From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!not-for-mail From: Random832 Newsgroups: gmane.emacs.devel Subject: Re: [PATCH] Add shell-quasiquote. Date: Mon, 19 Oct 2015 09:48:25 -0400 Message-ID: <871tcr7yvq.fsf@fastmail.com> References: <87si59wj42.fsf@T420.taylan> <878u6znii9.fsf@T420.taylan> <877fmjj9p6.fsf@fencepost.gnu.org> <87zizfm2dq.fsf@T420.taylan> NNTP-Posting-Host: plane.gmane.org Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Trace: ger.gmane.org 1445262571 9512 80.91.229.3 (19 Oct 2015 13:49:31 GMT) X-Complaints-To: usenet@ger.gmane.org NNTP-Posting-Date: Mon, 19 Oct 2015 13:49:31 +0000 (UTC) To: emacs-devel@gnu.org Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Mon Oct 19 15:49:22 2015 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by plane.gmane.org with esmtp (Exim 4.69) (envelope-from ) id 1ZoAoU-00011h-44 for ged-emacs-devel@m.gmane.org; Mon, 19 Oct 2015 15:49:22 +0200 Original-Received: from localhost ([::1]:39606 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ZoAoT-0007Ey-De for ged-emacs-devel@m.gmane.org; Mon, 19 Oct 2015 09:49:21 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:38538) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ZoAny-0006wi-HP for emacs-devel@gnu.org; Mon, 19 Oct 2015 09:48:51 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1ZoAnt-0002x9-FD for emacs-devel@gnu.org; Mon, 19 Oct 2015 09:48:50 -0400 Original-Received: from plane.gmane.org ([80.91.229.3]:54034) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ZoAnt-0002wt-97 for emacs-devel@gnu.org; Mon, 19 Oct 2015 09:48:45 -0400 Original-Received: from list by plane.gmane.org with local (Exim 4.69) (envelope-from ) id 1ZoAnr-0000e8-NL for emacs-devel@gnu.org; Mon, 19 Oct 2015 15:48:43 +0200 Original-Received: from c-68-39-146-59.hsd1.in.comcast.net ([68.39.146.59]) by main.gmane.org with esmtp (Gmexim 0.1 (Debian)) id 1AlnuQ-0007hv-00 for ; Mon, 19 Oct 2015 15:48:43 +0200 Original-Received: from random832 by c-68-39-146-59.hsd1.in.comcast.net with local (Gmexim 0.1 (Debian)) id 1AlnuQ-0007hv-00 for ; Mon, 19 Oct 2015 15:48:43 +0200 X-Injected-Via-Gmane: http://gmane.org/ Original-Lines: 12 Original-X-Complaints-To: usenet@ger.gmane.org X-Gmane-NNTP-Posting-Host: c-68-39-146-59.hsd1.in.comcast.net User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/24.3 (gnu/linux) Cancel-Lock: sha1:6++YP83MKn2WcZCszP+ut19+fPc= X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-Received-From: 80.91.229.3 X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Xref: news.gmane.org gmane.emacs.devel:192097 Archived-At: taylanbayirli@gmail.com (Taylan Ulrich "Bayırlı/Kammer") writes: > It was not criticism of shell-quote-argument (those are separate). > Indeed it quotes arguments. My variant also quotes things that may be > the name of the command and not an argument. But why does it *need* to? Do you realize that you are now suggesting an injection scenario whereby the attacker is _legitimately_ permitted to supply an arbitrary string for an ordinary command to be executed, but somehow letting them execute "if" [which will be a syntax error anyway since they can't supply the then/fi as separate statements] becomes a security hole?