package tui import ( "os/exec" "reflect" "strings" "testing" ) // TestShellQuoteArgsRoundTrip guards the updater's poll-script generation: cv fields // (e.g. cert_dir_path) are operator-entered and get embedded into a shell script run // inside the updater container. If shellQuote/shellQuoteArgs mis-escapes a value, that's // a command-injection bug, not just a cosmetic one. This feeds tricky values through a // real `sh` and checks they come back out exactly as they went in. func TestShellQuoteArgsRoundTrip(t *testing.T) { if _, err := exec.LookPath("sh"); err != nil { t.Skip("sh not available") } cases := [][]string{ {"simple"}, {"has space"}, {"it's got a quote"}, {"$(echo injected)"}, {"a;b|c&d"}, {"back`tick`"}, {"multi", "arg space", "o'clock", "$HOME", "'"}, } for _, args := range cases { script := "printf '%s\\n' " + shellQuoteArgs(args) out, err := exec.Command("sh", "-c", script).Output() if err != nil { t.Fatalf("sh failed for %v: %v", args, err) } got := strings.Split(strings.TrimRight(string(out), "\n"), "\n") if !reflect.DeepEqual(got, args) { t.Errorf("round trip mismatch for %v: got %v", args, got) } } }