Fix shell injection in user_set_shell and chown
Use argv list with run() instead of sh -c with f-string interpolation, fix mutable default argument in chown, add debug logging on failure.
This commit is contained in:
parent
cd62eff4a7
commit
06f296289e
|
|
@ -1964,18 +1964,22 @@ class Installer:
|
||||||
def user_set_shell(self, user: str, shell: str) -> bool:
|
def user_set_shell(self, user: str, shell: str) -> bool:
|
||||||
info(f'Setting shell for {user} to {shell}')
|
info(f'Setting shell for {user} to {shell}')
|
||||||
|
|
||||||
|
cmd = ['arch-chroot', '-S', str(self.target), 'chsh', '-s', shell, user]
|
||||||
try:
|
try:
|
||||||
self.arch_chroot(f'sh -c "chsh -s {shell} {user}"')
|
run(cmd)
|
||||||
return True
|
return True
|
||||||
except SysCallError:
|
except CalledProcessError as err:
|
||||||
|
debug(f'Error setting user shell: {err}')
|
||||||
return False
|
return False
|
||||||
|
|
||||||
def chown(self, owner: str, path: str, options: list[str] = []) -> bool:
|
def chown(self, owner: str, path: str, options: list[str] | None = None) -> bool:
|
||||||
cleaned_path = path.replace("'", "\\'")
|
options = options or []
|
||||||
|
cmd = ['arch-chroot', '-S', str(self.target), 'chown', *options, owner, path]
|
||||||
try:
|
try:
|
||||||
self.arch_chroot(f"sh -c 'chown {' '.join(options)} {owner} {cleaned_path}'")
|
run(cmd)
|
||||||
return True
|
return True
|
||||||
except SysCallError:
|
except CalledProcessError as err:
|
||||||
|
debug(f'Error changing ownership of {path}: {err}')
|
||||||
return False
|
return False
|
||||||
|
|
||||||
def set_vconsole(self, locale_config: LocaleConfiguration) -> None:
|
def set_vconsole(self, locale_config: LocaleConfiguration) -> None:
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue