Quote paths in commands run on the SSH server

Remote commands were built with f-strings, with paths either unquoted
or in double quotes. Paths with spaces broke ls and find, and $ or
backticks in a path were expanded by the server's shell. Quote every
path with shlex.quote.
This commit is contained in:
Fuxino
2026-10-08 20:22:35 +02:00
parent 8b30fefed3
commit baf5b07d23
+5 -5
View File
@@ -190,7 +190,7 @@ class Backup:
return 5 return 5
_, stdout, _ = self._ssh.exec_command( _, stdout, _ = self._ssh.exec_command(
f'if [ -d "{self.output}" ]; then echo "ok"; fi') f'if [ -d {shlex.quote(self.output)} ]; then echo "ok"; fi')
output = stdout.read().decode('utf-8').strip() output = stdout.read().decode('utf-8').strip()
@@ -229,7 +229,7 @@ class Backup:
assert self._ssh is not None assert self._ssh is not None
_, stdout, _ = self._ssh.exec_command( _, stdout, _ = self._ssh.exec_command(
f'ls {self.output}/simple_backup') f'ls {shlex.quote(self.output + "/simple_backup")}')
dirs = stdout.read().decode('utf-8').strip().split('\n') dirs = stdout.read().decode('utf-8').strip().split('\n')
@@ -247,10 +247,10 @@ class Backup:
for i in range(n_backup - self.keep): for i in range(n_backup - self.keep):
if self.remote_sudo: if self.remote_sudo:
_, _, stderr = self._ssh.exec_command( _, _, stderr = self._ssh.exec_command(
f'sudo rm -r "{self.output}/simple_backup/{dirs[i]}"') f'sudo rm -r {shlex.quote(f"{self.output}/simple_backup/{dirs[i]}")}')
else: else:
_, _, stderr = self._ssh.exec_command( _, _, stderr = self._ssh.exec_command(
f'rm -r "{self.output}/simple_backup/{dirs[i]}"') f'rm -r {shlex.quote(f"{self.output}/simple_backup/{dirs[i]}")}')
err = stderr.read().decode('utf-8').strip().split('\n')[0] err = stderr.read().decode('utf-8').strip().split('\n')[0]
@@ -304,7 +304,7 @@ class Backup:
sys.exit(5) sys.exit(5)
_, stdout, _ = self._ssh.exec_command( _, stdout, _ = self._ssh.exec_command(
f'find {self.output}/simple_backup/ -mindepth 1 -maxdepth 1 -type d | sort') f'find {shlex.quote(self.output + "/simple_backup/")} -mindepth 1 -maxdepth 1 -type d | sort')
output = stdout.read().decode('utf-8').strip().split('\n') output = stdout.read().decode('utf-8').strip().split('\n')
if output[-1] != '': if output[-1] != '':