Pick a password longer than 72 bytes for a PHP app on the default hash. PHP keeps the first 72 and throws the rest away, without a word. Then it lets you log in with only part of it. This week someone proposed that PHP refuse instead, and the list can't agree it's worth the break.
Hello world, it's Thursday, October 1, 2026, and here's what happened This Week in PHP Internals. 14 stories this week, so let's get into it. But first,
I think we can all agree that the number of small, paid subscription services we're all being bombarded with is getting a little bit out of hand. And this is what Scalpels aims to solve. It's a collection of professionally built, open source alternatives to the parts you actually use of things like Private Packagist, Mailtrap and remove.bg. You fork them into your own GitHub organization and deploy them to your own Laravel Cloud account, so you're only paying for your own usage, it scales to zero when it's not being used, and you're not just feeding another company's profits. If you want updates, you just pull them down from upstream. And since it's your own fork, you have complete control over the code and the features. And it's all MIT. Find your next tool at scalpels.app.
Bcrypt Limit (01:19)
This week's top story is a password that's too long. Sjoerd Langkemper's new RFC targets password_hash with bcrypt, which silently drops everything past the 72nd byte. He'd make that a deprecation in 8.7 and a ValueError in 8.8. His case is FreshRSS, where a 64-character nonce went in front of the hash, so the 72 bytes held no password at all.
Kamil Tekiela replied that checking the length is the application's job, not the algorithm's, and Tim Düsterhus agreed in full. It's also 72 bytes, not characters, Tim noted, so non-ASCII passwords could hit it. Rowan Tommins answered: "If every PHP login implementation was reviewed by an expert senior developer, we would not need the password_* API in the first place. The value of this API is that it makes doing the right thing easy, so that you don't need to be an expert in the underlying algorithms to use it safely."
Robert Chapin showed a shortened password verifying against the full one's hash, and asked: "Is the function named password_verify going to verify the password or not?" Tim says the lost bytes are not where the risk is, and he wrote: "I don't necessarily disagree with the BCrypt truncation being a problem, but in this case the cure is worse than the disease." Derick Rethans is a minus 1, writing: "The problem for me is that this a scary BC break." Overnight, Sjoerd asked Derick what would win him over, maybe switching the default away from bcrypt first.
Links: bcrypt max password length RFC · thread · implementation · FreshRSS bcrypt truncation write-up (CVE-2025-68402) · password_hash() manual
Regex Object (03:00)
PHP's proposed regex object has broad support and one unpopular word in its name. Gina P. Banyard's CompiledRegex prototype drew 18 replies, and Sjoerd Langkemper was in favour of "improving the API, instead of slapping more flags onto the existing one." Larry Garfield wrote: "I would ask that we just call it Regex, not CompiledRegex." Casper Langemeijer, Jordi Kroon and Juris Evertovskis also want it to lose the Compiled.
Then there are the 8 boolean flags. Juris says named arguments already make them readable, Gina would rather pass an enum set, which PHP doesn't have yet, and Ayesh Karunaratne and Jordi Boggiano want a factory that takes the modifier letters you already know.
Osama Aldemeery, who wrote the regex exceptions RFC, pointed out what a compiled pattern can't catch, writing: "Compilation errors are only half of the error story...the other half happens at match time, on patterns that compiled just fine." Tim Düsterhus suggested passing the class could simply switch on throw-on-error, and Osama says he may park his RFC until Gina's reaches a vote.
Links: pre-RFC thread · prototype · PREG_THROW_ON_ERROR thread · composer/pcre, cited by Jordi Boggiano
Io Terminal (04:16)
PHP may finally read single key presses without shelling out to stty. Pratik Bhujel's terminal extension is now the Io\Terminal RFC for 8.7, covering terminal size, raw mode that restores itself, single keys and hidden input.
A Symfony Console pull request, approved by Nicolas Grekas, already uses the extension when it's installed, and Nicolas wrote: "PHP definitely needs native terminal support, calling stty is a workaround we've been carrying since way too long." Nicolas suggested raw mode stay on while any token for that terminal is alive and reset when the last one goes, and Pratik adopted it the same day.
Larry Garfield is in favour, but called false-on-error an anti-pattern and asked for a way to mock it. Version 0.3 makes Terminal the interface and SystemTerminal the native class. Pratik is giving it the full 14 days before an intent to vote.
Links: Io\Terminal RFC · thread · implementation · reference extension · Symfony Console PR using it
Time Instant (05:15)
The proposed Time\Instant class got a bridge back to DateTime this week. Tim Düsterhus and Derick Rethans added toInstant() to DateTime and DateTimeImmutable, and ISO strings now keep their trailing zeros, to show how precise the value is. They won't write the RFC for testing clocks, because they're not convinced it belongs in core, so Tim wrote: "we want to invite you (as the PHP internals community) to write the follow-up RFC for testing clocks". He also asked for a "LGTM, ship it" if people are happy.
Mirco Babin answered with 8 comments. One is that Time\Clock and the PSR-20 clock both define now(), so one class can't implement both. Tim is keeping now(), with a 15-year horizon in mind, but he'll discuss a single SystemClock::get() with Derick. And when Mirco asked for minute precision for bus timetables, Morgan replied: "Well, then it's not an instant, is it?"
Links: Time\Instant and Time\Clock RFC · thread · PSR-20 Clock
Array Shorthand (06:14)
Weilin Du wants PHP arrays to stop making you type every name twice. His new RFC turns =$x into 'x' => $x, in arrays, destructuring and foreach. It started with a colon and switched to the equals sign within the hour, because the colon clashes with the ternary.
Sebastian Bergmann will vote against, writing: "A syntax change should be backed by data, for instance an analysis of a representative body of real-world code." David Carlier showed that one missing comma would silently turn one valid program into another. Anton Smirnov pointed out that compact and extract still exist.
On the other side, Christian Schneider has run a local patch for this "for many years". Weilin pointed to the same pattern in Composer, Laravel, PHPUnit and Symfony, but says it already feels like he could withdraw the RFC.
Links: array shorthand RFC · thread · implementation
IO Hooks (07:14)
A new RFC would let ordinary blocking PHP run concurrently, without rewriting it. Jakub Zelenka's IO Hooks starts from the fact that PHP has had Fibers since 8.1, but every blocking function still blocks the whole process, so AMPHP, ReactPHP and Revolt reimplement IO themselves.
Under his proposal, blocking calls in streams, sockets, curl and the sleep functions get handed to a provider, usually an event loop, which suspends the Fiber until the IO is done. The RFC compares it to Go's runtime. With no provider installed, PHP behaves exactly as today. With one, sleep(1) in one Fiber is a second of work for the others.
It depends on a second RFC posted the same evening, Polling API Additions, which fills the gaps in 8.6's Poll API, like sockets, timers and signals. IO Hooks is in an early stage, and neither has replies yet.
Links: IO Hooks RFC · IO Hooks thread · proof of concept · Polling API Additions RFC · Polling API Additions thread
List Ban (08:14)
The internals list has removed a contributor. Sepehr Mahmoudi spent the last month posting new-function proposals. On September 15, Derick Rethans warned him over AI-generated content and the number of new threads. On September 21, Ilija Tovilo, as list moderator, set limits of one new thread a month and three emails a week, and called it a last warning. On Sunday Sepehr proposed another RFC, an intl_date_format function.
On Monday Derick confirmed that, after consultation off list, the address is blocked from emailing php.net, wiki access is withdrawn, and it's unsubscribed from the list.
And this is a tough one. It sucks having to take the nuclear option. He was clearly eager to help, but the list had spent literal weeks trying to get him to slow down, and to stop burdening the list with AI responses, and at some point you've got to enforce the consequences that have been laid out.
Links: thread · Derick Rethans, Sep 28 (news-web)
Quick Hits (09:18)
Quick hits. PHP 8.6.0 RC2 is out. RC1 was skipped over a packaging error, so RC2 is the first release candidate, and RC3 is due October 8.
Links: PHP 8.6.0RC2 · why RC1 was skipped
The same day brought security releases for 8.5, 8.4, 8.3 and 8.2.
Links: PHP 8.5.11 · PHP 8.4.26, 8.3.35, 8.2.34
Sjoerd Langkemper changed his number-base RFC to throw a plain Exception instead of a ValueError, since bad input isn't necessarily a bug in your program. intval stays as it is.
Links: number-base functions RFC · thread
Juliette Reinders Folmer wants to deprecate the b string prefix, a leftover from PHP 6, and Tim suggested adding it to the 8.7 deprecations RFC.
Links: deprecate the b prefix · 8.7 deprecations RFC
Pedro Veloso floated a #[Pure] attribute the engine would enforce. Larry Garfield said it needs to do more than the static analysers already do, like memoizing.
Links: pure functions idea
Karoly Negyesi posted a pre-RFC with an implementation for implements … by, which hands an interface's methods to a property, modelled on Kotlin.
Links: automated delegation pre-RFC · implementation
And Alexander Danilov found that much of post-quantum OpenSSL already works in PHP, and offered small PRs for the gaps.
Links: OpenSSL post-quantum
And the PEAR vote Nick S. planned for September 28 hasn't opened. The RFC is still in discussion.
Links: End PEAR Project Endorsement RFC
TL;DR (10:36)
So that's the week. An RFC wants bcrypt to refuse passwords past 72 bytes, and the list is split on whether it's worth the break. Several replies want the regex object called just Regex, Io\Terminal is an RFC, and Time\Instant is looking for someone to write testing clocks. The array shorthand met skeptics, and IO Hooks would make blocking code concurrent. The list also removed a contributor after two warnings. Nothing is in voting for a 7th straight week. Links below.
The PHP Foundation funds more than half of ongoing php-src commits, so if you use the language, maybe consider donating at opencollective.com/phpfoundation — or try guilting your employer into it.
If you found this useful, a like or a comment helps more people find it. And if you missed last week's episode — where a new time class couldn't tell you what time it is — that's a good one to watch next. Thanks again to Scalpels.app for supporting this week's episode. We're Artisan Build. See you next week.
Top comments (0)