Bug #80731 [Com]: escapeshellarg() silently corrupts "\xFF" on linux

From: Date: Thu, 11 Feb 2021 15:34:02 +0000
Subject: Bug #80731 [Com]: escapeshellarg() silently corrupts "\xFF" on linux
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-232063@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80731&edit=1 ID: 80731 Comment by: divinity76 at gmail dot com Reported by: divinity76 at gmail dot com Summary: escapeshellarg() silently corrupts "\xFF" on linux Status: Open Type: Bug Package: *Data Exchange functions Operating System: Linux PHP Version: 8.0.2 Block user comment: N Private report: N New Comment: FWIW this returns bool(true): <?php function linux_escapeshellarg(string $arg):string{ if(false!==strpos($arg, "\x00")){ throw new \InvalidArgumentException("argument contains null bytes, it's impossible to escape null bytes!"); } return "'".strtr($arg,["'"=>"'\\''"])."'"; } $everything_except_null = ""; for($i=1;$i<=0xFF;++$i){ $everything_except_null.=chr($i); } $cmd = "printf '%s' ".linux_escapeshellarg($everything_except_null); $res = shell_exec($cmd); var_dump($res === $everything_except_null); Previous Comments: ------------------------------------------------------------------------ [2021-02-11 15:03:19] divinity76 at gmail dot com Description: ------------ escapeshellarg() silently corrupts "\xFF" on linux Test script: --------------- <?php /** * quote arguments using linux escape rules, regardless of host OS * (eg, it will use linux escape rules even when running on Windows) * * @param string $arg * @throws \InvalidArgumentException if argument contains null bytes * @return string */ function linux_escapeshellarg(string $arg): string { if (false !== strpos($arg, "\x00")) { throw new \InvalidArgumentException("argument contains null bytes, it's impossible to escape null bytes!"); } return "'" . strtr($arg, [ "'" => "'\\''" ]) . "'"; } $cmd = "printf '%s' ".linux_escapeshellarg("\xFF"); var_dump(bin2hex(shell_exec($cmd))); // ^ works fine. $cmd = "printf '%s' ".escapeshellarg("\xFF"); var_dump(bin2hex(shell_exec($cmd))); // ^ is corrupted.. Expected result: ---------------- string(2) "ff" string(2) "ff" Actual result: -------------- string(2) "ff" string(0) "" ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80731&edit=1

« previous php.bugs (#232063) next »