Bug #80652 [NEW]: Regex delimiters not validated correctly
| From: | greg at subaqua dot co dot uk | Date: | Thu, 21 Jan 2021 13:13:11 +0000 |
| Subject: | Bug #80652 [NEW]: Regex delimiters not validated correctly | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-231677@lists.php.net to get a copy of this message | ||
From: greg at subaqua dot co dot uk
Operating system: n/a
PHP version: Irrelevant
Package: PCRE related
Bug Type: Bug
Bug description:Regex delimiters not validated correctly
Description:
------------
The documentation at
https://www.php.net/manual/en/regexp.reference.delimiters.php
says
that:
When using the PCRE functions, it is required that the pattern is
enclosed by delimiters. A delimiter can be any non-alphanumeric,
non-backslash, non-whitespace character.
The validation for delimiters works in *most* cases and gives a warning
such as:
Warning: preg_split(): Delimiter must not be alphanumeric or backslash
in php shell code on line 1
However, it fails to detect the invalid delimiters in the string " *,
*".
Instead, it runs without error/warning and gives output based on a
substring(?) of the supplied regex.
According to https://3v4l.org/DdBp1 it affects all versions of
PHP from
4.3 to 8.0
Test script:
---------------
# Valid delimiters - PASS
php > var_export(preg_split('/ *, */', 'a , b'));
array (
0 => 'a',
1 => 'b',
)
# Invalid delimiters - PASS - gives warning as expected
php > var_dump(preg_split('X *, *Y', 'a , b'));
Warning: preg_split(): Delimiter must not be alphanumeric or backslash
in php shell code on line 1
bool(false)
# Invalid delimiters - FAIL - should warn about either mismatched or
invalid delimiters.
# Instead, it gives no warning and unexpected output.
php > var_export(preg_split(' *, *', 'a , b'));
array (
0 => 'a ',
1 => 'b',
)
Expected result:
----------------
I expect the invalid delimiters to trigger a warning.
Actual result:
--------------
The invalid delimiters are silently ignored.
The output does not correspond to the supplied regex.
--
Edit bug report at https://bugs.php.net/bug.php?id=80652&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=80652&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=80652&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=80652&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=80652&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=80652&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=80652&r=support
Expected behavior: https://bugs.php.net/fix.php?id=80652&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=80652&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=80652&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=80652&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=80652&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=80652&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=80652&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=80652&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=80652&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=80652&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=80652&r=mysqlcfg