From: Junio C Hamano Date: Sun, 31 Aug 2008 16:27:38 GMT Subject: Re: [PATCH] change Perl syntax to support Perl 5.6 Message-ID: <7v63ph40at.fsf@gitster.siamese.dyndns.org> In-Reply-To: <8663phnw3z.fsf@blue.stonehenge.com> merlyn@stonehenge.com (Randal L. Schwartz) writes: >>>>>> "Avery" == Avery Pennarun writes: > > Avery> Shell quoting is a disaster (including security holes, where relevant) > Avery> waiting to happen. The above is the only sane way to do it, and it > Avery> isn't very hard to implement. (Instead of system() in the subprocess, > Avery> you can use exec().) > > quotemeta() is about regex quoting. This is not precisely the same as shell > quoting, and is both misleading, and potentially broken. Agreed to, and grateful for, both of your comments. Do you like the one Jakub quoted from how gitweb does it? It looks like this: # quote the given arguments for passing them to the shell # quote_command("command", "arg 1", "arg with ' and ! characters") # => "'command' 'arg 1' 'arg with '\'' and '\!' characters'" # Try to avoid using this function wherever possible. sub quote_command { return join(' ', map( { my $a = $_; $a =~ s/(['!])/'\\$1'/g; "'$a'" } @_ )); }