馃崚Fix command expansion in env.sh - #591
Open
etcwilde wants to merge 3 commits into
Open
Conversation
Teaching Swiftly to escape the `SWIFTLY_*` environment variables and wrap them with single quotes.
Updating unmodified env.sh files to use the single quotes.
Adding tests to verify that the environment variables are single-quoted appropriately and that Swiftly upgrades from both old formats correctly.
etcwilde
requested review from
cmcgee1024,
justice-adams-apple and
shahmishal
as code owners
September 11, 2026 19:28
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Swiftly copies the contents of the SWIFTLY_HOME_DIR, SWIFTLY_BIN_DIR, and SWIFTLY_TOOLCHAINS_DIR environment variables into the generated env.sh file. If these environment variables contain a command, the command is executed.
This changes Swiftly to use single-quotes, preventing variable expansions and command execution when sourcing the env.sh. Also changes Swiftly to escape single quotes in the environment variable to prevent ending the single-quoted string and passing arbitrary outputs.
1.2 Cherry-Pick: #590