NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
Packagist · #1145 most downloaded on Packagist
PHP Standard Library
Last release 13 days ago
25 Sep 2026
Release timing varies
gaps range from 8 days to 7 months
Some releases are documented
notes for 32 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
6 years old
75 releases · first in 2020
This release adds Type\numeric() , fixes HTTP header validation, and updates the documentation site.
This release adds Type\numeric(), fixes HTTP header validation, and updates the documentation site.
Type\numeric(): A new type for integers, floats, and numeric strings. It preserves the input’s type, so numeric strings remain strings. Coercion also accepts Stringable objects whose string value is numeric. (by @gsteel in #793)use Psl\Type;
Type\numeric()->assert(42); // 42
Type\numeric()->assert(3.14); // 3.14
Type\numeric()->assert('1.23'); // '1.23'HTTP\Client: Validates all Transfer-Encoding response fields, including repeated fields. Invalid or unsupported transfer codings now raise a ProtocolException instead of falling back to Content-Length. Valid chunked responses still take precedence over Content-Length. (by @azjezz in #806)HTTP\Client and H2: Reject conflicting Content-Length fields in HTTP/1.1 responses and HTTP/2 headers while accepting identical duplicates. (by @azjezz in #800)Dict\diff(): Corrects the PHPDoc value type bound to scalar|null|resource|Stringable, matching the string conversion used for comparisons. Runtime behavior is unchanged. (by @azjezz in #796)Iter\last_key_opt(): Corrected the description to say that the function returns the last key. (by @klifoth in #803)Install: composer require php-standard-library/php-standard-library:^6.3
Full Changelog: 6.2.1...6.3.0
One column per quarter.
numeric type - #793 by @gsteelTransfer-Encoding response fields and reject invalid or unsupported transfer codings instead of falling back to Content-Length - #806This release fixes a server-side HTTP/2 vulnerability in the Psl\H2 component ( GHSA-pw9p-jvrm-f7rm ).
This release fixes a server-side HTTP/2 vulnerability in the Psl\H2 component (GHSA-pw9p-jvrm-f7rm).
Psl\H2\ServerConnection did not validate that the total bytes received in HTTP/2 DATA frames matched the content-length header declared in the initial HEADERS frame, in violation of RFC 9113 §8.1.1 and §8.1.2.6. #777
A malicious client could:
This affects consumers using Psl\H2\ServerConnection directly to accept untrusted client traffic. Consumers of documented high-level PSL APIs are not affected.
content-length on server-side HEADERS receive (RFC 9110 §8.6: must be a non-negative decimal integer).Psl\H2\Exception\StreamException on mismatch or overflow.Client-side validation is intentionally not performed, as RFC 9110 §9.3.2 permits HEAD responses to declare content-length without sending DATA.
Psl\H2\ConnectionTrait::waitForSendWindow() now flushes pending buffered writes before suspending. Without this, frames written inside a buffered() block never reach the wire, and a peer that only sends WINDOW_UPDATE after seeing our DATA would deadlock.composer require php-standard-library/psl:^6.2.1
Discovered during internal review prior to public exploitation.
content-length header against received DATA on server connections, preventing HTTP/2 request smuggling on Psl\H2\ServerConnection (GHSA-pw9p-jvrm-f7rm)New unified Configuration replacing the deprecated ClientConfiguration and ServerConfiguration . Both ClientConnection and ServerConnection accept it.…
A massive release — three new networking stack components (HTTP, SMTP, DNS), the EitherOrBoth type with full-outer-join iterators, a major IO toolkit expansion, and broad covariance improvements across the type system.
HTTP\Message — version-agnostic HTTP message abstractions. Request/Response value objects with streaming bodies (ReadHandleInterface), FieldMap (ordered, case-insensitive headers with lazy index), ProtocolVersion covering HTTP/1.0 through HTTP/3, trailers as Async\Awaitable<FieldMap>, status/method constants per RFC 9110, and Transaction/Exchange for informational (1xx) responses and HTTP/2 server-push pairs.HTTP\Client — async HTTP/1.1 and HTTP/2 client with automatic protocol negotiation via ALPN. Connection pooling (H1 idle reuse, H2 session sharing across concurrent requests), event-driven stream dispatch, transparent reconnection on GOAWAY/TCP reset, RedirectClient and RetryClient decorators, per-request SendConfiguration, SSRF protection via DeniedDestinationsMiddleware, SOCKS5 proxy and HTTP CONNECT tunnel support, H2 flow control with BDP auto-tuning, and 104 integration tests against httpbun.MIME — comprehensive RFC 2045–2049 toolkit. Media type parsing and content negotiation, MIME part construction with automatic transfer encoding, streaming multipart bodies and parsing (alternative, related, form, generic), Content-Disposition with safe filename extraction, RFC 2231 parameter encoding with continuations and charset conversion, content sniffing from bytes or seekable handles, S/MIME signing/verification/encryption/decryption per RFC 5652/8551, and DKIM signing with RSA-SHA256 and Ed25519-SHA256 per RFC 6376/8463.Message — RFC 5322 internet message construction, parsing, and serialization. Typed header fields with fluent with*() mutation, address methods accepting string|Mailbox|AddressList, streaming serialize()/parse(), reply/reply-all/forward with automatic threading headers, RFC 5321 SMTP envelope derivation, and full RFC 5322 address parsing including RFC 2047 encoded-word support.SMTP — RFC 5321 SMTP client with connection pooling. Low-level Connection for protocol-level operations and high-level Transport managing the full lifecycle (EHLO/HELO, STARTTLS, AUTH, send, RSET). Implicit TLS on port 465 and STARTTLS upgrade with automatic detection, SMTP pipelining (RFC 2920), BDAT chunking (RFC 3030), DSN (RFC 3461), REQUIRETLS (RFC 8689), MT-PRIORITY (RFC 6710), DELIVERBY (RFC 2852), FUTURERELEASE (RFC 4865), BINARYMIME/8BITMIME/SMTPUTF8 negotiation, IDN punycode for international addresses, partial recipient success tracking, CRLF/null byte injection protection, and five authentication mechanisms: PLAIN, LOGIN, XOAUTH2, CRAM-MD5, SCRAM-SHA-256.DNS — async DNS resolution with full protocol support. SystemResolver mirrors OS DNS behavior; UDP and pooled TCP resolvers with automatic TCP fallback on truncation; DNS-over-TLS (DoT) and DNS-over-HTTPS (DoH, RFC 8484). RacingResolver races multiple nameservers concurrently, SplitHorizonResolver routes by domain, SearchDomainResolver expands short names, HostsFileResolver checks the OS hosts file, CachedResolver decorator with TTL-aware caching, and StaticResolver for tests. Cross-platform system configuration loading on Linux, macOS, and Windows. EDNS0 extensions (cookies, client subnet, padding, NSID, keepalive). 20+ record types covering A, AAAA, NS, CNAME, MX, TXT, SRV, SOA, PTR, CAA, SSHFP, TLSA, SVCB, HTTPS, LOC, NAPTR, DS, DNSKEY, RRSIG, NSEC, NSEC3.DNSSEC — full DNSSEC validation chain. SecureResolver validates RRSIG signatures, TrustChainResolver walks DS/DNSKEY from root to target zone, CachedTrustChainResolver for performance, StaticTrustChainResolver for offline use. NSEC and NSEC3 authenticated denial of existence proofs. Seven signature algorithms: RSA/SHA-1, RSA/SHA-256, RSA/SHA-512, ECDSA P-256, ECDSA P-384, Ed25519, Ed448. Specific exceptions for signature failures, broken trust chains, invalid proofs, and unsigned responses.EitherOrBoth — three-variant disjoint union (Left/Right/Both) for values that may be present on either or both of two sides. Inspired by Rust's itertools::EitherOrBoth and Haskell's Data.These. Unlike Either, no side is privileged. Use cases: three-way diffs (insert/delete/update events), layered config merging, multi-source enrichment, dual-validation with independent failure paths, snapshot comparison, request/response pairing. Full surface: map, mapLeft, mapRight, mapAny, swap, proceed, apply, containsLeft, containsRight, plus left()/right()/both() free constructors.Iter\merge_join_by / Iter\merge_join_by_key — full-outer-join stream producers yielding EitherOrBoth events. merge_join_by is a lazy two-cursor merge over sorted inputs (O(1) memory, Comparison\Order-returning comparator). merge_join_by_key is a hash-based variant for keyed inputs that need no pre-sorting (O(|right|) memory).Eight new handle types for streaming composition:
IterableReadHandle — lazily consume an iterable<string> without buffering.ConcatReadHandle — read from two handles in sequence, switching at EOF.JoinedReadWriteHandle — combine separate read and write handles into one.TeeWriteHandle — fan out writes to two handles with backpressure buffering.SinkWriteHandle / SinkReadHandle / SinkReadWriteHandle — /dev/null-like handles for discarding writes and reporting EOF immediately on reads.TruncatedReadHandle — silently report EOF after N bytes.BoundedReadHandle — throw RuntimeException if the underlying handle exceeds N bytes.FixedLengthReadHandle — read exactly N bytes, throw on premature EOF.Plus IO\copy_chunked() and IO\copy_bidirectional_chunked() for explicit chunk-size control.
Read-only template parameters across the library are now annotated @template-covariant, letting values flow into wider declarations:
Async\Awaitable<T>, Promise\PromiseInterface<T>Result\ResultInterface<T>, Result\Success<T>, Result\Failure<T, Te>Option\Option<T>Either\Either<TLeft, TRight>, Either\Left<TLeft>, Either\Right<TRight>Tree\NodeInterface<T>, Tree\LeafNode<T>, Tree\TreeNode<T>Collection interfaces and implementations (Map, Set, Vector)Async\Sequence, KeyedSequence, Semaphore, and KeyedSemaphore now correctly distinguish contravariant inputs from covariant outputs.
H2)Configuration replacing the deprecated ClientConfiguration and ServerConfiguration. Both ClientConnection and ServerConnection accept it. Client-side BDP auto-tuning is now available when maxReceiveWindowSize is set on the unified config.TCP\bindTo — bind to a specific local address before connecting or listening. Available on both ConnectConfiguration and ListenConfiguration with withBindTo() builders; connect() respects it via socket.bindto.Type\bool() — now coerces 'true'/'false' string literals (thanks @veewee, #735).Type\class_string — allow null argument to assert or coerce a bare class-string.HTTP\Client\SendConfiguration::$connectionTimeout — per-request maximum duration for TCP + TLS handshake, using a linked cancellation token.IO\copy() flushes the writer if it implements BufferedWriteHandleInterface — no data left in buffers.Async\State no longer captures $this in queued callbacks, fixing delayed GC of Deferred/Awaitable chains.URI correctly parses bare IPv6 addresses (e.g., http://::1/path) as IPHost instead of misparsing as a registered name with numeric port.H2 separates maxConcurrent (peer's limit on our streams) from peerMaxConcurrent (our limit on peer's streams), so client's own SETTINGS no longer limit its outgoing streams.H2\BDPEstimator emits an initial connection-level WINDOW_UPDATE during initialize(), bringing the receive window from the RFC default (65535) up to initialWindowSize to prevent flow-control stalls under burst concurrency.H2 waiter notification copies the list before iterating and properly removes satisfied waiters — no iteration corruption or memory leaks.IO\ResourceHandle read/write callbacks and cancellation subscriptions null out the suspension reference before resuming or throwing — no more "Must call suspend() before calling throw()" errors during handle destruction or shutdown races.Will be removed in PSL 7.0:
TCP\Socket — use ConnectConfiguration::$bindTo / ListenConfiguration::$bindTo.H2\ClientConfiguration and H2\ServerConfiguration — use the unified H2\Configuration.Install: composer require php-standard-library/psl:^6.2
EitherOrBoth component - a three-variant disjoint union (Left / Right / Both) for values that may be present on either or both of two sides, inspired by Rust's itertools::EitherOrBoth and Haskell's Data.These. Primary use case: three-way diff of two collections (insert / delete / update events). Secondary: layered config merge, multi-source enrichment, dual-validation, snapshot comparison. Full map / mapLeft / mapRight / mapAny / swap / proceed / apply / containsLeft / containsRight surface; left() / right() / both() free constructors.Iter\merge_join_by and Iter\merge_join_by_key - full-outer-join stream producers that yield EitherOrBoth events as a rewindable Iter\Iterator. merge_join_by is a lazy two-cursor merge over sorted inputs (O(1) memory on first traversal, Psl\Comparison\Order-returning comparator, matching Rust's itertools::merge_join_by); merge_join_by_key is a hash-based variant for keyed inputs that do not need to be pre-sorted (O(|right|) memory).IO\IterableReadHandle - a streaming ReadHandleInterface that lazily consumes an iterable<string> without buffering the entire content in memoryIO\ConcatReadHandle - reads from two handles in sequence, switching to the second when the first reaches EOFIO\JoinedReadWriteHandle - joins a ReadHandleInterface and WriteHandleInterface into a single read-write handle, delegating all operations to the respective underlying handleIO\TeeWriteHandle - writes to two handles simultaneously with backpressure buffering when the second handle is slowerIO\SinkWriteHandle - a /dev/null-like write handle that discards all written dataIO\SinkReadHandle - a read handle that is always at EOF, unlike MemoryHandle('') which only reports EOF after the first readIO\SinkReadWriteHandle - a sink that discards writes and always reports EOF on readsIO\TruncatedReadHandle - reads up to N bytes from an underlying handle, silently reporting EOF when the limit is reachedIO\BoundedReadHandle - reads up to N bytes from an underlying handle, throwing RuntimeException if the underlying handle has more data than the limit allowsIO\FixedLengthReadHandle - reads exactly N bytes from an underlying handle, throwing RuntimeException on premature EOFIO\copy_chunked() and IO\copy_bidirectional_chunked() - variants of IO\copy() and IO\copy_bidirectional() that accept a custom chunk sizeSendConfiguration::$connectionTimeout - per-request maximum duration for establishing a connection (TCP + TLS handshake), using a linked cancellation token'true'/'false' string literals in Type\bool() coercion - #735 by @verwetoMIME component - comprehensive MIME toolkit implementing RFC 2045-2049 and related standards
MediaType, MediaRange, MediaPreferences) per RFC 2045, RFC 6838, RFC 9110Part\Text, Part\Data) per RFC 2045MultiPart\Composite, MultiPart\Alternative, MultiPart\Related, MultiPart\Form, MultiPart\Parser) per RFC 2046, RFC 2387, RFC 7578Headers)ContentDisposition) per RFC 2183cid: URI support (ContentId) per RFC 2392Parameters)Sniff\from_string, Sniff\from_handle)SMIME\Signer, SMIME\Verifier, SMIME\Encryptor, SMIME\Decryptor) per RFC 5652, RFC 8551DKIM\Signer) per RFC 6376, RFC 8301, RFC 8463Message component - RFC 5322 internet message construction, parsing, and serialization
with*() methods (Message) per RFC 5322string|Mailbox|AddressList for conveniencePartInterface from the MIME component per RFC 2045serialize() and parse() accepting string or ReadHandleInterfaceEnvelope) per RFC 5321Mailbox, Group, AddressList with RFC 2047 encoded-word supportSMTP component - RFC 5321 SMTP client with connection pooling, TLS, and authentication
Connection implementing Network\StreamInterface for protocol-level SMTP operationsTransport managing the full SMTP lifecycle: connect, EHLO/HELO, STARTTLS, AUTH, send, RSETTCP\SocketPoolEnhancedStatusCode parsingSendConfigurationDuration or DateTimeInterfaceDeliveryReport for per-recipient rejection trackingPossibleAttackExceptionTransportConfiguration and SendConfiguration with fluent with*() buildersDNS component - async DNS resolution with full protocol support
SystemResolver mirrors OS DNS behavior, usable as a default parameter valueTCPResolverRacingResolver races multiple nameservers concurrently for fastest responseSplitHorizonResolver routes queries by domain name for split-horizon DNSSearchDomainResolver expands short names using search domain listsHostsFileResolver checks the OS hosts file before network queriesCachedResolver decorator with TTL-aware caching via Cache\StoreInterfaceStaticResolver for hardcoded records in tests and developmentHTTPSResolver using the HTTP client (RFC 8484)ResponseCode helper methods: isSuccess(), isError(), isServerError(), isNameError()DNSSEC component - full DNSSEC validation chain
SecureResolver validates RRSIG signatures on every responseTrustChainResolver walks DS/DNSKEY chain from root to target zoneCachedTrustChainResolver caches trust chain results for performanceStaticTrustChainResolver for offline/air-gapped environmentsSignatureFailedException, BrokenTrustChainException, InvalidProofException, UnsignedResponseExceptionHTTP Message component - version-agnostic HTTP message abstractions
Request and Response immutable value objects with streaming body (ReadHandleInterface)FieldMap ordered, case-insensitive header field collection with lazy indexProtocolVersion enum covering HTTP/1.0, HTTP/1.1, HTTP/2, and HTTP/3Async\Awaitable<FieldMap> for HTTP/2 and chunked HTTP/1.1reason_phrase() function for HTTP/1.x status line serializationwith*() mutation methods on both Request and ResponseTransaction groups the final response with informational (1xx) responses and server push exchangesExchange represents a pushed request/response pair for HTTP/2 server pushHTTP Client component - async HTTP/1.1 and HTTP/2 client with connection pooling
Client with automatic protocol negotiation via ALPN (HTTP/2 preferred, HTTP/1.1 fallback)PooledConnector with HTTP/1.x idle connection reuse and HTTP/2 session sharing across concurrent requestsH2Multiplexer and per-stream H2Stream stateRedirectClient decorator following 301/302/303/307/308 redirects with method rewriting per RFC 9110, cross-origin credential stripping, and auto-referrerRetryClient decorator with configurable exponential backoff and jitter for transport-level failuresSendConfiguration for per-request overrides (body size limits, TLS, protocol versions, tunnel) merged with ClientConfiguration defaultsDeniedDestinationsMiddleware for SSRF protection against private IP ranges (RFC 1918, RFC 4193, loopback, link-local)HandlerInterface / MiddlewareInterface chain with access to peer address and TLS stateClientConfiguration::$proxy using Psl\Socks\ConnectorClientConfiguration::$tunnel with TLS and proxy authenticationnoTunneling host bypass rules (exact match, domain suffix, wildcard)ResponseBodyHandle implementing ReadHandleInterfaceConfiguration replacing deprecated ClientConfiguration and ServerConfiguration
ClientConnection and ServerConnection now accept Configuration in addition to their legacy config typesClientConnection now supports BDP auto-tuning when using Configuration with maxReceiveWindowSize setbindTo option to ConnectConfiguration for binding to a specific local address before connectingbindTo option to ListenConfiguration for binding to a specific local address before listeningwithBindTo() fluent builder method to both ConnectConfiguration and ListenConfigurationconnect() now respects ConnectConfiguration::$bindTo by setting the socket.bindto stream context optionType\class_string to assert or coerce bare class-string@template-covariant across the library, allowing values to flow into wider declarations:
Async\Awaitable<T>, Promise\PromiseInterface<T>Result\ResultInterface<T>, Result\Success<T>, Result\Failure<T, Te>Option\Option<T>Either\Either<TLeft, TRight>, Either\Left<TLeft>, Either\Right<TRight>Tree\NodeInterface<T>, Tree\LeafNode<T>, Tree\TreeNode<T>@template-covariant (CollectionInterface, AccessibleCollectionInterface, IndexAccessInterface, MapInterface, Map, SetInterface, Set, VectorInterface, Vector); mutable collections remain invariant.Sequence, KeyedSequence, Semaphore, KeyedSemaphore template parameters with the correct variance; keys/inputs are @template-contravariant (write-position only) and outputs are @template-covariant (read-position only).Vector::getIterator() and MutableVector::getIterator() return type from Iterator<int<0, max>, T> to Iterator<int, T>.IO\copy() now flushes the writer after copying if it implements BufferedWriteHandleInterface, ensuring no data remains in an internal bufferState::subscribe() and State::invokeCallbacks() no longer capture $this in queued closures, preventing delayed garbage collection of Deferred/Awaitable chainshttp://::1/path) are now correctly parsed as IPHost instead of being misparsed as a registered name with a numeric portmaxConcurrent (peer's limit on our streams) from peerMaxConcurrent (our limit on peer's streams) in StreamTable, preventing the client's own SETTINGS from limiting its outgoing streamsBDPEstimator now produces an initial connection-level WINDOW_UPDATE during initialize() to bring the receive window from the RFC default (65535) up to initialWindowSize, preventing flow-control stalls when many concurrent streams receive data simultaneouslynotifyWindowWaiters() now copies the waiter list before iterating and properly removes satisfied waiters, preventing iteration corruption and memory leaksResourceHandle readable/writable callbacks now null out the suspension reference before calling resume(), preventing "Must call suspend() before calling throw()" errors during handle destructionResourceHandle::doRead() and doWrite() cancellation subscriptions now null out the suspension reference before throwing, preventing double-wake when cancellation and close race during PHP shutdownSocket class -- use ConnectConfiguration::$bindTo or ListenConfiguration::$bindTo instead. Will be removed in PSL 7.0.ClientConfiguration -- use Configuration instead. Will be removed in PSL 7.0.ServerConfiguration -- use Configuration instead. Will be removed in PSL 7.0.This release fixes a server-side HTTP/2 vulnerability in the Psl\H2 component ( GHSA-pw9p-jvrm-f7rm ).
This release fixes a server-side HTTP/2 vulnerability in the Psl\H2 component (GHSA-pw9p-jvrm-f7rm).
Psl\H2\ServerConnection did not validate that the total bytes received in HTTP/2 DATA frames matched the content-length header declared in the initial HEADERS frame, in violation of RFC 9113 §8.1.1 and §8.1.2.6. #778
A malicious client could:
This affects consumers using Psl\H2\ServerConnection directly to accept untrusted client traffic. Consumers of documented high-level PSL APIs are not affected.
content-length on server-side HEADERS receive (RFC 9110 §8.6: must be a non-negative decimal integer).Psl\H2\Exception\StreamException on mismatch or overflow.Client-side validation is intentionally not performed, as RFC 9110 §9.3.2 permits HEAD responses to declare content-length without sending DATA.
Psl\H2\ConnectionTrait::waitForSendWindow() now flushes pending buffered writes before suspending. Without this, frames written inside a buffered() block never reach the wire, and a peer that only sends WINDOW_UPDATE after seeing our DATA would deadlock.composer require php-standard-library/psl:^6.1.2
Discovered during internal review prior to public exploitation.
Str\chr() and Str\from_code_points() now reject invalid Unicode code points
Str\chr() previously returned an empty string for invalid code points (negative values, surrogates, values above U+10FFFF) because mb_chr() returns false and it was silently cast to string. It now throws Str\Exception\OutOfBoundsException.
Str\from_code_points() had a hand-rolled UTF-8 encoder that silently produced invalid byte sequences; encoding surrogates, wrapping out-of-range values via modulo, and accepting negative inputs. The implementation has been replaced with a simple loop over Str\chr(), making both functions fully consistent. Invalid code points now throw Str\Exception\OutOfBoundsException.
use Psl\Str;
// These all threw no error before, now they throw OutOfBoundsException:
Str\chr(-1);
Str\chr(0xD800); // surrogate
Str\chr(0x110000); // above Unicode max
Str\from_code_points(72, 0xD800, 111); // throws on the surrogateValid inputs are unaffected — chr() and from_code_points() produce identical output for all valid Unicode code points (U+0000..U+D7FF, U+E000..U+10FFFF).
All ambiguous function calls have been made explicit. Every call site now uses either a use function import for global PHP functions or namespace\foo() for same-namespace functions.
Str\width(), Str\truncate(), and Str\width_slice() PHPDoc now explicitly states that width is defined by mb_strwidth() / mb_strimwidth(), and cross-references related functions like Str\length(), Str\Grapheme\length(), and Str\Grapheme\slice().usleep() resolution is too coarse for sub-millisecond timing assertions.Str\chr() now throws OutOfBoundsException for invalid Unicode code points instead of silently returning an empty stringStr\from_code_points() now validates code points and throws OutOfBoundsException for out-of-range values, surrogates, and negative inputs instead of producing invalid UTF-8; implementation now delegates to Str\chr() for consistent behaviorwidth(), truncate(), and width_slice() PHPDoc to explicitly reference mb_strwidth()/mb_strimwidth() semanticsIn PSL 5.x, we focused on the foundational networking stack-TCP, TLS, Unix sockets, UDP, and connection pooling. It was all about getting the low-leve
In PSL 5.x, we focused on the foundational networking stack-TCP, TLS, Unix sockets, UDP, and connection pooling. It was all about getting the low-level plumbing right.
With the 6.x series, we're moving up the stack and diving into protocols. Our ultimate goal is to bring robust support for HTTP/2, DNS, SMTP, WebSockets, and more. PSL 6.1.0 is the crucial first step: it delivers the core infrastructure that all of these upcoming features will rely on.
Everything in 6.1 was built with a clear destination in mind. We are paving the way for:
The components introduced today are the engine for this roadmap. The new H2 connections will drive the HTTP client and server, the new async Cache will back the DNS resolver, and the new Compression system will handle content-encoding seamlessly.
We've added streaming compression and decompression natively to IO handles. By defining your own CompressorInterface or DecompressorInterface (brotli, gzip, zstd, etc.), PSL gives you four handle decorators to wire them directly into the IO system:
CompressingReadHandle & CompressingWriteHandleDecompressingReadHandle & DecompressingWriteHandleWe've also included compress() and decompress() convenience functions for simple, one-shot operations. Under the hood, write handles implement the new BufferedWriteHandleInterface for explicit flushing and cancellation, while read handles accept configurable chunk sizes. Compressors automatically reset after calling finish(), making them easily reusable across streams.
This release includes a complete RFC 7541 encoder and decoder, featuring static table lookups, dynamic table indexing, and Huffman coding.
We wanted to be absolutely certain of its reliability, so we tested it against 14 independent implementations from the http2jp test suite. That translates to 1,172 tests and over 102,000 assertions, covering every encoding variant and edge case with full roundtrip verification.
We’ve shipped full support for the HTTP/2 binary framing protocol (RFC 9113), plus key extensions.
To keep responsibilities clean, connections are split by role. ServerConnection handles client prefaces, response headers, server pushes, Alt-Svc, and ORIGIN. Meanwhile, ClientConnection manages connection prefaces, priority signaling, and extended CONNECT.
Comprehensive Frame Support:
ALTSVC (RFC 7838) for HTTP/3 migration signaling.ORIGIN (RFC 8336) for connection coalescing.PRIORITY_UPDATE (RFC 9218) for extensible prioritization.Smart, Async-Native Flow Control:
We've designed flow control to get out of your way. sendAllData() automatically chunks payloads by window size and waits for updates. waitForSendWindow() suspends the fiber entirely (zero polling!) and resumes exactly when the window opens. Multiple fibers can wait on different streams with independent cancellation, and connection-level updates efficiently wake all relevant waiters.
Additional H2 Features:
getStreamState(), activeStreamCount(), isConnected()).ServerConfiguration and ClientConfiguration using fluent with* builders.We're introducing an async-safe, in-memory LRU cache. The standout feature here is per-key atomicity powered by KeyedSequence.
If two fibers request the same cache key simultaneously, only one will compute the result. The other simply waits and receives the cached value—preventing cache stampedes and eliminating duplicate work.
LocalStore: A bounded LRU cache with a configurable max size and TTL support. It uses an event loop timer for proactive expiration, dropping to zero overhead when there are no expiring entries.NullStore: A dummy cache that never stores and always recomputes. It's perfect for testing or temporarily disabling caching without having to modify your calling code.We've introduced BufferedWriteHandleInterface, which extends the standard WriteHandleInterface with a flush() method. This is essential for handles that buffer data internally (like the new compression writers) and need an explicit "send everything now" trigger with full cancellation support.
Psl\IO\BufferedWriteHandleInterface, extending WriteHandleInterface with flush() for handles that buffer data internally before writing to an underlying resourceCompression component with streaming compression/decompression abstractions for IO handles. Provides CompressorInterface, DecompressorInterface, four handle decorators (CompressingReadHandle, CompressingWriteHandle, DecompressingReadHandle, DecompressingWriteHandle), and convenience functions compress() and decompress()HPACK component - RFC 7541 HPACK header compression for HTTP/2H2 component - HTTP/2 binary framing protocol implementationCache component - async-safe in-memory LRU cache with per-key atomicity via KeyedSequence, proactive TTL expiration via event loopNo code changes. This release improves the release infrastructure.
No code changes. This release improves the release infrastructure.
6.0.x) to the tag before splitting, ensuring split repos always receive the correct commits for patch releases.See CHANGELOG.md for details.
Patch release fixing a bug in IO\Reader that affected non-blocking stream reads (TLS, TCP, etc.).
Patch release fixing a bug in IO\Reader that affected non-blocking stream reads (TLS, TCP, etc.).
Reader::readUntil() and Reader::readUntilBounded() assumed that an empty read() meant end-of-stream. On non-blocking handles (TLS, TCP, Unix sockets), read() can return empty before data arrives. This caused readLine() to return the entire stream content as a single string instead of splitting into individual lines.
This bug affected any code using IO\Reader with network streams. If you were using readLine(), readUntil(), or readUntilBounded() on a non-blocking stream and getting unexpected results, this is the fix.
Documentation source links (See src/Psl/Default/ for the full API) now link to packages/default/src/Psl/Default/ instead of the non-existent top-level src/Psl/Default/.
See CHANGELOG.md for details.
chore: update changelog
chore: update changelog (#683)
Reader::readUntil() and Reader::readUntilBounded() no longer treat empty reads from non-blocking streams as EOF, fixing readLine() returning the entire content instead of individual lines when used with non-blocking streamspackages/{name}/src/Psl/ instead of the non-existent top-level src/Psl/ pathsplitter audit command to verify organization repository settings (wiki, issues, discussions, PRs, tag immutability).This is a major release with breaking changes. The most impactful:
PSL 6.0 is the biggest release in the project's history. New home, new packages, new capabilities.
PSL has moved. The repository, the organization, the website - everything has a new address:
azjezz/psl)psl.carthage.software)php-standard-library/php-standard-library (was azjezz/psl)The azjezz/psl package is now abandoned. Run composer require php-standard-library/php-standard-library to switch.
The namespace has not changed. It is Psl\, and it will always remain Psl\.
PSL is now split into 61 independently installable packages. You no longer need to pull in the entire library.
Need just type-safe coercion? composer require php-standard-library/type
Building an async TCP server? composer require php-standard-library/tcp
Working with URIs? composer require php-standard-library/uri
Every package declares its own dependencies, so you only get what you actually use. The full library install still works for those who want everything:
composer require php-standard-library/php-standard-libraryAll 61 packages live under the php-standard-library GitHub organization, each with its own read-only split repository for Composer.
Full RFC-compliant resource identifier handling:
Standalone RFC 3492 Punycode encoding and decoding for internationalized domain names.
A new cancellation system replaces the old Duration $timeout pattern across all async/IO operations:
CancellationTokenInterface - base contractTimeoutCancellationToken - auto-cancels after a durationSignalCancellationToken - manually triggered cancellationLinkedCancellationToken - cancelled when either of two inner tokens firesTaskGroup and WaitGroup for structured concurrencyQuotedPrintable and EncodedWord encoding (RFC 2045, RFC 2047)TLS\Listener for wrapping any listener with TLSTCP\RestrictedListener for IP/CIDR-based access controlNetwork\CompositeListener for accepting from multiple listenersBufferedReadHandleInterface with readByte(), readLine(), readUntil()This is a major release with breaking changes. The most impactful:
Cancellation replaces timeouts. All null|Duration $timeout parameters are now CancellationTokenInterface $cancellation = new NullCancellationToken().
// Before (5.x)
$data = $reader->read(timeout: Duration::seconds(5));
// After (6.0)
$data = $reader->read(cancellation: new Async\TimeoutCancellationToken(Duration::seconds(5)));Naming conventions. All variables, parameters, and properties now use $camelCase.
Configuration objects. TCP\listen(), TCP\connect(), Unix\listen(), UDP\Socket::bind(), and Socks\Connector now accept configuration objects instead of individual parameters.
Removed timeout exceptions. IO\Exception\TimeoutException, Network\Exception\TimeoutException, Process\Exception\TimeoutException, and Shell\Exception\TimeoutException are removed. Use Async\Exception\CancelledException instead.
TLS renamed. TLS\ServerConfig -> TLS\ServerConfiguration, TLS\ClientConfig -> TLS\ClientConfiguration.
See the full CHANGELOG for the complete list.
RetryConnector backoff sleep now respects cancellation tokensIO\write(), IO\write_line(), IO\write_error(), IO\write_error_line(), and Str\format() no longer crash when the message contains % characters and no arguments are passedPSL is built by its community. Thank you to everyone who contributed code, reported bugs, sponsored the project, or simply used it in production.
null|Duration $timeout parameters across IO, Network, TCP, TLS, Unix, UDP, Socks, Process, and Shell components have been replaced with CancellationTokenInterface $cancellation = new NullCancellationToken(). This enables both timeout-based and signal-based cancellation of async operations.Psl\IO\Exception\TimeoutException - use Psl\Async\Exception\CancelledException instead.Psl\Network\Exception\TimeoutException - use Psl\Async\Exception\CancelledException instead.Psl\Process\Exception\TimeoutException - use Psl\Async\Exception\CancelledException instead.Psl\Shell\Exception\TimeoutException - use Psl\Async\Exception\CancelledException instead.Psl\IO\CloseHandleInterface now requires an isClosed(): bool method.Network\SocketInterface::getLocalAddress() and Network\StreamInterface::getPeerAddress() no longer throw exceptions. Addresses are resolved at construction time and cached, making these O(1) property lookups with no syscall.BufferedReadHandleInterface::readLine() now always splits on "\n" instead of PHP_EOL. Trailing "\r" is stripped, so both "\n" and "\r\n" line endings are handled consistently across all platforms. Use readUntil(PHP_EOL) for system-dependent behavior.Psl\TLS\ServerConfig renamed to Psl\TLS\ServerConfiguration.Psl\TLS\ClientConfig renamed to Psl\TLS\ClientConfiguration.$camelCase naming instead of $snake_case.TCP\listen(), TCP\connect(), TCP\Socket::listen(), TCP\Socket::connect() now accept configuration objects (TCP\ListenConfiguration, TCP\ConnectConfiguration) instead of individual parameters for socket options.Unix\listen() and Unix\Socket::listen() now accept Unix\ListenConfiguration instead of individual parameters.UDP\Socket::bind() now accepts UDP\BindConfiguration instead of individual parameters.TCP\Socket setter/getter methods (setReuseAddress, setReusePort, setNoDelay, etc.) have been removed. Use configuration objects instead.TCP\Connector constructor now accepts TCP\ConnectConfiguration instead of bool $noDelay.Socks\Connector constructor changed from (string $proxyHost, int $proxyPort, ?string $username, ?string $password, ConnectorInterface $connector) to (ConnectorInterface $connector, Socks\Configuration $configuration).ingoing to ongoing across Semaphore, Sequence, KeyedSemaphore, and KeyedSequence (hasIngoingOperations() -> hasOngoingOperations(), getIngoingOperations() -> getOngoingOperations(), etc.).Psl\Async\CancellationTokenInterface for cancelling async operationsPsl\Async\NullCancellationToken - no-op token used as default parameter valuePsl\Async\SignalCancellationToken - manually triggered cancellation via cancel(?Throwable $cause)Psl\Async\TimeoutCancellationToken - auto-cancels after a Duration, replacing the old Duration $timeout patternPsl\Async\LinkedCancellationToken - cancelled when either of two inner tokens is cancelled, useful for combining a request-scoped token with an operation-specific timeoutPsl\Async\Exception\CancelledException - thrown when a cancellation token is triggered; the cause (e.g., TimeoutException) is attached as $previous. Use $e->getToken() to identify which token triggered the cancellation.Async\sleep() now accepts an optional CancellationTokenInterface parameter, allowing early wake-up on cancellationAwaitable::await() now accepts an optional CancellationTokenInterface parameterSequence::waitFor() and Sequence::waitForPending() now accept an optional CancellationTokenInterface parameterSemaphore::waitFor() and Semaphore::waitForPending() now accept an optional CancellationTokenInterface parameterKeyedSequence::waitFor() and KeyedSequence::waitForPending() now accept an optional CancellationTokenInterface parameterKeyedSemaphore::waitFor() and KeyedSemaphore::waitForPending() now accept an optional CancellationTokenInterface parameterSenderInterface::send() and ReceiverInterface::receive() now accept an optional CancellationTokenInterface parameterListenerInterface::accept() now accepts an optional CancellationTokenInterface parameterTCP\ListenerInterface::accept() now accepts an optional CancellationTokenInterface parameterUnix\ListenerInterface::accept() now accepts an optional CancellationTokenInterface parameterTLS\Acceptor::accept(), TLS\LazyAcceptor::accept(), TLS\ClientHello::complete(), and TLS\Connector::connect() now accept an optional CancellationTokenInterface parameter - cancellation propagates through the TLS handshakeTLS\TCPConnector::connect() and TLS\connect() now pass the cancellation token through to the TLS handshakePsl\Async\TaskGroup for running closures concurrently and awaiting them all with defer() + awaitAll()Psl\Async\WaitGroup, a counter-based synchronization primitive with add(), done(), and wait()Psl\Encoding\QuotedPrintable\encode(), decode(), and encode_line() for RFC 2045 quoted-printable encoding with configurable line length and line endingPsl\Encoding\EncodedWord\encode() and decode() for RFC 2047 encoded-word encoding/decoding in MIME headers (B-encoding and Q-encoding with automatic selection)TLS\ListenerInterface and TLS\Listener, wrapping any Network\ListenerInterface to perform TLS handshakes on accepted connectionsBase64\Variant::Mime for RFC 2045 MIME Base64 with 76-char line wrapping and CRLF, using constant-time encoding/decodingEncodingReadHandle, DecodingReadHandle, EncodingWriteHandle, DecodingWriteHandle), QuotedPrintable (same 4), and Hex (same 4), bridging Psl\IO and Psl\Encoding for transparent encode/decode on read/writePsl\IO\BufferedReadHandleInterface, extending ReadHandleInterface with readByte(), readLine(), readUntil(), and readUntilBounded()Psl\IO\Reader now implements BufferedReadHandleInterfaceTCP\ListenConfiguration and TCP\ConnectConfiguration with immutable with* builder methodsUnix\ListenConfiguration with immutable with* builder methodsUDP\BindConfiguration with immutable with* builder methodsSocks\Configuration with immutable with* builder methods for proxy host, port, and credentialsTCP\RestrictedListener, wrapping a listener to restrict connections to a set of allowed IP\Address and CIDR\Block entriesNetwork\CompositeListener, accepting connections from multiple listeners concurrently through a single accept() callURI component - RFC 3986 URI parsing, normalization, reference resolution, and RFC 6570 URI Template expansion (Levels 1–4), with RFC 5952 IPv6 canonical form and RFC 6874 zone identifiersIRI component - RFC 3987 Internationalized Resource Identifier parsing with Unicode support, RFC 3492 Punycode encoding/decoding, and RFC 5891/5892 IDNA 2008 domain name processingURL component - strict URL type with scheme and authority validation, default port stripping for known schemes, and URI/IRI conversionPunycode component - RFC 3492 Punycode encoding and decoding for internationalized domain namesRetryConnector backoff sleep now respects cancellation tokens, allowing retry loops to be cancelled during the delayIO\write(), IO\write_line(), IO\write_error(), IO\write_error_line(), and Str\format() no longer pass the message through sprintf/vsprintf when no arguments are given, preventing format string errors when the message contains % charactersReplace Duration timeout parameters with TimeoutCancellationToken:
// Before (5.x)
$data = $reader->read(timeout: Duration::seconds(5));
// After (6.0)
$data = $reader->read(cancellation: new Async\TimeoutCancellationToken(Duration::seconds(5)));
For manual cancellation (e.g., cancel all request IO when a client disconnects):
$token = new Async\SignalCancellationToken();
// Pass to all request-scoped IO
$body = $reader->readAll(cancellation: $token);
// Cancel from elsewhere
$token->cancel();
Reader::readUntilBounded() reads from a handle until a suffix is found, just like readUntil() , but enforces a maximum byte limit. If the suffix is no
Reader::readUntilBounded() reads from a handle until a suffix is found, just like readUntil(), but enforces a maximum byte limit. If the suffix is not encountered within $max_bytes, an IO\Exception\OverflowException is thrown.
This is essential when reading from untrusted sources. for example, capping HTTP header lines so a malicious client cannot exhaust memory by sending an endless line:
use Psl\IO;
$reader = new IO\Reader($connection);
// Read a header line, but never buffer more than 8KB
$line = $reader->readUntilBounded("\r\n", max_bytes: 8192);Type\json_decoded() and Type\nullish()Two new type coercions from @veewee:
Type\json_decoded(TypeInterface $inner): accepts a JSON string and transparently decodes it, then coerces the result through $inner. Useful for APIs and form fields that pass structured data as JSON strings.
Type\nullish(TypeInterface $inner): matches null, the absence of a key (for shape fields), and the inner type. Ideal for optional-and-nullable shape fields where "missing" and "null" should be treated the same.
Documentation: psl.carthage.software/ | IO | Type
Full Changelog: 5.4.0...5.5.0
Reader::readUntilBounded(string $suffix, int $max_bytes, ?Duration $timeout) method, which reads until a suffix is found, but throws IO\Exception\OverflowException if the content exceeds $max_bytes before the suffix is encountered - #620 - by @azjezzIO\Exception\OverflowException exception class - #620 - by @azjezzType\json_decoded() type for transparent JSON string coercion - #619 by @veeweeType\nullish() type for optional-and-nullable shape fields - #618 by @veeweefeat(dict, vec): add filter_nonnull_by and map_nonnull - #576 by @Dima-369
backlog parameter to TCP\listen() for configuring the pending connection queue size - #617 - by @azjezzfeat(io): introduce IO\spool() for memory-backed handles that spill to disk
IO\spool() for memory-backed handles that spill to diskfeat: introduce IP component with immutable, binary-backed Address value object and Family enum
IP component with immutable, binary-backed Address value object and Family enumCIDR\Block::contains() now accepts string|IP\Addressfeat(tls): introduce TLS\TCPConnector for poolable TLS connections
TLS\TCPConnector for poolable TLS connectionsTLS\StreamInterface now extends TCP\StreamInterface, enabling TLS streams to be used with TCP\SocketPoolInterfaceDropped PHP 8.3 support; minimum is now PHP 8.4 - #584 by @azjezz
Network, TCP, Unix) - #585 by @azjezzPsl\Shell internals refactored; dead code removed - #596 by @azjezzPsl\Env\temp_dir() now always returns a canonicalized path - #599 by @azjezzAnsi component - #588 by @azjezzTerminal component - #589 by @azjezzProcess component - #578 by @azjezzBinary component - #598 by @azjezzInteroperability component - #582 by @azjezzTLS component - #585 by @azjezzUDP component - #585 by @azjezzCIDR component - #585 by @azjezzSocks component - #585 by @azjezzPeriod, Interval, TemporalAmountInterface - #595 by @azjezzIO\copy() and IO\copy_bidirectional() - #585 by @azjezzVec\flatten() - #583 by @azjezzCrypto component with symmetric/asymmetric encryption, signing, AEAD, KDF, HKDF, key exchange, and stream ciphers - #607 by @azjezzrange() for float precision - #581 by @azjezzcreate_temporary_file - #580, #597 by @azjezzrefactor(phpunit): resolve test case naming deprecations - #573 by @simPod
fix(tree): explicit type precedence - #566 by @azjezz
chore: add support for PHP 8.5 - #549 by @veewee
feat: add Graph component with directed and undirected graph support - #547 by @azjezz
Graph component with directed and undirected graph support - #547 by @azjezzTree component for hierarchical data structures - #546 by @azjezzmake to just - #544 by @azjezzrefactor: remove redundant @var tags from constants - #533 by @azjezz
@var tags from constants - #533 by @azjezzPsl\Result\wrap() no longer unwraps nested results - #531 by @azjezz
Psl\Result\wrap() no longer unwraps nested results - #531 by @azjezzPsl\Collection\Map, Psl\Collection\MutableMap, Psl\Collection\Set, and Psl\Collection\MutableSet now have a more natural JSON serialization - #512 by @josh-raiPsl\IO and Psl\File namespaces have been removed to simplify the component's hierarchy - #518 by @azjezzPsl\sequence() function has been removed - #519 by @azjezzcontainer type - #513 by @azjezzint_range type - #510 by @george-steelalways_assert type - #522 by @azjezzsearch_with_keys_opt and search_with_keys functions - #490 by @simon-podlipskyIter and Regex - #528 by @azjezzNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
feat(encoding): introduce Base64\Variant enum to support encoding/decoding different variants - #408 by @Gashmob
Base64\Variant enum to support encoding/decoding different variants - #408 by @Gashmobfeat(type): introduce Type\converted function - #405 by @veewee
feat(result): introduce Result\try_catch function - #403 by @azjezz
fix(type): un-deprecate Psl\Type\positive_int function - #400 by @dragosprotung
Psl\Type\positive_int function - #400 by @dragosprotungdeprecated Psl\Type\positive_int function, use Psl\Type\uint instead - by @azjezz
Psl\Range component - #378 by @azjezzPsl\Str\range, Psl\Str\Byte\range, and Psl\Str\Grapheme\range functions - #385 by @azjezzPsl\Type\uint function - #393 by @azjezzPsl\Type\i8, Psl\Type\i16, Psl\Type\i32, Psl\Type\i64 functions - #392 by @azjezzPsl\Type\u8, Psl\Type\u16, Psl\Type\u32 functions - #395 by @KennedyTedescoPsl\Type\f32, and Psl\Type\f64 functions - #396 by @KennedyTedescoPsl\Type\nonnull function - #392 by @azjezzandThen method - #398 by @veeweePsl\Type\positive_int function, use Psl\Type\uint instead - by @azjezzfix(vec): Vec\reproduce and Vec\range return type is always non-empty-list - #383 by @dragosprotung
chore: support psalm v5 - #369 by @veewee
feat(option): introduce option component - #356 by @azjezz
introduced a new Psl\Type\unit_enum function - @19d1230 by @azjezz
Psl\Type\unit_enum function - @19d1230 by @azjezzPsl\Type\backed_enum function - @19d1230 by @azjezzPsl\Type\mixed_vec function - #362 by @BackEndTeaPsl\Type\mixed_dict function - #362 by @BackEndTeaPsl\Type\vec performance - #364 by @BackEndTeaPsl\Type\float, and Psl\Type\num - #367 by @bcremerNothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
BC - removed Psl\Arr component.
BC - removed Psl\Arr component.
BC - removed Psl\Type\is_array, Psl\Type\is_arraykey, Psl\Type\is_bool, Psl\Type\is_callable, Psl\Type\is_float, Psl\Type\is_instanceof, Psl\Type\is_int, Psl\Type\is_iterable, Psl\Type\is_null, Psl\Type\is_numeric, Psl\Type\is_object, Psl\Type\is_resource, Psl\Type\is_scalar, and Psl\Type\is_string functions ( use TypeInterface::matches($value) instead ).
BC - removed Psl\Iter\chain, Psl\Iter\chunk, Psl\Iter\chunk_with_keys, Psl\Iter\diff_by_key, Psl\Iter\drop, Psl\Iter\drop_while, Psl\Iter\enumerate, Psl\Iter\filter, Psl\Iter\filter_keys, Psl\Iter\filter_nulls, Psl\Iter\filter_with_key, Psl\Iter\flat_map, Psl\Iter\flatten, Psl\Iter\flip, Psl\Iter\from_entries, Psl\Iter\from_keys, Psl\Iter\keys, Psl\Iter\map, Psl\Iter\map_keys, Psl\Iter\map_with_key, Psl\Iter\merge, Psl\Iter\product, Psl\Iter\pull, Psl\Iter\pull_with_key, Psl\Iter\range, Psl\Iter\reductions, Psl\Iter\reindex, Psl\Iter\repeat, Psl\Iter\reproduce, Psl\Iter\reverse, Psl\Iter\slice, Psl\Iter\take, Psl\Iter\take_while, Psl\Iter\to_array, Psl\Iter\to_array_with_keys, Psl\Iter\values, and Psl\Iter\zip functions.
BC - signature of Psl\Iter\reduce_keys function changed from reduce_keys<Tk, Tv, Ts>(iterable<Tk, Tv> $iterable, (callable(?Ts, Tk): Ts) $function, Ts|null $initial = null): Ts|null to reduce_keys<Tk, Tv, Ts>(iterable<Tk, Tv> $iterable, (callable(Ts, Tk): Ts) $function, Ts $initial): Ts.
BC - signature of Psl\Iter\reduce_with_keys function changed from reduce_with_keys<Tk, Tv, Ts>(iterable<Tk, Tv> $iterable, (callable(?Ts, Tk, Tv): Ts) $function, Ts|null $initial = null): Ts|null to reduce_with_keys<Tk, Tv, Ts>(iterable<Tk, Tv> $iterable, (callable(Ts, Tk, Tv): Ts) $function, Ts $initial): Ts.
BC - removed bundled psalm plugin Psl\Integration\Psalm\Plugin, use php-standard-library/psalm-plugin package instead.
dropped support for PHP 8.0
BC - signature of Psl\Type\object function changed from object<T of object>(classname<T> $classname): TypeInterface<T> to object(): TypeInterface<object> ( to preserve the old behavior, use Psl\Type\instance_of )
introduced Psl\Type\instance_of function, with the signature of instance_of<T of object>(classname<T> $classname): TypeInterface<T>.
introduced a new Psl\Async component.
refactored Psl\IO handles API.
introduced a new Psl\File component.
refactor Psl\Shell\execute to use Psl\IO component.
introduced a Psl\IO\pipe(): (Psl\IO\CloseReadHandleInterface, Psl\IO\CloseWriteHandleInterface) function to create a pair of handles, where writes to the WriteHandle can be read from the ReadHandle.
BC - $encoding argument for Psl\Str functions now accepts Psl\Str\Encoding instead of ?string.
introduced a new Psl\Runtime component.
introduced a new Psl\Network component.
introduced a new Psl\TCP component.
introduced a new Psl\Unix component.
introduced a new Psl\Channel component.
introduced a new IO\write() function.
introduced a new IO\write_line() function.
introduced a new IO\write_error() function.
introduced a new IO\write_error_line() functions.
introduced a new Psl\Html\Encoding enum.
BC - $encoding argument for Psl\Html functions now accepts Psl\Html\Encoding instead of ?string.
BC - Psl\Shell\escape_command function has been removed, no replacement is available.
introduced a new Psl\Math\acos function.
introduced a new Psl\Math\asin function.
introduced a new Psl\Math\atan function.
introduced a new Psl\Math\atan2 function.
BC - The type of the $numbers argument of Psl\Math\mean has changed to list<int|float> instead of iterable<int|float>.
BC - The type of the $numbers argument of Psl\Math\median has changed to list<int|float> instead of iterable<int|float>.
introduced a new Psl\Promise component.
BC - Psl\Result\ResultInterface now implements Psl\Promise\PromiseInterface
BC - Psl\Type\resource('curl')->toString() now uses PHP built-in resource kind notation ( i.e: resource (curl) ) instead of generic notation ( i.e: resource<curl> )
BC - Psl\Str, Psl\Str\Byte, and Psl\Str\Grapheme functions now throw Psl\Str\Exception\OutOfBoundsException instead of Psl\Exception\InvaraintViolationsException when $offset is out-of-bounds.
BC - Psl\Collection\IndexAccessInterface::at() now throw Psl\Collection\Exception\OutOfBoundsException instead of Psl\Exception\InvariantViolationException if $k is out-of-bounds.
BC - Psl\Collection\AccessibleCollectionInterface::slice signature has changed from slice(int $start, int $length): static to slice(int $start, ?int $length = null): static
BC - All psl functions previously accepting callable, now accept only Closure.
BC - Psl\DataStructure\QueueInterface::dequeue, and Psl\DataStructure\StackInterface::pop now throw Psl\DataStructure\Exception\UnderflowException instead of Psl\Exception\InvariantViolationException when the data structure is empty.
BC - Psl\Filesystem\write_file($file, $content) function has been removed, use Psl\File\write($file, $content); instead.
To preserve the same behavior as the old function, use
Psl\File\write($file, $content, Filesystem\is_file($file) ? File\WriteMode::TRUNCATE : File\WriteMode::OPEN_OR_CREATE).
BC - Psl\Filesystem\read_file($file, $offset, $length) function has been removed, use Psl\File\read($file, $offset, $length) instead.
BC - Psl\Filesystem\append_file($file, $contents) function has been removed, use Psl\File\write($file, $contents, File\WriteMode::APPEND) instead.
BC - Psl\Filesystem functions no longer throw Psl\Exception\InvariantViolationException.
New exceptions:
Psl\Filesystem\Exception\NotReadableException thrown when attempting to read from a non-readable nodePsl\Filesystem\Exception\NotFileException thrown when attempting a file operation on a non-file node.Psl\Filesystem\Exception\NotDirectoryException thrown when attempting a directory operation on a non-directory node.Psl\Filesystem\Exception\NotSymbolicLinkException thrown when attempting a symbolic link operation on a non-symbolic link node.Psl\Filesystem\Exception\NotFoundException thrown when attempting an operation on a non-existing node.introduced Psl\Hash\Algorithm enum.
introduced Psl\Hash\Hmac\Algorithm enum.
BC - Psl\Hash\hash, and Psl\Hash\Context::forAlgorithm now take Psl\Hash\Algorithm as an algorithm, rather than a string.
BC - Psl\Hash\Hmac\hash, and Psl\Hash\Context::hmac now take Psl\Hash\Hmac\Algorithm as an algorithm, rather than a string.
BC - A new method chunk(positive-int $size): CollectionInterface has been added to Psl\Collection\CollectionInterface.
introduced a new Psl\OS component.
introduced Psl\Password\Algorithm enum
BC - all constants of Psl\Password component has been removed.
BC - function Psl\Password\algorithms() have been removed.
BC - Psl\Result\ResultInterface::getException() method has been renamed to Psl\Result\ResultInterface::getThrowable()
BC - Psl\Result\wrap function now catches all Throwables instead of only Exceptions
introduced a new Psl\Result\reflect function
BC - Psl\Shell\escape_argument function has been removed, Shell\execute arguments are now always escaped.
BC - $escape_arguments argument of Shell\execute function has been removed.
introduced a new Psl\Shell\ErrorOutputBehavior enum
added a new $error_output_behavior argument to Shell\execute function, which can be used to return the command error output content, as well as the standard output content.
introduced a new Psl\Shell\unpack function to unpack packed result of Shell\execute ( see Psl\Shell\ErrorOutputBehavior::Packed ).
introduced a new Psl\Shell\stream_unpack function to unpack packed result of Shell\execute chunk by chunk, maintaing order ( see Psl\Shell\ErrorOutputBehavior::Packed ).
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →