Commit 33d7f34694f for php

commit 33d7f34694f942dd6a6696450fc45fb114a0a0fb
Merge: fbed672173f 630406c8956
Author: ndossche <7771979+ndossche@users.noreply.github.com>
Date:   Thu Oct 8 20:40:48 2026 +0200

    Merge branch 'PHP-8.4' into PHP-8.5

    * PHP-8.4:
      zend_alloc: move a small block shrunk to the size of the bin below

diff --cc NEWS
index 56d20ae2212,f2c2a126aa6..19f11fd33db
--- a/NEWS
+++ b/NEWS
@@@ -7,8 -7,17 +7,11 @@@ PH
      in its previous chain. (Edmond)
    . Fixed bug GH-23979 (Nullsafe operator must not flush delayed oplines of an
      enclosing function). (ndossche)
+   . Fixed memory manager keeping a block reallocated to exactly the size of
+     the next smaller bin in its larger bin, which efree_size() then freed
+     into the wrong one. (Marc Bennewitz)

 -- DOM:
 -  . Fixed bug GH-23352 (UAF reading an attribute value node retained across
 -    DOMDocument::adoptNode()). (David Carlier)
 -
  - Opcache:
 -  . Fixed bug GH-20890 (Segfault in zval_undefined_cv with non-simple property
 -    hook with minimal tracing JIT). (ndossche)
    . Fixed bug GH-17626 (JIT corrupts an opline handler when blacklisting a
      root trace at the opcache.jit_max_root_traces limit, causing spurious
      "Too few arguments" errors and crashes). (RV7PR)
diff --cc ext/zend_test/test.stub.php
index eb4a6fac879,c595677fc4a..1e693707e3f
--- a/ext/zend_test/test.stub.php
+++ b/ext/zend_test/test.stub.php
@@@ -262,8 -246,8 +262,10 @@@ namespace

      function zend_leak_bytes(int $bytes = 3): void {}

 +    function zend_delref(mixed $variable): void {}
 +
+     function zend_test_erealloc_block_size(int $old_size, int $new_size): array {}
+
      function zend_string_or_object(object|string $param): object|string {}

      function zend_string_or_object_or_null(object|string|null $param): object|string|null {}
diff --cc ext/zend_test/test_arginfo.h
index d605cff30ef,93792ac7c66..f4bd4c9ee7d
Binary files differ