MCPcopy Create free account
hub / github.com/DeusData/codebase-memory-mcp / validate_windows_cmd_interpolation_arg

Function validate_windows_cmd_interpolation_arg

src/mcp/mcp.c:9492–9498  ·  view source on GitHub ↗

These characters retain command-language meaning inside quoted cmd.exe * arguments: percent expands environment variables, exclamation can expand * delayed variables, and caret changes parsing. Never interpolate them from a * stored project root or request branch into the Windows detect_changes payload. * /V:OFF is defense in depth for exclamation; validation remains the boundary. */

Source from the content-addressed store, hash-verified

9490 * stored project root or request branch into the Windows detect_changes payload.
9491 * /V:OFF is defense in depth for exclamation; validation remains the boundary. */
9492static bool validate_windows_cmd_interpolation_arg(const char *s) {
9493#ifdef _WIN32
9494 return s && strpbrk(s, "%!^") == NULL;
9495#else
9496 return s != NULL;
9497#endif
9498}
9499
9500static bool validate_search_args(const char *root_path, const char *file_pattern) {
9501 if (!validate_search_path_arg(root_path)) {

Callers 1

handle_detect_changesFunction · 0.85

Calls

no outgoing calls

Tested by

no test coverage detected