details:   https://code.tryton.org/tryton/commit/18bd1a03d745
branch:    default
user:      Cédric Krier <[email protected]>
date:      Wed Sep 30 09:34:18 2026 +0200
description:
        Escape arguments of report convert command

        Closes #15035
diffstat:

 trytond/CHANGELOG                |   1 +
 trytond/trytond/report/report.py |  21 +++++++++++----------
 2 files changed, 12 insertions(+), 10 deletions(-)

diffs (50 lines):

diff -r 0c76d2bc7558 -r 18bd1a03d745 trytond/CHANGELOG
--- a/trytond/CHANGELOG Wed Sep 30 09:39:21 2026 +0200
+++ b/trytond/CHANGELOG Wed Sep 30 09:34:18 2026 +0200
@@ -1,3 +1,4 @@
+* Escape arguments of report convert command (issue15035)
 * Escape title and text when rendering HTML editor (issue15032)
 * Allow trytond-admin to manage any user
 * Add bulk_create, bulk_delete, bulk_save and bulk_func to ModelStorage
diff -r 0c76d2bc7558 -r 18bd1a03d745 trytond/trytond/report/report.py
--- a/trytond/trytond/report/report.py  Wed Sep 30 09:39:21 2026 +0200
+++ b/trytond/trytond/report/report.py  Wed Sep 30 09:34:18 2026 +0200
@@ -8,6 +8,7 @@
 import operator
 import os
 import pathlib
+import shlex
 import shutil
 import subprocess
 import tempfile
@@ -451,20 +452,20 @@
                 '--convert-to "%(output_extension)s" '
                 '--outdir "%(directory)s" '
                 '"%(input_path)s"')
-            cmd %= {
-                'directory': directory,
-                'input_format': input_format,
-                'input_extension': input_extension,
-                'input_path': input_path,
-                'output_format': output_format,
-                'output_extension': output_extension,
-                'output_path': output_path,
-                }
+            args = map(lambda s: s % {
+                    'directory': directory,
+                    'input_format': input_format,
+                    'input_extension': input_extension,
+                    'input_path': input_path,
+                    'output_format': output_format,
+                    'output_extension': output_extension,
+                    'output_path': output_path,
+                    }, shlex.split(cmd))
             for count in range(retry, -1, -1):
                 if count != retry:
                     time.sleep(0.02 * (retry - count))
                 try:
-                    subprocess.check_call(cmd, timeout=timeout, shell=True)
+                    subprocess.run(args, timeout=timeout, check=True)
                 except subprocess.CalledProcessError:
                     if count:
                         continue

Reply via email to