Skip to content
CAI
Software that uses CAICheck a score

symfony/http-kernel

56.1

Adequate · 26 September 2026

14.3k

lines of production code

PHP

primary language

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the core HTTP kernel of the Symfony framework, responsible for managing the request lifecycle, resolving controllers, and handling responses. It provides a declarative attribute-based system for mapping request data, enforcing rate limits, and managing caching, while supporting fragment rendering and granular cache warming. The component also includes infrastructure for debugging, profiling, and logging, with a refactored architecture that decouples argument resolution from controller lookup.

How it got here

2010–2011 — HttpKernel architectural modernization

16 changes.

This period focused on a comprehensive refactoring of the HttpKernel component, decoupling controller resolution from argument handling and replacing legacy logging and caching subsystems with modern PSR standards. The work introduced new infrastructure for cache warming, granular cache clearing, and enhanced profiler storage, while deprecating older bundle and file locator classes to align with the DependencyInjection component.

2012 — HttpKernel test coverage and debugging

14 changes.

This period focused on establishing comprehensive unit test coverage for the HttpKernel component, including its bundles, cache mechanisms, controllers, and event listeners. It also introduced new debugging utilities for error handling, event tracing, and virtual request management to support these tests and improve observability.

2013–2017 — Controller argument resolution and fragment security

13 changes.

This period focused on modernizing the controller layer by introducing the ControllerMetadata component and a comprehensive suite of typed argument resolvers for handling request data, types, and attributes. Concurrently, the fragment rendering subsystem was refactored to enforce strict attribute validation and improve security, while extensive test coverage was added across HttpKernel, FileLocator, and exception handling components.

2019–2026 — HTTP Kernel attribute system

7 changes.

This period introduced a comprehensive set of PHP attributes for the HttpKernel component, enabling declarative control over controller behavior, request mapping, and rate limiting. The work included implementing new features like \#\[MapRequestPayload\] and \#\[RateLimit\], alongside extensive test coverage and fixture additions to validate the new attribute classes and their integration with the kernel.

Features

HttpKernel events now expose controller metadata and support attribute evaluation

The HttpKernel event classes (ControllerEvent, ControllerArgumentsEvent, ViewEvent, etc.) now include a \controllerMetadata\ property that provides read-only access to controller information, including arguments, named arguments, and attributes. This replaces the previous direct exposure of \ControllerArgumentsEvent\ in \ViewEvent\ (which is now deprecated). Additionally, these metadata objects and events now feature an \evaluate()\ method, allowing developers to evaluate expressions or closures against the controller's context (request, arguments, and controller instance) during the request lifecycle.

Event · high confidence

Introduce ControllerMetadata component for argument metadata

The new ControllerMetadata component provides the ArgumentMetadata class and ArgumentMetadataFactory to expose detailed metadata about controller method arguments, including names, types, variadic status, default values, nullability, and PHP 8 attributes. This enables argument resolvers to inspect and handle controller inputs more precisely, supporting features like attribute-based configuration and improved type resolution.

ControllerMetadata · high confidence

Introduce PSR-6 cache pool clearing capability

The CacheClearer component now includes a Psr6CacheClearer implementation that allows clearing specific PSR-6 cache pools by name, in addition to clearing all pools. This enables more granular cache management, allowing users to clear individual cache pools rather than only the entire cache directory.

CacheClearer · high confidence

Introduction of the Cache Warmer sub-framework

This change introduces a new cache warming infrastructure within the HttpKernel component, allowing applications to pre-generate cache artifacts and optimize performance. It adds the CacheWarmer and CacheWarmerAggregate classes to manage and execute multiple warmers, the WarmableInterface for defining cache-warming logic, and the CacheWarmerInterface to distinguish between mandatory and optional warmers. The aggregate handles deprecation logging during warmup and validates that warmers return valid files or classes for preloading, while also supporting a build directory for read-only artifacts.

CacheWarmer · high confidence

New HTTP Kernel attributes for controller configuration and request mapping

This release introduces a comprehensive set of new PHP attributes for the HttpKernel component, enabling declarative control over controller behavior and request data handling. Developers can now use \\#\[MapRequestPayload\]\ and \\#\[MapQueryString\]\ to automatically deserialize and validate request bodies and query strings into typed objects, while \\#\[MapQueryParameter\]\, \\#\[MapRequestHeader\]\, \\#\[MapDateTime\]\, and \\#\[MapUploadedFile\]\ provide targeted resolution for specific input types. Request handling is further enhanced with \\#\[Cache\]\ for defining HTTP cache headers, \\#\[RateLimit\]\ for declarative rate limiting, and \\#\[IsSignatureValid\]\ for validating signed requests. Controller lifecycle and output are managed via \\#\[AsController\]\ for service autoconfiguration, \\#\[Serialize\]\ for response serialization, and \\#\[WithHttpStatus\]\ and \\#\[WithLogLevel\]\ for customizing exception responses. The \\#\[ValueResolver\]\ base class and \\#\[AsTargetedValueResolver\]\ tag establish a new extensible system for custom argument resolvers.

Attribute · high confidence

New debug components for error handling, event tracing, and virtual request management

This change introduces three new classes in the Debug namespace to enhance debugging capabilities. ErrorHandlerConfigurator allows for centralized configuration of the error handler, including mapping error levels to loggers and managing scream/scope modes. TraceableEventDispatcher extends the base event dispatcher to integrate with the Stopwatch component, automatically managing sections for request, view, response, and terminate events to provide accurate performance profiling. VirtualRequestStack provides a mechanism to handle virtual requests separately from standard HTTP requests, preventing mixing of request types within the stack.

Debug · high confidence

New typed controller argument resolvers for request data

The Controller/ArgumentResolver location now includes a comprehensive suite of new value resolvers that enable type-hinted controller arguments to be automatically resolved from various request sources. Specifically, the diff adds resolvers for backed enums (BackedEnumValueResolver), dates (DateTimeValueResolver), default values (DefaultValueResolver), query parameters (QueryParameterValueResolver), request attributes (RequestAttributeValueResolver), request headers (RequestHeaderValueResolver), complex request payloads with validation (RequestPayloadValueResolver), the Request object itself (RequestValueResolver), services (ServiceValueResolver), the session (SessionValueResolver), UIDs (UidValueResolver), and variadic arguments (VariadicValueResolver). Additionally, it introduces a NotTaggedControllerValueResolver to provide better error messages when controllers are not registered as services, and a TraceableValueResolver to expose timing information via the stopwatch.

Controller/ArgumentResolver · high confidence

Removals

Removal of HttpKernel Cache subsystem

The Cache subsystem within the HttpKernel component has been removed. This includes the deletion of the Cache, Esi, EsiListener, and Store classes, which previously provided HTTP caching, Edge Side Includes (ESI) processing, and cache storage logic. Users relying on this built-in caching mechanism will no longer have access to these features in this location.

Cache · high confidence

Architecture

Refactored DataCollector architecture with new base class and interfaces

The DataCollector component has been refactored to introduce a new abstract DataCollector base class and a DataCollectorInterface, replacing the previous implementation. This change standardizes how collectors store and serialize data, introducing a cloneVar method for efficient serialization via VarDumper and a LateDataCollectorInterface for deferred data collection. Existing collectors like ConfigDataCollector, RequestDataCollector, and LoggerDataCollector have been updated to use this new structure, improving performance and consistency across the profiler.

DataCollector · high confidence

Behavioural changes

2517 commits (181 fixes) modifying (repo-wide)

A change to existing behaviour in (repo-wide) — 2517 commits (181 fixs), 17 files.

(repo-wide) · low confidence · unverified

Decoupled argument resolution from controller resolution

The Controller component now separates the logic for determining which controller to execute from the logic for resolving its method arguments. A new ArgumentResolver and ArgumentResolverInterface handle argument resolution (including support for pinned resolvers via the \#\[ValueResolver\] attribute), while the ControllerResolverInterface is simplified to only return the controller callable. This architectural change allows argument resolvers to be extended or replaced independently of the controller lookup mechanism.

Controller · high confidence

Deprecation of HttpKernel Bundle infrastructure in favor of DependencyInjection

The \Symfony\\Component\\HttpKernel\\Bundle\ classes (\Bundle\, \AbstractBundle\, \BundleInterface\, and \BundleAdapter\) are now deprecated as of Symfony 8.1. The \BundleInterface\ in this namespace now extends the base interface from \Symfony\\Component\\DependencyInjection\\Kernel\, and the \Bundle\ class delegates its core logic to \BaseAbstractBundle\. Users should migrate to the DependencyInjection component's bundle infrastructure, using the \\#\[AsCommand\]\ attribute or the \console.command\ service tag instead of overriding the deprecated \registerCommands()\ method.

Bundle · high confidence

Deprecation of HttpKernel FileLocator class

The Symfony\\Component\\HttpKernel\\Config\\FileLocator class is now deprecated as of version 8.1. Users should migrate to Symfony\\Component\\DependencyInjection\\Kernel\\FileLocator instead, as the HttpKernel version now simply extends the DependencyInjection version and triggers a deprecation warning when used.

Config · high confidence

Expanded HTTP exception classes and refactored HttpException base

The HttpKernel now provides a broader set of specific HTTP exception classes (including AccessDenied, BadRequest, Conflict, Gone, LengthRequired, Locked, NotAcceptable, PreconditionFailed, PreconditionRequired, ServiceUnavailable, TooManyRequests, UnprocessableEntity, and UnsupportedMediaType) to allow developers to throw precise HTTP error responses. The base HttpException class has been refactored to implement HttpExceptionInterface, expose status codes and headers via typed properties, and include a static fromStatusCode factory method for dynamic exception creation. Additionally, ForbiddenHttpException was renamed to PreconditionRequiredHttpException (status 428), and UnauthorizedHttpException now requires a WWW-Authenticate challenge string.

Exception · high confidence

HttpCache component refactored with new architecture and SSI support

The HttpCache component has been significantly restructured to improve reliability and add new capabilities. The cache store now uses flock() for file locking to prevent race conditions, and the ESI/SSI rendering logic has been moved away from eval() to a safer boundary-based evaluation method. A new SSI (Server-Side Includes) implementation has been added alongside the existing ESI support, allowing both tag types to be processed. Additionally, the component now supports the X-Forwarded-For header for better proxy compatibility, and the cache key generation has been updated to use the xxh128 algorithm for improved performance.

HttpCache · high confidence

HttpKernel DI components moved and legacy classes deprecated

The DependencyInjection sub-namespace of HttpKernel has been reorganized: core compiler passes (ControllerArgumentValueResolverPass, ControllerAttributesListenerPass, FragmentRendererPass, LoggerPass, RegisterControllerArgumentLocatorsPass, RegisterLocaleAwareServicesPass, RemoveEmptyControllerArgumentLocatorsPass, ResettableServicePass) and the ConfigurableExtension base class are now defined in this location, while the legacy Extension, MergeExtensionConfigurationPass, ServicesResetter, and ServicesResetterInterface classes are deprecated in favor of their counterparts in the DependencyInjection component.

DependencyInjection · high confidence

Introduce AppliedRateLimit class to expose rate limit state

A new \AppliedRateLimit\ class has been added to the \Symfony\\Component\\HttpKernel\\RateLimiter\ namespace. This class wraps a \RateLimit\ instance and the number of tokens consumed, providing a \getRemainingCalls()\ method that calculates the remaining calls by dividing remaining tokens by the consumed token count. This internal structure supports the exposure of rate limit details, such as the \X-RateLimit-\*\ headers, for requests governed by the \\#\[RateLimit\]\ attribute.

RateLimiter · high confidence

Profiler storage refactored to use file-based storage with search enhancements

The profiler's storage mechanism has been replaced with a new file-based implementation (FileProfilerStorage) that stores data in subfolders and compresses profiles using gzip. This change introduces the ability to search profiler results by HTTP status code, request method, and time range, and adds visual indicators in the profiler list for errors and dump output. Additionally, the Profiler class now supports explicit enable/disable toggling and integrates with a new ProfilerStateChecker for conditional activation.

Profiler · high confidence

Redesigned Symfony Welcome Page with dynamic theming and animations

The Symfony Welcome Page has been completely redesigned with a new visual identity, including a starry night background animation and a randomized color theme for each visit. The page now features embedded SVG icons from the Tabler Icons project and includes a favicon. It is displayed when no routing configuration is found or no homepage is defined, providing a better onboarding experience for new projects.

Resources · high confidence

Refactored event listeners to support controller attributes and improved session handling

The EventListener component has been restructured to support the new controller attribute system and fix session management. A new ControllerAttributesListener now dispatches events for controller attributes, enabling listeners like CacheAttributeListener and IsSignatureValidAttributeListener to react to attributes such as \#\[Cache\] and \#\[IsSignatureValid\] directly on controllers. Session handling in AbstractSessionListener has been improved to better support non-standard PHP runtimes (like RoadRunner or Swoole) by explicitly managing session cookies and IDs, and to prevent sending deleted session cookies twice. Additionally, the DebugHandlersListener is now marked as internal, and the DisallowRobotsIndexingListener ensures dev applications are not indexed by search engines.

EventListener · high confidence

Refactored fragment rendering with new URI generation and strict attribute validation

The Fragment component has been restructured to improve reliability and security. A new \FragmentUriGenerator\ class now centralizes the creation of fragment URLs, ensuring that controller attributes are strictly validated to contain only scalar or null values, which prevents errors when passing complex objects to ESI and SSI renderers. The \AbstractSurrogateFragmentRenderer\ now enforces this validation and properly escapes URIs in surrogate tags to ensure valid HTML output. Additionally, the \InlineFragmentRenderer\ has been updated to correctly forward request headers, locale, format, and the \\_stateless\ attribute to sub-requests, resolving inconsistencies in sub-request context. The \HIncludeFragmentRenderer\ is now deprecated in favor of ESI, inline, or Symfony UX Turbo.

Fragment · high confidence

Replaces legacy logger with PSR-3 implementation and updates debug interfaces

The legacy \LoggerInterface\ with its custom methods (e.g., \emerg\, \crit\, \err\) has been removed and replaced by a new \Logger\ class that implements PSR-3 (\AbstractLogger\). This new logger writes to stderr or specified streams, respects the \SHELL\_VERBOSITY\ environment variable for default log levels, and includes a \DebugLoggerConfigurator\ to manage debug processors. The \DebugLoggerInterface\ has been updated to return structured log arrays including timestamps and context, and now supports per-request log tracking via the \RequestStack\.

Log · high confidence

Test coverage

Added AcmeFooBundle test fixture for configuration prepend behavior; Added controller test fixtures for attribute-based resolution and type handling; Added placeholder files to test fixtures; Added test coverage for HttpKernel exception classes; Added test fixture attributes for HttpKernel attribute handling; Added test fixture for ExtensionPresentBundle; Added test fixture for bundle-as-compiler-pass functionality; Added test fixture for invalid extension bundle; Added test fixtures for DataCollector scenarios; Added test fixtures for HttpKernel resettable services and signature validation; Added tests for ArgumentMetadata and ArgumentMetadataFactory; Added tests for FileLocator resource location behavior; Added tests for HttpKernel attribute classes; Added tests for Symfony HttpKernel Bundle behavior; Added tests for new controller attribute event classes and methods; Added tests for the HttpKernel Logger; Added unit tests for CacheWarmerAggregate and CacheWarmer; Added unit tests for ChainCacheClearer and Psr6CacheClearer; Added unit tests for FileProfilerStorage and Profiler; Added unit tests for HttpCache components; Added unit tests for HttpKernel DataCollectors; Added unit tests for HttpKernel argument value resolvers; Added unit tests for HttpKernel components; Added unit tests for HttpKernel controller and argument resolvers; Added unit tests for HttpKernel dependency injection compiler passes; Added unit tests for HttpKernel event listeners; Added unit tests for HttpKernel fragment renderers.

Dependencies

Symfony HttpKernel 8.2 dependency requirements

The \symfony/http-kernel\ package now requires PHP 8.4.1 or higher and aligns its dependencies with Symfony 8.2 components (such as \symfony/event-dispatcher\, \symfony/http-foundation\, \symfony/dependency-injection\, \symfony/routing\, and \symfony/var-dumper\). It also enforces conflicts with \symfony/flex\ versions older than 2.10 and specific older versions of \symfony/rate-limiter\ and \symfony/serializer\ to ensure compatibility.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 43 → 56 (+12.8)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 88 → 82 (-5.5)
  • Architecture 94 → 99 (+4.7)
  • Maturity 42 → 48 (+5.3)
  • Readiness 17 → 42 (+25.0)
  • Security 100 → 100 (+0.0)

Resolved (28)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • Duplicated block (11 lines × 3) (Tests/HttpCache/HttpCacheTest.php)
  • Duplicated block (12 lines × 2) (Tests/Controller/ArgumentResolver/UploadedFileValueResolverTest.php)
  • Duplicated block (15 lines × 2) (Tests/HttpCache/HttpCacheTest.php)
  • Duplicated block (17 lines × 2) (Tests/Controller/ArgumentResolver/RequestHeaderValueResolverTest.php)
  • Duplicated block (5 lines × 2) (Tests/HttpCache/EsiTest.php)
  • Duplicated block (5 lines × 2) (Tests/HttpCache/SsiTest.php)
  • Duplicated block (5 lines × 3) (Tests/HttpCache/EsiTest.php)
  • Duplicated block (5 lines × 3) (Tests/HttpCache/StoreTest.php)
  • Duplicated block (6 lines × 2) (Tests/DataCollector/LoggerDataCollectorTest.php)
  • Duplicated block (6 lines × 2) (Tests/DependencyInjection/RegisterControllerArgumentLocatorsPassTest.php)
  • Duplicated block (6 lines × 2) (Tests/EventListener/LocaleAwareListenerTest.php)
  • Duplicated block (6 lines × 2) (Tests/EventListener/RateLimitAttributeListenerTest.php)
  • Duplicated block (6 lines × 2) (Tests/Fragment/InlineFragmentRendererTest.php)
  • Duplicated block (7 lines × 2) (Tests/Controller/ArgumentResolver/QueryParameterValueResolverTest.php)
  • Duplicated block (7 lines × 2) (Tests/EventListener/CacheAttributeListenerTest.php)
  • Duplicated block (7 lines × 2) (Tests/EventListener/RouterListenerTest.php)
  • Duplicated block (7 lines × 2) (Tests/EventListener/SessionListenerTest.php)
  • Duplicated block (7 lines × 2) (Tests/Fragment/InlineFragmentRendererTest.php)
  • …and 8 more

New (166)

  • AbstractSessionListener.onKernelResponse (cognitive 26) (EventListener/AbstractSessionListener.php)
  • AbstractSessionListener.onKernelResponse (cyclomatic 19) (EventListener/AbstractSessionListener.php)
  • ArgumentResolver.getArguments (cognitive 70) (Controller/ArgumentResolver.php)
  • ArgumentResolver.getArguments (cyclomatic 26) (Controller/ArgumentResolver.php)
  • Boundary-crossing change coupling: CacheWarmer.php ↔ Store.php (CacheWarmer/CacheWarmer.php)
  • CacheAttributeListener.processAttributeAfterController (cognitive 29) (EventListener/CacheAttributeListener.php)
  • CacheAttributeListener.processAttributeAfterController (cyclomatic 30) (EventListener/CacheAttributeListener.php)
  • CacheWarmerAggregate.warmUp (cognitive 42) (CacheWarmer/CacheWarmerAggregate.php)
  • CacheWarmerAggregate.warmUp (cyclomatic 27) (CacheWarmer/CacheWarmerAggregate.php)
  • Change coupling: Esi.php ↔ Ssi.php (HttpCache/Esi.php)
  • Change coupling: RegisterControllerArgumentLocatorsPass.php ↔ RemoveEmptyControllerArgumentLocatorsPass.php (DependencyInjection/RegisterControllerArgumentLocatorsPass.php)
  • ConfigDataCollector.collect (cognitive 20) (DataCollector/ConfigDataCollector.php)
  • ConfigDataCollector.collect (cyclomatic 20) (DataCollector/ConfigDataCollector.php)
  • ControllerEvent.setController (cognitive 21) (Event/ControllerEvent.php)
  • ControllerResolver.checkController (cognitive 24) (Controller/ControllerResolver.php)
  • ControllerResolver.checkController (cyclomatic 17) (Controller/ControllerResolver.php)
  • ControllerResolver.getController (cognitive 21) (Controller/ControllerResolver.php)
  • ControllerResolver.getControllerError (cognitive 21) (Controller/ControllerResolver.php)
  • ControllerResolver.getControllerError (cyclomatic 17) (Controller/ControllerResolver.php)
  • DateTimeValueResolver.resolve (cognitive 23) (Controller/ArgumentResolver/DateTimeValueResolver.php)
  • …and 146 more

Changes since last survey

  • 93 commits — 83 feature/other, 10 fixes

By area

  • (repo) — 38 commits
  • (root) — 33 commits
  • Tests/KernelTest.php — 3 commits
  • EventListener/LocaleAwareListener.php — 2 commits
  • Profiler/FileProfilerStorage.php — 2 commits
  • Tests/Controller — 2 commits
  • CacheWarmer/CacheWarmerAggregate.php — 1 commit
  • Controller/ArgumentResolver — 1 commit
  • Controller/ControllerResolver.php — 1 commit
  • DataCollector/DumpDataCollector.php — 1 commit
  • DataCollector/EventDataCollector.php — 1 commit
  • DataCollector/LoggerDataCollector.php — 1 commit
  • DependencyInjection/ServicesResetter.php — 1 commit
  • EventListener/AbstractSessionListener.php — 1 commit
  • EventListener/ProfilerListener.php — 1 commit
  • Fragment/InlineFragmentRenderer.php — 1 commit
  • HttpCache/HttpCache.php — 1 commit
  • Tests/EventListener — 1 commit
  • Tests/HttpCache — 1 commit

Notable commits

  • fix: [HttpKernel] Fix concurrent cache warmups corrupting the deprecations log
  • fix: [HttpKernel] Fix failing reset methods preventing later services from resetting
  • fix: [HttpKernel] Fix regression when a locale aware service is never initialized
  • fix: [HttpKernel] Fix undefined $lock variable when locking the container build fails early
  • fix: bug #65496 [HttpKernel] Send the response content before terminating the kernel in the test client (nicolas-grekas)
  • fix: bug #65512 [HttpKernel] Ignore the session id that PHP kept from a previous request (nicolas-grekas)
  • fix: bug #65516 [HttpKernel] Forward the request headers to inline rendered fragments (nicolas-grekas)
  • fix: bug #65526 [HttpKernel] Restore the locale that was in use before a sub-request (nicolas-grekas)
  • fix: bug #65540 [HttpKernel] Fix caching responses that cannot provide their content (nicolas-grekas)
  • fix: bug #65687 [HttpKernel] Validate the profiler token before using it as a file name (nicolas-grekas)
  • change: Bump Symfony version to 6.4.45
  • change: Bump Symfony version to 6.4.46-DEV
  • change: Bump Symfony version to 7.4.17-DEV
  • change: Bump Symfony version to 7.4.18
  • change: Bump Symfony version to 7.4.19-DEV
  • change: Bump Symfony version to 8.1.5-DEV
  • change: Bump Symfony version to 8.1.6
  • change: Bump Symfony version to 8.1.7-DEV
  • change: Check arrays and bools directly instead of comparing them to count()/true/false/[]
  • change: Check arrays and bools directly instead of comparing them to count()/true/false/[]
  • …and 73 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

symfony/http-kernel was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 05a2a41a51bab5bf28c0df6b787a77ba56d7ff35 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.