You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Rust中如何将变量传入Command执行的bash命令行参数

问题根因

代码中传入Bash的$path是Shell语法层面的环境变量占位符,和Rust作用域内定义的path字符串变量不属于同一个运行环境,Bash进程启动时没有读取到对应名称的环境变量,自然无法替换为你预期的路径值。

优先方案:直接调用命令跳过Bash层

std::process::Command原生支持参数传递,不需要嵌套bash -c执行外部命令,这种写法不存在Shell注入风险,是官方推荐的标准实现:

use std::process::{Command, Stdio};

fn main() {
    let path = "/home/directory/";
    let status = Command::new("mv")
        .arg("somefile.txt")
        .arg(path)
        .stdout(Stdio::piped())
        .spawn()
        .expect("Failed to spawn process")
        .wait()
        .expect("Process wasn't running");
}

如果需要拼接路径和文件名,直接在Rust层用format!("{path}/target.txt")处理即可,不需要交给Shell解析。

备选方案:必须使用Bash时的传参方式

如果命令逻辑依赖Bash特性(比如管道、通配符、Shell内置指令等),不要直接在Rust层拼接命令字符串,选择以下两种安全传参方式:

通过环境变量传值

调用env()方法向Bash进程注入指定环境变量,Bash执行命令时可以直接读取对应变量值:

use std::process::{Command, Stdio};

fn main() {
    let path = "/home/directory/";
    let status = Command::new("/bin/bash")
        .arg("-c")
        .arg("mv somefile.txt $path")
        .env("path", path) // 向子进程注入path环境变量
        .stdout(Stdio::piped())
        .spawn()
        .expect("Failed to spawn process")
        .wait()
        .expect("Process wasn't running");
}

通过Bash位置参数传值

把Rust变量作为bash -c的附加参数传入,Bash会自动按顺序将参数赋值给$0、$1等位置变量,不需要额外处理特殊字符转义:

use std::process::{Command, Stdio};

fn main() {
    let path = "/home/directory/";
    let status = Command::new("/bin/bash")
        .arg("-c")
        // $0对应命令字符串后传入的第一个附加参数
        .arg("mv somefile.txt $0")
        .arg(path)
        .stdout(Stdio::piped())
        .spawn()
        .expect("Failed to spawn process")
        .wait()
        .expect("Process wasn't running");
}

禁止直接用Rust字符串格式化把变量值拼接到Bash命令字符串中,一旦变量内容包含空格、引号、分号等特殊Shell字符,会出现执行逻辑错误,甚至引发Shell注入安全漏洞。

内容的提问来源于stack exchange,提问作者blueStack453

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.30 20:03:24