Skip to content

Commit 3dbe518

Browse files
committed
test: keep unknown batch wrappers out of the shell fallback
1 parent 44e3434 commit 3dbe518

2 files changed

Lines changed: 9 additions & 1 deletion

File tree

‎packages/core/src/runtime/engineProcess.spec.ts‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -51,6 +51,14 @@ describe("engine process launch", () => {
5151
});
5252

5353
describe.skipIf(process.platform !== "win32")("Windows npm launcher", () => {
54+
it("rejects unknown batch wrappers instead of forwarding arguments through a shell", () => {
55+
for (const ext of ['cmd', 'bat']) {
56+
const wrapper = join(binDir, `unknown.${ext}`);
57+
writeFileSync(wrapper, '@echo off\r\necho %*\r\n');
58+
expect(() => spawnEngine(wrapper, ['a"b&c'], { stdio: 'pipe' })).toThrow(/doesn't appear to be a cmd-shim/);
59+
}
60+
});
61+
5462
it("runs a cmd shim in a spaced path with quoted and shell-special arguments", async () => {
5563
const args = ['two words', 'a"b', '(paren)', 'x&y', '%PATH%', 'semi;colon'];
5664
const child = spawnEngine(cmd, args, { stdio: ["ignore", "pipe", "pipe"] });

‎packages/core/src/runtime/engineProcess.ts‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@ export const spawnEngine = ((command, args, options) => {
1010
// Global npm shims require another cmd parsing pass, which can reinterpret
1111
// quoted arguments. Resolve their target as npm does for a symlink instead.
1212
// cross-spawn then follows the target's shebang without passing through cmd.
13-
if (process.platform === "win32" && /\.cmd$/i.test(command)) {
13+
if (process.platform === "win32" && /\.(?:cmd|bat)$/i.test(command)) {
1414
command = resolve(dirname(command), readCmdShim.sync(command));
1515
}
1616
return crossSpawn(command, args, options);

0 commit comments

Comments
 (0)