nushell/crates
Ian Manske f3cf693ec7
Disallow more characters in arguments for internal cmd commands (#13009)
# Description
Makes `run-external` error if arguments to `cmd.exe` internal commands
contain newlines or a percent sign. This is because the percent sign can
expand environment variables, potentially? allowing command injection.
Newlines I think will truncate the rest of the arguments and should
probably be disallowed to be safe.

# After Submitting
- If the user calls `cmd.exe` directly, then this bypasses our
handling/checking for internal `cmd` commands. Instead, we use the
handling from the Rust std lib which, in this case, does not do special
handling and is potentially unsafe. Then again, it could be the user's
specific intention to run `cmd` with whatever trusted input. The problem
is that since we use the std lib handling, it assumes the exe uses the C
runtime escaping rules and will perform some unwanted escaping. E.g., it
will add backslashes to the quotes in `cmd echo /c '""'`.
- If `cmd` is called indirectly via a `.bat` or `.cmd` file, then we use
the Rust std lib which has separate handling for bat files that should
be safe, but will reject some inputs.
- ~~I'm not sure how we handle `PATHEXT`, that can also cause a file
without an extension to be run as a bat file. If so, I don't know where
the handling, if any, is done for that.~~ It looks like we use the
`which` crate to do the lookup using `PATHEXT`. Then, we pass the exe
path from that to the Rust std lib `Command`, which should be safe
(except for the first `cmd.exe` note).

So, in the future we need to unify and/or fix these different
implementations, including our own special handling for internal `cmd`
commands that this PR tries to fix.
2024-05-30 19:24:48 +00:00
..
nu_plugin_custom_values Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu_plugin_example Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu_plugin_formats Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu_plugin_gstat Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu_plugin_inc Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu_plugin_nu_example Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu_plugin_polars Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu_plugin_python Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu_plugin_query Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu_plugin_stress_internals Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-cli fixes a bug in OSC9;9 execution (#12994) 2024-05-29 18:06:47 -05:00
nu-cmd-base Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-cmd-extra Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-cmd-lang fix do closure with both required, options, and rest args (#13002) 2024-05-30 08:29:46 -05:00
nu-cmd-plugin Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-color-config Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-command Disallow more characters in arguments for internal cmd commands (#13009) 2024-05-30 19:24:48 +00:00
nu-engine Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-explore Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-glob Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-json Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-lsp Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-parser Restore tilde expansion on external command names (#13001) 2024-05-29 18:48:29 -07:00
nu-path Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-plugin Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-plugin-core Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-plugin-engine Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-plugin-protocol Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-plugin-test-support Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-pretty-hex Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-protocol Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-std Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-system Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-table Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-term-grid Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-test-support Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nu-utils Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
nuon Bump version to 0.94.1 (#12988) 2024-05-28 22:41:23 +00:00
README.md Remove old nushell/merge engine-q 2022-02-07 14:54:06 -05:00

Nushell core libraries and plugins

These sub-crates form both the foundation for Nu and a set of plugins which extend Nu with additional functionality.

Foundational libraries are split into two kinds of crates:

  • Core crates - those crates that work together to build the Nushell language engine
  • Support crates - a set of crates that support the engine with additional features like JSON support, ANSI support, and more.

Plugins are likewise also split into two types:

  • Core plugins - plugins that provide part of the default experience of Nu, including access to the system properties, processes, and web-connectivity features.
  • Extra plugins - these plugins run a wide range of different capabilities like working with different file types, charting, viewing binary data, and more.