Category
php-in-php · stdlib · php-src-strict
Problem
password_hash() / password_verify() / password_get_info() VM semantics live in PHP (ext/standard/VmPassword.php, VmPasswordNative.php libcrypt FFI), but JIT/AOT still emit a ~917-line LLVM module via lib/JIT/Builtin/StringPasswordCryptoJit.php (lib/JIT/Builtin/StringPasswordCrypto.php).
This duplicates bcrypt/argon2 option parsing, salt generation, and verify loops in LLVM — blocks self-host M5 (#1492) and risks VM/JIT drift on PASSWORD_* constants, invalid algo ValueError, and enum-case operands (#6267).
php-src reference
Repro
<?php
$hash = password_hash('secret', PASSWORD_BCRYPT, ['cost' => 4]);
var_export(password_verify('secret', $hash));
echo "\n";
var_export(password_get_info($hash)['algoName'] ?? null);
echo "\n";
./script/docker-exec.sh -- bash -lc 'source script/php-env.sh
php bin/vm.php test/repro-maintainer/password_hash_smoke.php 2>&1 || php bin/vm.php -r "
\$h = password_hash(\"secret\", PASSWORD_BCRYPT, [\"cost\" => 4]);
var_export(password_verify(\"secret\", \$h)); echo PHP_EOL;
"
php bin/jit.php -r "
\$h = password_hash(\"secret\", PASSWORD_BCRYPT, [\"cost\" => 4]);
var_export(password_verify(\"secret\", \$h)); echo PHP_EOL;
" 2>&1 | head -5
'
| Check |
VM (VmPassword) |
JIT (StringPasswordCryptoJit) |
password_verify true |
expected |
must match after migration |
| Invalid algo |
ValueError |
same message (not LogicException) |
Scope (PHP-in-PHP first)
| Layer |
Path |
| PHP SSOT |
ext/standard/VmPassword.php, PasswordJitHelper.php (extend) |
| LLVM to shrink |
lib/JIT/Builtin/StringPasswordCryptoJit.php, StringPasswordCrypto.php |
| Thin ABI |
Keep libcrypt FFI in VmPasswordNative.php only — no new runtime/*.c |
| Tests |
test/compliance/cases/stdlib/password_hash*.phpt |
Done when
Verification
./script/docker-exec.sh -- bash -lc 'source script/php-env.sh && ./script/ci-fast.sh --filter password_hash'
Related
Category
php-in-php·stdlib· php-src-strictProblem
password_hash()/password_verify()/password_get_info()VM semantics live in PHP (ext/standard/VmPassword.php,VmPasswordNative.phplibcrypt FFI), but JIT/AOT still emit a ~917-line LLVM module vialib/JIT/Builtin/StringPasswordCryptoJit.php(lib/JIT/Builtin/StringPasswordCrypto.php).This duplicates bcrypt/argon2 option parsing, salt generation, and verify loops in LLVM — blocks self-host M5 (#1492) and risks VM/JIT drift on
PASSWORD_*constants, invalid algoValueError, and enum-case operands (#6267).php-src reference
ext/standard/password.c—php_password_hash,php_password_verify,php_password_get_infoext/standard/crypt.c—crypt()when routed through password layerRepro
VmPassword)StringPasswordCryptoJit)password_verifytrueValueErrorLogicException)Scope (PHP-in-PHP first)
ext/standard/VmPassword.php,PasswordJitHelper.php(extend)lib/JIT/Builtin/StringPasswordCryptoJit.php,StringPasswordCrypto.phpVmPasswordNative.phponly — no newruntime/*.ctest/compliance/cases/stdlib/password_hash*.phptDone when
password_hash/password_verify/password_get_infocall compiled PHP helpers (same as VM)StringPasswordCryptoJit.phpLLVM removed or reduced to trampoline; PR cites lines deletedTypeErrorunder php-src-strict on VM and JIT./script/ci-fast.sh --filter password_hashgreenVerification
./script/docker-exec.sh -- bash -lc 'source script/php-env.sh && ./script/ci-fast.sh --filter password_hash'Related