Skip to content

fix: quote script paths before handing them to a shell - #23

Merged
tas50 merged 1 commit into
mainfrom
quote-shell-paths
Aug 28, 2026
Merged

tas50 merged 1 commit into
mainfrom
quote-shell-paths

Conversation

@tas50

@tas50 tas50 commented Aug 28, 2026

Copy link
Copy Markdown
Member

fix: quote script paths before handing them to a shell

Each test script was run as bash #{file} with the path interpolated raw. That
path is rooted at BUSSER_ROOT, which the caller chooses and Test Kitchen places
under a user-controlled directory, so a space anywhere in it split the command
and bash was handed a fragment instead of the script.

The command is now built by command_for, which escapes the path. The specs
assert on Shellwords.split -- what a shell would actually see -- so they check
the property rather than the escaping syntax.

Each test script was run as `bash #{file}` with the path interpolated raw. That
path is rooted at BUSSER_ROOT, which the caller chooses and Test Kitchen places
under a user-controlled directory, so a space anywhere in it split the command
and bash was handed a fragment instead of the script.

The command is now built by `command_for`, which escapes the path. The specs
assert on `Shellwords.split` -- what a shell would actually see -- so they check
the property rather than the escaping syntax.

Signed-off-by: Tim Smith <tsmith84@proton.me>
@tas50
tas50 merged commit 3a3ecfc into main Aug 28, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant