Skip to content

Stdlib: htmlspecialchars()/htmlentities() ENT_* named flag constants rejected — LogicException not escaped output (ext/standard/html.c) #9586

Description

@PurHur

Category

stdlib · php-src-strict

Problem

htmlspecialchars() / htmlentities() second argument cannot accept ENT_* named constants at runtime—the VM throws:

LogicException: htmlspecialchars() flags must be an integer in this compiler build
Call Zend VM today
htmlspecialchars("<a&'>", ENT_QUOTES) '&lt;a&amp;&#039;&gt;' LogicException
htmlentities("<a&'>", ENT_COMPAT) '&lt;a&amp;\'&gt;' LogicException

Same class of bug as #9564 (PHP_ROUND_HALF_*), #9565 (PATHINFO_*), #9278 (SORT_*)—builtin arg lowering does not resolve core PHP constants to integers.

php-src reference

Repro

./script/docker-exec.sh -- bash -lc 'source script/php-env.sh && php bin/vm.php test/repro/maintainer_gap_htmlspecialchars_ent_flags.php'
php bin/vm.php test/repro/maintainer_gap_htmlspecialchars_ent_flags.php

Implementation hints (PHP-in-PHP)

  • ext/standard/htmlspecialchars.php, ext/standard/htmlentities.php — resolve ENT_* via StdlibConstants / shared builtin int-arg helper (same path as sort/round flags)
  • ext/standard/VmString.php — semantics already correct once $flags is an int
  • JIT: JitHtmlspecialchars / compile-time constant folding in htmlspecialchars::compileTimeLong

Done when

  • Repro script matches Zend under VM (php bin/vm.php)
  • ENT_QUOTES, ENT_COMPAT, ENT_HTML5 combinations work
  • Compliance guard added under test/compliance/cases/stdlib/
  • JIT/AOT agree when flags lowering is in scope

Related

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:vmVirtual machineenhancementNew feature or requestimplementation-readySpec complete: repro, php-src ref, done-when — safe for workers to claimphase-4:stdlibPhase 4 – stdlib for web appsstdlib

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions