summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorDennis Fink2026-02-25 09:16:23 +0100
committerDennis Fink2026-02-25 09:16:23 +0100
commitb10b81fefbe529be7db14ca65ec4b4a293782d39 (patch)
tree807ed5ed084cded51ae3be85da965ce9d5e4705b
parent48e3265ea845437bce4c4895275470e8a1776073 (diff)
downloadtranscode.sh-b10b81fefbe529be7db14ca65ec4b4a293782d39.tar.gz
transcode.sh-b10b81fefbe529be7db14ca65ec4b4a293782d39.zip
refactor(preset): return ffargs via nameref instead of global variable
load_preset now accepts the name of the caller's array as a second argument and populates it via a nameref (local -n), replacing the previous implicit global ffargs. The preset is sourced into a local ffargs contained within load_preset's scope and copied to the caller on return. encode_one declares its own local ffargs=() and passes its name to load_preset, making the data flow explicit and eliminating the implicit coupling through the global. The nameref variable is prefixed with an underscore to avoid accidental aliasing of any same-named local in the calling scope.
-rwxr-xr-xtranscode.sh18
1 files changed, 15 insertions, 3 deletions
diff --git a/transcode.sh b/transcode.sh
index f3b5a4a..6b0bb22 100755
--- a/transcode.sh
+++ b/transcode.sh
@@ -339,6 +339,10 @@ fi
# Load ffmpeg argument preset by name.
#
+# Arguments:
+# $1 - preset name
+# $2 - name of the caller's array variable to populate (nameref)
+#
# Security:
# Presets are sourced as shell code. Names are validated against a strict
# allowlist (alphanumerics, hyphens, underscores only) to prevent path
@@ -350,8 +354,12 @@ fi
# The sourced preset MUST set the bash array `ffargs`.
# Presets may reference variables from the caller (encode_one) such as:
# output_pixel_format, input_pixel_format, input_codec
+# On return the caller's array (named by $2) is populated with the preset's
+# ffargs; the preset-local `ffargs` variable is unset before returning.
load_preset() {
local preset="$1"
+ local -n _load_preset_out="$2"
+
# Strict allowlist: only alphanumerics, hyphens, and underscores are permitted.
# This prevents path traversal, shell metacharacter injection, and symlink-based
# attacks more reliably than a blocklist approach.
@@ -381,8 +389,7 @@ load_preset() {
exit $EXIT_CONFIG_ERROR
fi
- unset -v ffargs
- ffargs=()
+ local ffargs=()
debug "Sourcing preset file:" "$file"
@@ -395,6 +402,8 @@ load_preset() {
}
debug "Preset ffargs:" "$(printf "%q " "${ffargs[@]}")"
+
+ _load_preset_out=("${ffargs[@]}")
}
if [[ $# -eq 0 ]]; then
@@ -685,7 +694,10 @@ encode_one() {
fi
debug "Selected output pixel format:" "$output_pixel_format"
- load_preset "$PRESET_NAME"
+ # Load preset early so a missing/invalid preset fails before we create a
+ # temp file or do any further work.
+ local ffargs=()
+ load_preset "$PRESET_NAME" ffargs
local extension filename directory tmp base stem