Sandbox the address the same way on the Show paths

They passed ':sandbox' as a modifier, which the address check makes safe today
but which stops covering anything that ever slips past it.
This commit is contained in:
Junegunn Choi committed 2026-09-28 00:08:50 +09:00
1 parent 81ae642d5b
commit 2b6e8b2132
1 file changed
+10 -3
+10 -3
View File
@@ -535,11 +535,18 @@ function! s:execute_silent(cmd)
endfunction
" A tag address can be any Ex command, and a tags file can come from an
" untrusted source, so run it in a sandbox as a builtin tag jump does
" untrusted source, so run it in a sandbox as a builtin tag jump does. ':sandbox'
" as a modifier only covers the command up to the first '|', so hand the address
" to ':execute', which keeps all of it inside the sandbox
function! s:execute_tag_address(excmd)
silent keepjumps keepalt sandbox execute a:excmd
endfunction
" The same, as a command for a win_execute() list
function! s:sandboxed(cmd)
return 'sandbox execute '.string(a:cmd)
endfunction
" Address of a tag, given the rest of the line after the file name. Only the
" forms a tags file is meant to hold, a line number and a search pattern,
" chained with ';' for '--excmd=combine' and cut at the ';"' terminator as
@@ -762,7 +769,7 @@ function! s:goto_entry(winid, bufnr, dir, kind, entry) abort
return
endif
let cmds = s:edit_cmds(a:winid, path)
\ + ['sandbox keepjumps '.excmd, 'normal! ^zvzz']
\ + [s:sandboxed('keepjumps '.excmd), 'normal! ^zvzz']
elseif a:kind ==# 'btags'
let parts = split(entry, "\t")
if len(parts) < 3 || !bufexists(a:bufnr)
@@ -773,7 +780,7 @@ function! s:goto_entry(winid, bufnr, dir, kind, entry) abort
return
endif
let cmds = ['keepalt keepjumps hide buffer '.a:bufnr,
\ 'sandbox keepjumps '.excmd, 'normal! zvzz']
\ s:sandboxed('keepjumps '.excmd), 'normal! zvzz']
elseif a:kind ==# 'marks'
" A lowercase mark is local to the buffer the run started on
let mark = matchstr(entry, '^\s*\zs\S')