diff --git a/lib/bash/git/lib_git.sh b/lib/bash/git/lib_git.sh index bb6f694..8cabb64 100644 --- a/lib/bash/git/lib_git.sh +++ b/lib/bash/git/lib_git.sh @@ -226,6 +226,10 @@ git_get_current_branch() { log_error "Usage: git_get_current_branch " return 1 fi + if ! __is_valid_variable_name__ "$result_var_name"; then + log_error "git_get_current_branch: result variable name must be a valid Bash variable name." + return 1 + fi printf -v "$result_var_name" '%s' "" diff --git a/lib/bash/git/tests/lib_git.bats b/lib/bash/git/tests/lib_git.bats index 3ed92d9..b663364 100644 --- a/lib/bash/git/tests/lib_git.bats +++ b/lib/bash/git/tests/lib_git.bats @@ -55,6 +55,18 @@ setup() { [[ "$output" != *"Usage: get_git_branch"* ]] } +@test "git_get_current_branch rejects invalid result variable names" { + local repo="$TEST_TMPDIR/repo" + + init_git_repo "$repo" + + bats_run git_get_current_branch "$repo" "bad-name" + + [ "$status" -eq 1 ] + [[ "$output" == *"git_get_current_branch: result variable name must be a valid Bash variable name"* ]] + [[ "$output" != *"invalid variable name"* ]] +} + @test "git_update_repo skips dirty repositories when no dirty path is allowed" { local repo="$TEST_TMPDIR/repo" diff --git a/lib/bash/std/lib_std.sh b/lib/bash/std/lib_std.sh index b147e53..584a0c7 100644 --- a/lib/bash/std/lib_std.sh +++ b/lib/bash/std/lib_std.sh @@ -842,6 +842,11 @@ safe_truncate() { ####################################################### ASSERTIONS #################################################### +__is_valid_variable_name__() { + local var_name="${1-}" var_name_re='^[A-Za-z_][A-Za-z0-9_]*$' + [[ "$var_name" =~ $var_name_re ]] +} + # # assert_not_null - Checks that one or more variables are not empty. # @@ -861,13 +866,13 @@ safe_truncate() { # $@: One or more variable names to check. # assert_not_null() { - local unset_vars=() var_name var_name_re='^[A-Za-z_][A-Za-z0-9_]*$' + local unset_vars=() var_name if (($# == 0)); then fatal_error "assert_not_null: No variable names provided for validation." fi for var_name in "$@"; do - if ! [[ "$var_name" =~ $var_name_re ]]; then + if ! __is_valid_variable_name__ "$var_name"; then fatal_error "assert_not_null expects variable names, not values; one or more arguments are not valid Bash variable names." fi # Use indirection to get the value of the variable whose name is stored in var_name. @@ -892,6 +897,9 @@ assert_integer() { local var_name int_re='^[-+]?[0-9]+$' (($# == 0)) && fatal_error "assert_integer: No variable names provided." for var_name in "$@"; do + if ! __is_valid_variable_name__ "$var_name"; then + fatal_error "assert_integer expects variable names, not values; one or more arguments are not valid Bash variable names." + fi local value="${!var_name-}" ! [[ "$value" =~ $int_re ]] && fatal_error "Variable '$var_name' with value '$value' is not a valid integer." done @@ -909,6 +917,9 @@ assert_integer() { assert_integer_range() { local var_name="${1-}" min="${2-}" max="${3-}" (($# != 3)) && fatal_error "assert_integer_range: Expected 3 arguments, got $#." + if ! __is_valid_variable_name__ "$var_name"; then + fatal_error "assert_integer_range expects a variable name as its first argument." + fi local value="${!var_name-}" assert_integer "$var_name" min max ((value < min || value > max)) && fatal_error "Variable '$var_name' ($value) is out of range [$min, $max]." @@ -1134,6 +1145,9 @@ safe_unalias() { get_my_source_dir() { local result_name="${1-}" [[ -n "$result_name" ]] || fatal_error "get_my_source_dir: No result variable name provided." + if ! __is_valid_variable_name__ "$result_name"; then + fatal_error "get_my_source_dir: result variable name must be a valid Bash variable name." + fi local source_dir # Reference: https://stackoverflow.com/a/246128/6862601 source_dir="$(cd "$(dirname "${BASH_SOURCE[1]}")" >/dev/null 2>&1 && pwd -P)" || diff --git a/lib/bash/std/tests/lib_std.bats b/lib/bash/std/tests/lib_std.bats index a6bee4b..f52bf7f 100644 --- a/lib/bash/std/tests/lib_std.bats +++ b/lib/bash/std/tests/lib_std.bats @@ -992,6 +992,24 @@ EOF [[ "$output" == *"is not a valid integer"* ]] } +@test "assert_integer rejects invalid variable names without echoing values" { + local script="$TEST_TMPDIR/assert-integer-name.sh" + + create_script "$script" <