v26.09.8 — the consumer close() that stranded its client, and a main that could not pass its own gate
The leak
RdKafkaConsumerClient::close() called KafkaConsumer::close() and then released the property. Releasing the property is exactly right and was always there; it did nothing, because by the time it ran the handle was already gone.
ext-rdkafka 6.0.5, kafka_consumer.c:531-542, is the whole of that method:
rd_kafka_consumer_close(intern->rk);
intern->rk = NULL;
No rd_kafka_destroy(), and the free handler at kafka_consumer.c:53-64 destroys the handle only if (intern->rk) — which close() has just nulled. The PHP object is freed and the rd_kafka_t is not.
Measured on PHP 8.5.8 / ext-rdkafka 6.0.5 / librdkafka 2.15.1, no broker: four OS threads stranded per closed consumer, still there after five seconds of polling; zero when the reference is dropped. Unconditional, not a race. It now calls unsubscribe(), which leaves the group and lets the drop destroy the client.
The regression test counts rd_kafka_thread_cnt() rather than asserting a WeakReference goes null, because the natural test is green on this bug: the PHP object really is freed and the leak is underneath it, in C.
main could not pass composer check
Three reasons, which is why CI had been red on every PHP version since 26.09.6:
- The version is carried in four places and 26.09.6 moved one.
Version::VERSIONsaid26.09.6, the CHANGELOG heading26.09.7, the README badge26.09.5, and the verbatim listing indocs/versioning.md26.09.5— so the code inside the tagv26.09.7reported itself as26.09.6. All four now say26.09.8. pint --testwas red in three files from the 26.09.7 commit.phpstanhad three errors inInMemoryJwksProviderTest, from one missing@return.
composer check now passes: pint, phpstan clean, 3808 tests, deptrac 0/0.
Known: the split mirrors are still unpublished
The Release workflow refused again at its preflight, as it has since 26.09.5, and it is right to: the split action exits 0 even when its push fails, so the gate stops a matrix of green jobs that published nothing.
ACCESS_TOKEN is unset and the fireflyframework/firefly-* repositories do not exist. No split package has ever been published for any version. Fixing that needs an org PAT and the repositories — docs/publishing.md steps 6-7 — and is the one part of a release this project cannot do for itself.