jesseduffield.lazygit/pkg/commands/oscommands/os_windows.go
Vadym d44c7cfe64 fix(windows): set console title via SetConsoleTitleW instead of shelling out to cmd /c title
Fixes #5766.

UpdateWindowTitle built a `title <repo-name> - Lazygit` string and ran it
through `cmd /c "title ..."`. When the current directory's basename contains
a cmd.exe metacharacter such as `&`, cmd.exe treats it as a command
separator: "test&aaa" gets split into `title test` and `aaa`, and cmd.exe
then tries to execute `aaa` as a program. That fails with:

    'aaa' n'est pas reconnu en tant que commande interne ou externe...

which lazygit's error handling surfaced as an uncaught error, crashing the
whole run (and, per the second half of the report, closing the parent
shell). This reproduces both ways described in the issue: launching lazygit
directly inside a folder with '&' in its name, and opening such a repo from
the recent-repos menu.

Fix

UpdateWindowTitle now calls the Win32 SetConsoleTitleW API directly via
syscall.NewLazyDLL/kernel32.dll (the same mechanism pkg/gocui/gui_windows.go
already uses for GetConsoleScreenBufferInfo), instead of building a shell
command string and handing it to cmd.exe. This sidesteps cmd.exe's argument
parsing entirely — the title is passed to the OS as a UTF-16 string, so it's
set verbatim regardless of what characters the directory name contains. No
shell, no quoting rules, no injection surface.

Testing

    go build ./...
    GOOS=windows GOARCH=amd64 go build ./...
    GOOS=windows GOARCH=amd64 go vet ./pkg/commands/oscommands/...
    GOOS=windows GOARCH=amd64 go test -c ./pkg/commands/oscommands/   # compiles
    go test ./pkg/commands/oscommands/... -v                          # passes on darwin
    go test <all non-integration packages> -count=1                  # all green

I don't have a Windows machine to run the test binary on directly, but I
cross-compiled the package (and its test binary) for windows/amd64 to
confirm it builds and type-checks cleanly, and the two new tests below will
execute for real on the windows-latest CI runner this repo already uses.

New tests in pkg/commands/oscommands/os_windows_test.go (windows-only,
build-tagged, same as the existing file):
- TestUpdateWindowTitle_NameWithAmpersand: chdirs into a directory named
  "test&aaa" (the exact string from the report) and asserts
  UpdateWindowTitle no longer errors, then reads the title back with
  GetConsoleTitleW and asserts it's the literal, unsplit directory name -
  reproducing #5766 and proving it's fixed.
- TestUpdateWindowTitle_PlainName: sanity check that the ordinary case
  (no special characters) still produces the expected "<name> - Lazygit"
  title.

Both tests skip gracefully (rather than fail) if GetConsoleTitleW is
unavailable in the CI environment (e.g. no attached console), so they can't
produce a false failure unrelated to this fix.
2026-07-23 18:37:51 +02:00

75 lines
2.2 KiB
Go

package oscommands
import (
"fmt"
"os"
"os/exec"
"path/filepath"
"syscall"
"unsafe"
)
// setRawCmdLine hands cmd.exe the exact command line we built, bypassing
// os/exec's default composition (which quotes args with the
// CommandLineToArgvW `\"` convention that cmd.exe doesn't understand).
//
// The shell-building logic in NewShell is portable and dispatches on
// platform.OS, which keeps it (and its quoting) unit-testable on any host.
// Assigning SysProcAttr.CmdLine is the only step that needs a Windows-only
// field, so it's the single piece split out behind a build tag; every other
// platform gets the no-op in os_default_platform.go.
func setRawCmdLine(cmd *exec.Cmd, cmdLine string) {
if cmd.SysProcAttr == nil {
cmd.SysProcAttr = &syscall.SysProcAttr{}
}
cmd.SysProcAttr.CmdLine = cmdLine
}
func GetPlatform() *Platform {
return &Platform{
OS: "windows",
Shell: "cmd",
ShellArg: "/c",
}
}
var (
kernel32 = syscall.NewLazyDLL("kernel32.dll")
procSetConsoleTitle = kernel32.NewProc("SetConsoleTitleW")
)
// UpdateWindowTitle sets the console window title directly via the
// SetConsoleTitleW Win32 API instead of shelling out to `cmd /c title ...`.
//
// The repo name is attacker/user-controlled input (it's just the current
// directory's basename), and cmd.exe treats characters such as & as command
// separators. A directory named e.g. "test&aaa" would previously be split
// into two commands ("title test" and "aaa"), and cmd.exe would then try to
// run "aaa" as a program, printing an error to stderr that crashed the run
// (see #5766). Calling the Win32 API directly sidesteps cmd.exe's argument
// parsing entirely: the title string is passed as-is, verbatim, regardless
// of what characters it contains.
func (c *OSCommand) UpdateWindowTitle() error {
path, getWdErr := os.Getwd()
if getWdErr != nil {
return getWdErr
}
title := fmt.Sprint(filepath.Base(path), " - Lazygit")
titlePtr, err := syscall.UTF16PtrFromString(title)
if err != nil {
return err
}
r1, _, callErr := procSetConsoleTitle.Call(uintptr(unsafe.Pointer(titlePtr)))
if r1 == 0 {
return callErr
}
return nil
}
func TerminateProcessGracefully(proc *os.Process) error {
// Signals other than SIGKILL are not supported on Windows
return nil
}