From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!not-for-mail From: Random832 Newsgroups: gmane.emacs.devel Subject: Re: [PATCH] Add shell-quasiquote. Date: Sat, 17 Oct 2015 17:20:02 -0400 Message-ID: <87vba519bx.fsf@fastmail.com> References: <87si59wj42.fsf@T420.taylan> <83eggt4esi.fsf@gnu.org> <87fv19wh7b.fsf@T420.taylan> <83bnbx4d7e.fsf@gnu.org> <87twppuzfu.fsf@T420.taylan> <83a8rh48if.fsf@gnu.org> <87io65utmt.fsf@T420.taylan> <5622B3C6.4030208@cs.ucla.edu> NNTP-Posting-Host: plane.gmane.org Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Trace: ger.gmane.org 1445116854 903 80.91.229.3 (17 Oct 2015 21:20:54 GMT) X-Complaints-To: usenet@ger.gmane.org NNTP-Posting-Date: Sat, 17 Oct 2015 21:20:54 +0000 (UTC) To: emacs-devel@gnu.org Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Sat Oct 17 23:20:45 2015 Return-path: Envelope-to: ged-emacs-devel@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by plane.gmane.org with esmtp (Exim 4.69) (envelope-from ) id 1ZnYuD-00044F-6f for ged-emacs-devel@m.gmane.org; Sat, 17 Oct 2015 23:20:45 +0200 Original-Received: from localhost ([::1]:59792 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ZnYuC-0004hh-O5 for ged-emacs-devel@m.gmane.org; Sat, 17 Oct 2015 17:20:44 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:41791) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ZnYu8-0004hZ-Bh for emacs-devel@gnu.org; Sat, 17 Oct 2015 17:20:41 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1ZnYu5-0000FM-2n for emacs-devel@gnu.org; Sat, 17 Oct 2015 17:20:40 -0400 Original-Received: from plane.gmane.org ([80.91.229.3]:44846) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ZnYu4-0000EI-PV for emacs-devel@gnu.org; Sat, 17 Oct 2015 17:20:36 -0400 Original-Received: from list by plane.gmane.org with local (Exim 4.69) (envelope-from ) id 1ZnYu1-0003rX-Rv for emacs-devel@gnu.org; Sat, 17 Oct 2015 23:20:34 +0200 Original-Received: from c-68-39-146-59.hsd1.in.comcast.net ([68.39.146.59]) by main.gmane.org with esmtp (Gmexim 0.1 (Debian)) id 1AlnuQ-0007hv-00 for ; Sat, 17 Oct 2015 23:20:33 +0200 Original-Received: from random832 by c-68-39-146-59.hsd1.in.comcast.net with local (Gmexim 0.1 (Debian)) id 1AlnuQ-0007hv-00 for ; Sat, 17 Oct 2015 23:20:33 +0200 X-Injected-Via-Gmane: http://gmane.org/ Original-Lines: 21 Original-X-Complaints-To: usenet@ger.gmane.org X-Gmane-NNTP-Posting-Host: c-68-39-146-59.hsd1.in.comcast.net User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/24.3 (gnu/linux) Cancel-Lock: sha1:Uwitz4r4avXgM8sV+7XepyBm/Y4= X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-Received-From: 80.91.229.3 X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Original-Sender: emacs-devel-bounces+ged-emacs-devel=m.gmane.org@gnu.org Xref: news.gmane.org gmane.emacs.devel:191884 Archived-At: Paul Eggert writes: > Taylan Ulrich Bayırlı/Kammer wrote: >> You seem to be implying that using shell-quote-argument will uphold the >> invariant that the code is safe against injection. I'm asking for >> explicit confirmation of that. > > Yes, it's safe. In contrast, the version you proposed is not safe for > really weird csh-like shells, where it can mishandle '!'. If supporting csh-like shells is a concern, I'll point out that the newline mishandling I noted in another post allows one to, at least, inject an arbitrary command with no arguments: (call-process "csh" nil t "csh" "-c" (concat "echo " (shell-quote-argument "\nevil-command\n"))) Unmatched '. evil-command: Command not found. Unmatched '. 1