Skip to content

Fix SCCP evaluation of isset()/empty() on dimension of non-escaping object - #24090

Closed
ndossche wants to merge 2 commits into
php:PHP-8.4from
ndossche:fix-sccp-isset-dim-partial-object
Closed

ndossche wants to merge 2 commits into
php:PHP-8.4from
ndossche:fix-sccp-isset-dim-partial-object

Conversation

@ndossche

@ndossche ndossche commented Oct 3, 2026

Copy link
Copy Markdown
Member

ct_eval_isset_dim() treated partial objects like scalars and folded the result to false/true. But using an object as an array either calls ArrayAccess::offsetExists() or throws an Error.

…bject

`ct_eval_isset_dim()` treated partial objects like scalars and folded the
result to false/true. But using an object as an array either calls
`ArrayAccess::offsetExists()` or throws an Error.

@arnaud-lb arnaud-lb left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me!

Comment thread Zend/Optimizer/sccp.c
} else if (IS_PARTIAL_OBJECT(op1)) {
/* Objects may implement ArrayAccess or throw. */
return FAILURE;
} else {

@arnaud-lb arnaud-lb Oct 5, 2026 •

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We could add an assertion here to check that op1 is actually a scalar.

It looks like that ct_eval_isset_dim() pre-dates IS_PARTIAL_OBJECT and we forgot to update it when introducing IS_PARTIAL_OBJECT. An assertion would have spotted the issue earlier.

@ndossche ndossche closed this in 423529d Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants