Keep places and accesses at the terminal, and refuse a line break in any setting
Through the settings verb, or a settings line run by the generic command verb, any caller of the mesh's console could place a module's directory at /etc with an owner of its own and have the node-engine, as root, hand it over at the next push, or mount any of the machine's paths into a container (hq issue 339). A change to either key is now refused in every process a verb runs, the generic verb refuses settings writes outright, and neither key may name the machine's own trees from anywhere, the terminal included. A line break, carriage return or NUL in any setting, which a file it is written into reads as a line of the caller's own, is refused where a layer is kept and where it is composed; PEM blocks alone may hold lines.
This commit is contained in:
@@ -245,7 +245,7 @@ func TestCommandRunsTheLineAsGiven(t *testing.T) {
|
||||
if err != nil || strings.Join(argv, " ") != "node account g14 jochen" {
|
||||
t.Fatalf("a plain line: %v %v", argv, err)
|
||||
}
|
||||
argv, err = argvFor("command", map[string]any{"command": `settings set dnsmasq '{"a": "b c"}' --node ace`})
|
||||
argv, err = argvFor("command", map[string]any{"command": `settings show dnsmasq '{"a": "b c"}' --node ace`})
|
||||
if err != nil || len(argv) != 6 || argv[3] != `{"a": "b c"}` {
|
||||
t.Fatalf("a quoted word stays one word: %q %v", argv, err)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user