Skip to content

fix(linux): preserve XDG executable paths and arguments - #39

Merged
zzzgydi merged 2 commits into
zzzgydi:mainfrom
vincentkoc:fix/xdg-exec-quoting
Sep 16, 2026
Merged

zzzgydi merged 2 commits into
zzzgydi:mainfrom
vincentkoc:fix/xdg-exec-quoting

Conversation

@vincentkoc

@vincentkoc vincentkoc commented Sep 13, 2026 •

Copy link
Copy Markdown
Contributor

XDG autostart currently joins the executable and arguments without quoting. A path containing spaces can fail to start, and spaced or empty arguments lose their boundaries. Quote each literal argument using Desktop Entry string escaping and Exec quoting, including literal percent sequences.

This addresses the XDG portion of #32. Ordinary commands retain their representation; systemd, macOS and Windows implementations and dependencies are unchanged. Production delta is +30 lines for the serializer.

The regression fixture uses gio launch to start a copied test executable from a path containing spaces, quotes, a backslash, a dollar sign and a backtick. The executable records its exact arguments, including empty values, control whitespace, quotes, percent sequences and Unicode. The test owns a disposable HOME and verifies disable removes the desktop entry.

Validation at cd52eaa3ac2a045a42af8bc24dcc636def861fcc:

  • cargo test --locked --lib --test xdg_exec passed on native Linux (Rust 1.98.1, gio 2.88.0) and FreeBSD 15.1-p3 (Rust 1.98.1, gio 2.88.3): three unit tests, zero ignored tests, and the real-launch fixture completed.
  • Linux ran on a disposable secretless Crabbox. FreeBSD receipt, attempt 1, checks the source SHA before testing.
  • Independent source and native-proof review completed. No desktop login/session or GUI behavior is claimed.

Known boundary: GLib's desktop loader checks the executable name before expanding %%, so percent-bearing executable names remain a launcher limitation. The real-launch fixture tests literal percent characters in arguments. See the Exec specification and GLib loader.

A separate 0.5 quoting backport lets existing consumers receive this fix without a global 0.6 upgrade. A small 0.5 filesystem backport separately restores the recursive-directory/complete-write fix from #19 with contributor credit. Both maintenance candidates passed their separate native Linux tests on disposable secretless Crabboxes, with independent source and proof review: the 0.5 quoting candidate passed the real GIO executable/argument fixture; the filesystem candidate passed the fresh-HOME, replacement, disable and filesystem-error fixture. They still require an upstream maintenance release; no version is invented or published.

@zzzgydi

zzzgydi commented Sep 16, 2026

Copy link
Copy Markdown
Owner

Thanks for the fix and the thorough testing! Merged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants