Re: Re: Bug #3519 Updated: EscapeShellCmd is never useful

From: Date: Mon, 06 Mar 2000 17:15:15 +0000
Subject: Re: Re: Bug #3519 Updated: EscapeShellCmd is never useful
References: 1 2  Groups: php.dev 
Request: Send a blank email to php-dev+get-16459@lists.php.net to get a copy of this message
rasmus@php.net wrote: > > There was no outcome on the mailing list. Rasmus just kept making inaccurate > > claims about shell command lines, and I kept pointing out why he was wrong, > > until he got bored. The function is still broken. > > This is a rather one-side summary of the conclusion. I pointed out how > EscapeShellCmd() is useful when used on individual arguments, ... and I pointed out why this is not the case, and certainly this suggestion is not documented, and is certainly not possible at all without more documentation of what EscapeShellCmd does. > and I agreed that another command to work on full strings would be > useful. Err, EscapeShellCmd is the command which the PHP documentation claims is supposed to be used on full strings. It was I that said this is not useful, and that a new function is required that works on individual arguments. > Feel free to write it. char * _php3_escapeshellarg(char *str) { char *cmd; register char *in, *out; cmd = emalloc(4 * l + 3); in = str; out = cmd; *(out++) = '\''; while(*in) { if (*out == '\'') { *(out++) = '\''; *(out++) = '\\'; *(out++) = '\''; *(out++) = '\''; } else { *(out++) = *in; } in++; } *(out++) = '\''; *(out++) = '\0'; cmd = erealloc(cmd, out - cmd); return cmd; } (made by munging the original escapeshellcmd function). Cheers Jon -- \/ Jon Ribbens / jon@oaktree.co.uk

« previous php.dev (#16459) next »