Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 20 Jun 2018 06:24:03 +0000 (UTC)
From:      Devin Teske <dteske@FreeBSD.org>
To:        src-committers@freebsd.org, svn-src-all@freebsd.org, svn-src-stable@freebsd.org, svn-src-stable-11@freebsd.org
Subject:   svn commit: r335409 - stable/11/usr.sbin/sysrc
Message-ID:  <201806200624.w5K6O318015062@repo.freebsd.org>

next in thread | raw e-mail | index | archive | help
Author: dteske
Date: Wed Jun 20 06:24:03 2018
New Revision: 335409
URL: https://svnweb.freebsd.org/changeset/base/335409

Log:
  MFC r334303: sysrc(8): Test variable names for invalid characters
  
  PR:		bin/187461
  Reported by:	ebay@looksharp.net
  Sponsored by:	Smule, Inc.

Modified:
  stable/11/usr.sbin/sysrc/sysrc
Directory Properties:
  stable/11/   (props changed)

Modified: stable/11/usr.sbin/sysrc/sysrc
==============================================================================
--- stable/11/usr.sbin/sysrc/sysrc	Wed Jun 20 06:11:51 2018	(r335408)
+++ stable/11/usr.sbin/sysrc/sysrc	Wed Jun 20 06:24:03 2018	(r335409)
@@ -370,6 +370,18 @@ if [ "$LIST_SERVICE_CONFS" ]; then
 fi
 
 #
+# Validate arguments
+#
+for name in "$@"; do
+	# NB: shell expansion syntax removed first
+	name="${name%%:[+=-]*}"
+	name="${name%%[%#+=-]*}"
+	[ "$name" = "${name#*[!$VALID_VARNAME_CHARS]}" ] || die \
+		"%s: %s: name contains characters not allowed in shell" \
+		"$pgm" "$name"
+done
+
+#
 # Process `-s name' argument
 #
 if [ "$SERVICE" -a ! "${RC_CONFS+set}" ]; then



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201806200624.w5K6O318015062>