note 24565 deleted from function.escapeshellarg by didou
| From: | didou@php.net | Date: | Sun, 18 May 2003 04:44:26 +0000 |
| Subject: | note 24565 deleted from function.escapeshellarg by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-48426@lists.php.net to get a copy of this message | ||
Note Submitter: mhsims@NOSPAM.midsouth.rr.com
----
The (anonymous) note above is very misleading. Allow me to address some of the points raised.
(These examples use bash...I'm not familiar with other shells but I'm assuming arguments
work the same).
The user above asserts that 'foo'\''bar' is unusable as a shell argument,
but this is not the case. Some simple testing would have illustrated this. He expects this
function to output 'foo\'bar' instead, but THAT string is the one that is unusable.
Here is an excerpt from the bash man page:
'Enclosing characters in single quotes preserves the literal value of each character within the
quotes. A single quote MAY NOT occur between single quotes, EVEN WHEN PRECEDED BY A
BACKSLASH.' - emphasis mine
A simple test shows this:
$ touch foo\'bar
$ ls foo\'bar
foo'bar
So far so good. Now let's try to add single quotes around the filename:
$ ls 'foo\'bar'
>
Bash has interpreted both the backslash and the single quote literally, and now we have an uneven
number of quotes, so bash thinks we aren't finished with the command yet. The proper way to
pass the argument is:
$ ls 'foo'\''bar'
foo'bar
Which is exactly what escapeshellarg() does.
Also, the user above states that this function "leaves semicolons and other dangerous
characters unquoted", which is not true. The entire argument is surrounded by single quotes,
so any semicolons contained within are interpreted by the shell as literal semicolons. Again, a
small test illustrates this:
$ ls 'foo'\''bar; rm -Rf *'
ls: foo'bar; rm -Rf *: No such file or directory