Skip to content

[BUGFIX] Return processed paths from plugin config - #19

Merged
sbuerk merged 3 commits into
mainfrom
bugfix/18-config-processed-paths
Sep 27, 2026
Merged

sbuerk merged 3 commits into
mainfrom
bugfix/18-config-processed-paths

Conversation

@sbuerk

@sbuerk sbuerk commented Sep 27, 2026 •

Copy link
Copy Markdown
Owner

Config::processFixtureExtensionPaths() computed the processed path
list, but returned the unprocessed input. The default (absolute) mode
of paths(), get() and all() was broken completely and a trailing
slash reached the fixture-path repository url.

The processed list is returned now. Relative mode normalizes paths the
same way the absolute mode does, keeps an empty result as the current
directory and merges selections of different notations of the same
path. Test cases cover both flags.

Two [TASK] commits keep CI green:

  • Guard the package name type in FixturePathRepository, which
    PHPStan reports with current dependencies.
  • Raise phpunit/phpunit from the pinned 9.6.22 to ^9.6.33. The
    pinned version is affected by CVE-2026-24765 and recent Composer
    versions refuse to install it, failing CI for PHP 8.1 and newer.

Resolves: #18

PHPStan reports a possibly invalid array key type for the package
name read from a fixture package `composer.json`, which is `mixed`
at that point.

The name is now verified to be a string before it is used to look
up a version from the repository options. A non-string name fails
package loading later on anyway, so behaviour does not change.
`Config::processFixtureExtensionPaths()` computed the processed
path list, but returned the unprocessed input. `paths()`, `get()`
and `all()` therefore handed out the configured keys as written in
`composer.json`, regardless of the passed flag. The default mode,
which should return absolute paths, was completely broken and a
trailing slash reached the `fixture-path` repository url.

The processed list is returned now. Relative mode normalizes the
configured path using the composer filesystem utility, the same
way the absolute mode already did. An empty result is kept as the
current directory, and selections of different notations of the
same path are merged instead of being dropped.

Additionally:

* `realpath()` normalizes before checking for an empty path, so
  `./` resolves to the base dir instead of reading an offset of an
  empty string.
* `isRelativePathsFlag()` checks the flag bit with `!== 0`, which
  does not depend on the constant value.
* An unused config instance left over in
  `handleRootPackageExtraConfig()` is removed.

Resolves: #18
`phpunit/phpunit` was pinned to 9.6.22, which is affected by
CVE-2026-24765 (PKSA-z3gr-8qht-p93v). Composer blocks packages with
known security advisories by default in recent versions, which lets
dependency installation fail in CI for PHP 8.1 and newer.

The constraint is raised to `^9.6.33`, the first 9.6 release that is
not affected, still supporting PHP 7.4.
@sbuerk
sbuerk merged commit 139d3d3 into main Sep 27, 2026
18 checks passed
@sbuerk
sbuerk deleted the bugfix/18-config-processed-paths branch September 27, 2026 14:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUGFIX] Config::processFixtureExtensionPaths() returns the unprocessed paths

1 participant