diff --git a/doc/gpp.pp b/doc/gpp.pp index c3807c4..e48f14f 100644 --- a/doc/gpp.pp +++ b/doc/gpp.pp @@ -179,7 +179,7 @@ $define{SYNTAX}{ $pre$ gpp [$dp$$bra$o$pipe$O$ket$ $I{outfile}$] [$dp$I$I{/include/path}$ ...] - [$dp$D$I{name=val}$ ...] [$dp$z$pipe$+z] [$dp$x] [$dp$m] + [$dp$D$I{name=val}$ ...] [$dp$z$pipe$+z] [$dp$e] [$dp$x] [$dp$m] [$dp$C$pipe$$dp$T$pipe$$dp$H$pipe$$dp$X$pipe$$dp$P$pipe$$dp$U ... [$dp$M ...]] [$dp$n$pipe$+n] [+c$I{$l$n$g$}$ $I{str1}$ $I{str2}$] [+s$I{$l$n$g$}$ $I{str1}$ $I{str2}$ $I{c}$] [$dp$c $I{str1}$] [$dp$$dp$nostdinc] [$dp$$dp$nocurinc] @@ -316,10 +316,15 @@ converted to CR$ndash$LF. This is the default if GPP is compiled with the WIN$und$NT option. $li$ +$BI{$d$e}$ +Enable the use of the $I{$dz$exec}$ meta-macro. Since $I{$dz$exec}$ includes +the output of an arbitrary shell command line, it may cause a potential +security threat, and is thus disabled unless this or the $I{$d$x}$ option is specified. If a shell command fails, GPP emits an error message and exits. +$li$ $BI{$d$x}$ Enable the use of the $I{$dz$exec}$ meta-macro. Since $I{$dz$exec}$ includes the output of an arbitrary shell command line, it may cause a potential -security threat, and is thus disabled unless this option is specified. +security threat, and is thus disabled unless this or the $I{$d$e}$ option is specified. If a shell command fails, GPP ignores it. $li$ $BI{$d$m}$ Enable automatic mode switching to the cpp compatibility mode if the name @@ -871,12 +876,9 @@ $BI{$dz$exec }{command}$ This causes GPP to execute the specified command line and include its standard output in the current output. Note that, for security reasons, this meta-macro -is disabled unless the $I{$d$x}$ command line flag was specified. +is disabled unless the $I{$d$e}$ or $I{$d$x}$ command line flag was specified. If use of $I{$dz$exec}$ is not allowed, a warning message is printed -and the output is left blank. Note that the specified command line is -evaluated before being executed, thus allowing the use of macros in the -command-line. However, the output of the command is included verbatim and -not evaluated. If you need the output to be evaluated, you must use +and the output is left blank. If $I{$dz$exec}$ fails and the $I{$d$e}$ command line flag was specified, GPP emits an error message and exits. If the $I{$d$x}$ command line flag was specified, GPP ignores the failure. Note that the specified command line is evaluated before being executed, thus allowing the use of macros in the command-line. However, the output of the command is included verbatim and not evaluated. If you need the output to be evaluated, you must use $I{$dz$defeval}$ (see above) to cause a double evaluation. $li$ $BI{$dz$eval }{expr}$ diff --git a/src/gpp.c b/src/gpp.c index 1ade1fa..d0935c9 100644 --- a/src/gpp.c +++ b/src/gpp.c @@ -168,6 +168,7 @@ int nmacros, nalloced; char *includedir[MAXINCL]; int nincludedirs; int execallowed; +int popenchecked; int dosmode; int autoswitch; /* must be a format-like string that has % % % in it. @@ -345,7 +346,7 @@ void display_version(void) { } void usage(void) { - printf("Usage : gpp [-{o|O} outfile] [-I/include/path] [-Dname=val ...] [-z] [-x] [-m]\n"); + printf("Usage : gpp [-{o|O} outfile] [-I/include/path] [-Dname=val ...] [-z] [-e] [-x] [-m]\n"); printf(" [-n] [-C | -T | -H | -X | -P | -U ... [-M ...]] [+c str1 str2]\n"); printf(" [+s str1 str2 c] [long options] [infile]\n\n"); printf(" default: #define x y macro(arg,...)\n"); @@ -359,7 +360,8 @@ void usage(void) { printf(" -o : output to outfile\n"); printf(" -O : output to outfile and stdout\n"); printf(" -z : line terminator is CR-LF (MS-DOS style)\n"); - printf(" -x : enable #exec built-in macro\n"); + printf(" -e : enable #exec built-in macro; exit if #exec fails.\n"); + printf(" -x : enable #exec built-in macro; warn if #exec fails.\n"); printf(" -m : enable automatic mode switching upon including .h/.c files\n"); printf(" -n : send LF characters serving as macro terminators to output\n"); printf(" +c : use next 2 args as comment start and comment end sequences\n"); @@ -1244,6 +1246,7 @@ void initthings(int argc, char **argv) { commented[0] = 0; iflevel = 0; execallowed = 0; + popenchecked = 0; autoswitch = 0; dosmode = DEFAULT_CRLF; @@ -1475,6 +1478,9 @@ void initthings(int argc, char **argv) { parseCmdlineDefine(s); free(s); break; + case 'e': + popenchecked = 1; + /* fallthrough */ case 'x': execallowed = 1; break; @@ -2687,12 +2693,17 @@ int ParsePossibleMeta(void) { } f = popen(s, "r"); free(s); - if (f == NULL ) + if (f == NULL ) { + if (popenchecked) + bug("Cannot #exec. Command not found(?)"); + else warning("Cannot #exec. Command not found(?)"); - else { + } else { while ((c = fgetc(f)) != EOF) outchar((char) c); - pclose(f); + + if (pclose(f) != 0 && popenchecked) + bug("Failed #exec process"); } } }