Skip to content

[pull] master from php:master - #1314

Merged
pull[bot] merged 16 commits into
turkdevops:masterfrom
php:master
Sep 28, 2026
Merged

pull[bot] merged 16 commits into
turkdevops:masterfrom
php:master

Conversation

@pull

@pull pull Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

TimWolla and others added 16 commits September 28, 2026 12:38
The UTF-8 encoder turned surrogate codepoints into 3-byte sequences like
"\xED\xA0\x80", which are not valid UTF-8. Such codepoints come from
UCS-2, UCS-4 or HTML-ENTITIES input, or from mb_decode_numericentity().
Since mbstring marks the UTF-8 strings it returns as valid UTF-8,
functions that trust that flag, like mb_check_encoding(), mb_scrub() or
preg_match(), accepted them too.

Surrogates are now replaced by the substitute character, as codepoints
above U+10FFFF already are. The internal mode used by mb_strpos() and
similar functions still encodes them, so that different surrogates don't
match each other.
And stop throwing the exceptions directly, fixing quiet mode handling at the same time.
* Add persistent stream context shutdown reproducer

* Clear persistent stream request pointers after shutdown
Using more than 16 filters in a php://filter URL was deprecated in 8.6, and will fail in PHP 8.7.

RFC: https://wiki.php.net/rfc/limit-maximum-number-of-filter-chains
zend_accel_inheritance_cache_add() linked the new entry into
proto->inheritance_cache before updating ZCSG(map_ptr_last), so another
process could take that entry in zend_accel_inheritance_cache_get(), extend
its map_ptr table only up to the previous value, and cache a class whose
methods' run_time_cache offsets sit past its own CG(map_ptr_last). Calling
such a method read an uninitialised slot, kept by
zend_init_func_run_time_cache() as it is not NULL, which an fcall observer
then dereferenced. The entry is now published last.

The store order alone does not hold on weakly ordered architectures, hence
the fences. The acquire sits right after ce->inheritance_cache is read, not
before the ZCSG(map_ptr_last) test: it pairs with the release only when
sequenced after the load reading the published pointer, and it also has to
cover the entry walk in zend_accel_inheritance_cache_find().

Close GH-23676
* PHP-8.4:
  Fix GH-23637: opcache inheritance cache entry published too early
* PHP-8.5:
  Fix GH-23637: opcache inheritance cache entry published too early
* PHP-8.6:
  Fix GH-23637: opcache inheritance cache entry published too early
@pull pull Bot locked and limited conversation to collaborators Sep 28, 2026
@pull pull Bot added the ⤵️ pull label Sep 28, 2026
@pull
pull Bot merged commit da4cc29 into turkdevops:master Sep 28, 2026
0 of 3 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants