security: audit Command call sites; confirm no argument injection
Closes #18 All six Command::new call sites audited: - bitwarden.rs (sh -c): shell string is a hardcoded literal; no user data. - bitwarden.rs (bw unlock): all args hardcoded. - bitwarden.rs (bw get): item_name and session passed as discrete .args() elements; no shell. - nothooks/runner.rs (nu/sh/etc): interp and script path passed as discrete args; no shell. - notstrap/repo.rs (git clone): url and dest passed as discrete .arg() calls; no shell. - notfiles/tests/integration.rs: test harness with hardcoded args only. Added SAFETY comments on the three sites that handle user-controlled config values.
This commit is contained in:
@@ -89,6 +89,10 @@ impl HookRunner {
|
||||
Ok(i) => i,
|
||||
Err(msg) => return HookResult::Failed(msg),
|
||||
};
|
||||
// SAFETY: `interp` is derived from the file extension or an explicit `interpreter` field
|
||||
// in HookSpec (both come from config, not untrusted shell input). `spec.script` is a
|
||||
// filesystem path from config. Both are passed as discrete args with no shell involved,
|
||||
// so argument injection is not possible.
|
||||
let result = Command::new(&interp).arg(&spec.script).status();
|
||||
|
||||
match result {
|
||||
|
||||
Reference in New Issue
Block a user