Commit be420663e32 for php

commit be420663e32d90d319d21d18de50a02dac1b04ad
Merge: fd19f41128d 89b1f7199e8
Author: ndossche <7771979+ndossche@users.noreply.github.com>
Date:   Thu Oct 8 18:49:31 2026 +0200

    Merge branch 'PHP-8.5' into PHP-8.6

    * PHP-8.5:
      Fix OSS-Fuzz #568005340: FETCH_DIM_FUNC_ARG partial conversion
      Fix too wide type inference for ASSIGN_DIM_OP
      Fix type inference of ADD_ARRAY_UNPACK with integer keys

diff --cc NEWS
index f58b84c88fd,734c2577921..cce4f4a0ee4
--- a/NEWS
+++ b/NEWS
@@@ -10,15 -10,10 +10,18 @@@ PH
    . Fixed bug GH-17626 (JIT corrupts an opline handler when blacklisting a
      root trace at the opcache.jit_max_root_traces limit, causing spurious
      "Too few arguments" errors and crashes). (RV7PR)
+   . Fix type inference of ADD_ARRAY_UNPACK with integer keys. (ndossche)
+   . Fix too wide type inference for ASSIGN_DIM_OP. (ndossche)
+   . Fix OSS-Fuzz #568005340 (FETCH_DIM_FUNC_ARG partial conversion). (ndossche)

 +- Phar:
 +  . Fixed GH-24166 (Double-free in Phar::webPhar() in CGI without PATH_INFO).
 +    (RigelYoung, Jakub Zelenka)
 +
 +- Standard:
 +  . Fixed chown() and lchown() failing to resolve user names in ZTS builds
 +    when getpwnam_r() needs a larger buffer. (Ilia Alshanetsky)
 +
  - Zip:
    . Fixed use-after-free when re-entering ZipArchive during destruction or
      a close warning, and rejected opening streams while closing. (jvoisin)
diff --cc Zend/Optimizer/optimize_func_calls.c
index 0e6c5797c68,72997615af6..4275bdb4071
--- a/Zend/Optimizer/optimize_func_calls.c
+++ b/Zend/Optimizer/optimize_func_calls.c
@@@ -267,7 -267,9 +268,9 @@@ void zend_optimize_func_calls(zend_op_a
  								&& opline->op2_type == IS_UNUSED) {
  							/* FETCH_DIM_FUNC_ARG supports UNUSED op2, while FETCH_DIM_R does not.
  							 * Performing the replacement would create an invalid opcode. */
 -							call_stack[call - 1].try_inline = 0;
 +							call_stack[call - 1].try_inline = false;
+ 							/* Don't remove the associated CHECK_FUNC_ARG opcode. */
+ 							call_stack[call - 1].last_check_func_arg_opline = NULL;
  							break;
  						}