build_activate_command, build_wait_command, and build_revoke_command in src/deploy.rs build the command sent to the remote host as a single ssh argument. They quote values by hand: closure, temp_path, and profile_path get wrapped in hard-coded single quotes, while profile_user, profile_name, and log_dir are interpolated with no quoting at all.
If any of those values contain a single quote or a space, the resulting command breaks, or in the worst case lets extra shell syntax through to the remote shell.
This is the same class of bug as #130, which #347 just fixed for --ssh-opts using the shlex crate. The fix here would look similar: build each command as a list of tokens instead of a hand-formatted string, then join the tokens with shlex::try_join (falling back to a plain space join on the rare try_join error) right before handing the result to ssh.
sudo_cmd should stay as-is: it's meant to be parsed as shell syntax by the remote host (e.g. sudo -u deploy), not treated as a single literal value.
In practice these values are usually safe, since Nix store paths can't contain quotes or spaces. So this is lower severity than #130 was. But profile_user, profile_name, and log_dir come from a deploy.nix config the tool doesn't otherwise constrain, so it's worth fixing properly rather than leaving it as a latent bug.
Found while reviewing #347.
build_activate_command,build_wait_command, andbuild_revoke_commandinsrc/deploy.rsbuild the command sent to the remote host as a singlesshargument. They quote values by hand:closure,temp_path, andprofile_pathget wrapped in hard-coded single quotes, whileprofile_user,profile_name, andlog_dirare interpolated with no quoting at all.If any of those values contain a single quote or a space, the resulting command breaks, or in the worst case lets extra shell syntax through to the remote shell.
This is the same class of bug as #130, which #347 just fixed for
--ssh-optsusing theshlexcrate. The fix here would look similar: build each command as a list of tokens instead of a hand-formatted string, then join the tokens withshlex::try_join(falling back to a plain space join on the raretry_joinerror) right before handing the result tossh.sudo_cmdshould stay as-is: it's meant to be parsed as shell syntax by the remote host (e.g.sudo -u deploy), not treated as a single literal value.In practice these values are usually safe, since Nix store paths can't contain quotes or spaces. So this is lower severity than #130 was. But
profile_user,profile_name, andlog_dircome from adeploy.nixconfig the tool doesn't otherwise constrain, so it's worth fixing properly rather than leaving it as a latent bug.Found while reviewing #347.