INNER CODE UNIT · Rust
is_safe_shell_command
ovexro/dockpanel · panel/backend/src/routes/mod.rs:288
pub fn is_safe_shell_command(cmd: &str) -> Result<(), &'static str> {
if cmd.trim().is_empty() {
return Err("Command cannot be empty");
}
if cmd.len() > 4096 {
return Err("Command too long (max 4096 chars)");
}
if cmd.contains('\0') {
return Err("Command must not contain null bytes");
}
if cmd.contains('\n') || cmd.contains('\r') {
return Err("Command must not contain newlines");
}
// A bare `;` always chains regardless of exit status; a bare (unpaired)
// `|` chains just as effectively — neither is caught by the verb-anchored
// patterns below (";bash", "| sh", ...), which never matched "id;whoami"
// or "id|whoami" (no space, no shell name). `&&`/`||` remain allowed for