External References
This curated list of external resources provides authoritative information about regex syntax, engine behavior, and performance. These are the sources PHPRegex uses when verifying diagnostics and documenting edge cases.
Table of Contents
| Category | Resources |
|---|---|
| PCRE2 Specification | Official PCRE2 documentation |
| PHP References | PHP.net PCRE manual |
| Security and ReDoS | Security guides |
| Engine Internals | How regex engines work |
| Tutorials | Learning resources |
| Testing and Visualization | Tools |
| Unicode | Unicode standards |
| Engine Compatibility | Other engines |
PCRE2 Specification
The authoritative source for PCRE2 syntax and behavior.
| Resource | Description |
|---|---|
| PCRE2 Syntax Overview | Quick syntax reference |
| PCRE2 Pattern Syntax | Pattern documentation |
| PCRE2 Performance | Performance considerations |
| PCRE2 API | Engine API details |
Key topics covered:
- Pattern modifiers (
imsxuADJSUX) - Escape sequences
- Assertions and zero-width matches
- Atomic grouping and possessive quantifiers
- Backtracking control verbs
PHP-Specific References
PHP’s implementation of PCRE and language-specific features.
| Resource | Description |
|---|---|
| PHP PCRE Manual | PCRE extension reference |
| Pattern Syntax Reference | PHP pattern syntax |
| Pattern Modifiers | Modifier documentation |
| preg_last_error() | Error detection function |
| preg_last_error_msg() | Error message function |
PHP-specific notes:
- PHP uses PCRE2 (since PHP 7.3)
\g{0}is invalid - use\g<0>or(?R)- Backtrack limits via
pcre.backtrack_limit - Recursion limits via
pcre.recursion_limit
Security and ReDoS
Understanding and preventing Regular Expression Denial of Service attacks.
| Resource | Description |
|---|---|
| OWASP ReDoS | Comprehensive ReDoS overview |
| Catastrophic Backtracking | Detailed explanation with examples |
| OWASP Input Validation Cheat Sheet | Prevention strategies |
Key concepts:
- Exponential vs polynomial backtracking
- Common risky patterns
- Mitigation strategies
- Detection techniques
Engine Internals and Theory
How regex engines actually work under the hood.
| Resource | Description |
|---|---|
| Russ Cox: Regex Matching Can Be Simple And Fast | Classic article on NFA vs DFA |
| Wikipedia: NFA | NFA theory |
| Wikipedia: Backtracking | Backtracking algorithm |
Why this matters:
- Backtracking engines (PCRE) can be exponential
- Non-backtracking engines (RE2) are linear
- Understanding tradeoffs helps write better patterns
Tutorials and Practical Guidance
Learn regex from beginner to advanced.
| Resource | Description |
|---|---|
| Regular-Expressions.info | Comprehensive tutorial hub |
| Character Classes | Deep dive on [...] |
| Quantifiers and Greediness | Repetition explained |
| Lookarounds | Zero-width assertions |
| RexEgg | Advanced regex tutorial |
| RegexOne | Interactive learning |
Recommended learning path:
- Start with Regular-Expressions.info basics
- Practice on RegexOne
- Explore advanced topics on RexEgg
- Study PCRE2 manual for PHP-specifics
Testing and Visualization
Tools to test, debug, and visualize regex patterns.
| Tool | Description | URL |
|---|---|---|
| regex101 | Popular tester with PCRE2 support | https://regex101.com/ |
| regexper | Railroad diagram visualization | https://regexper.com/ |
| Regexr | Another popular tester | https://regexr.com/ |
regex101 tips:
- Set flavor to “PCRE (PHP)”
- Use the structure panel to see groups
- Check the match information for backtracking
- Use the pattern generator for test cases
Unicode References
Unicode support in regex patterns.
| Resource | Description |
|---|---|
| Unicode Regular Expressions (UTS #18) | Unicode technical standard |
| Unicode Code Charts | Code charts per block |
| General Category Values (UAX #44) | Character categories |
Common Unicode patterns:
// Match any letter (any language)
'/\p{L}/u'
// Match Chinese characters
'/\p{Han}/u'
// Match emoji
'/\p{Emoji}/u'
// Match numbers in any script
'/\p{N}/u'
Engine Compatibility
How other regex engines compare to PCRE2.
| Engine | Description | Syntax Differences |
|---|---|---|
| RE2 | Google’s linear-time engine | No backreferences, no lookbehinds |
| JavaScript | V8 regex engine | Different flags, some PCRE features missing |
| Python re | Standard library | Similar to PCRE2, some differences |
| .NET | .NET regex | More features, different syntax |
RE2 comparison (useful for understanding PCRE tradeoffs):
// PCRE2 - can be exponential
preg_match('/(a+)+b/', $input);
// RE2 - always linear
// $re2->match('(a+)+b', $input); // No exponential behavior
Quick Reference Cards
| Category | URL |
|---|---|
| PCRE2 Quick Reference | https://www.pcre.org/current/doc/html/pcre2quick.html |
| PCRE2 Summary | https://www.pcre.org/current/doc/html/pcre2summary.html |
| PHP PCRE Summary | https://www.php.net/manual/en/reference.pcre.php |
Citation Style
When referencing these sources in documentation or code comments:
// See: PCRE2 Pattern Syntax
// https://www.pcre.org/current/doc/html/pcre2pattern.html
// Based on: OWASP ReDoS Prevention
// https://community.owasp.org/attacks/Regular_expression_Denial_of_Service_-_ReDoS
Related Documentation
| Topic | File |
|---|---|
| ReDoS Guide | ReDoS guide |
| Cookbook | cookbook.md |
| API Reference | api.md |
| Diagnostics | diagnostics.md |