From 81ae642d5b3ab1d8165ae017203c1fce7cfe4cd4 Mon Sep 17 00:00:00 2001 From: Junegunn Choi Date: Mon, 28 Sep 2026 00:08:49 +0900 Subject: [PATCH] Keep the whole tag address inside the preview sandbox ':sandbox' is a modifier and covers only the command up to the first '|', so an address like '/pat/|!touch file' still ran the shell command as soon as an entry was highlighted. ':execute' on a value taken from the environment keeps all of it inside the sandbox, and takes the address out of the '-c' string as well. :Helptags previews a plugin's doc/tags through the same script. --- bin/tagpreview.sh | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/bin/tagpreview.sh b/bin/tagpreview.sh index 01bfa30..0be6687 100755 --- a/bin/tagpreview.sh +++ b/bin/tagpreview.sh @@ -30,12 +30,14 @@ else exit 1 fi -# The address comes from a tags file, which can be untrusted, and a preview -# runs as soon as an entry is highlighted. Sandboxed as a builtin tag jump is, -# so that it cannot run a shell command or touch a file -CENTER="$("${VIMNAME}" -R -i NONE -u NONE -e -m -s "${FILE}" \ +# The address comes from a tags file, which can be untrusted, and a preview runs +# as soon as an entry is highlighted. Sandboxed as a builtin tag jump is, so that +# it cannot run a shell command or touch a file. ':sandbox' on its own only +# covers the command up to the first '|', hence 'sandbox execute' on a value +# passed through the environment, which keeps the whole address inside +CENTER="$(FZFVIM_EXCMD="${EXCMD}" "${VIMNAME}" -R -i NONE -u NONE -e -m -s "${FILE}" \ -c "set nomagic" \ - -c "silent sandbox ${EXCMD}" \ + -c 'silent sandbox execute $FZFVIM_EXCMD' \ -c 'let l=line(".") | new | put =l | print | qa!')" || exit START_LINE="$(( CENTER - FZF_PREVIEW_LINES / 2 ))"