2021-09-16 21:38:43 +08:00
|
|
|
//go:build windows
|
2020-12-21 09:37:48 +11:00
|
|
|
// +build windows
|
|
|
|
|
|
|
|
package secureexec
|
|
|
|
|
|
|
|
import (
|
|
|
|
"os/exec"
|
|
|
|
|
|
|
|
"github.com/cli/safeexec"
|
|
|
|
)
|
|
|
|
|
|
|
|
// calling exec.Command directly on a windows machine poses a security risk due to
|
|
|
|
// the current directory being searched first before any directories in the PATH
|
|
|
|
// variable, meaning you might clone a repo that contains a program called 'git'
|
|
|
|
// which does something malicious when executed.
|
|
|
|
|
|
|
|
// see https://github.com/golang/go/issues/38736 for more context. We'll likely
|
|
|
|
// be able to just throw out this code and switch to the official solution when it exists.
|
|
|
|
|
|
|
|
// I consider this a minor security concern because you're just as vulnerable if
|
|
|
|
// you call `git status` from the command line directly but no harm in playing it
|
|
|
|
// safe.
|
|
|
|
|
2023-05-23 19:09:23 +10:00
|
|
|
var pathCache = map[string]string{}
|
|
|
|
|
2020-12-21 09:37:48 +11:00
|
|
|
func Command(name string, args ...string) *exec.Cmd {
|
2023-05-23 19:09:23 +10:00
|
|
|
path := getPath(name)
|
|
|
|
|
|
|
|
return exec.Command(path, args...)
|
|
|
|
}
|
|
|
|
|
|
|
|
func getPath(name string) string {
|
|
|
|
if path, ok := pathCache[name]; ok {
|
|
|
|
return path
|
|
|
|
}
|
|
|
|
|
|
|
|
path, err := safeexec.LookPath(name)
|
2020-12-21 09:37:48 +11:00
|
|
|
if err != nil {
|
2023-05-23 19:09:23 +10:00
|
|
|
pathCache[name] = name
|
|
|
|
return name
|
2020-12-21 09:37:48 +11:00
|
|
|
}
|
|
|
|
|
2023-05-23 19:09:23 +10:00
|
|
|
pathCache[name] = path
|
|
|
|
return path
|
2020-12-21 09:37:48 +11:00
|
|
|
}
|