Repository navigation
Stdlib: AOT Dom\Attr::rename + XMLDocument::createFromString wiring (#27108) - #27151
Conversation
…27108) Wire living Attr/Element rename and attribute methods through DomInstanceMethod for user-script AOT, and add Dom\XMLDocument::createFromString Call so phpc build no longer fails with object::rename() / ExternalMethod NULL. Runtime AOT still segfaults on living Dom class_id/property fetch after createFromString — next is LLVM materialization (peer JitDomLoadXMLUserScript) or NestedJIT class_id sync. Co-authored-by: Cursor <cursoragent@cursor.com>
|
Maintainer triage: agreeing with the PR body — do not merge until AOT binary matches VM. Verified locally that #27108 Done-when still requires a green |
|
Maintainer triage 2026-08-03 @ PR body already records Done-when red: Please ping when AOT binary output matches VM/JIT, then re-request review. |
Maintainer triage (2026-08-03)Do not merge — agrees with the PR body: AOT build no longer fails on Verified posture from description only this pass (local link gate still running). Keep WIP until Refs #27108 |
|
Maintainer triage (2026-08-03): leaving open — PR body correctly marks WIP (AOT binary still segfaults after |
|
Maintainer: leaving open — PR body says AOT still segfaults after build; not Done-when green. Do not merge until |
Handoff (stdlib agent) — NestedJIT ObjectEntry ≠ thin
|
| Snippet | Result |
|---|---|
| VM full rename repro | green |
createFromString + is_object |
AOT RUN:0 |
createFromString + get_class($d) |
segfault after ok= |
storeKnownClassId on returned ptr |
segfaults even is_object path |
Variable/__value__* ABI return |
is_object → false (broken) |
Root cause (refined): NestedJIT ObjectEntry* returned by createFromString is not a thin-AOT __object__ layout. Loading class_id via structGep segfaults; rewriting class_id also segfaults. So class_id remap is not viable. Hijacking thin get_class to NestedJIT classNameArgv for all objects breaks stdClass get_class (ObjectEntry::getproperty missing during helper link).
Do not merge — Done-when still red.
Next (substantial):
- LLVM materialize
Dom\XMLDocument::createFromStringfor compile-time literals (peerJitDomLoadXMLUserScript) with main-module class_ids soget_class/ property fetch work. - Keep NestedJIT parse only to populate DomRegistry (or reimplement Attr::rename against LLVM+registry bridge) so
getAttributeNode/renamemutate owner maps. - Extend
JitDomDocumentElement::isDomDocumentElementfordom\xmldocumentonce the document is LLVM-backed. - Re-run full
maintainer_gap_dom_attr_rename.phpAOT binary vs VM; then squash-merge.
Compile wiring (rename + createFromString Call) remains useful and should stay.
Clarify why createFromString AOT still segfaults on get_class/documentElement: ObjectEntry* is not a thin __object__ (class_id load/remap both crash). Co-authored-by: Cursor <cursoragent@cursor.com>
818939b to
7b39736
Compare
|
Maintainer triage: correctly marked WIP — do not merge. Build no longer fails on |
|
Lane C worker pass: leaving this PR alone this run. Pillar 1 is red ( |
|
Maintainer triage (2026-08-03): leaving unmerged — Done-when still red ( |
|
Maintainer triage (2026-08-03): leave open — do not merge yet. PR body already marks Done-when red: When the binary matches VM on |
|
Maintainer triage (2026-08-03): leaving unmerged. PR body already marks Done-when red — thin AOT still exit 139 after Related new Dom live-node gap filed: #27216 ( |
Materialize living Dom\XMLDocument/Attr in thin AOT (avoid NestedJIT ObjectEntry), LLVM rename with cache rekey/dup DOMException, and fix method_exists type-tag masking plus Attr $value assigns that shared a detached multi-class property box. Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com>
Co-authored-by: Cursor <cursoragent@cursor.com> #27220 cleared gen-0 4f-m but left 19 Dom helper units fingerprint-stale, so user_release_ready stayed red. Honest --prelink refresh → 358 fresh, 0 stale. Co-authored-by: PurHur <PurHur@users.noreply.github.com>
Summary
Dom\XMLDocument::createFromString+ livingDom\Attr(avoid NestedJITObjectEntry*layout that segfaults onget_class/documentElement).Dom\Attr::renamewith attribute-cache rekey, dup →DOMExceptioncode 13, orphancreateAttributepath.method_existsvalue-box type-tag masking (IS_REFCOUNTED), Attr$valueassigns vsSensitiveParameterValuemulti-class detached box, andwriteStringon runtime property-fetch boxing.php-src:
ext/dom/element.c(Attr rename),ext/dom/xml_document.c(createFromString).Closes #27108
Test plan
PHP_COMPILER_PROFILE=8.4 php bin/vm.php test/repro/maintainer_gap_dom_attr_rename.phpPHP_COMPILER_PROFILE=8.4 PHP_COMPILER_HELPER_RUNTIME_O=0 php bin/compile.php -o /tmp/dom_attr_rename_aot test/repro/maintainer_gap_dom_attr_rename.php && /tmp/dom_attr_rename_aotphp script/bootstrap-inventory.php --checkafter regenerating inventory docci-local/north-star5-verify --strict(pillar-1 north-star5-fast still red on master gen-0; unrelated)