From mboxrd@z Thu Jan 1 00:00:00 1970 X-Spam-Checker-Version: SpamAssassin 3.4.4 (2020-01-24) on inbox.vuxu.org X-Spam-Level: X-Spam-Status: No, score=-3.3 required=5.0 tests=DKIM_SIGNED,DKIM_VALID, MAILING_LIST_MULTI,RCVD_IN_DNSWL_MED,UNPARSEABLE_RELAY autolearn=ham autolearn_force=no version=3.4.4 Received: (qmail 25690 invoked from network); 16 May 2021 00:40:55 -0000 Received: from zero.zsh.org (2a02:898:31:0:48:4558:7a:7368) by inbox.vuxu.org with ESMTPUTF8; 16 May 2021 00:40:55 -0000 ARC-Seal: i=1; cv=none; a=rsa-sha256; d=zsh.org; s=rsa-20200801; t=1621125656; b=WrpZ2o8mLOyV+L+VgOHwrTjmD4IwtCM2xkdgS70Iu2H/Ny3ghRlKm/nQJcF8pKxihOlwlOmzIQ NT8ilBttfo2tClob6rzJgJkT4rwqKgJYID6V5075IShOMjNHhIE/16AQBZws62MeF3rpQLuaM7 8VAVEoB7tXX+5TTkxzgsspe7c0v58Tkap2f4BGo0LvyA2ZT+3/AYRFjiUN96+e2SLS/KjZB/e1 htE6xR/sFwDH2T9CJVgwHozEVnKWWAn/+IR7UnCV8c/sKOLb2INh+gpO/VazvZNlqvjVso0Xjd 19i3WveoqXMotv9RjBksGd/5z7my5yKzdZ0DKvXdxye+kw==; ARC-Authentication-Results: i=1; zsh.org; iprev=pass (mail-oo1-f43.google.com) smtp.remote-ip=209.85.161.43; dkim=pass header.d=brasslantern-com.20150623.gappssmtp.com header.s=20150623 header.a=rsa-sha256; dmarc=none header.from=brasslantern.com; arc=none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed; d=zsh.org; s=rsa-20200801; t=1621125656; bh=hNylpNGfJYZYa6pQ2FuKtrg/XYyV1Q+h52jTr6Jb9zo=; h=List-Archive:List-Owner:List-Post:List-Unsubscribe:List-Subscribe:List-Help: List-Id:Sender:Content-Transfer-Encoding:Content-Type:To:Subject:Message-ID: Date:From:In-Reply-To:References:MIME-Version:DKIM-Signature:DKIM-Signature; b=JzsI++EKt5VZx/fZfy1hwFwQtxJvPKcYXwsTOtXInbgeiQN4NF+099qzCq7fmg9q5x8oR+hySz NYyFSF9keAzrFvU1Dh59PRXT7XycG2Uann0kEvDOt3TupBqAPua7w1mzbWpxDrMp7K+hc6x/FH a25VSeNmM+82bN3ZcwUUp7K6fmx2VFZmx96s6wCQAWNWCAj1x8zpruBkJQ65LgdTobmry5RZwA 4+7QxknLLsYzT23/nedgOO9937Fq9bqduGJ3DHPHSZj3rKxe0f3P005Im/wvvzzSPe73JAHTKl xLQdXS0ye9eD0oSLm31nPTfRheyOUUpyq2YCFW1d5LIMuw==; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=zsh.org; s=rsa-20200801; h=List-Archive:List-Owner:List-Post:List-Unsubscribe: List-Subscribe:List-Help:List-Id:Sender:Content-Transfer-Encoding: Content-Type:To:Subject:Message-ID:Date:From:In-Reply-To:References: MIME-Version:Reply-To:Cc:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID; bh=qNuxJXitwInqEr8KI8e7eyMtPaTdMfnY1xhOd5PSJE4=; b=anhX8DeIZP11BUBphHbLqroxSS u9eT2dK1sc2MJd4b0p3gg+41k26L4rgFioLPNs/rHS/i6ksuEuOie1VRveNw6Y1mkdCfUNfLRZPlT IKbB5diPH/vP61FcSP3xX7INPZQKF7bLluybfpIykHi25IMnAcD+i4P+c5ldmkR/rQjo6FMJITGB1 brXVKVp8g6Y8S97KsZQVx/lDWbnG/56vGOIUSGrZdTluWBrTd3bmqwlXzALNAH7qsgPT+IcdycXBH R6t8NXoACjT7sWeiM2te24sfVI0a7RY2CG1OTNa1RauaQRdbRtGKfEcpoBKwavA/nE1yGBGcHDmSe lHFkFMGw==; Received: from authenticated user by zero.zsh.org with local id 1li4pz-000L1o-8B; Sun, 16 May 2021 00:40:55 +0000 Authentication-Results: zsh.org; iprev=pass (mail-oo1-f43.google.com) smtp.remote-ip=209.85.161.43; dkim=pass header.d=brasslantern-com.20150623.gappssmtp.com header.s=20150623 header.a=rsa-sha256; dmarc=none header.from=brasslantern.com; arc=none Received: from mail-oo1-f43.google.com ([209.85.161.43]:35391) by zero.zsh.org with esmtps (TLS1.3:TLS_AES_128_GCM_SHA256:128) id 1li4pl-000Kls-JL; Sun, 16 May 2021 00:40:42 +0000 Received: by mail-oo1-f43.google.com with SMTP id s20-20020a4ae9940000b02902072d5df239so721140ood.2 for ; Sat, 15 May 2021 17:40:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=brasslantern-com.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :content-transfer-encoding; bh=qNuxJXitwInqEr8KI8e7eyMtPaTdMfnY1xhOd5PSJE4=; b=Vrf37ZBNML6NJpimXPQxbNLe5jIh4g9ZaQMSbvQIlX/JNYwr7qDI0XYI2Emn060KAj 8u1yTa8nfRkb1i8MPIKuDd8EbQIGaxIrHzJaSCLH4aecGv1Rgq9moHdVP30b4RWFI32K f08x1vHDA9wed8DlbH2W/oIpTuIUhcttaF+N5vKa5OwL+WF8k/+RHl4Q7XBxFTQ+4D8W S6NseZBT6gW5PYO9EafTaBQrFQbVKyyYtBZrbU8PGf1oqTjEDlTa8cU3Pg+1sH9+g3Ii IzAki01w99V2hkm+FrfMZBc59kH9ppjMcs5gvxEvjPLU3Rs9TmDgD9e9n8/qYh59fYo8 3hiw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:content-transfer-encoding; bh=qNuxJXitwInqEr8KI8e7eyMtPaTdMfnY1xhOd5PSJE4=; b=XIyafz0ZonOxmmftSLL6e/zKWAK1PugjL3MkdkG+dnisR9D0dqa4Gk1gujAJIYXyg/ xekY8JQfuuE0l4F3l9+QQZ0aomDgOSABRhwxNfjjFwsrHAVa4Gzqf8n0JSycnIAlOyzO nCtPFUIyWYQljoF97NLt8VaYbzhfhXl9WF9/Ye7oCGN2qK2yN2lngQvX7oCvzy/hZSVQ pH20qkYQT9IpUeN+za7ZnegjmAQnUJa0kHoxcENv/PHxKYSOr58qY1wq1XBc4kIeTdTr HtFQoAIFZNvnQUVuUHL8ex780JSje2782kM5Rfe6GS2wGCnnOZYzsDXw6HdHO7Bjccxv ZTsw== X-Gm-Message-State: AOAM530Qo3O7muBykE8mU3UcD/mj6q8WS8x98Nwx5QlVfRwrnAqv3ftY zbbdoBmdv0XWyI6xDI3TsS8Csg/IAWuVtJQmdcY+7wMHhkSplw== X-Google-Smtp-Source: ABdhPJx7nSls0owh3jqQl1ydiUFksO+KJoCFLfg1sxhahFlmIh2JH9Uy6YoHBl8HzpUpjfMCcLtWK9HNcXO1+ZvkqMA= X-Received: by 2002:a4a:c446:: with SMTP id h6mr30794769ooq.82.1621125639971; Sat, 15 May 2021 17:40:39 -0700 (PDT) MIME-Version: 1.0 References: <88f30242-af89-433c-b763-4a15b72a498b@www.fastmail.com> In-Reply-To: <88f30242-af89-433c-b763-4a15b72a498b@www.fastmail.com> From: Bart Schaefer Date: Sat, 15 May 2021 17:40:28 -0700 Message-ID: Subject: Re: I've caught up on pending commits; how about you? To: Zsh hackers list Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Seq: 48831 Archived-At: X-Loop: zsh-workers@zsh.org Errors-To: zsh-workers-owner@zsh.org Precedence: list Precedence: bulk Sender: zsh-workers-request@zsh.org X-no-archive: yes List-Id: List-Help: List-Subscribe: List-Unsubscribe: List-Post: List-Owner: List-Archive: On Sat, May 15, 2021 at 4:22 PM Daniel Shahaf wrot= e: > > And there's the ctags patch that has been committed with some review > points outstanding. A glance at _ctags in master shows that external > command output is passed to _values' =C2=ABspec=C2=BB arguments unsanitiz= ed. I don't have access to the ctags variant that supports --list-languages, but I presume you're referring to _values -s , languages $languages The value of $languages comes from _ctags_languages which produces only strings matching the sed pattern [A-Za-z][A-Za-z0-9#_+]* What additional sanitation do you feel is needed? This was done in response to your previous criticism of this point. As far as I can tell the only un-address review points are from Oliver's workers/48296