From 747cd594a21dc43a178b535a22becfd7b3648224 Mon Sep 17 00:00:00 2001 From: Junegunn Choi Date: Mon, 28 Sep 2026 03:10:41 +0900 Subject: [PATCH] Do not run backticks in a file name from a tags file expand() globs and runs backticks, so an entry naming '`touch FILE`.c' ran the command, and on CTRL-O it ran even for an address the new check then refused. fnamemodify(':p') instead, as s:in_dir already does for the same reason. It gives up '$VAR' in a name, which no tag generator writes. The address is now checked before the name is touched, so nothing happens at all for an entry that will not be used. --- autoload/fzf/vim.vim | 16 ++++++++++------ 1 file changed, 10 insertions(+), 6 deletions(-) diff --git a/autoload/fzf/vim.vim b/autoload/fzf/vim.vim index 30a32bd..0978811 100755 --- a/autoload/fzf/vim.vim +++ b/autoload/fzf/vim.vim @@ -772,13 +772,15 @@ function! s:goto_entry(winid, bufnr, dir, kind, entry) abort return endif let excmd = s:tag_address(join(parts[2:-2], '')[:-2], 1) - let relpath = parts[1][:-2] - let path = relpath =~ (s:is_win ? '^[A-Z]:\' : '^/') - \ ? relpath : join([fnamemodify(parts[-1], ':h'), relpath], '/') - let path = expand(path, 1) if empty(excmd) return s:warn('Unsupported tag address: '.s:strip(parts[0])) endif + let relpath = parts[1][:-2] + let path = relpath =~ (s:is_win ? '^[A-Z]:\' : '^/') + \ ? relpath : join([fnamemodify(parts[-1], ':h'), relpath], '/') + " fnamemodify(), not expand(), which runs backticks in the name a tags file + " gives, as s:in_dir says + let path = fnamemodify(path, ':p') if !filereadable(path) return endif @@ -1800,10 +1802,12 @@ function! s:tags_sink(from, lines) let relpath = parts[1][:-2] let abspath = relpath =~ (s:is_win ? '^[A-Z]:\' : '^/') ? relpath : join([base, relpath], '/') + " fnamemodify(), not expand(), which runs backticks in the name + let abspath = fnamemodify(abspath, ':p') if len(list) == 1 - call s:action_for(key, expand(abspath, 1)) + call s:action_for(key, abspath) else - call s:open(expand(abspath, 1)) + call s:open(abspath) endif call s:execute_tag_address(excmd) call add(qfl, {'filename': expand('%'), 'lnum': line('.'), 'text': getline('.')})