a058e0
From ff8028c4d95425faa5b0705b8ed8c84b1112c7e4 Mon Sep 17 00:00:00 2001
a058e0
From: =?UTF-8?q?Petr=20P=C3=ADsa=C5=99?= <ppisar@redhat.com>
a058e0
Date: Wed, 2 Aug 2017 17:29:13 +0200
a058e0
Subject: [PATCH] Use exucatable name as a source of taintedness
a058e0
MIME-Version: 1.0
a058e0
Content-Type: text/plain; charset=UTF-8
a058e0
Content-Transfer-Encoding: 8bit
a058e0
a058e0
Test::Simple >= 1.302065 injects variables into the environment. These
a058e0
are not tainted and caused a random t/07_taint.t test failures.
a058e0
a058e0
This patch fixes it by using executable name $0 instead.
a058e0
a058e0
https://github.com/pjf/ipc-system-simple/issues/21
a058e0
Signed-off-by: Petr Písař <ppisar@redhat.com>
a058e0
---
a058e0
 t/07_taint.t | 4 ++--
a058e0
 1 file changed, 2 insertions(+), 2 deletions(-)
a058e0
a058e0
diff --git a/t/07_taint.t b/t/07_taint.t
a058e0
index 49cee12..be449cd 100644
a058e0
--- a/t/07_taint.t
a058e0
+++ b/t/07_taint.t
a058e0
@@ -17,8 +17,8 @@ use_ok("IPC::System::Simple","run","capture");
a058e0
 
a058e0
 chdir("t");     # Ignore return, since we may already be in t/
a058e0
 
a058e0
-my $taint = $ENV{(keys(%ENV))[0]} . "foo";	# ."foo" to avoid zero length
a058e0
-ok(tainted($taint),"Sanity - ENV vars are tainted");
a058e0
+my $taint = $0 . "foo";	# ."foo" to avoid zero length
a058e0
+ok(tainted($taint),"Sanity - executable name is tainted");
a058e0
 
a058e0
 my $evil_zero = 1 - (length($taint) / length($taint));
a058e0
 
a058e0
-- 
a058e0
2.9.4
a058e0