Commit 423529d2b7c for php
commit 423529d2b7c8293f5f31ece1a0f9869601f8fee7
Author: ndossche <7771979+ndossche@users.noreply.github.com>
Date: Sat Oct 3 11:29:36 2026 +0200
Fix SCCP evaluation of isset()/empty() on dimension of non-escaping object
`ct_eval_isset_dim()` treated partial objects like scalars and folded the
result to false/true. But using an object as an array either calls
`ArrayAccess::offsetExists()` or throws an Error.
Closes GH-24090.
diff --git a/NEWS b/NEWS
index 14b0d0b08db..52dda8a9daa 100644
--- a/NEWS
+++ b/NEWS
@@ -124,6 +124,8 @@ PHP NEWS
extensions declaring frameless functions. (Ilia Alshanetsky)
. Fixed bug GH-23991 (JIT generates invalid IR for multiple recursive calls).
(ndossche)
+ . Fix SCCP evaluation of isset()/empty() on dimension of non-escaping object.
+ (ndossche)
- OpenSSL:
. Fixed stream_socket_enable_crypto() leaving the socket non-blocking
diff --git a/Zend/Optimizer/sccp.c b/Zend/Optimizer/sccp.c
index ca5184d8d5a..ab863fd093d 100644
--- a/Zend/Optimizer/sccp.c
+++ b/Zend/Optimizer/sccp.c
@@ -436,7 +436,11 @@ static inline zend_result ct_eval_isset_dim(zval *result, uint32_t extended_valu
} else if (Z_TYPE_P(op1) == IS_STRING) {
// TODO
return FAILURE;
+ } else if (IS_PARTIAL_OBJECT(op1)) {
+ /* Objects may implement ArrayAccess or throw. */
+ return FAILURE;
} else {
+ ZEND_ASSERT(Z_TYPE_P(op1) <= IS_DOUBLE);
ZVAL_BOOL(result, (extended_value & ZEND_ISEMPTY));
return SUCCESS;
}
diff --git a/ext/opcache/tests/opt/sccp_isset_dim_partial_object.phpt b/ext/opcache/tests/opt/sccp_isset_dim_partial_object.phpt
new file mode 100644
index 00000000000..ac10d6773c6
--- /dev/null
+++ b/ext/opcache/tests/opt/sccp_isset_dim_partial_object.phpt
@@ -0,0 +1,36 @@
+--TEST--
+SCCP: isset()/empty() on dimension of non-escaping object must not be evaluated
+--INI--
+opcache.enable=1
+opcache.enable_cli=1
+opcache.optimization_level=-1
+--EXTENSIONS--
+opcache
+--FILE--
+<?php
+class P {}
+
+function f() {
+ $o = new P;
+ return isset($o[1]);
+}
+
+function g() {
+ $o = new P;
+ return empty($o[1]);
+}
+
+try {
+ var_dump(f());
+} catch (Error $e) {
+ echo $e->getMessage(), "\n";
+}
+try {
+ var_dump(g());
+} catch (Error $e) {
+ echo $e->getMessage(), "\n";
+}
+?>
+--EXPECT--
+Cannot use object of type P as array
+Cannot use object of type P as array