Quote a string for bash
Spaces, quotes, $, !, line breaks: paste a text and get it written so that bash reads it exactly, as a single argument. Or the other way round: see what bash makes of a quoted word.
To check in a terminal: printf prints the value it receives, and nothing else.
Which one to choose
'…'Single quotes- Nothing inside is interpreted, not even
\: the safest. Only a single quote cannot appear inside; it is written'\''(close, escaped quote, reopen). $'…'ANSI-C ($'…')- Understands
\n,\t,\e,\x41…: the only readable way to write a tab or an escape character. A bash feature (also in zsh and ksh, not in sh). "…"Double quotes- Useful when a variable must be expanded inside (
"$HOME/x").\,$,`and"must be escaped, and!triggers history expansion in a terminal: the tool puts it outside, in'!'. \Backslashes- Each special character gets its own
\, likeprintf %qdoes. Short when there is only a space or two; unreadable beyond.
Transparency
The text is analysed and rewritten in your browser, by the scripts listed below. It never leaves this page.
- Enforced by your browser
- This page's Content Security Policy allows a single destination, the site's audience measurement (
connect-src https://stats.r-no.fr, see below), and forbids any form submission (form-action 'none'), so even a bug could not send what you type anywhere. You can read the policy at the top of the page source. - Audience measurement
- Like every page of the site, this one counts its visit with Umami, installed on R-no’s own server (
stats.r-no.fr). It receives the address of the page, without parameters or anchor, the site you came from (its domain only), your browser, system, language and screen size, and the country, region and city deduced from your IP address, which is not kept. It never receives what you type, nor the result of the tool. No cookie, nothing stored in your browser; if your browser asks not to be tracked (Do Not Track), nothing is measured. The data is erased after 25 months.- /commun/mesure.js: the filter applied before each sending, written for R-no Toolbox. 1.4 kB
SHA-256225eec74fd12623d82fc05ee7d222be629ce454d081c129e8d1e249ed37ee716 - https://stats.r-no.fr/m.js: Umami’s tracker, open source (MIT), served by the measurement server. Its fingerprint is not shown here: it changes with each version of Umami, and you cannot check from your browser that it is the published code. For that part, you have to trust R-no.
- /commun/mesure.js: the filter applied before each sending, written for R-no Toolbox. 1.4 kB
- What is stored
- No cookie, and nothing in the address. What you type is never stored: it disappears when you reload or close the page. Your language is given by the address itself (
/en/or/fr/): nothing is stored to remember it. Like any website, the server records the download of the page and its files in its access logs (IP address, date and time, address requested, browser name). It never receives what you type. - Code that runs here
-
- app.js: the quoting and the reading of bash words, written for R-no Toolbox. Not minified, no third-party library. 17.1 kB
SHA-256d73f0398fdd00e66799d3ea7e7a38500a31e70ecf95dea10520970537c65ab44 - textes.js: the French messages of the tool, shown by its script (the rest of the French page is written into its HTML when the site is built). It only defines texts, with no logic. 7.9 kB
SHA-25646462d5a5030c64eb623c00b180966a9a3a8fff8f352658647faf9d44960ea41 - /commun/langue.js: the language helper, the same on every page of the site. It reads the language of the page and gives the tool its messages in that language. It stores nothing. 1.6 kB
SHA-25680f76f69773ef628d36d09bf8387cfedebda4529210d7120649b6f5603310631
- app.js: the quoting and the reading of bash words, written for R-no Toolbox. Not minified, no third-party library. 17.1 kB
- Before you paste
- This page only writes text: it runs nothing, neither here nor on your machine. What you paste into a terminal or a configuration file runs with your rights, so read it first. The code it writes downloads nothing and calls no outside service.
- How it was checked
- Each of the four forms was run through bash 5.2 on tricky texts (quotes,
!, line breaks, control characters, emoji) and gave back the exact original. The reading mode applies the same rules as bash to quotes and backslashes. - Check it yourself
- Download a script and compare its fingerprint with the one above:
curl -s https://r-no.fr/bash/quote/app.js | shasum -a 256 - Limits
- Written for bash (and zsh, ksh).
sh(dash) does not know$'…'. The reading mode does not perform expansions ($var,$(…),*,~,{a,b}): it cannot know your variables or files, so it points them out. A NUL character cannot be passed to a command at all. At most 100,000 characters.