Validate shell-safe arguments for search. */ Search/grep paths and globs are ALWAYS single-quoted (POSIX sh) or * double-/single-quoted (Windows cmd/PowerShell) on the command line, which * neutralises '&' — a very common character in real paths (R&D, "Foo & Bar", * OneDrive). Accept '&' here while still rejecting every metacharacter that * could break out of the quoting (#272). */
| 9458 | * OneDrive). Accept '&' here while still rejecting every metacharacter that |
| 9459 | * could break out of the quoting (#272). */ |
| 9460 | static bool validate_search_path_arg(const char *s) { |
| 9461 | if (!s) { |
| 9462 | return false; |
| 9463 | } |
| 9464 | for (const char *p = s; *p; p++) { |
| 9465 | switch (*p) { |
| 9466 | case '\'': |
| 9467 | case '"': |
| 9468 | case ';': |
| 9469 | case '|': |
| 9470 | case '$': |
| 9471 | case '`': |
| 9472 | case '<': |
| 9473 | case '>': |
| 9474 | case '\n': |
| 9475 | case '\r': |
| 9476 | #ifndef _WIN32 |
| 9477 | case '\\': |
| 9478 | #endif |
| 9479 | return false; |
| 9480 | default: |
| 9481 | break; |
| 9482 | } |
| 9483 | } |
| 9484 | return true; |
| 9485 | } |
| 9486 | |
| 9487 | /* These characters retain command-language meaning inside quoted cmd.exe |
| 9488 | * arguments: percent expands environment variables, exclamation can expand |
no outgoing calls
no test coverage detected