Re: 'safe' printing to the terminal

[email protected] (Russ Allbery) Mon, 11 May 2026 09:07:05 -0700
Newsgroups perl.perl5.porters
Organization The Eyrie
Message-ID <[email protected]>
Michiel Beijen <[email protected]> writes:

> I feel 'printing of untrusted output to the terminal' is something that
> should have a de-facto solution in core perl; would it be weird to want
> to have a 'standard' solution for this?

I think this would be a very good idea. There have been a pretty
consistent stream of security reports about inadequate escaping, and most
people don't realize how many weird things can be done with terminal
escape sequences.

I would go one step farther and would add that it would be a good idea to
provide some sort of pragma that automatically escapes the output of die
and warn, given how frequently untrusted data such as potentially
attacker-controlled file names are embedded in those messages via string
interpolation.

-- 
#!/usr/bin/perl -- Russ Allbery, Just Another Perl Hacker
$^=q;@!>~|{>krw>yn{u<$$<[~||<Juukn{=,<S~|}<Jwx}qn{<Yn{u<Qjltn{ > 0gFzD gD,
 00Fz, 0,,( 0hF 0g)F/=, 0> "L$/GEIFewe{,$/ 0C$~> "@=,m,|,(e 0.), 01,pnn,y{
rw} >;,$0=q,$,,($_=$^)=~y,$/ C-~><@=\n\r,-~$:-u/ #y,d,s,(\$.),$1,gee,print