PHP preg regular-expression engine
Regex Tools runs patterns in the actual PHP 8.5.8 preg implementation,
backed by PCRE2 10.44. The browser runtime is the Asyncify build from
@php-wasm/web-8-5@3.1.46; its host API is
@php-wasm/universal@3.1.46.
The fixed bridge.php file is installed in PHP's private virtual filesystem.
Pattern, flags, subject, limits, and replacement are written separately as
JSON. No user-controlled value is evaluated or interpolated into PHP source.
The bridge selects a safe preg delimiter and passes only validated modifiers.
PHP reports PREG_OFFSET_CAPTURE positions as UTF-8 bytes. The adapter retains
those native ranges and normalizes code-point boundaries to browser UTF-16.
Unpaired UTF-16 surrogates are rejected before entering the runtime. Without
the u modifier, a byte-oriented match that splits a UTF-8 character is
reported as unsupported because it cannot be represented losslessly in a
browser string.
Replacement never asks preg_replace to materialize an unbounded result.
Native preg_match records remain authoritative; a fixed bridge parser mirrors
PHP 8.5.8's preg_get_backref() rules and streams literal/capture bytes into
the requested cap. The identity self-test compares that fixed implementation
with preg_replace only as a parity oracle. The bridge returns bounded bytes as
base64 so JSON escaping cannot unexpectedly multiply the transport envelope.
A timeout, cancellation, supersession, or crash terminates the dedicated
worker and its entire PHP WebAssembly heap.
Exact source and native-component boundary
The shipped php.wasm is SHA-256
ed97ea5422dbf23e0687c98203cc8c6d7f2772a3d71b03d4991d2fdd93a048f0
from @php-wasm/web-8-5@3.1.46. That npm package records WordPress Playground
commit 581c7c172428159eb4e6c5309054a568cd39a97a (v3.1.46). The PHP source
base is tag php-8.5.8, tag object
8a3b5a5124006c11a8fbfce838ec7dd53615cc77, peeled commit
26b97507444c4fbda072f57dda1820f7b7d5e467; the final main module uses
Emscripten 4.0.19 at
08e2de1031913e4ba7963b1c56f35f036a7d4d56.
native-components.json is the machine-readable inventory for this exact
binary. It records 32 linked source/component surfaces:
- PHP and its bundled PCRE2, libbcmath, timelib/tzdata, libmagic, Lexbor, libmbfl, uriparser and libavifinfo code;
- zlib, libzip, libxml2, SQLite, libgd, libjpeg-turbo, libpng, libwebp/libsharpyuv, libavif, libaom/libyuv, OpenSSL, curl, libiconv and Oniguruma;
- the WordPress Playground wrapper plus the Emscripten runtime, musl, compiler-rt, libc++, libc++abi and dlmalloc surfaces.
Every versioned external archive or Git route, available archive hash/commit,
runtime evidence, licence/notice route and patent notice is recorded there.
The Oniguruma recipe is the one upstream exception: it cloned its default
branch without a revision. The inventory therefore does not falsely identify
the release tag as the build commit. It pins the exact committed libonig.a
blob and SHA-256, its Emscripten 4.0.5 compiler provenance, the installed header
blob, runtime version 6.9.10, audited release source and the bounded upstream
source interval 005482a…3eb317d before the header changed.
The same inventory explicitly records why GMP, libsodium, tidy and ICU/intl
names found by a raw string scan are not linked extensions: those names are
Zend optimizer metadata or an unshipped side module, and the runtime verifier
asserts their absence. It also records that FreeType is disabled in the exact
libgd recipe even though the recipe's synthetic gdlib-config --features
string makes gd_info() report it, that ImageMagick/imagick is disabled, and
that libavif's local AOM 3.12.1—not the adjacent standalone AOM 3.13.1
recipe—is linked. Positive extension/library versions, negative detections and
AOM/libjpeg binary markers are executable pack-verification gates.
Redistribution
The pack explicitly elects PHP License version 4 (BSD-3-Clause) for the PHP
8.5.8 codebase through the earlier licence's later-version option.
The pack also carries the exact Zend Engine licence, php-src's official binary
redistribution notice, the CLI HTTP parser's MIT terms, and the
public-domain, CC0 and FNV permission statements for the linked hash
implementations. @php-wasm retains GPL-2.0-or-later. Linked LGPL, BSD, MIT,
Apache, zlib, public-domain and patent-notice obligations are carried in 42
independently SHA-256-pinned legal files. The builder copies the inventory and
those exact files into the closed pack; SHA256SUMS and
engine-metadata.json cover them again, but cannot replace the independent
hashes in the verifier lock.