de1b92
From ff8028c4d95425faa5b0705b8ed8c84b1112c7e4 Mon Sep 17 00:00:00 2001
de1b92
From: =?UTF-8?q?Petr=20P=C3=ADsa=C5=99?= <ppisar@redhat.com>
de1b92
Date: Wed, 2 Aug 2017 17:29:13 +0200
de1b92
Subject: [PATCH] Use exucatable name as a source of taintedness
de1b92
MIME-Version: 1.0
de1b92
Content-Type: text/plain; charset=UTF-8
de1b92
Content-Transfer-Encoding: 8bit
de1b92
de1b92
Test::Simple >= 1.302065 injects variables into the environment. These
de1b92
are not tainted and caused a random t/07_taint.t test failures.
de1b92
de1b92
This patch fixes it by using executable name $0 instead.
de1b92
de1b92
https://github.com/pjf/ipc-system-simple/issues/21
de1b92
Signed-off-by: Petr Písař <ppisar@redhat.com>
de1b92
---
de1b92
 t/07_taint.t | 4 ++--
de1b92
 1 file changed, 2 insertions(+), 2 deletions(-)
de1b92
de1b92
diff --git a/t/07_taint.t b/t/07_taint.t
de1b92
index 49cee12..be449cd 100644
de1b92
--- a/t/07_taint.t
de1b92
+++ b/t/07_taint.t
de1b92
@@ -17,8 +17,8 @@ use_ok("IPC::System::Simple","run","capture");
de1b92
 
de1b92
 chdir("t");     # Ignore return, since we may already be in t/
de1b92
 
de1b92
-my $taint = $ENV{(keys(%ENV))[0]} . "foo";	# ."foo" to avoid zero length
de1b92
-ok(tainted($taint),"Sanity - ENV vars are tainted");
de1b92
+my $taint = $0 . "foo";	# ."foo" to avoid zero length
de1b92
+ok(tainted($taint),"Sanity - executable name is tainted");
de1b92
 
de1b92
 my $evil_zero = 1 - (length($taint) / length($taint));
de1b92
 
de1b92
-- 
de1b92
2.9.4
de1b92