note 24565 deleted from function.escapeshellarg by didou

From: Date: Sun, 18 May 2003 04:44:26 +0000
Subject: note 24565 deleted from function.escapeshellarg by didou
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-48426@lists.php.net to get a copy of this message
Note Submitter: mhsims@NOSPAM.midsouth.rr.com ---- The (anonymous) note above is very misleading. Allow me to address some of the points raised. (These examples use bash...I'm not familiar with other shells but I'm assuming arguments work the same). The user above asserts that 'foo'\''bar' is unusable as a shell argument, but this is not the case. Some simple testing would have illustrated this. He expects this function to output 'foo\'bar' instead, but THAT string is the one that is unusable. Here is an excerpt from the bash man page: 'Enclosing characters in single quotes preserves the literal value of each character within the quotes. A single quote MAY NOT occur between single quotes, EVEN WHEN PRECEDED BY A BACKSLASH.' - emphasis mine A simple test shows this: $ touch foo\'bar $ ls foo\'bar foo'bar So far so good. Now let's try to add single quotes around the filename: $ ls 'foo\'bar' > Bash has interpreted both the backslash and the single quote literally, and now we have an uneven number of quotes, so bash thinks we aren't finished with the command yet. The proper way to pass the argument is: $ ls 'foo'\''bar' foo'bar Which is exactly what escapeshellarg() does. Also, the user above states that this function "leaves semicolons and other dangerous characters unquoted", which is not true. The entire argument is surrounded by single quotes, so any semicolons contained within are interpreted by the shell as literal semicolons. Again, a small test illustrates this: $ ls 'foo'\''bar; rm -Rf *' ls: foo'bar; rm -Rf *: No such file or directory

« previous php.notes (#48426) next »