Skip to content

[pull] master from php:master - #1322

Merged
pull[bot] merged 28 commits into
turkdevops:masterfrom
php:master
Sep 30, 2026
Merged

pull[bot] merged 28 commits into
turkdevops:masterfrom
php:master

Conversation

@pull

@pull pull Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

derickr and others added 28 commits September 30, 2026 10:38
* PHP-8.4:
  Updated to version 2026.5 (2026e)
* PHP-8.5:
  Updated to version 2026.5 (2026e)
* PHP-8.6:
  Updated to version 2026.5 (2026e)
…24009)

ZipArchive::registerProgressCallback() is only available when PHP is built
against libzip 1.3.0 or newer. Skip gh18431.phpt when the method is absent
to avoid an undefined method error, as the other progress callback tests
already do.

Closes #24009
* PHP-8.4:
  Fix GH-24006: Skip gh18431.phpt when libzip lacks progress callbacks (#24009)
* PHP-8.5:
  Fix GH-24006: Skip gh18431.phpt when libzip lacks progress callbacks (#24009)
* PHP-8.6:
  Fix GH-24006: Skip gh18431.phpt when libzip lacks progress callbacks (#24009)
php_cli_server_content_sender_send() moved on to the next queued chunk
after a short send() of the current one. When that send() succeeded, its
bytes went out ahead of the current chunk's remainder, and the full-send
branch pointed buffer.first past both, unlinking the partially sent chunk.
The client received later chunks spliced into the body, the connection was
closed short of Content-Length, and the unsent remainder leaked. Stop at
the first partial write and resume from that chunk on the next POLLOUT.

Closes GH-23969
CLOCK_MONOTONIC_RAW is not disciplined by NTP, so it ticks with the raw
frequency error of the underlying oscillator, which is 4% under WSL2 and
makes hrtime() disagree with microtime() by that much.

The slew that GH-19221 wanted to avoid is bounded to 500ppm by the kernel
and is what makes CLOCK_MONOTONIC track elapsed real time.

zend_hrtime_posix_clock_id stays for ABI compatibility, but nothing reads
it anymore.

Co-authored-by: Tim Düsterhus <tim@tideways-gmbh.com>
* PHP-8.6:
  zend_hrtime: use CLOCK_MONOTONIC instead of CLOCK_MONOTONIC_RAW (#23790)
* PHP-8.4:
  sapi/cli: Fix built-in server truncating responses after a partial write
* PHP-8.5:
  sapi/cli: Fix built-in server truncating responses after a partial write
* PHP-8.6:
  sapi/cli: Fix built-in server truncating responses after a partial write
PDOStatement::execute() returned false on a bind, parse, or driver
failure without clearing stmt->executed, so a later fetch returned rows
from the previous success. Close the previous result on entry, before
the error state is cleared, so a cursor closer that records an error
cannot replace the SQLSTATE of the failure execute() reports.

Closes GH-23938
* PHP-8.4:
  ext/pdo: Drop the previous result when execute() fails
…rgs (#23254)

Non-literal expressions must be evaluated once and memoized to maintain
semantics.
* PHP-8.6:
  Fix array_map optimization with non-literal function or non-literal args (#23254)
IR commit: 93f92f5b5a49a02295685e340ebb0b83562cbe79
* PHP-8.6:
  Update IR (#24013)
* PHP-8.5:
  ext/pdo: Drop the previous result when execute() fails
* PHP-8.6:
  ext/pdo: Drop the previous result when execute() fails
SQLite3Stmt::reset() reports a failed sqlite3_reset() through
php_sqlite3_error(), but SQLite3Result::reset() returned false silently
and SQLite3Result::finalize() ignored the result. Both now surface the
underlying SQLite error the same way; finalize() keeps its : true return
type and reports without altering the return value.

Fixes GH-22051
Closes GH-22363
dispatch_param_event iterates bound_params with ZEND_HASH_FOREACH
while sqlite's EXEC_PRE hook can run __toString; execute() then
destroys the table and bindValue() replaces buckets. Steal one
_reserved bit as in_param_event (no layout size change; the header
is installed) and throw Error from bindParam, bindValue, bindColumn,
execute, and closeCursor while the hook is running. fetch is left
unguarded: nested FOREACH is read-only and FETCH_POST writes column
zvals, not the HashTable. 8.5/master already have a uint16_t
bitfield with in_fetch; the forward merge needs in_param_event:1
and reserved:11.

Closes GH-23252
* PHP-8.4:
  Fix HashTable UAF when rebound from a parameter __toString()
* PHP-8.5:
  Fix HashTable UAF when rebound from a parameter __toString()
* PHP-8.6:
  Fix HashTable UAF when rebound from a parameter __toString()
@pull pull Bot locked and limited conversation to collaborators Sep 30, 2026
@pull pull Bot added the ⤵️ pull label Sep 30, 2026
@pull
pull Bot merged commit cb28aa0 into turkdevops:master Sep 30, 2026
0 of 2 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants