Commit f8324d20886 for php

commit f8324d20886a854059542f0d95d866aa9a4e01c1
Merge: 69367447d1c 2cf3a178df3
Author: ndossche <7771979+ndossche@users.noreply.github.com>
Date:   Tue Sep 29 19:28:29 2026 +0200

    Merge branch 'PHP-8.5' into PHP-8.6

    * PHP-8.5:
      NEWS
      Fix property hook escape analysis causing misoptimization
      Fix __isset escape analysis causing misoptimization

diff --cc NEWS
index b4ebac826d7,2813c24fc06..d700a7be0de
--- a/NEWS
+++ b/NEWS
@@@ -1,80 -1,18 +1,81 @@@
  PHP                                                                        NEWS
  |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
 -?? ??? ????, PHP 8.5.12
 +?? ??? ????, PHP 8.6.0RC3

  - Core:
 -  . Fixed bug GH-23644 (Optimizer leaves a constant-vs-constant comparison
 -    unfolded, crashing the VM in zval_undefined_cv). (ndossche)
 -  . Fixed OSS-Fuzz 532353396 (assertion failure with static type). (Girgias)
 -  . Fix GH-23662 (Avoid NAN warning in print_r()). (CodedByManish)
 -  . Fix GH-21999: GC inconsistency with lazy object, var_dump(), and object
 -    comparison. (Arnaud)
    . Fixed OSS-Fuzz #536440507 (Immutable class incorrect assertion).
      (ndossche)
 +  . Fixed bug GH-23628 (Tracing JIT reads undefined property slots of lazy
 +    proxy objects instead of forwarding to the real instance). (lisachenko)
 +  . Fixed bug GH-23882 (array_map() optimization is incorrect for
 +    strict_types=1). (timwolla)
 +  . Fixed OSS-Fuzz #565486253 (coerced arg with '...' on non-variadic
 +    function). (ndossche)
    . Fixed AVX being reported as supported when the OS has not enabled AVX
      state. (Ilia Alshanetsky)
 +  . Fixed OSS-Fuzz #552682112 (assertion failure wrt
 +    zp_arg_must_be_sent_by_ref()). (ndossche)
 +  . Fixed GH-23921 (Fibers start with error_reporting = 0 when the
 +    error_reporting INI directive is not set). (Girgias)
 +
 +- FFI:
 +  . Fixed crashes with FFI callbacks created from __call() trampolines
 +    and array callables whose object is released. (Ilia Alshanetsky)
 +
 +- MySQLnd:
 +  . Fixed field_count not resetting on OK packet. (Kamil Tekiela)
 +  . Fixed memory leak when closing a prepared statement after its connection
 +    was killed. (Kamil Tekiela)
 +
 +- Opcache:
 +  . Fix zend_analyze_calls() call_stack buffer overrun. (Mrmaxmeier)
 +  . Fixed bug GH-23679 (Tracing JIT writes a parent private property into a
 +    child's shadowing public property). (Ilia Alshanetsky)
-   . Fix incorrect DCE due to unsound escape analysis. (ndossche)
++  . Fix multiple incorrect DCE due to unsound escape analysis. (ndossche,
++    arnaud-lb)
 +
 +- OpenSSL:
 +  . Fixed stream_socket_enable_crypto() leaving the socket non-blocking
 +    after a handshake timeout. (Ilia Alshanetsky)
 +
 +- PCNTL:
 +  . Fixed pcntl_signal_dispatch() dropping the queued signals when it runs while
 +    an exception is pending. (nicolas-grekas)
 +  . Fixed pcntl_signal_dispatch() dropping the signals queued behind a handler
 +    that throws. (nicolas-grekas)
 +  . Fixed bug GH-23986 (/proc/self paths resolve to the parent process after
 +    pcntl_fork()). (Lazizbek Ergashev)
 +
 +- PDO:
 +  . Fixed PDO::setAttribute() installing a PDO::ATTR_STATEMENT_CLASS class
 +    whose constructor arguments it rejects. (Ilia Alshanetsky)
 +  . Fixed PDO::ATTR_STATEMENT_CLASS constructor_args type errors reporting
 +    "array given" regardless of the value passed. (Ilia Alshanetsky)
 +  . Fixed PDOStatement::bindParam() and bindColumn() leaking the driver
 +    options value. (Ilia Alshanetsky)
 +
 +- PDO_PGSQL:
 +  . Fixed crash when a persistent connection fails. (KentarouTakeda)
 +
 +- Zip:
 +  . Fixed bug GH-23899 (Assertion failure when a cancel callback returns an
 +    invalid type during shutdown). (Weilin Du)
 +
 +24 Sep 2026, PHP 8.6.0RC2
 +
 +- Core:
 +  . Fixed incorrect internal pointer and foreach iterator positions when
 +    compacting arrays with holes. (Weilin Du)
 +  . Fix handling of references to typed properties during unserialization
 +    of various internal classes. (ndossche, timwolla)
 +  . Fixed OSS-Fuzz 532353396 (assertion	failure	with static type). (Girgias)
 +  . Fix GH-23662 (Avoid NAN warning in print_r()). (CodedByManish)
 +  . Fixed bug GH-23752 (Use scoped diagnostic suppression for the global
 +    register declarations so the caller's -Wvolatile-register-var state is
 +    restored). (yqtian-se)
 +  . Fixed OSS-Fuzz #538730793 (Assertion failure when returning by-ref from
 +    closure invoke). (ndossche)
 +  . Fixed OSS-Fuzz #540904105 (ASSERT: ast->attr == T_CLASS_C). (ndossche)

  - CLI
    . Fix GH-22567 (Windows ZTS CLI SAPI should refresh its TSRMLS cache during
diff --cc Zend/Optimizer/escape_analysis.c
index ca1cb6c1fde,3c2864d14fb..59e0cea05a7
--- a/Zend/Optimizer/escape_analysis.c
+++ b/Zend/Optimizer/escape_analysis.c
@@@ -170,9 -173,11 +170,11 @@@ static bool is_allocation_def(const zen
  				 && !ce->destructor
  				 && !ce->__get
  				 && !ce->__set
+ 				 && !ce->__isset
+ 				 && !ce->num_hooked_props
  				 && !(ce->ce_flags & forbidden_flags)
  				 && (ce->ce_flags & ZEND_ACC_CONSTANTS_UPDATED)) {
 -					return 1;
 +					return true;
  				}
  				break;
  			}
@@@ -239,8 -244,10 +241,10 @@@ static bool is_local_def(const zend_op_
  				 && !ce->destructor
  				 && !ce->__get
  				 && !ce->__set
+ 				 && !ce->__isset
+ 				 && !ce->num_hooked_props
  				 && !ce->parent) {
 -					return 1;
 +					return true;
  				}
  				break;
  			}