Commit f9639b562af for php

commit f9639b562af53493f92d656917e403a17c563e57
Author: ndossche <7771979+ndossche@users.noreply.github.com>
Date:   Tue Sep 29 00:00:25 2026 +0200

    Fix __isset escape analysis causing misoptimization

    Co-authored-by: Arnaud Le Blanc <365207+arnaud-lb@users.noreply.github.com>

diff --git a/Zend/Optimizer/escape_analysis.c b/Zend/Optimizer/escape_analysis.c
index 352d647e925..0287da7286f 100644
--- a/Zend/Optimizer/escape_analysis.c
+++ b/Zend/Optimizer/escape_analysis.c
@@ -173,6 +173,7 @@ static bool is_allocation_def(zend_op_array *op_array, zend_ssa *ssa, int def, i
 				 && !ce->destructor
 				 && !ce->__get
 				 && !ce->__set
+				 && !ce->__isset
 				 && !(ce->ce_flags & forbidden_flags)
 				 && (ce->ce_flags & ZEND_ACC_CONSTANTS_UPDATED)) {
 					return 1;
@@ -242,6 +243,7 @@ static bool is_local_def(zend_op_array *op_array, zend_ssa *ssa, int def, int va
 				 && !ce->destructor
 				 && !ce->__get
 				 && !ce->__set
+				 && !ce->__isset
 				 && !ce->parent) {
 					return 1;
 				}
diff --git a/ext/opcache/tests/opt/dce_016.phpt b/ext/opcache/tests/opt/dce_016.phpt
new file mode 100644
index 00000000000..2185a4abfee
--- /dev/null
+++ b/ext/opcache/tests/opt/dce_016.phpt
@@ -0,0 +1,50 @@
+--TEST--
+DCE must not remove assignments to properties of an object escaping through __isset
+--INI--
+opcache.enable=1
+opcache.enable_cli=1
+opcache.optimization_level=-1
+opcache.file_update_protection=0
+--EXTENSIONS--
+opcache
+--FILE--
+<?php
+
+class C {
+    public $x = 0;
+    function __isset($n) {
+        global $g;
+        $g = $this;
+        return true;
+    }
+}
+
+function f() {
+    $o = new C;
+    isset($o->foo);
+    $o->x = 42;
+}
+
+f();
+var_dump($g->x);
+
+#[AllowDynamicProperties]
+class F {
+    function __isset($n) {
+        $this->x = 2;
+        return true;
+    }
+}
+
+function i() {
+    $o = new F;
+    $o->x = 1;
+    isset($o->foo);
+    var_dump($o->x);
+}
+i();
+
+?>
+--EXPECT--
+int(42)
+int(2)