Bug #74472 [Com]: readdir strips leading and trailing quotes in a filename
| From: | spam2 at rhsoft dot net | Date: | Wed, 19 Apr 2017 14:36:59 +0000 |
| Subject: | Bug #74472 [Com]: readdir strips leading and trailing quotes in a filename | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-208667@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74472&edit=1
ID: 74472
Comment by: spam2 at rhsoft dot net
Reported by: james at workinout dot com
Summary: readdir strips leading and trailing quotes in a
filename
Status: Not a bug
Type: Bug
Package: Filesystem function related
Operating System: Fedora
PHP Version: 7.1.4
Block user comment: N
Private report: N
New Comment:
> escapeshellarg() works. after it adds back single quotes around the file
there is nothing to add BACK because there was nothing
> using echo shows the single quotes are added back
no
> but as i said below, readdir() is stripping the quotes,
DAMNED there are no quotes in the filename, read the responses you got here and try to understand at
least the basics
> otherwise, I would not need to use escapeshellarg
DAMNED you ALWAYS have to use escapeshellarg() when you supply soemting as shell param BECAUSE it
filename could contain a space or special chars which are DANGEROUS and could pe interpreted by the
caller in unpredicatable ways
SIMPLE EXAMPLE:
file is called '-rf *' and yes YOU CAN create such file by "touch \*" - guess
what happens with passthru("rm /folder/$file");
Previous Comments:
------------------------------------------------------------------------
[2017-04-19 14:29:57] requinix@php.net
James. There are no quotes in the filename. Not at all. ls is lying to you.
------------------------------------------------------------------------
[2017-04-19 14:25:24] james at workinout dot com
escapeshellarg() works. after it adds back single quotes around the file then stat works. using echo
shows the single quotes are added back. but as i said below, readdir() is stripping the quotes,
otherwise, I would not need to use escapeshellarg.
as someone said below, its better not to use quotes in filenames ..
------------------------------------------------------------------------
[2017-04-19 08:27:47] spam2 at rhsoft dot net
well, whatever theme he is using - i would stop to use anything from that developer which did not
get the basics that a filename on webservers only should have [a-z][0-9]-_ meaning no special chars,
no spaces, no uppercase letters
anyways the "ls" out put is to help noobs copy&paste
stat with spaces
versus
stat 'with spaces'
however, it's not uncommon that outputs of interactive shells are different than what scripts
really see (colors, automatic paging and so on) - hence pipe it through "cat" leads to get
the non-interactive version because of the pipe
------------------------------------------------------------------------
[2017-04-19 08:11:05] requinix@php.net
Then that would explain why OP thought the filename had quotes.
...wow, that's a stupid decision.
------------------------------------------------------------------------
[2017-04-19 08:03:52] spam2 at rhsoft dot net
requinix@php.net: you missed the "actually, running it all on fedora 25" and most likely
you use some outdated stuff like Debian
here you go:
https://bugzilla.redhat.com/show_bug.cgi?id=1361694
https://unix.stackexchange.com/questions/258679/why-is-ls-suddenly-wrapping-items-with-spaces-in-single-quotes
[harry@rh:/downloads]$ /bin/ls -la
insgesamt 132
drwxrwxrwt 2 root root 122880 19. Apr 10:01 .
drwxr-xr-x+ 36 harry root 4096 16. Mär 15:44 ..
-rw-r----- 1 harry verwaltung 0 19. Apr 10:01 'with spaces'
[harry@rh:/downloads]$ /bin/ls -la | cat
insgesamt 132
drwxrwxrwt 2 root root 122880 19. Apr 10:01 .
drwxr-xr-x+ 36 harry root 4096 16. Mär 15:44 ..
-rw-r----- 1 harry verwaltung 0 19. Apr 10:01 with spaces
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=74472
--
Edit this bug report at https://bugs.php.net/bug.php?id=74472&edit=1