How to use this reference
Editorial learning objective: distinguish preserving argument boundaries from authorizing their meaning. Review which executable and interpreter receive data, what actions the receiving program assigns to arguments, and whether those actions fit the intended authority. This resource supports conceptual design review, without execution recipes.
Before reading
- Basic familiarity with processes, arguments, and operating-system differences.
Context and limits
- Windows batch-file handling can involve shell parsing even when the application has not explicitly selected a shell. The runtime guidance for this case is conditional, not a universal recommendation to enable shell execution.
- shlex quoting is not guaranteed correct for non-POSIX shells or Windows shells.
- The authorization distinction is editorial synthesis, not a claim that these Python APIs enforce application policy.
- No vulnerability finding, award, payload, reproduction sequence, or testing authorization is established.
Sources and provenance
- subprocess: Security Considerations Python Software Foundation · reviewed 2026-10-03
- shlex.quote: Unix-shell portability warning Python Software Foundation · reviewed 2026-10-03
Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.