Skip to content

Reject null characters in process arguments - #135236

Merged
adamsitnik merged 1 commit into
dotnet:mainfrom
adamsitnik:reject-null-process-arguments
Oct 6, 2026
Merged

adamsitnik merged 1 commit into
dotnet:mainfrom
adamsitnik:reject-null-process-arguments

Conversation

@adamsitnik

Copy link
Copy Markdown
Member

Summary

Reject embedded null characters in ProcessStartInfo.Arguments and ProcessStartInfo.ArgumentList when starting a process.

Validation runs in the shared ProcessStartInfo.ThrowIfInvalid path, before platform-specific command-line or argv construction. It reports Arguments or the indexed ArgumentList[n] entry as the invalid parameter.

As with the environment-variable validation added in #132214 and clarified in #132640, this is hygienic validation rather than a primary security mitigation. Process arguments are trusted inputs under .NET's published security baseline.

Tests

  • dotnet build /t:test .\src\libraries\System.Diagnostics.Process\tests\System.Diagnostics.Process.Tests.csproj — passed: 692 total, 0 failed, 2 skipped.
  • Verified both new regression tests failed before the implementation and passed afterward.

Note

This pull request description was generated by GitHub Copilot.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: f5c176bc-b912-4c76-9b72-ff2c26f2bba0
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).
13 pipeline(s) were filtered out due to trigger conditions.
There may be pipelines that require an authorized user to comment /azp run to run.

@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @dotnet/area-system-diagnostics-process
See info in area-owners.md if you want to be subscribed.

@adamsitnik
adamsitnik merged commit f236034 into dotnet:main Oct 6, 2026
85 of 87 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants