Skip to content

fix(unikernels): reject single quotes in Linux init args to prevent boot-cmdline corruption - #898

Draft
Anand-240 wants to merge 1 commit into
urunc-dev:mainfrom
Anand-240:fix/linux-cmdline-quote-escaping
Draft

fix(unikernels): reject single quotes in Linux init args to prevent boot-cmdline corruption#898
Anand-240 wants to merge 1 commit into
urunc-dev:mainfrom
Anand-240:fix/linux-cmdline-quote-escaping

Conversation

@Anand-240

@Anand-240 Anand-240 commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Summary

parseCmdLine() in pkg/unikontainers/unikernels/linux.go wraps multi-word arguments in single quotes so urunit can recover argument boundaries from the guest's boot cmdline. It does this with plain string concatenation and does not escape quote characters already present in the argument.

If an argument contains both a space and a single quote, for example sh -c "echo it's broken", the wrap produces an unbalanced quote sequence such as 'sh' 'echo it's broken', which corrupts the token boundaries that urunit parses out of /proc/cmdline. The guest init process can then receive the wrong arguments with no error surfaced to the user.

Since urunit's own cmdline parser lives outside this repo and its escaping rules are not known here, this change rejects arguments containing a single quote with a clear error instead of guessing an escaping scheme that might not match what urunit actually supports.

Fixes #897

Changes

  • pkg/unikontainers/unikernels/linux.go: parseCmdLine now returns an error when an argument contains a single quote, before attempting to wrap it.
  • pkg/unikontainers/unikernels/linux_test.go: new table driven tests covering the empty cmdline case, single word app, multi word argument quoting, and the new rejection behavior for quoted arguments.

Test plan

  • go test ./pkg/unikontainers/unikernels/... -run TestLinux -v passes (5/5 subtests)
  • go build ./pkg/unikontainers/unikernels/... succeeds

…oot-cmdline corruption

parseCmdLine() wrapped multi-word arguments in unescaped single quotes
for urunit compatibility. An argument containing both a space and a
single quote, for example sh -c "echo it's broken", produced an
unbalanced quote sequence, corrupting the token-boundary parsing that
urunit performs on /proc/cmdline and causing the guest init process to
receive the wrong arguments.

Since urunit's cmdline parser lives outside this repo and its escaping
semantics are unknown, reject arguments containing a single quote with
a clear error instead of guessing an escaping scheme.

Fixes urunc-dev#897
@netlify

netlify Bot commented Aug 3, 2026

Copy link
Copy Markdown

Deploy Preview for urunc canceled.

Name Link
🔨 Latest commit 244b483
🔍 Latest deploy log https://app.netlify.com/projects/urunc/deploys/6a7120f7a64ea50008617169

@Anand-240 Anand-240 changed the title test fix(unikernels): reject single quotes in Linux init args to prevent boot-cmdline corruption Aug 3, 2026
@cmainas cmainas added invalid This doesn't seem right do-not-merge labels Aug 4, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

do-not-merge invalid This doesn't seem right

Projects

None yet

2 participants