pub fn is_pre_quoted_passthrough_enabled() -> boolExpand description
Whether the legacy pre-quoted passthrough heuristic is active.
Older versions treated a value that happened to start and end with a quote
character as “already quoted” and spliced it into the command as shell
syntax, so the value '/My Documents/x' reached the command as
/My Documents/x - the quotes vanished. sh does the opposite: "$var"
always yields the value verbatim, quote characters included, which is also
what Bun’s $, zx and execa do. Worse, the heuristic could hand the shell
unbalanced quotes, and an injected command ran (issue #41).
The heuristic is therefore off by default; set
COMMAND_STREAM_PREQUOTED_PASSTHROUGH=1 to restore it for code that relies
on hand-quoted values. Even then only values that stay balanced are passed
through, so the injection above can no longer happen.