Skip to content

Stdlib: htmlspecialchars/htmlentities ENT_IGNORE returns empty — Zend strips invalid UTF-8 bytes (ext/standard/html.c) #32063

Description

@PurHur

Category

Stdlib · php-src-strict / htmlspecialchars ENT_IGNORE

Problem

htmlspecialchars() / htmlentities() with ENT_IGNORE must drop invalid UTF-8 lead bytes and keep the following valid bytes. Zend returns "(" for "\xC3\x28" and "a(b" for "a\xC3\x28b". VM/JIT return empty string for the whole input (they treat any invalid UTF-8 without ENT_SUBSTITUTE as a total conversion failure).

ENT_SUBSTITUTE already matches Zend ("\xEF\xBF\xBD("). Valid UTF-8 "\xC3\xA9" in a standalone script matches Zend. Distinct from closed #14739 (ENT_SUBSTITUTE / conversion-failure) and #10734 (htmlentities named-entity encode).

VmString::htmlspecialchars() has no ENT_IGNORE branch: invalid UTF-8 and 0 === ($flags & ENT_SUBSTITUTE) returns ''.

Probed 2026-08-18 @ bf1a18dfa1 — Zend 8.2.32 vs php bin/vm.php / php bin/jit.php.

Repro Zend 8.2.32 VM/JIT
htmlspecialchars("\xC3\x28", ENT_QUOTES|ENT_IGNORE, 'UTF-8') string(1) "(" string(0) ""
htmlentities("\xC3\x28", ENT_QUOTES|ENT_IGNORE, 'UTF-8') string(1) "(" string(0) ""
htmlspecialchars("a\xC3\x28b", ENT_QUOTES|ENT_IGNORE, 'UTF-8') string(3) "a(b" string(0) ""
htmlspecialchars("\xC3\x28", ENT_QUOTES|ENT_SUBSTITUTE, 'UTF-8') "\u{FFFD}(" same ✓
htmlspecialchars("\xC3\x28", ENT_QUOTES, 'UTF-8') alone "" "" ✓

php-src reference

PHP implementation target

  • ext/standard/VmString.php — htmlspecialchars() / htmlentities(): when ENT_IGNORE is set, strip invalid sequences in place (do not return '' for the whole string)
  • ext/standard/HtmlspecialcharsJitHelper.php — same flags; reuse the PHP implementation
  • No new runtime/*.c

Repro

./script/docker-exec.sh -- bash -lc 'php bin/vm.php test/repro/maintainer_gap_htmlspecialchars_ent_ignore.php'
./script/docker-exec.sh -- bash -lc 'php bin/jit.php test/repro/maintainer_gap_htmlspecialchars_ent_ignore.php'
./script/docker-exec.sh -- bash -lc 'php test/repro/maintainer_gap_htmlspecialchars_ent_ignore.php'  # Zend baseline
<?php
error_reporting(E_ALL);
var_dump(htmlspecialchars("\xC3\x28", ENT_QUOTES | ENT_IGNORE, 'UTF-8'));
var_dump(htmlspecialchars("a\xC3\x28b", ENT_QUOTES | ENT_IGNORE, 'UTF-8'));

Done when

  • VM/JIT: ENT_IGNORE on "\xC3\x28" yields "("; on "a\xC3\x28b" yields "a(b" (Zend)
  • htmlentities(..., ENT_IGNORE) matches htmlspecialchars
  • ENT_SUBSTITUTE and valid UTF-8 é unchanged
  • Compliance .phpt under test/compliance/cases/stdlib/
  • php-src-strict; no php-compiler-strict shortcut

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:vmVirtual machinebugSomething isn't workingimplementation-readySpec complete: repro, php-src ref, done-when — safe for workers to claimphase-4:stdlibPhase 4 – stdlib for web appsstdlib

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions