Skip to content

Add PHP 8.3.32, 8.4.23, and 8.5.8 configurations with extension suppo… - #77

Merged
jwaisner merged 2 commits into
mainfrom
cve
Jul 10, 2026
Merged

jwaisner merged 2 commits into
mainfrom
cve

Conversation

@N6REJ

@N6REJ N6REJ commented Jul 8, 2026

Copy link
Copy Markdown
Collaborator

php 8.3.32, 8.4.23, and 8.5.8 CVE fix

@github-actions

github-actions Bot commented Jul 8, 2026 •

Copy link
Copy Markdown
Contributor

🐘 PHP Module Tests - Results

Test Date: 2026-07-10 00:45:40 UTC
Status: ✅ All tests passed

📊 Test Results by Version

PHP 8.3.32

win10-amd
win10-intel
win11-amd
win11-intel

PHP 8.4.23

win10-amd
win10-intel
win11-amd
win11-intel

PHP 8.5.8

win10-amd
win10-intel
win11-amd
win11-intel

Results: 12 of 12 tests completed

All tests passed successfully! ✨


📋 Test Phases

Each version is tested through the following phases:

  • Phase 1: Basic PHP Validation (Download, Extract, Verify Executable)
  • Phase 2: Extension Validation (Download, Architecture Check, Loading Test)
  • Phase 3: Dependency Validation (Download Dependencies, Test with Dependencies)
  • Phase 4: Functional Testing (Test Extension Functionality)

Check artifacts for detailed logs.

@qodo-code-review

qodo-code-review Bot commented Jul 8, 2026 •

Copy link
Copy Markdown

PR Summary by Qodo

Add PHP 8.3.32/8.4.23/8.5.8 bundle configs and bump release to 2026.7.7

🐞 Bug fix ⚙️ Configuration changes 🕐 20-40 Minutes

Grey Divider

AI Description

• Add new PHP 8.3.32, 8.4.23, and 8.5.8 bundle configuration directories for CVE-fixed builds.
• Wire extension/dependency download URLs (imagick, memcache, xdebug, ImageMagick) for the new
 bundles.
• Bump bundle release version to 2026.7.7.
Diagram

graph TD
  BP["build.properties"] --> CFG["New PHP configs"] --> MODS["exts/deps props"] --> GH{{"GitHub assets"}}
  CFG --> INI["php.ini"]
  CFG --> BAM["bearsampp.conf"]
  CFG --> PEAR["pear.properties"]
  CFG --> ARC["archived configs"]
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Generate per-version configs from templates
  • ➕ Avoids committing large duplicated php.ini files per patch version
  • ➕ Makes version bumps mostly data-only (version + URLs)
  • ➕ Reduces drift risk across supported PHP versions
  • ➖ Requires adding/maintaining a generation step in the release pipeline
  • ➖ Harder to hand-edit one version without regenerating outputs
2. Common base php.ini + per-version override snippets
  • ➕ Keeps shared defaults consistent across versions
  • ➕ Smaller diffs and faster reviews when updating patch versions
  • ➖ Requires packaging/runtime layering logic
  • ➖ May be tricky if directives differ significantly between minors/TS builds

Recommendation: For a self-contained binary bundle repo, committing full per-version directories is acceptable and keeps consumption simple. If these CVE/version rollovers happen frequently, templating or base+override php.ini would materially reduce repo bloat and review noise while keeping behavior consistent.

Files changed (37) +5856 / -1

Documentation (3) +6 / -0
README.txtAdd deps folder README for PHP 8.3.32 +2/-0

Add deps folder README for PHP 8.3.32

• Documents where to place PECL dependency binaries and notes that the deps directory is injected into PATH.

bin/php8.3.32/deps/README.txt

README.txtAdd deps folder README for PHP 8.4.23 +2/-0

Add deps folder README for PHP 8.4.23

• Documents where to place PECL dependency binaries and notes that the deps directory is injected into PATH.

bin/php8.4.23/deps/README.txt

README.txtAdd deps folder README for PHP 8.5.8 +2/-0

Add deps folder README for PHP 8.5.8

• Documents where to place PECL dependency binaries and notes that the deps directory is injected into PATH.

bin/php8.5.8/deps/README.txt

Other (34) +5850 / -1
bearsampp.confRetain PHP 8.3.31 Bearsampp metadata under archived +0/-0

Retain PHP 8.3.31 Bearsampp metadata under archived

• Adds/relocates the PHP 8.3.31 Bearsampp configuration into the archived directory as part of the version rollover (no content changes shown in diff).

bin/archived/php8.3.31/bearsampp.conf

deps.propertiesRetain PHP 8.3.31 dependency properties under archived +0/-0

Retain PHP 8.3.31 dependency properties under archived

• Adds/relocates the PHP 8.3.31 dependency mapping into the archived directory (no content changes shown in diff).

bin/archived/php8.3.31/deps.properties

README.txtRetain PHP 8.3.31 deps README under archived +0/-0

Retain PHP 8.3.31 deps README under archived

• Adds/relocates the dependency placement README into the archived directory (no content changes shown in diff).

bin/archived/php8.3.31/deps/README.txt

exts.propertiesRetain PHP 8.3.31 extension URL mappings under archived +0/-0

Retain PHP 8.3.31 extension URL mappings under archived

• Adds/relocates the PHP 8.3.31 extension download mappings into the archived directory (no content changes shown in diff).

bin/archived/php8.3.31/exts.properties

pear.propertiesRetain PHP 8.3.31 PEAR mapping under archived +0/-0

Retain PHP 8.3.31 PEAR mapping under archived

• Adds/relocates the PHP 8.3.31 PEAR artifact mapping into the archived directory (no content changes shown in diff).

bin/archived/php8.3.31/pear.properties

php.iniRetain PHP 8.3.31 php.ini under archived +0/-0

Retain PHP 8.3.31 php.ini under archived

• Adds/relocates the PHP 8.3.31 php.ini into the archived directory for prior-version retention (no content changes shown in diff).

bin/archived/php8.3.31/php.ini

bearsampp.confRetain PHP 8.4.22 Bearsampp metadata under archived +0/-0

Retain PHP 8.4.22 Bearsampp metadata under archived

• Adds/relocates the PHP 8.4.22 Bearsampp configuration into the archived directory as part of the version rollover (no content changes shown in diff).

bin/archived/php8.4.22/bearsampp.conf

deps.propertiesRetain PHP 8.4.22 dependency properties under archived +0/-0

Retain PHP 8.4.22 dependency properties under archived

• Adds/relocates the PHP 8.4.22 dependency mapping into the archived directory (no content changes shown in diff).

bin/archived/php8.4.22/deps.properties

README.txtRetain PHP 8.4.22 deps README under archived +0/-0

Retain PHP 8.4.22 deps README under archived

• Adds/relocates the dependency placement README into the archived directory (no content changes shown in diff).

bin/archived/php8.4.22/deps/README.txt

exts.propertiesRetain PHP 8.4.22 extension URL mappings under archived +0/-0

Retain PHP 8.4.22 extension URL mappings under archived

• Adds/relocates the PHP 8.4.22 extension download mappings into the archived directory (no content changes shown in diff).

bin/archived/php8.4.22/exts.properties

pear.propertiesRetain PHP 8.4.22 PEAR mapping under archived +0/-0

Retain PHP 8.4.22 PEAR mapping under archived

• Adds/relocates the PHP 8.4.22 PEAR artifact mapping into the archived directory (no content changes shown in diff).

bin/archived/php8.4.22/pear.properties

php.iniRetain PHP 8.4.22 php.ini under archived +0/-0

Retain PHP 8.4.22 php.ini under archived

• Adds/relocates the PHP 8.4.22 php.ini into the archived directory for prior-version retention (no content changes shown in diff).

bin/archived/php8.4.22/php.ini

bearsampp.confRetain PHP 8.5.7 Bearsampp metadata under archived +0/-0

Retain PHP 8.5.7 Bearsampp metadata under archived

• Adds/relocates the PHP 8.5.7 Bearsampp configuration into the archived directory as part of the version rollover (no content changes shown in diff).

bin/archived/php8.5.7/bearsampp.conf

deps.propertiesRetain PHP 8.5.7 dependency properties under archived +0/-0

Retain PHP 8.5.7 dependency properties under archived

• Adds/relocates the PHP 8.5.7 dependency mapping into the archived directory (no content changes shown in diff).

bin/archived/php8.5.7/deps.properties

README.txtRetain PHP 8.5.7 deps README under archived +0/-0

Retain PHP 8.5.7 deps README under archived

• Adds/relocates the dependency placement README into the archived directory (no content changes shown in diff).

bin/archived/php8.5.7/deps/README.txt

exts.propertiesRetain PHP 8.5.7 extension URL mappings under archived +0/-0

Retain PHP 8.5.7 extension URL mappings under archived

• Adds/relocates the PHP 8.5.7 extension download mappings into the archived directory (no content changes shown in diff).

bin/archived/php8.5.7/exts.properties

pear.propertiesRetain PHP 8.5.7 PEAR mapping under archived +0/-0

Retain PHP 8.5.7 PEAR mapping under archived

• Adds/relocates the PHP 8.5.7 PEAR artifact mapping into the archived directory (no content changes shown in diff).

bin/archived/php8.5.7/pear.properties

php.iniRetain PHP 8.5.7 php.ini under archived +0/-0

Retain PHP 8.5.7 php.ini under archived

• Adds/relocates the PHP 8.5.7 php.ini into the archived directory for prior-version retention (no content changes shown in diff).

bin/archived/php8.5.7/php.ini

bearsampp.confAdd Bearsampp config for PHP 8.3.32 +9/-0

Add Bearsampp config for PHP 8.3.32

• Introduces bundle metadata for PHP 8.3.32, including CLI executable names, php.ini reference, Apache 2.4 module, and bundle release placeholder.

bin/php8.3.32/bearsampp.conf

deps.propertiesAdd ImageMagick dependency URL for PHP 8.3.32 +1/-0

Add ImageMagick dependency URL for PHP 8.3.32

• Defines the ImageMagick dependency artifact URL used by the PHP 8.3.32 bundle.

bin/php8.3.32/deps.properties

exts.propertiesAdd extension download URLs for PHP 8.3.32 +4/-0

Add extension download URLs for PHP 8.3.32

• Adds extension artifact URLs for imagick, memcache, and xdebug for PHP 8.3.32, plus a zip module URL entry.

bin/php8.3.32/exts.properties

pear.propertiesAdd PEAR artifact URL for PHP 8.3.32 +1/-0

Add PEAR artifact URL for PHP 8.3.32

• Adds the PEAR distribution URL used by the PHP 8.3.32 bundle.

bin/php8.3.32/pear.properties

php.iniAdd default php.ini for PHP 8.3.32 +1959/-0

Add default php.ini for PHP 8.3.32

• Adds the full default php.ini shipped with the PHP 8.3.32 bundle.

bin/php8.3.32/php.ini

bearsampp.confAdd Bearsampp config for PHP 8.4.23 +9/-0

Add Bearsampp config for PHP 8.4.23

• Introduces bundle metadata for PHP 8.4.23, including CLI executable names, php.ini reference, Apache 2.4 module, and bundle release placeholder.

bin/php8.4.23/bearsampp.conf

deps.propertiesAdd ImageMagick dependency URL for PHP 8.4.23 +1/-0

Add ImageMagick dependency URL for PHP 8.4.23

• Defines the ImageMagick dependency artifact URL used by the PHP 8.4.23 bundle.

bin/php8.4.23/deps.properties

exts.propertiesAdd extension download URLs for PHP 8.4.23 +4/-0

Add extension download URLs for PHP 8.4.23

• Adds extension artifact URLs for imagick, memcache, and xdebug for PHP 8.4.23, plus a zip module URL entry.

bin/php8.4.23/exts.properties

pear.propertiesAdd PEAR artifact URL for PHP 8.4.23 +1/-0

Add PEAR artifact URL for PHP 8.4.23

• Adds the PEAR distribution URL used by the PHP 8.4.23 bundle.

bin/php8.4.23/pear.properties

php.iniAdd default php.ini for PHP 8.4.23 +1925/-0

Add default php.ini for PHP 8.4.23

• Adds the full default php.ini shipped with the PHP 8.4.23 bundle.

bin/php8.4.23/php.ini

bearsampp.confAdd Bearsampp config for PHP 8.5.8 +9/-0

Add Bearsampp config for PHP 8.5.8

• Introduces bundle metadata for PHP 8.5.8, including CLI executable names, php.ini reference, Apache 2.4 module, and bundle release placeholder.

bin/php8.5.8/bearsampp.conf

deps.propertiesAdd ImageMagick dependency URL for PHP 8.5.8 +1/-0

Add ImageMagick dependency URL for PHP 8.5.8

• Defines the ImageMagick dependency artifact URL used by the PHP 8.5.8 bundle.

bin/php8.5.8/deps.properties

exts.propertiesAdd extension download URLs for PHP 8.5.8 +4/-0

Add extension download URLs for PHP 8.5.8

• Adds extension artifact URLs for imagick, memcache, and xdebug for PHP 8.5.8, plus a zip module URL entry.

bin/php8.5.8/exts.properties

pear.propertiesAdd PEAR artifact URL for PHP 8.5.8 +1/-0

Add PEAR artifact URL for PHP 8.5.8

• Adds the PEAR distribution URL used by the PHP 8.5.8 bundle.

bin/php8.5.8/pear.properties

php.iniAdd default php.ini for PHP 8.5.8 +1920/-0

Add default php.ini for PHP 8.5.8

• Adds the full default php.ini shipped with the PHP 8.5.8 bundle.

bin/php8.5.8/php.ini

build.propertiesBump bundle release version to 2026.7.7 +1/-1

Bump bundle release version to 2026.7.7

• Updates the bundle release identifier from 2026.6.2 to 2026.7.7 for the new PHP bundle set.

build.properties

@qodo-code-review

qodo-code-review Bot commented Jul 8, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0) 🎨 UX issues (0) 🔗 Cross-repo conflicts (0) 📜 Skill insights (0)

Grey Divider


Action required

1. Imagick/ImageMagick tag mismatch ✓ Resolved 🐞 Bug ≡ Correctness
Description
The new PHP 8.3.32/8.4.23/8.5.8 configs download ImageMagick from php-2026.7.7 but keep the
imagick extension on php-2026.6.2, so the build can combine/overwrite different ImageMagick DLL
sets into the same imagick/ directory. Because the build processes extensions before dependencies,
this mismatch can produce an inconsistent runtime DLL set and cause imagick load/runtime failures.
Code

bin/php8.3.32/exts.properties[1]

+imagick=https://github.com/Bearsampp/modules-untouched/releases/download/php-2026.6.2/php_imagick-3.8.1-8.3-ts-vs16-x64.zip
Evidence
In the new version folders, deps.properties uses php-2026.7.7 ImageMagick while
exts.properties uses php-2026.6.2 imagick. The build pipeline copies imagick’s CORE_*.dll into
phpPrepPath/imagick/ and then later copies ImageMagick *.dll into that same directory, so mixing
different release tags can produce an inconsistent DLL set. Archived versions keep both imagick and
ImageMagick on the same release tag, and the README describes the intended flow as keeping
dependency URLs synchronized with the latest modules-untouched release.

bin/php8.3.32/exts.properties[1-4]
bin/php8.3.32/deps.properties[1-1]
bin/php8.4.23/exts.properties[1-4]
bin/php8.4.23/deps.properties[1-1]
bin/php8.5.8/exts.properties[1-4]
bin/php8.5.8/deps.properties[1-1]
build.gradle[1268-1295]
build.gradle[1727-1736]
build.gradle[1934-1963]
bin/archived/php8.3.31/exts.properties[1-4]
bin/archived/php8.3.31/deps.properties[1-1]
README.md[52-99]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The new PHP version configs mix modules-untouched release tags: `deps.properties` points ImageMagick at `php-2026.7.7` while `exts.properties` still points `imagick` at `php-2026.6.2`. The build copies files from both sources into the same `imagick/` folder, which can yield an inconsistent set of DLLs in the final bundle.

## Issue Context
- `processExtensions()` copies `CORE_*.dll` from the imagick extension archive into `phpPrepPath/imagick/`.
- `processDependencies()` later copies `*.dll` from the ImageMagick dependency archive into the same `phpPrepPath/imagick/`.
- With mismatched sources, the dependency step may overwrite (or partially overlap with) DLLs placed by the extension step.

## Fix
Pick one of these approaches and apply consistently for **8.3.32, 8.4.23, and 8.5.8**:
1) Update `exts.properties` imagick URL(s) to the corresponding imagick package from `php-2026.7.7` that matches ImageMagick 7.1.2-27.
2) Or revert `deps.properties` ImageMagick URL(s) back to the matching ImageMagick version/release tag used by the imagick packages (e.g., `php-2026.6.2` / 7.1.2-24).
3) (Optional hardening) Adjust the build copy rules so the dependency injection does not overwrite imagick-bundled `CORE_*.dll` (or vice versa), to prevent accidental mixing.

## Fix Focus Areas
- bin/php8.3.32/exts.properties[1-4]
- bin/php8.3.32/deps.properties[1-1]
- bin/php8.4.23/exts.properties[1-4]
- bin/php8.4.23/deps.properties[1-1]
- bin/php8.5.8/exts.properties[1-4]
- bin/php8.5.8/deps.properties[1-1]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Qodo Logo

Comment thread bin/php8.3.32/exts.properties Outdated
… modules across supported PHP versions
@qodo-code-review

Copy link
Copy Markdown

Code review by qodo was updated up to the latest commit 859dabd

@jwaisner
jwaisner merged commit be0bf70 into main Jul 10, 2026
16 checks passed
@jwaisner
jwaisner deleted the cve branch July 10, 2026 00:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants