makeBinaryWrapper: reject prefix/suffix with an empty path segment

Preferred to reject explictly the value instead of silently sanitizing
it. It's closer to what we do for the invalid env name and it will allow
us to spot derivation that were impacted by the issue that has not yet
been fixed.

(cherry picked from commit d2cbb4ba81)
This commit is contained in:
Thomas Gerbet
2026-08-02 16:58:01 +02:00
committed by github-actions[bot]
parent 727e2e000c
commit db7e106fc1

View File

@@ -261,6 +261,7 @@ setEnvPrefix() {
val=$(escapeStringLiteral "$3")
printf '%s' "set_env_prefix(\"$env\", \"$sep\", \"$val\");"
assertValidEnvName "$1"
assertNoEmptySegment "--prefix" "$1" "$2" "$3"
}
# suffix ENV SEP VAL
@@ -271,6 +272,7 @@ setEnvSuffix() {
val=$(escapeStringLiteral "$3")
printf '%s' "set_env_suffix(\"$env\", \"$sep\", \"$val\");"
assertValidEnvName "$1"
assertNoEmptySegment "--suffix" "$1" "$2" "$3"
}
# setEnv KEY VALUE
@@ -323,6 +325,14 @@ assertValidEnvName() {
esac
}
assertNoEmptySegment() {
local flag="$1" env="$2" sep="$3" val="$4"
[ -n "$sep" ] || return 0
if [[ "$sep$val$sep" == *"$sep$sep"* ]]; then
printf '\n%s\n' "#error $flag $env would introduce an empty PATH-like segment (empty, or a leading/trailing/doubled \`$sep\`). This is interpreted as \"search the current directory\" by shells, execvp() and the dynamic linker, see https://github.com/NixOS/nixpkgs/security/advisories/GHSA-p7v3-pr2c-8584. Guard the value with e.g. lib.optionalString (list != [])."
fi
}
setSepSurroundCheck() {
printf '%s' "\
int is_surrounded_by_sep(char *env, char *ptr, unsigned long len, char *sep) {