diff --git a/bin/tagpreview.sh b/bin/tagpreview.sh index 01bfa30..0be6687 100755 --- a/bin/tagpreview.sh +++ b/bin/tagpreview.sh @@ -30,12 +30,14 @@ else exit 1 fi -# The address comes from a tags file, which can be untrusted, and a preview -# runs as soon as an entry is highlighted. Sandboxed as a builtin tag jump is, -# so that it cannot run a shell command or touch a file -CENTER="$("${VIMNAME}" -R -i NONE -u NONE -e -m -s "${FILE}" \ +# The address comes from a tags file, which can be untrusted, and a preview runs +# as soon as an entry is highlighted. Sandboxed as a builtin tag jump is, so that +# it cannot run a shell command or touch a file. ':sandbox' on its own only +# covers the command up to the first '|', hence 'sandbox execute' on a value +# passed through the environment, which keeps the whole address inside +CENTER="$(FZFVIM_EXCMD="${EXCMD}" "${VIMNAME}" -R -i NONE -u NONE -e -m -s "${FILE}" \ -c "set nomagic" \ - -c "silent sandbox ${EXCMD}" \ + -c 'silent sandbox execute $FZFVIM_EXCMD' \ -c 'let l=line(".") | new | put =l | print | qa!')" || exit START_LINE="$(( CENTER - FZF_PREVIEW_LINES / 2 ))"