INNER CODE UNIT · Python
shell_value
IvanMurzak/Unity-MCP · .github/scripts/chain_feed.py:576
def shell_value(name, value, windows=None):
"""One placeholder value made safe to paste into a `shell=True` recipe.
POSIX `/bin/sh`: `shlex.quote` — a value made only of `[A-Za-z0-9@%+=:,./_-]` (every
validated ws version and every ordinary runner path) comes back unchanged, so the plan text
is the same as before; anything else is single-quoted. Windows `cmd.exe` has no quoting that
neutralises `%`/`!`/`^`, so there the value must already be free of cmd metacharacters (the
lock values are, by `validate_lock`); a runner path with whitespace or parentheses is
double-quoted. CR, LF and NUL are refused on both — no quoting survives a line break.
"""
text = str(value)
if any(ch in text for ch in "\r\n\x00"):
raise Refusal("placeholder {%s} value %r carries a line break or NUL; refusing to build a shell command" % (name, text))
if windows is None:
windows = os.name == "nt"
if windows:
bad = sorted(set(text) & set(_CMD_METACHARS))
if bad: