将传递给xp_cmdshell的命令参数转义为dtexec

ama*_*tar 3 sql t-sql ssis stored-procedures sql-server-2008

我使用存储过程和xp_cmdshell调用远程调用SSIS包:

declare @cmd varchar(5000)
set @cmd = '"C:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\dtexec.exe" /Rep E /Sql Package /SET \Package.Variables[User::ImportFileName].Value;c:\foo.xlsx'
print @cmd
exec xp_cmdshell @cmd
Run Code Online (Sandbox Code Playgroud)

这工作得很好,但是我不能保证变量值(C:\ foo.xslx)不会包含空格,所以我想逃避,与像下面的报价:

set @cmd = '"C:\Program Files (x86)\Microsoft SQL Server\100\DTS\Binn\dtexec.exe" /Rep E /Sql Package /SET \Package.Variables[User::ImportFileName].Value;"c:\foo.xlsx"'
Run Code Online (Sandbox Code Playgroud)

但通过这样做,我得到了错误

'C:\Program' is not recognized as an internal or external command, operable program or batch file.
Run Code Online (Sandbox Code Playgroud)

如果CMD.EXE内执行上述两个命令的正常工作,所以我猜测SQL Server在解释我的双引号和改变的东西,但我想不出什么.

Ben*_*Ben 6

简而言之,放在CMD /S /C "开头和"结尾.在两者之间,您可以拥有任意数量的报价.

这是你如何做到的:

declare @cmd varchar(8000)
-- Note you can use CMD builtins and output redirection etc with this technique, 
-- as we are going to pass the whole thing to CMD to execute
set @cmd = 'echo "Test" > "c:\my log directory\logfile.txt" 2> "c:\my other directory\err.log" '


declare @retVal int
declare @output table(
    ix int identity primary key,
    txt varchar(max)
)


-- Magic goes here:
set @cmd = 'CMD /S /C " ' + @cmd + ' " '

insert into @output(txt)
exec @retVal = xp_cmdshell @cmd
insert @output(txt) select '(Exit Code: ' + cast(@retVal as varchar(10))+')'

select * from @output
Run Code Online (Sandbox Code Playgroud)