Skip to content

AOT: fix native typed property fetch and asymmetric private(set) guard (#16354) - #16361

Merged
PurHur merged 1 commit into
masterfrom
agent/issue-16354-aot-asymmetric-private-set
Jul 5, 2026
Merged

PurHur merged 1 commit into
masterfrom
agent/issue-16354-aot-asymmetric-private-set

Conversation

@PurHur

@PurHur PurHur commented Jul 5, 2026

Copy link
Copy Markdown
Owner

Summary

Verification

./script/docker-exec.sh -- bash -lc 'PHP_COMPILER_PROFILE=8.4 php bin/vm.php test/repro/issue_16354_aot_asymmetric_private_set.php'
# 2 + caught: Cannot modify public private(set) property C::$x from global scope

./script/docker-exec.sh -- bash -lc 'PHP_COMPILER_PROFILE=8.4 ./phpc build -o /tmp/issue16354 test/repro/issue_16354_aot_asymmetric_private_set.php && /tmp/issue16354; echo exit=$?'
# 2 + caught (exit 0 when catch omits getMessage(); getMessage on caught Error in AOT remains a separate gap)

./script/docker-exec.sh -- bash -lc 'source script/php-env.sh && vendor/bin/phpunit --filter "AotTest::testCases.*asymmetric_visibility_public_private_set_int"'
# OK (1 test, 5 assertions)

./script/docker-exec.sh -- bash -lc 'source script/php-env.sh && vendor/bin/phpunit --filter "AotTest::testCases.*clone_object"'
# OK (1 test, 5 assertions)

PHP_COMPILER_PROFILE=8.4 php script/capability-syntax.php --check
# asymmetric visibility row AOT=yes

Closes #16354

Made with Cursor

Root cause: JIT loadValue returned heap pointers for TYPE_NATIVE_LONG
property slots instead of loaded scalars, and assignOperand promoted
property-fetch temporaries to boxed stack slots (dropping objectPropertySlot),
skipping AsymmetricVisibilityGuard on native-typed writes.

Co-authored-by: Cursor <cursoragent@cursor.com>
@PurHur
PurHur merged commit 371d61d into master Jul 5, 2026
@PurHur
PurHur deleted the agent/issue-16354-aot-asymmetric-private-set branch July 5, 2026 08:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

AOT: asymmetric private(set) property reads garbage and write guard never fires (#3165 regression)

1 participant