From mboxrd@z Thu Jan 1 00:00:00 1970 X-Spam-Checker-Version: SpamAssassin 3.4.4 (2020-01-24) on inbox.vuxu.org X-Spam-Level: X-Spam-Status: No, score=-3.3 required=5.0 tests=DKIM_SIGNED,DKIM_VALID, MAILING_LIST_MULTI,RCVD_IN_DNSWL_MED autolearn=ham autolearn_force=no version=3.4.4 Received: (qmail 4933 invoked from network); 11 Feb 2023 05:37:28 -0000 Received: from zero.zsh.org (2a02:898:31:0:48:4558:7a:7368) by inbox.vuxu.org with ESMTPUTF8; 11 Feb 2023 05:37:28 -0000 ARC-Seal: i=1; cv=none; a=rsa-sha256; d=zsh.org; s=rsa-20210803; t=1676093848; b=ZFFMtcJzH6pOxA4FCMJNi4xEwsC+jhsQCXGaSp9MxjQHZuBVBAec712Txie9cRIb3J6IhQn8db geRD3k4RpPbbVeyuaE25QvKyJwJfKiJyYvalw/5RB1nuKIUkVBC2pzRqUehvCwsQcT1TS7WqwX cwSllmE8P64l1hf34XTvRWgoDBukWTlVnN/4zV3fph27/UwSWGqVX82gKeG6Wj4+o/8sY0gq1e haPDo8AdE/Xln8O/eYdtUwEjifmCpLeQ3uqHFUmJjPaOqvVMszaPAwri9uD15GRkeM4s+cWVTV Jut9YoVeNy3t3z6ML/2BOdV9Y4d6H/EVZzz3aTF09MRKjw==; ARC-Authentication-Results: i=1; zsh.org; iprev=pass (mail-ed1-f54.google.com) smtp.remote-ip=209.85.208.54; dkim=pass header.d=brasslantern-com.20210112.gappssmtp.com header.s=20210112 header.a=rsa-sha256; dmarc=none header.from=brasslantern.com; arc=none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed; d=zsh.org; s=rsa-20210803; t=1676093848; bh=CUlHslgGiqcrfc0os0vXL8KzF1EYwPtbgRFguTBGdb0=; h=List-Archive:List-Owner:List-Post:List-Unsubscribe:List-Subscribe:List-Help: List-Id:Sender:Content-Type:To:Subject:Message-ID:Date:From:In-Reply-To: References:MIME-Version:DKIM-Signature:DKIM-Signature; b=YM4djlGNDuJCEvVEcxpdOSUtjLOwgzLsHzEUp63vyORJcNdvv83SrGlgxrbzfjanYN/E5kmD9L 26Mv8ul10BjJepQ1kU1eT9uKSY3h2N7umPwyg3+5msj35tbPuyWNxXI6F/FZgB3455lIhAwyRI WnOm7k/ohXKLgReVm0AonTtsFf6LOir4haeVeu0Frs0xMD0Y2Jmccqdkljz3ganDY8U4SvwYTG 7Q3BK/5UQ8LOay5Rl++uqIsm23gq0UlBMT2qtJfqicg8UlKmKQjtAkdCYmkzgyj9QLGBnTvjkq oGJ1IrrmzcvcY8l6sxGeWdkRd5Y/NG446X8BwsIkxDKWlw==; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=zsh.org; s=rsa-20210803; h=List-Archive:List-Owner:List-Post:List-Unsubscribe: List-Subscribe:List-Help:List-Id:Sender:Content-Type:To:Subject:Message-ID: Date:From:In-Reply-To:References:MIME-Version:Reply-To:Cc: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID; bh=7ovq4ilFcIlveen1PIiIy8OcxYuOGbEn42Fw5PRE1bY=; b=VgToWWiubIbIANilZaPlqVbeQw e/WEz3wzXtAYGI410OepL3WX9CSFyJgmxywo5g+xa2ZVDWhjT9bpzT/9IvAXDfWRkFXA5ROBLLvfG aZzCId0Ss9FIs0q0iIcgEXjb7vaLRXP8/tMNkaIKQ4lnelkmBanb2SGqjdj1cSyn6iqDDP1l9S7LB 9Ew0IyPu77RT/piRN3ocyRedtKW8ppULzaPATMcmmd59RZ2BZQ6hc1GXmmGBj6nxy2unHhKoDJo3J ZHFZDSuj93FcgJM+vtR5REQqm6y8WvsJqwP79WXNjtZ2oP0DdfyCZr6nDmnpdqdxDeQn//JCC3tb1 ebDHzWkA==; Received: by zero.zsh.org with local id 1pQiZj-000CkE-HF; Sat, 11 Feb 2023 05:37:27 +0000 Authentication-Results: zsh.org; iprev=pass (mail-ed1-f54.google.com) smtp.remote-ip=209.85.208.54; dkim=pass header.d=brasslantern-com.20210112.gappssmtp.com header.s=20210112 header.a=rsa-sha256; dmarc=none header.from=brasslantern.com; arc=none Received: from mail-ed1-f54.google.com ([209.85.208.54]:38706) by zero.zsh.org with esmtps (TLS1.3:TLS_AES_128_GCM_SHA256:128) id 1pQiZD-000CQD-Ab; Sat, 11 Feb 2023 05:36:55 +0000 Received: by mail-ed1-f54.google.com with SMTP id cq19so3988441edb.5 for ; Fri, 10 Feb 2023 21:36:55 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=brasslantern-com.20210112.gappssmtp.com; s=20210112; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :from:to:cc:subject:date:message-id:reply-to; bh=7ovq4ilFcIlveen1PIiIy8OcxYuOGbEn42Fw5PRE1bY=; b=yY3C8f28Wb/KaAbyGfEdxjXGng8KSeVliF0nm9dsU5iYAhwqVEV3BpFf6zoLet3UUs KyVKaPAFFDHHf6frVqk+IoKrkxJU2aGXghyFnRv5JgscOGtRSQGp8+Ogo9Pp6IFopFII Kj3D3zubH0Oesz4tblxNnZ8vnYfGHdZqWmAr99vmfXW4uBa9yDi80RpeWpupI5sd54t1 xZZzCs98s+QKNUf9k98qJNXomLKoxzYthUPn8kIXZ0s9aY88XfkdagyZEP6GyiX4zxdh iNCdPy+nf+4bSQIxSNAMESy7guIFfi0E4SvVjmwNaWsNnhL/7lL4TqtpOeUWJ1lapCxi 6X+Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=to:subject:message-id:date:from:in-reply-to:references:mime-version :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=7ovq4ilFcIlveen1PIiIy8OcxYuOGbEn42Fw5PRE1bY=; b=Su0mxc/uj7v1LHk5di/xWzuLaAsoaCfQu/RNmH77F3o/6wyyOfy2SRsOrkaNrR34O/ 1P8eZr3f+8g010jgAVgi4Nz5h+z9jM/nfBS+68eLTe6zzQL6JmIy4VIHFiKRdoJqt23Q M8YfcvZgHQwC2Pef+CDKMz19Y3/EazMEkV4iaWmwTQ6w+Ti8MfT/Q2Orq4qbbwLaAnA2 PtZDIzKbPKbb5+2902TvSqugT9hSWXI6aX3hRQ26LigxGEpP9ktWiFHd96v90OHxUQSj DjmSJ+KCi0+Q3E+lLjGZFnL+dRik5100NHVO3G9tIYbCN/RxC+YNmLflOtqR3CqKG1dl oQ1g== X-Gm-Message-State: AO0yUKVvYODnfzyqhBq1CU3kvFB46u0M0n7VxpRtGj5jJa9ea2Qj2p7i l3tXadxyqW1Aezw+w80ak1GDUjcBMeJLzfo9Kl59jbQyNvCzMtj7 X-Google-Smtp-Source: AK7set9YZUhdYZQPdK+o+rGhIBi9hw53aW1S0K2g7hGCUaN++8sex4/JLTzNFmaUaEmAKXxyc/n+vXsTTav9dsPQ/m0= X-Received: by 2002:a50:9f6a:0:b0:4ac:20b:96b0 with SMTP id b97-20020a509f6a000000b004ac020b96b0mr939274edf.3.1676093814868; Fri, 10 Feb 2023 21:36:54 -0800 (PST) MIME-Version: 1.0 References: <67689-1675827940.088548@BxvG.D9_b.7RzI> <12608-1675903622.800470@Xj82.e3y1.svhG> <66045-1675975796.128039@FBF_.0yMO.Y8fk> In-Reply-To: From: Bart Schaefer Date: Fri, 10 Feb 2023 21:36:43 -0800 Message-ID: Subject: Speaking of dangerous referents To: Zsh hackers list Content-Type: text/plain; charset="UTF-8" X-Seq: 51397 Archived-At: X-Loop: zsh-workers@zsh.org Errors-To: zsh-workers-owner@zsh.org Precedence: list Precedence: bulk Sender: zsh-workers-request@zsh.org X-no-archive: yes List-Id: List-Help: , List-Subscribe: , List-Unsubscribe: , List-Post: List-Owner: List-Archive: Oliver wrote: > > And it could be wise to limit what can be done as part of the > > subscript evaluation to avoid a CVE similar to the last one. % print $ZSH_PATCHLEVEL ubuntu/5.8-3ubuntu1.1 % empty=() % loop='empty[${(P)loop}]' % print ${(P)loop} zsh: segmentation fault (core dumped) zsh -f