Skip to content

SC2016: allow single quotes for sh -c script run via another command - #3551

Open
kolyshkin wants to merge 1 commit into
koalaman:masterfrom
kolyshkin:sc2016-sh-c
Open

kolyshkin wants to merge 1 commit into
koalaman:masterfrom
kolyshkin:sc2016-sh-c

Conversation

@kolyshkin

@kolyshkin kolyshkin commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

SC2016 is not emitted for single-quoted strings passed to commands like
sh, bash, sudo or docker, as those are commonly used to pass a
script to a shell. This only works when such a command is the one being
run, missing many other cases where a shell is run via a wrapper, e.g.

runc exec ctr sh -c 'echo $HOME'
xargs -I{} sh -c 'echo $PWD/{}'
nsenter -t 1 -m bash -eu -o pipefail -c 'echo $HOME'
kubectl exec pod -- sh -euc 'echo $HOME'
run --separate-stderr bash -c 'echo $HOME'   # bats

Do not emit SC2016 for a single-quoted argument which immediately
follows a shell (sh, bash, dash, ash, ksh, ksh88, ksh93, mksh, oksh,
zsh)
invocation with options, the last of which contains c (like -c or
-euc). Other arguments (e.g. sh -x '...', sh script -c '...', or
a second single-quoted argument after the script) are still reported.

Tested on runc's integration tests: no new warnings, and 6 out of 17
# shellcheck disable=SC2016 annotations become unnecessary.

Fixes #1894
Fixes #3222

…mand

SC2016 is not emitted for single-quoted strings passed to commands like
sh, bash, sudo or docker, as those are commonly used to pass a script
to a shell. This only works when such a command is the one being run,
missing many other cases where a shell is run via a wrapper, such as

	runc exec ctr sh -c 'echo $HOME'
	nsenter -t 1 -m bash -eu -o pipefail -c 'echo $HOME'
	kubectl exec pod -- sh -euc 'echo $HOME'

Do not emit SC2016 for a single-quoted argument which immediately
follows a shell (sh, bash, dash, etc.) invocation with options ending
with one containing -c.

Signed-off-by: Kir Kolyshkin <kolyshkin@gmail.com>
@kolyshkin

Copy link
Copy Markdown
Contributor Author

@e-kwsm @koalaman PTAL (relatively simple fix which makes sense).

isShellInvocation _ = False
endsWithDashC opts =
case opts of
[flag] -> "-" `isPrefixOf` flag && not ("--" `isPrefixOf` flag) && 'c' `elem` flag

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
[flag] -> "-" `isPrefixOf` flag && not ("--" `isPrefixOf` flag) && 'c' `elem` flag
[flag] -> flag `matches` mkRegex "^-[a-zA-Z]*c[a-zA-Z]*$"

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BATS] Inconsistent SC2016 when using run Invalid SC2016 for xargs sh -c '$PWD'

2 participants