Commit 2bb327e0043 for php

commit 2bb327e00436e0c3005c009765eb4b379592911b
Merge: 5261965b8f0 c72a5cad08b
Author: ndossche <7771979+ndossche@users.noreply.github.com>
Date:   Tue Sep 29 21:40:11 2026 +0200

    Merge branch 'PHP-8.5' into PHP-8.6

    * PHP-8.5:
      Fix GH-23842: skipLazyInitialization() copies unresolved constant defaults

diff --cc NEWS
index 19c3b30ee95,1f0cfb46efe..b76282a5c9a
--- a/NEWS
+++ b/NEWS
@@@ -1,92 -1,18 +1,96 @@@
  PHP                                                                        NEWS
  |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
 -?? ??? ????, PHP 8.5.12
 +?? ??? ????, PHP 8.6.0RC3

  - Core:
 -  . Fixed bug GH-23644 (Optimizer leaves a constant-vs-constant comparison
 -    unfolded, crashing the VM in zval_undefined_cv). (ndossche)
 -  . Fixed OSS-Fuzz 532353396 (assertion failure with static type). (Girgias)
 -  . Fix GH-23662 (Avoid NAN warning in print_r()). (CodedByManish)
 -  . Fix GH-21999: GC inconsistency with lazy object, var_dump(), and object
 -    comparison. (Arnaud)
    . Fixed OSS-Fuzz #536440507 (Immutable class incorrect assertion).
      (ndossche)
 +  . Fixed bug GH-23628 (Tracing JIT reads undefined property slots of lazy
 +    proxy objects instead of forwarding to the real instance). (lisachenko)
 +  . Fixed bug GH-23882 (array_map() optimization is incorrect for
 +    strict_types=1). (timwolla)
 +  . Fixed OSS-Fuzz #565486253 (coerced arg with '...' on non-variadic
 +    function). (ndossche)
    . Fixed AVX being reported as supported when the OS has not enabled AVX
      state. (Ilia Alshanetsky)
 +  . Fixed OSS-Fuzz #552682112 (assertion failure wrt
 +    zp_arg_must_be_sent_by_ref()). (ndossche)
 +  . Fixed GH-23921 (Fibers start with error_reporting = 0 when the
 +    error_reporting INI directive is not set). (Girgias)
 +
 +- FFI:
 +  . Fixed crashes with FFI callbacks created from __call() trampolines
 +    and array callables whose object is released. (Ilia Alshanetsky)
 +
 +- MySQLnd:
 +  . Fixed field_count not resetting on OK packet. (Kamil Tekiela)
 +  . Fixed memory leak when closing a prepared statement after its connection
 +    was killed. (Kamil Tekiela)
 +
 +- Opcache:
 +  . Fix zend_analyze_calls() call_stack buffer overrun. (Mrmaxmeier)
 +  . Fixed bug GH-23679 (Tracing JIT writes a parent private property into a
 +    child's shadowing public property). (Ilia Alshanetsky)
 +  . Fix multiple incorrect DCE due to unsound escape analysis. (ndossche,
 +    arnaud-lb)
 +
 +- OpenSSL:
 +  . Fixed stream_socket_enable_crypto() leaving the socket non-blocking
 +    after a handshake timeout. (Ilia Alshanetsky)
 +  . Fix memory leak by doing early salt validation. (adapik)
 +
 +- PCNTL:
 +  . Fixed pcntl_signal_dispatch() dropping the queued signals when it runs while
 +    an exception is pending. (nicolas-grekas)
 +  . Fixed pcntl_signal_dispatch() dropping the signals queued behind a handler
 +    that throws. (nicolas-grekas)
 +  . Fixed bug GH-23986 (/proc/self paths resolve to the parent process after
 +    pcntl_fork()). (Lazizbek Ergashev)
 +
 +- PDO:
 +  . Fixed PDO::setAttribute() installing a PDO::ATTR_STATEMENT_CLASS class
 +    whose constructor arguments it rejects. (Ilia Alshanetsky)
 +  . Fixed PDO::ATTR_STATEMENT_CLASS constructor_args type errors reporting
 +    "array given" regardless of the value passed. (Ilia Alshanetsky)
 +  . Fixed PDOStatement::bindParam() and bindColumn() leaking the driver
 +    options value. (Ilia Alshanetsky)
 +
 +- PDO_DBLIB:
 +  . Fixed bug GH-23741 (segfault after a failed query inside a PDO
 +    transaction). Errors raised by beginTransaction(), commit(), rollBack()
 +    and lastInsertId() are now reported instead of being dropped.
 +    (Ilia Alshanetsky)
 +
 +- PDO_PGSQL:
 +  . Fixed crash when a persistent connection fails. (KentarouTakeda)
 +
++- Reflection:
++  . Fixed bug GH-23842 (ReflectionProperty::skipLazyInitialization() copies
++    invalid constant defaults with OPcache). (DirkTrunkstar, Lazizbek Ergashev)
++
 +- SimpleXML:
 +  . Fixed reconstructing a SimpleXMLElement freeing a child element that
 +    another variable still references. (Ilia Alshanetsky)
 +
 +- Zip:
 +  . Fixed bug GH-23899 (Assertion failure when a cancel callback returns an
 +    invalid type during shutdown). (Weilin Du)
 +
 +24 Sep 2026, PHP 8.6.0RC2
 +
 +- Core:
 +  . Fixed incorrect internal pointer and foreach iterator positions when
 +    compacting arrays with holes. (Weilin Du)
 +  . Fix handling of references to typed properties during unserialization
 +    of various internal classes. (ndossche, timwolla)
 +  . Fixed OSS-Fuzz 532353396 (assertion	failure	with static type). (Girgias)
 +  . Fix GH-23662 (Avoid NAN warning in print_r()). (CodedByManish)
 +  . Fixed bug GH-23752 (Use scoped diagnostic suppression for the global
 +    register declarations so the caller's -Wvolatile-register-var state is
 +    restored). (yqtian-se)
 +  . Fixed OSS-Fuzz #538730793 (Assertion failure when returning by-ref from
 +    closure invoke). (ndossche)
 +  . Fixed OSS-Fuzz #540904105 (ASSERT: ast->attr == T_CLASS_C). (ndossche)

  - CLI
    . Fix GH-22567 (Windows ZTS CLI SAPI should refresh its TSRMLS cache during
diff --cc ext/reflection/php_reflection.c
index 8466cbcd27d,ea78bf601d4..7552b00c115
--- a/ext/reflection/php_reflection.c
+++ b/ext/reflection/php_reflection.c
@@@ -6223,7 -6400,7 +6223,7 @@@ ZEND_METHOD(ReflectionProperty, skipLaz
  		RETURN_THROWS();
  	}

- 	const zval *src = &object->ce->default_properties_table[OBJ_PROP_TO_NUM(prop->offset)];
 -	zval *src = &CE_DEFAULT_PROPERTIES_TABLE(object->ce)[OBJ_PROP_TO_NUM(prop->offset)];
++	const zval *src = &CE_DEFAULT_PROPERTIES_TABLE(object->ce)[OBJ_PROP_TO_NUM(prop->offset)];
  	zval *dst = OBJ_PROP(object, prop->offset);

  	if (!(Z_PROP_FLAG_P(dst) & IS_PROP_LAZY)) {