mirror of
https://github.com/junegunn/fzf.vim.git
synced 2026-09-28 06:32:21 +08:00
Do not run arbitrary Ex commands from tag addresses
A tags file can come from an untrusted source, and its address field can hold any Ex command, which :Tags, :BTags and their CTRL-O Show callback ran as is. - Take only a line number or a search pattern, chained with ';' for '--excmd=combine' and cut at the ';"' terminator as Vim's find_extra() does. A pattern left unterminated runs to the end of the line, taking any '|' or ';' with it, so it cannot chain a command - Run the address in a sandbox, as builtin tag jumps do since Vim 6.0 Close #1626
This commit is contained in:
+26
-6
@@ -534,6 +534,26 @@ function! s:execute_silent(cmd)
|
||||
silent keepjumps keepalt execute a:cmd
|
||||
endfunction
|
||||
|
||||
" A tag address can be any Ex command, and a tags file can come from an
|
||||
" untrusted source, so run it in a sandbox as a builtin tag jump does
|
||||
function! s:execute_tag_address(excmd)
|
||||
silent keepjumps keepalt sandbox execute a:excmd
|
||||
endfunction
|
||||
|
||||
" Address of a tag, given the rest of the line after the file name. Only the
|
||||
" forms a tags file is meant to hold, a line number and a search pattern,
|
||||
" chained with ';' for '--excmd=combine' and cut at the ';"' terminator as
|
||||
" Vim's find_extra() does. A pattern left unterminated runs to the end of the
|
||||
" line, taking any '|' or ';' with it, so it cannot chain a command. Returns
|
||||
" an empty string for anything else, which is then not run.
|
||||
let s:tag_address_part = '\%(\d\+\|/\%(\\.\|[^/\\]\)*/\|?\%(\\.\|[^?\\]\)*?\)'
|
||||
let s:tag_address_open = '\%(/\%(\\.\|[^/\\]\)*\|?\%(\\.\|[^?\\]\)*\)'
|
||||
function! s:tag_address(rest)
|
||||
let address = matchstr(a:rest,
|
||||
\ '^'.s:tag_address_part.'\%(;'.s:tag_address_part.'\)*\ze\%(;"\|$\)')
|
||||
return empty(address) ? matchstr(a:rest, '^'.s:tag_address_open.'$') : address
|
||||
endfunction
|
||||
|
||||
" [key, [filename, [stay_on_edit: 0]]]
|
||||
function! s:action_for(key, ...)
|
||||
let Cmd = get(get(g:, 'fzf_action', s:default_action), a:key, '')
|
||||
@@ -729,7 +749,7 @@ function! s:goto_entry(winid, bufnr, dir, kind, entry) abort
|
||||
if len(parts) < 3
|
||||
return
|
||||
endif
|
||||
let excmd = matchstr(join(parts[2:-2], '')[:-2], '^.\{-}\ze;\?"\t')
|
||||
let excmd = s:tag_address(join(parts[2:-2], '')[:-2])
|
||||
let relpath = parts[1][:-2]
|
||||
let path = relpath =~ (s:is_win ? '^[A-Z]:\' : '^/')
|
||||
\ ? relpath : join([fnamemodify(parts[-1], ':h'), relpath], '/')
|
||||
@@ -738,14 +758,14 @@ function! s:goto_entry(winid, bufnr, dir, kind, entry) abort
|
||||
return
|
||||
endif
|
||||
let cmds = s:edit_cmds(a:winid, path)
|
||||
\ + ['keepjumps '.excmd, 'normal! ^zvzz']
|
||||
\ + ['sandbox keepjumps '.excmd, 'normal! ^zvzz']
|
||||
elseif a:kind ==# 'btags'
|
||||
let parts = split(entry, "\t")
|
||||
if len(parts) < 3 || !bufexists(a:bufnr)
|
||||
return
|
||||
endif
|
||||
let cmds = ['keepalt keepjumps hide buffer '.a:bufnr,
|
||||
\ 'keepjumps '.parts[2], 'normal! zvzz']
|
||||
\ 'sandbox keepjumps '.parts[2], 'normal! zvzz']
|
||||
elseif a:kind ==# 'marks'
|
||||
" A lowercase mark is local to the buffer the run started on
|
||||
let mark = matchstr(entry, '^\s*\zs\S')
|
||||
@@ -1654,7 +1674,7 @@ function! s:btags_sink(from, lines)
|
||||
let qfl = []
|
||||
for line in a:lines[1:]
|
||||
let parts = split(line, "\t")
|
||||
call s:execute_silent(parts[2])
|
||||
call s:execute_tag_address(parts[2])
|
||||
call add(qfl, {'filename': expand('%'), 'lnum': line('.'), 'text': getline('.')})
|
||||
if empty(tagname)
|
||||
let tagname = s:strip(parts[0])
|
||||
@@ -1724,7 +1744,7 @@ function! s:tags_sink(from, lines)
|
||||
for line in list
|
||||
try
|
||||
let parts = split(line, '\t\zs')
|
||||
let excmd = matchstr(join(parts[2:-2], '')[:-2], '^.\{-}\ze;\?"\t')
|
||||
let excmd = s:tag_address(join(parts[2:-2], '')[:-2])
|
||||
let base = fnamemodify(parts[-1], ':h')
|
||||
let relpath = parts[1][:-2]
|
||||
let abspath = relpath =~ (s:is_win ? '^[A-Z]:\' : '^/') ? relpath : join([base, relpath], '/')
|
||||
@@ -1734,7 +1754,7 @@ function! s:tags_sink(from, lines)
|
||||
else
|
||||
call s:open(expand(abspath, 1))
|
||||
endif
|
||||
call s:execute_silent(excmd)
|
||||
call s:execute_tag_address(excmd)
|
||||
call add(qfl, {'filename': expand('%'), 'lnum': line('.'), 'text': getline('.')})
|
||||
if empty(tagname)
|
||||
let tagname = s:strip(parts[0])
|
||||
|
||||
Reference in New Issue
Block a user