diff options
Diffstat (limited to '')
| -rwxr-xr-x | transcode.sh | 114 |
1 files changed, 60 insertions, 54 deletions
diff --git a/transcode.sh b/transcode.sh index 129ba88..3f317e6 100755 --- a/transcode.sh +++ b/transcode.sh @@ -477,13 +477,13 @@ load_config() { fi # We use -r and not -f to allow things like /dev/null - [[ -r "$CONFIG_FILE" ]] || { + if [[ ! -r "$CONFIG_FILE" ]]; then if [[ $_CLI_CONFIG_FILE -eq 1 ]]; then error "Config file not found:" "$CONFIG_FILE" exit $EXIT_CONFIG_ERROR fi return 0 - } + fi command -v tomlq >/dev/null 2>&1 || { error "tomlq not found but $CONFIG_FILE exists. Install tomlq or remove the config file." @@ -676,20 +676,21 @@ parse_skip_codec_parameter() { # output_pixel_format, input_pixel_format, input_codec, input_frame_rate, # input_fps, output_gop_size load_preset() { - local preset="$1" - # Strict allowlist: only alphanumerics, hyphens, and underscores are permitted. - # This prevents path traversal, shell metacharacter injection, and symlink-based - # attacks more reliably than a blocklist approach. - if [[ -z "$preset" || ! "$preset" =~ ^[a-zA-Z0-9_-]+$ ]]; then - error "Invalid preset name (only alphanumerics, hyphens, underscores allowed):" "$preset" + local preset_name="$1" + + # Strict allowlist: only alphanumerics, hyphens, and underscores are + # permitted. This prevents path traversal, shell metacharacter injection, and + # symlink-based attacks more reliably than a blocklist approach. + if [[ -z "$preset_name" || ! "$preset_name" =~ ^[a-zA-Z0-9_-]+$ ]]; then + error "Invalid preset name (only alphanumerics, hyphens, underscores allowed):" "$preset_name" exit $EXIT_USAGE_ERROR fi - local file="$PRESET_DIR/$preset.sh" - [[ -f "$file" ]] || { + local file="$PRESET_DIR/$preset_name.sh" + if [[ ! -f "$file" ]]; then error "Preset not found:" "$file" exit $EXIT_CONFIG_ERROR - } + fi # Reject preset files that are world-writable to prevent arbitrary users from # injecting shell code. @@ -716,10 +717,10 @@ load_preset() { # shellcheck source=/dev/null source "$file" - ((${#ffargs[@]})) || { - error "Preset '$preset' did not set ffargs" + if [[ ${#ffargs[@]} -eq 0 ]]; then + error "Preset '$preset_name' did not set ffargs" exit $EXIT_RUNTIME_FAILURE - } + fi debug "Preset ffargs:" "$(printf "%q " "${ffargs[@]}")" } @@ -852,23 +853,23 @@ while [[ $# -gt 0 ]]; do shift ;; --config-file) - [[ $# -ge 2 ]] || { + if [[ $# -lt 2 ]]; then error "Missing value for $1" exit $EXIT_USAGE_ERROR - } - [[ -n "$2" ]] || { + fi + if [[ ! -n "$2" ]]; then error "Value for $1 must not be empty" exit $EXIT_USAGE_ERROR - } + fi CONFIG_FILE="$2" _CLI_CONFIG_FILE=1 shift 2 ;; --config-file=*) - [[ -n "${1#*=}" ]] || { + if [[ ! -n "${1#*=}" ]]; then error "Value for --config-file must not be empty" exit $EXIT_USAGE_ERROR - } + fi CONFIG_FILE="${1#*=}" _CLI_CONFIG_FILE=1 shift @@ -879,22 +880,22 @@ while [[ $# -gt 0 ]]; do shift ;; -f | --encode-file) - [[ $# -ge 2 ]] || { + if [[ $# -lt 2 ]]; then error "Missing value for $1" exit $EXIT_USAGE_ERROR - } - [[ -n "$2" ]] || { + fi + if [[ ! -n "$2" ]]; then error "Value for $1 must not be empty" exit $EXIT_USAGE_ERROR - } + fi ENCODE_FILE="$2" shift 2 ;; --encode-file=*) - [[ -n "${1#*=}" ]] || { + if [[ ! -n "${1#*=}" ]]; then error "Value for --encode-file must not be empty" exit $EXIT_USAGE_ERROR - } + fi ENCODE_FILE="${1#*=}" shift ;; @@ -903,10 +904,10 @@ while [[ $# -gt 0 ]]; do shift ;; -N | --nice) - [[ $# -ge 2 ]] || { + if [[ $# -lt 2 ]]; then error "Missing value for $1" exit $EXIT_USAGE_ERROR - } + fi NICE_VALUE="$2" _CLI_NICE=1 shift 2 @@ -927,32 +928,32 @@ while [[ $# -gt 0 ]]; do shift ;; --size-report-file) - [[ $# -ge 2 ]] || { + if [[ $# -lt 2 ]]; then error "Missing value for $1" exit $EXIT_USAGE_ERROR - } - [[ -n "$2" ]] || { + fi + if [[ ! -n "$2" ]]; then error "Value for $1 must not be empty" exit $EXIT_USAGE_ERROR - } + fi SIZE_REPORT_FILE="$2" _CLI_SIZE_REPORT_FILE=1 shift 2 ;; --size-report-file=*) - [[ -n "${1#*=}" ]] || { + if [[ ! -n "${1#*=}" ]]; then error "Value for --size-report-file must not be empty" exit $EXIT_USAGE_ERROR - } + fi SIZE_REPORT_FILE="${1#*=}" _CLI_SIZE_REPORT_FILE=1 shift ;; -S | --skip-codec) - [[ $# -ge 2 ]] || { + if [[ $# -lt 2 ]]; then error "Missing value for $1" exit $EXIT_USAGE_ERROR - } + fi parse_skip_codec_parameter "$2" shift 2 ;; @@ -986,10 +987,10 @@ while [[ $# -gt 0 ]]; do --hwaccel=*) HWACCEL=1 HWACCEL_VALUE="${1#*=}" - [[ -n "$HWACCEL_VALUE" ]] || { + if [[ ! -n "$HWACCEL_VALUE" ]]; then error "Value for --hwaccel must not be empty" exit $EXIT_USAGE_ERROR - } + fi _CLI_HWACCEL=1 shift ;; @@ -999,23 +1000,23 @@ while [[ $# -gt 0 ]]; do shift ;; -p | --preset) - [[ $# -ge 2 ]] || { + if [[ $# -lt 2 ]]; then error "Missing value for $1" exit $EXIT_USAGE_ERROR - } - [[ -n "$2" ]] || { + fi + if [[ ! -n "$2" ]]; then error "Value for $1 must not be empty" exit $EXIT_USAGE_ERROR - } + fi PRESET_NAME="$2" _CLI_PRESET=1 shift 2 ;; --preset=*) - [[ -n "${1#*=}" ]] || { + if [[ ! -n "${1#*=}" ]]; then error "Value for --preset must not be empty" exit $EXIT_USAGE_ERROR - } + fi PRESET_NAME="${1#*=}" _CLI_PRESET=1 shift @@ -1075,7 +1076,7 @@ if [[ $_CLI_SIZE_REPORT_FILE -eq 1 && $SIZE_REPORT -eq 0 ]]; then warn "--size-report-file has no effect without --size-report" fi -if [[ ! "$NICE_VALUE" =~ ^-?[0-9]+$ ]] || ((NICE_VALUE < -20 || NICE_VALUE > 19)); then +if [[ ! "$NICE_VALUE" =~ ^-?[0-9]+$ || $NICE_VALUE -lt -20 || $NICE_VALUE -gt 19 ]]; then error "Invalid nice value (must be an integer between -20 and 19):" "$NICE_VALUE" exit $EXIT_USAGE_ERROR fi @@ -1116,7 +1117,9 @@ calculate_saved_percentage() { # Empty byte/percentage fields are allowed for failures where no output size # exists. append_size_report_row() { - [[ $SIZE_REPORT -eq 1 && $DRY_RUN -eq 0 ]] || return $EXIT_OK + if [[ $SIZE_REPORT -ne 1 || $DRY_RUN -ne 0 ]]; then + return $EXIT_OK + fi local status="$1" local filename="$2" @@ -1135,10 +1138,12 @@ append_size_report_row() { printf "%s\t%s\t%s\t%s\t%s\n" "$status" "$filename" "$original_bytes" "$new_bytes" "$saved_pct" >>"$SIZE_REPORT_FILE" } -# Print per-file size feedback after an encode attempt that produced an output file. +# Print per-file size feedback after an encode attempt that produced an output +# file. print_size_report_feedback() { - [[ $SIZE_REPORT -eq 1 ]] || return $EXIT_OK - + if [[ $SIZE_REPORT -eq 0 ]]; then + return $EXIT_OK + fi local status="$1" local original_bytes="$2" local new_bytes="$3" @@ -1154,16 +1159,17 @@ print_size_report_feedback() { print_size_report_summary() { local amount_total_files="$1" - [[ $SIZE_REPORT -eq 1 && $QUIET -eq 0 && $amount_total_files -gt 1 ]] || return $EXIT_OK + if [[ $SIZE_REPORT -ne 1 || $QUIET -ne 0 || $amount_total_files -le 1 ]]; then + return $EXIT_OK + fi local skipped_total failed_total average_saved_pct skipped_total=$((_REPORT_SKIPPED_CODEC + _REPORT_SKIPPED_LARGER)) failed_total=$((_REPORT_ENCODING_FAILED + _REPORT_INTEGRITY_FAILED)) + average_saved_pct=0 if [[ $_REPORT_TOTAL_ORIGINAL_BYTES -gt 0 ]]; then average_saved_pct=$((_REPORT_TOTAL_SAVED_BYTES * 100 / _REPORT_TOTAL_ORIGINAL_BYTES)) - else - average_saved_pct=0 fi printf "\n${BOLD}${BLUE}Size report summary:${ALL_OFF}\n" @@ -1452,10 +1458,10 @@ encode_one() { STATUS=$EXIT_OK if [[ -n $ENCODE_FILE ]]; then - [[ -f "$ENCODE_FILE" ]] || { + if [[ ! -f "$ENCODE_FILE" ]]; then error "Encode file not found:" "$ENCODE_FILE" exit $EXIT_USAGE_ERROR - } + fi # Build the file list into an array first so we know the total count. mapfile -t FILES_TO_ENCODE < <( while IFS= read -r file || [[ -n "$file" ]]; do |
