Skip to content

[pull] master from php:master - #1302

Merged
pull[bot] merged 14 commits into
turkdevops:masterfrom
php:master
Sep 24, 2026
Merged

pull[bot] merged 14 commits into
turkdevops:masterfrom
php:master

Conversation

@pull

@pull pull Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

henderkes and others added 14 commits September 24, 2026 15:33
For immutable classes, the flag for updated constants lives on the
mutable part (see zend_update_class_constants).
That means the assertion is bogus and can be replaced with a more
complex check via a helper function.
For the case where we perform the flags check, but not as an assertion
but as a proper check, deferring to zend_update_class_constants() is
enough because it already checks the flags correctly itself.

Closes GH-23781.
* PHP-8.4:
  Fix OSS-Fuzz #536440507: Immutable class incorrect assertion
* PHP-8.5:
  Fix OSS-Fuzz #536440507: Immutable class incorrect assertion
* PHP-8.6:
  Fix OSS-Fuzz #536440507: Immutable class incorrect assertion
  fix aarch64 gcc preserve_none detection (#23883)
…ies and unset properties (#23640)

A lazy proxy keeps its own property slots IS_UNDEF|IS_PROP_LAZY even after
it has been initialized, and the object handlers forward every property
access to the real instance. The tracing JIT was not aware of this in two
places:

1. When the recorded trace contained a FETCH_OBJ_R/IS/W on a known property
   whose slot was IS_UNDEF, the known-offset fast path was still compiled.
   For a lazy proxy this path never succeeds, and it deoptimized on every
   execution. Use the generic code path (that falls back to the object
   handlers for undefined slots) when the slot was IS_UNDEF at recording
   time. This also covers uninitialized and unset properties.

2. During deoptimization of a failed result type guard after FETCH_OBJ_IS,
   an IS_UNDEF slot was turned into NULL, assuming an undefined property.
   For a slot flagged IS_PROP_LAZY the fetch has to be forwarded to the
   real instance instead, so re-execute the opline in the VM, the same way
   it is already done for FETCH_OBJ_R.
* PHP-8.5:
  Fix GH-23628: Tracing JIT reads undefined property slots of lazy proxies and unset properties (#23640)
* PHP-8.6:
  Fix GH-23628: Tracing JIT reads undefined property slots of lazy proxies and unset properties (#23640)
* PHP-8.5:
  [ci skip] Fix test failure
* PHP-8.6:
  [ci skip] Fix test failure
The output hash was sized for the replacement only, so copying the kept
input elements grew it by doubling. Size it for the final element count.
@pull pull Bot locked and limited conversation to collaborators Sep 24, 2026
@pull pull Bot added the ⤵️ pull label Sep 24, 2026
@pull
pull Bot merged commit a8caefc into turkdevops:master Sep 24, 2026
0 of 2 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants