Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
27 changes: 27 additions & 0 deletions .github/scripts/install-alpine-php.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
#!/bin/sh
# Installs PHP $PHP_MINOR and the extension's build tools into the Alpine
# containers of the musl turbo legs in phar.yml. With PHP_ZTS=1 it builds a
# thread-safe PHP from the release tarball instead (build-php.sh): Alpine
# packages no thread-safe PHP, while the official php:*-alpine Docker images
# are thread-safe from 8.6 on.
set -eu

apk add --no-cache bash curl git make g++ musl-dev linux-headers patch tar zstd

if [ "${PHP_ZTS:-0}" = "1" ]; then
apk add --no-cache pkgconf xz libxml2-dev oniguruma-dev curl-dev openssl-dev zlib-dev
PHP_MINOR="$PHP_MINOR" PHP_ZTS=1 sh "$(dirname "$0")/../turbo-build/build-php.sh"
exit 0
fi

V="$(echo "$PHP_MINOR" | tr -d .)"
# Alpine's php86 packages are currently only in edge/testing.
if [ "$PHP_MINOR" = "8.6" ]; then
echo 'https://dl-cdn.alpinelinux.org/alpine/edge/testing' >> /etc/apk/repositories
fi
apk add --no-cache \
"php$V" "php$V-dev" "php$V-ctype" "php$V-curl" "php$V-mbstring" \
"php$V-tokenizer" "php$V-iconv" "php$V-openssl" "php$V-phar" \
"php$V-dom" "php$V-xml" "php$V-xmlwriter" "php$V-simplexml"
ln -sf "/usr/bin/php$V" /usr/local/bin/php
ln -sf "/usr/bin/php-config$V" /usr/local/bin/php-config
29 changes: 15 additions & 14 deletions .github/turbo-build/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
# Prebuilt image for the turbo-compile gnu legs in phar.yml, published to
# ghcr.io/phpstan/turbo-build by turbo-build-image.yml (tags gnu-php8.3,
# gnu-php8.4, gnu-php8.5, gnu-php8.6; each a linux/amd64 + linux/arm64
# manifest).
# gnu-php8.4, gnu-php8.5, gnu-php8.6, gnu-php8.6-zts; each a linux/amd64 +
# linux/arm64 manifest).
#
# Baking the PHP toolchain in keeps apt and the ondrej/php PPA out of the
# compile jobs entirely: ports.ubuntu.com (the only Ubuntu arm64 mirror,
Expand All @@ -14,18 +14,19 @@
FROM ubuntu:22.04

ARG PHP_MINOR
# 1 builds a thread-safe PHP (the -zts tags)
ARG PHP_ZTS=0
ENV DEBIAN_FRONTEND=noninteractive

# PHP 8.6 is a prerelease, and ondrej/php trails its tags by weeks: on
# 2026-09-25 it still served 8.6.0beta3, whose module API (20250926) the
# 8.6.0RC2 that the php:8.6-rc images ship had already replaced
# (20260924) — an extension built against one refuses to load into the
# other. The 8.6 image therefore builds the official release tarball on
# the same base. Drop these and the source branch below once ondrej/php
# ships 8.6.0.
ARG PHP86_VERSION=8.6.0RC2
ARG PHP86_URL=https://downloads.php.net/~mbeccati/php-8.6.0RC2.tar.xz
ARG PHP86_SHA256=ef3fba21c311e9bbace0e2102702446d322c275b8a10e6b33b28f2561299671c
# These images build PHP from the official release tarball pinned in
# build-php.sh instead of installing it from ondrej/php:
# - PHP 8.6 is a prerelease, and ondrej/php trails its tags by weeks: on
# 2026-09-25 it still served 8.6.0beta3, whose module API (20250926) the
# 8.6.0RC2 that the php:8.6-rc images ship had already replaced
# (20260924) — an extension built against one refuses to load into the
# other. Switch the NTS 8.6 image to the PPA once it ships 8.6.0.
# - ondrej/php packages no thread-safe PHP at all, so the ZTS images always
# build from source.

# The source label links the GHCR package to this repository.
LABEL org.opencontainers.image.source="https://github.com/phpstan/phpstan-src"
Expand All @@ -48,9 +49,9 @@ RUN test -n "$PHP_MINOR"; \
return 1; \
}; \
apt_install software-properties-common gnupg ca-certificates curl git make g++ patch unzip zstd \
&& if [ "$PHP_MINOR" = "8.6" ]; then \
&& if [ "$PHP_MINOR" = "8.6" ] || [ "$PHP_ZTS" = "1" ]; then \
apt_install pkg-config xz-utils libxml2-dev libonig-dev libcurl4-openssl-dev libssl-dev zlib1g-dev \
&& PHP_VERSION="$PHP86_VERSION" PHP_URL="$PHP86_URL" PHP_SHA256="$PHP86_SHA256" sh /tmp/build-php.sh; \
&& PHP_MINOR="$PHP_MINOR" PHP_ZTS="$PHP_ZTS" sh /tmp/build-php.sh; \
else \
add-apt-repository -y ppa:ondrej/php \
&& apt_install "php$PHP_MINOR-cli" "php$PHP_MINOR-dev" "php$PHP_MINOR-curl" "php$PHP_MINOR-mbstring" "php$PHP_MINOR-xml" \
Expand Down
34 changes: 30 additions & 4 deletions .github/turbo-build/build-php.sh
Original file line number Diff line number Diff line change
@@ -1,14 +1,37 @@
#!/bin/sh
# Builds and installs PHP $PHP_VERSION into /usr/local from the official
# release tarball at $PHP_URL, verified against $PHP_SHA256. Used by the
# Dockerfile for the PHP minors ondrej/php does not ship yet.
# Builds and installs PHP $PHP_MINOR into /usr/local from the official
# release tarball pinned below, thread-safe when $PHP_ZTS is 1. Used by the
# Dockerfile for the PHP builds ondrej/php does not ship (prerelease
# minors, and every thread-safe build), and by the musl ZTS legs in
# phar.yml, which run it in Alpine — Alpine packages no thread-safe PHP.
#
# The extensions match what the turbo-compile legs use from the PPA
# images: tokenizer for the parser tests, pcntl + posix for the fork
# tests, opcache (always built in since 8.5) for the trusted-types test,
# and curl, mbstring, openssl, xml and zlib for Composer.
set -eu

# The tarball for each minor this script builds; one pin shared by the
# glibc image and the musl legs, so both build the same release.
case "$PHP_MINOR" in
8.6)
PHP_VERSION=8.6.0RC2
PHP_URL=https://downloads.php.net/~mbeccati/php-8.6.0RC2.tar.xz
PHP_SHA256=ef3fba21c311e9bbace0e2102702446d322c275b8a10e6b33b28f2561299671c
;;
*)
echo "build-php.sh: no tarball pinned for PHP $PHP_MINOR" >&2
exit 1
;;
esac
export PHP_VERSION
PHP_ZTS="${PHP_ZTS:-0}"
export PHP_ZTS
ZTS_FLAG=""
if [ "$PHP_ZTS" = "1" ]; then
ZTS_FLAG="--enable-zts"
fi

cd /tmp
curl -fsSLo php.tar.xz "$PHP_URL"
echo "$PHP_SHA256 php.tar.xz" | sha256sum -c -
Expand All @@ -17,6 +40,7 @@ tar -xJf php.tar.xz -C php-src --strip-components=1
rm php.tar.xz

cd php-src
# shellcheck disable=SC2086 # ZTS_FLAG is empty or a single word
./configure \
--prefix=/usr/local \
--disable-cgi \
Expand All @@ -27,7 +51,8 @@ cd php-src
--enable-pcntl \
--with-curl \
--with-openssl \
--with-zlib
--with-zlib \
$ZTS_FLAG
make -j"$(nproc)"
make install

Expand All @@ -41,4 +66,5 @@ cd /tmp
rm -rf php-src

php -r 'if (PHP_VERSION !== getenv("PHP_VERSION")) { fwrite(STDERR, "built PHP " . PHP_VERSION . ", expected " . getenv("PHP_VERSION") . "\n"); exit(1); }'
php -r 'if ((int) PHP_ZTS !== (int) getenv("PHP_ZTS")) { fwrite(STDERR, "built PHP_ZTS=" . PHP_ZTS . ", expected " . getenv("PHP_ZTS") . "\n"); exit(1); }'
php -m
Loading
Loading