Bug #68140 [Nab]: escapeshellarg doesn't escape double quotes, it removes them instead
| From: | ab@php.net | Date: | Sun, 05 Oct 2014 10:39:21 +0000 |
| Subject: | Bug #68140 [Nab]: escapeshellarg doesn't escape double quotes, it removes them instead | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-187858@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68140&edit=1
ID: 68140
Updated by: ab@php.net
Reported by: petrhudecek2010 at gmail dot com
Summary: escapeshellarg doesn't escape double quotes, it
removes them instead
Status: Not a bug
Type: Bug
Package: Program Execution
Operating System: Windows 8.1
PHP Version: 5.6.1
Block user comment: N
Private report: N
New Comment:
But this is the exact point - it is only known for sure that "arg" is fine, except we
maintain the escaping info for every arbitrary program. It's more about the platform knowledge,
but adding a note to the docs about this might make sense.
Thanks
Previous Comments:
------------------------------------------------------------------------
[2014-10-04 19:30:06] petrhudecek2010 at gmail dot com
If escaping is supposed to be the program's task, not the shell's task, then the quotation
marks should be passed to the program, not replaced by spaces by escapeshellarg. Currently,
escapeshellarg, on Windows, replaces double quotes with spaces, then encloses the entire argument
with double quotes which is not something every program wants, nor is it documented.
Can I at least amend the documentation so it clarifies what the function does on Windows?
------------------------------------------------------------------------
[2014-10-04 19:19:09] ab@php.net
Yeah, that were pretty valid with bash. For cmd.exe you'd do like
<?php
$arg = escapeshellarg('echo \'hello\';');
echo
php -r $arg;
or i do it with
$arg = escapeshellarg("echo 'hello';");
system(PHP_BINARY . " -r $arg");
The behavior is though correct - on Windows escaping seems to be not the shell task, but the one of
a program you're working with. Some programs can "eat" it with "" (escape
with another double quote) or ^". The common thing is however to have an argument enclosed with
double quotes or even without them. So a normal inline code is like
php.exe -r "echo 'hello';"
on Linux you would replace double quotes with single quotes and vice versa, as double quotes could
be possible extrapolated with a Linux shell like bash/dash/etc.
Thanks.
------------------------------------------------------------------------
[2014-10-04 11:02:03] petrhudecek2010 at gmail dot com
I'm using this code (simplified from what I actually need, but shows the principle):
<?php
$arg = escapeshellarg('echo "hello";');
echo php -r $arg;
I wanted it to print hello, instead it says that hello is not a defined constant because it strips
the double quotes.
------------------------------------------------------------------------
[2014-10-04 10:15:25] ab@php.net
What is the particular command you're running?
Thanks.
------------------------------------------------------------------------
[2014-10-03 06:08:21] petrhudecek2010 at gmail dot com
Description:
------------
On Windows, the function escapeshellarg quotes the string in double quotes but instead of escaping
existing double quotes, it removes them instead.
Test script:
---------------
<?php
echo escapeshellarg('"');
Expected result:
----------------
"\""
Actual result:
--------------
" "
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=68140&edit=1