makeBinaryWrapper: reject prefix/suffix with an empty path segment

Preferred to reject explictly the value instead of silently sanitizing
it. It's closer to what we do for the invalid env name and it will allow
us to spot derivation that were impacted by the issue that has not yet
been fixed.

(cherry picked from commit d2cbb4ba81)
This commit is contained in:
Thomas Gerbet
2026-08-02 16:58:01 +02:00
committed by github-actions[bot]
parent 0c32f40fe3
commit 037cf8a7f0

View File

@@ -261,6 +261,7 @@ setEnvPrefix() {
val=$(escapeStringLiteral "$3")
printf '%s' "set_env_prefix(\"$env\", \"$sep\", \"$val\");"
assertValidEnvName "$1"
assertNoEmptySegment "--prefix" "$1" "$2" "$3"
}
# suffix ENV SEP VAL
@@ -271,6 +272,7 @@ setEnvSuffix() {
val=$(escapeStringLiteral "$3")
printf '%s' "set_env_suffix(\"$env\", \"$sep\", \"$val\");"
assertValidEnvName "$1"
assertNoEmptySegment "--suffix" "$1" "$2" "$3"
}
# setEnv KEY VALUE
@@ -323,6 +325,14 @@ assertValidEnvName() {
esac
}
assertNoEmptySegment() {
local flag="$1" env="$2" sep="$3" val="$4"
[ -n "$sep" ] || return 0
if [[ "$sep$val$sep" == *"$sep$sep"* ]]; then
printf '\n%s\n' "#error $flag $env would introduce an empty PATH-like segment (empty, or a leading/trailing/doubled \`$sep\`). This is interpreted as \"search the current directory\" by shells, execvp() and the dynamic linker, see https://github.com/NixOS/nixpkgs/security/advisories/GHSA-p7v3-pr2c-8584. Guard the value with e.g. lib.optionalString (list != [])."
fi
}
setSepSurroundCheck() {
printf '%s' "\
int is_surrounded_by_sep(char *env, char *ptr, unsigned long len, char *sep) {