diff --git a/bin/tagpreview.sh b/bin/tagpreview.sh index 852515b..2890a04 100755 --- a/bin/tagpreview.sh +++ b/bin/tagpreview.sh @@ -32,22 +32,15 @@ fi # The address comes from a tags file, which can be untrusted, and a preview runs # as soon as an entry is highlighted. Sandboxed as a builtin tag jump is, so that -# it cannot run a shell command or touch a file. ':sandbox' on its own only -# covers the command up to the first '|', hence 'sandbox execute' on a value -# passed through the environment, which keeps the whole address inside -export FZFVIM_EXCMD="${EXCMD}" -# WSL shares only the variables named in WSLENV with a Windows vim.exe -export WSLENV="FZFVIM_EXCMD/w${WSLENV:+:${WSLENV}}" -# Ex mode starts on the last line, so an address that did not reach Vim would -# center the preview there rather than say anything. Show nothing instead -REQUIRE_EXCMD="" -if [ -n "${EXCMD}" ]; then - REQUIRE_EXCMD='if empty($FZFVIM_EXCMD) | cquit | endif' -fi +# it cannot run a shell command or touch a file. ':sandbox' on its own only covers +# the command up to the first '|', so hand the whole address to ':execute' as a +# string literal, doubling the quotes in it. A newline would end that line and +# leave the rest outside the sandbox, and no tags file holds one, so drop them +EXCMD=${EXCMD//$'\n'/ } +EXCMD_LITERAL=${EXCMD//\'/\'\'} CENTER="$("${VIMNAME}" -R -i NONE -u NONE -e -m -s "${FILE}" \ -c "set nomagic" \ - -c "${REQUIRE_EXCMD}" \ - -c 'silent sandbox execute $FZFVIM_EXCMD' \ + -c "silent sandbox execute '${EXCMD_LITERAL}'" \ -c 'let l=line(".") | new | put =l | print | qa!')" || exit START_LINE="$(( CENTER - FZF_PREVIEW_LINES / 2 ))"