Re: Re: [PEPr] Comment on RFC::EvalForbiddance
| From: | Martin Jansen | Date: | Tue, 16 Aug 2005 20:17:53 +0000 |
| Subject: | Re: Re: [PEPr] Comment on RFC::EvalForbiddance | ||
| References: | 1 2 3 4 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-39438@lists.php.net to get a copy of this message | ||
On Tue Aug 16, 2005 at 11:3224PM +0400, Alexey Borzov wrote:
> So the only thing you gain from these proposal is a lot of noise from
> package developers who are using eval() and would like to continue doing so.
You (and a few others) have raised reasonable points today. I'm not yet
sure if I like them, but I'll think about them and adjust the proposal
accordingly.
If nothing else, we all spent a few minutes today digesting the problems
with eval(). ;-)
> >>While I do understand that in morons' packages eval() may create a huge
> >>security threat,
> >
> >I wouldn't call Stig and Daniel morons, but you are of course free to call
> >people whatever you want. :-)
>
> OK, using the word "moron" wasn't the brightest idea on my part, sorry.
>
> Indeed, these guys didn't have resources to even review the package they
> inherited for possible security issues. And now you think that people of
> their qualification will review package belonging to someone else?..
The RfC does not mention code review in the way you are imagining it
anywhere. Instead it demands that in cases where people want to add
new code that uses eval(), this *small portion* of code gets reviewed.
- Martin