cache_size);
    2196        9716 :         memset(op_array->run_time_cache, 0, op_array->cache_size);
    2197        9716 : }
    2198             : /* }}} */
    2199             : 
    2200             : static zend_always_inline void i_init_code_execute_data(zend_execute_data *execute_data, zend_op_array *op_array, zval *return_value) /* {{{ */
    2201             : {
    2202             :         ZEND_ASSERT(EX(func) == (zend_function*)op_array);
    2203             : 
    2204       10887 :         EX(opline) = op_array->opcodes;
    2205       10887 :         EX(call) = NULL;
    2206       10887 :         EX(return_value) = return_value;
    2207             : 
    2208       10887 :         zend_attach_symbol_table(execute_data);
    2209             : 
    2210       10887 :         if (!op_array->run_time_cache) {
    2211       10887 :                 op_array->run_time_cache = emalloc(op_array->cache_size);
    2212       10887 :                 memset(op_array->run_time_cache, 0, op_array->cache_size);
    2213             :         }
    2214       10887 :         EX_LOAD_RUN_TIME_CACHE(op_array);
    2215       10887 :         EX_LOAD_LITERALS(op_array);
    2216             : 
    2217       10887 :         EG(current_execute_data) = execute_data;
    2218             : }
    2219             : /* }}} */
    2220             : 
    2221             : static zend_always_inline void i_init_execute_data(zend_execute_data *execute_data, zend_op_array *op_array, zval *return_value) /* {{{ */
    2222             : {
    2223             :         ZEND_ASSERT(EX(func) == (zend_function*)op_array);
    2224             : 
    2225      596771 :         EX(opline) = op_array->opcodes;
    2226      596771 :         EX(call) = NULL;
    2227      596771 :         EX(return_value) = return_value;
    2228             : 
    2229      596771 :         if (EX_CALL_INFO() & ZEND_CALL_HAS_SYMBOL_TABLE) {
    2230       23248 :                 zend_attach_symbol_table(execute_data);
    2231             :         } else {
    2232             :                 uint32_t first_extra_arg, num_args;
    2233             : 
    2234             :                 /* Handle arguments */
    2235      573523 :                 first_extra_arg = op_array->num_args;
    2236      573523 :                 num_args = EX_NUM_ARGS();
    2237      573523 :                 if (UNEXPECTED(num_args > first_extra_arg)) {
    2238         807 :                         if (EXPECTED(!(op_array->fn_flags & ZEND_ACC_CALL_VIA_TRAMPOLINE))) {
    2239             :                                 zval *end, *src, *dst;
    2240         805 :                                 uint32_t type_flags = 0;
    2241             : 
    2242         805 :                                 if (EXPECTED((op_array->fn_flags & ZEND_ACC_HAS_TYPE_HINTS) == 0)) {
    2243             :                                         /* Skip useless ZEND_RECV and ZEND_RECV_INIT opcodes */
    2244         799 :                                         EX(opline) += first_extra_arg;
    2245             :                                 }
    2246             : 
    2247             :                                 /* move extra args into separate array after all CV and TMP vars */
    2248         805 :                                 end = EX_VAR_NUM(first_extra_arg - 1);
    2249         805 :                                 src = end + (num_args - first_extra_arg);
    2250         805 :                                 dst = src + (op_array->last_var + op_array->T - first_extra_arg);
    2251         805 :                                 if (EXPECTED(src != dst)) {
    2252             :                                         do {
    2253         828 :                                                 type_flags |= Z_TYPE_INFO_P(src);
    2254         828 :                                                 ZVAL_COPY_VALUE(dst, src);
    2255         828 :                                                 ZVAL_UNDEF(src);
    2256         828 :                                                 src--;
    2257         828 :                                                 dst--;
    2258         828 :                                         } while (src != end);
    2259             :                                 } else {
    2260             :                                         do {
    2261         758 :                                                 type_flags |= Z_TYPE_INFO_P(src);
    2262         758 :                                                 src--;
    2263         758 :                                         } while (src != end);
    2264             :                                 }
    2265         805 :                                 ZEND_ADD_CALL_FLAG(execute_data, ((type_flags >> Z_TYPE_FLAGS_SHIFT) & IS_TYPE_REFCOUNTED));
    2266             :                         }
    2267      572716 :                 } else if (EXPECTED((op_array->fn_flags & ZEND_ACC_HAS_TYPE_HINTS) == 0)) {
    2268             :                         /* Skip useless ZEND_RECV and ZEND_RECV_INIT opcodes */
    2269      572702 :                         EX(opline) += num_args;
    2270             :                 }
    2271             : 
    2272             :                 /* Initialize CV variables (skip arguments) */
    2273      573523 :                 if (EXPECTED((int)num_args < op_array->last_var)) {
    2274      226398 :                         zval *var = EX_VAR_NUM(num_args);
    2275      226398 :                         zval *end = EX_VAR_NUM(op_array->last_var);
    2276             : 
    2277             :                         do {
    2278      654216 :                                 ZVAL_UNDEF(var);
    2279      654216 :                                 var++;
    2280      654216 :                         } while (var != end);
    2281             :                 }
    2282             :         }
    2283             : 
    2284      596771 :         if (!op_array->run_time_cache) {
    2285       26215 :                 if (op_array->function_name) {
    2286        5934 :                         op_array->run_time_cache = zend_arena_alloc(&CG(arena), op_array->cache_size);
    2287             :                 } else {
    2288       23248 :                         op_array->run_time_cache = emalloc(op_array->cache_size);
    2289             :                 }
    2290       26215 :                 memset(op_array->run_time_cache, 0, op_array->cache_size);
    2291             :         }
    2292      596771 :         EX_LOAD_RUN_TIME_CACHE(op_array);
    2293      596771 :         EX_LOAD_LITERALS(op_array);
    2294             : 
    2295      596771 :         EG(current_execute_data) = execute_data;
    2296             : }
    2297             : /* }}} */
    2298             : 
    2299      573523 : ZEND_API void zend_init_execute_data(zend_execute_data *execute_data, zend_op_array *op_array, zval *return_value) /* {{{ */
    2300             : {
    2301      573523 :         EX(prev_execute_data) = EG(current_execute_data);
    2302             :         i_init_execute_data(execute_data, op_array, return_value);
    2303      573523 : }
    2304             : /* }}} */
    2305             : 
    2306             : static zend_always_inline zend_bool zend_is_by_ref_func_arg_fetch(const zend_op *opline, zend_execute_data *call) /* {{{ */
    2307             : {
    2308     2353978 :         uint32_t arg_num = opline->extended_value & ZEND_FETCH_ARG_MASK;
    2309             : 
    2310     2353978 :         if (EXPECTED(arg_num <= MAX_ARG_FLAG_NUM)) {
    2311     2351981 :                 return QUICK_ARG_SHOULD_BE_SENT_BY_REF(call->func, arg_num);
    2312             :         }
    2313        3994 :         return ARG_SHOULD_BE_SENT_BY_REF(call->func, arg_num);
    2314             : }
    2315             : /* }}} */
    2316             : 
    2317           7 : static zend_execute_data *zend_vm_stack_copy_call_frame(zend_execute_data *call, uint32_t passed_args, uint32_t additional_args) /* {{{ */
    2318             : {
    2319             :         zend_execute_data *new_call;
    2320           7 :         int used_stack = (EG(vm_stack_top) - (zval*)call) + additional_args;
    2321             : 
    2322             :         /* copy call frame into new stack segment */
    2323           7 :         new_call = zend_vm_stack_extend(used_stack * sizeof(zval));
    2324           7 :         *new_call = *call;
    2325           7 :         ZEND_ADD_CALL_FLAG(new_call, ZEND_CALL_ALLOCATED);
    2326             : 
    2327           7 :         if (passed_args) {
    2328           1 :                 zval *src = ZEND_CALL_ARG(call, 1);
    2329           1 :                 zval *dst = ZEND_CALL_ARG(new_call, 1);
    2330             :                 do {
    2331       10000 :                         ZVAL_COPY_VALUE(dst, src);
    2332       10000 :                         passed_args--;
    2333       10000 :                         src++;
    2334       10000 :                         dst++;
    2335       10000 :                 } while (passed_args);
    2336             :         }
    2337             : 
    2338             :         /* delete old call_frame from previous stack segment */
    2339           7 :         EG(vm_stack)->prev->top = (zval*)call;
    2340             : 
    2341             :         /* delete previous stack segment if it becames empty */
    2342           7 :         if (UNEXPECTED(EG(vm_stack)->prev->top == ZEND_VM_STACK_ELEMENTS(EG(vm_stack)->prev))) {
    2343           0 :                 zend_vm_stack r = EG(vm_stack)->prev;
    2344             : 
    2345           0 :                 EG(vm_stack)->prev = r->prev;
    2346           0 :                 efree(r);
    2347             :         }
    2348             : 
    2349           7 :         return new_call;
    2350             : }
    2351             : /* }}} */
    2352             : 
    2353             : static zend_always_inline void zend_vm_stack_extend_call_frame(zend_execute_data **call, uint32_t passed_args, uint32_t additional_args) /* {{{ */
    2354             : {
    2355         217 :         if (EXPECTED((uint32_t)(EG(vm_stack_end) - EG(vm_stack_top)) > additional_args)) {
    2356         210 :                 EG(vm_stack_top) += additional_args;
    2357             :         } else {
    2358           7 :                 *call = zend_vm_stack_copy_call_frame(*call, passed_args, additional_args);
    2359             :         }
    2360             : }
    2361             : /* }}} */
    2362             : 
    2363             : static zend_always_inline zend_generator *zend_get_running_generator(zend_execute_data *execute_data) /* {{{ */
    2364             : {
    2365             :         /* The generator object is stored in EX(return_value) */
    2366     2451903 :         zend_generator *generator = (zend_generator *) EX(return_value);
    2367             :         /* However control may currently be delegated to another generator.
    2368             :          * That's the one we're interested in. */
    2369     2451903 :         return generator;
    2370             : }
    2371             : /* }}} */
    2372             : 
    2373        3919 : static void cleanup_unfinished_calls(zend_execute_data *execute_data, uint32_t op_num) /* {{{ */
    2374             : {
    2375        3919 :         if (UNEXPECTED(EX(call))) {
    2376        1079 :                 zend_execute_data *call = EX(call);
    2377        1079 :                 zend_op *opline = EX(func)->op_array.opcodes + op_num;
    2378             :                 int level;
    2379             :                 int do_exit;
    2380             :                 
    2381        1079 :                 if (UNEXPECTED(opline->opcode == ZEND_INIT_FCALL ||
    2382             :                         opline->opcode == ZEND_INIT_FCALL_BY_NAME ||
    2383             :                         opline->opcode == ZEND_INIT_NS_FCALL_BY_NAME ||
    2384             :                         opline->opcode == ZEND_INIT_DYNAMIC_CALL ||
    2385             :                         opline->opcode == ZEND_INIT_USER_CALL ||
    2386             :                         opline->opcode == ZEND_INIT_METHOD_CALL ||
    2387             :                         opline->opcode == ZEND_INIT_STATIC_METHOD_CALL ||
    2388             :                         opline->opcode == ZEND_NEW)) {
    2389             :                         ZEND_ASSERT(op_num);
    2390          23 :                         opline--;
    2391             :                 }
    2392             : 
    2393             :                 do {
    2394             :                         /* If the exception was thrown during a function call there might be
    2395             :                          * arguments pushed to the stack that have to be dtor'ed. */
    2396             : 
    2397             :                         /* find the number of actually passed arguments */
    2398        1102 :                         level = 0;
    2399        1102 :                         do_exit = 0;
    2400             :                         do {
    2401        3895 :                                 switch (opline->opcode) {
    2402             :                                         case ZEND_DO_FCALL:
    2403             :                                         case ZEND_DO_ICALL:
    2404             :                                         case ZEND_DO_UCALL:
    2405             :                                         case ZEND_DO_FCALL_BY_NAME:
    2406         735 :                                                 level++;
    2407         735 :                                                 break;
    2408             :                                         case ZEND_INIT_FCALL:
    2409             :                                         case ZEND_INIT_FCALL_BY_NAME:
    2410             :                                         case ZEND_INIT_NS_FCALL_BY_NAME:
    2411             :                                         case ZEND_INIT_DYNAMIC_CALL:
    2412             :                                         case ZEND_INIT_USER_CALL:
    2413             :                                         case ZEND_INIT_METHOD_CALL:
    2414             :                                         case ZEND_INIT_STATIC_METHOD_CALL:
    2415             :                                         case ZEND_NEW:
    2416        1815 :                                                 if (level == 0) {
    2417        1080 :                                                         ZEND_CALL_NUM_ARGS(call) = 0;
    2418        1080 :                                                         do_exit = 1;
    2419             :                                                 }
    2420        1815 :                                                 level--;
    2421        1815 :                                                 break;
    2422             :                                         case ZEND_SEND_VAL:
    2423             :                                         case ZEND_SEND_VAL_EX:
    2424             :                                         case ZEND_SEND_VAR:
    2425             :                                         case ZEND_SEND_VAR_EX:
    2426             :                                         case ZEND_SEND_REF:
    2427             :                                         case ZEND_SEND_VAR_NO_REF:
    2428             :                                         case ZEND_SEND_VAR_NO_REF_EX:
    2429             :                                         case ZEND_SEND_USER:
    2430         921 :                                                 if (level == 0) {
    2431          17 :                                                         ZEND_CALL_NUM_ARGS(call) = opline->op2.num;
    2432          17 :                                                         do_exit = 1;
    2433             :                                                 }
    2434         921 :                                                 break;
    2435             :                                         case ZEND_SEND_ARRAY:
    2436             :                                         case ZEND_SEND_UNPACK:
    2437           5 :                                                 if (level == 0) {
    2438           5 :                                                         do_exit = 1;
    2439             :                                                 }
    2440             :                                                 break;
    2441             :                                 }
    2442        3895 :                                 if (!do_exit) {
    2443        2793 :                                         opline--;
    2444             :                                 }
    2445        3895 :                         } while (!do_exit);
    2446        1102 :                         if (call->prev_execute_data) {
    2447             :                                 /* skip current call region */
    2448          23 :                                 level = 0;
    2449          23 :                                 do_exit = 0;
    2450             :                                 do {
    2451          52 :                                         switch (opline->opcode) {
    2452             :                                                 case ZEND_DO_FCALL:
    2453             :                                                 case ZEND_DO_ICALL:
    2454             :                                                 case ZEND_DO_UCALL:
    2455             :                                                 case ZEND_DO_FCALL_BY_NAME:
    2456           0 :                                                         level++;
    2457           0 :                                                         break;
    2458             :                                                 case ZEND_INIT_FCALL:
    2459             :                                                 case ZEND_INIT_FCALL_BY_NAME:
    2460             :                                                 case ZEND_INIT_NS_FCALL_BY_NAME:
    2461             :                                                 case ZEND_INIT_DYNAMIC_CALL:
    2462             :                                                 case ZEND_INIT_USER_CALL:
    2463             :                                                 case ZEND_INIT_METHOD_CALL:
    2464             :                                                 case ZEND_INIT_STATIC_METHOD_CALL:
    2465             :                                                 case ZEND_NEW:
    2466          23 :                                                         if (level == 0) {
    2467          23 :                                                                 do_exit = 1;
    2468             :                                                         }
    2469          23 :                                                         level--;
    2470             :                                                         break;
    2471             :                                         }
    2472          52 :                                         opline--;
    2473          52 :                                 } while (!do_exit);
    2474             :                         }
    2475             : 
    2476        1102 :                         zend_vm_stack_free_args(EX(call));
    2477             : 
    2478        1102 :                         if (ZEND_CALL_INFO(call) & ZEND_CALL_RELEASE_THIS) {
    2479          13 :                                 if (ZEND_CALL_INFO(call) & ZEND_CALL_CTOR) {
    2480           5 :                                         GC_REFCOUNT(Z_OBJ(call->This))--;
    2481           5 :                                         if (GC_REFCOUNT(Z_OBJ(call->This)) == 1) {
    2482           5 :                                                 zend_object_store_ctor_failed(Z_OBJ(call->This));
    2483             :                                         }
    2484             :                                 }
    2485          13 :                                 OBJ_RELEASE(Z_OBJ(call->This));
    2486             :                         }
    2487        1102 :                         if (call->func->common.fn_flags & ZEND_ACC_CLOSURE) {
    2488           4 :                                 zend_object_release((zend_object *) call->func->common.prototype);
    2489        1098 :                         } else if (call->func->common.fn_flags & ZEND_ACC_CALL_VIA_TRAMPOLINE) {
    2490           6 :                                 zend_string_release(call->func->common.function_name);
    2491           6 :                                 zend_free_trampoline(call->func);
    2492             :                         }
    2493             : 
    2494        1102 :                         EX(call) = call->prev_execute_data;
    2495             :                         zend_vm_stack_free_call_frame(call);
    2496        1102 :                         call = EX(call);
    2497        1102 :                 } while (call);
    2498             :         }
    2499        3919 : }
    2500             : /* }}} */
    2501             : 
    2502        3955 : static void cleanup_live_vars(zend_execute_data *execute_data, uint32_t op_num, uint32_t catch_op_num) /* {{{ */
    2503             : {
    2504             :         int i;
    2505             : 
    2506        9324 :         for (i = 0; i < EX(func)->op_array.last_live_range; i++) {
    2507        5782 :                 const zend_live_range *range = &EX(func)->op_array.live_range[i];
    2508        5782 :                 if (range->start > op_num) {
    2509             :                         /* further blocks will not be relevant... */
    2510         413 :                         break;
    2511        5369 :                 } else if (op_num < range->end) {
    2512        1402 :                         if (!catch_op_num || catch_op_num >= range->end) {
    2513         123 :                                 uint32_t kind = range->var & ZEND_LIVE_MASK;
    2514         123 :                                 uint32_t var_num = range->var & ~ZEND_LIVE_MASK;
    2515         123 :                                 zval *var = EX_VAR(var_num);
    2516             : 
    2517         123 :                                 if (kind == ZEND_LIVE_TMPVAR) {
    2518             :                                         zval_ptr_dtor_nogc(var);
    2519          98 :                                 } else if (kind == ZEND_LIVE_LOOP) {
    2520          44 :                                         if (Z_TYPE_P(var) != IS_ARRAY && Z_FE_ITER_P(var) != (uint32_t)-1) {
    2521           0 :                                                 zend_hash_iterator_del(Z_FE_ITER_P(var));
    2522             :                                         }
    2523             :                                         zval_ptr_dtor_nogc(var);
    2524          54 :                                 } else if (kind == ZEND_LIVE_ROPE) {
    2525           6 :                                         zend_string **rope = (zend_string **)var;
    2526           6 :                                         zend_op *last = EX(func)->op_array.opcodes + op_num;
    2527          29 :                                         while ((last->opcode != ZEND_ROPE_ADD && last->opcode != ZEND_ROPE_INIT)
    2528           8 :                                                         || last->result.var != var_num) {
    2529             :                                                 ZEND_ASSERT(last >= EX(func)->op_array.opcodes);
    2530           9 :                                                 last--;
    2531             :                                         }
    2532           6 :                                         if (last->opcode == ZEND_ROPE_INIT) {
    2533           4 :                                                 zend_string_release(*rope);
    2534             :                                         } else {
    2535           2 :                                                 int j = last->extended_value;
    2536             :                                                 do {
    2537           6 :                                                         zend_string_release(rope[j]);
    2538           6 :                                                 } while (j--);
    2539             :                                         }
    2540          48 :                                 } else if (kind == ZEND_LIVE_SILENCE) {
    2541             :                                         /* restore previous error_reporting value */
    2542          48 :                                         if (!EG(error_reporting) && Z_LVAL_P(var) != 0) {
    2543          34 :                                                 EG(error_reporting) = Z_LVAL_P(var);
    2544             :                                         }
    2545             :                                 }
    2546             :                         }
    2547             :                 }
    2548             :         }
    2549        3955 : }
    2550             : /* }}} */
    2551             : 
    2552         296 : void zend_cleanup_unfinished_execution(zend_execute_data *execute_data, uint32_t op_num, uint32_t catch_op_num) {
    2553         296 :         cleanup_unfinished_calls(execute_data, op_num);
    2554         296 :         cleanup_live_vars(execute_data, op_num, catch_op_num);
    2555         296 : }
    2556             : 
    2557           1 : static void zend_swap_operands(zend_op *op) /* {{{ */
    2558             : {
    2559             :         znode_op     tmp;
    2560             :         zend_uchar   tmp_type;
    2561             : 
    2562           1 :         tmp          = op->op1;
    2563           1 :         tmp_type     = op->op1_type;
    2564           1 :         op->op1      = op->op2;
    2565           1 :         op->op1_type = op->op2_type;
    2566           1 :         op->op2      = tmp;
    2567           1 :         op->op2_type = tmp_type;
    2568           1 : }
    2569             : /* }}} */
    2570             : 
    2571       13428 : static zend_never_inline zend_execute_data *zend_init_dynamic_call_string(zend_string *function, uint32_t num_args) /* {{{ */
    2572             : {
    2573             :         zend_function *fbc;
    2574             :         zval *func;
    2575             :         zend_class_entry *called_scope;
    2576             :         zend_string *lcname;
    2577             :         const char *colon;
    2578             : 
    2579       26898 :         if ((colon = zend_memrchr(ZSTR_VAL(function), ':', ZSTR_LEN(function))) != NULL &&
    2580          17 :                 colon > ZSTR_VAL(function) &&
    2581          15 :                 *(colon-1) == ':'
    2582             :         ) {
    2583             :                 zend_string *mname;
    2584          14 :                 size_t cname_length = colon - ZSTR_VAL(function) - 1;
    2585          14 :                 size_t mname_length = ZSTR_LEN(function) - cname_length - (sizeof("::") - 1);
    2586             : 
    2587          28 :                 lcname = zend_string_init(ZSTR_VAL(function), cname_length, 0);
    2588             : 
    2589          14 :                 called_scope = zend_fetch_class_by_name(lcname, NULL, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
    2590          14 :                 if (UNEXPECTED(called_scope == NULL)) {
    2591             :                         zend_string_release(lcname);
    2592           3 :                         return NULL;
    2593             :                 }
    2594             : 
    2595          22 :                 mname = zend_string_init(ZSTR_VAL(function) + (cname_length + sizeof("::") - 1), mname_length, 0);
    2596             : 
    2597          11 :                 if (called_scope->get_static_method) {
    2598           0 :                         fbc = called_scope->get_static_method(called_scope, mname);
    2599             :                 } else {
    2600          11 :                         fbc = zend_std_get_static_method(called_scope, mname, NULL);
    2601             :                 }
    2602          11 :                 if (UNEXPECTED(fbc == NULL)) {
    2603           1 :                         if (EXPECTED(!EG(exception))) {
    2604           1 :                                 zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(called_scope->name), ZSTR_VAL(mname));
    2605             :                         }
    2606             :                         zend_string_release(lcname);
    2607             :                         zend_string_release(mname);
    2608           1 :                         return NULL;
    2609             :                 }
    2610             : 
    2611             :                 zend_string_release(lcname);
    2612             :                 zend_string_release(mname);
    2613             : 
    2614          10 :                 if (UNEXPECTED(!(fbc->common.fn_flags & ZEND_ACC_STATIC))) {
    2615           1 :                         if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
    2616           2 :                                 zend_error(E_DEPRECATED,
    2617             :                                         "Non-static method %s::%s() should not be called statically",
    2618           2 :                                         ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
    2619           1 :                                 if (UNEXPECTED(EG(exception) != NULL)) {
    2620           0 :                                         return NULL;
    2621             :                                 }
    2622             :                         } else {
    2623           0 :                                 zend_throw_error(
    2624             :                                         zend_ce_error,
    2625             :                                         "Non-static method %s::%s() cannot be called statically",
    2626           0 :                                         ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
    2627           0 :                                 return NULL;
    2628             :                         }
    2629             :                 }
    2630             :         } else {
    2631       13414 :                 if (ZSTR_VAL(function)[0] == '\\') {
    2632           2 :                         lcname = zend_string_alloc(ZSTR_LEN(function) - 1, 0);
    2633           1 :                         zend_str_tolower_copy(ZSTR_VAL(lcname), ZSTR_VAL(function) + 1, ZSTR_LEN(function) - 1);
    2634             :                 } else {
    2635       13413 :                         lcname = zend_string_tolower(function);
    2636             :                 }
    2637       13414 :                 if (UNEXPECTED((func = zend_hash_find(EG(function_table), lcname)) == NULL)) {
    2638           3 :                         zend_throw_error(NULL, "Call to undefined function %s()", ZSTR_VAL(function));
    2639             :                         zend_string_release(lcname);
    2640           3 :                         return NULL;
    2641             :                 }
    2642             :                 zend_string_release(lcname);
    2643             : 
    2644       13411 :                 fbc = Z_FUNC_P(func);
    2645       13411 :                 called_scope = NULL;
    2646             :         }
    2647             : 
    2648       13421 :         if (EXPECTED(fbc->type == ZEND_USER_FUNCTION) && UNEXPECTED(!fbc->op_array.run_time_cache)) {
    2649          44 :                 init_func_run_time_cache(&fbc->op_array);
    2650             :         }
    2651             : 
    2652       13421 :         return zend_vm_stack_push_call_frame(ZEND_CALL_NESTED_FUNCTION | ZEND_CALL_DYNAMIC,
    2653             :                 fbc, num_args, called_scope, NULL);
    2654             : }
    2655             : /* }}} */
    2656             : 
    2657         612 : static zend_never_inline zend_execute_data *zend_init_dynamic_call_object(zval *function, uint32_t num_args) /* {{{ */
    2658             : {
    2659             :         zend_function *fbc;
    2660             :         zend_class_entry *called_scope;
    2661             :         zend_object *object;
    2662         612 :         uint32_t call_info = ZEND_CALL_NESTED_FUNCTION | ZEND_CALL_DYNAMIC;
    2663             : 
    2664        1836 :         if (EXPECTED(Z_OBJ_HANDLER_P(function, get_closure)) &&
    2665         612 :             EXPECTED(Z_OBJ_HANDLER_P(function, get_closure)(function, &called_scope, &fbc, &object) == SUCCESS)) {
    2666             : 
    2667         612 :                 if (fbc->common.fn_flags & ZEND_ACC_CLOSURE) {
    2668             :                         /* Delay closure destruction until its invocation */
    2669             :                         ZEND_ASSERT(GC_TYPE((zend_object*)fbc->common.prototype) == IS_OBJECT);
    2670         601 :                         GC_REFCOUNT((zend_object*)fbc->common.prototype)++;
    2671         601 :                         call_info |= ZEND_CALL_CLOSURE;
    2672          11 :                 } else if (object) {
    2673          10 :                         call_info |= ZEND_CALL_RELEASE_THIS;
    2674          10 :                         GC_REFCOUNT(object)++; /* For $this pointer */
    2675             :                 }
    2676             :         } else {
    2677           0 :                 zend_throw_error(NULL, "Function name must be a string");
    2678           0 :                 return NULL;
    2679             :         }
    2680             : 
    2681         612 :         if (EXPECTED(fbc->type == ZEND_USER_FUNCTION) && UNEXPECTED(!fbc->op_array.run_time_cache)) {
    2682           8 :                 init_func_run_time_cache(&fbc->op_array);
    2683             :         }
    2684             : 
    2685        1224 :         return zend_vm_stack_push_call_frame(call_info,
    2686             :                 fbc, num_args, called_scope, object);
    2687             : }
    2688             : /* }}} */
    2689             : 
    2690          32 : static zend_never_inline zend_execute_data *zend_init_dynamic_call_array(zend_array *function, uint32_t num_args) /* {{{ */
    2691             : {
    2692             :         zend_function *fbc;
    2693             :         zend_class_entry *called_scope;
    2694             :         zend_object *object;
    2695          32 :         uint32_t call_info = ZEND_CALL_NESTED_FUNCTION | ZEND_CALL_DYNAMIC;
    2696             : 
    2697          32 :         if (zend_hash_num_elements(function) == 2) {
    2698             :                 zval *obj;
    2699             :                 zval *method;
    2700          32 :                 obj = zend_hash_index_find(function, 0);
    2701          32 :                 method = zend_hash_index_find(function, 1);
    2702             : 
    2703          32 :                 if (UNEXPECTED(!obj) || UNEXPECTED(!method)) {
    2704           1 :                         zend_throw_error(NULL, "Array callback has to contain indices 0 and 1");
    2705           1 :                         return NULL;
    2706             :                 }
    2707             : 
    2708          31 :                 ZVAL_DEREF(obj);
    2709          43 :                 if (UNEXPECTED(Z_TYPE_P(obj) != IS_STRING) && UNEXPECTED(Z_TYPE_P(obj) != IS_OBJECT)) {
    2710           0 :                         zend_throw_error(NULL, "First array member is not a valid class name or object");
    2711           0 :                         return NULL;
    2712             :                 }
    2713             : 
    2714          31 :                 ZVAL_DEREF(method);
    2715          31 :                 if (UNEXPECTED(Z_TYPE_P(method) != IS_STRING)) {
    2716           0 :                         zend_throw_error(NULL, "Second array member is not a valid method");
    2717           0 :                         return NULL;
    2718             :                 }
    2719             : 
    2720          31 :                 if (Z_TYPE_P(obj) == IS_STRING) {
    2721          19 :                         object = NULL;
    2722          19 :                         called_scope = zend_fetch_class_by_name(Z_STR_P(obj), NULL, ZEND_FETCH_CLASS_DEFAULT | ZEND_FETCH_CLASS_EXCEPTION);
    2723          19 :                         if (UNEXPECTED(called_scope == NULL)) {
    2724           4 :                                 return NULL;
    2725             :                         }
    2726             : 
    2727          15 :                         if (called_scope->get_static_method) {
    2728           0 :                                 fbc = called_scope->get_static_method(called_scope, Z_STR_P(method));
    2729             :                         } else {
    2730          15 :                                 fbc = zend_std_get_static_method(called_scope, Z_STR_P(method), NULL);
    2731             :                         }
    2732          15 :                         if (UNEXPECTED(fbc == NULL)) {
    2733           1 :                                 if (EXPECTED(!EG(exception))) {
    2734           1 :                                         zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(called_scope->name), Z_STRVAL_P(method));
    2735             :                                 }
    2736           1 :                                 return NULL;
    2737             :                         }
    2738          14 :                         if (!(fbc->common.fn_flags & ZEND_ACC_STATIC)) {
    2739           2 :                                 if (fbc->common.fn_flags & ZEND_ACC_ALLOW_STATIC) {
    2740           4 :                                         zend_error(E_DEPRECATED,
    2741             :                                                 "Non-static method %s::%s() should not be called statically",
    2742           4 :                                                 ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
    2743           2 :                                         if (UNEXPECTED(EG(exception) != NULL)) {
    2744           0 :                                                 return NULL;
    2745             :                                         }
    2746             :                                 } else {
    2747           0 :                                         zend_throw_error(
    2748             :                                                 zend_ce_error,
    2749             :                                                 "Non-static method %s::%s() cannot be called statically",
    2750           0 :                                                 ZSTR_VAL(fbc->common.scope->name), ZSTR_VAL(fbc->common.function_name));
    2751           0 :                                         return NULL;
    2752             :                                 }
    2753             :                         }
    2754             :                 } else {
    2755          12 :                         called_scope = Z_OBJCE_P(obj);
    2756          12 :                         object = Z_OBJ_P(obj);
    2757             : 
    2758          12 :                         fbc = Z_OBJ_HT_P(obj)->get_method(&object, Z_STR_P(method), NULL);
    2759          12 :                         if (UNEXPECTED(fbc == NULL)) {
    2760           0 :                                 if (EXPECTED(!EG(exception))) {
    2761           0 :                                         zend_throw_error(NULL, "Call to undefined method %s::%s()", ZSTR_VAL(object->ce->name), Z_STRVAL_P(method));
    2762             :                                 }
    2763           0 :                                 return NULL;
    2764             :                         }
    2765             : 
    2766          12 :                         if ((fbc->common.fn_flags & ZEND_ACC_STATIC) != 0) {
    2767           3 :                                 object = NULL;
    2768             :                         } else {
    2769           9 :                                 call_info |= ZEND_CALL_RELEASE_THIS;
    2770           9 :                                 GC_REFCOUNT(object)++; /* For $this pointer */
    2771             :                         }
    2772             :                 }
    2773             :         } else {
    2774           0 :                 zend_throw_error(NULL, "Function name must be a string");
    2775           0 :                 return NULL;
    2776             :         }
    2777             : 
    2778          26 :         if (EXPECTED(fbc->type == ZEND_USER_FUNCTION) && UNEXPECTED(!fbc->op_array.run_time_cache)) {
    2779          10 :                 init_func_run_time_cache(&fbc->op_array);
    2780             :         }
    2781             : 
    2782          52 :         return zend_vm_stack_push_call_frame(call_info,
    2783             :                 fbc, num_args, called_scope, object);
    2784             : }
    2785             : /* }}} */
    2786             : 
    2787             : #define ZEND_FAKE_OP_ARRAY ((zend_op_array*)(zend_intptr_t)-1)
    2788             : 
    2789       11504 : static zend_never_inline zend_op_array* ZEND_FASTCALL zend_include_or_eval(zval *inc_filename, int type) /* {{{ */
    2790             : {
    2791       11504 :         zend_op_array *new_op_array = NULL;
    2792             :         zval tmp_inc_filename;
    2793             : 
    2794       11504 :         ZVAL_UNDEF(&tmp_inc_filename);
    2795       11504 :         if (Z_TYPE_P(inc_filename) != IS_STRING) {
    2796           2 :                 ZVAL_STR(&tmp_inc_filename, zval_get_string(inc_filename));
    2797           1 :                 inc_filename = &tmp_inc_filename;
    2798             :         }
    2799             : 
    2800       11504 :         if (type != ZEND_EVAL && strlen(Z_STRVAL_P(inc_filename)) != Z_STRLEN_P(inc_filename)) {
    2801           0 :                 if (type == ZEND_INCLUDE_ONCE || type == ZEND_INCLUDE) {
    2802           0 :                         zend_message_dispatcher(ZMSG_FAILED_INCLUDE_FOPEN, Z_STRVAL_P(inc_filename));
    2803             :                 } else {
    2804           0 :                         zend_message_dispatcher(ZMSG_FAILED_REQUIRE_FOPEN, Z_STRVAL_P(inc_filename));
    2805             :                 }
    2806             :         } else {
    2807       11504 :                 switch (type) {
    2808             :                         case ZEND_INCLUDE_ONCE:
    2809             :                         case ZEND_REQUIRE_ONCE: {
    2810             :                                         zend_file_handle file_handle;
    2811             :                                         zend_string *resolved_path;
    2812             : 
    2813        6031 :                                         resolved_path = zend_resolve_path(Z_STRVAL_P(inc_filename), (int)Z_STRLEN_P(inc_filename));
    2814        6031 :                                         if (resolved_path) {
    2815        6027 :                                                 if (zend_hash_exists(&EG(included_files), resolved_path)) {
    2816         568 :                                                         goto already_compiled;
    2817             :                                                 }
    2818             :                                         } else {
    2819           8 :                                                 resolved_path = zend_string_copy(Z_STR_P(inc_filename));
    2820             :                                         }
    2821             : 
    2822        5463 :                                         if (SUCCESS == zend_stream_open(ZSTR_VAL(resolved_path), &file_handle)) {
    2823             : 
    2824        5461 :                                                 if (!file_handle.opened_path) {
    2825           4 :                                                         file_handle.opened_path = zend_string_copy(resolved_path);
    2826             :                                                 }
    2827             : 
    2828        5461 :                                                 if (zend_hash_add_empty_element(&EG(included_files), file_handle.opened_path)) {
    2829        5460 :                                                         zend_op_array *op_array = zend_compile_file(&file_handle, (type==ZEND_INCLUDE_ONCE?ZEND_INCLUDE:ZEND_REQUIRE));
    2830        5460 :                                                         zend_destroy_file_handle(&file_handle);
    2831             :                                                         zend_string_release(resolved_path);
    2832        5460 :                                                         if (Z_TYPE(tmp_inc_filename) != IS_UNDEF) {
    2833           0 :                                                                 zend_string_release(Z_STR(tmp_inc_filename));
    2834             :                                                         }
    2835        5460 :                                                         return op_array;
    2836             :                                                 } else {
    2837           1 :                                                         zend_file_handle_dtor(&file_handle);
    2838             : already_compiled:
    2839         569 :                                                         new_op_array = ZEND_FAKE_OP_ARRAY;
    2840             :                                                 }
    2841             :                                         } else {
    2842           2 :                                                 if (type == ZEND_INCLUDE_ONCE) {
    2843           0 :                                                         zend_message_dispatcher(ZMSG_FAILED_INCLUDE_FOPEN, Z_STRVAL_P(inc_filename));
    2844             :                                                 } else {
    2845           2 :                                                         zend_message_dispatcher(ZMSG_FAILED_REQUIRE_FOPEN, Z_STRVAL_P(inc_filename));
    2846             :                                                 }
    2847             :                                         }
    2848             :                                         zend_string_release(resolved_path);
    2849             :                                 }
    2850         569 :                                 break;
    2851             :                         case ZEND_INCLUDE:
    2852             :                         case ZEND_REQUIRE:
    2853        4447 :                                 new_op_array = compile_filename(type, inc_filename);
    2854        4445 :                                 break;
    2855             :                         case ZEND_EVAL: {
    2856        1026 :                                         char *eval_desc = zend_make_compiled_string_description("eval()'d code");
    2857        1026 :                                         new_op_array = zend_compile_string(inc_filename, eval_desc);
    2858        1024 :                                         efree(eval_desc);
    2859             :                                 }
    2860             :                                 break;
    2861             :                         EMPTY_SWITCH_DEFAULT_CASE()
    2862             :                 }
    2863             :         }
    2864        6038 :         if (Z_TYPE(tmp_inc_filename) != IS_UNDEF) {
    2865           1 :                 zend_string_release(Z_STR(tmp_inc_filename));
    2866             :         }
    2867        6038 :         return new_op_array;
    2868             : }
    2869             : /* }}} */
    2870             : 
    2871           0 : static zend_never_inline int zend_do_fcall_overloaded(zend_function *fbc, zend_execute_data *call, zval *ret) /* {{{ */
    2872             : {
    2873             :         zend_object *object;
    2874             : 
    2875             :         /* Not sure what should be done here if it's a static method */
    2876           0 :         if (UNEXPECTED(Z_TYPE(call->This) != IS_OBJECT)) {
    2877             :                 zend_vm_stack_free_args(call);
    2878           0 :                 if (fbc->type == ZEND_OVERLOADED_FUNCTION_TEMPORARY) {
    2879           0 :                         zend_string_release(fbc->common.function_name);
    2880             :                 }
    2881           0 :                 efree(fbc);
    2882             :                 zend_vm_stack_free_call_frame(call);
    2883             : 
    2884           0 :                 zend_throw_error(NULL, "Cannot call overloaded function for non-object");
    2885           0 :                 return 0;
    2886             :         }
    2887             : 
    2888           0 :         object = Z_OBJ(call->This);
    2889             : 
    2890           0 :         ZVAL_NULL(ret);
    2891             : 
    2892           0 :         EG(current_execute_data) = call;
    2893           0 :         object->handlers->call_method(fbc->common.function_name, object, call, ret);
    2894           0 :         EG(current_execute_data) = call->prev_execute_data;
    2895             : 
    2896             :         zend_vm_stack_free_args(call);
    2897             : 
    2898           0 :         if (fbc->type == ZEND_OVERLOADED_FUNCTION_TEMPORARY) {
    2899           0 :                 zend_string_release(fbc->common.function_name);
    2900             :         }
    2901           0 :         efree(fbc);
    2902             : 
    2903           0 :         return 1;
    2904             : }
    2905             : /* }}} */
    2906             : 
    2907             : #ifdef HAVE_GCC_GLOBAL_REGS
    2908             : # if defined(__GNUC__) && ZEND_GCC_VERSION >= 4008 && defined(i386)
    2909             : #  define ZEND_VM_FP_GLOBAL_REG "%esi"
    2910             : #  define ZEND_VM_IP_GLOBAL_REG "%edi"
    2911             : # elif defined(__GNUC__) && ZEND_GCC_VERSION >= 4008 && defined(__x86_64__)
    2912             : #  define ZEND_VM_FP_GLOBAL_REG "%r14"
    2913             : #  define ZEND_VM_IP_GLOBAL_REG "%r15"
    2914             : # elif defined(__GNUC__) && ZEND_GCC_VERSION >= 4008 && defined(__powerpc64__)
    2915             : #  define ZEND_VM_FP_GLOBAL_REG "r28"
    2916             : #  define ZEND_VM_IP_GLOBAL_REG "r29"
    2917             : # elif defined(__IBMC__) && ZEND_GCC_VERSION >= 4002 && defined(__powerpc64__)
    2918             : #  define ZEND_VM_FP_GLOBAL_REG "r28"
    2919             : #  define ZEND_VM_IP_GLOBAL_REG "r29"
    2920             : # endif
    2921             : #endif
    2922             : 
    2923             : #define ZEND_VM_NEXT_OPCODE_EX(check_exception, skip) \
    2924             :         CHECK_SYMBOL_TABLES() \
    2925             :         if (check_exception) { \
    2926             :                 OPLINE = EX(opline) + (skip); \
    2927             :         } else { \
    2928             :                 OPLINE = opline + (skip); \
    2929             :         } \
    2930             :         ZEND_VM_CONTINUE()
    2931             : 
    2932             : #define ZEND_VM_NEXT_OPCODE_CHECK_EXCEPTION() \
    2933             :         ZEND_VM_NEXT_OPCODE_EX(1, 1)
    2934             : 
    2935             : #define ZEND_VM_NEXT_OPCODE() \
    2936             :         ZEND_VM_NEXT_OPCODE_EX(0, 1)
    2937             : 
    2938             : #define ZEND_VM_SET_NEXT_OPCODE(new_op) \
    2939             :         CHECK_SYMBOL_TABLES() \
    2940             :         OPLINE = new_op
    2941             : 
    2942             : #define ZEND_VM_SET_OPCODE(new_op) \
    2943             :         CHECK_SYMBOL_TABLES() \
    2944             :         OPLINE = new_op; \
    2945             :         ZEND_VM_INTERRUPT_CHECK()
    2946             : 
    2947             : #define ZEND_VM_SET_RELATIVE_OPCODE(opline, offset) \
    2948             :         ZEND_VM_SET_OPCODE(ZEND_OFFSET_TO_OPLINE(opline, offset))
    2949             : 
    2950             : #define ZEND_VM_JMP(new_op) \
    2951             :         if (EXPECTED(!EG(exception))) { \
    2952             :                 ZEND_VM_SET_OPCODE(new_op); \
    2953             :         } else { \
    2954             :                 LOAD_OPLINE(); \
    2955             :         } \
    2956             :         ZEND_VM_CONTINUE()
    2957             : 
    2958             : #define ZEND_VM_INC_OPCODE() \
    2959             :         OPLINE++
    2960             : 
    2961             : 
    2962             : #ifndef VM_SMART_OPCODES
    2963             : # define VM_SMART_OPCODES 1
    2964             : #endif
    2965             : 
    2966             : #if VM_SMART_OPCODES
    2967             : # define ZEND_VM_REPEATABLE_OPCODE \
    2968             :         do {
    2969             : # define ZEND_VM_REPEAT_OPCODE(_opcode) \
    2970             :         } while (UNEXPECTED((++opline)->opcode == _opcode)); \
    2971             :         OPLINE = opline; \
    2972             :         ZEND_VM_CONTINUE()
    2973             : # define ZEND_VM_SMART_BRANCH(_result, _check) do { \
    2974             :                 int __result; \
    2975             :                 if (EXPECTED((opline+1)->opcode == ZEND_JMPZ)) { \
    2976             :                         __result = (_result); \
    2977             :                 } else if (EXPECTED((opline+1)->opcode == ZEND_JMPNZ)) { \
    2978             :                         __result = !(_result); \
    2979             :                 } else { \
    2980             :                         break; \
    2981             :                 } \
    2982             :                 if ((_check) && UNEXPECTED(EG(exception))) { \
    2983             :                         HANDLE_EXCEPTION(); \
    2984             :                 } \
    2985             :                 if (__result) { \
    2986             :                         ZEND_VM_SET_NEXT_OPCODE(opline + 2); \
    2987             :                 } else { \
    2988             :                         ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline + 1, (opline+1)->op2)); \
    2989             :                 } \
    2990             :                 ZEND_VM_CONTINUE(); \
    2991             :         } while (0)
    2992             : # define ZEND_VM_SMART_BRANCH_JMPZ(_result, _check) do { \
    2993             :                 if ((_check) && UNEXPECTED(EG(exception))) { \
    2994             :                         HANDLE_EXCEPTION(); \
    2995             :                 } \
    2996             :                 if (_result) { \
    2997             :                         ZEND_VM_SET_NEXT_OPCODE(opline + 2); \
    2998             :                 } else { \
    2999             :                         ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline + 1, (opline+1)->op2)); \
    3000             :                 } \
    3001             :                 ZEND_VM_CONTINUE(); \
    3002             :         } while (0)
    3003             : # define ZEND_VM_SMART_BRANCH_JMPNZ(_result, _check) do { \
    3004             :                 if ((_check) && UNEXPECTED(EG(exception))) { \
    3005             :                         HANDLE_EXCEPTION(); \
    3006             :                 } \
    3007             :                 if (!(_result)) { \
    3008             :                         ZEND_VM_SET_NEXT_OPCODE(opline + 2); \
    3009             :                 } else { \
    3010             :                         ZEND_VM_SET_OPCODE(OP_JMP_ADDR(opline + 1, (opline+1)->op2)); \
    3011             :                 } \
    3012             :                 ZEND_VM_CONTINUE(); \
    3013             :         } while (0)
    3014             : #else
    3015             : # define ZEND_VM_REPEATABLE_OPCODE
    3016             : # define ZEND_VM_REPEAT_OPCODE(_opcode)
    3017             : # define ZEND_VM_SMART_BRANCH(_result, _check)
    3018             : # define ZEND_VM_SMART_BRANCH_JMPZ(_result, _check)
    3019             : # define ZEND_VM_SMART_BRANCH_JMPNZ(_result, _check)
    3020             : #endif
    3021             : 
    3022             : #ifdef __GNUC__
    3023             : # define ZEND_VM_GUARD(name) __asm__("#" #name)
    3024             : #else
    3025             : # define ZEND_VM_GUARD(name)
    3026             : #endif
    3027             : 
    3028             : #define GET_OP1_UNDEF_CV(ptr, type) \
    3029             :         _get_zval_cv_lookup_ ## type(ptr, opline->op1.var, execute_data)
    3030             : #define GET_OP2_UNDEF_CV(ptr, type) \
    3031             :         _get_zval_cv_lookup_ ## type(ptr, opline->op2.var, execute_data)
    3032             : 
    3033             : #include "zend_vm_execute.h"
    3034             : 
    3035           0 : ZEND_API int zend_set_user_opcode_handler(zend_uchar opcode, user_opcode_handler_t handler)
    3036             : {
    3037           0 :         if (opcode != ZEND_USER_OPCODE) {
    3038           0 :                 if (handler == NULL) {
    3039             :                         /* restore the original handler */
    3040           0 :                         zend_user_opcodes[opcode] = opcode;
    3041             :                 } else {
    3042           0 :                         zend_user_opcodes[opcode] = ZEND_USER_OPCODE;
    3043             :                 }
    3044           0 :                 zend_user_opcode_handlers[opcode] = handler;
    3045           0 :                 return SUCCESS;
    3046             :         }
    3047           0 :         return FAILURE;
    3048             : }
    3049             : 
    3050           0 : ZEND_API user_opcode_handler_t zend_get_user_opcode_handler(zend_uchar opcode)
    3051             : {
    3052           0 :         return zend_user_opcode_handlers[opcode];
    3053             : }
    3054             : 
    3055           0 : ZEND_API zval *zend_get_zval_ptr(int op_type, const znode_op *node, const zend_execute_data *execute_data, zend_free_op *should_free, int type)
    3056             : {
    3057           0 :         return get_zval_ptr(op_type, *node, execute_data, should_free, type);
    3058             : }
    3059             : 
    3060           0 : ZEND_API void ZEND_FASTCALL zend_check_internal_arg_type(zend_function *zf, uint32_t arg_num, zval *arg)
    3061             : {
    3062           0 :         zend_verify_internal_arg_type(zf, arg_num, arg);
    3063           0 : }
    3064             : 
    3065           0 : ZEND_API int ZEND_FASTCALL zend_check_arg_type(zend_function *zf, uint32_t arg_num, zval *arg, zval *default_value, void **cache_slot)
    3066             : {
    3067           0 :         return zend_verify_arg_type(zf, arg_num, arg, default_value, cache_slot);
    3068             : }
    3069             : 
    3070             : /*
    3071             :  * Local variables:
    3072             :  * tab-width: 4
    3073             :  * c-basic-offset: 4
    3074             :  * indent-tabs-mode: t
    3075             :  * End:
    3076             :  */

Generated by: LCOV version 1.10

Generated at Sun, 28 Aug 2016 17:09:57 +0000 (7 hours ago)

Copyright © 2005-2016 The PHP Group
All rights reserved.