logoalt Hacker News

CodesInChaos • today at 2:34 PM • 4 replies • view on HN

Unfortunately half of its badness isn't isn't the shell itself, but the convention of how parameters are passed to processes on Unix systems.


Replies

hnlmorg • today at 4:19 PM

That’s not correct because POSIX passes what is ostensibly an array of strings.

Windows, on the other hand, only passes one string. So it’s up to the application to choose how to handle whitespace, quotation marks, and other nuances with parsing parameters.

Variable expansion in Bash is lazy. But there’s no reason why variables cannot be tokenised so that strings with spaces aren’t treated as multiple parameters. And in fact that’s exactly how some other shells work, such as the one I maintain.

formerly_proven • today at 3:08 PM

Array of arguments is vastly superior and more secure than every program/runtime inventing a slightly different way of splitting a command string into an array of arguments. No debate. A real problem is the related birth defect in ssh2.

akoboldfrying • today at 3:01 PM

Well, the only other way I can think of that it could be done is the Windows way, whereby you pass the unparsed command line, spaces and all, as a string to the new process. And while this is arguably the cleaner interface, in practice it has meant even worse quote handling, since how -- or even whether -- double quotes are parsed now depends on the probably undocumented process startup code chosen by the program's compiler vendor.

Want to quote a command line that may already contain double quotes, in order to pass it as an argument to some other program? No, you don't. It isn't right to want that.

➕ show 1 reply
sysguest • today at 3:38 PM

yeah but... that convention is so much of a security/bug headache

sometimes, its footguns seem worse than javascript...

hope some typescript-like "typed shell" becomes mainstream someday

➕ show 3 replies