Skip to content

Commit 3181ad7

Browse files
cloud-setup-databases: shell-escape values passed to EncryptionCLI
processEncryptionStuff()'s encrypt() built the java EncryptionCLI command by hand-wrapping each dynamic value in literal double quotes, then handed the joined string to runCmd(), which runs it through `subprocess.Popen(..., shell=True)`. Double quotes do not stop the shell from expanding "$..." inside them, so a password like `pa$sword` is silently truncated to `pa` before it ever reaches EncryptionCLI, and the wrong value gets encrypted into db.properties. Use shlex.quote() instead of manual double-quote wrapping for the jar path, the value being encrypted, and the management server secret key. shlex.quote() produces shell-safe quoting for arbitrary values, including but not limited to '$'. Verified with a standalone reproduction that shells out the same way runCmd() does: with the old double-quote wrapping, a password of `pa$sword` arrives at the child process as `pa`; with shlex.quote(), it arrives intact as `pa$sword`. Fixes: #14186 Signed-off-by: SiddharthSanch <111047247+SiddharthSanch@users.noreply.github.com>
1 parent ac8d69c commit 3181ad7

1 file changed

Lines changed: 8 additions & 2 deletions

File tree

‎setup/bindir/cloud-setup-databases.in‎

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -21,6 +21,7 @@ import os
2121
import sys
2222
import subprocess
2323
import glob
24+
import shlex
2425
from random import choice
2526
import string
2627
from optparse import OptionParser
@@ -418,8 +419,13 @@ for example:
418419

419420
def processEncryptionStuff(self):
420421
def encrypt(value):
421-
cmd = ['java','-classpath','"' + self.encryptionJarPath + '"','com.cloud.utils.crypt.EncryptionCLI','-i','"' + value + '"', '-p', '"' +
422-
self.mgmtsecretkey + '"', self.encryptorVersion]
422+
# runCmd() joins this list with spaces and runs it through a shell, so each
423+
# dynamic value must be shell-escaped with shlex.quote() rather than hand-wrapped
424+
# in double quotes: double quotes still let the shell expand "$..." in the value
425+
# (e.g. a password of pa$sword is truncated to pa), silently corrupting it.
426+
cmd = ['java', '-classpath', shlex.quote(self.encryptionJarPath),
427+
'com.cloud.utils.crypt.EncryptionCLI', '-i', shlex.quote(value),
428+
'-p', shlex.quote(self.mgmtsecretkey), self.encryptorVersion]
423429
return str(runCmd(cmd)).strip('\r\n')
424430

425431
def saveMgmtServerSecretKey():

0 commit comments

Comments
 (0)