Bug #77388 [PATCH]: invalid range in character class doesn't bubble up

From: Date: Wed, 17 Jul 2019 09:15:37 +0000
Subject: Bug #77388 [PATCH]: invalid range in character class doesn't bubble up
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-221824@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77388&edit=1

 ID:                 77388
 Patch added by:     sjon@php.net
 Reported by:        sjon at hortensius dot net
 Summary:            invalid range in character class doesn't bubble up
 Status:             Open
 Type:               Bug
 Package:            PCRE related
 Operating System:   archlinux
 PHP Version:        7.3.0
 Block user comment: N
 Private report:     N

 New Comment:

The following pull request has been associated:

Patch Name: Ref #77388 - disallow passing BAD_ESCAPE_IS_LITERAL, esp by default
On GitHub:  https://github.com/php/php-src/pull/4429
Patch:      https://github.com/php/php-src/pull/4429.patch


Previous Comments:
------------------------------------------------------------------------
[2019-01-09 19:05:24] cmb@php.net

> It's also advisable to stop passing the BAD_ESCAPE_IS_LITERAL
> flag by default from PHP, […]

Would you mind starting a discussion on the internals@ mailing
list?

> […] , should I file a separate bug/feature for that?

IMHO, this ticket is fine.

------------------------------------------------------------------------
[2019-01-06 10:22:21] sjon at hortensius dot net

this has been fixed in https://vcs.pcre.org/pcre2?view=revision&revision=1058

It's also advisable to stop passing the BAD_ESCAPE_IS_LITERAL flag by default from PHP, should
I file a separate bug/feature for that?

------------------------------------------------------------------------
[2019-01-01 14:58:25] sjon at hortensius dot net

thanks, I agree. I've filed https://bugs.exim.org/show_bug.cgi?id=2362
upstream

------------------------------------------------------------------------
[2018-12-31 11:41:01] nikic@php.net

Just checked, /[^_-\s]/bad_escape_is_literal in pcre2test works, so this is indeed the reason.

I think this is a PCRE bug though, because I don't think that option should affect this
particular case, because \s is a legal escape, it's just not allowed as part of a range.
Something like /[^\s-_]/bad_escape_is_literal results in a "Unrecognized escape sequence
"\s"" error.

------------------------------------------------------------------------
[2018-12-31 11:35:25] nikic@php.net

Might be because we're setting PCRE2_EXTRA_BAD_ESCAPE_IS_LITERAL for BC reasons, though I
don't think it's *supposed* to affect this case.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=77388


--
Edit this bug report at https://bugs.php.net/bug.php?id=77388&edit=1


Thread (9 messages)

« previous php.bugs (#221824) next »