Commit Graph

11040 Commits

Author SHA1 Message Date
zeertzjq
db55c537cb vim-patch:9.2.0728: filetype: supertux info pattern is relative to current dir
Problem:  filetype: supertux info pattern is relative to current
          directory (after 9.2.0716).
Solution: Add `*/` to the start of the pattern (zeertzjq)

closes: vim/vim#20629

c30ee2efa9
2026-06-27 07:04:55 +08:00
zeertzjq
26331797d2 vim-patch:9.2.0716: filetype: not all supertux files are recognized
Problem:  filetype: not all supertux files are recognized
Solution: Detect more supertux related files as scheme filetype
          (Wu Zhenyu)

levels:
*.stwm: supertux world map
https://github.com/SuperTux/supertux/wiki/Worldmap-Format
*.stl: supertux level
https://github.com/SuperTux/supertux/wiki/Level-Format
*.stxt: supertux scrolling texts
https://github.com/SuperTux/supertux/wiki/File_formats#scrolling-texts

images:
*.sprite: supertux sprite
https://github.com/SuperTux/supertux/wiki/Sprite
*.strf: supertux tileset
https://github.com/SuperTux/supertux/wiki/Tileset
*.satc: supertux autotiles configuration
*.stcd: supertux converter data

font:
*.stf: supetux font

particles:
*.stcp: supertux custom particle

music:
*.music: supertux music

config:
~/.local/share/supertux2/config: supertux config
https://github.com/SuperTux/supertux/wiki/S-Expression#supertux-config-file
*.stsg: supertux save game

info:
info: https://github.com/SuperTux/supertux/wiki/File_formats#level-subsets

related: vim/vim#16287
closes:  vim/vim#20615

758543dcb7

Co-authored-by: Wu, Zhenyu <wuzhenyu@ustc.edu>
2026-06-27 07:04:54 +08:00
Justin M. Keyes
dda2216188 Merge #40434 from justinmk/fixcmdwin 2026-06-26 17:40:41 -04:00
jdrouhard
150088551e fix(lsp): define autocmds for capabilities once per buffer #40435
fix(lsp): define autocmds for capabilities in new(), not on_attach()

Problem: Defining autocmds in on_attach() caused issues when multiple
clients provide the same capability for a buffer. Each attaching client
would "replace" the previously defined one since they are all identical.
Then the first one to detach clears them out and any remaining attached
clients would no longer trigger the autocmd for the capability. Further,
the semantic tokens module itself didn't quite work with multiple
clients since any LspNotify (from any client) would send a token request
to all attached clients with no differentiation and the debounce timer
was shared across all clients.

Solution: Always define the buffer-local autocmds in the capability's
`new()` function, and don't mess with the autocmds in on_attach or
on_detach. The capability framework itself will clear the autocmds when
the last client detaches. Also, refactor a bit of the semantic tokens
module so that the various methods take a specific client_id to perform
the work on, and split out timers so each client has its own.
2026-06-26 15:19:42 -04:00
Justin M. Keyes
fe4983327b fix(cmdwin): set 'buflisted'
Problem:
Legacy cmdwin set 'buflisted', but new one doesn't.
https://github.com/neovim/neovim/issues/40431#issuecomment-4811593353

'buflisted' useful for:
- "bufferline" style tablines, they usually show only listed buffers.
- some automatic actions can be conditioned on whether a buffer is
  listed; 'buflisted' signals that the buffer is "important enough".

Solution:
Set 'buflisted'.
2026-06-26 21:18:14 +02:00
Justin M. Keyes
496af49bda fix(cmdwin): implement Enter/Ctrl-C as builtins
What echasnovski wants, echasnovski gets.
2026-06-26 21:18:14 +02:00
Justin M. Keyes
5675c11910 fix(cmdwin): space in cmdwin-char 'statuscolumn'
To match the old behavior, the cmdwin-char should not be followed by
a space char.
2026-06-26 21:04:10 +02:00
Justin M. Keyes
ac623bd417 fix(cmdwin): duplicate line in history
Problem:
After ctrl-f from the cmdline, the last 2 lines of cmdwin are redundant.

Solution:
In `open_cmdwin`, clear the live cmdline so that unwinding it (via
Ctrl_C) does not add it to history.
2026-06-26 21:04:10 +02:00
jdrouhard
c98c93fcf8 refactor(lsp): convert diagnostics to capability framework #40433
Problem:
Diagnostic tracking used a separate bufstates table and manual
LspDetach/LspNotify autocmd management via _enable()/_refresh(),
duplicating the lifecycle logic already provided by the Capability
framework. This caused inconsistencies in how client attach/detach and
buffer teardown were handled compared to other LSP features.

Solution:
Replace the ad-hoc bufstate tracking and _enable/_refresh pattern in
vim.lsp.diagnostic with a proper Diagnostics subclass of Capability.
This cleans up a few random places in the main lsp module and client
module that were poking the diagnostics. It also fixes some pre-existing
bugs and inconsistencies that were discovered:

- Refresh diagnostics immediately on attach instead of lazily by the
  first didOpen/didChange notification
- Fix Capability.active lookup in M.enable() to key by it_bufnr instead
  of the filter bufnr
- Set lsp defaults before calling the _text_document_did_open_handler in
  Client:on_attach() so defaults are there before any lsp notification
  occurs
- Log (and return early) on any error from a diagnostic request result
  instead of only returning early for server cancelled errors
2026-06-26 14:41:26 -04:00
Barrett Ruth
85718f9874 fix(lsp): use root_dir as cmd CWD #40331
Problem:
cmd given as string[] always starts using Nvim's CWD, which is arbitrary.

Solution:
If cmd_cwd is not given, use root_dir as CWD.

BREAKING CHANGE: LSP commands given as string arrays now use `root_dir` as
the process working directory when `cmd_cwd` is unset.

Co-authored-by: Justin M. Keyes <justinkz@gmail.com>
2026-06-26 14:12:33 -04:00
Barrett Ruth
6576e75eeb feat(dir.lua): global "-" default mapping #40426 2026-06-26 06:17:00 -04:00
Barrett Ruth
b9b1992d9d docs(runtime): directory filetype #40424 2026-06-25 19:05:44 -04:00
Barrett Ruth
bf917a503a feat(runtime): replace netrw with a very small script #39723
Problem:
`:edit <dir>` and `nvim <dir>` currently rely on netrw to show local directory
contents.

Solution:
- Provide `filetype=directory`.
- Introduce dir.lua, a small plugin that provides directory listing, opening
  items, parent navigation, and refresh.
- `netrw` remains available for `:Explore`, remote paths, archives, and file
  operations. To continue 

Co-authored-by: Justin M. Keyes <justinkz@gmail.com>
2026-06-25 17:31:18 -04:00
Justin M. Keyes
dd5ebae7ac Merge #40325 from justinmk/cmdwin 2026-06-25 13:06:01 -04:00
Justin M. Keyes
5ddb4b672e fix(ui2): "msg_history_show" error while in cmdwin
Problem:
Executing :messages while in cmdwin fails:

    Error in "msg_history_show" UI event handler (ns=nvim.ui2):
    Lua: …/_core/ui2/messages.lua:699: Invalid 'height': expected positive Integer
    stack traceback:
    [C]: in function 'nvim_win_set_config'
    …/_core/ui2/messages.lua:699: in function 'set_pos'
    …/_core/ui2/messages.lua:329: in function 'set_target_pos'
    …/_core/ui2/messages.lua:389: in function 'show_msg'
    …/_core/ui2/messages.lua:553: in function 'handler'
    …/_core/ui2.lua:161: in function 'ui_callback'
    …/_core/ui2.lua:210: in function <…/_core/ui2.lua:202>

The bug: when `texth.all` is small (e.g. 0 from a hidden pager whose new
content isn't laid out yet), or when the available height after
subtracting the cmdwin is small, `math.min(min, …)` can yield 0, and
`nvim_win_set_config` rejects `height=0`.

Solution:
Floor at 1.
2026-06-25 18:36:24 +02:00
Justin M. Keyes
b2bf7bcfb1 feat(cmdwin): implement cmdwin as a normal buf+win
Problem:

cmdwin (the `:q` cmdline buffer) has various limitations which require
special-casing all over the codebase.

Besides complicating the code, it also breaks async plugins if they try
to create buffers/windows after some work is done, if the user happens
to open cmdwin at the wrong the moment:

    Lua callback: …/guh.nvim/lua/guh/util.lua:531:
    E11: Invalid in command-line window; <CR> executes, CTRL-C quits
    stack traceback:
        [C]: in function 'nvim_buf_delete'
        …/guh.nvim/lua/guh/util.lua:531: in function <…/guh.nvim/lua/guh/util.lua:526>

Solution:

Just say no to "inception". Reimplement cmdwin as a normal buffer+window.

All of the cmdwin contortions (in both core, and innocent plugins) exist
literally only to support "inception": recursive
cmdwin-in-cmdline-things, like `<c-r>=`, `/`, search-during-substitute,
`:input()`, etc. So we just won't support that (though I have
a potential plan for that later, which I call "modal parking lot").

The benefit is that plugins, and core, no longer have to care about
cmdwin.

BONUS:
- mouse-drag on vertical separators works (it only worked for
  horizontal/statusline before)
- inccommand-in-cmdwin now works correctly, for free (thus don't need
  #40077).

POTENTIAL FOLLOWUPS
- Drop `CHECK_CMDWIN` ("E11: Invalid in command-line window"), allow chaos.
- Unify `BUFLOCK_OK` / `LOCK_OK` ?

DESIGN:
- Eliminate lots of C globals, `EX_CMDWIN`, etc.
- `text_locked()` no longer reports true for cmdwin.
- cmdwin = a normal window with 'winfixbuf', 'bufhidden=wipe',
  'buftype=nofile'. Invariants come from those options rather than
  special cases throughout the codebase.
- `nv_record` for q:/q//q? calls Lua
  `nlua_call_vimfn("vim._core.cmdwin", …)`. No `K_CMDWIN`
  / cmdline-reader detour.
- `cedit_key` (`c_CTRL-F`) schedules a deferred event that calls
  `vim._core.cmdwin.open(type, content, pos)` and returns `Ctrl_C` so
  the in-flight cmdline cancels. Reader state is not serialized; instead
  the captured `(type, line, col)` is replayed via
  `nvim_feedkeys(type..line.."<CR>", "nt", …)` after user confirms.
- On confirm/cancel: `<CR>` / `<C-C>` calls into Lua which closes the
  window and re-feeds the cmdline.

BREAKING CHANGES:
- Expression-register cmdline (`<C-R>=` from insert-mode) no longer
  supports cmdwin. Same applies to `input()` / `inputlist()` (already
  covered by `text_locked`).
- Usage of cmdwin in macros/mappings will probably break (assuming they
  ever worked).
2026-06-25 18:36:24 +02:00
Dmytro Meleshko
bcfc2037ef perf(treesitter): reduce memory usage of _select.lua #40409
Problem:  The table `history` in treesitter/_select.lua stores references
          to previously selected TSNodes, but a TSNode needs to keep its
          whole TSTree alive in memory, which may be kept alive even
          after closing the buffer to which this history corresponds.

Solution: Store just the bits of information from the TSNode we need to
          go back in selection history (the range and ID), without
          referencing the TSNode itself.
2026-06-25 11:46:26 -04:00
Dmytro Meleshko
9afa8477b3 fix(treesitter): incremental selection causes beeps when the bell is enabled #40414
Problem:  The function visual_select() in treesitter/_select.lua is
          executing `:normal! v<Esc>` to ensure that `gv` later goes
          back to character Visual mode, but doing so when mode() is
          already `v` first switches back to the Normal mode, then
          executes <Esc>, which causes a beep.
Solution: Check if the mode() is already `v` and avoid any switching in
          that case.
2026-06-25 11:36:24 -04:00
Barrett Ruth
4d9e5acfb5 fix(lsp): skip invalid file watcher globs #40376 #40396
Some servers register `workspace/didChangeWatchedFiles` watchers for URI
schemes that cannot be watched locally. Skipping the unsupported glob
and keep the rest of the registration batch active.
2026-06-25 03:44:33 -04:00
jdrouhard
3c924d13fe fix(lsp): fire LspNotify didChange autocmds after undo/redo #40404
Problem: LspNotify autocmds were not being triggered for didChange
requests when being used during undo/redo (and possibly other) actions.
autocmds are blocked when calling on_lines() callbacks while doing the
undo/redo action.

Solution: Defer firing the autocmd until after the action is complete.
This is closer to what existed before, but now there's a check in the
deferred function to only fire the autocmd if the client is still
active and the buffer is still attached, if applicable.
2026-06-25 03:37:39 -04:00
Barrett Ruth
8bf7fc810a fix(tty): filter terminal probes by channel #40356
Problem:
Terminal probes sent with `nvim_ui_send()` can reach more than one stdout TTY
UI. Probes with a known TTY UI owner should not accept `TermResponse`s from
unrelated UI channels. 

Solution:
Thread the existing `chan` filter through owned terminal probes. This covers
startup/attach background detection, fallback truecolor detection, and
`vim.tty.query()` forwarding opts to `vim.tty.request()`.

Note: Not every terminal escape path is updated here. I only passed `chan` when
the caller already knows which TTY UI owns the probe. For example, this does
not include:
- (Followup) OSC 52 (system clipboard) detection. It needs to capture the
  `UIEnter` channel. Adding `{ chan = ... }` only to the nested query would be
  half a fix.
- OSC 52 _paste_ is left global because the provider callback does not have
  a UI channel (paste is invoked without a ui channel/tty ui object).
2026-06-24 10:40:36 -04:00
zeertzjq
c7f83f90ed vim-patch:8dfde7b: runtime(dnsmasq): add new keywords and order existing keywords alphabetically (#40385)
closes: vim/vim#20616

8dfde7b336

Co-authored-by: Pooyan Khanjankhani <pooyankhan@gmail.com>
2026-06-24 07:45:11 +08:00
Justin M. Keyes
8e3b216d0b docs: bufadd(), fnameescape() guidance #40378 2026-06-23 10:08:50 -04:00
Barrett Ruth
db30608058 fix(tui): attribute TermResponse to source channel #40330
Problem: Attach-time terminal probes cannot distinguish responses from
different attached UIs.

Solution: Identify the UI by RPC channel id in `TermResponse` and make
`vim.tty.request()` filter responses by channel.
2026-06-23 06:19:56 -04:00
zeertzjq
8832c381e1 vim-patch:9.2.0705: :delete # silently fails to update "# and clobbers "0 (#40371)
Problem:  ':delete #' silently fails to update "# and clobbers "0.
Solution: Treat "# like "/, writable only with :let and setreg().

closes: vim/vim#20592

7aeab74687

Co-authored-by: Doug Kearns <dougkearns@gmail.com>
2026-06-23 00:52:39 +00:00
zeertzjq
59a5e320da vim-patch:4ed61e0: runtime(dtrace): handle DTrace probe highlighting before action blocks
Recognize DTrace probe descriptions that are followed immediately by an
action block, such as:

    BEGIN{ trace(1); }
    syscall::open:entry{ trace(1); }

The fourth probe field now consumes the remaining non-whitespace text, and
the lookahead allows zero or more whitespace before the following token.

closes: vim/vim#20560

4ed61e0a19

Co-authored-by: Vladimír Marek <vlmarek13@gmail.com>
2026-06-23 06:51:48 +08:00
zeertzjq
8532fc2021 vim-patch:fc6d0d4: runtime(beancount): Add support for non-ASCII account names
closes: vim/vim#20597

fc6d0d418d

Co-authored-by: 依云 <lilydjwg@gmail.com>
2026-06-23 06:51:33 +08:00
zeertzjq
b595654c39 vim-patch:8c670b3: runtime(fennel): Update Last Update header
forgotten from commit 8513982a5ed5a84ba8e4e532505b07b4fa1efbdb

8c670b3a51

Co-authored-by: Christian Brabandt <cb@256bit.org>
2026-06-23 06:50:12 +08:00
zeertzjq
8f98882c11 vim-patch:8513982: runtime(fennel): add more ";" comment leaders to 'comments'
closes: vim/vim#20579

8513982a5e

Co-authored-by: yilisharcs <yilisharcs@gmail.com>
2026-06-23 06:49:13 +08:00
Luuk van Baal
e542b42903 fix(ui2): message before empty prompt not shown
Problem:  Message before empty input() is not visible.
Solution: Route to dialog window with active prompt (hl_id >= 0).
2026-06-22 15:56:26 +02:00
Luuk van Baal
d16bd456a8 fix(cmdline): encode no prompt in cmdline_show.hl_id
Problem:  Unable to distinguish an empty prompt from no prompt in
          cmdline_show event.
Solution: Set cmdline_show.hl_id to -1 when no prompt is active.
2026-06-22 15:56:26 +02:00
Luuk van Baal
60a46036c0 fix(ui2): clear search_count after clearing the screen
Problem:  Clearing the screen doesn't clear the "last" virtual text.
          Dupe counter virtual text is not increased beyond 1.
Solution: Clear "last" virtual text when clearing the screen.
          Restore assignment lost in a previous commit.
2026-06-22 15:14:53 +02:00
zeertzjq
7d0adc08f7 vim-patch:9.2.0699: [security]: possible code execution with python complete (#40363)
Problem:  [security]: possible code execution with python complete
          (morningbread)
Solution: Use repr() to quote the doc strings correctly

Github Security Advisory:
https://github.com/vim/vim/security/advisories/GHSA-ppj8-wqjf-6fp3

Supported by AI

cce141c427

Co-authored-by: Christian Brabandt <cb@256bit.org>
2026-06-22 02:26:37 +00:00
zeertzjq
e59684318e vim-patch:f83e00b: runtime(xslt,xsd): speed up highlighting by optimizing lookbehinds in patterns
Move ownership to chrisbra/vim-xml-ftplugin

closes: vim/vim#20436

f83e00b7f8

Co-authored-by: Dmytro Meleshko <dmytro.meleshko@gmail.com>
2026-06-22 09:51:52 +08:00
zeertzjq
19446ec9cb vim-patch:77099ed: runtime(cpp): add C++26 lexical constructs to syntax highlighting
Add a guarded "C++ 26 extensions" block (cpp_no_cpp26) covering new
lexical surface introduced since C++23:

- [[ ... ]] attributes as a region, so P3394 annotations carrying a
  value expression (eg [[=foo{1}]]) no longer trip cErrInBracket on
  their braces/parens. A \w\@1<! look-behind keeps it from matching a
  subscripted immediately-invoked lambda (arr[[]{...}()]).
- ^^ reflection operator (P2996).
- [: :] splice brackets (P2996).
- contract_assert keyword (P2900).

Add input/cpp_cpp26.cpp exercising these constructs with screendumps,
and update dumps/cpp_noreturn_00.dump for the new [[ ]] attribute
delimiter highlighting.

closes: vim/vim#20577

77099ed6b3

Co-authored-by: Gareth Lloyd <gareth@ignition-web.co.uk>
2026-06-22 09:51:52 +08:00
zeertzjq
131f9f73ac vim-patch:98bf999: runtime(lua): Update ftplugin, fix matchit block comment pattern (#40349)
Include the unecessary but idiomatic leading '--' in the closing block
comment token.

E.g.,
	--[[
	 ...
	--]]

closes: vim/vim#20590

98bf999d58

Co-authored-by: Doug Kearns <dougkearns@gmail.com>
2026-06-21 13:40:03 +00:00
zeertzjq
a1a1977c70 vim-patch:4e6e1fc: runtime(algol68): Update syntax, support size prefixes in denotations (#40344)
Explicitly match the LONG/SHORT size prefixes in integral, real and bits
denotations.

LONG/SHORT are matched as part of the denotation rather than as a mode.

closes: vim/vim#20512

4e6e1fc5ea

Co-authored-by: Doug Kearns <dougkearns@gmail.com>
2026-06-21 08:12:45 +08:00
zeertzjq
9a5944cdc0 vim-patch:9.2.0678: [security]: potential powershell code execution in zip.vim (#40343)
Problem:  [security]: potential powershell code execution in zip.vim
          (DDugs)
Solution: Cleanup zip.vim, introduce PSEscape() to escape() potential powershell code,
          use consistent s:Escape() in the various PowerShell functions

Github Security Advisory:
https://github.com/vim/vim/security/advisories/GHSA-x5fg-h5w9-9frf

b2cc9be119

Co-authored-by: Christian Brabandt <cb@256bit.org>
2026-06-21 08:12:27 +08:00
Barrett Ruth
74f163c67d fix(defaults): detect 'background'/'termguicolors' on UI attach #40175
Problem:  Terminal background and truecolor detection runs only at startup,
          gated on a UI being attached. A headless server has no UI then, so
          `'background'` and `'termguicolors'` are never detected and remote
          UIs ignore the terminal's theme.
Solution: Also (re)detect on UIEnter. The most recently attached terminal
          wins; an explicit user value is preserved.
2026-06-20 20:09:34 -04:00
Justin M. Keyes
07f02ae8de test: cleanup mksession_spec 2026-06-20 19:55:29 +02:00
Justin M. Keyes
9caef3a2f4 fix(health): check more "old" files 2026-06-20 19:55:29 +02:00
luukvbaal
9618032936 perf(ui2): accumulate message lines #40338
Problem:  Writing a message with a large number of newlines
          (:echo "foo\n"->repeat(1000000)) takes longer than it has to
          (since c973c7ae).
Solution: Accumulate newlines in a single API call when possible.
2026-06-20 13:01:58 -04:00
jdrouhard
54188fa242 fix(lsp): make LspNotify more robust #40332
Problem: LspNotify never passed a buffer when executing the autocmds, so
buffer-local LspNotify autocmd subscriptions didn't have the correct buf
in the event metadata. It was also wrapped in a schedule() so the actual
autocmd was delayed until after the event loop.

This could result in the wrong buffer receiving the notification if
multiple LspNotify autocmds with buffer filters were added. Only the
"latest" one would actually receive non-buffer-filtered autocmds, not
the matching one. It also caused listeners to receive the notification
"out of sync" with when the notification is actually sent. If a buffer
is being deleted (which fires a textDocument/didClose notification), the
notification is scheduled and fired after the buffer is already gone.

Solution: For LSP notifications that pertain to a particular buffer, set
it when executing the LspNotify autocmds so the callback functions that
are filtered on that buffer will get the correct notifications and the
metadata buf field will be correct. Additionally, there is no need to
wrap the LspNotify callback in vim.schedule when it can be called inline
when the notification to the rpc server is fired.

This is tested by removing now-unnecessary autocmds from semantic tokens
(InsertEnter and BufWinEnter should no longer be necessary now that
requests are fired by LspNotify). Without this fix, simply modifying a
buffer doesn't actually trigger LspNotify correctly, and the test for
that fails.
2026-06-20 12:46:58 -04:00
jdrouhard
6bc6461eac fix(lsp): multiline semantic token processing #40339
Problem: When multiline semantic token support was introduced, the loop
that finds the end line for a particular token didn't sanitize the token
length sent back by the LSP server. If the server returned an overflowed
length (near uint32 max), neovim would burn cpu and loop for an
extremely long time while trying to find the "end line" represented by
the massively large token, causing neovim to seemingly hang.

Solution: Stop looping once the calculated end_line reaches the actual
last line of the buffer.

Fixes #36257
2026-06-20 10:51:21 -04:00
luukvbaal
69160854c5 feat(column): per row click handlers for 'statuscolumn' (#40265)
Problem:
- Current 'statuscolumn' click label caveat is restrictive.
- v:virtnum is not unique to a line if it has both above and
  below virtual lines.
- 'statuscolumn' click handler may expect v:virt/lnum to be set.

Solution:
- Store per-row click definitions for the statuscolumn in a
  (nested line/virt number) map.
- Implement strategy that gives each 'statuscolumn' row a unique
  v:virtnum.
- Set v:virt/lnum when determining which line is clicked.
2026-06-20 15:59:08 +02:00
jdrouhard
b5181300ae refactor(lsp): refactor linked_editing_range to use vim.lsp._capability (#40327)
Problem: linked_editing_range was still doing most of the capability
boilerplate itself.

Solution: refactor it to make use of the common Capability framework for
handling enabling, disabling, etc.
2026-06-19 10:42:14 -07:00
zeertzjq
1e30f5d242 fix(:checkhealth): open after current tabpage (#40319) 2026-06-19 17:45:21 +08:00
zeertzjq
cb33b05ba3 vim-patch:8181c6e: runtime(luau): runtime support is incomplete
Problem:  runtime(luau): runtime support is incomplete.
Solution: Add Luau syntax, indent, filetype plugin and indent tests.

closes: vim/vim#20544

8181c6e313

Co-authored-by: Lopy <70210066+lopi-py@users.noreply.github.com>
2026-06-19 09:45:06 +08:00
zeertzjq
3e851d407e vim-patch:b0ce576: runtime(tar): fix lz4 extraction on non-Linux systems
Patch 9.2.0306 fixed malformed lz4 extraction commands by using "tar -I lz4"
on Linux and leaving non-Linux tar implementations to auto-detect lz4 input.
That still fails on systems where tar does not support either -I lz4 or
automatic lz4 decompression, such as Solaris /usr/bin/tar.

Keep the existing Linux path using GNU tar's "-I lz4" support.  For non-Linux
systems, use lz4 explicitly to decompress the archive to stdout and feed the
resulting tar stream to the configured tar extraction command.  This is the
same style tar.vim already used for lz4 archives before patch 9.2.0306.

Follow-up for vim/vim#19925

closes: vim/vim#20555

b0ce576fbc

Co-authored-by: Vladimír Marek <vlmarek13@gmail.com>
2026-06-19 09:44:07 +08:00
zeertzjq
025a3e2baf vim-patch:9.2.0479: [security]: runtime(tar): command injection in tar plugin
Problem:  [security]: runtime(tar): command injection in tar plugin
          (Christopher Lusk)
Solution: Use the correct shellescape(args, 1) form for a :! command

Github Advisory:
https://github.com/vim/vim/security/advisories/GHSA-2fpv-9ff7-xg5w

3fb5e58fbc

Co-authored-by: Christian Brabandt <cb@256bit.org>
2026-06-19 09:43:55 +08:00