Resolve the shell explicitly — %COMSPEC%, else \cmd.exe — so it * can be passed as lpApplicationName and CreateProcess never walks the search * path (no cmd.exe planting from a hostile CWD). Heap string; caller frees. */
| 177 | * can be passed as lpApplicationName and CreateProcess never walks the search |
| 178 | * path (no cmd.exe planting from a hostile CWD). Heap string; caller frees. */ |
| 179 | static wchar_t *cbm_resolve_comspec(void) { |
| 180 | wchar_t buf[MAX_PATH]; |
| 181 | const wchar_t suffix[] = L"\\cmd.exe"; |
| 182 | DWORD n = GetEnvironmentVariableW(L"COMSPEC", buf, MAX_PATH); |
| 183 | if (n == 0 || n >= MAX_PATH) { |
| 184 | UINT sn = GetSystemDirectoryW(buf, MAX_PATH); |
| 185 | if (sn == 0 || (size_t)sn + wcslen(suffix) >= MAX_PATH) { |
| 186 | return NULL; |
| 187 | } |
| 188 | wmemcpy(buf + sn, suffix, wcslen(suffix) + 1); |
| 189 | } |
| 190 | return _wcsdup(buf); |
| 191 | } |
| 192 | |
| 193 | /* On failure returns NULL with *stage naming the failing step and *gle the |
| 194 | * GetLastError value captured at that step (0 when errno is the signal). */ |
no outgoing calls
no test coverage detected