Skip to content

Harden bin/example-image and bin/load against shell injection - #76

Merged
flavorjones merged 1 commit into
masterfrom
issue-33-shell-interpolation
Sep 29, 2026
Merged

flavorjones merged 1 commit into
masterfrom
issue-33-shell-interpolation

Conversation

@flavorjones

Copy link
Copy Markdown
Member

Motivation

bin/example-image builds the example cell image. bin/load boots a cell image and drives a load scenario against it from a second container, the driver. They are developer and CI helpers. Neither is on the production conversion path.

Each passed an input through a shell:

  • bin/example-image listed each gem's files with git -C #{REPO} ls-files #{gem} in backticks (bin/example-image:60). REPO is the checkout path. A path that contained shell syntax such as $(...) ran as a command on the host, and a path with a space broke the listing.
  • bin/load built the driver's bash -c string with $SCENARIO $SECONDS_ARG $THREADS inside it (bin/load:62-66). Shell syntax in any of those arguments ran as a command in the driver container.

The person running the script supplies these values, so the impact is low. The purple-team assessment of 2026-08-22 rated it Low (HC-PT-014).

Details

  • bin/example-image runs git through IO.popen with an argument array.
  • bin/load passes the values as positional parameters to a fixed bash -c program, which hands them to examples/load as "$@".
  • examples/gate runs each script against a fake docker with $(touch injected) in its inputs. Each check fails if the file appears, and fails against the scripts on master.

Additional information

The issue also suggests validating the numeric inputs in bin/load and pinning the driver image. This PR does neither. examples/load already rejects a non-numeric duration or thread count with Float() and Integer(). bin/conformance uses the same unpinned ruby:3.4 driver default, so pinning belongs in a separate change that covers both scripts.

Fixes #33

`bin/example-image` ran `git ls-files` through a shell with the checkout
path in the command string, and `bin/load` put its scenario, duration
and thread count into a `bash -c` string run in the driver container. A
value containing shell syntax ran as a command. Pass these values to
the commands as arguments.

[Fix #33]
Copilot AI balanced review requested due to automatic review settings September 28, 2026 21:28

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@flavorjones
flavorjones merged commit 079e811 into master Sep 29, 2026
16 checks passed
@flavorjones
flavorjones deleted the issue-33-shell-interpolation branch September 29, 2026 16:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Developer helpers interpolate values into shell strings

2 participants