Skip to content

merge: cascade 8.4 into master - #184

Merged
lisachenko merged 4 commits into
masterfrom
8.4
Aug 9, 2026
Merged

merge: cascade 8.4 into master#184
lisachenko merged 4 commits into
masterfrom
8.4

Conversation

@github-actions

@github-actions github-actions Bot commented Aug 9, 2026

Copy link
Copy Markdown
Contributor

Automated cascade merge of 8.4 into master (branch flow defined in .github/branch-flow.json).

Resolve conflicts in favour of the newer engine structures where they touch include/ - regenerate headers on the target branch instead of merging them textually. See AGENTS.md.

claude and others added 4 commits August 9, 2026 11:50
…pe(), ClassSpecializer::evict()

Dependant packages were reaching behind the API line for operations that had no
named entry point: probing Core::$executor to ask "is the engine booted",
deleting class-table buckets through the @internal HashTable::delete(), and
pairing Core::sizeof(Core::type(...)) so a raw FFI\CType crossed the boundary.

- ClassSpecializer::evict(): the destroying counterpart of specialize().
  Removes the class-table bucket so destroy_zend_class() dismantles the entry
  now, while op_array-refcounted bodies shared with the source stay alive.
  Refuses internal and shared-memory (immutable/preloaded) entries. The
  explicit-teardown test now exercises it.
- Core::sizeOfType(): the named form of the sizeof(type(...)) pair;
  Core::type() is @internal so no raw CType crosses the API line anymore.
- Core::isUsable(): non-throwing projection of the boot guard, for consumers
  and test bootstraps deciding whether engine paths can run here at all -
  hand-rolled ffi.enable checks get the supported 'preload' mode wrong.
- AGENTS.md: a 'Consuming z-engine from another package' section drawing the
  line those leaks crossed because it was never written down.

No ReflectionClass::evict() mirror on purpose: an instance method destroying
the entry its own wrapper points at invites use-after-free on $this.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019TGQqR7ByjHrVSYKVHPrkJ
Closes #21, open since 2019 on one blocker recorded in its own comments:
'the composer autoloader calls Core::init() before preload initialization'.
An unconditional boot binds the definitions with FFI::cdef(), which lasts for
the preload request only, and leaves an engine behind that turns the script's
own Core::preload() into a no-op - the server starts and every request after
it fails.

bootstrap.php (autoload.files) therefore recognises the preload stage and
serves it with Core::preload(), whose FFI::load() publishes the definitions
under FFI_SCOPE for the life of the server; everything else gets Core::init().
The stage is identified by the one fact that distinguishes it - during
preloading the script named by opcache.preload is the first file the process
included. Verified end to end on a matching PHP line: FFI::scope('ZEngine')
resolves in the request that follows, and does not when the preload script
skips the boot.

A host that cannot run the engine (no ext-ffi, ffi.enable=0, wrong PHP minor,
no definitions for the platform) is left uninitialized in silence - throwing
from an autoloaded file would break static analysis, FFI-disabled test jobs
and composer-time tooling at require. Nothing is lost: Core::init() is
idempotent, so code that needs the engine calls it and gets the same
explanation this file swallowed. ZENGINE_AUTOBOOT=0 skips the boot entirely.

Core::preload() is now idempotent too, so the explicit call an existing
opcache.preload script makes after requiring the autoloader stays harmless.

Review feedback on the API additions:
- Core::isUsable() dropped - init() and isInitialized() are enough
- evict() reads the class through ReflectionClass::isUserDefined()/
  isImmutable()/isPreloaded() instead of ce_flags off the raw entry; the new
  isPreloaded() sits beside isImmutable()
- the consumer section folded into 'Public APIs never leak CData', keeping the
  @internal / FFI-CData part

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019TGQqR7ByjHrVSYKVHPrkJ
PHP does not support opcache preloading on Windows at all, so both preload
cases failed there: the engine reported 'Preloading is not supported on
Windows', and the scratch script path went through a short name (RUNNER~1)
whose tilde broke -d ini parsing before that.

Guarded with the same skip the repository already uses for opcache.preload
(issue #119), on the two cases that need it rather than the whole class - the
opt-out and silent-failure cases are plain autoload behaviour and keep running
everywhere. The --fail-on-skipped opcache gate runs on Linux and macOS, where
preloading exists and neither case skips.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019TGQqR7ByjHrVSYKVHPrkJ
…audit-1t6xy7

feat: boot from Composer's autoloader (closes #21), plus ClassSpecializer::evict() and Core::sizeOfType()
@lisachenko
lisachenko merged commit c1ff722 into master Aug 9, 2026
20 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants