[php-src] Issue #12134: PHP does not hide command line arguments
| From: | saur0n | Date: | Wed, 06 Sep 2023 05:39:07 +0000 |
| Subject: | [php-src] Issue #12134: PHP does not hide command line arguments | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-245338@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/12134
Author: saur0n
### Description
Run php-cli with argument
-H, then check process list:
```
php -H -e & ps ax
```
It is expected that php cleans its command line arguments, but it does not do this.
The problem is that
[this](https://github.com/php/php-src/blob/e72b6f471aaabafc35ee5f7e1259ebd441da7d66/sapi/cli/php_cli.c#L949)
fragment of code works not on original argv, but on argv that was modified
by save_ps_args:
```
/*
* Do not move this initialization. It needs to happen before argv is used
* in any way.
*/
argv = save_ps_args(argc, argv);
```
### PHP Version
PHP 8.2.10
### Operating System
_No response_