The weekly PHP internals digest for September 2, 2026 covered 11 stories. The lead: Luca Rodenhäuser examined the scanner rule that defines a PHP identifier in bytes, not characters. Every byte at or above hex 80 is accepted, so $x followed by a no-break space is a distinct variable that looks identical. He proposed a per-file declare to restrict this and scanned the 250 most-installed Packagist packages, finding exactly one identifier that would break.
Larry Garfield suggested skipping the opt-in and enforcing the rule in PHP 9, arguing 99.99% of developers would never notice. Rodenhäuser reran the scan against the top 5,000 packages. Half a million files produced 1,447 non-ASCII identifiers, 91% of them in math-php, where variable names spell out formulas. Derick Rethans questioned whether 13.7 KB of tables in every PHP process is worth it, Juliette Reinders Folmer asked about variable variables, and Rowan Tommins asked how much was rejection versus normalisation. Rodenhäuser split his proposal into three parts: a diagnostic, a well-formedness rule, and a conformance rule.
Nick Sdot opened an RFC to end PHP's endorsement of PEAR. After reviewing three months of prior discussions he built a static mirror so the command-line tool keeps working. His case: PEAR is partly broken, spammed, barely active and unmaintained. Rowan Tommins backed it. Sdot counted 6 packages still publishing to PEAR, 3 of them PEAR's own infrastructure, 2 recently marked unmaintained, leaving exactly one independent maintained package: Net_SMTP.
Sjoerd Langkemper announced a vote on making octdec, hexdec, bindec and base_convert throw a ValueError on invalid input. Tim Düsterhus objected that passing untrusted input to these functions is an expected use case, so the Error hierarchy is wrong; developers will want to catch what comes back. He cited the coding standards policy stating the Error hierarchy must not be used for errors expected to be thrown and caught during normal operation, and argued base conversion is parsing.
Sepehr Mahmoudi's array-filtering function returned renamed array_str_contains, retargeted at PHP 8.7. Seifeddine Gmati called it redundant and argued the same logic would justify array_str_starts_with and hundreds more. Bruce Weirdan asked whether closure overhead itself should be fixed instead, which would speed up every builtin taking a callable. Mahmoudi conceded a filter must read the whole array rather than stopping at the first match, and promised static analysis across Packagist to back the frequency claim.
The debate about machine-written list mail turned concrete when Juris drafted guideline text advising newcomers to write their own messages without AI help, noting perfect English is not required. He then wrote three paragraphs in Latvian, machine-translated them, and sent both versions. Sepehr Mahmoudi acknowledged AI had been writing his replies. Weilin Du asked the thread to stop naming people; Yuya Hamada apologised. No written policy exists.
Théo Attali proposed a date format constant for milliseconds with a trailing Z, matching JavaScript's toISOString, since DATE_RFC3339_EXTENDED uses a numeric offset. Andreas Heigl, who added the extended constants, declined to add more and pointed to a userland formatter working since PHP 5.3. Tim Düsterhus redirected the idea toward the new date and time API: PHP 8.6 ships the first piece, and the proposed timezone-less Time\Instant would be the natural home for a Zulu-format method.
Riaan de Beer offered libxml-rs, a native-Rust reimplementation of libxml2 compatible at the C ABI level, claiming xmllint and xmlcatalog come out byte-identical against libxml2 2.15.3 across 1,110 tests. He asked only for an experimental test build. The list instead disputed his claim that libxml2 has been unmaintained since December 2025; Pierre noted many commits since, and others said new maintainers had stepped up, one of whom helps php-src directly.
On whether RFCs should ship a userland polyfill, Nicolas Grekas said every polyfillable feature ends up in the symfony/polyfill monorepo anyway, and the shipped version often differs from the RFC, so polyfills need a separate workflow. Tim Düsterhus rejected Larry Garfield's benchmarking argument: performance is a moving target, stdlib additions must be maintained for 15+ years, and usefulness plus API design should decide. He noted PIE has made building private extensions easier than ever.
Three releases landed in three days: Calvin Buckley shipped PHP 8.4.25, a security release; Daniel Scherzer released 8.5.10, a bugfix; Matteo Beccati put 8.6.0beta2 up for testing. Nick Sdot replied to the nameof RFC asking to see it in 8.7, answering a message from May 2023. No RFC has been in the voting phase for three weeks running.




Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.