diff options
author | lolilolicon <lolilolicon@gmail.com> | 2014-09-08 00:57:31 +0800 |
---|---|---|
committer | Allan McRae <allan@archlinux.org> | 2014-09-15 09:32:29 +1000 |
commit | ee207d7c7b34ca54ad9bf65952eb1d567ef41ceb (patch) | |
tree | 2b49d25e3d66cafed53995c1d904990863ec8573 /lib/libalpm/rawstr.c | |
parent | 95e1a1ef8223dea2b8eb41e60428858b1c39f47f (diff) |
makepkg: do not eval dlcmd
This eval enables the following in a PKGBUILD to "just work":
source=('$pkgname-$pkgver.tar.gz'::'https://host/$pkgver.tar.gz')
This has at least two problems:
- It violated the principle of least surprise.
- It could be a security issue since URLs are arbitrary input.
Instead, expand the dlagent command line into an array, replace the %o,
%u place holders, and run the resultant command line as is.
Embedded spaces in the DLAGENTS entry can be escaped with a backslash.
Fixes FS#41682
Signed-off-by: Allan McRae <allan@archlinux.org>
Diffstat (limited to 'lib/libalpm/rawstr.c')
0 files changed, 0 insertions, 0 deletions