Re: [PATCH] Put quotes around branch names to prevent special characters from being interpreted by the shell.
- From
Jeff King <peff@peff.net>
- Date
- Jun 7, 2010, 06:01 UTC
- Message-ID
- <20100607060147.GA20958@coredump.intra.peff.net>
- In-Reply-To
- <AANLkTik7PV-2u24UF78U6rtuffw4XUGS1F4hD2_ElrZZ@mail.gmail.com>
On Mon, Jun 07, 2010 at 05:48:11AM +0000, Ævar Arnfjörð Bjarmason wrote:
Show 5 quoted lines
> On Mon, Jun 7, 2010 at 05:10, Jay Soffian <jaysoffian@gmail.com> wrote: > > BTW, quotemeta is technically intended for use with regular > > expressions, isn't it? > > Yes, it's completely insecure to use it for shell interpolation.
It's intended for use with regexps, but I don't think it is insecure for shell interpolation. According to perldoc, it quotes 'all characters not matching "/[A-Za-z_0-9]/"'. So it's excessive for shell quoting, but not insecure.
> In Perl it's best to use the list form of system() so that the command > will escape things for you automatically.
Agreed, but it's not escaping things automatically. It simply skips the shell invocation entirely.
-Peff