Merge pull request #1198 from Asher-/fix/shell-command-safety

Use shlex.quote for shell argument escaping on POSIX
This commit is contained in:
Michael Panchenko authored and GitHub committed 2026-03-23 10:18:28 +01:00
commit 7ed2862b08
1 file changed
+11 -4
+11 -4
View File
@@ -1,4 +1,5 @@
import platform
import shlex
import subprocess
@@ -15,8 +16,14 @@ def subprocess_kwargs() -> dict:
def quote_arg(arg: str) -> str:
"""
Adds quotes around an argument if it contains spaces.
Quotes a shell argument to prevent interpretation of metacharacters.
Uses :func:`shlex.quote` on POSIX systems for proper escaping of all
shell-special characters. On Windows, wraps arguments containing spaces
in double quotes (Windows shell does not interpret single-quoted strings).
"""
if " " not in arg:
return arg
return f'"{arg}"'
if platform.system() == "Windows":
if " " not in arg:
return arg
return f'"{arg}"'
return shlex.quote(arg)