Diff to HTML by rtfpessoa

Files changed (4) hide show
  1. runtime/doc/options.txt +16 -0
  2. runtime/doc/quickref.txt +2 -1
  3. runtime/doc/tagsrch.txt +3 -2
  4. runtime/doc/version9.txt +1 -0
runtime/doc/options.txt CHANGED
@@ -9223,6 +9223,22 @@ A jump table for the options with a short description can be found at |Q_op|.
9223
  file names from the list. This avoids problems when a future version
9224
  uses another default.
9225
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
9226
  *'tagstack'* *'tgst'* *'notagstack'* *'notgst'*
9227
  'tagstack' 'tgst' boolean (default on)
9228
  global
 
9223
  file names from the list. This avoids problems when a future version
9224
  uses another default.
9225
 
9226
+ *'tagsecure'* *'tsc'* *'notagsecure'* *'notsc'*
9227
+ 'tagsecure' 'tsc' boolean (default on)
9228
+ global
9229
+ When on, Vim refuses to follow tag entries whose file field looks like
9230
+ a URL ("scheme://..."), aborting the jump with error |E1576|. This
9231
+ prevents tag files from causing Vim to open URLs through |netrw|, which
9232
+ would trigger a network request and expose netrw's URL-handling code to
9233
+ attacker-controlled input or lead to environment exfiltration.
9234
+
9235
+ Tag files might be distributed alongside source code (e.g. via Git
9236
+ repositories) and may therefore be untrustworthy. Only disable
9237
+ this option if you fully control the tag files Vim will read.
9238
+
9239
+ This option cannot be set from a |modeline| or in the |sandbox|, for
9240
+ security reasons.
9241
+
9242
  *'tagstack'* *'tgst'* *'notagstack'* *'notgst'*
9243
  'tagstack' 'tgst' boolean (default on)
9244
  global
runtime/doc/quickref.txt CHANGED
@@ -1,4 +1,4 @@
1
- *quickref.txt* For Vim version 9.2. Last change: 2026 Apr 21
2
 
3
 
4
  VIM REFERENCE MANUAL by Bram Moolenaar
@@ -960,6 +960,7 @@ Short explanation of each option: *option-list*
960
  'taglength' 'tl' number of significant characters for a tag
961
  'tagrelative' 'tr' file names in tag file are relative
962
  'tags' 'tag' list of file names used by the tag command
 
963
  'tagstack' 'tgst' push tags onto the tag stack
964
  'tcldll' name of the Tcl dynamic library
965
  'term' name of the terminal
 
1
+ *quickref.txt* For Vim version 9.2. Last change: 2026 May 17
2
 
3
 
4
  VIM REFERENCE MANUAL by Bram Moolenaar
 
960
  'taglength' 'tl' number of significant characters for a tag
961
  'tagrelative' 'tr' file names in tag file are relative
962
  'tags' 'tag' list of file names used by the tag command
963
+ 'tagsecure' 'tsc' do not open remote files using tag commands
964
  'tagstack' 'tgst' push tags onto the tag stack
965
  'tcldll' name of the Tcl dynamic library
966
  'term' name of the terminal
runtime/doc/tagsrch.txt CHANGED
@@ -1,4 +1,4 @@
1
- *tagsrch.txt* For Vim version 9.2. Last change: 2026 Feb 14
2
 
3
 
4
  VIM REFERENCE MANUAL by Bram Moolenaar
@@ -581,7 +581,8 @@ ctags).
581
  doubtful). It cannot contain a <Tab>.
582
  *E1576*
583
  Using a remote file via network protocol (e.g. using
584
- http://remote/file.txt) is not allowed.
 
585
  {tagaddress} The Ex command that positions the cursor on the tag. It can
586
  be any Ex command, although restrictions apply (see
587
  |tag-security|). Posix only allows line numbers and search
 
1
+ *tagsrch.txt* For Vim version 9.2. Last change: 2026 May 17
2
 
3
 
4
  VIM REFERENCE MANUAL by Bram Moolenaar
 
581
  doubtful). It cannot contain a <Tab>.
582
  *E1576*
583
  Using a remote file via network protocol (e.g. using
584
+ http://remote/file.txt) is not allowed unless 'tagsecure'
585
+ is unset.
586
  {tagaddress} The Ex command that positions the cursor on the tag. It can
587
  be any Ex command, although restrictions apply (see
588
  |tag-security|). Posix only allows line numbers and search
runtime/doc/version9.txt CHANGED
@@ -52688,6 +52688,7 @@ Options: ~
52688
  configure the height.
52689
  't_BS' Begin synchronized update.
52690
  't_ES' End synchronized update.
 
52691
  'termresize' Method for handling terminal resize events.
52692
  'termsync' Enable support for terminal DEC 2026 sync mode.
52693
  'winhighlight' Window-local highlight group mappings.
 
52688
  configure the height.
52689
  't_BS' Begin synchronized update.
52690
  't_ES' End synchronized update.
52691
+ 'tagsecure' Do not open remote files using tag commands
52692
  'termresize' Method for handling terminal resize events.
52693
  'termsync' Enable support for terminal DEC 2026 sync mode.
52694
  'winhighlight' Window-local highlight group mappings.