Files
vscode/extensions
Dmitriy VasyuraandCopilot fb964648ff copilot: fix shell argument injection in generated commit messages (#337547)
* Fix shell argument injection in generated commit messages

The commit-message sanitizer escaped `"` before `\`, so the second replace
re-escaped the backslash the first one had just added and turned `"` into
`\\"`. Inside a double-quoted shell string that reads as an escaped backslash
followed by a closing quote, ending the `-m` argument early and leaving the
rest of the message to be parsed as separate shell tokens. Backticks were not
escaped at all, so a message containing `cmd` in backticks still triggered
command substitution.

Quote the message with single quotes instead, which suppress expansion and
substitution outright rather than depending on every metacharacter being
escaped individually. Quoting is shell-aware because `'` is not a quote
character in cmd.exe and PowerShell escapes an embedded `'` by doubling it
rather than with the POSIX `'\''` idiom. This also fixes the previous `\`
doubling silently corrupting backslashes under PowerShell.

The helper lives in its own module so it is covered by the fast unit suite
and can be reused by the other terminal sendText call sites.

Fixes #316995
Fixes #316996

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Harden commit-message quoting per shell, else use the commit box

The first fix still let a generated message break out of its quoted
argument in several shells. Because sendText turns every line break into an
Enter key press, a breakout in a multi-line message ran without the user
pressing Enter.

- PowerShell also ends a single-quoted string at the typographic single
  quotes U+2018, U+2019, U+201A and U+201B, which are common in generated
  text.
- Windows PowerShell 5.1 does not escape an embedded double quote when it
  builds git's command line, so the quote split the argument. PowerShell 5.1
  and 7 both report the shell as pwsh, so a double quote is refused.
- fish treats \' and \\ as escapes inside single quotes, so a backslash
  defeated the POSIX '\'' idiom.
- nu has no escape for a single quote. cmd.exe expands %VAR% inside double
  quotes and runs each line as soon as it is entered. csh expands ! inside
  single quotes and cannot continue them onto a new line.

Typed control characters are also commands to the shell's line editor; for
example, a Backspace can erase the opening quote. A message containing one
is refused for every shell.

quoteShellArgument now uses an allowlist of shells whose quoting rules are
known, and returns undefined when a value cannot be quoted safely. The
command then puts the message in the Source Control commit box instead of
typing it into the terminal.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Shorten comments in commit-message shell quoting

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* Strip or replace unsafe characters instead of refusing them

Refusing a message sent it to the Source Control commit box. The Agents
window has no Source Control view, though, and Agent Host terminals never
report a shell type, so there every message was refused and then lost.

buildGitCommitCommand now always builds a command, except for agent CLIs:

- Control characters are stripped for every shell.
- PowerShell gets ' in place of ", and a space after a trailing \. Git's
  message cleanup removes that space again.
- cmd.exe and other or undetected shells get one -m per paragraph, reduced
  to characters that every shell treats literally inside double quotes.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-09-29 15:06:22 +00:00
..
2026-09-03 21:17:28 +00:00
…
…
…
…
2026-09-17 22:18:25 +00:00
…
…
…
…
…
…
…
…
…
…
…
…
2026-09-17 22:18:25 +00:00
…
…
…
…
…
…
…
…
…
…
…
…