From 7a83627edd9cd26b08066a0cef43fd6f4bf00c81 Mon Sep 17 00:00:00 2001 From: ndossche <7771979+ndossche@users.noreply.github.com> Date: Sat, 3 Oct 2026 11:29:36 +0200 Subject: [PATCH] Fix SCCP evaluation of isset()/empty() on dimension of non-escaping object `ct_eval_isset_dim()` treated partial objects like scalars and folded the result to false/true. But using an object as an array either calls `ArrayAccess::offsetExists()` or throws an Error. --- Zend/Optimizer/sccp.c | 3 ++ .../opt/sccp_isset_dim_partial_object.phpt | 36 +++++++++++++++++++ 2 files changed, 39 insertions(+) create mode 100644 ext/opcache/tests/opt/sccp_isset_dim_partial_object.phpt diff --git a/Zend/Optimizer/sccp.c b/Zend/Optimizer/sccp.c index ca5184d8d5ab..7b9c43ceeaba 100644 --- a/Zend/Optimizer/sccp.c +++ b/Zend/Optimizer/sccp.c @@ -436,6 +436,9 @@ static inline zend_result ct_eval_isset_dim(zval *result, uint32_t extended_valu } else if (Z_TYPE_P(op1) == IS_STRING) { // TODO return FAILURE; + } else if (IS_PARTIAL_OBJECT(op1)) { + /* Objects may implement ArrayAccess or throw. */ + return FAILURE; } else { ZVAL_BOOL(result, (extended_value & ZEND_ISEMPTY)); return SUCCESS; diff --git a/ext/opcache/tests/opt/sccp_isset_dim_partial_object.phpt b/ext/opcache/tests/opt/sccp_isset_dim_partial_object.phpt new file mode 100644 index 000000000000..ac10d6773c68 --- /dev/null +++ b/ext/opcache/tests/opt/sccp_isset_dim_partial_object.phpt @@ -0,0 +1,36 @@ +--TEST-- +SCCP: isset()/empty() on dimension of non-escaping object must not be evaluated +--INI-- +opcache.enable=1 +opcache.enable_cli=1 +opcache.optimization_level=-1 +--EXTENSIONS-- +opcache +--FILE-- +getMessage(), "\n"; +} +try { + var_dump(g()); +} catch (Error $e) { + echo $e->getMessage(), "\n"; +} +?> +--EXPECT-- +Cannot use object of type P as array +Cannot use object of type P as array