pcre: shouldn't pass BAD_ESCAPE_IS_LITERAL by default
| From: | Sjon Hortensius | Date: | Fri, 08 Feb 2019 10:57:31 +0000 |
| Subject: | pcre: shouldn't pass BAD_ESCAPE_IS_LITERAL by default | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-104305@lists.php.net to get a copy of this message | ||
Hi internals,
PHP enables bad_escape_is_literal by default when using pcre methods - this
results in invalid escape-patterns (such as \i) being interpreted as a
literal
i. This option is documented in pcre as "a dangerous option. Use
with care" - and the pcre author raised concern about PHP enabling this by
default (see https://bugs.exim.org/show_bug.cgi?id=2362 ).
I agree and I'd like to propose to disable this in the next major version.
The existing modifier to disable this (X - PCRE_EXTRA) can be removed as
well. Would this require an RFC ?
Cheers,
Sjon