Home » Releases » 5.4 » 5.4.45 »

PHP 5.4.0

PHP 5.4 is no longer officially supported by the PHP project.

Official support refers to that provided direct by the PHP Project.

If you install PHP via third-party packages, support timelines may be different. Please read the Release Support Policy for more information.

The latest release of PHP 5.4 is 5.4.45.

Source Code

Change Log

  • installation

    • autoconf 2.59+ is now supported (and required) for generating the configure script with ./buildconf. Autoconf 2.60+ is desirable otherwise the configure help order may be incorrect.
      Rasmus
      Chris Jones
  • removed legacy features

    • break/continue $var syntax.
      Dmitry
    • Safe mode and all related php.ini options.
      Kalle
    • register_globals and register_long_arrays php.ini options.
      Kalle
    • import_request_variables().
      Kalle
    • allow_call_time_pass_reference.
      Pierrick
    • define_syslog_variables php.ini option and its associated function.
      Kalle
    • highlight.bg php.ini option.
      Kalle
    • safe_mode, safe_mode_gid, safe_mode_include_dir, safe_mode_exec_dir, safe_mode_allowed_env_vars and safe_mode_protected_env_vars php.ini options.
    • zend.ze1_compatibility_mode php.ini option.
    • Session bug compatibility mode (session.bug_compat_42 and session.bug_compat_warn php.ini options).
      Kalle
    • session_is_registered(), session_register() and session_unregister() functions.
      Kalle
    • y2k_compliance php.ini option.
      Kalle
    • magic_quotes_gpc, magic_quotes_runtime and magic_quotes_sybase php.ini options. get_magic_quotes_gpc, get_magic_quotes_runtime are kept but always return false, set_magic_quotes_runtime raises an E_CORE_ERROR.
      Pierrick
      Pierre
    • Removed support for putenv("TZ=..") for setting the timezone.
      Derick
    • Removed the timezone guessing algorithm in case the timezone isn't set with date.timezone or date_default_timezone_set(). Instead of a guessed timezone, "UTC" is now used instead.
      Derick
  • moved extensions to pecl

    • ext/sqlite.
      Note: the ext/sqlite3 and ext/pdo_sqlite extensions are not affected) (Johannes
  • general improvements

    • Added short array syntax support ([1,2,3]), see UPGRADING guide for full details.
      rsky0711 at gmail . com
      sebastian.deutsch at 9elements . com
      Pierre
    • Added binary number format (0b001010).
      Jonah dot Harris at gmail dot com
    • Added support for Class::{expr}() syntax (Pierrick)
    • Added multibyte support by default. Previously PHP had to be compiled with --enable-zend-multibyte. Now it can be enabled or disabled through the zend.multibyte directive in php.ini.
      Dmitry
    • Removed compile time dependency from ext/mbstring (Dmitry)
    • Added support for Traits.
      Stefan
      with fixes by Dmitry and Laruence
    • Added closure $this support back.
      Stas
    • Added array dereferencing support.
      Felipe
    • Added callable typehint.
      Hannes
    • Added indirect method call through array. FR #47160.
      Felipe
    • Added DTrace support.
      David Soria Parra
    • Added class member access on instantiation (e.g.
      new foo)->bar()) support. (Felipe
    • <?= is now always available regardless of the short_open_tag setting.
      Rasmus
    • Implemented Zend Signal Handling (configurable option --enable-zend-signals, off by default).
      Lucas Nealan
      Arnaud Le Blanc
      Brian Shire
      Ilia
    • Improved output layer, see README.NEW-OUTPUT-API for internals.
      Mike
    • Improved UNIX build system to allow building multiple PHP binary SAPIs and one SAPI module the same time. FR #53271, FR #52419.
      Jani
    • Implemented closure rebinding as parameter to bindTo.
      Gustavo Lopes
    • Improved the warning message of incompatible arguments.
      Laruence
    • Improved ternary operator performance when returning arrays.
      Arnaud
      Dmitry
    • Changed error handlers to only generate docref links when the docref_root php.ini setting is not empty.
      Derick
    • Changed silent conversion of array to string to produce a notice.
      Patrick
    • Changed default encoding from ISO-8859-1 to UTF-8 when not specified in htmlspecialchars and htmlentities.
      Rasmus
    • Changed casting of null/''/false into an Object when adding a property from E_STRICT into a warning.
      Scott
    • Changed E_ALL to include E_STRICT.
      Stas
    • Disabled Windows CRT warning by default, can be enabled again using the php.ini directive windows_show_crt_warnings.
      Pierre
    • Fixed bug #55378: Binary number literal returns float number though its value is small enough.
      Derick
    • Improved Zend Engine memory usage: (Dmitry)
    • Improved parse error messages.
      Felipe
    • Replaced zend_function.pass_rest_by_reference by ZEND_ACC_PASS_REST_BY_REFERENCE in zend_function.fn_flags.
    • Replaced zend_function.return_reference by ZEND_ACC_RETURN_REFERENCE in zend_function.fn_flags.
    • Removed zend_arg_info.required_num_args as it was only needed for internal functions. Now the first arg_info for internal functions (which has special meaning) is represented by the zend_internal_function_info structure.
    • Moved zend_op_array.size, size_var, size_literal, current_brk_cont, backpatch_count into CG(context) as they are used only during compilation.
    • Moved zend_op_array.start_op into EG(start_op) as it's used only for 'interactive' execution of a single top-level op-array.
    • Replaced zend_op_array.done_pass_two by ZEND_ACC_DONE_PASS_TWO in zend_op_array.fn_flags.
    • op_array.vars array is trimmed (reallocated) during pass_two.
    • Replaced zend_class_entry.constants_updated by ZEND_ACC_CONSTANTS_UPDATED in zend_class_entry.ce_flags.
    • Reduced the size of zend_class_entry by sharing the same memory space by different information for internal and user classes. See zend_class_entry.info union.
    • Reduced size of temp_variable.
    • Improved Zend Engine - performance tweaks and optimizations: (Dmitry)
    • Inlined most probable code-paths for arithmetic operations directly into executor.
    • Eliminated unnecessary iterations during request startup/shutdown.
    • Changed $GLOBALS into a JIT autoglobal, so it's initialized only if used.
      this may affect opcode caches!
    • Improved performance of @ (silence) operator.
    • Simplified string offset reading. Given $str="abc" then $str[1][0] is now a legal construct.
    • Added caches to eliminate repeatable run-time bindings of functions, classes, constants, methods and properties.
    • Added concept of interned strings. All strings constants known at compile time are allocated in a single copy and never changed.
    • ZEND_RECV now always has IS_CV as its result.
    • ZEND_CATCH now has to be used only with constant class names.
    • ZEND_FETCH_DIM_? may fetch array and dimension operands in different order.
    • Simplified ZEND_FETCH_*_R operations. They can't be used with the EXT_TYPE_UNUSED flag any more. This is a very rare and useless case. ZEND_FREE might be required after them instead.
    • Split ZEND_RETURN into two new instructions ZEND_RETURN and ZEND_RETURN_BY_REF.
    • Optimized access to global constants using values with pre-calculated hash_values from the literals table.
    • Optimized access to static properties using executor specialization. A constant class name may be used as a direct operand of ZEND_FETCH_* instruction without previous ZEND_FETCH_CLASS.
    • zend_stack and zend_ptr_stack allocation is delayed until actual usage.
  • other improvements to zend engine

    • Added an optimization which saves memory and emalloc/efree calls for empty HashTables.
      Stas
      Dmitry
    • Added ability to reset user opcode handlers (Yoram).
    • Changed the structure of op_array.opcodes. The constant values are moved from opcode operands into a separate literal table.
      Dmitry
    • Fixed (disabled) inline-caching for ZEND_OVERLOADED_FUNCTION methods.
      Dmitry
  • improved core functions

    • Enforce an extended class' __construct arguments to match the abstract constructor in the base class.
    • Disallow reusing superglobal names as parameter names.
    • Added optional argument to debug_backtrace() and debug_print_backtrace() to limit the amount of stack frames returned.
      Sebastian
      Patrick
    • Added hex2bin() function.
      Scott
    • number_format() no longer truncates multibyte decimal points and thousand separators to the first byte. FR #53457.
      Adam
    • Added support for object references in recursive serialize() calls. FR #36424.
      Mike
    • Added support for SORT_NATURAL and SORT_FLAG_CASE in array sort functions (sort, rsort, ksort, krsort, asort, arsort and array_multisort). FR#55158 (Arpad)
    • Added stream metadata API support and stream_metadata() stream class handler.
      Stas
    • User wrappers can now define a stream_truncate() method that responds to truncation, e.g. through ftruncate(). FR #53888.
      Gustavo
    • Improved unserialize() performance.
      galaxy dot mipt at gmail dot com
      Kalle
    • Changed array_combine() to return empty array instead of FALSE when both parameter arrays are empty. FR #34857.
      joel.perras@gmail.com
    • Fixed bug #61095 (Incorect lexing of 0x00*+<NUM>).
      Etienne
    • Fixed bug #60965 (Buffer overflow on htmlspecialchars/entities with $double=false).
      Gustavo
    • Fixed bug #60895 (Possible invalid handler usage in windows random functions).
      Pierre
    • Fixed bug #60879 (unserialize() Does not invoke __wakeup() on object).
      Pierre
      Steve
    • Fixed bug #60825 (Segfault when running symfony 2 tests).
      Dmitry
      Laruence
    • Fixed bug #60627 (httpd.worker segfault on startup with php_value).
    • Fixed bug #60613 (Segmentation fault with $cls->{expr}() syntax).
      Dmitry
    • Fixed bug #60611 (Segmentation fault with Cls::{expr}() syntax).
      Laruence) (Laruence
    • Fixed bug #60558 (Invalid read and writes).
      Laruence
    • Fixed bug #60444 (Segmentation fault with include & class extending). (Laruence, Dmitry).
    • Fixed bug #60362 (non-existent sub-sub keys should not have values).
      Laruence
      alan_k
      Stas
    • Fixed bug #60350 (No string escape code for ESC (ascii 27), normally \e).
      php at mickweiss dot com
    • Fixed bug #60321 (ob_get_status(true) no longer returns an array when buffer is empty).
      Pierrick
    • Fixed bug #60282 (Segfault when using ob_gzhandler() with open buffers).
      Laruence
    • Fixed bug #60240 (invalid read/writes when unserializing specially crafted strings).
      Mike
    • Fixed bug #60227 (header() cannot detect the multi-line header with CR(0x0D)).
      rui
    • Fixed bug #60174 (Notice when array in method prototype error).
      Laruence
    • Fixed bug #60169 (Conjunction of ternary and list crashes PHP).
      Laruence
    • Fixed bug #60038 (SIGALRM cause segfault in php_error_cb).
      Laruence) (klightspeed at netspace dot net dot au
    • Fixed bug #55871 (Interruption in substr_replace()).
      Stas
    • Fixed bug #55801 (Behavior of unserialize has changed).
      Mike
    • Fixed bug #55758 (Digest Authenticate missed in 5.4) .
      Laruence
    • Fixed bug #55748 (multiple NULL Pointer Dereference with zend_strndup()) (CVE-2011-4153).
      Stas
    • Fixed bug #55124 (recursive mkdir fails with current (dot) directory in path).
      Pierre
    • Fixed bug #55084 (Function registered by header_register_callback is called only once per process).
      Hannes
    • Implement FR #54514 (Get php binary path during script execution).
      Laruence
    • Fixed bug #52211 (iconv() returns part of string on error).
      Felipe
    • Fixed bug #51860 (Include fails with toplevel symlink to /).
      Dmitry
  • improved generic sapi support

    • Added $_SERVER['REQUEST_TIME_FLOAT'] to include microsecond precision.
      Patrick
    • Added header_register_callback() which is invoked immediately prior to the sending of headers and after default headers have been added.
      Scott
    • Added http_response_code() function. FR #52555.
      Paul Dragoonis
      Kalle
    • Fixed bug #55500 (Corrupted $_FILES indices lead to security concern).
      CVE-2012-1172). (Stas
    • Fixed bug #54374 (Insufficient validating of upload name leading to corrupted $_FILES indices).
      CVE-2012-1172). (Stas
      lekensteyn at gmail dot com
  • improved cli sapi

    • Added built-in web server that is intended for testing purpose.
      Moriyoshi
      Laruence
      and fixes by Pierre
      Derick
      Arpad
      chobieee at gmail dot com
    • Added command line option --rz <name> which shows information of the named Zend extension.
      Johannes
    • Interactive readline shell improvements: (Johannes)
    • Added "cli.pager" php.ini setting to set a pager for output.
    • Added "cli.prompt" php.ini setting to configure the shell prompt.
    • Added shortcut #inisetting=value to change php.ini settings at run-time.
    • Changed shell not to terminate on fatal errors.
    • Interactive shell works with shared readline extension. FR #53878.
    • Improved CGI/FastCGI SAPI: (Dmitry)
    • Added apache compatible functions: apache_child_terminate(), getallheaders(), apache_request_headers() and apache_response_headers()
    • Improved performance of FastCGI request parsing.
    • Fixed reinitialization of SAPI callbacks after php_module_startup().
      Dmitry
  • improved php-fpm sapi

    • Removed EXPERIMENTAL flag.
      fat
    • Fixed bug #60659 (FPM does not clear auth_user on request accept).
      bonbons at linux-vserver dot org
  • improved litespeed sapi

    • Fixed bug #55769 (Make Fails with "Missing Separator" error).
      Adam
  • improved date extension

    • Added the + modifier to parseFromFormat to allow trailing text in the string to parse without throwing an error.
      Stas
      Derick
  • improved dba extension

    • Added Tokyo Cabinet abstract DB support.
      Michael Maclean
    • Added Berkeley DB 5 support.
      Johannes
      Chris Jones
  • improved dom extension

    • Added the ability to pass options to loadHTML (Chregu, fxmulder at gmail dot com)
  • improved filesystem functions

    • scandir() now accepts SCANDIR_SORT_NONE as a possible sorting_order value. FR #53407.
      Adam
  • improved hash extension

    • Added Jenkins's one-at-a-time hash support.
      Martin Jansen
    • Added FNV-1 hash support.
      Michael Maclean
    • Made Adler32 algorithm faster. FR #53213.
      zavasek at yandex dot ru
    • Removed Salsa10/Salsa20, which are actually stream ciphers (Mike)
    • Fixed bug #60221 (Tiger hash output byte order) (Mike)
  • improved intl extension

    • Added Spoofchecker class, allows checking for visibly confusable characters and other security issues.
      Scott
    • Added Transliterator class, allowing transliteration of strings.
      Gustavo
    • Added support for UTS #46.
      Gustavo
    • Fixed build on Fedora 15 / Ubuntu 11.
      Hannes
    • Fixed bug #55562 (grapheme_substr() returns false on big length).
      Stas
  • improved json extension

    • Added new json_encode() option JSON_UNESCAPED_UNICODE. FR #53946.
      Alexander
      Gwynne
    • Added JsonSerializable interface.
      Sara
    • Added JSON_BIGINT_AS_STRING, extended json_decode() sig with $options.
      Sara
    • Added support for JSON_NUMERIC_CHECK option in json_encode() that converts numeric strings to integers.
      Ilia
    • Added new json_encode() option JSON_UNESCAPED_SLASHES. FR #49366.
      Adam
    • Added new json_encode() option JSON_PRETTY_PRINT. FR #44331.
      Adam
  • improved ldap extension

    • Added paged results support. FR #42060.
      ando@OpenLDAP.org
      iarenuno@eteo.mondragon.edu
      jeanseb@au-fil-du.net
      remy.saissy@gmail.com
  • improved mbstring extension

    • Added Shift_JIS/UTF-8 Emoji (pictograms) support.
      Rui
    • Added JIS X0213:2004 (Shift_JIS-2004, EUC-JP-2004, ISO-2022-JP-2004) support.
      Rui
    • Ill-formed UTF-8 check for security enhancements.
      Rui
    • Added MacJapanese (Shift_JIS) and gb18030 encoding support.
      Rui
    • Added encode/decode in hex format to mb_[en|de]code_numericentity().
      Rui
    • Added user JIS X0213:2004 (Shift_JIS-2004, EUC-JP-2004, ISO-2022-JP-2004) support.
      Rui
    • Added the user defined area for CP936 and CP950 (Rui).
    • Fixed bug #60306 (Characters lost while converting from cp936 to utf8).
      Laruence
  • improved mysql extensions

    • MySQL: Deprecated mysql_list_dbs(). FR #50667.
      Andrey
    • mysqlnd: Added named pipes support. FR #48082.
      Andrey
    • MySQLi: Added iterator support in MySQLi. mysqli_result implements Traversable.
      Andrey
      Johannes
    • PDO_mysql: Removed support for linking with MySQL client libraries older than 4.1.
      Johannes
    • ext/mysql, mysqli and pdo_mysql now use mysqlnd by default.
      Johannes
    • Fixed bug #55473 (mysql_pconnect leaks file descriptors on reconnect).
      Andrey
      Laruence
    • Fixed bug #55653 (PS crash with libmysql when binding same variable as param and out).
      Laruence
  • improved openssl extension

    • Added AES support. FR #48632.
      yonas dot y at gmail dot com
      Pierre
    • Added no padding option to openssl_encrypt()/openssl_decrypt().
      Scott
    • Use php's implementation for Windows Crypto API in openssl_random_pseudo_bytes.
      Pierre
    • On error in openssl_random_pseudo_bytes() made sure we set strong result to false.
      Scott
    • Fixed possible attack in SSL sockets with SSL 3.0 / TLS 1.0. CVE-2011-3389.
      Scott
    • Fixed bug #61124 (Crash when decoding an invalid base64 encoded string).
      me at ktamura dot com
      Scott
  • improved pdo

    • Fixed PDO objects binary incompatibility.
      Dmitry
  • pdo dblib driver

    • Added nextRowset support.
    • Fixed bug #50755 (PDO DBLIB Fails with OOM).
  • improved postgresql extension

    • Added support for "extra" parameter for PGNotify().
      r dot i dot k at free dot fr
      Ilia
  • improved pcre extension

    • Changed third parameter of preg_match_all() to optional. FR #53238.
      Adam
  • improved readline extension

    • Fixed bug #54450 (Enable callback support when built against libedit).
      fedora at famillecollet dot com
      Hannes
  • improved reflection extension

    • Added ReflectionClass::newInstanceWithoutConstructor() to create a new instance of a class without invoking its constructor. FR #55490.
      Sebastian
    • Added ReflectionExtension::isTemporary() and ReflectionExtension::isPersistent() methods.
      Johannes
    • Added ReflectionZendExtension class.
      Johannes
    • Added ReflectionClass::isCloneable().
      Felipe
  • improved session extension

    • Expose session status via new function, session_status (FR #52982) (Arpad)
    • Added support for object-oriented session handlers.
      Arpad
    • Added support for storing upload progress feedback in session data.
      Arnaud
    • Changed session.entropy_file to default to /dev/urandom or /dev/arandom if either is present at compile time.
      Rasmus
    • Fixed bug #60860 (session.save_handler=user without defined function core dumps).
      Felipe
    • Implement FR #60551 (session_set_save_handler should support a core's session handler interface).
      Arpad
    • Fixed bug #60640 (invalid return values).
      Arpad
  • improved snmp extension (boris lytochkin)

    • Added OO API. FR #53594 (php-snmp rewrite).
    • Sanitized return values of existing functions. Now it returns FALSE on failure.
    • Allow ~infinite OIDs in GET/GETNEXT/SET queries. Autochunk them to max_oids upon request.
    • Introducing unit tests for extension with ~full coverage.
    • IPv6 support.
      FR #42918
    • Way of representing OID value can now be changed when SNMP_VALUE_OBJECT is used for value output mode. Use or'ed SNMP_VALUE_LIBRARY(default if not specified) or SNMP_VALUE_PLAIN.
      FR #54502
    • Fixed bug #60749 (SNMP module should not strip non-standard SNMP port from hostname).
      Boris Lytochkin
    • Fixed bug #60585 (php build fails with USE flag snmp when IPv6 support is disabled).
      Boris Lytochkin
    • Fixed bug #53862 (snmp_set_oid_output_format does not allow returning to default)
    • Fixed bug #46065 (snmp_set_quick_print() persists between requests)
    • Fixed bug #45893 (Snmp buffer limited to 2048 char)
    • Fixed bug #44193 (snmp v3 noAuthNoPriv doesn't work)
  • improved soap extension

    • Added new SoapClient option "keep_alive". FR #60329.
      Pierrick
    • Fixed basic HTTP authentication for WSDL sub requests.
      Dmitry
  • improved spl extension

    • Added RegexIterator::getRegex() method.
      Joshua Thijssen
    • Added SplObjectStorage::getHash() hook.
      Etienne
    • Added CallbackFilterIterator and RecursiveCallbackFilterIterator.
      Arnaud
    • Added missing class_uses(..) as pointed out by #55266 (Stefan)
    • Immediately reject wrong usages of directories under Spl(Temp)FileObject and friends.
      Etienne
      Pierre
    • FilesystemIterator, GlobIterator and (Recursive)DirectoryIterator now use the default stream context.
      Hannes
    • Fixed bug #60201 (SplFileObject::setCsvControl does not expose third argument via Reflection).
      Peter
    • Fixed bug #55287 (spl_classes() not includes CallbackFilter classes) (sasezaki at gmail dot com, salathe)
  • improved sysvshm extension

    • Fixed bug #55750 (memory copy issue in sysvshm extension).
      Ilia
      jeffhuang9999 at gmail dot com
  • improved tidy extension

    • Fixed bug #54682 (Tidy::diagnose() NULL pointer dereference).
      Maksymilian Arciemowicz
      Felipe
  • improved tokenizer extension

    • Fixed bug #54089 (token_get_all with regards to __halt_compiler is not binary safe).
      Nikita Popov
  • improved xsl extension

    • Added XsltProcessor::setSecurityPrefs($options) and getSecurityPrefs() to define forbidden operations within XSLT stylesheets, default is not to enable write operations from XSLT. Bug #54446 (Chregu, Nicolas Gregoire)
    • XSL doesn't stop transformation anymore, if a PHP function can't be called (Christian)
  • improved zlib extension

    • Re-implemented non-file related functionality.
      Mike
    • Fixed bug #55544 (ob_gzhandler always conflicts with zlib.output_compression).
      Mike

PHP 5.4


  Represents a security release