Created SC1098 (markdown)

koalaman
2015-09-02 21:08:26 -07:00
parent 0df90eacc3
commit 2ff0e3e751

24
SC1098.md Normal file

@@ -0,0 +1,24 @@
## Quote/escape special characters when using eval, e.g. eval "a=(b)".
### Problematic code:
eval $var=(a b)
### Correct code:
eval "$var=(a b)"
### Rationale:
Shells differ widely in how they handle unescaped parentheses in `eval` expressions.
* `eval foo=bar` is allowed by dash, bash and ksh.
* `eval foo=(bar)` is allowed by bash and ksh, but not dash.
* `eval $var=(bar)` is allowed by ksh, but not bash or dash.
* `eval foo() ( echo bar; )` is not allowed by any shell.
Since the expression is evaluated as shell script code anyways, it should be passed in as a literal string without relying on special case parsing rules in the target shell. Quote or escape the characters appropriately.
### Exceptions:
None.