mirror of
https://github.com/microsoft/vscode.git
synced 2026-09-30 18:46:00 +01:00
* Fix shell argument injection in generated commit messages The commit-message sanitizer escaped `"` before `\`, so the second replace re-escaped the backslash the first one had just added and turned `"` into `\\"`. Inside a double-quoted shell string that reads as an escaped backslash followed by a closing quote, ending the `-m` argument early and leaving the rest of the message to be parsed as separate shell tokens. Backticks were not escaped at all, so a message containing `cmd` in backticks still triggered command substitution. Quote the message with single quotes instead, which suppress expansion and substitution outright rather than depending on every metacharacter being escaped individually. Quoting is shell-aware because `'` is not a quote character in cmd.exe and PowerShell escapes an embedded `'` by doubling it rather than with the POSIX `'\''` idiom. This also fixes the previous `\` doubling silently corrupting backslashes under PowerShell. The helper lives in its own module so it is covered by the fast unit suite and can be reused by the other terminal sendText call sites. Fixes #316995 Fixes #316996 Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Harden commit-message quoting per shell, else use the commit box The first fix still let a generated message break out of its quoted argument in several shells. Because sendText turns every line break into an Enter key press, a breakout in a multi-line message ran without the user pressing Enter. - PowerShell also ends a single-quoted string at the typographic single quotes U+2018, U+2019, U+201A and U+201B, which are common in generated text. - Windows PowerShell 5.1 does not escape an embedded double quote when it builds git's command line, so the quote split the argument. PowerShell 5.1 and 7 both report the shell as pwsh, so a double quote is refused. - fish treats \' and \\ as escapes inside single quotes, so a backslash defeated the POSIX '\'' idiom. - nu has no escape for a single quote. cmd.exe expands %VAR% inside double quotes and runs each line as soon as it is entered. csh expands ! inside single quotes and cannot continue them onto a new line. Typed control characters are also commands to the shell's line editor; for example, a Backspace can erase the opening quote. A message containing one is refused for every shell. quoteShellArgument now uses an allowlist of shells whose quoting rules are known, and returns undefined when a value cannot be quoted safely. The command then puts the message in the Source Control commit box instead of typing it into the terminal. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Shorten comments in commit-message shell quoting Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> * Strip or replace unsafe characters instead of refusing them Refusing a message sent it to the Source Control commit box. The Agents window has no Source Control view, though, and Agent Host terminals never report a shell type, so there every message was refused and then lost. buildGitCommitCommand now always builds a command, except for agent CLIs: - Control characters are stripped for every shell. - PowerShell gets ' in place of ", and a space after a trailing \. Git's message cleanup removes that space again. - cmd.exe and other or undetected shells get one -m per paragraph, reduced to characters that every shell treats literally inside double quotes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> --------- Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>