Do not run backticks in a file name from a tags file

expand() globs and runs backticks, so an entry naming '`touch FILE`.c' ran the
command, and on CTRL-O it ran even for an address the new check then refused.
fnamemodify(':p') instead, as s:in_dir already does for the same reason. It
gives up '$VAR' in a name, which no tag generator writes.

The address is now checked before the name is touched, so nothing happens at all
for an entry that will not be used.
This commit is contained in:
Junegunn Choi committed 2026-09-28 03:10:41 +09:00
1 parent b1c03ea0ef
commit 747cd594a2
1 file changed
+10 -6
+10 -6
View File
@@ -772,13 +772,15 @@ function! s:goto_entry(winid, bufnr, dir, kind, entry) abort
return
endif
let excmd = s:tag_address(join(parts[2:-2], '')[:-2], 1)
let relpath = parts[1][:-2]
let path = relpath =~ (s:is_win ? '^[A-Z]:\' : '^/')
\ ? relpath : join([fnamemodify(parts[-1], ':h'), relpath], '/')
let path = expand(path, 1)
if empty(excmd)
return s:warn('Unsupported tag address: '.s:strip(parts[0]))
endif
let relpath = parts[1][:-2]
let path = relpath =~ (s:is_win ? '^[A-Z]:\' : '^/')
\ ? relpath : join([fnamemodify(parts[-1], ':h'), relpath], '/')
" fnamemodify(), not expand(), which runs backticks in the name a tags file
" gives, as s:in_dir says
let path = fnamemodify(path, ':p')
if !filereadable(path)
return
endif
@@ -1800,10 +1802,12 @@ function! s:tags_sink(from, lines)
let relpath = parts[1][:-2]
let abspath = relpath =~ (s:is_win ? '^[A-Z]:\' : '^/') ? relpath : join([base, relpath], '/')
" fnamemodify(), not expand(), which runs backticks in the name
let abspath = fnamemodify(abspath, ':p')
if len(list) == 1
call s:action_for(key, expand(abspath, 1))
call s:action_for(key, abspath)
else
call s:open(expand(abspath, 1))
call s:open(abspath)
endif
call s:execute_tag_address(excmd)
call add(qfl, {'filename': expand('%'), 'lnum': line('.'), 'text': getline('.')})