Bug #68140 [Nab]: escapeshellarg doesn't escape double quotes, it removes them instead

From: Date: Sun, 05 Oct 2014 10:39:21 +0000
Subject: Bug #68140 [Nab]: escapeshellarg doesn't escape double quotes, it removes them instead
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-187858@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68140&edit=1 ID: 68140 Updated by: ab@php.net Reported by: petrhudecek2010 at gmail dot com Summary: escapeshellarg doesn't escape double quotes, it removes them instead Status: Not a bug Type: Bug Package: Program Execution Operating System: Windows 8.1 PHP Version: 5.6.1 Block user comment: N Private report: N New Comment: But this is the exact point - it is only known for sure that "arg" is fine, except we maintain the escaping info for every arbitrary program. It's more about the platform knowledge, but adding a note to the docs about this might make sense. Thanks Previous Comments: ------------------------------------------------------------------------ [2014-10-04 19:30:06] petrhudecek2010 at gmail dot com If escaping is supposed to be the program's task, not the shell's task, then the quotation marks should be passed to the program, not replaced by spaces by escapeshellarg. Currently, escapeshellarg, on Windows, replaces double quotes with spaces, then encloses the entire argument with double quotes which is not something every program wants, nor is it documented. Can I at least amend the documentation so it clarifies what the function does on Windows? ------------------------------------------------------------------------ [2014-10-04 19:19:09] ab@php.net Yeah, that were pretty valid with bash. For cmd.exe you'd do like <?php $arg = escapeshellarg('echo \'hello\';'); echo php -r $arg; or i do it with $arg = escapeshellarg("echo 'hello';"); system(PHP_BINARY . " -r $arg"); The behavior is though correct - on Windows escaping seems to be not the shell task, but the one of a program you're working with. Some programs can "eat" it with "" (escape with another double quote) or ^". The common thing is however to have an argument enclosed with double quotes or even without them. So a normal inline code is like php.exe -r "echo 'hello';" on Linux you would replace double quotes with single quotes and vice versa, as double quotes could be possible extrapolated with a Linux shell like bash/dash/etc. Thanks. ------------------------------------------------------------------------ [2014-10-04 11:02:03] petrhudecek2010 at gmail dot com I'm using this code (simplified from what I actually need, but shows the principle): <?php $arg = escapeshellarg('echo "hello";'); echo php -r $arg; I wanted it to print hello, instead it says that hello is not a defined constant because it strips the double quotes. ------------------------------------------------------------------------ [2014-10-04 10:15:25] ab@php.net What is the particular command you're running? Thanks. ------------------------------------------------------------------------ [2014-10-03 06:08:21] petrhudecek2010 at gmail dot com Description: ------------ On Windows, the function escapeshellarg quotes the string in double quotes but instead of escaping existing double quotes, it removes them instead. Test script: --------------- <?php echo escapeshellarg('"'); Expected result: ---------------- "\"" Actual result: -------------- " " ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68140&edit=1

« previous php.bugs (#187858) next »