From 731a25e096cf9af3c0c5b3303796df7b3e91df36 Mon Sep 17 00:00:00 2001 From: Dennis Fink Date: Sun, 27 Sep 2026 21:13:54 +0200 Subject: fix(commands): quote command arguments in diagnostics Format executed commands with shlex.join() so debug and error messages preserve argument boundaries and shell quoting. Reuse the formatted command string for both command logging and failure reporting. --- prometheus_pacman_exporter/__init__.py | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) (limited to 'prometheus_pacman_exporter') diff --git a/prometheus_pacman_exporter/__init__.py b/prometheus_pacman_exporter/__init__.py index 3e29849..0125187 100644 --- a/prometheus_pacman_exporter/__init__.py +++ b/prometheus_pacman_exporter/__init__.py @@ -135,12 +135,13 @@ def run_command( :param accepted_exit_codes: Exit codes considered successful. :return: Completed process with stdout and stderr captured. """ - debug("Running command", " ".join(command), err=True) + command_string = shlex.join(command) + debug("Running command", command_string, err=True) result = subprocess.run(command, capture_output=True, encoding="utf-8", check=False) if result.returncode not in accepted_exit_codes: error( - f"Command ({' '.join(command)}) failed with exit code {result.returncode}" + f"Command ({command_string}) failed with exit code:", str(result.returncode) ) if result.stderr: error("stderr:", result.stderr.strip()) -- cgit v1.3.1