Quote paths in commands run on the SSH server
Remote commands were built with f-strings, with paths either unquoted or in double quotes. Paths with spaces broke ls and find, and $ or backticks in a path were expanded by the server's shell. Quote every path with shlex.quote.
This commit is contained in:
@@ -190,7 +190,7 @@ class Backup:
|
|||||||
return 5
|
return 5
|
||||||
|
|
||||||
_, stdout, _ = self._ssh.exec_command(
|
_, stdout, _ = self._ssh.exec_command(
|
||||||
f'if [ -d "{self.output}" ]; then echo "ok"; fi')
|
f'if [ -d {shlex.quote(self.output)} ]; then echo "ok"; fi')
|
||||||
|
|
||||||
output = stdout.read().decode('utf-8').strip()
|
output = stdout.read().decode('utf-8').strip()
|
||||||
|
|
||||||
@@ -229,7 +229,7 @@ class Backup:
|
|||||||
assert self._ssh is not None
|
assert self._ssh is not None
|
||||||
|
|
||||||
_, stdout, _ = self._ssh.exec_command(
|
_, stdout, _ = self._ssh.exec_command(
|
||||||
f'ls {self.output}/simple_backup')
|
f'ls {shlex.quote(self.output + "/simple_backup")}')
|
||||||
|
|
||||||
dirs = stdout.read().decode('utf-8').strip().split('\n')
|
dirs = stdout.read().decode('utf-8').strip().split('\n')
|
||||||
|
|
||||||
@@ -247,10 +247,10 @@ class Backup:
|
|||||||
for i in range(n_backup - self.keep):
|
for i in range(n_backup - self.keep):
|
||||||
if self.remote_sudo:
|
if self.remote_sudo:
|
||||||
_, _, stderr = self._ssh.exec_command(
|
_, _, stderr = self._ssh.exec_command(
|
||||||
f'sudo rm -r "{self.output}/simple_backup/{dirs[i]}"')
|
f'sudo rm -r {shlex.quote(f"{self.output}/simple_backup/{dirs[i]}")}')
|
||||||
else:
|
else:
|
||||||
_, _, stderr = self._ssh.exec_command(
|
_, _, stderr = self._ssh.exec_command(
|
||||||
f'rm -r "{self.output}/simple_backup/{dirs[i]}"')
|
f'rm -r {shlex.quote(f"{self.output}/simple_backup/{dirs[i]}")}')
|
||||||
|
|
||||||
err = stderr.read().decode('utf-8').strip().split('\n')[0]
|
err = stderr.read().decode('utf-8').strip().split('\n')[0]
|
||||||
|
|
||||||
@@ -304,7 +304,7 @@ class Backup:
|
|||||||
sys.exit(5)
|
sys.exit(5)
|
||||||
|
|
||||||
_, stdout, _ = self._ssh.exec_command(
|
_, stdout, _ = self._ssh.exec_command(
|
||||||
f'find {self.output}/simple_backup/ -mindepth 1 -maxdepth 1 -type d | sort')
|
f'find {shlex.quote(self.output + "/simple_backup/")} -mindepth 1 -maxdepth 1 -type d | sort')
|
||||||
output = stdout.read().decode('utf-8').strip().split('\n')
|
output = stdout.read().decode('utf-8').strip().split('\n')
|
||||||
|
|
||||||
if output[-1] != '':
|
if output[-1] != '':
|
||||||
|
|||||||
Reference in New Issue
Block a user