Re: Null bytes in anonymous class names
| From: | Rowan Collins | Date: | Thu, 05 Nov 2015 14:59:29 +0000 |
| Subject: | Re: Null bytes in anonymous class names | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-89082@lists.php.net to get a copy of this message | ||
On 05/11/2015 14:21, Niklas Keller wrote:
Hello, I discovered today that anonymous class names contain a null byte right after "class@anonymous". I don't think class names should contain non-printable characters. How about removing that null byte? https://3v4l.org/QUKpV https://github.com/php/php-src/blob/da8e6ec4a5063d9f60f83f43c55bc17d015cac8b/Zend/zend_compile.c#L5207 Regards, NiklasPHP uses null bytes quite a lot to produce deliberately illegal identifiers. For instance the old eval-like create_function() [e.g. https://3v4l.org/hqHjh] and the serialization of private members [e.g. https://3v4l.org/R6Y6k] In this case, I guess the "@" in "class@anonymous" makes the name illegal anyway, but I'm not sold on the null byte being more unacceptable here than anywhere else. Regards, -- Rowan Collins [IMSoP]