completion(zsh): use private mktemp dir for completion FIFO

FIFO path was predictable (${TMPDIR:-/tmp}/fzf-complete-fifo-$$) and
_fzf_feed_fifo ignored rm/mkfifo failures, so on a shared /tmp another
user could pre-create the path (symlink or FIFO) and have the victim's
redirect follow it.

Allocate the FIFO inside a per-invocation mktemp -d directory, check
mkfifo status, and clean up the directory instead of the bare path.

Reported-by: sb24CK (https://github.com/sb24CK)
This commit is contained in:
Junegunn Choi committed 2026-10-11 11:27:06 +09:00
1 parent f126ff2954
commit cbc11e4d95
2 files changed
+7 -4

No files matched your search

+2
View File
@@ -13,6 +13,8 @@ CHANGELOG
- On tmux 3.7, the window is still unzoomed, as tmux 3.7b crashes when a floating pane is created over a zoomed window
- Security fixes
- fzf-tmux no longer evaluates an attached layout size (e.g. `-l50`) via bash arithmetic, which could run commands or inject tmux flags (GHSA-w6x2-f5m4-xw82)
- zsh completion now creates its FIFO in a private `mktemp -d` directory instead of a predictable `/tmp` path (GHSA-7rj6-7pqx-v7rm)
- Reported by Sai Sreewathsa Kovalluri, Shon Babu, and Kannan K (Researchers) of Innspark Solutions
0.74.4
------
+5 -4
View File
@@ -215,7 +215,7 @@ _fzf_dir_completion() {
_fzf_feed_fifo() {
command rm -f "$1"
mkfifo "$1"
command mkfifo "$1" || return
cat <&0 > "$1" &|
}
@@ -242,8 +242,9 @@ _fzf_complete() {
rest=("$@")
fi
local fifo lbuf matches post
fifo="${TMPDIR:-/tmp}/fzf-complete-fifo-$$"
local fifo fifo_dir lbuf matches post
fifo_dir=$(command mktemp -d "${TMPDIR:-/tmp}/fzf-completion-XXXXXX") || return
fifo="$fifo_dir/fifo"
lbuf=${rest[0]}
post="${funcstack[1]}_post"
type $post > /dev/null 2>&1 || post=cat
@@ -256,7 +257,7 @@ _fzf_complete() {
if [ -n "$matches" ]; then
LBUFFER="$lbuf$matches"
fi
command rm -f "$fifo"
command rm -rf "$fifo_dir"
}
# To use custom hostname lists, override __fzf_list_hosts.