From baf5b07d23e8c68b06e758107c93d2bc43bcec50 Mon Sep 17 00:00:00 2001 From: Fuxino Date: Thu, 8 Oct 2026 20:22:35 +0200 Subject: [PATCH] Quote paths in commands run on the SSH server Remote commands were built with f-strings, with paths either unquoted or in double quotes. Paths with spaces broke ls and find, and $ or backticks in a path were expanded by the server's shell. Quote every path with shlex.quote. --- simple_backup/simple_backup.py | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/simple_backup/simple_backup.py b/simple_backup/simple_backup.py index f4d9431..7e99cc3 100755 --- a/simple_backup/simple_backup.py +++ b/simple_backup/simple_backup.py @@ -190,7 +190,7 @@ class Backup: return 5 _, stdout, _ = self._ssh.exec_command( - f'if [ -d "{self.output}" ]; then echo "ok"; fi') + f'if [ -d {shlex.quote(self.output)} ]; then echo "ok"; fi') output = stdout.read().decode('utf-8').strip() @@ -229,7 +229,7 @@ class Backup: assert self._ssh is not None _, stdout, _ = self._ssh.exec_command( - f'ls {self.output}/simple_backup') + f'ls {shlex.quote(self.output + "/simple_backup")}') dirs = stdout.read().decode('utf-8').strip().split('\n') @@ -247,10 +247,10 @@ class Backup: for i in range(n_backup - self.keep): if self.remote_sudo: _, _, stderr = self._ssh.exec_command( - f'sudo rm -r "{self.output}/simple_backup/{dirs[i]}"') + f'sudo rm -r {shlex.quote(f"{self.output}/simple_backup/{dirs[i]}")}') else: _, _, stderr = self._ssh.exec_command( - f'rm -r "{self.output}/simple_backup/{dirs[i]}"') + f'rm -r {shlex.quote(f"{self.output}/simple_backup/{dirs[i]}")}') err = stderr.read().decode('utf-8').strip().split('\n')[0] @@ -304,7 +304,7 @@ class Backup: sys.exit(5) _, stdout, _ = self._ssh.exec_command( - f'find {self.output}/simple_backup/ -mindepth 1 -maxdepth 1 -type d | sort') + f'find {shlex.quote(self.output + "/simple_backup/")} -mindepth 1 -maxdepth 1 -type d | sort') output = stdout.read().decode('utf-8').strip().split('\n') if output[-1] != '':