Repository navigation
Conversation
The triple-quote lookahead in readBlockString() moved one byte at a time and decoded at each step, so after a quote it could land inside a multibyte character and read past the end of the body. Comparing the next three bytes with substr() avoids decoding there. LexerTest::lexOne() now turns PHP warnings into exceptions, so out-of-bounds reads fail the tests instead of passing with a warning. 🤖 Generated with Claude Code
🤖 Generated with Claude Code
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Unterminated block strings ending in a quote and a multibyte character make the Lexer read past the document.
"""a"éraisesUninitialized string offset 7instead of aSyntaxError.The triple-quote lookahead in
readBlockString()now compares the next three bytes instead of decoding byte by byte.The old lookahead could land inside a multibyte character
After a quote, it moved the cursor one byte, decoded a character, and moved one byte again.
When the next character was multibyte, the second step started on a continuation byte.
readChar()read that byte as the lead byte of a 2-byte character.Backslashes followed by a multibyte character hit the same path.
Results are unchanged apart from the crash, and block strings lex faster
50,000 random block strings of quotes, backslashes,
\""", newlines and multibyte characters lex the same on master and on this branch.The only differences are the 1,218 inputs where master read out of bounds.
The lookahead decodes three fewer characters per character.
A document with 20,000 block string arguments parses in 0.98s instead of 1.76s.
Lexer tests now fail on PHP warnings
phpunit.xml.distdoes not fail on warnings, so the new cases passed even before the fix.LexerTest::lexOne()turns warnings into exceptions while lexing.🤖 Generated with Claude Code