Zsh Mailing List Archive
Messages sorted by:
Reverse Date,
Date,
Thread,
Author
Re: Security issue in Zsh restricted mode (zsh -r) – escape via history built‑ins
- X-seq: zsh-workers 54184
- From: Bart Schaefer <schaefer@xxxxxxxxxxxxxxxx>
- To: cyber security <cs7778503@xxxxxxxxx>
- Cc: zsh-workers@xxxxxxx
- Subject: Re: Security issue in Zsh restricted mode (zsh -r) – escape via history built‑ins
- Date: Wed, 11 Feb 2026 10:10:03 -0800
- Arc-authentication-results: i=1; mx.google.com; arc=none
- Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:dkim-signature; bh=DRSGTzHvl7MXxqQm4eaePF+xoqhnFRS+lil8VXsrbYw=; fh=o3KcVA6EPPy/srL4SlkuJTSO8k8d/HLSdxMU/iq81dU=; b=ghY2TPy7Jt2rB1S/DMh/opYkWItZqoLVHWfz44bL+djRs5ZFXNScjCI22Ac//sYDpc jpPW69pRl2WfzA3ow02B4w+vQuY5hur/Z7aSfTdwhsJKPsxqYq7mcABq+G9/pQNlPfux rVOb/UJlW9iH7+il90bYjGU6Ye+fVhU0ukCNFMi6N8h2ujpBoHqd1GxyjQdg/zSG2O+s 4dNuH3rrjMD4YU3b1W2JuVwnq6/a5V1P7VnYsXAZahboGFpSJzrmt8QkNuj/L/b03y6G bPAKI7UGJYhgOETUJiCLwJaYldMCTeDUnTO9XnpbiZDB1DNmZmhubJpbjeK59bSxgH9m 2d1g==; darn=zsh.org
- Arc-seal: i=1; a=rsa-sha256; t=1770833414; cv=none; d=google.com; s=arc-20240605; b=MXvCtzJ2z8f9j3OX/jmLNPPsR73M18lt1II3E/zAcrXluVVqgjatVZ/Rp5E4d/PHzy D9dzr8coQjn7k2p/yr9lNa6b3X1D9pW6StotS36lecbBH4jDlSHJ/GmaphSqqmhNbrrx TlUZ1JCe25bcQbVS6ks0IchgWyzrDHcZi01j/hPT8jqSpro6EA4O1ezD7HM64VOLjuY0 40dOTxmTKk4s055sVYrmkG6U7VguItuwlUH74A0bk83iIDzJS7jHPPgsyx27e2qiIPam mcYJzyJ+RsgSYZgm8rOohxmIjiYfQQdScF0strGCknG4weyaH6k5Jm/fLEIZQld8e+9H V+BQ==
- Archived-at: <https://zsh.org/workers/54184>
- In-reply-to: <CAPmip_w7x6Q2OQpyL-bzxvhZzXCUPh+P-xfex+8okMDqK=a3nQ@mail.gmail.com>
- List-id: <zsh-workers.zsh.org>
- References: <CAPmip_z18_wQBZ09GG7TEKZ0GsTqQ34iZRvhsMAExOLSCcdQsg@mail.gmail.com> <72787-1769800688.979791@U6Lk.sn9M.AyYc> <CAHYJk3T4W+U3mCzqGB7LUkJp-JuUSiEBNe4hx0e-=zMyZQuPGQ@mail.gmail.com> <62255-1769947817.277408@Fj-1.JoGb.8iVT> <59616-1770769280.438132@XTM7.n7uI.5s3U> <CAPmip_w7x6Q2OQpyL-bzxvhZzXCUPh+P-xfex+8okMDqK=a3nQ@mail.gmail.com>
On Tue, Feb 10, 2026 at 10:14 PM cyber security <cs7778503@xxxxxxxxx> wrote:
>
> I agree with you. Yes disable those local functions!
If you're referring to this ...
> > dnl Do you want to disable use of locale functions
> > AH_TEMPLATE([CONFIG_LOCALE],
> > [Undefine if you don't want local features. By default this is defined.])
That's *locale* as in the ability to select different languages,
different collation order, etc. Also, it's not part of the diffs,
just part of the context.
I think the reference to "local features" in the explanatory text is a typo.
Messages sorted by:
Reverse Date,
Date,
Thread,
Author