Category
Stdlib · php-src-strict / htmlspecialchars ENT_IGNORE
Problem
htmlspecialchars() / htmlentities() with ENT_IGNORE must drop invalid UTF-8 lead bytes and keep the following valid bytes. Zend returns "(" for "\xC3\x28" and "a(b" for "a\xC3\x28b". VM/JIT return empty string for the whole input (they treat any invalid UTF-8 without ENT_SUBSTITUTE as a total conversion failure).
ENT_SUBSTITUTE already matches Zend ("\xEF\xBF\xBD("). Valid UTF-8 "\xC3\xA9" in a standalone script matches Zend. Distinct from closed #14739 (ENT_SUBSTITUTE / conversion-failure) and #10734 (htmlentities named-entity encode).
VmString::htmlspecialchars() has no ENT_IGNORE branch: invalid UTF-8 and 0 === ($flags & ENT_SUBSTITUTE) returns ''.
Probed 2026-08-18 @ bf1a18dfa1 — Zend 8.2.32 vs php bin/vm.php / php bin/jit.php.
| Repro |
Zend 8.2.32 |
VM/JIT |
htmlspecialchars("\xC3\x28", ENT_QUOTES|ENT_IGNORE, 'UTF-8') |
string(1) "(" |
string(0) "" |
htmlentities("\xC3\x28", ENT_QUOTES|ENT_IGNORE, 'UTF-8') |
string(1) "(" |
string(0) "" |
htmlspecialchars("a\xC3\x28b", ENT_QUOTES|ENT_IGNORE, 'UTF-8') |
string(3) "a(b" |
string(0) "" |
htmlspecialchars("\xC3\x28", ENT_QUOTES|ENT_SUBSTITUTE, 'UTF-8') |
"\u{FFFD}(" |
same ✓ |
htmlspecialchars("\xC3\x28", ENT_QUOTES, 'UTF-8') alone |
"" |
"" ✓ |
php-src reference
PHP implementation target
ext/standard/VmString.php — htmlspecialchars() / htmlentities(): when ENT_IGNORE is set, strip invalid sequences in place (do not return '' for the whole string)
ext/standard/HtmlspecialcharsJitHelper.php — same flags; reuse the PHP implementation
- No new
runtime/*.c
Repro
./script/docker-exec.sh -- bash -lc 'php bin/vm.php test/repro/maintainer_gap_htmlspecialchars_ent_ignore.php'
./script/docker-exec.sh -- bash -lc 'php bin/jit.php test/repro/maintainer_gap_htmlspecialchars_ent_ignore.php'
./script/docker-exec.sh -- bash -lc 'php test/repro/maintainer_gap_htmlspecialchars_ent_ignore.php' # Zend baseline
<?php
error_reporting(E_ALL);
var_dump(htmlspecialchars("\xC3\x28", ENT_QUOTES | ENT_IGNORE, 'UTF-8'));
var_dump(htmlspecialchars("a\xC3\x28b", ENT_QUOTES | ENT_IGNORE, 'UTF-8'));
Done when
Category
Stdlib· php-src-strict /htmlspecialcharsENT_IGNOREProblem
htmlspecialchars()/htmlentities()withENT_IGNOREmust drop invalid UTF-8 lead bytes and keep the following valid bytes. Zend returns"("for"\xC3\x28"and"a(b"for"a\xC3\x28b". VM/JIT return empty string for the whole input (they treat any invalid UTF-8 withoutENT_SUBSTITUTEas a total conversion failure).ENT_SUBSTITUTEalready matches Zend ("\xEF\xBF\xBD("). Valid UTF-8"\xC3\xA9"in a standalone script matches Zend. Distinct from closed #14739 (ENT_SUBSTITUTE / conversion-failure) and #10734 (htmlentities named-entity encode).VmString::htmlspecialchars()has noENT_IGNOREbranch: invalid UTF-8 and0 === ($flags & ENT_SUBSTITUTE)returns''.Probed 2026-08-18 @
bf1a18dfa1— Zend 8.2.32 vsphp bin/vm.php/php bin/jit.php.htmlspecialchars("\xC3\x28", ENT_QUOTES|ENT_IGNORE, 'UTF-8')string(1) "("string(0) ""htmlentities("\xC3\x28", ENT_QUOTES|ENT_IGNORE, 'UTF-8')string(1) "("string(0) ""htmlspecialchars("a\xC3\x28b", ENT_QUOTES|ENT_IGNORE, 'UTF-8')string(3) "a(b"string(0) ""htmlspecialchars("\xC3\x28", ENT_QUOTES|ENT_SUBSTITUTE, 'UTF-8')"\u{FFFD}("htmlspecialchars("\xC3\x28", ENT_QUOTES, 'UTF-8')alone""""✓php-src reference
ext/standard/html.c—php_escape_html_entities_ex;ENT_HTML_IGNORE_ERRORSskips the incomplete/invalid sequence and continuesext/standard/html.stub.php—htmlspecialchars/htmlentities$flags/$encodingPHP implementation target
ext/standard/VmString.php—htmlspecialchars()/htmlentities(): whenENT_IGNOREis set, strip invalid sequences in place (do notreturn ''for the whole string)ext/standard/HtmlspecialcharsJitHelper.php— same flags; reuse the PHP implementationruntime/*.cRepro
Done when
ENT_IGNOREon"\xC3\x28"yields"("; on"a\xC3\x28b"yields"a(b"(Zend)htmlentities(..., ENT_IGNORE)matcheshtmlspecialcharsENT_SUBSTITUTEand valid UTF-8éunchanged.phptundertest/compliance/cases/stdlib/