Skip to content

fix shell quoting #8641

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
May 27, 2025
Merged

fix shell quoting #8641

merged 1 commit into from
May 27, 2025

Conversation

kroening
Copy link
Member

This adds missing cases to shell_quote(...), preventing potential priviledge escalation.

  • Each commit message has a non-empty body, explaining why the change was made.
  • n/a Methods or procedures I have added are documented, following the guidelines provided in CODING_STANDARD.md.
  • n/a The feature or user visible behaviour I have added or modified has been documented in the User Guide in doc/cprover-manual/
  • Regression or unit tests are included, or existing tests cover the modified code (in this case I have detailed which ones those are in the commit message).
  • n/a My commit message includes data points confirming performance improvements (if claimed).
  • My PR is restricted to a single feature or bugfix.
  • White-space or formatting changes outside the feature-related changed lines are in commits of their own.

REQUIRE(shell_quote("foo.bar") == "foo.bar");
REQUIRE(shell_quote("foo\nbar") == "'foo\nbar'");
REQUIRE(shell_quote("foo(bar)") == "'foo(bar)'");
REQUIRE(shell_quote("foo'bar") == "'foo\'bar'");
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This test is failing.

@kroening kroening force-pushed the shell-quote-fix branch 2 times, most recently from 9561e47 to 157b18d Compare May 27, 2025 00:35
Copy link

codecov bot commented May 27, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 80.38%. Comparing base (3c915eb) to head (9b0a0c3).
Report is 2 commits behind head on develop.

Additional details and impacted files
@@             Coverage Diff             @@
##           develop    #8641      +/-   ##
===========================================
+ Coverage    80.37%   80.38%   +0.01%     
===========================================
  Files         1686     1686              
  Lines       206885   206888       +3     
  Branches        73       73              
===========================================
+ Hits        166276   166305      +29     
+ Misses       40609    40583      -26     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

This adds missing cases to shell_quote(...), preventing potential priviledge
escalation.
@kroening kroening merged commit 50be009 into develop May 27, 2025
41 checks passed
@kroening kroening deleted the shell-quote-fix branch May 27, 2025 12:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants