diff --git a/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh b/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh index 275f77ea3e71..fa59cb7d15a3 100644 --- a/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh +++ b/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh @@ -261,6 +261,7 @@ setEnvPrefix() { val=$(escapeStringLiteral "$3") printf '%s' "set_env_prefix(\"$env\", \"$sep\", \"$val\");" assertValidEnvName "$1" + assertNoEmptySegment "--prefix" "$1" "$2" "$3" } # suffix ENV SEP VAL @@ -271,6 +272,7 @@ setEnvSuffix() { val=$(escapeStringLiteral "$3") printf '%s' "set_env_suffix(\"$env\", \"$sep\", \"$val\");" assertValidEnvName "$1" + assertNoEmptySegment "--suffix" "$1" "$2" "$3" } # setEnv KEY VALUE @@ -323,6 +325,14 @@ assertValidEnvName() { esac } +assertNoEmptySegment() { + local flag="$1" env="$2" sep="$3" val="$4" + [ -n "$sep" ] || return 0 + if [[ "$sep$val$sep" == *"$sep$sep"* ]]; then + printf '\n%s\n' "#error $flag $env would introduce an empty PATH-like segment (empty, or a leading/trailing/doubled \`$sep\`). This is interpreted as \"search the current directory\" by shells, execvp() and the dynamic linker, see https://github.com/NixOS/nixpkgs/security/advisories/GHSA-p7v3-pr2c-8584. Guard the value with e.g. lib.optionalString (list != [])." + fi +} + setSepSurroundCheck() { printf '%s' "\ int is_surrounded_by_sep(char *env, char *ptr, unsigned long len, char *sep) {