fix(unikernels): reject single quotes in Linux init args to prevent boot-cmdline corruption - #898
Draft
Anand-240 wants to merge 1 commit into
Draft
Conversation
…oot-cmdline corruption parseCmdLine() wrapped multi-word arguments in unescaped single quotes for urunit compatibility. An argument containing both a space and a single quote, for example sh -c "echo it's broken", produced an unbalanced quote sequence, corrupting the token-boundary parsing that urunit performs on /proc/cmdline and causing the guest init process to receive the wrong arguments. Since urunit's cmdline parser lives outside this repo and its escaping semantics are unknown, reject arguments containing a single quote with a clear error instead of guessing an escaping scheme. Fixes urunc-dev#897
✅ Deploy Preview for urunc canceled.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
parseCmdLine() in pkg/unikontainers/unikernels/linux.go wraps multi-word arguments in single quotes so urunit can recover argument boundaries from the guest's boot cmdline. It does this with plain string concatenation and does not escape quote characters already present in the argument.
If an argument contains both a space and a single quote, for example sh -c "echo it's broken", the wrap produces an unbalanced quote sequence such as 'sh' 'echo it's broken', which corrupts the token boundaries that urunit parses out of /proc/cmdline. The guest init process can then receive the wrong arguments with no error surfaced to the user.
Since urunit's own cmdline parser lives outside this repo and its escaping rules are not known here, this change rejects arguments containing a single quote with a clear error instead of guessing an escaping scheme that might not match what urunit actually supports.
Fixes #897
Changes
Test plan