Req #77521 [Com]: Validate regexes
Edit report at https://bugs.php.net/bug.php?id=77521&edit=1
ID: 77521
Comment by: flip101 at gmail dot com
Reported by: flip101 at gmail dot com
Summary: Validate regexes
Status: Open
Type: Feature/Change Request
Package: PCRE related
Operating System: Ubuntu 18.04
PHP Version: 7.3.1
Block user comment: N
Private report: N
New Comment:
Hi danack. Before when i tested this my PHP shell (psysh) was not showing the PREG_INTERNAL_ERROR
value. When i put your code in a file i see this error too. That's great now i don't need
a custom error handler. However i still like a separate function for validating the regex.
Unfortunately adding a PREG_INVALID_PATTERN won't be backwards compatible now because people
might already be checking for $preg === 1 :(
I'm not sure if PREG_INTERNAL_ERROR can happen in other ways that having an invalid pattern. It
would be good to make the invalid pattern case explicit.
Previous Comments:
------------------------------------------------------------------------
[2019-01-25 16:17:37] danack@php.net
I believe using preg_last_error() and silencing the preg_match error gives a sane way to validate if
a regex is acceptable to PCRE.
$invalid_pattern = '/(\d+/';
$dummy_subject = '';
@preg_match($invalid_pattern, $dummy_subject);
$lastError = preg_last_error();
if ($lastError) {
echo "something was wrong with the regex";
}
Does that not cover detecting valid regexes?
Admittedly getting the exact position of the error would be more than a little useful...
------------------------------------------------------------------------
[2019-01-25 15:53:30] flip101 at gmail dot com
Description:
------------
At the moment there is poor support to validate a regex. Since the inception of PHP where it was
mainly used for creating personal home pages it's been used in more domains. Therefor having
the ability to validate regexes would be a useful thing.
As far as i know regexes can be validated to the PCRE engine in the following way:
1. make a custom error handler for PHP warning
2. register customer error handler
3. call preg_match with invalid regex
4. unregister custom error handler.
5. throw exception (or another way of dealing with the error)
The motivation that led me here is the following library and issue:
https://hoa-project.net/En/Literature/Hack/Compiler.html#PP_language
https://github.com/hoaproject/Compiler/issues/15
But i believe there will be other projects now and in the feature that would benefit from a change
in PHP PCRE module.
I propose the following changes that should be backwards compatible:
1. Add constant PREG_INVALID_PATTERN (representing int 7) to https://secure.php.net/manual/en/function.preg-last-error.php
which gets set when a pattern is an invalid regex.
2. Add a bool preg_validate_pattern($string) function that only calls the PCRE2 compile function
and checks for succesful compilation. Skipping the step of actually trying to match a subject which
is usually done.
Test script:
---------------
<?php
$invalid_pattern = '/(\d+/';
$dummy_subject = '';
preg_match($invalid_pattern, $dummy_subject);
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77521&edit=1
Thread (9 messages)