Req #76797 [Wfx]: Ability to access php compiler (deprecated create_function)

From: Date: Tue, 16 Oct 2018 23:16:54 +0000
Subject: Req #76797 [Wfx]: Ability to access php compiler (deprecated create_function)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217599@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76797&edit=1

 ID:                 76797
 User updated by:    mageia at mokraemer dot de
 Reported by:        mageia at mokraemer dot de
 Summary:            Ability to access php compiler (deprecated
                     create_function)
 Status:             Wont fix
 Type:               Feature/Change Request
 Package:            *General Issues
 Operating System:   Linux
 PHP Version:        7.2.9
 Block user comment: N
 Private report:     N

 New Comment:

is there any advice on how to check syntax inside php?

For user contributed code, I really want to check the syntax before using the code.


Previous Comments:
------------------------------------------------------------------------
[2018-08-26 22:47:55] requinix@php.net

* https://wiki.php.net/rfc/howto

------------------------------------------------------------------------
[2018-08-26 22:47:05] requinix@php.net

I'm going to step up and say wontfix on this.

The main problem here is that PHP isn't designed to work in a way where it can syntactically
validate code and not allow that code to impact the runtime as well. There are assorted performance
enhancements and features that assume code being inspected is supposed to be (potentially) executed.
For example, class and function definitions are normally hoisted and that happens before any code is
executed.

Refactoring PHP to support another interstitial layer where code is validated before anything gets
interpreted seems to me like a lot of effort for little gain. Consider that you can already
php -l a file, plus there are third-party libraries out there that are made to do this.

While it's definitely not a good suggestion, note that create_function is basically just a
wrapper around eval()ing a function definition so if you don't mind ignoring common sense then
there's not much to stop you from doing
  eval('function() { ?>' . preg_replace(['|use [\w,\s\\\\]*;|'],
'', $code) . '<?php };');

If you feel strongly about adding something that can be accessed from PHP code, check out the RFC
process.
  https://wiki.php.net/rfc
(though the mailing lists are down...)

------------------------------------------------------------------------
[2018-08-26 21:00:13] mageia at mokraemer dot de

Description:
------------
In previous versions it was possible to access the php compiler via create_function to make syntax
checks on (generated) sources. Since this function is deprecated, there is no function to check php
files for syntax errors in php.

Unsing this function is a hack, I know. But using include,... will cause php to call the shutdown
function. What I want, is just parsing of the file, and receiving an error object which shows me if
and where errors are.

Test script:
---------------
$code='<?php my php script with errors;?>';
$var = create_function('', '?>' . preg_replace(['|use
[\w,\s\\\\]*;|'], '', $code) . '<?php ');
if(empty($var) && ( $error = error_get_last() )){
  echo 'compile error. Details:';
  print_r($error);
}



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=76797&edit=1


Thread (1 message)

  • mageia at mokraemer dot de
  • Unknown Message
    • mageia at mokraemer dot de
« previous php.bugs (#217599) next »