The weekly PHP internals recap for September 9, 2026 opens with three corrections: PHP 8.4.25 was a bug-fix release, not a security release; the unnamed libxml-rs contributors were James Gilliland and David Carlier; and Tim Düsterhus disagreed with Sjoerd on substance, contrary to what was said last week.
The top story is a vote that lasted 56 hours. Osama Aldemeery opened voting on PREG_THROW_ON_ERROR, an opt-in flag turning PCRE errors into PregException. Tim Düsterhus, author of PHP's throwables policy, voted no within the hour. His reasons: a pattern failing to compile would keep its warning while the exception carried only the thin preg_last_error_msg text, and an exception thrown inside a preg_replace_callback callback would pass through unwrapped, violating the rule that an extension must wrap what it calls. Osama countered that wrapping a callback's exception produces a PregException that maps to no preg error, while preg_last_error() reports nothing. Fixing that requires a three-class hierarchy. Robert Humphries argued invalid patterns and bad UTF-8 are programmer errors, arguably PregError. Osama pulled the vote Sunday night, saying the flag violates the throwable policy and should not be fixed mid-vote.
Gina P. Banyard wants PHP to stop fixing a class of engine crashes that only fuzzers and LLMs trigger: use-after-free reports where an error handler frees the variable that raised the warning. Each fix costs a refcount dance everyone pays for in performance, and most triggers are deprecations PHP 9 removes anyway. She asked for consensus, ideally without an RFC, that callbacks mutating engine state are undefined behaviour. Ilia Alshanetsky wants case-by-case fixes. Ilija Tovilo said that approach has already been tried; he noted the false-positive reports consume security team time and said he and Arnaud plan a mitigating RFC. Tim Düsterhus added that PHP 9 will bring new deprecations of its own.
On PEAR: Chuck Burgess of the PEAR Group finally responded and agrees with sunsetting the website and removing PEAR from the PHP source. Nick S. wants the RFC's line about unresponsive maintainers struck; Larry Garfield and Tim Düsterhus call that a minor change, allowing a vote after a one-week cooldown. Rowan Tommins noted Chuck is one of eight PEAR Group members, so his agreement is one vote, not authority. The PEAR user accounts are gone, so the missing bug data is unrecoverable. Derick Rethans wants a readonly site for a year, then a tarball on museum.php.net. Rowan sent Nick's mirror a pull request restoring the old site's colours and a locked PEAR logo.
Luca Rodenhäuser closed the strict-identifiers thread without an RFC, crediting Claude Pache, Rowan Tommins and Larry Garfield with changing his mind. The question whether non-ASCII identifiers are a supported feature remains unanswered: the manual says they work by accident, while 1,447 of them appear in the top 5,000 packages. He will send a documentation PR describing current behaviour, and left an offer on the table: a compiler complaint about invisible characters in names, with 68 cases found in half a million files.
Sjoerd Langkemper's RFC making octdec, hexdec, bindec and base_convert throw on invalid input did not open voting as planned. After last week's argument that parsing is Exception territory, he asked which exception to use. Rowan Tommins said it must be Exception plus a dedicated subclass, never SPL, suggesting BaseConversionException. Tim Düsterhus would throw plain Exception, since the functions live in standard and may be redesigned into an int or number namespace later.
The performance debate continued. Larry Garfield argued benchmark results are one data point among many: array_str_contains() being 50% faster in C differs from 0.5%. Tim Düsterhus replied that performance is a property of the implementation, not the feature, and proposed the Optimizer as the alternative, the way PHP 8.6 already rewrites array_map. Meanwhile Sepehr Mahmoudi's scan of the top 200 Composer packages (about 21,000 files) found 32 filter-by-substring patterns, but Rowan's review showed at least 15 did extra logic, so the RFC now claims up to 17 of 32, with a benchmark promised.
Quick hits: Weilin Du plans to open voting on IntlRelativeDateTimeFormatter on September 15 and will fix Tim's catch about the internally cloned ICU number formatter by refreshing it lazily. Timo Poppinga wants openssl to expose OpenSSL's provider model generically so post-quantum algorithms like ML-KEM and ML-DSA work without per-algorithm constants. Dmytro Kulyk answered Nicolas Grekas's ten-month-old review of the NoSerialize attribute; the RFC now migrates 107 internal classes. Florent Morselli wants the data-encoding RFC's strict mode to reject whitespace and non-canonical trailing bits, since one WebAuthn credential currently has 16 valid spellings. For the fourth week running, nothing is in the voting phase.




Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Nothing arrived? Check your spam folder — and mark the mail as "Not spam" so it lands in your inbox next time.