Sign in

TimWolla

@timwolla.bsky.social
17 followers 21 following 20 posts
PostsRepliesMedia
TimWolla @timwolla.bsky.social · 30/05/2026
Oh come on. Calling this an auth bypass when this requires using a hash algorithm that is not considered reasonable for password storage for several decades and when there is password_verify() in PHP's stdlib for almost 15 years is not helping anyone write better code.
000
Reposted by TimWolla
The PHP Foundation @thephpf.bsky.social · 27/02/2026
We’re excited to welcome Elizabeth Barron as the new Executive Director of The PHP Foundation! 🐘 💜 Elizabeth brings PHP community roots, open-source governance experience from GitHub & CHAOSS, and a passion for making PHP thrive for decades to come. thephp.foundation/blog/2026/02... #php #phpc
thephp.foundation
Welcoming Elizabeth Barron as the New Executive Director of The PHP Foundation
The PHP Foundation — Supporting, Advancing, and Developing the PHP Language
095
TimWolla @timwolla.bsky.social · 24/11/2025
Yeah and unfortunately folks rely on `parse_url()`'s bespoke behavior which makes it hard to impossible to fix without someone calling in with xkcd.com/1172/, particularly in a patch release. I hope folks migrate to the new URI extension quickly.
xkcd.com
Workflow
250
Reposted by TimWolla
The PHP Foundation @thephpf.bsky.social · 27/10/2025
🗳️ Voting for the PHP 8.5 Release Page Contest is live! Check out the shortlisted designs and vote for your favorite with 👍 on GitHub: github.com/php/web-php/... Voting closes Nov 2 — winner announced Nov 4 💜
github.com
🗳️ [VOTING] PHP 8.5 Release Page Design Contest · Issue #1563 · php/web-php
A huge thank you to everyone who submitted their designs! Together with the jury we carefully reviewed all entries and selected a shortlist. Our main criteria were how well the task was understood,...
034
Reposted by TimWolla
The PHP Foundation @thephpf.bsky.social · 10/10/2025
Say goodbye to parse_url() headaches! 🥳 PHP 8.5 is introducing a new URI Extension with standards-compliant (RFC 3986 & WHATWG) and secure URL parsing. It provides a clean API and lets you easily modify URI components. Learn more 👇 thephp.foundation/blog/2025/10...
thephp.foundation
PHP’s New URI Extension: An Open Source Success Story
The PHP Foundation — Supporting, Advancing, and Developing the PHP Language
01912
Reposted by TimWolla
Alexandre Daubois @alexdaubois.bsky.social · 22/07/2025
⚙️ #PHP 8.5 sees its cloning supercharged! With the "clone with" RFC merged 5 days ago, we have much more possibilities when it comes to cloning objects. Supports hooks, readonly, __clone() overriding. Thanks @timwolla.bsky.social for the #DX improvement! 👏 PR: github.com/php/php-src/...
122
TimWolla @timwolla.bsky.social · 22/07/2025
For this one I mainly contributed the implementation. @edorian.bsky.social made the decisions and a large part of the discussion :-)
020
Reposted by TimWolla
Alexandre Daubois @alexdaubois.bsky.social · 18/07/2025
🚀 (1/11) #PHP 8.4 adds SSE2 and SHA-NI #hardware acceleration for #SHA-256: hash('sha256', /* your data */); What does this means exactly? HUGE performance boost! 💥 But how is it possible? 👇
111
TimWolla @timwolla.bsky.social · 08/02/2025
The resources mentioned in externals.io/message/120041 might come in helpful (especially StackOverflow Chat for a more direct line to some of the core contributors).
externals.io
An invitation to chat and some useful links about PHP internals and extensions development - Externals
#externals - Opening PHP's #internals to the outside
010
TimWolla @timwolla.bsky.social · 08/02/2025
If someone would have disagreed with having that function (or still disagrees until PHP 8.5 feature freeze), then I would have went the RFC route. But as that did not happen (yet), we could avoid the bureaucracy there and save the participants on Internals and the voters some mental load 🙂
010
TimWolla @timwolla.bsky.social · 08/02/2025
In that case, both naming and implementation was pretty obvious, without leaving much room for "creativity". It also filled a clear gap in the existing functionality, so it was just merged by simple agreement of the ext/curl maintainer.
100
TimWolla @timwolla.bsky.social · 08/02/2025
As an example, here's a recent-ish PR of mine adding a new ext/curl function to PHP 8.5 without going through the RFC process: github.com/php/php-src/...
github.com
curl: Add `curl_multi_get_handles()` by TimWolla · Pull Request #16363 · php/php-src
see https://curl.se/libcurl/c/curl_multi_get_handles.html
110
TimWolla @timwolla.bsky.social · 08/02/2025
I recommend sending plaintext-only emails when interacting with Internals: Formatting will look as expected and less data to send around the Internet. You can select that in the 3-dot menu when composing a message. Not sure if it can be set as default for specific recipients.
Screenshot (in German) of the 3-dot menu in Gmail's compose view. The plaintext option ("Nur-Text-Modus") is checked.
100
TimWolla @timwolla.bsky.social · 08/02/2025
Based on externals.io/email/126356..., the HTML variant of your email indeed contains some fancy formatting for that left bar, but it didn't do anything for the plaintext variant.
externals.io
https://externals.io/email/126356/source
Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:126356 X-Original-To: internals@lists.php.net Delivered-To: internals@lists.php.net Received: from php-smtp4.php.net ...
100
TimWolla @timwolla.bsky.social · 08/02/2025
So far you didn’t run into the issue, because the discussion thread is simple enough, but it will likely cause confusion for more complex discussions with multiple parallel discussion topics.
000
TimWolla @timwolla.bsky.social · 08/02/2025
Also one thing to keep in mind with Gmail’s web interface: Please use the “Reply button” on the email you are actually replying to. Gmail’s linear view makes this easy to do wrong, leading to incorrect threading in other emails clients that show a tree structure (e.g. Thunderbird in my case).
110
TimWolla @timwolla.bsky.social · 08/02/2025
And indeed, the quote didn’t properly make it through. I can’t comment on details of Gmail’s web interface, which I assume you’re using, but generally prefixing each line with a `>` should do the trick.
200
TimWolla @timwolla.bsky.social · 08/02/2025
You mentioned that someone from the Laravel community sparked the idea and then I searched social media for “PHP RFC”.
110
TimWolla @timwolla.bsky.social · 08/02/2025
Personally I don't ever run the entire test suite locally (no need to run, say, ext/dom tests if I work on something unrelated) and leave the full test to CI.
100
TimWolla @timwolla.bsky.social · 08/02/2025
And for running tests, you can restrict the tests to a specific directory by running `sapi/cli/php run-tests.php --show-diff ext/random/` for faster turn-around times.
100
TimWolla @timwolla.bsky.social · 08/02/2025
7 to 8 minutes sounds pretty slow for building on an M1. Did you build with `make -j$(nproc)` for multi-core compilation?
200
TimWolla @timwolla.bsky.social · 08/02/2025
Using the information learned from writing the PR you can ensure that your RFC text itself is in the best possible shape, cutting down on the amount of back-and-forth discussion and clarification required on the mailing-list, saving everyone involved time.
100
TimWolla @timwolla.bsky.social · 08/02/2025
Having the PR ready first will also help in working out all the details. By writing the tests you find necessary edge-cases that might need some explanation in the RFC itself.
100
TimWolla @timwolla.bsky.social · 08/02/2025
In simple cases an RFC might not actually be necessary! As a newcomer it might be easier to file a PR against php-src first and then folks will likely tell you if you need an RFC (either because they disagree with the feature, or because they feel further discussion is necessary).
110
TimWolla @timwolla.bsky.social · 08/02/2025
Friendly person here 👋 Happy to hear that my reply was well-received. My intention really was avoiding the “Internals is hard to approach” sentiment that is sometimes claimed on social media and it seems I succeeded with that 😁
110