Page MenuHomePhabricator

Support %LA (AND), %LO (OR) and %LQ (comma) conversions for qsprintf() to improve safety
ClosedPublic

Authored by epriestley on Nov 7 2018, 12:45 AM.
Tags
None
Referenced Files
Unknown Object (File)
Sun, Feb 2, 12:51 AM
Unknown Object (File)
Wed, Jan 29, 5:57 AM
Unknown Object (File)
Tue, Jan 28, 4:19 AM
Unknown Object (File)
Thu, Jan 23, 6:48 PM
Unknown Object (File)
Tue, Jan 21, 12:04 PM
Unknown Object (File)
Jan 6 2025, 3:24 AM
Unknown Object (File)
Dec 31 2024, 1:16 PM
Unknown Object (File)
Dec 29 2024, 9:55 AM
Subscribers
None

Details

Summary

Depends on D19782. Ref T13217. Ref T13216. Ref T6960. We currently construct some queries by passing implode(...) directly to qsprintf().

I believe we can cover all these cases (or, at least, almost all these cases) with conversions for imploding on AND, OR, or comma. This will ultimately let us make %Q safer.

Test Plan

Played around with these in a toy qsprintf() script; upcoming changes will convert Phabricator callsites more aggressively.

Diff Detail

Repository
rPHU libphutil
Lint
Lint Not Applicable
Unit
Tests Not Applicable