[php-src] master: Merge branch 'PHP-8.5'

Tim Düsterhus <[email protected]>
Newsgroups gmane.comp.php.cvs.general
Message-ID <[email protected]>
Author: Tim Düsterhus (TimWolla)
Date: 2026-07-12T20:53:05+02:00

Commit: https://github.com/php/php-src/commit/b84bd9ef3c800e8fa9e6314c58683ec27bc14aa2
Raw diff: https://github.com/php/php-src/commit/b84bd9ef3c800e8fa9e6314c58683ec27bc14aa2.diff

Merge branch 'PHP-8.5'

* PHP-8.5:
  ext/uri: Fix GH-22628 Percent-encoding of caret in WHATWG URL paths is not performed (#22700)

Changed paths:
  A  ext/lexbor/patches/0011-Percent-encode-the-caret-in-the-path.patch
  M  NEWS
  M  ext/lexbor/lexbor/url/url.c
  M  ext/lexbor/patches/0001-Expose-line-and-column-information-for-use-in-PHP.patch
  M  ext/lexbor/patches/0002-Track-implied-added-nodes-for-options-use-in-PHP.patch
  M  ext/lexbor/patches/0003-Patch-utilities-and-data-structure-to-be-able-to-gen.patch
  M  ext/lexbor/patches/0004-Remove-unused-upper-case-tag-static-data.patch
  M  ext/lexbor/patches/0005-Shrink-size-of-static-binary-search-tree.patch
  M  ext/lexbor/patches/0006-Patch-out-unused-CSS-style-code.patch
  M  ext/lexbor/patches/0007-Add-lxb_url_is_special-to-the-public-API-362.patch
  M  ext/lexbor/patches/0008-URL-fixed-setters-for-empty-hosts.patch
  M  ext/lexbor/patches/0009-URL-fixed-uninitialized-memory-in-the-path-buffer-gr.patch
  M  ext/lexbor/patches/0010-Fix-parsing-for-URL-containing-empty-host-and-userin.patch
  M  ext/uri/tests/whatwg/modification/path_success_auto_encoded.phpt
  M  ext/uri/tests/whatwg/parsing/path_success_percent_encode_set2.phpt


Diff:

diff --git a/NEWS b/NEWS
index f8fcd3556d1d..48b13b5bc90a 100644
--- a/NEWS
+++ b/NEWS
@@ -98,6 +98,8 @@ PHP                                                                        NEWS
     and a proxy set). (CVE-2026-12184) (ndossche)
 
 - URI:
+  . Fixed bug GH-22628 (Percent-encoding of caret in WHATWG URL paths is not
+    performed). (kocsismate)
   . Fixed bug GH-22629 (WHATWG Validation error incorrect with empty host and
     non-empty userinfo). (kocsismate)
 
diff --git a/ext/lexbor/lexbor/url/url.c b/ext/lexbor/lexbor/url/url.c
index aed468a1bed9..8099c12089bb 100644
--- a/ext/lexbor/lexbor/url/url.c
+++ b/ext/lexbor/lexbor/url/url.c
@@ -159,7 +159,7 @@ static const uint8_t lxb_url_map[256] =
     LXB_URL_MAP_USERINFO|LXB_URL_MAP_COMPONENT|LXB_URL_MAP_X_WWW_FORM, /* 0x5b ([) */
     LXB_URL_MAP_USERINFO|LXB_URL_MAP_COMPONENT|LXB_URL_MAP_X_WWW_FORM, /* 0x5c (\) */
     LXB_URL_MAP_USERINFO|LXB_URL_MAP_COMPONENT|LXB_URL_MAP_X_WWW_FORM, /* 0x5d (]) */
-    LXB_URL_MAP_USERINFO|LXB_URL_MAP_COMPONENT|LXB_URL_MAP_X_WWW_FORM, /* 0x5e (^) */
+    LXB_URL_MAP_USERINFO|LXB_URL_MAP_PATH|LXB_URL_MAP_COMPONENT|LXB_URL_MAP_X_WWW_FORM, /* 0x5e (^) */
     LXB_URL_MAP_UNDEF, /* 0x5f (_) */
     LXB_URL_MAP_PATH|LXB_URL_MAP_FRAGMENT|LXB_URL_MAP_USERINFO|LXB_URL_MAP_COMPONENT|LXB_URL_MAP_X_WWW_FORM, /* 0x60 (`) */
     LXB_URL_MAP_UNDEF, /* 0x61 (a) */
diff --git a/ext/lexbor/patches/0001-Expose-line-and-column-information-for-use-in-PHP.patch b/ext/lexbor/patches/0001-Expose-line-and-column-information-for-use-in-PHP.patch
index 533598837822..f23ec0f5034d 100644
--- a/ext/lexbor/patches/0001-Expose-line-and-column-information-for-use-in-PHP.patch
+++ b/ext/lexbor/patches/0001-Expose-line-and-column-information-for-use-in-PHP.patch
@@ -1,7 +1,7 @@
 From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
 From: Niels Dossche <[email protected]>
 Date: Sat, 26 Aug 2023 15:08:59 +0200
-Subject: [PATCH 01/10] Expose line and column information for use in PHP
+Subject: [PATCH 01/11] Expose line and column information for use in PHP
 
 ---
  source/lexbor/dom/interfaces/node.h  |  2 ++
diff --git a/ext/lexbor/patches/0002-Track-implied-added-nodes-for-options-use-in-PHP.patch b/ext/lexbor/patches/0002-Track-implied-added-nodes-for-options-use-in-PHP.patch
index 8814d5955354..8758c09a2e8f 100644
--- a/ext/lexbor/patches/0002-Track-implied-added-nodes-for-options-use-in-PHP.patch
+++ b/ext/lexbor/patches/0002-Track-implied-added-nodes-for-options-use-in-PHP.patch
@@ -1,7 +1,7 @@
 From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
 From: Niels Dossche <[email protected]>
 Date: Mon, 14 Aug 2023 20:18:51 +0200
-Subject: [PATCH 02/10] Track implied added nodes for options use in PHP
+Subject: [PATCH 02/11] Track implied added nodes for options use in PHP
 
 ---
  source/lexbor/html/tree.h                            | 3 +++
diff --git a/ext/lexbor/patches/0003-Patch-utilities-and-data-structure-to-be-able-to-gen.patch b/ext/lexbor/patches/0003-Patch-utilities-and-data-structure-to-be-able-to-gen.patch
index aa4802320491..56458a49deea 100644
--- a/ext/lexbor/patches/0003-Patch-utilities-and-data-structure-to-be-able-to-gen.patch
+++ b/ext/lexbor/patches/0003-Patch-utilities-and-data-structure-to-be-able-to-gen.patch
@@ -1,7 +1,7 @@
 From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
 From: Niels Dossche <[email protected]>
 Date: Thu, 24 Aug 2023 22:57:48 +0200
-Subject: [PATCH 03/10] Patch utilities and data structure to be able to
+Subject: [PATCH 03/11] Patch utilities and data structure to be able to
  generate smaller lookup tables
 
 Changed the generation script to check if everything fits in 32-bits.
diff --git a/ext/lexbor/patches/0004-Remove-unused-upper-case-tag-static-data.patch b/ext/lexbor/patches/0004-Remove-unused-upper-case-tag-static-data.patch
index 1a28b21ccdc5..f4fe2050998d 100644
--- a/ext/lexbor/patches/0004-Remove-unused-upper-case-tag-static-data.patch
+++ b/ext/lexbor/patches/0004-Remove-unused-upper-case-tag-static-data.patch
@@ -1,7 +1,7 @@
 From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
 From: Niels Dossche <[email protected]>
 Date: Wed, 29 Nov 2023 21:26:47 +0100
-Subject: [PATCH 04/10] Remove unused upper case tag static data
+Subject: [PATCH 04/11] Remove unused upper case tag static data
 
 ---
  source/lexbor/tag/res.h | 2 ++
diff --git a/ext/lexbor/patches/0005-Shrink-size-of-static-binary-search-tree.patch b/ext/lexbor/patches/0005-Shrink-size-of-static-binary-search-tree.patch
index a1dda1fcd112..f36a2d758181 100644
--- a/ext/lexbor/patches/0005-Shrink-size-of-static-binary-search-tree.patch
+++ b/ext/lexbor/patches/0005-Shrink-size-of-static-binary-search-tree.patch
@@ -1,7 +1,7 @@
 From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
 From: Niels Dossche <[email protected]>
 Date: Wed, 29 Nov 2023 21:29:31 +0100
-Subject: [PATCH 05/10] Shrink size of static binary search tree
+Subject: [PATCH 05/11] Shrink size of static binary search tree
 
 This also makes it more efficient on the data cache.
 ---
diff --git a/ext/lexbor/patches/0006-Patch-out-unused-CSS-style-code.patch b/ext/lexbor/patches/0006-Patch-out-unused-CSS-style-code.patch
index 57f1e0e92fcb..7c6e1beebf46 100644
--- a/ext/lexbor/patches/0006-Patch-out-unused-CSS-style-code.patch
+++ b/ext/lexbor/patches/0006-Patch-out-unused-CSS-style-code.patch
@@ -1,7 +1,7 @@
 From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
 From: Niels Dossche <[email protected]>
 Date: Sun, 7 Jan 2024 21:59:28 +0100
-Subject: [PATCH 06/10] Patch out unused CSS style code
+Subject: [PATCH 06/11] Patch out unused CSS style code
 
 ---
  source/lexbor/css/rule.h | 2 ++
diff --git a/ext/lexbor/patches/0007-Add-lxb_url_is_special-to-the-public-API-362.patch b/ext/lexbor/patches/0007-Add-lxb_url_is_special-to-the-public-API-362.patch
index ced72cbba90e..50bdc2397ba5 100644
--- a/ext/lexbor/patches/0007-Add-lxb_url_is_special-to-the-public-API-362.patch
+++ b/ext/lexbor/patches/0007-Add-lxb_url_is_special-to-the-public-API-362.patch
@@ -1,7 +1,7 @@
 From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
 From: =?UTF-8?q?M=C3=A1t=C3=A9=20Kocsis?= <[email protected]>
 Date: Sun, 17 May 2026 22:17:14 +0200
-Subject: [PATCH 07/10] Add lxb_url_is_special() to the public API (#362)
+Subject: [PATCH 07/11] Add lxb_url_is_special() to the public API (#362)
 
 As https://wiki.php.net/rfc/uri_followup#uri_type_detection relies on this information.
 ---
diff --git a/ext/lexbor/patches/0008-URL-fixed-setters-for-empty-hosts.patch b/ext/lexbor/patches/0008-URL-fixed-setters-for-empty-hosts.patch
index 233b42713c2b..4218461c3bad 100644
--- a/ext/lexbor/patches/0008-URL-fixed-setters-for-empty-hosts.patch
+++ b/ext/lexbor/patches/0008-URL-fixed-setters-for-empty-hosts.patch
@@ -1,7 +1,7 @@
 From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
 From: Alexander Borisov <[email protected]>
 Date: Fri, 26 Jun 2026 18:55:56 +0300
-Subject: [PATCH 08/10] URL: fixed setters for empty hosts.
+Subject: [PATCH 08/11] URL: fixed setters for empty hosts.
 MIME-Version: 1.0
 Content-Type: text/plain; charset=UTF-8
 Content-Transfer-Encoding: 8bit
diff --git a/ext/lexbor/patches/0009-URL-fixed-uninitialized-memory-in-the-path-buffer-gr.patch b/ext/lexbor/patches/0009-URL-fixed-uninitialized-memory-in-the-path-buffer-gr.patch
index 0b5ab2bce771..91e78a899f44 100644
--- a/ext/lexbor/patches/0009-URL-fixed-uninitialized-memory-in-the-path-buffer-gr.patch
+++ b/ext/lexbor/patches/0009-URL-fixed-uninitialized-memory-in-the-path-buffer-gr.patch
@@ -1,7 +1,7 @@
 From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
 From: Alexander Borisov <[email protected]>
 Date: Fri, 5 Jun 2026 22:13:32 +0300
-Subject: [PATCH 09/10] URL: fixed uninitialized memory in the path buffer
+Subject: [PATCH 09/11] URL: fixed uninitialized memory in the path buffer
  growth.
 
 When a path was long enough to outgrow the on-stack buffer, the first
diff --git a/ext/lexbor/patches/0010-Fix-parsing-for-URL-containing-empty-host-and-userin.patch b/ext/lexbor/patches/0010-Fix-parsing-for-URL-containing-empty-host-and-userin.patch
index e0b45ab4973f..9cbf3e0094ed 100644
--- a/ext/lexbor/patches/0010-Fix-parsing-for-URL-containing-empty-host-and-userin.patch
+++ b/ext/lexbor/patches/0010-Fix-parsing-for-URL-containing-empty-host-and-userin.patch
@@ -1,7 +1,7 @@
 From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
 From: =?UTF-8?q?M=C3=A1t=C3=A9=20Kocsis?= <[email protected]>
 Date: Thu, 9 Jul 2026 21:51:05 +0200
-Subject: [PATCH 10/10] Fix parsing for URL containing empty host and userinfo
+Subject: [PATCH 10/11] Fix parsing for URL containing empty host and userinfo
 
 The returned error code (LXB_URL_ERROR_TYPE_INVALID_CREDENTIALS) apparently contradicts the specification:
 
diff --git a/ext/lexbor/patches/0011-Percent-encode-the-caret-in-the-path.patch b/ext/lexbor/patches/0011-Percent-encode-the-caret-in-the-path.patch
new file mode 100644
index 000000000000..2781fad5bcb9
--- /dev/null
+++ b/ext/lexbor/patches/0011-Percent-encode-the-caret-in-the-path.patch
@@ -0,0 +1,29 @@
+From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
+From: =?UTF-8?q?M=C3=A1t=C3=A9=20Kocsis?= <[email protected]>
+Date: Fri, 10 Jul 2026 22:31:16 +0200
+Subject: [PATCH 11/11] Percent-encode the caret in the path
+
+The caret (^) is part of the path percent-encode set:
+
+"The path percent-encode set is a percent-encode set consisting of the query percent-encode set and U+003F (?), U+005E (^), U+0060 (`), U+007B ({), and U+007D (})."
+
+Until now, this character wasn't percent-encoded in the path likely due to a copy-paste error. This is mistake is fixed by adding LXB_URL_MAP_PATH to the lxb_url_map entry for the caret.
+
+Originally reported at https://github.com/php/php-src/issues/22628
+---
+ source/lexbor/url/url.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/source/lexbor/url/url.c b/source/lexbor/url/url.c
+index aed468a..8099c12 100644
+--- a/source/lexbor/url/url.c
++++ b/source/lexbor/url/url.c
+@@ -159,7 +159,7 @@ static const uint8_t lxb_url_map[256] =
+     LXB_URL_MAP_USERINFO|LXB_URL_MAP_COMPONENT|LXB_URL_MAP_X_WWW_FORM, /* 0x5b ([) */
+     LXB_URL_MAP_USERINFO|LXB_URL_MAP_COMPONENT|LXB_URL_MAP_X_WWW_FORM, /* 0x5c (\) */
+     LXB_URL_MAP_USERINFO|LXB_URL_MAP_COMPONENT|LXB_URL_MAP_X_WWW_FORM, /* 0x5d (]) */
+-    LXB_URL_MAP_USERINFO|LXB_URL_MAP_COMPONENT|LXB_URL_MAP_X_WWW_FORM, /* 0x5e (^) */
++    LXB_URL_MAP_USERINFO|LXB_URL_MAP_PATH|LXB_URL_MAP_COMPONENT|LXB_URL_MAP_X_WWW_FORM, /* 0x5e (^) */
+     LXB_URL_MAP_UNDEF, /* 0x5f (_) */
+     LXB_URL_MAP_PATH|LXB_URL_MAP_FRAGMENT|LXB_URL_MAP_USERINFO|LXB_URL_MAP_COMPONENT|LXB_URL_MAP_X_WWW_FORM, /* 0x60 (`) */
+     LXB_URL_MAP_UNDEF, /* 0x61 (a) */
diff --git a/ext/uri/tests/whatwg/modification/path_success_auto_encoded.phpt b/ext/uri/tests/whatwg/modification/path_success_auto_encoded.phpt
index 8f34b6db9de6..a871b6614a75 100644
--- a/ext/uri/tests/whatwg/modification/path_success_auto_encoded.phpt
+++ b/ext/uri/tests/whatwg/modification/path_success_auto_encoded.phpt
@@ -13,5 +13,5 @@ var_dump($url2->toAsciiString());
 ?>
 --EXPECT--
 string(1) "/"
-string(8) "/p^th%23"
-string(27) "https://example.com/p^th%23"
+string(10) "/p%5Eth%23"
+string(29) "https://example.com/p%5Eth%23"
diff --git a/ext/uri/tests/whatwg/parsing/path_success_percent_encode_set2.phpt b/ext/uri/tests/whatwg/parsing/path_success_percent_encode_set2.phpt
index 9419c817fbbd..dd82beeff101 100644
--- a/ext/uri/tests/whatwg/parsing/path_success_percent_encode_set2.phpt
+++ b/ext/uri/tests/whatwg/parsing/path_success_percent_encode_set2.phpt
@@ -22,10 +22,10 @@ object(Uri\WhatWg\Url)#%d (%d) {
   ["port"]=>
   NULL
   ["path"]=>
-  string(28) "/foo%22/%3Cbar%3E/^%7Bbaz%7D"
+  string(30) "/foo%22/%3Cbar%3E/%5E%7Bbaz%7D"
   ["query"]=>
   NULL
   ["fragment"]=>
   NULL
 }
-string(47) "https://example.com/foo%22/%3Cbar%3E/^%7Bbaz%7D"
+string(49) "https://example.com/foo%22/%3Cbar%3E/%5E%7Bbaz%7D"
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.