git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 6/6] t: teach lint that RHS of 'local VAR=VAL' needs to be quoted

From
Junio C Hamano <gitster@pobox.com>
Date
Apr 8, 2024, 17:31 UTC
Message-ID
<xmqqa5m3damh.fsf@gitster.g>
In-Reply-To
<20240407014344.GF1085004@coredump.intra.peff.net>
Jeff King <peff@peff.net> writes:
Show 27 quoted lines
> On Fri, Apr 05, 2024 at 05:09:02PM -0700, Junio C Hamano wrote:
>
>> Teach t/check-non-portable-shell.pl that right hand side of the
>> assignment done with "local VAR=VAL" need to be quoted.  We
>> deliberately target only VAL that begins with $ so that we can catch
>> 
>>  - $variable_reference and positional parameter reference like $4
>>  - $(command substitution)
>>  - ${variable_reference-with_magic}
>> 
>> while excluding
>> 
>>  - $'\n' that is a bash-ism freely usable in t990[23]
>>  - $(( arithmetic )) whose result should be $IFS safe.
>>  - $? that also is $IFS safe
>
> Hmm. Just porting over my comment from the other thread (before I
> realized you'd written this series), this misses:
>
>   local foo=bar/$1
>
> etc. Should we look for the "$" anywhere on the line? I doubt we can get
> things foolproof, but requiring somebody to quote:
>
>   local foo=$((1+2))
>
> does not seem like the worst outcome. I dunno.
Looking at the output from
    $ git grep -E -e 'local [a-zA-Z0-9_]+=[^"]*[$]' t/

the listed ones in the proposed commit log message are the false positives. Luckily we didn't have anything that tries to concatenate parameter reference to something else.

But with the pattern we do miss
    local var=$*

and possibly many others. So I am not sure. The false positives do look moderately bad, so I'd rather start with the simplest one proposed in the patch.

Previous: Jeff KingNext: Jeff King
Message 20 of 23 in “local VAR="VAL"”
  1. 0/6 local VAR="VAL"Junio C Hamano, Apr 6, 2024
  2. 1/6 CodingGuidelines: describe "export VAR=VAL" ruleJunio C Hamano, Apr 6, 2024
  3. Eric SunshineApr 6, 2024
  4. Junio C HamanoApr 6, 2024
  5. Andreas SchwabApr 6, 2024
  6. Junio C HamanoApr 6, 2024
  7. Eric SunshineApr 6, 2024
  8. 3/6 t: local VAR="VAL" (quote positional parameters)Junio C Hamano, Apr 6, 2024
  9. Patrick SteinhardtApr 8, 2024
  10. Junio C HamanoApr 8, 2024
  11. 2/6 CodingGuidelines: quote assigned value in 'local var=$val'Junio C Hamano, Apr 6, 2024
  12. rsbecker@nexbridge.comApr 6, 2024
  13. Junio C HamanoApr 6, 2024
  14. Eric SunshineApr 6, 2024
  15. Junio C HamanoApr 6, 2024
  16. 4/6 t: local VAR="VAL" (quote command substitution)Junio C Hamano, Apr 6, 2024
  17. 5/6 t: local VAR="VAL" (quote ${magic-reference})Junio C Hamano, Apr 6, 2024
  18. 6/6 t: teach lint that RHS of 'local VAR=VAL' needs to be quotedJunio C Hamano, Apr 6, 2024
  19. Jeff KingApr 7, 2024
  20. Junio C HamanoApr 8, 2024
  21. Jeff KingApr 8, 2024
  22. 7/6 t0610: local VAR="VAL" fixJunio C Hamano, Apr 6, 2024
  23. 8/6 t1016: local VAR="VAL" fixJunio C Hamano, Apr 6, 2024

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.