Through the environment it depended on WSLENV reaching a Windows vim.exe, and
the guard for that turned a missing address into a blank preview. An argument
always arrives. Doubling the quotes keeps it one ':execute' string, so the
sandbox still covers all of it.
Ex mode starts on the last line, so an empty $FZFVIM_EXCMD centered the preview
at the end of the file and said nothing. Quit with an error instead, which the
existing '|| exit' turns into a blank preview.
':sandbox' is a modifier and covers only the command up to the first '|', so an
address like '/pat/|!touch file' still ran the shell command as soon as an entry
was highlighted. ':execute' on a value taken from the environment keeps all of
it inside the sandbox, and takes the address out of the '-c' string as well.
:Helptags previews a plugin's doc/tags through the same script.
A preview runs as soon as an entry is highlighted, so a crafted tags file did
not even need to be selected to get a shell command out of
'vim -c "silent {excmd}"'.
The preview Vim starts with '-u NONE' and exits right after, so the sandbox
alone is enough there; nothing it still permits outlives the process.
- When computing the center line, 'exit' on failure instead of 'return'.
- Open vim in read-only mode to avoid a non-zero exit code if the file is
already opened.
Signed-off-by: Nicolas VINCENT <nico.vince@gmail.com>
The `tagpreview.sh` script is hardcoded to the `vim` binary. For users that only
have Neovim installed an error is displayed and no preview is rendered.
This change addresses this by falling back to the `nvim` binary if the `vim`
binary isn't present.