From: "Mark J. Reed" Date: 2003-09-01T09:26:42+09:00 Subject: Re: `echo %!(*` On Sun, Aug 31, 2003 at 06:00:34PM -0500, Shashank Date wrote: > I am not sure that I understand what you mean by "bypassing the shell", It's simple. When you execute `some command` (or the equivalent using %x), what Ruby actually executes is your command interpreter ("shell" in Unix-speak), passing it the string between `...` to execute. It's up to the shell to split up the command into words, handle wildcard expansion (at least on UNIX; the command interpreter on Windows leaves that latter duty up to the individual commands), etc. The problem is that all this power is a security hole because it's easy to trick command interpreters into doing ugly things just by passing something nefarious as a "filename". The original poster mentioned Kernel.system, which is the way to execute a command when you don't care about its output. If you pass it one long string, Kernel.system will also invoke the shell, but if instead you pass it separate arguments for each word of the command line, it bypasses the shell and executes the command directly. Thus: system("ps -fp#{$$}") # also invokes the shell system('ps', "-fp#{$$}") # doesn't invoke the shell psOutput = `ps -fp#{$$}` # invokes the shell The question is: how do you complete the list, that is, capture the command output without involving the shell? The only solution of which I'm aware is to use popen/exec: if fd = IO.popen('-') then psOutput = fd.readlines.join("\n") else exec 'ps', "-fp#{$$}" end Of course, you could turn this into a method: def safeBackticks(*args) if fd = IO.popen('-') then output = fd.readlines.join("\n") else exec *args end return output end