Edit report at https://bugs.php.net/bug.php?id=76797&edit=1
ID: 76797
User updated by: mageia at mokraemer dot de
Reported by: mageia at mokraemer dot de
Summary: Ability to access php compiler (deprecated
create_function)
Status: Wont fix
Type: Feature/Change Request
Package: *General Issues
Operating System: Linux
PHP Version: 7.2.9
Block user comment: N
Private report: N
New Comment:
is there any advice on how to check syntax inside php?
For user contributed code, I really want to check the syntax before using the code.
Previous Comments:
------------------------------------------------------------------------
[2018-08-26 22:47:55] requinix@php.net
* https://wiki.php.net/rfc/howto
------------------------------------------------------------------------
[2018-08-26 22:47:05] requinix@php.net
I'm going to step up and say wontfix on this.
The main problem here is that PHP isn't designed to work in a way where it can syntactically
validate code and not allow that code to impact the runtime as well. There are assorted performance
enhancements and features that assume code being inspected is supposed to be (potentially) executed.
For example, class and function definitions are normally hoisted and that happens before any code is
executed.
Refactoring PHP to support another interstitial layer where code is validated before anything gets
interpreted seems to me like a lot of effort for little gain. Consider that you can already
php -l a file, plus there are third-party libraries out there that are made to do this.
While it's definitely not a good suggestion, note that create_function is basically just a
wrapper around eval()ing a function definition so if you don't mind ignoring common sense then
there's not much to stop you from doing
eval('function() { ?>' . preg_replace(['|use [\w,\s\\\\]*;|'],
'', $code) . '<?php };');
If you feel strongly about adding something that can be accessed from PHP code, check out the RFC
process.
https://wiki.php.net/rfc
(though the mailing lists are down...)
------------------------------------------------------------------------
[2018-08-26 21:00:13] mageia at mokraemer dot de
Description:
------------
In previous versions it was possible to access the php compiler via create_function to make syntax
checks on (generated) sources. Since this function is deprecated, there is no function to check php
files for syntax errors in php.
Unsing this function is a hack, I know. But using include,... will cause php to call the shutdown
function. What I want, is just parsing of the file, and receiving an error object which shows me if
and where errors are.
Test script:
---------------
$code='<?php my php script with errors;?>';
$var = create_function('', '?>' . preg_replace(['|use
[\w,\s\\\\]*;|'], '', $code) . '<?php ');
if(empty($var) && ( $error = error_get_last() )){
echo 'compile error. Details:';
print_r($error);
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76797&edit=1