Skip to content

Remote activate/wait/revoke commands use naive shell quoting #400

Description

@heitor-lassarote

build_activate_command, build_wait_command, and build_revoke_command in src/deploy.rs build the command sent to the remote host as a single ssh argument. They quote values by hand: closure, temp_path, and profile_path get wrapped in hard-coded single quotes, while profile_user, profile_name, and log_dir are interpolated with no quoting at all.

If any of those values contain a single quote or a space, the resulting command breaks, or in the worst case lets extra shell syntax through to the remote shell.

This is the same class of bug as #130, which #347 just fixed for --ssh-opts using the shlex crate. The fix here would look similar: build each command as a list of tokens instead of a hand-formatted string, then join the tokens with shlex::try_join (falling back to a plain space join on the rare try_join error) right before handing the result to ssh.

sudo_cmd should stay as-is: it's meant to be parsed as shell syntax by the remote host (e.g. sudo -u deploy), not treated as a single literal value.

In practice these values are usually safe, since Nix store paths can't contain quotes or spaces. So this is lower severity than #130 was. But profile_user, profile_name, and log_dir come from a deploy.nix config the tool doesn't otherwise constrain, so it's worth fixing properly rather than leaving it as a latent bug.

Found while reviewing #347.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions