## Category `php-in-php` · `stdlib` · **php-src-strict** ## Problem `session_create_id()` JIT uses **`lib/JIT/Builtin/SessionCreateIdRuntime.php`** (~287 lines LLVM) with hex table + entropy logic duplicated from VM, although **`ext/standard/VmSession.php`** already implements php-src semantics (`php_session_create_id`). Workers should route JIT/AOT through compiled PHP helpers (same pattern as **#9495** SessionStorageRuntime, **#9411** SessionGcRuntime). ## php-src reference - [php/php-src `ext/session/session.c`](https://github.com/php/php-src/blob/master/ext/session/session.c) — `php_session_create_id`, prefix handling - [php/php-src `ext/session/session.stub.php`](https://github.com/php/php-src/blob/master/ext/session/session.stub.php) — `session_create_id(?string $prefix = null): string` ## Repro (parity guard during migration) ```php <?php $id = session_create_id(); var_export(is_string($id)); echo "\n"; var_export(strlen($id) >= 22 && strlen($id) <= 32); echo "\n"; $id2 = session_create_id('phpc-'); var_export(str_starts_with($id2, 'phpc-')); echo "\n"; ``` ```bash ./script/docker-exec.sh -- bash -lc 'source script/php-env.sh wc -l lib/JIT/Builtin/SessionCreateIdRuntime.php php bin/vm.php repro.php php bin/jit.php repro.php ' ``` | Check | VM (SSOT) | JIT today (gap) | |-------|-----------|-----------------| | returns string | OK | must match after migration | | length in php-src range | OK | must match | | optional `$prefix` | verify VM | must match | ## Scope (PHP-in-PHP first) | Path | Work | |------|------| | `ext/standard/SessionCreateIdJitHelper.php` (new) | wrap `VmSession::createId()` | | `lib/JIT/Builtin/SessionCreateIdRuntime.php` | thin bridge; delete hex/entropy LLVM | | `lib/JIT/Builtin/Type.php` / session batch | register helper link | | Tests | `test/compliance/cases/stdlib/session_create_id_jit.phpt` | **Forbidden:** new session ID logic in `runtime/*.c`. ## Done when (php-src-strict) - [ ] JIT/AOT repro matches VM/Zend on string type, length, prefix - [ ] `SessionCreateIdRuntime.php` ≤ thin trampoline; PR notes **LLVM lines removed** - [ ] `./script/docker-exec.sh -- bash -lc 'source script/php-env.sh && vendor/bin/phpunit --filter session_create_id_jit'` green - [ ] Session lifecycle compliance (**#6002**, **#9446**) unchanged ## Related - **#6002** · **#9446** session lifecycle · **#9495** SessionStorageRuntime · North star **#1492**
Category
php-in-php·stdlib· php-src-strictProblem
session_create_id()JIT useslib/JIT/Builtin/SessionCreateIdRuntime.php(~287 lines LLVM) with hex table + entropy logic duplicated from VM, althoughext/standard/VmSession.phpalready implements php-src semantics (php_session_create_id).Workers should route JIT/AOT through compiled PHP helpers (same pattern as #9495 SessionStorageRuntime, #9411 SessionGcRuntime).
php-src reference
ext/session/session.c—php_session_create_id, prefix handlingext/session/session.stub.php—session_create_id(?string $prefix = null): stringRepro (parity guard during migration)
$prefixScope (PHP-in-PHP first)
ext/standard/SessionCreateIdJitHelper.php(new)VmSession::createId()lib/JIT/Builtin/SessionCreateIdRuntime.phplib/JIT/Builtin/Type.php/ session batchtest/compliance/cases/stdlib/session_create_id_jit.phptForbidden: new session ID logic in
runtime/*.c.Done when (php-src-strict)
SessionCreateIdRuntime.php≤ thin trampoline; PR notes LLVM lines removed./script/docker-exec.sh -- bash -lc 'source script/php-env.sh && vendor/bin/phpunit --filter session_create_id_jit'greenRelated