Skip to content

[pull] master from php:master - #1316

Merged
pull[bot] merged 27 commits into
turkdevops:masterfrom
php:master
Sep 29, 2026
Merged

pull[bot] merged 27 commits into
turkdevops:masterfrom
php:master

Conversation

@pull

@pull pull Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

iliaal and others added 27 commits September 28, 2026 16:04
zend_cpu_startup() masked ZEND_CPU_FEATURE_AVX out of EDX when XCR0 lacks
the SSE or AVX state bits, but AVX is CPUID.1:ECX bit 28 and EDX bit 28 is
HTT. zend_cpu_supports(ZEND_CPU_FEATURE_AVX) kept reporting AVX, so builds
without __builtin_cpu_supports(), such as MSVC, let the JIT emit VEX-encoded
instructions that fault on such hosts.

Closes GH-23966
* PHP-8.4:
  Zend: clear the AVX bit in ECX when the OS has not enabled AVX state
* PHP-8.5:
  Zend: clear the AVX bit in ECX when the OS has not enabled AVX state
* PHP-8.6:
  Zend: clear the AVX bit in ECX when the OS has not enabled AVX state
* PHP-8.4:
  Fix incorrect DCE due to unsound escape analysis
* PHP-8.5:
  Fix incorrect DCE due to unsound escape analysis
* PHP-8.6:
  Fix incorrect DCE due to unsound escape analysis
…fail (#23855)

If the protection call fails, the memory is likely going to have the wrong
permissions and result in a later segmentation fault when trying to use it;
replace the `stderr` log messages with `zend_accel_error_noreturn()` calls that
abort the process.
* PHP-8.6:
  Opcache: abort process when `mprotect()` or `VirtualProtect()` calls fail (#23855)
…hunks

Apply the changes from libgd/libgd@7ff626c in
order to fix undefined behavior when creating a GD2 image when a compressed
chunk claims to take `INT_MAX` space.
* PHP-8.4:
  NEWS
  ext/gd: fix undefined behavior with GD2 images with `INT_MAX`-sized chunks
* PHP-8.5:
  NEWS
  ext/gd: fix undefined behavior with GD2 images with `INT_MAX`-sized chunks
* PHP-8.6:
  NEWS
  ext/gd: fix undefined behavior with GD2 images with `INT_MAX`-sized chunks
A handshake timeout returned before php_openssl_enable_crypto() restored
the socket blocking mode saved at entry. That return now restores it, as
the normal return already does.

Closes GH-23932
* PHP-8.4:
  ext/openssl: Restore blocking mode after a handshake timeout
…n bounds (#23955)

Add a hardening assertion that when `mb_wchar_to_uuencode()` needs to update
the length of the previous line, the location being written to is still part of
the same overall output string (i.e. at or after the start of the buffer's
`str`'s value pointer, and before the end of the char array).
* PHP-8.6:
  ext/mbstring: assert that `mb_wchar_to_uuencode()` pointer write is in bounds (#23955)
* PHP-8.5:
  ext/openssl: Restore blocking mode after a handshake timeout
* PHP-8.6:
  ext/openssl: Restore blocking mode after a handshake timeout
* PHP-8.6:
  ext/iconv: add a hardening assertion that `char_cnt` doesn't underflow (#23873)
@pull pull Bot locked and limited conversation to collaborators Sep 29, 2026
@pull pull Bot added the ⤵️ pull label Sep 29, 2026
@pull
pull Bot merged commit 810ac6d into turkdevops:master Sep 29, 2026
1 of 3 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants