1 /* Quoting for a system command.
2 Copyright (C) 2012-2020 Free Software Foundation, Inc.
3 Written by Bruno Haible <bruno@clisp.org>, 2012.
5 This program is free software: you can redistribute it and/or modify
6 it under the terms of the GNU General Public License as published by
7 the Free Software Foundation; either version 3 of the License, or
8 (at your option) any later version.
10 This program is distributed in the hope that it will be useful,
11 but WITHOUT ANY WARRANTY; without even the implied warranty of
12 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 GNU General Public License for more details.
15 You should have received a copy of the GNU General Public License
16 along with this program. If not, see <https://www.gnu.org/licenses/>. */
21 #include "system-quote.h"
30 #if defined _WIN32 && ! defined __CYGWIN__
32 /* The native Windows CreateProcess() function interprets characters like
33 ' ', '\t', '\\', '"' (but not '<' and '>') in a special way:
34 - Space and tab are interpreted as delimiters. They are not treated as
35 delimiters if they are surrounded by double quotes: "...".
36 - Unescaped double quotes are removed from the input. Their only effect is
37 that within double quotes, space and tab are treated like normal
39 - Backslashes not followed by double quotes are not special.
40 - But 2*n+1 backslashes followed by a double quote become
41 n backslashes followed by a double quote (n >= 0):
45 - '*', '?' characters may get expanded through wildcard expansion in the
46 callee: By default, in the callee, the initialization code before main()
47 takes the result of GetCommandLine(), wildcard-expands it, and passes it
48 to main(). The exceptions to this rule are:
49 - programs that inspect GetCommandLine() and ignore argv,
50 - mingw programs that have a global variable 'int _CRT_glob = 0;',
51 - Cygwin programs, when invoked from a Cygwin program.
53 # define SHELL_SPECIAL_CHARS "\"\\ \001\002\003\004\005\006\007\010\011\012\013\014\015\016\017\020\021\022\023\024\025\026\027\030\031\032\033\034\035\036\037*?"
54 # define SHELL_SPACE_CHARS " \001\002\003\004\005\006\007\010\011\012\013\014\015\016\017\020\021\022\023\024\025\026\027\030\031\032\033\034\035\036\037"
56 /* Copies the quoted string to p and returns the number of bytes needed.
57 If p is non-NULL, there must be room for system_quote_length (string)
60 windows_createprocess_quote (char *p
, const char *string
)
62 size_t len
= strlen (string
);
64 (len
== 0 || strpbrk (string
, SHELL_SPECIAL_CHARS
) != NULL
);
65 size_t backslashes
= 0;
78 for (; len
> 0; string
++, len
--)
86 for (j
= backslashes
+ 1; j
> 0; j
--)
99 for (j
= backslashes
; j
> 0; j
--)
107 /* The native Windows cmd.exe command interpreter also interprets:
108 - '\n', '\r' as a command terminator - no way to escape it,
109 - '<', '>' as redirections,
110 - '|' as pipe operator,
111 - '%var%' as a reference to the environment variable VAR (uppercase),
112 even inside quoted strings,
113 - '&' '[' ']' '{' '}' '^' '=' ';' '!' '\'' '+' ',' '`' '~' for other
114 purposes, according to
115 <https://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/cmd.mspx?mfr=true>
116 We quote a string like '%var%' by putting the '%' characters outside of
117 double-quotes and the rest of the string inside double-quotes: %"var"%.
118 This is guaranteed to not be a reference to an environment variable.
120 # define CMD_SPECIAL_CHARS "\"\\ \001\002\003\004\005\006\007\010\011\012\013\014\015\016\017\020\021\022\023\024\025\026\027\030\031\032\033\034\035\036\037!%&'*+,;<=>?[]^`{|}~"
121 # define CMD_FORBIDDEN_CHARS "\n\r"
123 /* Copies the quoted string to p and returns the number of bytes needed.
124 If p is non-NULL, there must be room for system_quote_length (string)
127 windows_cmd_quote (char *p
, const char *string
)
129 size_t len
= strlen (string
);
131 (len
== 0 || strpbrk (string
, CMD_SPECIAL_CHARS
) != NULL
);
132 size_t backslashes
= 0;
145 for (; len
> 0; string
++, len
--)
153 for (j
= backslashes
+ 1; j
> 0; j
--)
160 for (j
= backslashes
; j
> 0; j
--)
176 for (j
= backslashes
; j
> 0; j
--)
186 system_quote_length (enum system_command_interpreter interpreter
,
191 #if !(defined _WIN32 && ! defined __CYGWIN__)
195 return shell_quote_length (string
);
197 #if defined _WIN32 && ! defined __CYGWIN__
198 case SCI_WINDOWS_CREATEPROCESS
:
199 return windows_createprocess_quote (NULL
, string
);
202 case SCI_WINDOWS_CMD
:
203 return windows_cmd_quote (NULL
, string
);
207 /* Invalid interpreter. */
213 system_quote_copy (char *p
,
214 enum system_command_interpreter interpreter
,
219 #if !(defined _WIN32 && ! defined __CYGWIN__)
223 return shell_quote_copy (p
, string
);
225 #if defined _WIN32 && ! defined __CYGWIN__
226 case SCI_WINDOWS_CREATEPROCESS
:
227 p
+= windows_createprocess_quote (p
, string
);
232 case SCI_WINDOWS_CMD
:
233 p
+= windows_cmd_quote (p
, string
);
239 /* Invalid interpreter. */
245 system_quote (enum system_command_interpreter interpreter
,
250 #if !(defined _WIN32 && ! defined __CYGWIN__)
254 return shell_quote (string
);
256 #if defined _WIN32 && ! defined __CYGWIN__
257 case SCI_WINDOWS_CREATEPROCESS
:
259 case SCI_WINDOWS_CMD
:
261 size_t length
= system_quote_length (interpreter
, string
);
262 char *quoted
= XNMALLOC (length
, char);
263 system_quote_copy (quoted
, interpreter
, string
);
269 /* Invalid interpreter. */
275 system_quote_argv (enum system_command_interpreter interpreter
,
286 for (argp
= argv
; ; )
288 length
+= system_quote_length (interpreter
, *argp
) + 1;
294 command
= XNMALLOC (length
, char);
297 for (argp
= argv
; ; )
299 p
= system_quote_copy (p
, interpreter
, *argp
);