Skip to content

Commit

Permalink
Fix golangci-lint errors
Browse files Browse the repository at this point in the history
Fixes golangci-lint errors introduced by containers#258

If `gosec` linting is enabled for the return statement in `Cmd`, an
error will be returned: `G204: Subprocess launched with a potential tainted
input or cmd arguments (gosec)`. This error tries to make sure a
user cannot provide a binary that could cause harm to the system. However,
since the binary path is sanitized and the arguments are generated by
gvproxy, this should be safe to ignore.

Signed-off-by: Jake Correnti <jakecorrenti+github@proton.me>
  • Loading branch information
jakecorrenti committed Aug 17, 2023
1 parent ff26e92 commit 0d4226d
Show file tree
Hide file tree
Showing 2 changed files with 36 additions and 7 deletions.
30 changes: 23 additions & 7 deletions pkg/types/command.go
Original file line number Diff line number Diff line change
@@ -1,8 +1,10 @@
package types

import (
"errors"
"fmt"
"os/exec"
"strings"
)

type Command struct {
Expand Down Expand Up @@ -85,11 +87,7 @@ func (c *Command) AddVfkitSocket(socket string) {
}

func (c *Command) addForwardInfo(flag, value string) {
if _, ok := c.forwardInfo[flag]; ok {
c.forwardInfo[flag] = append(c.forwardInfo[flag], value)
} else {
c.forwardInfo[flag] = []string{value}
}
c.forwardInfo[flag] = append(c.forwardInfo[flag], value)
}

func (c *Command) AddForwardSock(socket string) {
Expand Down Expand Up @@ -186,8 +184,26 @@ func (c *Command) ToCmdline() []string {
return args
}

// validateGvproxyPath ensures the path provided by the user points to a gvproxy
// binary
func validateGvproxyPath(path string) error {
if !strings.ContainsAny(path, "/") && path == "gvproxy" {
return nil
}

lastSlashIndex := strings.LastIndex(path, "/")
if path[lastSlashIndex+1:] == "gvproxy" {
return nil
}

return errors.New("Invalid gvproxy binary path: " + path)
}

// Cmd converts Command to a commandline format and returns an exec.Cmd which
// can be executed by os/exec
func (c *Command) Cmd(gvproxyPath string) *exec.Cmd {
return exec.Command(gvproxyPath, c.ToCmdline()...)
func (c *Command) Cmd(gvproxyPath string) (*exec.Cmd, error) {
if err := validateGvproxyPath(gvproxyPath); err != nil {
return nil, err
}
return exec.Command(gvproxyPath, c.ToCmdline()...), nil // nolint:gosec
}
13 changes: 13 additions & 0 deletions test/basic_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -217,4 +217,17 @@ var _ = Describe("command-line format", func() {
"-pid-file ~/gv-pidfile.txt",
}))
})

It("invalid gvproxy path", func() {
command := types.NewCommand()
_, err := command.Cmd("/usr/bin/gvproxy-wrong")
Expect(err).To(HaveOccurred())
Expect(err.Error()).To(Equal("Invalid gvproxy binary path: /usr/bin/gvproxy-wrong"))
})

It("valid gvproxy path", func() {
command := types.NewCommand()
_, err := command.Cmd("/usr/bin/gvproxy")
Expect(err).ToNot(HaveOccurred())
})
})

0 comments on commit 0d4226d

Please sign in to comment.