Repository navigation
Run chown and id without a shell - #157
Conversation
osFileSystem.chown built "id -g <user>" and "chown '<user>:<group>' '<path>'" as strings and ran them with sh -c. The user, group and path now go to id and chown as separate arguments, after "--", so shell syntax in any of them stays plain text. The error messages do not change. homeDir still uses runCommand, because it needs the shell to expand ~user. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (2)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. Walkthrough
Suggested reviewers: Priority: ⬇️ Low Merge Risk: ⚪ Minimal · up to The direct 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
🟢 Approval recommended
The implementation safely preserves arguments as literal values and tests both affected injection paths.
0 open findings
What changed in this PR
Removes shell invocation from Unix ownership changes to prevent command injection.
Changes:
- Executes
idandchownwith discrete arguments and--. - Adds regression tests for shell syntax in paths and owners.
| File | Description |
|---|---|
system/os_file_system_unix.go |
Adds shell-free command execution for chown. |
system/os_file_system_unix_test.go |
Verifies shell syntax is not executed. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
What
osFileSystem.chownbuiltid -g <user>andchown '<user>:<group>' '<path>'as strings and ran them withsh -c. Now the user, group and path go toidandchownas separate arguments, after--. Shell syntax in any of them stays plain text.homeDirstill usesrunCommand, because it needs the shell to expand~user.chown -- user:group path, notchown user:group -- path. BSDchownreads a--after the first operand as a file name.Checks
systempackage on macOSgolang:1.26CopyFile/CopyDirspecs ingolang:1.26lsof; not related🤖 Generated with Claude Code