Commit 79572496206 for php
commit 795724962068de73e0ac78f3725188208ed8ee0b
Merge: 6bd5ab82aab 92e2fd60929
Author: Ilia Alshanetsky <ilia@ilia.ws>
Date: Tue Sep 29 16:09:31 2026 -0400
Merge branch 'PHP-8.5' into PHP-8.6
* PHP-8.5:
ext/tidy: Reject tidyNode use after the document is reparsed
diff --cc NEWS
index f36b4a6aecf,6fe75ef13e9..2bc21110f91
--- a/NEWS
+++ b/NEWS
@@@ -7,96 -7,18 +7,100 @@@ PH
and comparing less than zero. (Ilia Alshanetsky)
- Core:
- . Fixed bug GH-23644 (Optimizer leaves a constant-vs-constant comparison
- unfolded, crashing the VM in zval_undefined_cv). (ndossche)
- . Fixed OSS-Fuzz 532353396 (assertion failure with static type). (Girgias)
- . Fix GH-23662 (Avoid NAN warning in print_r()). (CodedByManish)
- . Fix GH-21999: GC inconsistency with lazy object, var_dump(), and object
- comparison. (Arnaud)
. Fixed OSS-Fuzz #536440507 (Immutable class incorrect assertion).
(ndossche)
+ . Fixed bug GH-23628 (Tracing JIT reads undefined property slots of lazy
+ proxy objects instead of forwarding to the real instance). (lisachenko)
+ . Fixed bug GH-23882 (array_map() optimization is incorrect for
+ strict_types=1). (timwolla)
+ . Fixed OSS-Fuzz #565486253 (coerced arg with '...' on non-variadic
+ function). (ndossche)
. Fixed AVX being reported as supported when the OS has not enabled AVX
state. (Ilia Alshanetsky)
+ . Fixed OSS-Fuzz #552682112 (assertion failure wrt
+ zp_arg_must_be_sent_by_ref()). (ndossche)
+ . Fixed GH-23921 (Fibers start with error_reporting = 0 when the
+ error_reporting INI directive is not set). (Girgias)
. Fixed GH-23980 (ZEND_ASSERT violation @ ZEND_INCLUDE_OR_EVAL). (ndossche)
+- FFI:
+ . Fixed crashes with FFI callbacks created from __call() trampolines
+ and array callables whose object is released. (Ilia Alshanetsky)
+
+- MySQLnd:
+ . Fixed field_count not resetting on OK packet. (Kamil Tekiela)
+ . Fixed memory leak when closing a prepared statement after its connection
+ was killed. (Kamil Tekiela)
+
+- Opcache:
+ . Fix zend_analyze_calls() call_stack buffer overrun. (Mrmaxmeier)
+ . Fixed bug GH-23679 (Tracing JIT writes a parent private property into a
+ child's shadowing public property). (Ilia Alshanetsky)
+ . Fix multiple incorrect DCE due to unsound escape analysis. (ndossche,
+ arnaud-lb)
+
+- OpenSSL:
+ . Fixed stream_socket_enable_crypto() leaving the socket non-blocking
+ after a handshake timeout. (Ilia Alshanetsky)
+ . Fix memory leak by doing early salt validation. (adapik)
+
+- PCNTL:
+ . Fixed pcntl_signal_dispatch() dropping the queued signals when it runs while
+ an exception is pending. (nicolas-grekas)
+ . Fixed pcntl_signal_dispatch() dropping the signals queued behind a handler
+ that throws. (nicolas-grekas)
+ . Fixed bug GH-23986 (/proc/self paths resolve to the parent process after
+ pcntl_fork()). (Lazizbek Ergashev)
+
+- PDO:
+ . Fixed PDO::setAttribute() installing a PDO::ATTR_STATEMENT_CLASS class
+ whose constructor arguments it rejects. (Ilia Alshanetsky)
+ . Fixed PDO::ATTR_STATEMENT_CLASS constructor_args type errors reporting
+ "array given" regardless of the value passed. (Ilia Alshanetsky)
+ . Fixed PDOStatement::bindParam() and bindColumn() leaking the driver
+ options value. (Ilia Alshanetsky)
+
+- PDO_DBLIB:
+ . Fixed bug GH-23741 (segfault after a failed query inside a PDO
+ transaction). Errors raised by beginTransaction(), commit(), rollBack()
+ and lastInsertId() are now reported instead of being dropped.
+ (Ilia Alshanetsky)
+
+- PDO_PGSQL:
+ . Fixed crash when a persistent connection fails. (KentarouTakeda)
+
+- Reflection:
+ . Fixed bug GH-23842 (ReflectionProperty::skipLazyInitialization() copies
+ invalid constant defaults with OPcache). (DirkTrunkstar, Lazizbek Ergashev)
+
+- SimpleXML:
+ . Fixed reconstructing a SimpleXMLElement freeing a child element that
+ another variable still references. (Ilia Alshanetsky)
+
++- Tidy:
++ . Fixed a use-after-free when a tidyNode is used after its document is
++ reparsed. (Ilia Alshanetsky)
++
+- Zip:
+ . Fixed bug GH-23899 (Assertion failure when a cancel callback returns an
+ invalid type during shutdown). (Weilin Du)
+
+24 Sep 2026, PHP 8.6.0RC2
+
+- Core:
+ . Fixed incorrect internal pointer and foreach iterator positions when
+ compacting arrays with holes. (Weilin Du)
+ . Fix handling of references to typed properties during unserialization
+ of various internal classes. (ndossche, timwolla)
+ . Fixed OSS-Fuzz 532353396 (assertion failure with static type). (Girgias)
+ . Fix GH-23662 (Avoid NAN warning in print_r()). (CodedByManish)
+ . Fixed bug GH-23752 (Use scoped diagnostic suppression for the global
+ register declarations so the caller's -Wvolatile-register-var state is
+ restored). (yqtian-se)
+ . Fixed OSS-Fuzz #538730793 (Assertion failure when returning by-ref from
+ closure invoke). (ndossche)
+ . Fixed OSS-Fuzz #540904105 (ASSERT: ast->attr == T_CLASS_C). (ndossche)
+
- CLI
. Fix GH-22567 (Windows ZTS CLI SAPI should refresh its TSRMLS cache during
request activation). (matyhtf)
diff --cc ext/tidy/tests/reparse_node.phpt
index 00000000000,7ba20b3939c..2ee03d8344e
mode 000000,100644..100644
--- a/ext/tidy/tests/reparse_node.phpt
+++ b/ext/tidy/tests/reparse_node.phpt
@@@ -1,0 -1,66 +1,57 @@@
+ --TEST--
+ tidyNode objects are invalid after reparsing their document
+ --EXTENSIONS--
+ tidy
+ --FILE--
+ <?php
+
-$node = unserialize('O:8:"tidyNode":0:{}');
-try {
- $node->hasChildren();
- echo "unowned node: no error\n";
-} catch (Error $e) {
- echo 'unowned node: ', $e::class, ': ', $e->getMessage(), "\n";
-}
-
+ $tidy = tidy_parse_string('<html><body><p>one</p><p>two</p></body></html>');
+ $node = $tidy->body()->child[0];
+ var_dump($node->isHtml());
+ var_dump($node->hasSiblings());
+
+ $tidy->parseString('<html><body><p>three</p></body></html>');
+
+ $operations = [
+ 'string cast' => static fn() => (string) $node,
+ 'hasChildren' => static fn() => $node->hasChildren(),
+ 'hasSiblings' => static fn() => $node->hasSiblings(),
+ 'isComment' => static fn() => $node->isComment(),
+ 'isHtml' => static fn() => $node->isHtml(),
+ 'isText' => static fn() => $node->isText(),
+ 'isJste' => static fn() => $node->isJste(),
+ 'isAsp' => static fn() => $node->isAsp(),
+ 'isPhp' => static fn() => $node->isPhp(),
+ 'getParent' => static fn() => $node->getParent(),
+ 'getPreviousSibling' => static fn() => $node->getPreviousSibling(),
+ 'getNextSibling' => static fn() => $node->getNextSibling(),
+ ];
+
+ foreach ($operations as $operation => $callback) {
+ try {
+ $callback();
+ echo $operation, ": no error\n";
+ } catch (Error $e) {
+ echo $operation, ': ', $e::class, ': ', $e->getMessage(), "\n";
+ }
+ }
+
+ var_dump($tidy->body()->child[0]->isHtml());
+
+ ?>
+ --EXPECT--
-unowned node: Error: tidyNode object is not initialized
+ bool(true)
+ bool(true)
+ string cast: Error: tidyNode object is no longer valid after its document was reparsed
+ hasChildren: Error: tidyNode object is no longer valid after its document was reparsed
+ hasSiblings: Error: tidyNode object is no longer valid after its document was reparsed
+ isComment: Error: tidyNode object is no longer valid after its document was reparsed
+ isHtml: Error: tidyNode object is no longer valid after its document was reparsed
+ isText: Error: tidyNode object is no longer valid after its document was reparsed
+ isJste: Error: tidyNode object is no longer valid after its document was reparsed
+ isAsp: Error: tidyNode object is no longer valid after its document was reparsed
+ isPhp: Error: tidyNode object is no longer valid after its document was reparsed
+ getParent: Error: tidyNode object is no longer valid after its document was reparsed
+ getPreviousSibling: Error: tidyNode object is no longer valid after its document was reparsed
+ getNextSibling: Error: tidyNode object is no longer valid after its document was reparsed
+ bool(true)