Re: RFC [Discussion]: Improve unserialize() error handling

From: Date: Wed, 07 Sep 2022 21:44:42 +0000
Subject: Re: RFC [Discussion]: Improve unserialize() error handling
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to internals+get-118576@lists.php.net to get a copy of this message
On Wed, Sep 7, 2022, at 10:37 AM, Tim Düsterhus wrote: > Hi > > On 9/5/22 23:12, Larry Garfield wrote: >>> RFC: Improve unserialize() error handling >>> >>> https://wiki.php.net/rfc/improve_unserialize_error_handling >>> >> Well-explained and well-argued. The only thing I'd add is that we should consider >> bumping the E_NOTICE to an E_WARNING, *and* slating it to increase to an exception in 9.0. This >> feels like a smaller BC concern than most, but people are extra sensitive these days about those >> edge cases so it's probably good to be cautious. > > Can you please clarify whether you mean: > > 1. Change the existing E_WARNING option to "E_WARNING+Exception in 9.0". > 2. Add a new "E_WARNING+Exception in 9.0" option the vote, such that the > vote will be "E_WARNING" vs "E_WARNING+Exception in 9.0" vs > "Exception" > > Best regards > Tim Düsterhus Either I guess? Honestly we should decide that in advance on the list. :-) E_WARNING+Exception in 9 is what I'd probably favor, with "Exception now" as a second choice. --Larry Garfield

« previous php.internals (#118576) next »