App macros silently did nothing on Windows: shlex.split(posix=False) kept quotes in the exe path. Fix passes the command string to Popen on Windows (CreateProcess handles quoting, still no shell); POSIX keeps shlex.split. Bumps to 1.1.1.
App macros silently did nothing on Windows: shlex.split(posix=False) kept quotes in the exe path. Fix passes the command string to Popen on Windows (CreateProcess handles quoting, still no shell); POSIX keeps shlex.split. Bumps to 1.1.1.
When shell=True was removed for security, the command was parsed with
shlex.split(posix=False) on Windows, which keeps the quote characters inside
the tokens — so a quoted path like "C:\Program Files\app.exe" became an argv[0]
containing literal quotes and CreateProcess couldn't find it, so app macros
silently did nothing.
Fix: on Windows pass the command string to Popen (shell=False) and let
CreateProcess parse it (handles quoted paths, still no shell/metacharacter
chaining); on POSIX keep shlex.split. Verified a real launch works and shell
redirection stays blocked.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
jknapp
merged commit 62559a59c9 into main2026-07-18 05:59:36 +00:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
App macros silently did nothing on Windows: shlex.split(posix=False) kept quotes in the exe path. Fix passes the command string to Popen on Windows (CreateProcess handles quoting, still no shell); POSIX keeps shlex.split. Bumps to 1.1.1.