62f676116e2f623329aaead72bfed5b4d2faa17f

Author
Marc Cornellà <marc.cornella@live.com>
Committer
GitHub <noreply@github.com>
Date

Message

Merge pull request #6863 from robbyrussell/fix-compfix-loading

compfix: better error message and loading of completions

Diff

 1diff --git a/lib/compfix.zsh b/lib/compfix.zsh
 2index 208aaadb1ebad0e25ebdef29192da815be8136bd..68decc1ed4d6fc5b51476fc9224f0d0171e96804 100644
 3--- a/lib/compfix.zsh
 4+++ b/lib/compfix.zsh
 5@@ -2,10 +2,6 @@
 6 # insecure ownership or permissions) by:
 7 #
 8 # * Human-readably notifying the user of these insecurities.
 9-# * Moving away all existing completion caches to a temporary directory. Since
10-#   any of these caches may have been generated from insecure directories, they
11-#   are all suspect now. Failing to do so typically causes subsequent compinit()
12-#   calls to fail with "command not found: compdef" errors. (That's bad.)
13 function handle_completion_insecurities() {
14   # List of the absolute paths of all unique insecure directories, split on
15   # newline from compaudit()'s output resembling:
16@@ -22,39 +18,27 @@ function handle_completion_insecurities() {
17   insecure_dirs=( ${(f@):-"$(compaudit 2>/dev/null)"} )
18 
19   # If no such directories exist, get us out of here.
20-  if (( ! ${#insecure_dirs} )); then
21-      print "[oh-my-zsh] No insecure completion-dependent directories detected."
22-      return
23-  fi
24+  (( ! ${#insecure_dirs} )) && return
25 
26   # List ownership and permissions of all insecure directories.
27   print "[oh-my-zsh] Insecure completion-dependent directories detected:"
28   ls -ld "${(@)insecure_dirs}"
29-  print "[oh-my-zsh] For safety, completions will be disabled until you manually fix all"
30-  print "[oh-my-zsh] insecure directory permissions and ownership and restart oh-my-zsh."
31-  print "[oh-my-zsh] See the above list for directories with group or other writability.\n"
32 
33-  # Locally enable the "NULL_GLOB" option, thus removing unmatched filename
34-  # globs from argument lists *AND* printing no warning when doing so. Failing
35-  # to do so prints an unreadable warning if no completion caches exist below.
36-  setopt local_options null_glob
37+  cat <<EOD
38 
39-  # List of the absolute paths of all unique existing completion caches.
40-  local -aU zcompdump_files
41-  zcompdump_files=( "${ZSH_COMPDUMP}"(.) "${ZDOTDIR:-${HOME}}"/.zcompdump* )
42+[oh-my-zsh] For safety, we will not load completions from these directories until
43+[oh-my-zsh] you fix their permissions and ownership and restart zsh.
44+[oh-my-zsh] See the above list for directories with group or other writability.
45 
46-  # Move such caches to a temporary directory.
47-  if (( ${#zcompdump_files} )); then
48-    # Absolute path of the directory to which such files will be moved.
49-    local ZSH_ZCOMPDUMP_BAD_DIR="${ZSH_CACHE_DIR}/zcompdump-bad"
50+[oh-my-zsh] To fix your permissions you can do so by disabling
51+[oh-my-zsh] the write permission of "group" and "others" and making sure that the
52+[oh-my-zsh] owner of these directories is either root or your current user.
53+[oh-my-zsh] The following command may help:
54+[oh-my-zsh]     compaudit | xargs chmod g-w,o-w
55 
56-    # List such files first.
57-    print "[oh-my-zsh] Insecure completion caches also detected:"
58-    ls -l "${(@)zcompdump_files}"
59+[oh-my-zsh] If the above didn't help or you want to skip the verification of
60+[oh-my-zsh] insecure directories you can set the variable ZSH_DISABLE_COMPFIX to
61+[oh-my-zsh] "true" before oh-my-zsh is sourced in your zshrc file.
62 
63-    # For safety, move rather than permanently remove such files.
64-    print "[oh-my-zsh] Moving to \"${ZSH_ZCOMPDUMP_BAD_DIR}/\"...\n"
65-    mkdir -p "${ZSH_ZCOMPDUMP_BAD_DIR}"
66-    mv "${(@)zcompdump_files}" "${ZSH_ZCOMPDUMP_BAD_DIR}/"
67-  fi
68+EOD
69 }
70diff --git a/oh-my-zsh.sh b/oh-my-zsh.sh
71index c0e2ba8f6a636403dd162e3c741b329a1f90f969..72527362f8e5f8ac628550413ffe582e51b5d76b 100644
72--- a/oh-my-zsh.sh
73+++ b/oh-my-zsh.sh
74@@ -63,15 +63,14 @@ if [ -z "$ZSH_COMPDUMP" ]; then
75 fi
76 
77 if [[ $ZSH_DISABLE_COMPFIX != true ]]; then
78-  # If completion insecurities exist, warn the user without enabling completions.
79+  # If completion insecurities exist, warn the user
80   if ! compaudit &>/dev/null; then
81-    # This function resides in the "lib/compfix.zsh" script sourced above.
82     handle_completion_insecurities
83-  # Else, enable and cache completions to the desired file.
84-  else
85-    compinit -d "${ZSH_COMPDUMP}"
86   fi
87+  # Load only from secure directories
88+  compinit -i -d "${ZSH_COMPDUMP}"
89 else
90+  # If the user wants it, load from all found directories
91   compinit -u -d "${ZSH_COMPDUMP}"
92 fi
93