[PEPr] Comment on RFC::EvalForbiddance
| From: | Philippe Jausions | Date: | Tue, 16 Aug 2005 19:03:43 +0000 |
| Subject: | [PEPr] Comment on RFC::EvalForbiddance | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-39429@lists.php.net to get a copy of this message | ||
Philippe Jausions (http://pear.php.net/user/jausions) has commented on the proposal for
RFC::EvalForbiddance.
Comment:
It should also be added that a workaround such as writing code to a file,
then including it, should be avoided just as well.
Another rational against the use of eval: performance. The code is
evaluated each time making it impossible to be code-byte cached by
optimizers.
What would really be useful is actual peer-review. But everybody is
time-crunched with their own packages, it could be difficult to keep on
eye on everybody's else package. Maybe some automated scan and post of
"suspicious" code to the PEAR-dev list on a regular basis would help for
that. (yes I know there is the CVS list.)
At least if the existing packages are scanned, we'll know where we stand.
Do we know how many packages are actually currently using eval()? There
may not be a reason for a complete ban, if the eval() is not widely
improperly used.
Proposal information:
http://pear.php.net/pepr/pepr-proposal-show.php?id=288
--
Sent by PEPr, the automatic proposal system at http://pear.php.net