From 426650fbe8943879af72703556ae5d1eb2eac734 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?J=C3=A9r=C3=B4me=20Tamarelle?= Date: Sun, 6 Sep 2026 16:02:47 +0200 Subject: [PATCH] fix(symfony6): don't run command substitutions on tab completion (#14058) The plugin is a copy of the completion script shipped by symfony/console. It has not been updated since it was added, and two fixes made upstream since then are missing. The completion request was assembled as a string from the raw words of the command line, then passed to "eval". Any command substitution present in a word was therefore executed by the completion, before the user validated the line. The request is now run as an array of arguments, without being read again by the shell, and "_describe" is called directly instead of through "eval". The alias of the command is resolved explicitly, since that was the only useful effect of the "eval". The request also runs with SHELL_VERBOSITY=0, so that completion keeps working for users who exported SHELL_VERBOSITY=-1. Ported from symfony/symfony#65818 and symfony/symfony#63859. --- plugins/symfony6/symfony6.plugin.zsh | 34 +++++++++++++++++----------- 1 file changed, 21 insertions(+), 13 deletions(-) diff --git a/plugins/symfony6/symfony6.plugin.zsh b/plugins/symfony6/symfony6.plugin.zsh index ed7dbe60e..e24243767 100644 --- a/plugins/symfony6/symfony6.plugin.zsh +++ b/plugins/symfony6/symfony6.plugin.zsh @@ -15,8 +15,8 @@ # - https://github.com/symfony/symfony/blob/5.4/src/Symfony/Component/Console/Resources/completion.bash # _sf_console() { - local lastParam flagPrefix requestComp out comp - local -a completions + local lastParam out comp sf_cmd + local -a completions flagPrefix requestComp inputs # The user could have moved the cursor backwards on the command-line. # We need to trigger completion from the $CURRENT location, so we need @@ -29,11 +29,20 @@ _sf_console() { setopt local_options BASH_REMATCH if [[ "${lastParam}" =~ '-.*=' ]]; then # We are dealing with a flag with an = - flagPrefix="-P ${BASH_REMATCH}" + flagPrefix=(-P "${BASH_REMATCH}") fi - # Prepare the command to obtain completions - requestComp="${words[0]} ${words[1]} _complete --no-interaction -szsh -a1 -c$((CURRENT-1))" i="" + # Prepare the command to obtain completions. An alias is resolved here, + # because the request is no longer read again by the shell. + sf_cmd="${words[1]}" + if [[ -n "${aliases[$sf_cmd]}" ]]; then + requestComp=(${(z)aliases[$sf_cmd]}) + else + requestComp=(${~sf_cmd}) + fi + + requestComp+=(_complete --no-interaction -szsh -a1 "-c$((CURRENT-1))") + for w in ${words[@]}; do w=$(printf -- '%b' "$w") # remove quotes from typed values @@ -47,19 +56,18 @@ _sf_console() { fi # empty values are ignored if [ ! -z "$w" ]; then - i="${i}-i${w} " + inputs+=("-i$w") fi done # Ensure at least 1 input - if [ "${i}" = "" ]; then - requestComp="${requestComp} -i\" \"" - else - requestComp="${requestComp} ${i}" + if (( ! $#inputs )); then + inputs=(-i' ') fi - # Use eval to handle any environment variables and such - out=$(eval ${requestComp} 2>/dev/null) + # The request is run without being read again by the shell, so that a + # "$(...)" or a backtick typed on the command line is not executed + out=$(SHELL_VERBOSITY=0 "${requestComp[@]}" "${inputs[@]}" 2>/dev/null) while IFS='\n' read -r comp; do if [ -n "$comp" ]; then @@ -75,7 +83,7 @@ _sf_console() { done < <(printf "%s\n" "${out[@]}") # Let inbuilt _describe handle completions - eval _describe "completions" completions $flagPrefix + _describe "completions" completions "${flagPrefix[@]}" return $? }