Skip to content

Harden install scripts against unusual option values (quote interpolations, validate version) #35

Description

@NicoVIII

Amber compiles {expr} interpolations inside $ ... $ command blocks to unquoted bash expansions, e.g. wget -qO ${local_filename} ${url} in the generated install.sh files. The version option is free-form text from a user's devcontainer.json, so a value containing spaces or glob characters word-splits into extra command arguments and fails in confusing ways (and is generally not a great injection surface).

Two complementary fixes:

  1. Quote interpolated values inside the Amber command blocks where they are used as single arguments, e.g. $ wget -qO "{local_filename}" "{url}" $, across lib/ and the feature scripts.
  2. Validate the version option early against a conservative pattern (e.g. ^[A-Za-z0-9._-]+$) and fail with a clear error message otherwise.

Touches lib/download.ab among others, so this should be coordinated with (or rebased on) PR #33, which rewrites the latest-version lookup in that file.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    foundationFoundation work which e.g. improves DX or code quality

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions