mirror of
https://github.com/neovim/neovim.git
synced 2026-07-31 12:49:11 +00:00
Problem: [security]: arbitrary code execution via keyword lookup in
sh.vim, zsh.vim and ps1.vim filetype plugin
(manus-use)
Solution: For powershell, quote the commands using single quotes, for
sh/zsh pass the argument as a separate list item to term_start()/system()
(Yasuhiro Matsumoto).
Github Security Advisory:
https://github.com/vim/vim/security/advisories/GHSA-r5v6-q6j8-8qw2
c5a82fe013
Co-authored-by: Yasuhiro Matsumoto <mattn.jp@gmail.com>
82 lines
2.7 KiB
VimL
82 lines
2.7 KiB
VimL
" Vim filetype plugin file
|
|
" Language: sh
|
|
" Maintainer: Doug Kearns <dougkearns@gmail.com>
|
|
" Previous Maintainer: Dan Sharp
|
|
" Contributor: Enno Nagel <ennonagel+vim@gmail.com>
|
|
" Eisuke Kawashima
|
|
" Last Change: 2024 Sep 19 by Vim Project (compiler shellcheck)
|
|
" 2024 Dec 29 by Vim Project (improve setting shellcheck compiler)
|
|
" 2025 Mar 09 by Vim Project (set b:match_skip)
|
|
" 2025 Jul 22 by phanium (use :hor term #17822)
|
|
" 2026 Jul 10 by Vim Project (pass K argument as a list, prevent shell injection)
|
|
|
|
if exists("b:did_ftplugin")
|
|
finish
|
|
endif
|
|
let b:did_ftplugin = 1
|
|
|
|
let s:save_cpo = &cpo
|
|
set cpo-=C
|
|
|
|
setlocal comments=b:#
|
|
setlocal commentstring=#\ %s
|
|
setlocal formatoptions-=t formatoptions+=croql
|
|
|
|
let b:undo_ftplugin = "setl com< cms< fo<"
|
|
|
|
" Shell: thanks to Johannes Zellner
|
|
if exists("loaded_matchit") && !exists("b:match_words")
|
|
let b:match_ignorecase = 0
|
|
let s:sol = '\%(;\s*\|^\s*\)\@<=' " start of line
|
|
let b:match_words =
|
|
\ s:sol .. 'if\>:' .. s:sol.'elif\>:' .. s:sol.'else\>:' .. s:sol .. 'fi\>,' ..
|
|
\ s:sol .. '\%(for\|while\)\>:' .. s:sol .. 'done\>,' ..
|
|
\ s:sol .. 'case\>:' .. s:sol .. 'esac\>'
|
|
unlet s:sol
|
|
let b:match_skip = "synIDattr(synID(line('.'),col('.'),0),'name') =~ 'shSnglCase'"
|
|
let b:undo_ftplugin ..= " | unlet! b:match_ignorecase b:match_words b:match_skip"
|
|
endif
|
|
|
|
if (has("gui_win32") || has("gui_gtk")) && !exists("b:browsefilter")
|
|
let b:browsefilter = "Bourne Shell Scripts (*.sh)\t*.sh\n" ..
|
|
\ "Korn Shell Scripts (*.ksh)\t*.ksh\n" ..
|
|
\ "Bash Shell Scripts (*.bash)\t*.bash\n"
|
|
if has("win32")
|
|
let b:browsefilter ..= "All Files (*.*)\t*\n"
|
|
else
|
|
let b:browsefilter ..= "All Files (*)\t*\n"
|
|
endif
|
|
let b:undo_ftplugin ..= " | unlet! b:browsefilter"
|
|
endif
|
|
|
|
let s:is_sh = get(b:, "is_sh", get(g:, "is_sh", 0))
|
|
let s:is_bash = get(b:, "is_bash", get(g:, "is_bash", 0))
|
|
let s:is_kornshell = get(b:, "is_kornshell", get(g:, "is_kornshell", 0))
|
|
|
|
if s:is_bash
|
|
if exists(':terminal') == 2
|
|
command! -buffer -nargs=1 ShKeywordPrg call term_start(['bash', '-c', 'help "$1" 2>/dev/null || man "$1"', '--', <q-args>])
|
|
else
|
|
command! -buffer -nargs=1 ShKeywordPrg echo system(['bash', '-c', 'help "$1" 2>/dev/null || MANPAGER= man "$1"', '--', <q-args>])
|
|
endif
|
|
setlocal keywordprg=:ShKeywordPrg
|
|
let b:undo_ftplugin ..= " | setl kp< | sil! delc -buffer ShKeywordPrg"
|
|
endif
|
|
|
|
if (s:is_sh || s:is_bash || s:is_kornshell) && executable('shellcheck')
|
|
if !exists('current_compiler')
|
|
compiler shellcheck
|
|
let b:undo_ftplugin ..= ' | compiler make'
|
|
endif
|
|
elseif s:is_bash
|
|
if !exists('current_compiler')
|
|
compiler bash
|
|
let b:undo_ftplugin ..= ' | compiler make'
|
|
endif
|
|
endif
|
|
|
|
let &cpo = s:save_cpo
|
|
unlet s:save_cpo s:is_sh s:is_bash s:is_kornshell
|
|
|
|
" vim: nowrap sw=2 sts=2 ts=8 noet:
|