Fix quoting of shell commands on Windows - #5704
Merged
Merged
Conversation
stefanhaller
force-pushed
the
fix-windows-cmd-quoting
branch
from
June 16, 2026 14:30
1b32aba to
93d2c0b
Compare
On Windows, Quote wraps arguments in bash-style `\"…\"` and rewrites embedded double quotes as `"'"'"`. Neither convention is understood by cmd.exe or CommandLineToArgvW, so commands built from quoted arguments are mis-parsed once they contain quotes or spaces (#5560). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
On Windows, NewShell escapes shell metacharacters (`&`, `|`, `<`, `>`, `%`) with `^` and splits the command into separate arguments. The operators in a custom command therefore never reach cmd as operators, so command chaining (`&&`), pipes, redirection and `%VAR%` expansion all silently break (#2427, #4147, #5113; the stray `^` is also what #3092 reports). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
lazygit builds a shell command by interpolating Quote'd arguments into a template and running the result via `cmd /c`. Several things were wrong on Windows: - Quote emitted bash-style `\"…\"` quoting, which cmd.exe doesn't understand. Making it usable at all previously required a fragile round-trip through str.ToArgv and re-escaping. - The assembled command line was handed to `cmd /c` without `/s`, so cmd's default rules stripped the wrong quotes once the line contained more than two of them (e.g. a quoted editor path at a location with spaces, plus a quoted filename that also contains spaces). - Shell metacharacters were escaped with `^` (`&` → `^&`, etc.), which neutralised command chaining, pipes, redirection and `%VAR%` expansion in custom commands. Quote now emits the standard Windows convention directly, and NewShell hands cmd.exe the fully-assembled line verbatim via SysProcAttr.CmdLine, wrapped as `cmd /s /c "<command>"`. The /s flag strips exactly the outer quote pair we add, leaving each argument's own quoting intact. With the `^` escaping gone, metacharacters in a custom command reach cmd as the author intended; this also removes the spurious `^` reported in #3092. Fixes #5560 Fixes #2427 Fixes #4147 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The unit tests only assert the arguments lazygit constructs; they can't catch cmd.exe's own quote-stripping, which is where #5560 actually manifested. This test builds a small editor executable, places it and the file it opens at paths containing spaces, runs it through real cmd.exe via NewShell, and checks the editor received the intended args. It runs only on Windows. Co-Authored-By: Antoine Gaudreau Simard <a.simard@multidev.net> Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
stefanhaller
force-pushed
the
fix-windows-cmd-quoting
branch
from
June 23, 2026 12:11
93d2c0b to
1381766
Compare
stefanhaller
enabled auto-merge
June 23, 2026 12:11
tmeijn
pushed a commit
to tmeijn/dotfiles
that referenced
this pull request
Jul 9, 2026
This MR contains the following updates: | Package | Update | Change | |---|---|---| | [jesseduffield/lazygit](https://github.com/jesseduffield/lazygit) | minor | `v0.62.2` → `v0.63.0` | MR created with the help of [el-capitano/tools/renovate-bot](https://gitlab.com/el-capitano/tools/renovate-bot). **Proposed changes to behavior should be submitted there as MRs.** --- ### Release Notes <details> <summary>jesseduffield/lazygit (jesseduffield/lazygit)</summary> ### [`v0.63.0`](https://github.com/jesseduffield/lazygit/releases/tag/v0.63.0) [Compare Source](jesseduffield/lazygit@v0.62.2...v0.63.0) <!-- Release notes generated using configuration in .github/release.yml at v0.63.0 --> #### What's Changed ##### Enhancements 🔥 - Add direnv support by [@​stefanhaller](https://github.com/stefanhaller) in [#​5660](jesseduffield/lazygit#5660) - Improve cycling through multiple pagers by [@​stefanhaller](https://github.com/stefanhaller) in [#​5678](jesseduffield/lazygit#5678) - Detect external repo changes via background polling by [@​stefanhaller](https://github.com/stefanhaller) in [#​5662](jesseduffield/lazygit#5662) - Make the side panels configurable by [@​stefanhaller](https://github.com/stefanhaller) in [#​5702](jesseduffield/lazygit#5702) - Add a global keybinding for editing the config file by [@​stefanhaller](https://github.com/stefanhaller) in [#​5728](jesseduffield/lazygit#5728) - Improve resolving non-textual and submodule merge conflicts by [@​stefanhaller](https://github.com/stefanhaller) in [#​5735](jesseduffield/lazygit#5735) - Auto-dismiss the continue-rebase prompt when it becomes stale by [@​stefanhaller](https://github.com/stefanhaller) in [#​5758](jesseduffield/lazygit#5758) - Support custom pagers and passphrase prompts on Windows by [@​stefanhaller](https://github.com/stefanhaller) in [#​5740](jesseduffield/lazygit#5740) - Make creating worktrees simpler and less error-prone by [@​stefanhaller](https://github.com/stefanhaller) in [#​5741](jesseduffield/lazygit#5741) - Improve deleting worktrees and their branches by [@​stefanhaller](https://github.com/stefanhaller) in [#​5748](jesseduffield/lazygit#5748) - Allow overriding the platform used for default keybindings by [@​stefanhaller](https://github.com/stefanhaller) in [#​5671](jesseduffield/lazygit#5671) - Add `gui.shrinkSidePanelsToContent` option by [@​stefanhaller](https://github.com/stefanhaller) in [#​5754](jesseduffield/lazygit#5754) - Show renamed files in the custom patch builder by [@​stefanhaller](https://github.com/stefanhaller) in [#​5759](jesseduffield/lazygit#5759) ##### Fixes 🔧 - Fix unstaging a submodule with dirty content by [@​stefanhaller](https://github.com/stefanhaller) in [#​5666](jesseduffield/lazygit#5666) - Fix coloring of wrapped delta lines by [@​stefanhaller](https://github.com/stefanhaller) in [#​5711](jesseduffield/lazygit#5711) - Fix Files Panel artefacts during rebase commands by [@​stefanhaller](https://github.com/stefanhaller) in [#​5661](jesseduffield/lazygit#5661) - Keep selected commits stable across refreshes by [@​stefanhaller](https://github.com/stefanhaller) in [#​5717](jesseduffield/lazygit#5717) - Fix quoting of shell commands on Windows by [@​stefanhaller](https://github.com/stefanhaller) in [#​5704](jesseduffield/lazygit#5704) - Silently consume unrecognized or malformed escape sequences by [@​stefanhaller](https://github.com/stefanhaller) in [#​5738](jesseduffield/lazygit#5738) - Don't include common ancestor when picking "both" for a conflict in diff3 style by [@​stefanhaller](https://github.com/stefanhaller) in [#​5747](jesseduffield/lazygit#5747) ##### Maintenance ⚙️ - Some fixes to our infrastructure by [@​stefanhaller](https://github.com/stefanhaller) in [#​5705](jesseduffield/lazygit#5705) - Restructure the `just` recipes for running integration tests by [@​stefanhaller](https://github.com/stefanhaller) in [#​5720](jesseduffield/lazygit#5720) - Fix flaky TestNewCmdTaskInstantStop test by [@​stefanhaller](https://github.com/stefanhaller) in [#​5743](jesseduffield/lazygit#5743) - Bump golang.org/x/sync from 0.20.0 to 0.21.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​5684](jesseduffield/lazygit#5684) - Bump golang.org/x/sys from 0.45.0 to 0.46.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​5685](jesseduffield/lazygit#5685) - Bump github.com/sahilm/fuzzy from 0.1.2 to 0.1.3 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​5706](jesseduffield/lazygit#5706) - Bump actions/cache from 5 to 6 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​5722](jesseduffield/lazygit#5722) - Bump actions/checkout from 6 to 7 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​5723](jesseduffield/lazygit#5723) - Bump goreleaser/goreleaser-action from 7.2.2 to 7.2.3 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​5745](jesseduffield/lazygit#5745) - Bump golangci/golangci-lint-action from 9.2.0 to 9.3.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​5746](jesseduffield/lazygit#5746) - Bump golang.org/x/net from 0.47.0 to 0.55.0 by [@​dependabot](https://github.com/dependabot)\[bot] in [#​5752](jesseduffield/lazygit#5752) - Pin gofumpt version to 0.9.2 by [@​stefanhaller](https://github.com/stefanhaller) in [#​5753](jesseduffield/lazygit#5753) - Fix a few flaky tests by [@​stefanhaller](https://github.com/stefanhaller) in [#​5756](jesseduffield/lazygit#5756) ##### I18n 🌎 - Update translations from Crowdin by [@​stefanhaller](https://github.com/stefanhaller) in [#​5760](jesseduffield/lazygit#5760) ##### Performance Improvements 📊 - Prevent staging from becoming slower over time by [@​stefanhaller](https://github.com/stefanhaller) in [#​5712](jesseduffield/lazygit#5712) **Full Changelog**: <jesseduffield/lazygit@v0.62.2...v0.63.0> </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever MR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this MR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this MR, check this box --- This MR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTYuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI1Ni4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJSZW5vdmF0ZSBCb3QiLCJhdXRvbWF0aW9uOmJvdC1hdXRob3JlZCIsImRlcGVuZGVuY3ktdHlwZTo6bWlub3IiXX0=-->
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Lazygit builds a shell command by interpolating Quote'd arguments into a template and running the result via
cmd /c. Several things were wrong on Windows:\"…\"quoting, which cmd.exe doesn't understand. Making it usable at all previously required a fragile round-trip through str.ToArgv and re-escaping.cmd /cwithout/s, so cmd's default rules stripped the wrong quotes once the line contained more than two of them (e.g. a quoted editor path at a location with spaces, plus a quoted filename that also contains spaces).^(&→^&, etc.), which neutralised command chaining, pipes, redirection and%VAR%expansion in custom commands.Quote now emits the standard Windows convention directly, and NewShell hands cmd.exe the fully-assembled line verbatim via SysProcAttr.CmdLine, wrapped as
cmd /s /c "<command>". The /s flag strips exactly the outer quote pair we add, leaving each argument's own quoting intact. With the^escaping gone, metacharacters in a custom command reach cmd as the author intended; this also removes the spurious^reported in #3092.Fixes #5560
Fixes #2427
Fixes #4147