details: https://code.tryton.org/tryton/commit/aa56d08502b0
branch: 8.0
user: Cédric Krier <[email protected]>
date: Wed Sep 30 09:34:18 2026 +0200
description:
Escape arguments of report convert command
Closes #15035
(grafted from 18bd1a03d7459e9ff226c42201d9fdf485ab4bad)
diffstat:
trytond/CHANGELOG | 1 +
trytond/trytond/report/report.py | 21 +++++++++++----------
2 files changed, 12 insertions(+), 10 deletions(-)
diffs (50 lines):
diff -r ec31799caab2 -r aa56d08502b0 trytond/CHANGELOG
--- a/trytond/CHANGELOG Wed Sep 30 09:39:21 2026 +0200
+++ b/trytond/CHANGELOG Wed Sep 30 09:34:18 2026 +0200
@@ -1,3 +1,4 @@
+* Escape arguments of report convert command (issue15035)
* Escape title and text when rendering HTML editor (issue15032)
Version 8.0.10 - 2026-09-16
diff -r ec31799caab2 -r aa56d08502b0 trytond/trytond/report/report.py
--- a/trytond/trytond/report/report.py Wed Sep 30 09:39:21 2026 +0200
+++ b/trytond/trytond/report/report.py Wed Sep 30 09:34:18 2026 +0200
@@ -8,6 +8,7 @@
import operator
import os
import pathlib
+import shlex
import shutil
import subprocess
import tempfile
@@ -449,20 +450,20 @@
'--convert-to "%(output_extension)s" '
'--outdir "%(directory)s" '
'"%(input_path)s"')
- cmd %= {
- 'directory': directory,
- 'input_format': input_format,
- 'input_extension': input_extension,
- 'input_path': input_path,
- 'output_format': output_format,
- 'output_extension': output_extension,
- 'output_path': output_path,
- }
+ args = map(lambda s: s % {
+ 'directory': directory,
+ 'input_format': input_format,
+ 'input_extension': input_extension,
+ 'input_path': input_path,
+ 'output_format': output_format,
+ 'output_extension': output_extension,
+ 'output_path': output_path,
+ }, shlex.split(cmd))
for count in range(retry, -1, -1):
if count != retry:
time.sleep(0.02 * (retry - count))
try:
- subprocess.check_call(cmd, timeout=timeout, shell=True)
+ subprocess.run(args, timeout=timeout, check=True)
except subprocess.CalledProcessError:
if count:
continue