Skip to content

[pull] master from php:master - #1319

Merged
pull[bot] merged 59 commits into
turkdevops:masterfrom
php:master
Sep 29, 2026
Merged

pull[bot] merged 59 commits into
turkdevops:masterfrom
php:master

Conversation

@pull

@pull pull Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

iliaal and others added 30 commits September 29, 2026 10:13
pdo_dbh_attribute_set() installed the new PDO::ATTR_STATEMENT_CLASS class and
released the old constructor arguments before checking that constructor_args
is an array, so a rejected setAttribute() left the new class in place for the
next prepare() or query(). Validate constructor_args first, and report its
type rather than the whole value's in the TypeError, here and in prepare().

Closes GH-23968
* PHP-8.4:
  ext/pdo: Keep statement class when ATTR_STATEMENT_CLASS is rejected

# Conflicts:
#	ext/pdo/pdo_dbh.c
…error_reporting INI directive is not set)

The way zend_fiber_execute() queries the error_reporting level is rather rather strange.

It cannot rely on the value of EG(error_reporting) as the @ silence operator may change it and this it would leak into the body of a fiber.
However, we can simply query the underlying value of the INI setting to get the correct error_reporting value as this is not modified by the @ operator.

Fixes an additional bug where the error_reporting value within a fiber was always E_ALL if the @ operator was used.

Closes GH-23930
* PHP-8.6:
  fibers: fix GH-23921 (Fibers start with error_reporting = 0 when the error_reporting INI directive is not set)
* PHP-8.5:
  ext/pdo: Keep statement class when ATTR_STATEMENT_CLASS is rejected
* PHP-8.6:
  ext/pdo: Keep statement class when ATTR_STATEMENT_CLASS is rejected
bindParam() and bindColumn() copied the driver options zval and then
addref'd it again. The extra reference kept the value alive after the
statement was destroyed. Keep the single reference from the copy.

Closes GH-23936
* PHP-8.4:
  ext/pdo: Release driver options after bindParam and bindColumn
* PHP-8.5:
  ext/pdo: Release driver options after bindParam and bindColumn
…ctions (#23989)

To be more explicit in what the zend_object* represents.
* PHP-8.6:
  ext/pdo: Release driver options after bindParam and bindColumn
…23835)

A column name that is not in the result set is a programming error, so
report it the way the method already reports an empty name or an index
below one, rather than through PDO::ATTR_ERRMODE. The equivalent parameter
failure in bindParam() and bindValue() stays an ERRMODE error: its site in
rewrite_name_to_position() is only reachable once execute() has populated
bound_param_map, never from the bind methods themselves.

Closes GH-23835
* PHP-8.4:
  Fix GH-23986: Clear the realpath cache in the child after pcntl_fork() (#23987)
* PHP-8.5:
  Fix GH-23986: Clear the realpath cache in the child after pcntl_fork() (#23987)
* PHP-8.6:
  Fix GH-23986: Clear the realpath cache in the child after pcntl_fork() (#23987)
Co-authored-by: Arnaud Le Blanc <365207+arnaud-lb@users.noreply.github.com>
Co-authored-by: Arnaud Le Blanc <365207+arnaud-lb@users.noreply.github.com>
ndossche and others added 27 commits September 29, 2026 19:28
* PHP-8.6:
  NEWS
  Fix property hook escape analysis causing misoptimization
  Fix __isset escape analysis causing misoptimization
pdo_dblib_stmt_execute() published &S->err to the DBPROCESS through
dbsetuserdata(), but FreeTDS keeps handing that pointer to the error and
message handlers for the life of the connection, long after the statement is
freed. A statement cannot retract it from its own destructor, since a GC
cycle can free the connection handle first, so every function that hands
H->link to libdblib now installs the pdo_dblib_err it owns. get_column_meta()
also stops allocating return_value before the dbcoltypeinfo() check that can
fail, which the new test would otherwise leak.

Fixes GH-23741
Closes GH-23751
* PHP-8.4:
  Fix GH-23741: pdo_dblib use-after-free of statement error state
* PHP-8.5:
  Fix GH-23741: pdo_dblib use-after-free of statement error state
* PHP-8.6:
  Fix GH-23741: pdo_dblib use-after-free of statement error state
Reconstructing a SimpleXMLElement decremented the shared node and then
installed a new document while the old pointer was still set, so the
second decrement freed a node a child object still held. Clear the
pointer before the new node is installed.

Closes GH-23931
* PHP-8.4:
  ext/libxml: Keep SimpleXML children alive across reconstruction
* PHP-8.6:
  openssl: Fix memory leak by doing early salt validation
* PHP-8.5:
  ext/libxml: Keep SimpleXML children alive across reconstruction
* PHP-8.6:
  ext/libxml: Keep SimpleXML children alive across reconstruction
…23825)

HAVE_EPOLL_PWAIT2 only tells whether the libc exports the wrapper, which
glibc does since 2.35 regardless of the running kernel. A PHP built on a
kernel with epoll_pwait2 and run on one older than 5.11 gets ENOSYS from
every Context::wait() call, which makes the epoll backend and thus the
Auto backend unusable. The same happens under emulation layers that do
not implement the syscall.

Try epoll_pwait2 first and on ENOSYS or ENOTSUP switch the process to
epoll_wait with a millisecond timeout, retrying the current call so the
failure is never visible to the caller. The flag is process wide since
kernel support is the same for every thread, and it is atomic so the
first concurrent waits in a ZTS build do not race on it.
…23825)

HAVE_EPOLL_PWAIT2 only tells whether the libc exports the wrapper, which
glibc does since 2.35 regardless of the running kernel. A PHP built on a
kernel with epoll_pwait2 and run on one older than 5.11 gets ENOSYS from
every Context::wait() call, which makes the epoll backend and thus the
Auto backend unusable. The same happens under emulation layers that do
not implement the syscall.

Try epoll_pwait2 first and on ENOSYS or ENOTSUP switch the process to
epoll_wait with a millisecond timeout, retrying the current call so the
failure is never visible to the caller. The flag is process wide since
kernel support is the same for every thread, and it is atomic so the
first concurrent waits in a ZTS build do not race on it.
* PHP-8.6:
  Fall back to epoll_wait when epoll_pwait2 is unavailable at runtime (#23825)
* PHP-8.4:
  Fix GH-23842: skipLazyInitialization() copies unresolved constant defaults
* PHP-8.5:
  Fix GH-23842: skipLazyInitialization() copies unresolved constant defaults
* PHP-8.6:
  Fix GH-23842: skipLazyInitialization() copies unresolved constant defaults
* PHP-8.4:
  Fix GH-23980: ZEND_ASSERT violation @ ZEND_INCLUDE_OR_EVAL (include/eval run with a pending exception)
* PHP-8.5:
  Fix GH-23980: ZEND_ASSERT violation @ ZEND_INCLUDE_OR_EVAL (include/eval run with a pending exception)
* PHP-8.6:
  Fix GH-23980: ZEND_ASSERT violation @ ZEND_INCLUDE_OR_EVAL (include/eval run with a pending exception)
…zero

A bc_num that is zero must carry PLUS, since bc_compare() orders by sign
first. The bc_divide() fast paths for a divisor of +/-1 or a power of ten,
bc_raise() with a positive exponent, and the Number add/sub/mul helpers
truncate to the requested scale and keep the operand sign, so
(new BcMath\Number('-0.001'))->div(1, 0) compares less than 0, is not
equal to 0, and makes sqrt() throw.

Closes GH-23967
* PHP-8.4:
  ext/bcmath: Clear the sign of BcMath\Number results that truncate to zero
* PHP-8.5:
  ext/bcmath: Clear the sign of BcMath\Number results that truncate to zero
* PHP-8.6:
  ext/bcmath: Clear the sign of BcMath\Number results that truncate to zero
@pull pull Bot locked and limited conversation to collaborators Sep 29, 2026
@pull pull Bot added the ⤵️ pull label Sep 29, 2026
@pull
pull Bot merged commit b19f17e into turkdevops:master Sep 29, 2026
0 of 2 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.