Doc #68140 [Nab]: escapeshellarg doesn't escape double quotes, it removes them instead
| From: | cmb@php.net | Date: | Fri, 24 Apr 2015 21:02:08 +0000 |
| Subject: | Doc #68140 [Nab]: escapeshellarg doesn't escape double quotes, it removes them instead | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-12254@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=68140&edit=1
ID: 68140
Updated by: cmb@php.net
Reported by: petrhudecek2010 at gmail dot com
Summary: escapeshellarg doesn't escape double quotes, it
removes them instead
Status: Not a bug
Type: Documentation Problem
Package: Program Execution
Operating System: Windows 8.1
PHP Version: 5.6.1
Block user comment: N
Private report: N
New Comment:
JFTR: the job of escapeshellarg() is to escape a *single* *argument* (e.g. hello). To escape a full
command (e.g. echo hello) use escapeshellcmd().
Previous Comments:
------------------------------------------------------------------------
[2015-04-24 09:41:28] salathe@php.net
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation better.
------------------------------------------------------------------------
[2015-04-24 09:37:47] salathe@php.net
Automatic comment from SVN on behalf of salathe
Revision: http://svn.php.net/viewvc/?view=revision&revision=336643
Log: Document how escapeshellarg behaves on Windows. (patch by Petr HudeÄek, doc bug #68140)
------------------------------------------------------------------------
[2014-10-05 10:39:21] ab@php.net
But this is the exact point - it is only known for sure that "arg" is fine, except we
maintain the escaping info for every arbitrary program. It's more about the platform knowledge,
but adding a note to the docs about this might make sense.
Thanks
------------------------------------------------------------------------
[2014-10-04 19:30:06] petrhudecek2010 at gmail dot com
If escaping is supposed to be the program's task, not the shell's task, then the quotation
marks should be passed to the program, not replaced by spaces by escapeshellarg. Currently,
escapeshellarg, on Windows, replaces double quotes with spaces, then encloses the entire argument
with double quotes which is not something every program wants, nor is it documented.
Can I at least amend the documentation so it clarifies what the function does on Windows?
------------------------------------------------------------------------
[2014-10-04 19:19:09] ab@php.net
Yeah, that were pretty valid with bash. For cmd.exe you'd do like
<?php
$arg = escapeshellarg('echo \'hello\';');
echo
php -r $arg;
or i do it with
$arg = escapeshellarg("echo 'hello';");
system(PHP_BINARY . " -r $arg");
The behavior is though correct - on Windows escaping seems to be not the shell task, but the one of
a program you're working with. Some programs can "eat" it with "" (escape
with another double quote) or ^". The common thing is however to have an argument enclosed with
double quotes or even without them. So a normal inline code is like
php.exe -r "echo 'hello';"
on Linux you would replace double quotes with single quotes and vice versa, as double quotes could
be possible extrapolated with a Linux shell like bash/dash/etc.
Thanks.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=68140
--
Edit this bug report at https://bugs.php.net/bug.php?id=68140&edit=1