fix(sidecar): keep a leading dash off the fast input path

A value starting with '-' could be read as an option by `adb input text`, so
the fast-path regex now requires a non-dash first character; such values fall
back to the driver. Also cover the dadb-target branch where a colon precedes a
non-numeric port (a USB serial, not host:port).
This commit is contained in:
pj committed 2026-06-10 21:21:20 +05:30
1 parent ee3dd480b7
commit 71b521fa1d
3 files changed
+11 -2

No files matched your search

@@ -552,7 +552,9 @@ class StubDriverBackend(
// FAST_INPUT_SAFE matches text that can be typed with adb `input text`: short,
// ASCII, and free of shell metacharacters and spaces. Anything else (unicode,
// injection payloads, overflow-length strings) falls back to the driver path.
internal val FAST_INPUT_SAFE = Regex("^[A-Za-z0-9@._+-]{1,64}$")
// The first character excludes '-' so the text can never be read as an option
// by `input text`.
internal val FAST_INPUT_SAFE = Regex("^[A-Za-z0-9@._+][A-Za-z0-9@._+-]{0,63}$")
class MaestroDriverBackend(private val serial: String?) : DriverBackend {
private val dadb: dadb.Dadb
@@ -16,4 +16,10 @@ class DadbTargetTest {
@Test fun usbSerialRoutesThroughAdbServer() {
assertEquals(DadbTarget.Server("663c91b1"), dadbTargetFor("663c91b1"))
}
// A colon with a non-numeric port is a USB serial that merely contains a
// colon, not a host:port, so it must route through the adb server.
@Test fun colonWithNonNumericPortIsAServerSerial() {
assertEquals(DadbTarget.Server("emulator:5554x"), dadbTargetFor("emulator:5554x"))
}
}
@@ -13,12 +13,13 @@ class InputTextTest {
// correctly. A regression here would corrupt edge-case input or shell-inject
// the device.
@Test fun fastInputPathAcceptsOnlyShellSafeAscii() {
for (safe in listOf("[email protected]", "ledger123", "Checking", "-1", "1e10", "0.0000001")) {
for (safe in listOf("[email protected]", "ledger123", "Checking", "1e10", "0.0000001", "42")) {
assertTrue(FAST_INPUT_SAFE.matches(safe), "expected fast path for: $safe")
}
val fallback = listOf(
"Emergency Fund", "🙂🔥💸", " ", "\t\n", "'; DROP TABLE--",
"<script>alert(1)</script>", "../../etc/passwd", "%s%n", "", "a".repeat(4096),
"-1", "-rf", // a leading dash could be read as an option by `input text`
)
for (text in fallback) {
assertTrue(!FAST_INPUT_SAFE.matches(text), "expected driver fallback for: $text")