Skip to content

Add PHP SECURITY FIXS & 8.6.0RC2 with configuration files, extension support, and dependency management - #83

Merged
jwaisner merged 13 commits into
mainfrom
rc2
Sep 25, 2026
Merged

jwaisner merged 13 commits into
mainfrom
rc2

Conversation

@N6REJ

@N6REJ N6REJ commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator

No description provided.

@N6REJ
N6REJ requested a review from jwaisner September 24, 2026 11:33
@N6REJ N6REJ added enhancement ✨ Improve program Security 🔐 Security issue labels Sep 24, 2026
@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Add PHP 8.3.35 and PHP 8.6.0 RC2 bundle definitions

✨ Enhancement ⚙️ Configuration changes 📝 Documentation 🕐 20-40 Minutes

Grey Divider

AI Description

• Adds complete Bearsampp bundle definitions for PHP 8.3.35 and 8.6.0 RC2.
• Configures version-specific runtime settings, extensions, dependencies, and PEAR packages.
• Advances the bundle release date to publish the new PHP versions.
Diagram

graph TD
  BP["Build metadata"] --> PIPE["Gradle pipeline"] --> B83["PHP 8.3.35"] --> RUN["Apache and CLI"]
  ASSET["Release assets"] --> PIPE
  C83["8.3 manifests"] --> PIPE
  C86["8.6 manifests"] --> PIPE --> B86["PHP 8.6 RC2"] --> RUN
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Generate bundles from shared templates
  • ➕ Reduces duplication across the two large php.ini files
  • ➕ Centralizes common Bearsampp defaults and placeholder paths
  • ➕ Makes future PHP version additions less error-prone
  • ➖ Requires broader build-system changes
  • ➖ May obscure intentional version-specific PHP directive differences
  • ➖ Generated output still needs compatibility validation
2. Defer RC2 until extensions are available
  • ➕ Avoids publishing incomplete optional extension support
  • ➕ Reduces risk from pre-release ABI changes
  • ➖ Delays early PHP 8.6 testing
  • ➖ Prevents users from evaluating the release candidate through Bearsampp

Recommendation: Keep the version-isolated directories because they match the repository's established packaging workflow and allow stable and release-candidate settings to diverge. The disabled PHP 8.6 extension entries are appropriate until compatible builds exist; however, verify the RC2 ImageMagick dependency URL because it currently references an 8.3 imagick extension archive rather than a portable ImageMagick dependency. Shared template generation is worth considering separately to reduce long-term php.ini duplication.

Files changed (13) +3909 / -1

Enhancement (2) +18 / -0
bearsampp.confRegister PHP 8.3.35 with Bearsampp +9/-0

Register PHP 8.3.35 with Bearsampp

• Defines the PHP 8.3.35 CLI executables, configuration file, PEAR launcher, Apache 2.4 module, and release placeholder.

bin/php8.3.35/bearsampp.conf

bearsampp.confRegister PHP 8.6.0 RC2 with Bearsampp +9/-0

Register PHP 8.6.0 RC2 with Bearsampp

• Defines the RC2 CLI executables, configuration file, PEAR launcher, Apache 2.4 module, and release placeholder.

bin/php8.6.0RC2/bearsampp.conf

Documentation (2) +4 / -0
README.txtDocument PHP dependency placement +2/-0

Document PHP dependency placement

• Explains that native PECL dependencies belong in this directory and are injected into PATH.

bin/php8.3.35/deps/README.txt

README.txtDocument RC2 dependency placement +2/-0

Document RC2 dependency placement

• Explains how native PECL dependencies are staged and exposed through PATH.

bin/php8.6.0RC2/deps/README.txt

Other (9) +3887 / -1
deps.propertiesDeclare the PHP 8.3 ImageMagick dependency +1/-0

Declare the PHP 8.3 ImageMagick dependency

• Maps the PHP 8.3.35 bundle to the portable ImageMagick 7.1.2-31 archive.

bin/php8.3.35/deps.properties

exts.propertiesConfigure PHP 8.3 optional extensions +4/-0

Configure PHP 8.3 optional extensions

• Provides compatible imagick, memcache, Xdebug, and zip artifacts for the PHP 8.3 thread-safe Windows build.

bin/php8.3.35/exts.properties

pear.propertiesConfigure PEAR for PHP 8.3 +1/-0

Configure PEAR for PHP 8.3

• References the PEAR 1.10.26 package used when assembling PHP 8.3.35.

bin/php8.3.35/pear.properties

php.iniAdd the PHP 8.3.35 runtime configuration +1959/-0

Add the PHP 8.3.35 runtime configuration

• Adds Bearsampp paths, development-oriented limits, standard extension loading, OPcache settings, and active trigger-based Xdebug configuration for PHP 8.3.35.

bin/php8.3.35/php.ini

deps.propertiesDeclare the PHP 8.6 RC2 ImageMagick dependency +1/-0

Declare the PHP 8.6 RC2 ImageMagick dependency

• Adds an ImageMagick dependency mapping whose current URL points to a PHP 8.3 imagick extension archive.

bin/php8.6.0RC2/deps.properties

exts.propertiesStage disabled extension mappings for PHP 8.6 +4/-0

Stage disabled extension mappings for PHP 8.6

• Records imagick, memcache, Xdebug, and zip candidates as commented entries, preventing incompatible PHP 8.5 artifacts from being installed automatically.

bin/php8.6.0RC2/exts.properties

pear.propertiesConfigure PEAR for PHP 8.6 RC2 +1/-0

Configure PEAR for PHP 8.6 RC2

• References the PEAR 1.10.26 package from the current dependency release.

bin/php8.6.0RC2/pear.properties

php.iniAdd the PHP 8.6.0 RC2 runtime configuration +1915/-0

Add the PHP 8.6.0 RC2 runtime configuration

• Adds version-specific Bearsampp paths, runtime limits, built-in extension settings, and disabled OPcache defaults. Xdebug tuning remains present while loading the unavailable extension stays disabled.

bin/php8.6.0RC2/php.ini

build.propertiesAdvance the PHP bundle release date +1/-1

Advance the PHP bundle release date

• Changes the bundle release identifier from 2026.8.27 to 2026.9.24 for the new packaged runtimes.

build.properties

@qodo-code-review

qodo-code-review Bot commented Sep 24, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (0) 📘 Rule violations (0) 📜 Skill insights (0)

Grey Divider


Action required

1. New PHP releases stay undiscoverable ✓ Resolved 🐞 Bug ≡ Correctness
Description
The new PHP 8.3.35 and 8.6.0RC2 modules have no corresponding entries in the repository's
releases.properties registry. CI rejects both detected versions and falls back to testing older
releases, while consumers of the registry cannot resolve either new package.
Code

bin/php8.3.35/bearsampp.conf[1]

+phpVersion = "8.3.35"
Evidence
The registry begins with PHP 8.5 releases and reaches PHP 8.3.33 without either newly added version.
Repository documentation requires new versions to be registered, and the CI workflow explicitly
skips changed versions that do not have matching registry keys before selecting older fallback
versions.

releases.properties[1-40]
docs/CI-CD-TESTING.md[24-35]
.github/workflows/php-extension-test.yml[84-105]
.github/workflows/php-extension-test.yml[146-169]
build.properties[1-4]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The two newly added PHP versions are absent from the release registry used to resolve downloadable packages and select versions for CI testing.

## Fix Focus Areas
- releases.properties[1-40]
- bin/php8.3.35/bearsampp.conf[1-1]
- bin/php8.6.0RC2/bearsampp.conf[1-1]

## Recommended Fix
Publish the generated archives and add entries for PHP 8.3.35 and PHP 8.6.0RC2 to `releases.properties`, using URLs containing the new `2026.9.24` release tag and exact packaged filenames.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


2. PHP 8.6 ships the wrong dependency ⊘ Outdated 🐞 Bug ≡ Correctness
Description
deps.properties labels a PHP 8.3 Imagick extension archive as the ImageMagick runtime dependency
for PHP 8.6.0RC2. During packaging, dependency handling copies that archive into the runtime
directory instead of installing an extension, so the bundle lacks the expected ImageMagick
distribution and contains an incompatible PHP DLL in its place.
Code

bin/php8.6.0RC2/deps.properties[1]

+Imagemagick = https://github.com/Bearsampp/modules-untouched/releases/download/php-2026.9.24/php_imagick-3.8.1-8.3-ts-vs16-x64.zip
Evidence
The target module identifies itself as PHP 8.6, but its dependency URL explicitly names a PHP 8.3
extension build. The build processes this file through the dependency path, which copies ImageMagick
dependency files into an imagick runtime directory, whereas extension installation into
ext/php_imagick.dll only occurs for entries in exts.properties; neighboring modules keep these
two artifact types separate.

bin/php8.6.0RC2/bearsampp.conf[1-1]
bin/php8.6.0RC2/deps.properties[1-1]
bin/php8.6.0RC2/exts.properties[1-4]
build.gradle[1669-1729]
build.gradle[1946-1970]
bin/php8.5.10/deps.properties[1-1]
bin/php8.5.10/exts.properties[1-1]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The PHP 8.6 dependency configuration downloads a PHP 8.3 Imagick extension archive where the build expects an ImageMagick runtime distribution.

## Fix Focus Areas
- bin/php8.6.0RC2/deps.properties[1-1]

## Recommended Fix
Replace the current URL with the PHP 8.6 release's portable ImageMagick runtime archive, following the `ImageMagick-...-portable-...` convention used by neighboring PHP modules. Keep any PHP-version-specific Imagick extension archive in `exts.properties` instead.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools



Remediation recommended

3. The prerelease is never tested ✓ Resolved 🐞 Bug ☼ Reliability
Description
The extension-test workflow extracts only three numeric version components from changed module
paths, truncating php8.6.0RC2 to 8.6.0. Its subsequent registry lookup therefore cannot select
the actual RC2 package even after that prerelease is registered under its full version.
Code

bin/php8.6.0RC2/bearsampp.conf[1]

+phpVersion = "8.6.0rc2"
Evidence
The new directory and configuration identify the release as 8.6.0RC2, while CI's regular expression
ends immediately after the numeric patch component. The truncated value is then used verbatim for
registry validation, making the prerelease unreachable through changed-file detection.

bin/php8.6.0RC2/bearsampp.conf[1-1]
.github/workflows/php-extension-test.yml[84-105]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

## Issue description
The CI version detector strips the RC suffix from the newly introduced PHP prerelease directory, preventing tests from selecting its exact release artifact.

## Fix Focus Areas
- .github/workflows/php-extension-test.yml[84-105]
- bin/php8.6.0RC2/bearsampp.conf[1-1]

## Recommended Fix
Extend the directory and PR-title version extraction patterns to preserve supported prerelease suffixes such as `RC2`, and use that exact value for the `releases.properties` lookup and test matrix.

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Context sources
Review mode: ⚖️ Balanced: Downgraded extended -> standard: change is below the extended eligibility bar (hunks 13/18, lines 3910/200; both must reach the floor). Router rationale: This adds two runtime PHP distributions with extensive configuration, extension/dependency URLs, version metadata, and multiple independent compatibility risks, making redundant review materially valuable.

Grey Divider

Tip of the day
💡 Did you know, you can enable the Remediation agent and Qodo fixes findings in a dedicated fix PR

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread bin/php8.6.0RC2/deps.properties Outdated
Comment thread bin/php8.3.35/bearsampp.conf
Comment thread bin/php8.6.0RC2/bearsampp.conf Outdated
Auto-generated from release 2026.9.24
@N6REJ N6REJ changed the title Add PHP 8.3.35 and 8.6.0RC2 with configuration files, extension support, and dependency management Add PHP 8.3.35 SECURITY FIX & 8.6.0RC2 with configuration files, extension support, and dependency management Sep 24, 2026
# Conflicts:
#	build.properties
# Conflicts:
#	releases.properties
…ation

Update regex patterns across workflow files and documentation to support pre-release version suffixes (alpha, beta, RC) in addition to standard semantic versions. This enables proper detection and testing of pre-release PHP versions like 8.6.0RC2 and 8.6.0beta3 throughout the CI/CD pipeline.
@github-actions

github-actions Bot commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

🐘 PHP Module Tests - Results

Test Date: 2026-09-24 22:47:59 UTC
Status: ✅ All tests passed

📊 Test Results by Version

PHP 8.2.34

win10-amd
win10-intel
win11-amd
win11-intel

PHP 8.3.35

win10-amd
win10-intel
win11-amd
win11-intel

PHP 8.4.26

win10-amd
win10-intel
win11-amd
win11-intel

PHP 8.5.11

win10-amd
win10-intel
win11-amd
win11-intel

PHP 8.6.0RC2

win10-amd
win10-intel
win11-amd
win11-intel

Results: 20 of 20 tests completed

All tests passed successfully! ✨


📋 Test Phases

Each version is tested through the following phases:

  • Phase 1: Basic PHP Validation (Download, Extract, Verify Executable)
  • Phase 2: Extension Validation (Download, Architecture Check, Loading Test)
  • Phase 3: Dependency Validation (Download Dependencies, Test with Dependencies)
  • Phase 4: Functional Testing (Test Extension Functionality)

Check artifacts for detailed logs.

Bearsampp Bot and others added 7 commits September 24, 2026 12:15
Auto-generated from release 2026.9.24
…encies

Update php.ini to use uppercase RC2 in include_path and extension_dir directives. Comment out Imagemagick and PEAR dependencies in properties files to temporarily disable extensions.
Auto-generated from release 2026.9.24
Auto-generated from release 2026.9.24
Auto-generated from release 2026.9.24
@N6REJ N6REJ changed the title Add PHP 8.3.35 SECURITY FIX & 8.6.0RC2 with configuration files, extension support, and dependency management Add PHP SECURITY FIXS & 8.6.0RC2 with configuration files, extension support, and dependency management Sep 24, 2026
@jwaisner
jwaisner merged commit b8f5b86 into main Sep 25, 2026
24 checks passed
@jwaisner
jwaisner deleted the rc2 branch September 25, 2026 03:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement ✨ Improve program Security 🔐 Security issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants