Req #76797 [Wfx]: Ability to access php compiler (deprecated create_function)

From: Date: Tue, 13 Nov 2018 17:03:39 +0000
Subject: Req #76797 [Wfx]: Ability to access php compiler (deprecated create_function)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217936@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76797&edit=1 ID: 76797 User updated by: mageia at mokraemer dot de Reported by: mageia at mokraemer dot de Summary: Ability to access php compiler (deprecated create_function) Status: Wont fix Type: Feature/Change Request Package: *General Issues Operating System: Linux PHP Version: 7.2.9 Block user comment: N Private report: N New Comment: I thought eval solves the problem, but it is not. The changed behaviour of eval "Before PHP 7, in this case eval() returned FALSE and execution of the following code continued normally. It is not possible to catch a parse error in eval() using set_error_handler()." makes it impossible to check for syntax errors and handle them apropriate! Previous Comments: ------------------------------------------------------------------------ [2018-10-16 23:39:51] mageia at mokraemer dot de sorry, I didn't see your comment. You're right, eval solves my problem. ------------------------------------------------------------------------ [2018-10-16 23:16:53] mageia at mokraemer dot de is there any advice on how to check syntax inside php? For user contributed code, I really want to check the syntax before using the code. ------------------------------------------------------------------------ [2018-08-26 22:47:55] requinix@php.net * https://wiki.php.net/rfc/howto ------------------------------------------------------------------------ [2018-08-26 22:47:05] requinix@php.net I'm going to step up and say wontfix on this. The main problem here is that PHP isn't designed to work in a way where it can syntactically validate code and not allow that code to impact the runtime as well. There are assorted performance enhancements and features that assume code being inspected is supposed to be (potentially) executed. For example, class and function definitions are normally hoisted and that happens before any code is executed. Refactoring PHP to support another interstitial layer where code is validated before anything gets interpreted seems to me like a lot of effort for little gain. Consider that you can already php -l a file, plus there are third-party libraries out there that are made to do this. While it's definitely not a good suggestion, note that create_function is basically just a wrapper around eval()ing a function definition so if you don't mind ignoring common sense then there's not much to stop you from doing eval('function() { ?>' . preg_replace(['|use [\w,\s\\\\]*;|'], '', $code) . '<?php };'); If you feel strongly about adding something that can be accessed from PHP code, check out the RFC process. https://wiki.php.net/rfc (though the mailing lists are down...) ------------------------------------------------------------------------ [2018-08-26 21:00:13] mageia at mokraemer dot de Description: ------------ In previous versions it was possible to access the php compiler via create_function to make syntax checks on (generated) sources. Since this function is deprecated, there is no function to check php files for syntax errors in php. Unsing this function is a hack, I know. But using include,... will cause php to call the shutdown function. What I want, is just parsing of the file, and receiving an error object which shows me if and where errors are. Test script: --------------- $code='<?php my php script with errors;?>'; $var = create_function('', '?>' . preg_replace(['|use [\w,\s\\\\]*;|'], '', $code) . '<?php '); if(empty($var) && ( $error = error_get_last() )){ echo 'compile error. Details:'; print_r($error); } ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76797&edit=1

« previous php.bugs (#217936) next »