[php-src] Issue #9582: htmlspecialchars_decode() ENT_SUBSTITUTE flag has no effect

From: Date: Tue, 20 Sep 2022 15:42:00 +0000
Subject: [php-src] Issue #9582: htmlspecialchars_decode() ENT_SUBSTITUTE flag has no effect
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-242442@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/9582 Author: lucaswerkmeister ### Description The htmlspecialchars() function has an ENT_SUBSTITUTE flag (enabled by default since PHP 8.1) that changes its behavior when encountering invalid code unit sequences: ``` php > var_dump( htmlspecialchars( substr( 'abcdeä', 0, 6 ), 0 ) ); php shell code:1: string(0) "" php > var_dump( htmlspecialchars( substr( 'abcdeä', 0, 6 ), ENT_SUBSTITUTE ) ); php shell code:1: string(8) "abcde�" ``` htmlspecialchars_decode() is [documented](https://www.php.net/manual/en/function.htmlspecialchars-decode.php) ([archive](https://web.archive.org/web/20220421085844/https://www.php.net/manual/en/function.htmlspecialchars-decode.php)) to have the same flag, with the same effect, but actually it does nothing: ``` php > var_dump( htmlspecialchars_decode( substr( 'abcdeä', 0, 6 ), 0 ) ); php shell code:1: string(6) "abcde" php > var_dump( htmlspecialchars_decode( substr( 'abcdeä', 0, 6 ), ENT_SUBSTITUTE ) ); php shell code:1: string(6) "abcde" ``` (Appearance on your terminal may vary; it actually just returns the incomplete code unit sequence. On my system, in php -a it looks empty, while PsySH renders it as Ã.) [According to 3v4l](https://3v4l.org/aqXYO), this behavior has been the same since htmlspecialchars_decode() was introduced (from 5.1.0 all the way to 8.2rc2), so perhaps instead of changing the behavior, this should just be considered a documentation bug (remove the flag from the documentation)? ### PHP Version PHP 8.1.2 ### Operating System Ubuntu 22.04

« previous php.bugs (#242442) next »