Skip to content

'az sql server create' mishandling password string #10370

Description

@hKaspy

Describe the bug

az sql server create --admin-password argument tries to interpret the password and fails on less-than sign.

I've tried single quotes, double quotes, putting in equal sign, variable... No Luck so far.

Errors:

PS C:\> az sql server create --admin-user "admin" --admin-password a<b
The system cannot find the file specified.
PS C:\> az sql server create --admin-user "admin" --admin-password 'a<b'
The system cannot find the file specified.
PS C:\> az sql server create --admin-user "admin" --admin-password "a<b"
The system cannot find the file specified.
PS C:\> az sql server create --admin-user "admin" --admin-password='a<b'
The system cannot find the file specified.
PS C:\> az sql server create --admin-user "admin" --admin-password="a<b"
The system cannot find the file specified.
PS C:\> $sqlPassword="a<b"
PS C:\> az sql server create --admin-user "admin" --admin-password $sqlPassword
The system cannot find the file specified.
PS C:\> az sql server create --admin-user "admin" --admin-password=$sqlPassword
The system cannot find the file specified.

To Reproduce:

az sql server create --admin-user "admin" --admin-password "a<b"

Expected Behavior

Fails with az sql server create: error: the following arguments are required: --resource-group/-g, --name/-n

Environment Summary

Windows-10-10.0.17134-SP0
Python 3.6.6
Shell: powershell.exe

azure-cli 2.0.71 *

Additional Context

Right-sided parenthesis also breaks this in different way:

PS C:\> az sql server create --admin-user "admin" --admin-password="a)b"
b was unexpected at this time.
C:\>  "C:\Program Files (x86)\Microsoft SDKs\Azure\CLI2\wbin\\..\python.exe" -IBm azure.cli sql server create --admin-user admin --admin-password=a)b

Activity

  1. changed the title [-]'az sql server create' mishandling password[/-] [+]'az sql server create' mishandling password string[/+] on Aug 29, 2019
  2. ghost removed on Aug 30, 2019
  3. jaredmoo commented on Sep 5, 2019

    @jaredmoo
    Contributor

    Thank you for reporting this issue. It looks like this issue affects more than just SQL commands.

    > az group create -n "a<b" -g "westus"
    The system cannot find the file specified.
    

    I'll include the CLI core team to help investigate deeper.

  4. Juliehzl commented on Sep 6, 2019

    @Juliehzl
    Contributor

    Jared Moore (@jaredmoo) are you want to run az group create -n "a<b" -l "westus" not -g "westus"? If yes, az group create will tell you Parameter 'resource_group_name' must conform to the following pattern: '^[-\\w\\._\\(\\)]+$'. az group have validation for parameters. So I think this may be just related to SQL not core.

  5. jaredmoo commented on Sep 6, 2019

    @jaredmoo
    Contributor

    In that case it might just be PowerShell interpreting as I/O redirection. Either way, if I can repro it with another arbitrary command then the issue is not isolated to SQL commands.

  6. added this to the Sprint 75 milestone on Sep 8, 2019
  7. Juliehzl commented on Sep 23, 2019

    @Juliehzl
    Contributor

    Jan Kašpar (@hKaspy) When I want to reproduce your issue, it looks "<" works but ")" cannot be parsed correctly in PS. Can you verify it?
    I really agree with what Jared Moore (@jaredmoo) said, it is more related to PS and there is a little we can do. But I will add these specific letters scenario in CLI document here to make users know these cases and use cli more effectively.

  8. hKaspy commented on Sep 23, 2019

    @hKaspy
    Author

    Zunli Hu (@Juliehzl) Tested again after update to azure-cli 2.0.73, issue still valid with a)b, but a<b resolved.

    Windows-10-10.0.17134-SP0
    Python 3.6.6
    Shell: powershell.exe
    azure-cli 2.0.73 *
    

    I disagree with you and Jared Moore (@jaredmoo), as this hints at bad string handling inside the script, since this happens no mather what string quotation technique I use. Per powershell documentation (5.1 in my case):

    When you enclose a string in single-quotation marks (a single-quoted string), the string is passed to the command exactly as you type it. No substitution is performed.

    Moreover, mkdir "a)b" is completely valid and creates a folder named a)b and mkdir "a>b" fails with mkdir : Illegal characters in path..

    This wouldn't be such a problem for me if it was not a password argument failing. It should accept any printable character. Invalidating <, ) and possibly other characters weakens password security.

    The issue is also in that Web GUI version accepts those characters, so (as happened to me) someone could create the DB password in GUI and then I am unable to replicate this in automated CI/CD script.

  9. hKaspy commented on Sep 23, 2019

    @hKaspy
    Author

    Tested now with Azure Key Vault, so we can rule out the SQL:

    az keyvault secret set --vault-name test-kv --name "test" --value "a)b"
    b was unexpected at this time.
    C:\>  "C:\Program Files (x86)\Microsoft SDKs\Azure\CLI2\wbin\\..\python.exe" -IBm azure.cli keyvault secret set --vault-name ice-sam-test-kv --name test --value a)b
    

    From this debug line i would guess that the problem is with azure.cli script invocation as the argument gets passed (or at least is printed that way in debug) as --value a)b, stripped of quotation marks.

  10. 4 remaining items

  11. yonzhan commented on Nov 2, 2019

    @yonzhan
    Collaborator

    Zunli Hu (@Juliehzl) please create a PS ticket and put it here, then we can close this issue.

  12. ArgTang commented on Nov 26, 2019

    @ArgTang

    Same issue for az postgres server create < and ) in pasword arg crashed prosess
    powershell 5, az cli 2.0.76

  13. modified the milestones: S161, S162 on Dec 1, 2019
  14. Juliehzl commented on Dec 1, 2019

    @Juliehzl
    Contributor

    Same issue for az postgres server create < and ) in pasword arg crashed prosess
    powershell 5, az cli 2.0.76

    Hi ArgTang, it is a powershell issue. Could you use cmd to unblock yourself? Out of curiosity, ) doesn't work for you, right? Could you share more info about ) scenario with me? It works for me as follows again.
    image

  15. jiasli commented on Dec 4, 2019

    @jiasli
    Contributor

    As Zunli Hu (@Juliehzl) stated, this is a Windows PowerShell issue. We have updated CLI doc for explanation and workaround: https://github.com/Azure/azure-cli/blob/dev/doc/use_cli_effectively.md#argument-parsing-issue-in-powershell

  16. jeroenterheerdt commented on Dec 6, 2019

    @jeroenterheerdt

    ArgTang please let us know if you need more help - otherwise we will proceed to close this issue.

  17. ArgTang commented on Dec 6, 2019

    @ArgTang

    Jeroen ter Heerdt (@jeroenterheerdt) no, i think we have a workaround. thanks

  18. jeroenterheerdt commented on Dec 6, 2019

    @jeroenterheerdt

    Jiashuo Li (@jiasli) please go ahead and close this.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions