git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] Convert open("-|") to qx{} calls

From
Randal L. Schwartz <merlyn@stonehenge.com>
Date
Feb 23, 2006, 16:07 UTC
Message-ID
<86hd6qgit5.fsf@blue.stonehenge.com>
In-Reply-To
<81b0412b0602230738s3445bd86h2d1d670e0ef5daed@mail.gmail.com>
>>>>> "Alex" == Alex Riesen <raa.lkml@gmail.com> writes:
Alex> Is $tmpname safe?
>> -       my $sha = <$F>;
>> +       my $sha = qx{git-hash-object -w $name};
>> +       !$? or exit $?;
Alex> Is $name safe?
>> -       while(<$f>) {
>> +       foreach (qx{git-ls-tree -r -z $gitrev $srcpath}) {
>> chomp;
Alex> Is $srcpath safe?
>> -                       while(<$F>) {
>> +                       foreach (qx{git-ls-files -z @o1}) {
Alex> @o1 must contain filenames. Can be dangerous
Convert all of these to use "safe_qx" (perl 5.6 compatible):
    sub safe_qx {
      defined (my $pid = open my $kid, "-|") or die "Cannot fork: $!";
      unless ($pid) { # child does:
        exec @_;
        die "Cannot exec @_: $!";
      }
      my $result = do { local $/; <$kid> };
      close $kid;                   # sets $?
      return $result;
    }

my $result = safe_qx('some shell command'); my $other_result = safe_qx('git-ls-tree', '-r', '-z', $gitrev, $srcpath);

Args are safe, as if being passed to system/exec, so a single arg can be a shell command, multiargs are passed arg-by-arg to a single exec target. $? is set correctly.

-- 
Randal L. Schwartz - Stonehenge Consulting Services, Inc. - +1 503 777 0095
<merlyn@stonehenge.com> <URL:http://www.stonehenge.com/merlyn/>
Perl/Unix/security consulting, Technical writing, Comedy, etc. etc.
See PerlTraining.Stonehenge.com for onsite and open-enrollment Perl training!
Previous: Alex RiesenNext: Junio C Hamano
Message 3 of 13 in “Convert open("-|") to qx{} calls”
  1. Convert open("-|") to qx{} callsJohannes Schindelin, Feb 23, 2006
  2. Alex RiesenFeb 23, 2006
  3. Randal L. SchwartzFeb 23, 2006
  4. Junio C HamanoFeb 23, 2006
  5. Randal L. SchwartzFeb 23, 2006
  6. Johannes SchindelinFeb 23, 2006
  7. Randal L. SchwartzFeb 23, 2006
  8. Alex RiesenFeb 23, 2006
  9. Randal L. SchwartzFeb 23, 2006
  10. Rogan DawesFeb 24, 2006
  11. Alex RiesenFeb 24, 2006
  12. Rogan DawesFeb 24, 2006
  13. Alex RiesenFeb 24, 2006

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.