Bug #74472 [Com]: readdir strips leading and trailing quotes in a filename

From: Date: Wed, 19 Apr 2017 06:47:18 +0000
Subject: Bug #74472 [Com]: readdir strips leading and trailing quotes in a filename
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-208657@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74472&edit=1 ID: 74472 Comment by: spam2 at rhsoft dot net Reported by: james at workinout dot com Summary: readdir strips leading and trailing quotes in a filename Status: Not a bug Type: Bug Package: Filesystem function related Operating System: osx 10.12 PHP Version: 7.1.4 Block user comment: N Private report: N New Comment: Nonsense - the quotes you see in ls - la are added by ls itself when the file name contains spaces and are a quoting so that noobs can copy and paste Just type "ls - la | cat" and you see what a non-interactive shell sees RTFM escapeshellargs Previous Comments: ------------------------------------------------------------------------ [2017-04-19 06:27:21] requinix@php.net echo will output a thing as it is with no modifications, besides converting it to a string if it isn't one already. var_dump, being a debugging tool, will output using a representation that makes it easier to know what the thing's exact type and value is; strings will have quotes around them to signify that they are strings, for instance. As you can see, readdir is not stripping quotes because there are no quotes to begin with. You have code that is adding the quotes somewhere, then on top of it apparently using addslashes which will escape the quotes with backslashes. I don't know why the code is doing any of that but I'm confident it should not be. Like I said, you need to be using escapeshellarg to put strings into shell commands. It does all the work for you - don't put quotes around the string yourself, don't addslashes yourself. ------------------------------------------------------------------------ [2017-04-19 06:18:21] james at workinout dot com actually, running it all on fedora 25, sorry about that typo strange. downloaded from drupal.org as far as i remember. its weird, I know. cant ever recall seeing a filename with quotes in it. i know about backslashes. used those with fortran in 1975. Entry before: {{ THEME SANITIZED }}.behaviors.js (quotes trimmed by readdir() ) Entry after: \'{{ THEME SANITIZED }}.behaviors.js\' (after using addslashes() ) perhaps echo() and var_dump() use different methods. var_dump using getc/putc ? echo not ? ------------------------------------------------------------------------ [2017-04-19 05:37:55] requinix@php.net Well that's not how the files are bundled. Where did you download it from? As for the backslashes, those are supposed to be there. That's how escaping works. https://www.shellscript.sh/escape.html Besides, I couldn't reproduce what you're describing anyways. And though this is Linux, I can't imagine it being any different on OSX. # ls -la total 4 drwxrwxrwx 2 root root 0 Apr 18 22:33 . drwxrwxrwx 2 root root 0 Apr 18 22:32 .. -rw-rw-rw- 1 root root 0 Apr 18 22:32 'foo' -rw-rw-rw- 1 root root 85 Apr 18 22:33 test.php # cat test.php <?php $h = opendir("."); while ($f = readdir($h)) { var_dump($f); } closedir($h); # ~/php/PHP-7.1.4/bin/php test.php string(1) "." string(2) ".." string(5) "'foo'" string(8) "test.php" ------------------------------------------------------------------------ [2017-04-19 05:28:14] james at workinout dot com the quotes I AM seeing are when I do ls -al in a bash shell. see below the filename ON the filesystem has leading and trailing quotes, as I said. i tried escapeshellarg() but it simply puts in backslashes in front of the quotes, which of course, creates a filename that does not exist. drwxr-xr-x 2 james apache 4096 Apr 10 19:21 . drwxr-xr-x 10 james apache 4096 Apr 10 19:21 .. -rw-r--r-- 1 james apache 2900 Apr 10 19:21 '{{ THEME SANITIZED }}.behaviors.js' obviously, the quotes are there... ------------------------------------------------------------------------ [2017-04-19 05:13:38] requinix@php.net The files don't have quotes. http://cgit.drupalcode.org/omega/tree/omega/starterkits/default/js?h=7.x-4.x The filename must be escaped in the shell command, like with escapeshellarg. Not doing so will cause problems for files that contain spaces or other potentially unsafe characters (such as '{'). For example, exec("stat --format=%G " . escapeshellarg($entry)); The fact that the escaped version has quotes is simply because that's the easiest way to make a string safe. The quotes you're seeing mentioned somewhere are probably indicative of either PHP code (quotes form a string) or an actual shell command (author escaped the filename). ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=74472 -- Edit this bug report at https://bugs.php.net/bug.php?id=74472&edit=1

« previous php.bugs (#208657) next »