Doc #80731 [Com]: escapeshellarg() silently corrupts "\xFF" on linux
| From: | divinity76 at gmail dot com | Date: | Thu, 11 Feb 2021 16:27:59 +0000 |
| Subject: | Doc #80731 [Com]: escapeshellarg() silently corrupts "\xFF" on linux | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-18523@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80731&edit=1
ID: 80731
Comment by: divinity76 at gmail dot com
Reported by: divinity76 at gmail dot com
Summary: escapeshellarg() silently corrupts "\xFF" on linux
Status: Verified
Type: Documentation Problem
Package: Program Execution
Operating System: Linux
PHP Version: 8.0.2
Block user comment: N
Private report: N
New Comment:
@cmd interesting, but that begs the question, why does it only complain when given null bytes, and
not complain when given locale-invalid-characters?
Previous Comments:
------------------------------------------------------------------------
[2021-02-11 15:40:57] cmb@php.net
If mblen() is available on the system, escapeshellarg() works on
multibyte characters according to the system locale[1], and skips
invalid characters[2]. This is, however, not documented.
[1] <https://3v4l.org/rdjpk>
[2] <https://github.com/php/php-src/blob/c6723538054d96291abb6bad4628b9f55bc7fc17/ext/standard/exec.c#L313>
------------------------------------------------------------------------
[2021-02-11 15:34:02] divinity76 at gmail dot com
FWIW this returns bool(true):
<?php
function linux_escapeshellarg(string $arg):string{
if(false!==strpos($arg, "\x00")){
throw new \InvalidArgumentException("argument contains null bytes, it's impossible
to escape null bytes!");
}
return
"'".strtr($arg,["'"=>"'\\''"])."'";
}
$everything_except_null = "";
for($i=1;$i<=0xFF;++$i){
$everything_except_null.=chr($i);
}
$cmd = "printf '%s' ".linux_escapeshellarg($everything_except_null);
$res = shell_exec($cmd);
var_dump($res === $everything_except_null);
------------------------------------------------------------------------
[2021-02-11 15:03:19] divinity76 at gmail dot com
Description:
------------
escapeshellarg() silently corrupts "\xFF" on linux
Test script:
---------------
<?php
/**
* quote arguments using linux escape rules, regardless of host OS
* (eg, it will use linux escape rules even when running on Windows)
*
* @param string $arg
* @throws \InvalidArgumentException if argument contains null bytes
* @return string
*/
function linux_escapeshellarg(string $arg): string
{
if (false !== strpos($arg, "\x00")) {
throw new \InvalidArgumentException("argument contains null bytes, it's impossible
to escape null bytes!");
}
return "'" . strtr($arg, [
"'" => "'\\''"
]) . "'";
}
$cmd = "printf '%s' ".linux_escapeshellarg("\xFF");
var_dump(bin2hex(shell_exec($cmd)));
// ^ works fine.
$cmd = "printf '%s' ".escapeshellarg("\xFF");
var_dump(bin2hex(shell_exec($cmd)));
// ^ is corrupted..
Expected result:
----------------
string(2) "ff"
string(2) "ff"
Actual result:
--------------
string(2) "ff"
string(0) ""
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80731&edit=1