Repository navigation
v2.0.1
Security fix: shell command injection eliminated
- Removed the
/bin/sh -c/cmd.exe /cwrapper layer: user input is never handed to any shell interpreter - Commands are tokenized with
shlex.split(); unclosed quotes return a format error and nothing is executed; empty commands are rejected - Blacklist / allowlist are matched against the real program name (
cmd_list[0]), not the raw input string; config fieldsblacklist/allowlist/enforce_allowlistunchanged - Executed via
subprocess.Popen(cmd_list, shell=False); streaming output, per-command timeout with automatic kill, stderr capture and audit log fully preserved; status markers[INFO]/[OK]/[FAIL]
Breaking change
In-game commands no longer support shell built-in syntax (pipes, redirections, wildcards, ;, &&, ||, $(), backticks). For complex logic, write a shell script, put it in the allowlist and run it by name. See README.