Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
46 commits
Select commit Hold shift + click to select a range
b4e3397
Fix heap-buffer-overflow in convert stream filters with NUL in line-b…
geeknik Feb 7, 2026
dcdfcf8
Fix GHSA-62xp-839h-2637: FastCGI allowed_clients compared only 96 bit…
alexandre-daubois Aug 25, 2026
0bb308e
Fix GHSA-vvx9-73fr-5jjx: do not fall back to CN if the cert has a ser…
bukka Aug 10, 2026
78cc82b
Fix GHSA-xr7j-rvgx-xq5p: OOB read in php_openssl_matches_wildcard_name()
bukka Aug 10, 2026
114dbb7
Fix GHSA-r6x9-5r99-36j7: Various packet overreads in mysqlnd wireprot…
bukka Jul 12, 2026
5af9465
Fix GHSA-fpwc-w8rq-cr92: strip credentials from user headers on cross…
alexandre-daubois Sep 14, 2026
3655b79
Fix GHSA-rgrp-mwpx-f6rm: unbounded recursion in ext/soap XML parsing …
alexandre-daubois Sep 17, 2026
b11bd1d
Fix GHSA-cj93-vc83-wgqv
ndossche Sep 13, 2026
0994e2e
Fix GHSA-j3wh-g957-2m85: phar tar entry injection
bukka Sep 13, 2026
f785c3f
Fix GHSA-9f67-6fw4-hpfp
shivammathur Sep 18, 2026
7ac9700
Fix GHSA-ch8v-r6jh-4vvr: encode 0xFF in FILTER_SANITIZE_ENCODED
iliaal Jul 29, 2026
547566f
[http] Fix out-of-bounds read on empty Location header
iliaal Aug 24, 2026
6466475
ext/standard: Fix 1-char relative Location redirects after GH-23467
jordikroon Aug 31, 2026
a14181c
Add NEWS entries
bukka Sep 18, 2026
3aedde0
ext/soap: make GHSA-cj93-vc83-wgqv test lean and reliable
bukka Sep 18, 2026
a1a7bd4
Fix GH-11662: Skip multicast test when unavailable
prateekbhujel Sep 22, 2026
247ae24
Merge branch 'PHP-8.4' into PHP-8.5
devnexen Sep 22, 2026
fdc4aa9
Merge branch 'PHP-8.5'
devnexen Sep 22, 2026
f9e0418
Merge branch 'PHP-8.2' into PHP-8.3
bukka Sep 22, 2026
2cd1675
Merge branch 'PHP-8.3' into PHP-8.4
bukka Sep 22, 2026
7d4f779
Skip bz2 GH-20807 test when less than 13 GiB of memory is available
bukka Sep 20, 2026
2ef7525
Merge branch 'PHP-8.4' into PHP-8.5
bukka Sep 22, 2026
48e53b0
Merge branch 'PHP-8.5'
bukka Sep 22, 2026
5efde93
Enable the TAILCALL VM when building with --disable-gcc-global-regs o…
henderkes Sep 22, 2026
7f8a74f
master is now for PHP 8.7.0-dev
mbeccati Sep 22, 2026
5a6c223
CI updates after forking 8.6
mbeccati Sep 22, 2026
6301283
ext/intl: Reject unconstructed Collator in attribute and strength met…
iliaal Aug 24, 2026
b800171
Merge branch 'PHP-8.4' into PHP-8.5
iliaal Sep 22, 2026
fe96b7a
Merge branch 'PHP-8.5' into PHP-8.6
iliaal Sep 22, 2026
a99cf8e
Merge branch 'PHP-8.6'
iliaal Sep 22, 2026
95c29bb
CI updates after forking 8.6
mbeccati Sep 22, 2026
9a3e7f3
Merge branch 'PHP-8.4' into PHP-8.5
mbeccati Sep 22, 2026
742d4f6
Merge branch 'PHP-8.5' into PHP-8.6
mbeccati Sep 22, 2026
0220772
Merge branch 'PHP-8.6'
mbeccati Sep 22, 2026
68d84fa
PHP 8.3 is now for PHP 8.3.36
bukka Sep 22, 2026
77541b3
Merge branch 'PHP-8.3' into PHP-8.4
bukka Sep 22, 2026
2b5a22f
Merge branch 'PHP-8.4' into PHP-8.5
bukka Sep 22, 2026
aefec40
Merge branch 'PHP-8.5' into PHP-8.6
bukka Sep 22, 2026
5714009
CI updates after forking 8.6
mbeccati Sep 22, 2026
5eaff70
Merge branch 'PHP-8.6'
bukka Sep 22, 2026
795440a
Fix GHSA-fpwc-w8rq-cr92: do not cut the request short when stripping …
bukka Sep 22, 2026
bf40d5f
Merge branch 'PHP-8.5' into PHP-8.6
bukka Sep 22, 2026
6388614
Merge branch 'PHP-8.6'
bukka Sep 22, 2026
8f9a9f3
Merge branch 'PHP-8.4' into PHP-8.5
mbeccati Sep 22, 2026
72769be
Merge branch 'PHP-8.5' into PHP-8.6
mbeccati Sep 22, 2026
a26f9e5
Merge branch 'PHP-8.6'
mbeccati Sep 22, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
3 changes: 2 additions & 1 deletion .github/matrix.php
Original file line number Diff line number Diff line change
@@ -1,7 +1,8 @@
<?php

const BRANCHES = [
['name' => 'master', 'ref' => 'master', 'version' => [8, 6]],
['name' => 'master', 'ref' => 'master', 'version' => [8, 7]],
['name' => 'PHP-8.6', 'ref' => 'PHP-8.6', 'version' => [8, 6]],
['name' => 'PHP-8.5', 'ref' => 'PHP-8.5', 'version' => [8, 5]],
['name' => 'PHP-8.4', 'ref' => 'PHP-8.4', 'version' => [8, 4]],
['name' => 'PHP-8.3', 'ref' => 'PHP-8.3', 'version' => [8, 3]],
Expand Down
2 changes: 1 addition & 1 deletion .github/scripts/windows/find-target-branch.bat
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,6 @@
for /f "usebackq tokens=3" %%i in (`findstr PHP_MAJOR_VERSION main\php_version.h`) do set BRANCH=%%i
for /f "usebackq tokens=3" %%i in (`findstr PHP_MINOR_VERSION main\php_version.h`) do set BRANCH=%BRANCH%.%%i

if /i "%BRANCH%" equ "8.6" (
if /i "%BRANCH%" equ "8.7" (
set BRANCH=master
)
1 change: 1 addition & 0 deletions .github/workflows/test.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,7 @@ on:
- PHP-8.3
- PHP-8.4
- PHP-8.5
- PHP-8.6
- master
pull_request:
paths-ignore: *ignore_paths
Expand Down
1,125 changes: 3 additions & 1,122 deletions NEWS

Large diffs are not rendered by default.

1,093 changes: 1 addition & 1,092 deletions UPGRADING

Large diffs are not rendered by default.

340 changes: 1 addition & 339 deletions UPGRADING.INTERNALS

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion Zend/zend.h
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@
#ifndef ZEND_H
#define ZEND_H

#define ZEND_VERSION "4.6.0-dev"
#define ZEND_VERSION "4.7.0-dev"

#define ZEND_ENGINE_3

Expand Down
2 changes: 1 addition & 1 deletion Zend/zend_extensions.h
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ You can use the following macro to check the extension API version for compatibi

/* The first number is the engine version and the rest is the date (YYYYMMDD).
* This way engine 2/3 API no. is always greater than engine 1 API no.. */
#define ZEND_EXTENSION_API_NO 420250926
#define ZEND_EXTENSION_API_NO 420260925

typedef struct _zend_extension_version_info {
int zend_extension_api_no;
Expand Down
2 changes: 1 addition & 1 deletion Zend/zend_modules.h
Original file line number Diff line number Diff line change
Expand Up @@ -30,7 +30,7 @@
#define ZEND_MODULE_INFO_FUNC_ARGS zend_module_entry *zend_module
#define ZEND_MODULE_INFO_FUNC_ARGS_PASSTHRU zend_module

#define ZEND_MODULE_API_NO 20250926
#define ZEND_MODULE_API_NO 20260925
#ifdef ZTS
#define USING_ZTS 1
#else
Expand Down
13 changes: 13 additions & 0 deletions Zend/zend_virtual_cwd.c
Original file line number Diff line number Diff line change
Expand Up @@ -1027,6 +1027,19 @@ CWD_API int virtual_file_ex(cwd_state *state, const char *path, verify_path_func
fprintf(stderr,"cwd = %s path = %s\n", state->cwd, path);
#endif

#ifdef ZEND_WIN32
switch (php_win32_ioutil_path_kind_a(path, path_length)) {
case PHP_WIN32_IOUTIL_PATH_RESERVED:
SET_ERRNO_FROM_WIN32_CODE(ERROR_INVALID_NAME);
return 1;
case PHP_WIN32_IOUTIL_PATH_DEVICE:
memcpy(resolved_path, path, path_length + 1);
goto verify;
default:
break;
}
#endif

/* cwd_length can be 0 when getcwd() fails.
* This can happen under solaris when a dir does not have read permissions
* but *does* have execute permissions */
Expand Down
2 changes: 1 addition & 1 deletion Zend/zend_vm_gen.php
Original file line number Diff line number Diff line change
Expand Up @@ -2522,7 +2522,7 @@ function gen_vm_opcodes_header(
$str .= "# define ZEND_VM_KIND\t\tZEND_VM_KIND_HYBRID\n";
}
if ($GLOBALS["vm_kind_name"][ZEND_VM_GEN_KIND] === "ZEND_VM_KIND_HYBRID" || $GLOBALS["vm_kind_name"][ZEND_VM_GEN_KIND] === "ZEND_VM_KIND_CALL") {
$str .= "#elif defined(HAVE_MUSTTAIL) && defined(HAVE_PRESERVE_NONE) && (defined(__x86_64__) || defined(_M_X64) || defined(__aarch64__)) && defined(__clang__)\n";
$str .= "#elif defined(HAVE_MUSTTAIL) && defined(HAVE_PRESERVE_NONE) && (defined(__x86_64__) || defined(__aarch64__))\n";
$str .= "# define ZEND_VM_KIND\t\tZEND_VM_KIND_TAILCALL\n";
$str .= "#else\n";
$str .= "# define ZEND_VM_KIND\t\tZEND_VM_KIND_CALL\n";
Expand Down
2 changes: 1 addition & 1 deletion Zend/zend_vm_opcodes.h

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

2 changes: 1 addition & 1 deletion configure.ac
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ dnl Basic autoconf initialization, generation of config.nice.
dnl ----------------------------------------------------------------------------

AC_PREREQ([2.68])
AC_INIT([PHP],[8.6.0-dev],[https://github.com/php/php-src/issues],[php],[https://www.php.net])
AC_INIT([PHP],[8.7.0-dev],[https://github.com/php/php-src/issues],[php],[https://www.php.net])
AC_CONFIG_SRCDIR([main/php_version.h])
AC_CONFIG_MACRO_DIR([build])
AC_CONFIG_AUX_DIR([build])
Expand Down
1 change: 0 additions & 1 deletion docs/release-process.md
Original file line number Diff line number Diff line change
Expand Up @@ -952,7 +952,6 @@ feature development that cannot go into the new version.
`Zend/zend.h`, and `win32/build/confutils.js`;
* update the API version numbers in `Zend/zend_extensions.h`,
`Zend/zend_modules.h`, and `main/php.h`; and
* add the new branch to the list in `CONTRIBUTING.md`.
See [Prepare for PHP 8.2][] and [Prepare for PHP 8.2 (bis)][] for an example
of what this commit should include.
Expand Down
6 changes: 6 additions & 0 deletions ext/bz2/tests/gh20807.phpt
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,12 @@ if (PHP_OS === 'FreeBSD') die('skip Worker does not handle OOM gracefully');
if (PHP_OS_FAMILY === 'Darwin') die('skip Too slow');
if (PHP_INT_SIZE !== 8) die('skip Only for 64-bit systems');
if (getenv('SKIP_ASAN')) die('skip ASAN makes this test too slow');
// The decompressed output needs more than 12 GiB of memory at its peak, which
// takes down smaller machines (e.g. 7 GB CI runners) with the OOM killer.
$memInfo = @file_get_contents('/proc/meminfo');
if ($memInfo && preg_match('/MemAvailable:\s+(\d+) kB/', $memInfo, $m) && $m[1] < 13 * 1024 * 1024) {
die('skip Insufficient available memory (less than 13 GiB)');
}
?>
--FILE--
<?php
Expand Down
16 changes: 16 additions & 0 deletions ext/intl/collator/collator_attr.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,10 @@ U_CFUNC PHP_FUNCTION( collator_get_attribute )
/* Fetch the object. */
COLLATOR_METHOD_FETCH_OBJECT;

if (collator_check_initialized(co) == FAILURE) {
RETURN_THROWS();
}

value = ucol_getAttribute( co->ucoll, static_cast<UColAttribute>(attribute), COLLATOR_ERROR_CODE_P( co ) );
COLLATOR_CHECK_STATUS( co, "Error getting attribute value" );

Expand All @@ -71,6 +75,10 @@ U_CFUNC PHP_FUNCTION( collator_set_attribute )
/* Fetch the object. */
COLLATOR_METHOD_FETCH_OBJECT;

if (collator_check_initialized(co) == FAILURE) {
RETURN_THROWS();
}

/* Set new value for the given attribute. */
ucol_setAttribute( co->ucoll, static_cast<UColAttribute>(attribute), static_cast<UColAttributeValue>(value), COLLATOR_ERROR_CODE_P( co ) );
COLLATOR_CHECK_STATUS( co, "Error setting attribute value" );
Expand All @@ -94,6 +102,10 @@ U_CFUNC PHP_FUNCTION( collator_get_strength )
/* Fetch the object. */
COLLATOR_METHOD_FETCH_OBJECT;

if (collator_check_initialized(co) == FAILURE) {
RETURN_THROWS();
}

/* Get current strength and return it. */
RETURN_LONG( ucol_getStrength( co->ucoll ) );
}
Expand All @@ -116,6 +128,10 @@ U_CFUNC PHP_FUNCTION( collator_set_strength )
/* Fetch the object. */
COLLATOR_METHOD_FETCH_OBJECT;

if (collator_check_initialized(co) == FAILURE) {
RETURN_THROWS();
}

/* Set given strength. */
ucol_setStrength( co->ucoll, static_cast<UColAttributeValue>(strength) );

Expand Down
15 changes: 15 additions & 0 deletions ext/intl/collator/collator_class.h
Original file line number Diff line number Diff line change
Expand Up @@ -50,6 +50,21 @@ typedef struct {
#define php_intl_collator_fetch_object(obj) ZEND_CONTAINER_OF(obj, Collator_object, zo)
#define Z_INTL_COLLATOR_P(zv) php_intl_collator_fetch_object(Z_OBJ_P(zv))

static zend_always_inline zend_result collator_check_initialized(Collator_object *co)
{
ZEND_ASSERT(co != NULL);

if (UNEXPECTED(co->ucoll == NULL)) {
intl_error_set_code( NULL, COLLATOR_ERROR_CODE( co ) );
intl_errors_set_custom_msg(COLLATOR_ERROR_P( co ), "Object not initialized");
zend_throw_error(NULL, "Object not initialized");

return FAILURE;
}

return SUCCESS;
}

#ifdef __cplusplus
extern "C" {
#endif
Expand Down
6 changes: 1 addition & 5 deletions ext/intl/collator/collator_compare.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -55,11 +55,7 @@ U_CFUNC PHP_FUNCTION( collator_compare )
/* Fetch the object. */
COLLATOR_METHOD_FETCH_OBJECT;

if (!co || !co->ucoll) {
intl_error_set_code( NULL, COLLATOR_ERROR_CODE( co ) );
intl_errors_set_custom_msg(COLLATOR_ERROR_P( co ), "Object not initialized");
zend_throw_error(NULL, "Object not initialized");

if (collator_check_initialized(co) == FAILURE) {
RETURN_THROWS();
}

Expand Down
6 changes: 1 addition & 5 deletions ext/intl/collator/collator_locale.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -48,11 +48,7 @@ U_CFUNC PHP_FUNCTION( collator_get_locale )
/* Fetch the object. */
COLLATOR_METHOD_FETCH_OBJECT;

if (!co || !co->ucoll) {
intl_error_set_code( nullptr, COLLATOR_ERROR_CODE( co ) );
intl_errors_set_custom_msg( COLLATOR_ERROR_P( co ), "Object not initialized");
zend_throw_error(nullptr, "Object not initialized");

if (collator_check_initialized(co) == FAILURE) {
RETURN_THROWS();
}

Expand Down
12 changes: 2 additions & 10 deletions ext/intl/collator/collator_sort.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -433,11 +433,7 @@ U_CFUNC PHP_FUNCTION( collator_sort_with_sort_keys )
/* Fetch the object. */
COLLATOR_METHOD_FETCH_OBJECT;

if (!co || !co->ucoll) {
intl_error_set_code( nullptr, COLLATOR_ERROR_CODE( co ) );
intl_errors_set_custom_msg( COLLATOR_ERROR_P( co ), "Object not initialized");
zend_throw_error(NULL, "Object not initialized");

if (collator_check_initialized(co) == FAILURE) {
RETURN_THROWS();
}

Expand Down Expand Up @@ -598,11 +594,7 @@ U_CFUNC PHP_FUNCTION( collator_get_sort_key )
/* Fetch the object. */
COLLATOR_METHOD_FETCH_OBJECT;

if (!co || !co->ucoll) {
intl_error_set_code( nullptr, COLLATOR_ERROR_CODE( co ) );
intl_errors_set_custom_msg( COLLATOR_ERROR_P( co ), "Object not initialized");
zend_throw_error(NULL, "Object not initialized");

if (collator_check_initialized(co) == FAILURE) {
RETURN_THROWS();
}

Expand Down
55 changes: 55 additions & 0 deletions ext/intl/tests/collator_attribute_unconstructed.phpt
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
--TEST--
Collator attribute and strength methods on unconstructed object
--EXTENSIONS--
intl
--FILE--
<?php

class Collator2 extends Collator {
public function __construct() {
// omitting parent::__construct($someLocale);
}
}

$c = new Collator2();

$methods = [
'getAttribute' => fn() => $c->getAttribute(Collator::NUMERIC_COLLATION),
'setAttribute' => fn() => $c->setAttribute(Collator::NUMERIC_COLLATION, Collator::ON),
'getStrength' => fn() => $c->getStrength(),
'setStrength' => fn() => $c->setStrength(Collator::SECONDARY),
];

foreach ($methods as $method => $call) {
try {
$call();
} catch (Error $e) {
echo $method, ': ', $e::class, ': ', $e->getMessage(), PHP_EOL;
}
}

$functions = [
'collator_get_attribute' => fn() => collator_get_attribute($c, Collator::NUMERIC_COLLATION),
'collator_set_attribute' => fn() => collator_set_attribute($c, Collator::NUMERIC_COLLATION, Collator::ON),
'collator_get_strength' => fn() => collator_get_strength($c),
'collator_set_strength' => fn() => collator_set_strength($c, Collator::SECONDARY),
];

foreach ($functions as $function => $call) {
try {
$call();
} catch (Error $e) {
echo $function, ': ', $e::class, ': ', $e->getMessage(), PHP_EOL;
}
}

?>
--EXPECT--
getAttribute: Error: Object not initialized
setAttribute: Error: Object not initialized
getStrength: Error: Object not initialized
setStrength: Error: Object not initialized
collator_get_attribute: Error: Object not initialized
collator_set_attribute: Error: Object not initialized
collator_get_strength: Error: Object not initialized
collator_set_strength: Error: Object not initialized
Loading