Skip to content

fix: quote config map values written into generated shell files - #1794

Open
Grace Wehner (gracewehner) wants to merge 1 commit into
ci_prodfrom
grwehner/harden-agent-config-value-handling
Open

Grace Wehner (gracewehner) wants to merge 1 commit into
ci_prodfrom
grwehner/harden-agent-config-value-handling

Conversation

@gracewehner

@gracewehner Grace Wehner (gracewehner) commented Oct 6, 2026 •

Copy link
Copy Markdown
Member

Follow-up to #1790. Fixes the unquoted interpolation in tomlparser-common-agent-config.rb, tomlparser-metric-collection-config.rb and setGlobalEnvVar, so a config map value still goes through shell processing when the generated file is sourced: quotes truncate it, a bare $ gets substituted away, surrounding whitespace is dropped.

Validated that there is no regressions or behavior changes for valid configs, both default and customized.

Tested on a backdoor cluster that the settings still reach the processes and settings still take effect.

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@gracewehner Grace Wehner (gracewehner) changed the title Quote config map values written into generated shell files fix: quote config map values written into generated shell files Oct 6, 2026
Follows #1790, which quoted the values written by tomlparser.rb. The same
unquoted interpolation remains in two other parsers and in setGlobalEnvVar, so
a value is subject to shell processing when the generated file is sourced
rather than arriving as configured: quotes truncate it, a bare $ is substituted
away, and surrounding whitespace is dropped.

Reuses the get_command_linux helper introduced by #1790, defined locally in
each parser to match how get_command_windows is already handled across the
tree:

- tomlparser-common-agent-config.rb and tomlparser-metric-collection-config.rb
- setGlobalEnvVar, which re-emitted values into /opt/env_vars using double
  quotes, leaving them open to the same processing when that file is sourced

Behaviour is unchanged for well-formed configuration. Across every affected
setting and value shape, the variable bash ends up with after sourcing is
identical to before, for both the shipped defaults and a fully populated
config. The Windows KEY=VALUE writes are untouched, since those are split on
'=' and must not carry quotes.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@gracewehner
Grace Wehner (gracewehner) force-pushed the grwehner/harden-agent-config-value-handling branch from 3c0e7b1 to f2d0b8c Compare October 6, 2026 17:18
@gracewehner

Copy link
Copy Markdown
Member Author

/azp run

@gracewehner
Grace Wehner (gracewehner) marked this pull request as ready for review October 6, 2026 17:24
@gracewehner
Grace Wehner (gracewehner) requested a review from a team as a code owner October 6, 2026 17:24
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 1 pipeline(s).
2 pipeline(s) were filtered out due to trigger conditions.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant