Skip to content

dash-tui: approval-dialog command preview doesn't quote args with spaces #443

Description

@jussielo-amd

Current behavior
The approval-dialog command preview builds its display string with a plain args.join(" ") (no quoting), in at least these spots:

  • crates/rocm-dash-tui/src/ui/onboarding.rs (stage_approval)
  • crates/rocm-dash-tui/src/ui/install_manager.rs
  • crates/rocm-dash-tui/src/ui/serve_wizard.rs
  • crates/rocm-dash-tui/src/ui/automations_manager.rs
  • crates/rocm-dash-tui/src/ui/command_screen.rs
  • crates/rocm-dash-tui/src/ui/engine_manager.rs
  • crates/rocm-dash-tui/src/ui/config_manager.rs
  • crates/rocm-dash-tui/src/ui/runtime_manager.rs
  • crates/rocm-dash-tui/src/ui/job_console.rs

If any argument value contains a space (most notably a --prefix folder path, e.g. /mnt/my folder or a Windows path like C:\Program Files\ROCm), the rendered preview is ambiguous about where that argument ends. For example:

rocm install sdk --channel release --format wheel --prefix /mnt/my folder --approve-replacing-active-default

reads as though folder were a separate argument.

Expected behavior
The preview shown in the approval gate should unambiguously reflect the actual argv the job will be spawned with — e.g. by quoting any argument that contains whitespace (or by joining with a small shared shell-quoting helper) before display.

Note: this is a display-only issue. The spawned process itself is unaffected, since args are passed as a Vec<String> directly to the process (not through a shell), so this does not change what actually runs — it only affects whether the user approving the mutating action can trust what the preview shows.

Steps to reproduce

  1. Open the onboarding wizard's Install SDK Configure step (or the Install Manager / Serve Wizard / etc.).
  2. Tab into the folder browser and choose (or create) a folder whose path contains a space.
  3. Confirm to reach the approval screen.
  4. Observe the rendered command preview — the path is not quoted or otherwise delimited.

Possible solution
Add a small shared shell_quote/display_args helper (e.g. alongside crate::ui::format) that quotes any arg containing whitespace or shell-meaningful characters, and use it at all the args.join(" ") call sites listed above instead of the bare join.

Additional context
Surfaced during code review of #441 (onboarding --prefix folder-browse support), which uses the same pre-existing args.join(" ") pattern for its approval preview. Scope was kept out of that PR since the pattern is repo-wide, not specific to onboarding.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions