<?php
include_once $_SERVER['DOCUMENT_ROOT'] . '/include/shared-manual.inc';
$TOC = array();
$TOC_DEPRECATED = array();
$PARENTS = array();
include_once dirname(__FILE__) ."/toc/ref.taint.inc";
$setup = array (
  'home' => 
  array (
    0 => 'index.php',
    1 => 'PHP Manual',
  ),
  'head' => 
  array (
    0 => 'UTF-8',
    1 => 'zh',
  ),
  'this' => 
  array (
    0 => 'function.taint.php',
    1 => 'taint',
    2 => '将字符串标记为已污染',
  ),
  'up' => 
  array (
    0 => 'ref.taint.php',
    1 => 'Taint 函数',
  ),
  'prev' => 
  array (
    0 => 'function.is-tainted.php',
    1 => 'is_tainted',
  ),
  'next' => 
  array (
    0 => 'function.untaint.php',
    1 => 'untaint',
  ),
  'alternatives' => 
  array (
  ),
  'source' => 
  array (
    'lang' => 'zh',
    'path' => 'reference/taint/functions/taint.xml',
  ),
  'history' => 
  array (
  ),
);
$setup["toc"] = $TOC;
$setup["toc_deprecated"] = $TOC_DEPRECATED;
$setup["parents"] = $PARENTS;
manual_setup($setup);

contributors($setup);

?>
<div id="function.taint" class="refentry">
 <div class="refnamediv">
  <h1 class="refname">taint</h1>
  <p class="verinfo">(PECL taint &gt;=0.1.0)</p><p class="refpurpose"><span class="refname">taint</span> &mdash; <span class="dc-title">将字符串标记为已污染</span></p>

 </div>

 <div class="refsect1 description" id="refsect1-function.taint-description">
  <h3 class="title">说明</h3>
  <div class="methodsynopsis dc-description">
   <span class="modifier">function</span> <span class="methodname"><strong>taint</strong></span>(<span class="methodparam"><span class="type"><a href="language.types.string.php" class="type string">string</a></span> <code class="parameter reference">&$string</code></span>, <span class="methodparam"><span class="type"><a href="language.types.string.php" class="type string">string</a></span> <code class="parameter reference">&...$strings</code></span>): <span class="type"><a href="language.types.boolean.php" class="type bool">bool</a></span></div>

  <p class="simpara">
   手动把指定的字符串标记为已污染，效果如同它们来自用户输入。
   变量以引用方式传入，但标记本身存储于字符串而非变量之上：
   共享同一字符串的所有变量会同时变为已污染状态。
  </p>
  <p class="simpara">
   该函数主要用于测试，以及在 <a href="reserved.variables.get.php" class="link">$_GET</a>、
   <a href="reserved.variables.post.php" class="link">$_POST</a>
   和 <a href="reserved.variables.cookies.php" class="link">$_COOKIE</a>
   超全局变量没有数据的 CLI 脚本中模拟用户输入。
  </p>
 </div>


 <div class="refsect1 parameters" id="refsect1-function.taint-parameters">
  <h3 class="title">参数</h3>
  <dl>
   
    <dt><code class="parameter">string</code></dt>
    <dd>
     <p class="simpara">
      持有待标记字符串的变量。
     </p>
    </dd>
   
   
    <dt><code class="parameter">strings</code></dt>
    <dd>
     <p class="simpara">
      更多待标记的变量。
     </p>
    </dd>
   
  </dl>
 </div>


 <div class="refsect1 returnvalues" id="refsect1-function.taint-returnvalues">
  <h3 class="title">返回值</h3>
  <p class="simpara">
   始终返回 <strong><code><a href="reserved.constants.php#constant.true">true</a></code></strong>。当
   <a href="taint.configuration.php#ini.taint.enable" class="link">taint.enable</a> 未开启时，
   该函数不做任何事，但仍然返回 <strong><code><a href="reserved.constants.php#constant.true">true</a></code></strong>。
  </p>
 </div>


 <div class="refsect1 examples" id="refsect1-function.taint-examples">
  <h3 class="title">示例</h3>
  <div class="example" id="example-1">
   <p><strong>示例 #1 <span class="function"><strong>taint()</strong></span> 示例</strong></p>
   <div class="example-contents">
<div class="phpcode"><pre><code style="color: #000000"><span style="color: #0000BB">&lt;?php
$name </span><span style="color: #007700">= </span><span style="color: #DD0000">"world"</span><span style="color: #007700">;
</span><span style="color: #0000BB">taint</span><span style="color: #007700">(</span><span style="color: #0000BB">$name</span><span style="color: #007700">);
</span><span style="color: #0000BB">var_dump</span><span style="color: #007700">(</span><span style="color: #0000BB">is_tainted</span><span style="color: #007700">(</span><span style="color: #0000BB">$name</span><span style="color: #007700">));
</span><span style="color: #0000BB">?&gt;</span></code></pre></div>
   </div>

   <div class="example-contents"><p>以上示例的输出类似于：</p></div>
   <div class="example-contents screen">
<div class="examplescode"><pre class="examplescode">bool(true)</pre>
</div>
   </div>
  </div>
 </div>


 <div class="refsect1 notes" id="refsect1-function.taint-notes">
  <h3 class="title">注释</h3>
  <blockquote class="note"><p><strong class="note">注意</strong>: 
   <p class="simpara">
    只有非空字符串会被标记；持有其他类型或空字符串的变量会被静默忽略。
   </p>
  </p></blockquote>
  <blockquote class="note"><p><strong class="note">注意</strong>: 
   <p class="simpara">
    interned、persistent 和 permanent 字符串（字符串字面量、
    opcache 共享的字符串）永远无法携带标记，会被静默跳过。
   </p>
  </p></blockquote>
 </div>


 <div class="refsect1 seealso" id="refsect1-function.taint-seealso">
  <h3 class="title">参见</h3>
  <p class="para">
   <ul class="simplelist">
    <li><span class="function"><a href="function.untaint.php" class="function" rel="rdfs-seeAlso">untaint()</a> - 清除字符串上的污点标记</span></li>
    <li><span class="function"><a href="function.is-tainted.php" class="function" rel="rdfs-seeAlso">is_tainted()</a> - 检查一个字符串是否被污染</span></li>
   </ul>
  </p>
 </div>


</div><?php manual_footer($setup); ?>