*/
std::string shellQuote(StringPiece argument);
+namespace detail {
+template <typename... Arguments>
+std::vector<std::string> shellify(
+ StringPiece format,
+ Arguments&&... arguments) {
+ auto command = sformat(
+ format,
+ shellQuote(to<std::string>(std::forward<Arguments>(arguments)))...);
+ return {"/bin/sh", "-c", command};
+}
+
+struct ShellCmdFormat {
+ StringPiece format;
+ template <typename... Arguments>
+ std::vector<std::string> operator()(Arguments&&... arguments) const {
+ return ::folly::detail::shellify(
+ format, std::forward<Arguments>(arguments)...);
+ }
+};
+
+} // namespace detail
+
+inline namespace literals {
+inline namespace shell_literals {
+constexpr detail::ShellCmdFormat operator"" _shellify(
+ char const* name,
+ std::size_t length) {
+ return {folly::StringPiece(name, length)};
+}
+} // inline namespace shell_literals
+} // inline namespace literals
+
/**
* Create argument array for `Subprocess()` for a process running in a
* shell.
*
* The shell to use is always going to be `/bin/sh`.
*
- * The format string should always be a string literal to protect against
- * shell injections. Arguments will automatically be escaped with `'`.
- *
- * TODO(dominik): find a way to ensure statically determined format strings.
+ * This is deprecated in favour of the user-defined-literal `_shellify`
+ * from namespace `folly::shell_literals` because that requires that the format
+ * string is a compile-time constant which can be inspected during code reviews
*/
template <typename... Arguments>
+FOLLY_DEPRECATED(
+ "Use `\"command {} {} ...\"_shellify(argument1, argument2 ...)` from "
+ "namespace `folly::literals::shell_literals`")
std::vector<std::string> shellify(
- const StringPiece format,
+ StringPiece format,
Arguments&&... arguments) {
- auto command = sformat(
- format,
- shellQuote(to<std::string>(std::forward<Arguments>(arguments)))...);
- return {"/bin/sh", "-c", command};
+ return detail::shellify(format, std::forward<Arguments>(arguments)...);
}
} // folly
}
TEST(Shell, Shellify) {
+ auto command = "rm -rf /"_shellify();
+ EXPECT_EQ(command[0], "/bin/sh");
+ EXPECT_EQ(command[1], "-c");
+ EXPECT_EQ(command[2], "rm -rf /");
+
+ command = "rm -rf {}"_shellify("someFile.txt");
+ EXPECT_EQ(command[2], "rm -rf 'someFile.txt'");
+
+ command = "rm -rf {}"_shellify(5);
+ EXPECT_EQ(command[2], "rm -rf '5'");
+
+ command = "ls {}"_shellify("blah'; rm -rf /");
+ EXPECT_EQ(command[2], "ls 'blah'\\''; rm -rf /'");
+}
+
+TEST(Shell, Shellify_deprecated) {
auto command = shellify("rm -rf /");
EXPECT_EQ(command[0], "/bin/sh");
EXPECT_EQ(command[1], "-c");