Commit 79572496206 for php

commit 795724962068de73e0ac78f3725188208ed8ee0b
Merge: 6bd5ab82aab 92e2fd60929
Author: Ilia Alshanetsky <ilia@ilia.ws>
Date:   Tue Sep 29 16:09:31 2026 -0400

    Merge branch 'PHP-8.5' into PHP-8.6

    * PHP-8.5:
      ext/tidy: Reject tidyNode use after the document is reparsed

diff --cc NEWS
index f36b4a6aecf,6fe75ef13e9..2bc21110f91
--- a/NEWS
+++ b/NEWS
@@@ -7,96 -7,18 +7,100 @@@ PH
      and comparing less than zero. (Ilia Alshanetsky)

  - Core:
 -  . Fixed bug GH-23644 (Optimizer leaves a constant-vs-constant comparison
 -    unfolded, crashing the VM in zval_undefined_cv). (ndossche)
 -  . Fixed OSS-Fuzz 532353396 (assertion failure with static type). (Girgias)
 -  . Fix GH-23662 (Avoid NAN warning in print_r()). (CodedByManish)
 -  . Fix GH-21999: GC inconsistency with lazy object, var_dump(), and object
 -    comparison. (Arnaud)
    . Fixed OSS-Fuzz #536440507 (Immutable class incorrect assertion).
      (ndossche)
 +  . Fixed bug GH-23628 (Tracing JIT reads undefined property slots of lazy
 +    proxy objects instead of forwarding to the real instance). (lisachenko)
 +  . Fixed bug GH-23882 (array_map() optimization is incorrect for
 +    strict_types=1). (timwolla)
 +  . Fixed OSS-Fuzz #565486253 (coerced arg with '...' on non-variadic
 +    function). (ndossche)
    . Fixed AVX being reported as supported when the OS has not enabled AVX
      state. (Ilia Alshanetsky)
 +  . Fixed OSS-Fuzz #552682112 (assertion failure wrt
 +    zp_arg_must_be_sent_by_ref()). (ndossche)
 +  . Fixed GH-23921 (Fibers start with error_reporting = 0 when the
 +    error_reporting INI directive is not set). (Girgias)
    . Fixed GH-23980 (ZEND_ASSERT violation @ ZEND_INCLUDE_OR_EVAL). (ndossche)

 +- FFI:
 +  . Fixed crashes with FFI callbacks created from __call() trampolines
 +    and array callables whose object is released. (Ilia Alshanetsky)
 +
 +- MySQLnd:
 +  . Fixed field_count not resetting on OK packet. (Kamil Tekiela)
 +  . Fixed memory leak when closing a prepared statement after its connection
 +    was killed. (Kamil Tekiela)
 +
 +- Opcache:
 +  . Fix zend_analyze_calls() call_stack buffer overrun. (Mrmaxmeier)
 +  . Fixed bug GH-23679 (Tracing JIT writes a parent private property into a
 +    child's shadowing public property). (Ilia Alshanetsky)
 +  . Fix multiple incorrect DCE due to unsound escape analysis. (ndossche,
 +    arnaud-lb)
 +
 +- OpenSSL:
 +  . Fixed stream_socket_enable_crypto() leaving the socket non-blocking
 +    after a handshake timeout. (Ilia Alshanetsky)
 +  . Fix memory leak by doing early salt validation. (adapik)
 +
 +- PCNTL:
 +  . Fixed pcntl_signal_dispatch() dropping the queued signals when it runs while
 +    an exception is pending. (nicolas-grekas)
 +  . Fixed pcntl_signal_dispatch() dropping the signals queued behind a handler
 +    that throws. (nicolas-grekas)
 +  . Fixed bug GH-23986 (/proc/self paths resolve to the parent process after
 +    pcntl_fork()). (Lazizbek Ergashev)
 +
 +- PDO:
 +  . Fixed PDO::setAttribute() installing a PDO::ATTR_STATEMENT_CLASS class
 +    whose constructor arguments it rejects. (Ilia Alshanetsky)
 +  . Fixed PDO::ATTR_STATEMENT_CLASS constructor_args type errors reporting
 +    "array given" regardless of the value passed. (Ilia Alshanetsky)
 +  . Fixed PDOStatement::bindParam() and bindColumn() leaking the driver
 +    options value. (Ilia Alshanetsky)
 +
 +- PDO_DBLIB:
 +  . Fixed bug GH-23741 (segfault after a failed query inside a PDO
 +    transaction). Errors raised by beginTransaction(), commit(), rollBack()
 +    and lastInsertId() are now reported instead of being dropped.
 +    (Ilia Alshanetsky)
 +
 +- PDO_PGSQL:
 +  . Fixed crash when a persistent connection fails. (KentarouTakeda)
 +
 +- Reflection:
 +  . Fixed bug GH-23842 (ReflectionProperty::skipLazyInitialization() copies
 +    invalid constant defaults with OPcache). (DirkTrunkstar, Lazizbek Ergashev)
 +
 +- SimpleXML:
 +  . Fixed reconstructing a SimpleXMLElement freeing a child element that
 +    another variable still references. (Ilia Alshanetsky)
 +
++- Tidy:
++  . Fixed a use-after-free when a tidyNode is used after its document is
++    reparsed. (Ilia Alshanetsky)
++
 +- Zip:
 +  . Fixed bug GH-23899 (Assertion failure when a cancel callback returns an
 +    invalid type during shutdown). (Weilin Du)
 +
 +24 Sep 2026, PHP 8.6.0RC2
 +
 +- Core:
 +  . Fixed incorrect internal pointer and foreach iterator positions when
 +    compacting arrays with holes. (Weilin Du)
 +  . Fix handling of references to typed properties during unserialization
 +    of various internal classes. (ndossche, timwolla)
 +  . Fixed OSS-Fuzz 532353396 (assertion	failure	with static type). (Girgias)
 +  . Fix GH-23662 (Avoid NAN warning in print_r()). (CodedByManish)
 +  . Fixed bug GH-23752 (Use scoped diagnostic suppression for the global
 +    register declarations so the caller's -Wvolatile-register-var state is
 +    restored). (yqtian-se)
 +  . Fixed OSS-Fuzz #538730793 (Assertion failure when returning by-ref from
 +    closure invoke). (ndossche)
 +  . Fixed OSS-Fuzz #540904105 (ASSERT: ast->attr == T_CLASS_C). (ndossche)
 +
  - CLI
    . Fix GH-22567 (Windows ZTS CLI SAPI should refresh its TSRMLS cache during
      request activation). (matyhtf)
diff --cc ext/tidy/tests/reparse_node.phpt
index 00000000000,7ba20b3939c..2ee03d8344e
mode 000000,100644..100644
--- a/ext/tidy/tests/reparse_node.phpt
+++ b/ext/tidy/tests/reparse_node.phpt
@@@ -1,0 -1,66 +1,57 @@@
+ --TEST--
+ tidyNode objects are invalid after reparsing their document
+ --EXTENSIONS--
+ tidy
+ --FILE--
+ <?php
+
 -$node = unserialize('O:8:"tidyNode":0:{}');
 -try {
 -	$node->hasChildren();
 -	echo "unowned node: no error\n";
 -} catch (Error $e) {
 -	echo 'unowned node: ', $e::class, ': ', $e->getMessage(), "\n";
 -}
 -
+ $tidy = tidy_parse_string('<html><body><p>one</p><p>two</p></body></html>');
+ $node = $tidy->body()->child[0];
+ var_dump($node->isHtml());
+ var_dump($node->hasSiblings());
+
+ $tidy->parseString('<html><body><p>three</p></body></html>');
+
+ $operations = [
+     'string cast' => static fn() => (string) $node,
+     'hasChildren' => static fn() => $node->hasChildren(),
+     'hasSiblings' => static fn() => $node->hasSiblings(),
+     'isComment' => static fn() => $node->isComment(),
+     'isHtml' => static fn() => $node->isHtml(),
+     'isText' => static fn() => $node->isText(),
+     'isJste' => static fn() => $node->isJste(),
+     'isAsp' => static fn() => $node->isAsp(),
+     'isPhp' => static fn() => $node->isPhp(),
+     'getParent' => static fn() => $node->getParent(),
+     'getPreviousSibling' => static fn() => $node->getPreviousSibling(),
+     'getNextSibling' => static fn() => $node->getNextSibling(),
+ ];
+
+ foreach ($operations as $operation => $callback) {
+     try {
+         $callback();
+         echo $operation, ": no error\n";
+     } catch (Error $e) {
+         echo $operation, ': ', $e::class, ': ', $e->getMessage(), "\n";
+     }
+ }
+
+ var_dump($tidy->body()->child[0]->isHtml());
+
+ ?>
+ --EXPECT--
 -unowned node: Error: tidyNode object is not initialized
+ bool(true)
+ bool(true)
+ string cast: Error: tidyNode object is no longer valid after its document was reparsed
+ hasChildren: Error: tidyNode object is no longer valid after its document was reparsed
+ hasSiblings: Error: tidyNode object is no longer valid after its document was reparsed
+ isComment: Error: tidyNode object is no longer valid after its document was reparsed
+ isHtml: Error: tidyNode object is no longer valid after its document was reparsed
+ isText: Error: tidyNode object is no longer valid after its document was reparsed
+ isJste: Error: tidyNode object is no longer valid after its document was reparsed
+ isAsp: Error: tidyNode object is no longer valid after its document was reparsed
+ isPhp: Error: tidyNode object is no longer valid after its document was reparsed
+ getParent: Error: tidyNode object is no longer valid after its document was reparsed
+ getPreviousSibling: Error: tidyNode object is no longer valid after its document was reparsed
+ getNextSibling: Error: tidyNode object is no longer valid after its document was reparsed
+ bool(true)