Req #78177 [Com]: Make proc_open accept command array
| From: | nicolas dot grekas+php at gmail dot com | Date: | Tue, 18 Jun 2019 11:56:08 +0000 |
| Subject: | Req #78177 [Com]: Make proc_open accept command array | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-221365@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78177&edit=1
ID: 78177
Comment by: nicolas dot grekas+php at gmail dot com
Reported by: nicolas dot grekas+php at gmail dot com
Summary: Make proc_open accept command array
Status: Open
Type: Feature/Change Request
Package: Program Execution
PHP Version: Next Minor Version
Block user comment: N
Private report: N
New Comment:
Oh btw, for reference, ext-async accepts command line arrays:
https://github.com/concurrent-php/ext-async#processbuilder
Previous Comments:
------------------------------------------------------------------------
[2019-06-18 08:16:29] nicolas dot grekas+php at gmail dot com
Unfortunately, I know all the workarounds, that's why I'm asking for this.
escapeshellarg is just a poor man's band aid. On Windows esp., it breaks many arguments, as
soon as they contains non-alphanumeric chars. E.g. a CR/LF or quotes.
There is a package that gives it a try, and which links to doc about how escaping works:
https://github.com/johnstevenson/winbox-args
TL;DR escaping is context-sensitive on Windows, si that it is impossible to fully escape a generic
string.
That's why this FR is much needed.
------------------------------------------------------------------------
[2019-06-18 07:51:29] sjon@php.net
implode(' ', array_map('escapeshellarg', $array)) might be a suitable workaround
------------------------------------------------------------------------
[2019-06-18 07:45:46] nicolas dot grekas+php at gmail dot com
Description:
------------
Right now, PHP misses a low level primitive to run a process without argument escaping issues.
The reason is that proc_open accepts only a string to define the command, so that a command line
parser is required under the hood.
This also creates the long-lasting issue with signaling, where the shell get them instead of the
command itself.
Both issues would be fixed by having a way to launch shell-less command lines.
All programming language have this, but PHP.
proc_open($array, ...) could be the way to go. We're missing this badly.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78177&edit=1