Apple's libc shells out to Perl to implement wordexp
github.com
github.com
Here's the current implementation: http://opensource.apple.com/source/Libc/Libc-1044.1.2/gen/Fr...
https://github.com/freebsd/freebsd/blob/master/lib/libc/gen/...
It looks very similar to the current OSX file posted in an earlier comment. Calls /bin/sh too.
- this piece of code is 2BSD-licensed
- it calls out to /bin/sh
- on OS X, /bin/sh is hardlinked to /bin/bash
- OS X's bash is GPLv2
Forking to shell is the only way to reuse bash's code. More often than not I really wish sh were not bash.
well, the other obvius way is to license this piece of code as GPLv2.
http://linux.die.net/man/3/wordexp
wordexp, wordfree - perform word expansion like a posix-shell
So, the implementer decided to take the short route, and just spawn a shell which, essentially, gets passed the input data to wordexp(), to do the work. But, of course, having something that starts with such a comment...
/* XXX this is _not_ designed to be fast (...) wordexp is also rife with security "challenges", unless you pass it WRDE_NOCMD it must support subshell expansion, and even if you don't beause it has to support so much of the standard shell (all the odd little variable expansion options for example) it is hard to do without a subshell). It is probably just plan a Bad Idea to call in anything setuid, or executing remotely. */
...in your standard C library wasn't such a smart idea to start with. Scroll down, there are many more gems in the comments!
Sometimes it's better to just implement it as
void wordexp() {
fprintf(stderr,"wordexp() is a security nightmare. Not implemented.\n");
assert(0);
}
or decide to deliberately only implement a safe subset of the full functionality specified (e.g. only ~user-homedir expansion and $VARIABLES), to at least cover the common use-cases without creating a security nightmare.(EDIT: typos)
In an ideal world, we'd have a libsh that exposed all of the steps of what /bin/sh does in a nice fashion, this function would call one of the libsh functions, and /bin/sh would be a 10-line while (true) { libsh_this(); libsh_that(); }.
In a slightly less ideal world, the shell would have a way to separate things with null characters, without bothering Perl.
We really don't live in an ideal world.
But my guess is that most users will call wordexp() just to expand a few variables or tilde-homedirs.
THIS, GODDAMNIT, THIS.
...and what a spelling errors:
"This kludge is needed because /bin/sh seems to set IFS to the defualt even if you have set it; We also can't just ignore it because it is hard/unplesent to code around or even a potential security problem because the test suiete explicitly checks to make sure setting IFS 'works'"
ESR writes about sloppy spelling: "Write in clear, grammatical, correctly-spelled language. We've found by experience that people who are careless and sloppy writers are usually also careless and sloppy at thinking and coding (often enough to bet on, anyway)."
:-\
I searched through the FreeBSD repo on Gitbub and the only references to wordexp is basically the code itself. Searching the whole Github does not show many things either.
How common is the function in practice and how important is it?
common in practice? openbsd doesn't support it. afaik few programs use it, and those that do are usually easily patched not to (can use glob instead or disable whatever feature entirely).
#include <wordexp.h>
#include <stdio.h>
int main() {
wordexp_t we;
char *s = "$(($(sleep 10)))";
printf("->%d\n", wordexp(s, &we, WRDE_NOCMD));
}
(Since the manual page strongly recommends not trusting wordexp with untrusted input even with WRDE_NOCMD, and based on a code search the function is rarely used in the first place, I don't think it's really sensitive.)http://opensource.apple.com/source/Libc/Libc-1044.1.2/gen/Fr...
I mean, let's say this libc thing is supposed to be installed in quite a lot of systems, are we really sure that perl thing is installed in all of those systems? And what if, by some crazy coincidence, perl happens to depend on libc?
Circular dependencies are perfectly normal.
aptitude search '~i~Dperl'Apple's libc is not an independent thing to them - it's a part of OSX and iOS. You're not supposed to be able to take it out and use it for other things.
Also, that code seems to be from 2008 (or at least that's the latest year in the copyright header) despite the commit being from 2012. Does anyone know if this has been updated? Inserting a NUL byte between each word, and at the end doesn't sound like it requires Perl...
/usr/bin/perl:
/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation (compatibility version 150.0.0, current version 1151.14.0)
/usr/lib/libSystem.B.dylib (compatibility version 1.0.0, current version 1213.0.0)
I thought there may be some strange cyclic dependency going on, but it seems not.
No, it's more clever than that. The shell will actually execute something like this:
/usr/bin/perl -e 'print join(chr(0), @ARGV), chr(0)' -- your input string goes here
So, what happens is that the shell (in this case, bash) performs argument expansion on your input string, then calls perl -e '...' with the expanded words as its arguments. What perl does is join all of those arguments with a NUL byte and spit them back out for the calling process to read, which makes figuring out where each expanded "word" begins and ends really simple.
Could you do this in shell? Probably. Would a correct implementation be as short and easy to understand? Probably not. Therefore, perl.
[ $# -gt 0 ] && export IFS="$1";/usr/lib/system/wordexp-helperAlso the source to the Yosemite implementation is available at: http://opensource.apple.com/source/Libc/Libc-1044.1.2/gen/Fr...
And Apple have always been masters in selling polished, nicely packages shit as the most advanced technology ever conceived.
My direct experience is that I have received value far in excess of what I have had to pay for the Apple products and services I have purchased over the years.
For example, I'm typing this reply on my PowerBook, which I use all day, every day in my work. I also have my iPhone with me constantly, and use it heavily.
Finally, the Apple brand was said to be worth about $104.7B vs. $62.8B for Microsoft in 2014. [1]
So, I am not saying you are wrong, only that I think some evidence would be helpful in making your case.
[1] http://bgr.com/2014/03/19/apple-vs-google-vs-microsoft-brand...
That said, I still have an iBook G4 from 2004 in perfect operation for mail/web/music (though one button is missing).