git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[RFC/PATCHv2] git-web--browse: avoid the use of eval

From
Chris Packham <judge.packham@gmail.com>
Date
Sep 19, 2011, 09:26 UTC
Message-ID
<1316424415-11156-1-git-send-email-judge.packham@gmail.com>
In-Reply-To
<20110918183846.GA31176@sigill.intra.peff.net>

Using eval causes problems when the URL contains an appropriately escaped ampersand (\&). Dropping eval from the built-in browser invocation avoids the problem.

Cc: peff@peff.net
Cc: chriscool@tuxfamily.org
Cc: jepler@unpythonic.net
Signed-off-by: Chris Packham <judge.packham@gmail.com>

--- Here's an updated patch which drops the uses of eval when invoking a supported browser. The default case still uses eval but adds some extra quoting which also fixes the problem. I've avoided touching the 'start' case because I don't have access to a windows system to test with.

I've replaced my tests With the test suggested by Peff (should I be giving him credit in the copyright line or something?). I've grabbed t9901 but if there is a better set of miscellaneous minor tests that I should be using let me know.

 git-web--browse.sh         |   10 +++++-----
 t/t9901-git-web--browse.sh |   21 +++++++++++++++++++++
 2 files changed, 26 insertions(+), 5 deletions(-)
 create mode 100755 t/t9901-git-web--browse.sh
diff --git a/git-web--browse.sh b/git-web--browse.sh
index e9de241..ee05f10 100755
--- a/git-web--browse.sh
+++ b/git-web--browse.sh
@@ -156,7 +156,7 @@ firefox|iceweasel|seamonkey|iceape)
 	;;
 google-chrome|chrome|chromium|chromium-browser)
 	# No need to specify newTab. It's default in chromium
-	eval "$browser_path" "$@" &
+	"$browser_path" "$@" &
 	;;
 konqueror)
 	case "$(basename "$browser_path")" in
@@ -164,10 +164,10 @@ konqueror)
 		# It's simpler to use kfmclient to open a new tab in konqueror.
 		browser_path="$(echo "$browser_path" | sed -e 's/konqueror$/kfmclient/')"
 		type "$browser_path" > /dev/null 2>&1 || die "No '$browser_path' found."
-		eval "$browser_path" newTab "$@"
+		"$browser_path" newTab "$@" &
 		;;
 	kfmclient)
-		eval "$browser_path" newTab "$@"
+		"$browser_path" newTab "$@" &
 		;;
 	*)
 		"$browser_path" "$@" &
@@ -175,7 +175,7 @@ konqueror)
 	esac
 	;;
 w3m|elinks|links|lynx|open)
-	eval "$browser_path" "$@"
+	"$browser_path" "$@"
 	;;
 start)
 	exec "$browser_path" '"web-browse"' "$@"
@@ -185,7 +185,7 @@ opera|dillo)
 	;;
 *)
 	if test -n "$browser_cmd"; then
-		( eval $browser_cmd "$@" )
+		( eval $browser_cmd \""$@"\" )
 	fi
 	;;
 esac
diff --git a/t/t9901-git-web--browse.sh b/t/t9901-git-web--browse.sh
new file mode 100755
index 0000000..141ed17
--- /dev/null
+++ b/t/t9901-git-web--browse.sh
@@ -0,0 +1,21 @@
+#!/bin/sh
+#
+# Copyright (c) 2011 Chris Packham
+#
+
+test_description='git web--browse basic tests
+
+This test checks that git web--browse can handle various valid URLs.'
+
+. ./test-lib.sh
+
+test_expect_success \
+	'accepts a URL with an ampersand in it' '
+	echo http://example.com/foo\&bar/ >expect &&
+	git config browser.custom.cmd echo &&
+	git web--browse --browser=custom \
+		http://example.com/foo\&bar/ >actual &&
+	test_cmp expect actual
+'
+
+test_done
-- 
1.7.7.rc1.4.g47f23.dirty
Previous: Jeff KingNext: Jeff King
Message 11 of 33 in “Configurable hyperlinking in gitk”
  1. Configurable hyperlinking in gitkJeff Epler, Sep 17, 2011
  2. Chris PackhamSep 17, 2011
  3. Chris PackhamSep 17, 2011
  4. Jeff EplerSep 17, 2011
  5. Chris PackhamSep 17, 2011
  6. git web--browse error handling URL with & in it (Was Re: [RFC/PATCH] Configurable hyperlinking in gitk)Chris Packham, Sep 18, 2011
  7. Chris PackhamSep 18, 2011
  8. Jeff KingSep 18, 2011
  9. git-web--browse: invoke kfmclient directlyChris Packham, Sep 18, 2011
  10. Jeff KingSep 18, 2011
  11. [RFC/PATCHv2] git-web--browse: avoid the use of evalChris Packham, Sep 19, 2011
  12. Jeff KingSep 19, 2011
  13. Chris PackhamSep 20, 2011
  14. Jeff KingSep 20, 2011
  15. Junio C HamanoSep 20, 2011
  16. Junio C HamanoSep 19, 2011
  17. Jeff KingSep 19, 2011
  18. Junio C HamanoSep 19, 2011
  19. Jeff KingSep 19, 2011
  20. Junio C HamanoSep 19, 2011
  21. Andreas SchwabSep 19, 2011
  22. Jeff KingSep 19, 2011
  23. Junio C HamanoSep 19, 2011
  24. Andreas SchwabSep 19, 2011
  25. Jakub NarebskiSep 19, 2011
  26. Christian CouderSep 18, 2011
  27. Marc BranchaudSep 19, 2011
  28. Jakub NarebskiSep 18, 2011
  29. Jeff EplerSep 22, 2011
  30. Configurable hyperlinking in gitkJeff Epler, Sep 22, 2011
  31. Configurable hyperlinking in gitkJeff Epler, Oct 11, 2011
  32. Junio C HamanoOct 11, 2011
  33. Chris PackhamOct 12, 2011

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.