Quote paths in commands run on the SSH server
Remote commands were built with f-strings, with paths either unquoted or in double quotes. Paths with spaces broke ls and find, and $ or backticks in a path were expanded by the server's shell. Quote every path with shlex.quote.
This commit is contained in:
@@ -190,7 +190,7 @@ class Backup:
|
||||
return 5
|
||||
|
||||
_, stdout, _ = self._ssh.exec_command(
|
||||
f'if [ -d "{self.output}" ]; then echo "ok"; fi')
|
||||
f'if [ -d {shlex.quote(self.output)} ]; then echo "ok"; fi')
|
||||
|
||||
output = stdout.read().decode('utf-8').strip()
|
||||
|
||||
@@ -229,7 +229,7 @@ class Backup:
|
||||
assert self._ssh is not None
|
||||
|
||||
_, stdout, _ = self._ssh.exec_command(
|
||||
f'ls {self.output}/simple_backup')
|
||||
f'ls {shlex.quote(self.output + "/simple_backup")}')
|
||||
|
||||
dirs = stdout.read().decode('utf-8').strip().split('\n')
|
||||
|
||||
@@ -247,10 +247,10 @@ class Backup:
|
||||
for i in range(n_backup - self.keep):
|
||||
if self.remote_sudo:
|
||||
_, _, stderr = self._ssh.exec_command(
|
||||
f'sudo rm -r "{self.output}/simple_backup/{dirs[i]}"')
|
||||
f'sudo rm -r {shlex.quote(f"{self.output}/simple_backup/{dirs[i]}")}')
|
||||
else:
|
||||
_, _, stderr = self._ssh.exec_command(
|
||||
f'rm -r "{self.output}/simple_backup/{dirs[i]}"')
|
||||
f'rm -r {shlex.quote(f"{self.output}/simple_backup/{dirs[i]}")}')
|
||||
|
||||
err = stderr.read().decode('utf-8').strip().split('\n')[0]
|
||||
|
||||
@@ -304,7 +304,7 @@ class Backup:
|
||||
sys.exit(5)
|
||||
|
||||
_, stdout, _ = self._ssh.exec_command(
|
||||
f'find {self.output}/simple_backup/ -mindepth 1 -maxdepth 1 -type d | sort')
|
||||
f'find {shlex.quote(self.output + "/simple_backup/")} -mindepth 1 -maxdepth 1 -type d | sort')
|
||||
output = stdout.read().decode('utf-8').strip().split('\n')
|
||||
|
||||
if output[-1] != '':
|
||||
|
||||
Reference in New Issue
Block a user