[Midnightbsd-cvs] [MidnightBSD/mports] afc799: lang/php84: update to 8.4.25

Lucas Holt noreply at github.com
Wed Sep 16 21:05:19 EDT 2026


  Branch: refs/heads/lang/php84
  Home:   https://github.com/MidnightBSD/mports
  Commit: afc7993d6b22f645f74d5d6b77222c5a041f2afa
      https://github.com/MidnightBSD/mports/commit/afc7993d6b22f645f74d5d6b77222c5a041f2afa
  Author: Lucas Holt <luke at foolishgames.com>
  Date:   2026-09-16 (Wed, 16 Sep 2026)

  Changed paths:
    M lang/php84/Makefile
    M lang/php84/distinfo

  Log Message:
  -----------
  lang/php84: update to 8.4.25

Upstream bug-fix release (27 Aug 2026).  No CVEs are addressed in this
release; the 8.4 security fixes for CVE-2026-17544, CVE-2026-17543,
CVE-2026-7260 and CVE-2026-9672 already shipped in 8.4.24.

Notable fixes include stack-overflow crashes on deeply nested arrays and
DOM documents, several Opcache JIT miscompilations (including DT_TEXTREL
in JIT-generated TLS access on x86_64), and a PCRE crash with \C in
UTF-8 patterns.

PORTREVISION is reset for the new distfile.

Validated on amd64: makesum (checksum matches the SHA256 published on
php.net), patch, build, fake and package all succeed.  Remaining fake
warnings about php-fpm.conf.default and www.conf.default are false
positives -- both are @sample entries in pkg-plist -- and libtool.m4.bak
is a sed backup artifact; lang/php82 and lang/php83 behave identically.
NO_TEST is already set for this port.

AI-Assisted-by: Claude Opus 5 <noreply at anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply at anthropic.com>
Claude-Session: https://claude.ai/code/session_01NSsgED5s7GPYJNb1HxuaU9
Signed-off-by: Lucas Holt <luke at foolishgames.com>



To unsubscribe from these emails, change your notification settings at https://github.com/MidnightBSD/mports/settings/notifications


More information about the Midnightbsd-cvs mailing list