Skip to content

[pull] master from php:master - #1274

Merged
pull[bot] merged 11 commits into
turkdevops:masterfrom
php:master
Sep 16, 2026
Merged

pull[bot] merged 11 commits into
turkdevops:masterfrom
php:master

Conversation

@pull

@pull pull Bot commented Sep 16, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

iliaal and others added 11 commits September 16, 2026 06:39
PDOStatement::getColumnMeta() indexed stmt->columns as soon as the driver
hook reported success, without checking that the columns had been
described or that the index was in range, so pdo_odbc, whose hook always
reports success, read out of bounds and crashed. Raise SQLSTATE 07009 and
return false instead, matching what the drivers that bound-check the
index in their own hook already return.

Closes GH-23654
* PHP-8.4:
  ext/pdo: Bound-check column index in getColumnMeta()
* PHP-8.5:
  ext/pdo: Bound-check column index in getColumnMeta()
We don't test ZPP for each individual function as this is global behaviour.
SQLite3::close() called from within a userland function, aggregate,
collation or authorizer callback freed the registered statements and
functions while sqlite3 was still executing, corrupting the active
statement and crashing the request. Track callback re-entry with a
per-database counter shared by all four callback kinds and throw an
Error from close() while it is non-zero; the database stays usable and
can be closed after the query completes.

Closes GH-23650
* PHP-8.4:
  ext/sqlite3: reject close() from inside a callback
* PHP-8.5:
  ext/sqlite3: reject close() from inside a callback
…rg specifier (#23706)

I misremembered the correct syntax for specifying the argnum in an `sprintf()`
format string and placed the number after the `$` instead of before. This lead
to `sprintf()` seeing an empty number and reporting:

> Argument number specifier must be greater than zero and less than 2147483647

which was misleading. Had the error message shown that the argnum is empty, it
would have been much clearer that it expect the number before the `$`.
@pull pull Bot locked and limited conversation to collaborators Sep 16, 2026
@pull pull Bot added the ⤵️ pull label Sep 16, 2026
@pull
pull Bot merged commit 938a311 into turkdevops:master Sep 16, 2026
0 of 2 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants