Re: RFC [Discussion]: Improve unserialize() error handling
| From: | Larry Garfield | Date: | Wed, 07 Sep 2022 21:44:42 +0000 |
| Subject: | Re: RFC [Discussion]: Improve unserialize() error handling | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-118576@lists.php.net to get a copy of this message | ||
On Wed, Sep 7, 2022, at 10:37 AM, Tim Düsterhus wrote:
> Hi
>
> On 9/5/22 23:12, Larry Garfield wrote:
>>> RFC: Improve unserialize() error handling
>>>
>>> https://wiki.php.net/rfc/improve_unserialize_error_handling
>>>
>> Well-explained and well-argued. The only thing I'd add is that we should consider
>> bumping the E_NOTICE to an E_WARNING, *and* slating it to increase to an exception in 9.0. This
>> feels like a smaller BC concern than most, but people are extra sensitive these days about those
>> edge cases so it's probably good to be cautious.
>
> Can you please clarify whether you mean:
>
> 1. Change the existing E_WARNING option to "E_WARNING+Exception in 9.0".
> 2. Add a new "E_WARNING+Exception in 9.0" option the vote, such that the
> vote will be "E_WARNING" vs "E_WARNING+Exception in 9.0" vs
> "Exception"
>
> Best regards
> Tim Düsterhus
Either I guess? Honestly we should decide that in advance on the list. :-) E_WARNING+Exception in
9 is what I'd probably favor, with "Exception now" as a second choice.
--Larry Garfield