? LICENSE.txt
? drushrc.php
? commands/core/installcore.drush.inc
? commands/core/drupal/environment.inc
? includes/table.inc
Index: commands/core/site_install.drush.inc
===================================================================
RCS file: /cvs/drupal-contrib/contributions/modules/drush/commands/core/site_install.drush.inc,v
retrieving revision 1.4
diff -u -p -r1.4 site_install.drush.inc
--- commands/core/site_install.drush.inc	21 Jun 2010 18:55:08 -0000	1.4
+++ commands/core/site_install.drush.inc	28 Sep 2010 23:42:44 -0000
@@ -56,22 +56,40 @@ function drush_core_pre_site_install() {
   drush_bootstrap(DRUSH_BOOTSTRAP_DRUPAL_SITE);
 
   // Drop and create DB if needed.
-  // TODO: support db-su like sql sync.
+  // @TODO: support db-su like sql sync.
+
   // Can't use drush_sql_query() since might not have a DB.
-  $exec = 'mysql ' . _drush_sql_get_credentials($db_spec);
-  // Strip DB name from credentials. Soon it won't exist anymore. We do
-  // need a DB name to connect to so use built-in mysql DB.
-  $replacement_db = 'information_schema';
-  // Make sure we are only replacing the database name,
-  // and not a username or password that is the same as the database name.
-  $exec = str_replace(" {$db_spec['database']}", " {$replacement_db}", $exec) . ' -e ';
-  if (drush_op('system', $exec . ' "DROP DATABASE IF EXISTS ' . $db_spec['database'] . '"') && !drush_get_context('DRUSH_SIMULATE')) {
-    drush_set_error(dt('Could not drop database: @name', array('@name' => $db_spec['database'])));
+  // Get credentials to connect to the server, but not the database which we
+  // are about to DROP.
+
+  // Save the database name before we unset() it.
+  $db_name = $db_spec['database'];
+  $scheme = _drush_sql_get_scheme($db_spec);
+
+  // _drush_sql_get_credentials() will set a default database according to
+  // the scheme if one is not set.
+  unset($db_spec['database']);
+  $credentials = _drush_sql_get_credentials($db_spec);
+
+  switch ($scheme) {
+    case 'mysql':
+      $command_parameter_name = 'execute';
+      break;
+    case 'pgsql':
+      $command_parameter_name = 'command';
+      break;
+  }
+  $execute = "$scheme $credentials --$command_parameter_name";
+
+  $simulate = drush_get_context('DRUSH_SIMULATE');
+
+  if (drush_op('system', "$execute='DROP DATABASE IF EXISTS `$db_name`'") && !$simulate) {
+    drush_set_error(dt('Could not drop database: @name', array('@name' => $db_name)));
     return;
   }
 
-  if (drush_op('system', $exec . '"CREATE DATABASE ' . $db_spec['database'] . '"') && !drush_get_context('DRUSH_SIMULATE')) {
-    drush_set_error(dt('Could not create new database: @name', array('@name' => $db_spec['database'])));
+  if (drush_op('system', "$execute='CREATE DATABASE `$db_name`'") && !$simulate) {
+    drush_set_error(dt('Could not create new database: @name', array('@name' => $db_name)));
     return;
   }
 }
Index: commands/sql/sql.drush.inc
===================================================================
RCS file: /cvs/drupal-contrib/contributions/modules/drush/commands/sql/sql.drush.inc,v
retrieving revision 1.49
diff -u -p -r1.49 sql.drush.inc
--- commands/sql/sql.drush.inc	8 Jun 2010 20:24:42 -0000	1.49
+++ commands/sql/sql.drush.inc	28 Sep 2010 23:42:44 -0000
@@ -523,26 +523,60 @@ function _drush_sql_get_credentials($db_
     $db_spec = _drush_sql_get_db_spec();
   }
 
+  // Build an array of key-value pairs for the parameters.
+  $parameters = array();
+
   switch (_drush_sql_get_scheme($db_spec)) {
     case 'mysql':
-      $cred = ' -h' . $db_spec['host'] .
-         (empty($db_spec['port']) ? '' : ' -P' . $db_spec['port']) .
-         ' -u' . $db_spec['username'] .
-         (empty($db_spec['password']) ? '' : ' -p' . $db_spec['password']) . ' ' . $db_spec['database'];
+      // Some drush commands (e.g. site-install) want to connect to the
+      // server, but not the database.  Connect to the built-in database.
+      $parameters['database'] = empty($db_spec['database']) ? 'information_schema' : $db_spec['database'];
+
+      // Host is required.
+      $parameters['host'] = $db_spec['host'];
+
+      // An empty port is invalid.
+      if (!empty($db_spec['port'])) {
+        $parameters['port'] = $db_spec['port'];
+      }
+
+      // User is required. Drupal calls it 'username'. MySQL calls it 'user'.
+      $parameters['user'] = $db_spec['username'];
+
+      // EMPTY password is not the same as NO password, and is valid.
+      if (isset($db_spec['password'])) {
+        $parameters['password'] = $db_spec['password'];
+      }
       break;
-  case 'pgsql':
-      $cred = (isset($db_spec['database']) ? ' -d ' . (empty($db_spec['database']) ? 'template1' :  $db_spec['database']) : '') .
-         (empty($db_spec['host'])  ? ' -h localhost ' : ' -h ' . $db_spec['host']) .
-         (empty($db_spec['port']) ? ' -p 5432 ' : ' -p ' . $db_spec['port']);
-      // Adding '-U' will cause Postgres to prompt for a password, so disable this for now.
-      // Use "sudo -u postgres drush sql ..." to access the database without a password,
-      // presuming that "postgres" is the database superuser and you have
-      // "local all all ident sameuser" in your Postgres pg_hba.conf file.
-      // See: http://drupal.org/node/438828
-      $cred .= ' -U ' . $db_spec['username'] . ' ';
+
+    case 'pgsql':
+      // Database is optional in Postgres.
+      if (isset($db_spec['database'])) {
+        $parameters['dbname'] = empty($db_spec['database']) ? 'template1' : $db_spec['database'];
+      }
+
+      // Host and port are optional but have defaults.
+      $parameters['host'] = empty($db_spec['host']) ? 'localhost' : $db_spec['host'];
+      $parameters['port'] = empty($db_spec['port']) ? '5432' : $db_spec['port'];
+
+      // Username is required.
+      $parameters['username'] = $db_spec['username'];
+
+      // Don't set the password.
+      // @see http://drupal.org/node/438828
       break;
   }
-  return escapeshellcmd($cred);
+
+  // Turn each parameter into a valid parameter string.
+  $parameter_strings = array();
+  foreach ($parameters as $key => $value) {
+    // Only escape the values, not the keys or the rest of the string.
+    $value = escapeshellcmd($value);
+    $parameter_strings[] = "--$key='$value'";
+  }
+
+  // Join the parameters and return.
+  return implode(' ', $parameter_strings);
 }
 
 function _drush_sql_get_invalid_url_msg($db_spec = NULL) {
