nix-store --print-env: fix shell quoting on _args output#14329
Merged
Conversation
ed3d0c8 to
68c48ce
Compare
matshch
approved these changes
Oct 22, 2025
Ericson2314
approved these changes
Oct 24, 2025
68c48ce to
5ed7379
Compare
5ed7379 to
d244930
Compare
d244930 to
1fb8796
Compare
The previous implementation double-quoted the _args variable by escaping each argument individually and then wrapping them all in single quotes, producing output like: _args=''-e' 'arg1' 'arg2'' This fix concatenates all arguments into a single string first, then escapes that string once, producing correct output like: _args='-e arg1 arg2' This prevents potential command injection issues when the output is sourced in shell scripts. Fixes NixOS#14327
1fb8796 to
ffe97db
Compare
brittonr
pushed a commit
to brittonr/nix
that referenced
this pull request
Apr 1, 2026
nix-store --print-env: fix shell quoting on _args output
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The previous implementation double-quoted the _args variable by escaping each argument individually and then wrapping them all in single quotes, producing output like: _args=''-e' 'arg1' 'arg2''
This fix concatenates all arguments into a single string first, then escapes that string once, producing correct output like: _args='-e arg1 arg2'
This prevents potential command injection issues when the output is sourced in shell scripts.
Fixes #14327
Motivation
Context
Add 👍 to pull requests you find important.
The Nix maintainer team uses a GitHub project board to schedule and track reviews.