Commit f9639b562af for php
commit f9639b562af53493f92d656917e403a17c563e57
Author: ndossche <7771979+ndossche@users.noreply.github.com>
Date: Tue Sep 29 00:00:25 2026 +0200
Fix __isset escape analysis causing misoptimization
Co-authored-by: Arnaud Le Blanc <365207+arnaud-lb@users.noreply.github.com>
diff --git a/Zend/Optimizer/escape_analysis.c b/Zend/Optimizer/escape_analysis.c
index 352d647e925..0287da7286f 100644
--- a/Zend/Optimizer/escape_analysis.c
+++ b/Zend/Optimizer/escape_analysis.c
@@ -173,6 +173,7 @@ static bool is_allocation_def(zend_op_array *op_array, zend_ssa *ssa, int def, i
&& !ce->destructor
&& !ce->__get
&& !ce->__set
+ && !ce->__isset
&& !(ce->ce_flags & forbidden_flags)
&& (ce->ce_flags & ZEND_ACC_CONSTANTS_UPDATED)) {
return 1;
@@ -242,6 +243,7 @@ static bool is_local_def(zend_op_array *op_array, zend_ssa *ssa, int def, int va
&& !ce->destructor
&& !ce->__get
&& !ce->__set
+ && !ce->__isset
&& !ce->parent) {
return 1;
}
diff --git a/ext/opcache/tests/opt/dce_016.phpt b/ext/opcache/tests/opt/dce_016.phpt
new file mode 100644
index 00000000000..2185a4abfee
--- /dev/null
+++ b/ext/opcache/tests/opt/dce_016.phpt
@@ -0,0 +1,50 @@
+--TEST--
+DCE must not remove assignments to properties of an object escaping through __isset
+--INI--
+opcache.enable=1
+opcache.enable_cli=1
+opcache.optimization_level=-1
+opcache.file_update_protection=0
+--EXTENSIONS--
+opcache
+--FILE--
+<?php
+
+class C {
+ public $x = 0;
+ function __isset($n) {
+ global $g;
+ $g = $this;
+ return true;
+ }
+}
+
+function f() {
+ $o = new C;
+ isset($o->foo);
+ $o->x = 42;
+}
+
+f();
+var_dump($g->x);
+
+#[AllowDynamicProperties]
+class F {
+ function __isset($n) {
+ $this->x = 2;
+ return true;
+ }
+}
+
+function i() {
+ $o = new F;
+ $o->x = 1;
+ isset($o->foo);
+ var_dump($o->x);
+}
+i();
+
+?>
+--EXPECT--
+int(42)
+int(2)