Commit 33d7f34694f for php
commit 33d7f34694f942dd6a6696450fc45fb114a0a0fb
Merge: fbed672173f 630406c8956
Author: ndossche <7771979+ndossche@users.noreply.github.com>
Date: Thu Oct 8 20:40:48 2026 +0200
Merge branch 'PHP-8.4' into PHP-8.5
* PHP-8.4:
zend_alloc: move a small block shrunk to the size of the bin below
diff --cc NEWS
index 56d20ae2212,f2c2a126aa6..19f11fd33db
--- a/NEWS
+++ b/NEWS
@@@ -7,8 -7,17 +7,11 @@@ PH
in its previous chain. (Edmond)
. Fixed bug GH-23979 (Nullsafe operator must not flush delayed oplines of an
enclosing function). (ndossche)
+ . Fixed memory manager keeping a block reallocated to exactly the size of
+ the next smaller bin in its larger bin, which efree_size() then freed
+ into the wrong one. (Marc Bennewitz)
-- DOM:
- . Fixed bug GH-23352 (UAF reading an attribute value node retained across
- DOMDocument::adoptNode()). (David Carlier)
-
- Opcache:
- . Fixed bug GH-20890 (Segfault in zval_undefined_cv with non-simple property
- hook with minimal tracing JIT). (ndossche)
. Fixed bug GH-17626 (JIT corrupts an opline handler when blacklisting a
root trace at the opcache.jit_max_root_traces limit, causing spurious
"Too few arguments" errors and crashes). (RV7PR)
diff --cc ext/zend_test/test.stub.php
index eb4a6fac879,c595677fc4a..1e693707e3f
--- a/ext/zend_test/test.stub.php
+++ b/ext/zend_test/test.stub.php
@@@ -262,8 -246,8 +262,10 @@@ namespace
function zend_leak_bytes(int $bytes = 3): void {}
+ function zend_delref(mixed $variable): void {}
+
+ function zend_test_erealloc_block_size(int $old_size, int $new_size): array {}
+
function zend_string_or_object(object|string $param): object|string {}
function zend_string_or_object_or_null(object|string|null $param): object|string|null {}
diff --cc ext/zend_test/test_arginfo.h
index d605cff30ef,93792ac7c66..f4bd4c9ee7d
Binary files differ