From 969dc7b24ffcdbc2a671471ed9198119aeca3bce Mon Sep 17 00:00:00 2001 From: Gina Peter Banyard Date: Sat, 19 Sep 2026 14:06:08 +0100 Subject: [PATCH 1/2] Zend: reorganise some type tests --- .../{typehints => type_declarations/iterable}/bug76198.phpt | 0 .../relative_types}/bug43332_1.phpt | 2 +- .../relative_types}/bug43332_2.phpt | 2 +- .../relative_types}/bug60573.phpt | 2 +- .../relative_types}/bug60573_2.phpt | 2 +- .../{ => relative_types}/parent_is_not_proto.phpt | 0 .../{ => relative_types}/self_on_closure_in_method.phpt | 0 .../{ => relative_types/static}/static_type_in_final_class.phpt | 0 .../{ => relative_types/static}/static_type_outside_class.phpt | 0 .../{ => relative_types/static}/static_type_param.phpt | 0 .../{ => relative_types/static}/static_type_property.phpt | 0 .../{ => relative_types/static}/static_type_return.phpt | 0 .../{ => relative_types/static}/static_type_trait.phpt | 0 13 files changed, 4 insertions(+), 4 deletions(-) rename Zend/tests/{typehints => type_declarations/iterable}/bug76198.phpt (100%) rename Zend/tests/{typehints => type_declarations/relative_types}/bug43332_1.phpt (86%) rename Zend/tests/{typehints => type_declarations/relative_types}/bug43332_2.phpt (80%) rename Zend/tests/{typehints => type_declarations/relative_types}/bug60573.phpt (90%) rename Zend/tests/{typehints => type_declarations/relative_types}/bug60573_2.phpt (90%) rename Zend/tests/type_declarations/{ => relative_types}/parent_is_not_proto.phpt (100%) rename Zend/tests/type_declarations/{ => relative_types}/self_on_closure_in_method.phpt (100%) rename Zend/tests/type_declarations/{ => relative_types/static}/static_type_in_final_class.phpt (100%) rename Zend/tests/type_declarations/{ => relative_types/static}/static_type_outside_class.phpt (100%) rename Zend/tests/type_declarations/{ => relative_types/static}/static_type_param.phpt (100%) rename Zend/tests/type_declarations/{ => relative_types/static}/static_type_property.phpt (100%) rename Zend/tests/type_declarations/{ => relative_types/static}/static_type_return.phpt (100%) rename Zend/tests/type_declarations/{ => relative_types/static}/static_type_trait.phpt (100%) diff --git a/Zend/tests/typehints/bug76198.phpt b/Zend/tests/type_declarations/iterable/bug76198.phpt similarity index 100% rename from Zend/tests/typehints/bug76198.phpt rename to Zend/tests/type_declarations/iterable/bug76198.phpt diff --git a/Zend/tests/typehints/bug43332_1.phpt b/Zend/tests/type_declarations/relative_types/bug43332_1.phpt similarity index 86% rename from Zend/tests/typehints/bug43332_1.phpt rename to Zend/tests/type_declarations/relative_types/bug43332_1.phpt index 35d817c985ee..7639633c3e95 100644 --- a/Zend/tests/typehints/bug43332_1.phpt +++ b/Zend/tests/type_declarations/relative_types/bug43332_1.phpt @@ -1,5 +1,5 @@ --TEST-- -Bug #43332.1 (self and parent as type hint in namespace) +Bug #43332.1 (self and parent as type declaration in namespace) --FILE-- Date: Sat, 19 Sep 2026 14:28:54 +0100 Subject: [PATCH 2/2] Zend: fix OSS-Fuzz 532353396, static is a built-in type And thus should never be allowed to be qualified, as this lead to other bugs such as it not considered to be a built-in type by Reflection if it had a namespace component. We *may* want to extend the unqualified restriction to self and parent in the future. --- .../static/fully_qualified_static.phpt | 12 ++++++++++++ .../static/namespace_relative_static.phpt | 12 ++++++++++++ Zend/zend_compile.c | 3 +++ 3 files changed, 27 insertions(+) create mode 100644 Zend/tests/type_declarations/relative_types/static/fully_qualified_static.phpt create mode 100644 Zend/tests/type_declarations/relative_types/static/namespace_relative_static.phpt diff --git a/Zend/tests/type_declarations/relative_types/static/fully_qualified_static.phpt b/Zend/tests/type_declarations/relative_types/static/fully_qualified_static.phpt new file mode 100644 index 000000000000..4967e3f3d116 --- /dev/null +++ b/Zend/tests/type_declarations/relative_types/static/fully_qualified_static.phpt @@ -0,0 +1,12 @@ +--TEST-- +Fully qualified (leading backslash) static type names must fail +--DESCRIPTION-- +OSS-Fuzz: https://issues.oss-fuzz.com/issues/532353396 +--FILE-- + +--EXPECTF-- +Fatal error: Type declaration 'static' must be unqualified in %s on line %d diff --git a/Zend/tests/type_declarations/relative_types/static/namespace_relative_static.phpt b/Zend/tests/type_declarations/relative_types/static/namespace_relative_static.phpt new file mode 100644 index 000000000000..0c1cde76f147 --- /dev/null +++ b/Zend/tests/type_declarations/relative_types/static/namespace_relative_static.phpt @@ -0,0 +1,12 @@ +--TEST-- +namespace\static is not a valid type declaration +--DESCRIPTION-- +OSS-Fuzz: https://issues.oss-fuzz.com/issues/532353396 +--FILE-- + +--EXPECTF-- +Fatal error: Type declaration 'static' must be unqualified in %s on line %d diff --git a/Zend/zend_compile.c b/Zend/zend_compile.c index d8d61ea979e4..941873663848 100644 --- a/Zend/zend_compile.c +++ b/Zend/zend_compile.c @@ -272,6 +272,7 @@ static const builtin_type_info builtin_types[] = { {ZEND_STRL("iterable"), IS_ITERABLE}, {ZEND_STRL("object"), IS_OBJECT}, {ZEND_STRL("mixed"), IS_MIXED}, + {ZEND_STRL("static"), IS_STATIC}, {NULL, 0, IS_UNDEF} }; @@ -7100,6 +7101,8 @@ static zend_type zend_compile_single_typename(zend_ast *ast) ZSTR_VAL(zend_string_tolower(type_name))); } + ZEND_ASSERT(type_code != IS_STATIC && "unqualified static type should have been handled by ZEND_AST_TYPE branch"); + /* Transform iterable into a type union alias */ if (type_code == IS_ITERABLE) { /* Set iterable bit for BC compat during Reflection and string representation of type */