Files
regex-tools/engines/php
..

PHP preg regular-expression engine

Regex Tools runs patterns in the actual PHP 8.5.8 preg implementation, backed by PCRE2 10.44. The browser runtime is the Asyncify build from @php-wasm/web-8-5@3.1.46; its host API is @php-wasm/universal@3.1.46.

The fixed bridge.php file is installed in PHP's private virtual filesystem. Pattern, flags, subject, limits, and replacement are written separately as JSON. No user-controlled value is evaluated or interpolated into PHP source. The bridge selects a safe preg delimiter and passes only validated modifiers.

PHP reports PREG_OFFSET_CAPTURE positions as UTF-8 bytes. The adapter retains those native ranges and normalizes code-point boundaries to browser UTF-16. Unpaired UTF-16 surrogates are rejected before entering the runtime. Without the u modifier, a byte-oriented match that splits a UTF-8 character is reported as unsupported because it cannot be represented losslessly in a browser string.

Replacement never asks preg_replace to materialize an unbounded result. Native preg_match records remain authoritative; a fixed bridge parser mirrors PHP 8.5.8's preg_get_backref() rules and streams literal/capture bytes into the requested cap. The identity self-test compares that fixed implementation with preg_replace only as a parity oracle. The bridge returns bounded bytes as base64 so JSON escaping cannot unexpectedly multiply the transport envelope. A timeout, cancellation, supersession, or crash terminates the dedicated worker and its entire PHP WebAssembly heap.

Exact source and native-component boundary

The shipped php.wasm is SHA-256 ed97ea5422dbf23e0687c98203cc8c6d7f2772a3d71b03d4991d2fdd93a048f0 from @php-wasm/web-8-5@3.1.46. That npm package records WordPress Playground commit 581c7c172428159eb4e6c5309054a568cd39a97a (v3.1.46). The PHP source base is tag php-8.5.8, tag object 8a3b5a5124006c11a8fbfce838ec7dd53615cc77, peeled commit 26b97507444c4fbda072f57dda1820f7b7d5e467; the final main module uses Emscripten 4.0.19 at 08e2de1031913e4ba7963b1c56f35f036a7d4d56.

native-components.json is the machine-readable inventory for this exact binary. It records 32 linked source/component surfaces:

  • PHP and its bundled PCRE2, libbcmath, timelib/tzdata, libmagic, Lexbor, libmbfl, uriparser and libavifinfo code;
  • zlib, libzip, libxml2, SQLite, libgd, libjpeg-turbo, libpng, libwebp/libsharpyuv, libavif, libaom/libyuv, OpenSSL, curl, libiconv and Oniguruma;
  • the WordPress Playground wrapper plus the Emscripten runtime, musl, compiler-rt, libc++, libc++abi and dlmalloc surfaces.

Every versioned external archive or Git route, available archive hash/commit, runtime evidence, licence/notice route and patent notice is recorded there. The Oniguruma recipe is the one upstream exception: it cloned its default branch without a revision. The inventory therefore does not falsely identify the release tag as the build commit. It pins the exact committed libonig.a blob and SHA-256, its Emscripten 4.0.5 compiler provenance, the installed header blob, runtime version 6.9.10, audited release source and the bounded upstream source interval 005482a…3eb317d before the header changed.

The same inventory explicitly records why GMP, libsodium, tidy and ICU/intl names found by a raw string scan are not linked extensions: those names are Zend optimizer metadata or an unshipped side module, and the runtime verifier asserts their absence. It also records that FreeType is disabled in the exact libgd recipe even though the recipe's synthetic gdlib-config --features string makes gd_info() report it, that ImageMagick/imagick is disabled, and that libavif's local AOM 3.12.1—not the adjacent standalone AOM 3.13.1 recipe—is linked. Positive extension/library versions, negative detections and AOM/libjpeg binary markers are executable pack-verification gates.

Redistribution

The pack explicitly elects PHP License version 4 (BSD-3-Clause) for the PHP 8.5.8 codebase through the earlier licence's later-version option. The pack also carries the exact Zend Engine licence, php-src's official binary redistribution notice, the CLI HTTP parser's MIT terms, and the public-domain, CC0 and FNV permission statements for the linked hash implementations. @php-wasm retains GPL-2.0-or-later. Linked LGPL, BSD, MIT, Apache, zlib, public-domain and patent-notice obligations are carried in 42 independently SHA-256-pinned legal files. The builder copies the inventory and those exact files into the closed pack; SHA256SUMS and engine-metadata.json cover them again, but cannot replace the independent hashes in the verifier lock.