diff --git a/bin/tagpreview.sh b/bin/tagpreview.sh index 0bc0b01..e22a732 100755 --- a/bin/tagpreview.sh +++ b/bin/tagpreview.sh @@ -30,6 +30,12 @@ else exit 1 fi +# Ex mode starts on the last line, so an entry with no address would report the +# end of the file as the tag. Every other path refuses such an entry +if [ -z "${EXCMD}" ]; then + exit 1 +fi + # The address comes from a tags file, which can be untrusted, and a preview runs # as soon as an entry is highlighted. Sandboxed as a builtin tag jump is, so that # it cannot run a shell command or touch a file. ':sandbox' on its own only covers