Req #78177 [Opn->Csd]: Make proc_open accept command array

From: Date: Fri, 28 Jun 2019 09:19:03 +0000
Subject: Req #78177 [Opn->Csd]: Make proc_open accept command array
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-221534@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78177&edit=1 ID: 78177 Updated by: nikic@php.net Reported by: nicolas dot grekas+php at gmail dot com Summary: Make proc_open accept command array -Status: Open +Status: Closed Type: Feature/Change Request Package: Program Execution PHP Version: Next Minor Version -Assigned To: +Assigned To: nikic Block user comment: N Private report: N New Comment: Implemented in https://github.com/php/php-src/commit/8be051015e04ce6151da77581922eea65330f354. Previous Comments: ------------------------------------------------------------------------ [2019-06-27 11:49:19] sjon@php.net The following pull request has been associated: Patch Name: Support array command in proc_open() On GitHub: https://github.com/php/php-src/pull/4305 Patch: https://github.com/php/php-src/pull/4305.patch ------------------------------------------------------------------------ [2019-06-18 11:56:08] nicolas dot grekas+php at gmail dot com Oh btw, for reference, ext-async accepts command line arrays: https://github.com/concurrent-php/ext-async#processbuilder ------------------------------------------------------------------------ [2019-06-18 08:16:29] nicolas dot grekas+php at gmail dot com Unfortunately, I know all the workarounds, that's why I'm asking for this. escapeshellarg is just a poor man's band aid. On Windows esp., it breaks many arguments, as soon as they contains non-alphanumeric chars. E.g. a CR/LF or quotes. There is a package that gives it a try, and which links to doc about how escaping works: https://github.com/johnstevenson/winbox-args TL;DR escaping is context-sensitive on Windows, si that it is impossible to fully escape a generic string. That's why this FR is much needed. ------------------------------------------------------------------------ [2019-06-18 07:51:29] sjon@php.net implode(' ', array_map('escapeshellarg', $array)) might be a suitable workaround ------------------------------------------------------------------------ [2019-06-18 07:45:46] nicolas dot grekas+php at gmail dot com Description: ------------ Right now, PHP misses a low level primitive to run a process without argument escaping issues. The reason is that proc_open accepts only a string to define the command, so that a command line parser is required under the hood. This also creates the long-lasting issue with signaling, where the shell get them instead of the command itself. Both issues would be fixed by having a way to launch shell-less command lines. All programming language have this, but PHP. proc_open($array, ...) could be the way to go. We're missing this badly. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78177&edit=1

« previous php.bugs (#221534) next »