Merge branch 'master' into sh_merge_master
diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml
index 5c89064..e3f2370 100644
--- a/.github/workflows/ci.yml
+++ b/.github/workflows/ci.yml
@@ -40,6 +40,7 @@
         - 'pypy-3.8'
         - 'pypy-3.9'
         - 'pypy-3.10'
+        - 'pypy-3.11'
         - 'graalpy-24.1'
 
         # Items in here will either be added to the build matrix (if not
diff --git a/docs/advanced/functions.rst b/docs/advanced/functions.rst
index 372934b..ff00c9c 100644
--- a/docs/advanced/functions.rst
+++ b/docs/advanced/functions.rst
@@ -81,9 +81,11 @@
 |                                                  | it is no longer used. Warning: undefined behavior will ensue when the C++  |
 |                                                  | side deletes an object that is still referenced and used by Python.        |
 +--------------------------------------------------+----------------------------------------------------------------------------+
-| :enum:`return_value_policy::reference_internal`  | Indicates that the lifetime of the return value is tied to the lifetime    |
-|                                                  | of a parent object, namely the implicit ``this``, or ``self`` argument of  |
-|                                                  | the called method or property. Internally, this policy works just like     |
+| :enum:`return_value_policy::reference_internal`  | If the return value is an lvalue reference or a pointer, the parent object |
+|                                                  | (the implicit ``this``, or ``self`` argument of the called method or       |
+|                                                  | property) is kept alive for at least the lifespan of the return value.     |
+|                                                  | **Otherwise this policy falls back to :enum:`return_value_policy::move`    |
+|                                                  | (see #5528).** Internally, this policy works just like                     |
 |                                                  | :enum:`return_value_policy::reference` but additionally applies a          |
 |                                                  | ``keep_alive<0, 1>`` *call policy* (described in the next section) that    |
 |                                                  | prevents the parent object from being garbage collected as long as the     |
diff --git a/include/pybind11/attr.h b/include/pybind11/attr.h
index dc9570f..1b513f5 100644
--- a/include/pybind11/attr.h
+++ b/include/pybind11/attr.h
@@ -363,7 +363,7 @@
 
         bases.append((PyObject *) base_info->type);
 
-#if PY_VERSION_HEX < 0x030B0000
+#ifdef PYBIND11_BACKWARD_COMPATIBILITY_TP_DICTOFFSET
         dynamic_attr |= base_info->type->tp_dictoffset != 0;
 #else
         dynamic_attr |= (base_info->type->tp_flags & Py_TPFLAGS_MANAGED_DICT) != 0;
diff --git a/include/pybind11/detail/class.h b/include/pybind11/detail/class.h
index f53fdf7..08e23af 100644
--- a/include/pybind11/detail/class.h
+++ b/include/pybind11/detail/class.h
@@ -576,9 +576,9 @@
 inline void enable_dynamic_attributes(PyHeapTypeObject *heap_type) {
     auto *type = &heap_type->ht_type;
     type->tp_flags |= Py_TPFLAGS_HAVE_GC;
-#if PY_VERSION_HEX < 0x030B0000 || defined(PYPY_VERSION) // For PyPy see PR #5508
-    type->tp_dictoffset = type->tp_basicsize;            // place dict at the end
-    type->tp_basicsize += (ssize_t) sizeof(PyObject *);  // and allocate enough space for it
+#ifdef PYBIND11_BACKWARD_COMPATIBILITY_TP_DICTOFFSET
+    type->tp_dictoffset = type->tp_basicsize;           // place dict at the end
+    type->tp_basicsize += (ssize_t) sizeof(PyObject *); // and allocate enough space for it
 #else
     type->tp_flags |= Py_TPFLAGS_MANAGED_DICT;
 #endif
diff --git a/include/pybind11/detail/common.h b/include/pybind11/detail/common.h
index eab3e1c..f119474 100644
--- a/include/pybind11/detail/common.h
+++ b/include/pybind11/detail/common.h
@@ -1261,5 +1261,10 @@
 #    define PYBIND11_DETAILED_ERROR_MESSAGES
 #endif
 
+// CPython 3.11+ provides Py_TPFLAGS_MANAGED_DICT, but PyPy3.11 does not, see PR #5508.
+#if PY_VERSION_HEX < 0x030B0000 || defined(PYPY_VERSION)
+#    define PYBIND11_BACKWARD_COMPATIBILITY_TP_DICTOFFSET
+#endif
+
 PYBIND11_NAMESPACE_END(detail)
 PYBIND11_NAMESPACE_END(PYBIND11_NAMESPACE)