Page MenuHomePhorge

Fix incorrect quoting of author in 'arc patch'

Authored by ldanna on Oct 17 2021, 20:02.
Referenced Files
F2304158: D25026.1721100862.diff
Mon, Jul 15, 03:34
F2303327: D25026.1721069524.diff
Sun, Jul 14, 18:52
Unknown Object (File)
Fri, Jul 12, 16:54
Unknown Object (File)
Fri, Jul 12, 15:12
Unknown Object (File)
Fri, Jul 12, 09:49
Unknown Object (File)
Fri, Jul 12, 04:57
Unknown Object (File)
Thu, Jul 11, 07:21
Unknown Object (File)
Wed, Jul 10, 10:50



Author field is formatted with csprintf, which would be appropriate
if the resulting string was concatenated into a shell command as a
string -- but because the flags are passed as a vector of strings
and not parsed by the shell, this results in extraneous shell
quoting making it into to author field. In particular this
renders my name as D'\''Anna instead of D'Anna

Test Plan

Performed 'arc patch' with and without these changes, confirmed
that my apostrophe was no longer mangled by shell quotes in the
resulting commit.

Diff Detail

rARC Arcanist
Lint Not Applicable
Tests Not Applicable

Event Timeline

ldanna requested review of this revision.Oct 17 2021, 20:02

I feel like this is a good change. I do not see any security vulnerabilities that could be introduced by this..

I will let everyone else chime in as shell escaping code is an attack vector

This revision is now accepted and ready to land.Oct 22 2021, 15:48

Thank you for submitting this change!

@speck thanks, how do I land the change?