RFC [Discussion]: Improve unserialize() error handling
| From: | Tim Düsterhus | Date: | Mon, 05 Sep 2022 17:20:00 +0000 |
| Subject: | RFC [Discussion]: Improve unserialize() error handling | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-118566@lists.php.net to get a copy of this message | ||
Hi
I've now written up an RFC as a follow-up for the "What type of Exception to use for unserialize() failure?" thread [1]:
----
RFC: Improve unserialize() error handling
https://wiki.php.net/rfc/improve_unserialize_error_handling
Proof of concept implementation is in:
https://github.com/php/php-src/pull/9425
Discussion period for that RFC is officially opened up.
----
The primary point of discussion in the previous mailing list thread and in the PR comments is whether unserialize() should continue to emit E_WARNING or whether that should consistently be changed to an Exception. As of now I plan to explicitly vote on this and the RFC contains some opinions on that matter.
Best regards
Tim Düsterhus
[1] https://externals.io/message/118311