Bug 64147 - apr_escape_shell() does not escape whitespace
Summary: apr_escape_shell() does not escape whitespace
Status: NEW
Alias: None
Product: APR
Classification: Unclassified
Component: APR (show other bugs)
Version: HEAD
Hardware: PC Linux
: P2 normal (vote)
Target Milestone: ---
Assignee: Apache Portable Runtime bugs mailinglist
Depends on:
Reported: 2020-02-16 19:13 UTC by James McCoy
Modified: 2020-02-16 19:13 UTC (History)
0 users


Note You need to log in before you can comment on or make changes to this bug.
Description James McCoy 2020-02-16 19:13:02 UTC
While trying to fix an issue in svn's invocation of an editor (https://lists.apache.org/thread.html/ra13cf8823fde4066b6b0bade0ce43dd0ee19e0a5be4082b786c3e0ff%40%3Ccommits.subversion.apache.org%3E), I ran across the fact that apr_escape_shell() doesn't escape spaces or tabs.  Given that whitespace is one of the most common problematic character classess in shell, I was a bit surprised by this.

Is this an oversight or intentional behavior?  There's not much guidance in the documentation about what is expected to be escaped.  I'm currently working around this by manually escaping whitespace after calling apr_pescape_shell(), but that seems suboptimal.