diff options
| -rwxr-xr-x | transcode.sh | 18 |
1 files changed, 15 insertions, 3 deletions
diff --git a/transcode.sh b/transcode.sh index f3b5a4a..6b0bb22 100755 --- a/transcode.sh +++ b/transcode.sh @@ -339,6 +339,10 @@ fi # Load ffmpeg argument preset by name. # +# Arguments: +# $1 - preset name +# $2 - name of the caller's array variable to populate (nameref) +# # Security: # Presets are sourced as shell code. Names are validated against a strict # allowlist (alphanumerics, hyphens, underscores only) to prevent path @@ -350,8 +354,12 @@ fi # The sourced preset MUST set the bash array `ffargs`. # Presets may reference variables from the caller (encode_one) such as: # output_pixel_format, input_pixel_format, input_codec +# On return the caller's array (named by $2) is populated with the preset's +# ffargs; the preset-local `ffargs` variable is unset before returning. load_preset() { local preset="$1" + local -n _load_preset_out="$2" + # Strict allowlist: only alphanumerics, hyphens, and underscores are permitted. # This prevents path traversal, shell metacharacter injection, and symlink-based # attacks more reliably than a blocklist approach. @@ -381,8 +389,7 @@ load_preset() { exit $EXIT_CONFIG_ERROR fi - unset -v ffargs - ffargs=() + local ffargs=() debug "Sourcing preset file:" "$file" @@ -395,6 +402,8 @@ load_preset() { } debug "Preset ffargs:" "$(printf "%q " "${ffargs[@]}")" + + _load_preset_out=("${ffargs[@]}") } if [[ $# -eq 0 ]]; then @@ -685,7 +694,10 @@ encode_one() { fi debug "Selected output pixel format:" "$output_pixel_format" - load_preset "$PRESET_NAME" + # Load preset early so a missing/invalid preset fails before we create a + # temp file or do any further work. + local ffargs=() + load_preset "$PRESET_NAME" ffargs local extension filename directory tmp base stem |
