mirror of
https://github.com/junegunn/fzf.git
synced 2026-10-11 15:49:20 +08:00
completion(zsh): use private mktemp dir for completion FIFO
FIFO path was predictable (${TMPDIR:-/tmp}/fzf-complete-fifo-$$) and
_fzf_feed_fifo ignored rm/mkfifo failures, so on a shared /tmp another
user could pre-create the path (symlink or FIFO) and have the victim's
redirect follow it.
Allocate the FIFO inside a per-invocation mktemp -d directory, check
mkfifo status, and clean up the directory instead of the bare path.
Reported-by: sb24CK (https://github.com/sb24CK)
This commit is contained in:
2 files changed
+7
-4
No files matched your search
@@ -13,6 +13,8 @@ CHANGELOG
|
||||
- On tmux 3.7, the window is still unzoomed, as tmux 3.7b crashes when a floating pane is created over a zoomed window
|
||||
- Security fixes
|
||||
- fzf-tmux no longer evaluates an attached layout size (e.g. `-l50`) via bash arithmetic, which could run commands or inject tmux flags (GHSA-w6x2-f5m4-xw82)
|
||||
- zsh completion now creates its FIFO in a private `mktemp -d` directory instead of a predictable `/tmp` path (GHSA-7rj6-7pqx-v7rm)
|
||||
- Reported by Sai Sreewathsa Kovalluri, Shon Babu, and Kannan K (Researchers) of Innspark Solutions
|
||||
|
||||
0.74.4
|
||||
------
|
||||
|
||||
@@ -215,7 +215,7 @@ _fzf_dir_completion() {
|
||||
|
||||
_fzf_feed_fifo() {
|
||||
command rm -f "$1"
|
||||
mkfifo "$1"
|
||||
command mkfifo "$1" || return
|
||||
cat <&0 > "$1" &|
|
||||
}
|
||||
|
||||
@@ -242,8 +242,9 @@ _fzf_complete() {
|
||||
rest=("$@")
|
||||
fi
|
||||
|
||||
local fifo lbuf matches post
|
||||
fifo="${TMPDIR:-/tmp}/fzf-complete-fifo-$$"
|
||||
local fifo fifo_dir lbuf matches post
|
||||
fifo_dir=$(command mktemp -d "${TMPDIR:-/tmp}/fzf-completion-XXXXXX") || return
|
||||
fifo="$fifo_dir/fifo"
|
||||
lbuf=${rest[0]}
|
||||
post="${funcstack[1]}_post"
|
||||
type $post > /dev/null 2>&1 || post=cat
|
||||
@@ -256,7 +257,7 @@ _fzf_complete() {
|
||||
if [ -n "$matches" ]; then
|
||||
LBUFFER="$lbuf$matches"
|
||||
fi
|
||||
command rm -f "$fifo"
|
||||
command rm -rf "$fifo_dir"
|
||||
}
|
||||
|
||||
# To use custom hostname lists, override __fzf_list_hosts.
|
||||
|
||||
Reference in new issue
Block a user