pcre: shouldn't pass BAD_ESCAPE_IS_LITERAL by default

From: Date: Fri, 08 Feb 2019 10:57:31 +0000
Subject: pcre: shouldn't pass BAD_ESCAPE_IS_LITERAL by default
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-104305@lists.php.net to get a copy of this message
Hi internals, PHP enables bad_escape_is_literal by default when using pcre methods - this results in invalid escape-patterns (such as \i) being interpreted as a literal i. This option is documented in pcre as "a dangerous option. Use with care" - and the pcre author raised concern about PHP enabling this by default (see https://bugs.exim.org/show_bug.cgi?id=2362 ). I agree and I'd like to propose to disable this in the next major version. The existing modifier to disable this (X - PCRE_EXTRA) can be removed as well. Would this require an RFC ? Cheers, Sjon

« previous php.internals (#104305) next »