From db7e106fc13e536f06fc658b52a2bf439035b7cb Mon Sep 17 00:00:00 2001 From: Thomas Gerbet Date: Sun, 2 Aug 2026 16:58:01 +0200 Subject: [PATCH] makeBinaryWrapper: reject prefix/suffix with an empty path segment Preferred to reject explictly the value instead of silently sanitizing it. It's closer to what we do for the invalid env name and it will allow us to spot derivation that were impacted by the issue that has not yet been fixed. (cherry picked from commit d2cbb4ba810112c938f92645fa58d3fcd1d5ce18) --- .../ma/makeBinaryWrapper/make-binary-wrapper.sh | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh b/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh index 275f77ea3e71..fa59cb7d15a3 100644 --- a/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh +++ b/pkgs/by-name/ma/makeBinaryWrapper/make-binary-wrapper.sh @@ -261,6 +261,7 @@ setEnvPrefix() { val=$(escapeStringLiteral "$3") printf '%s' "set_env_prefix(\"$env\", \"$sep\", \"$val\");" assertValidEnvName "$1" + assertNoEmptySegment "--prefix" "$1" "$2" "$3" } # suffix ENV SEP VAL @@ -271,6 +272,7 @@ setEnvSuffix() { val=$(escapeStringLiteral "$3") printf '%s' "set_env_suffix(\"$env\", \"$sep\", \"$val\");" assertValidEnvName "$1" + assertNoEmptySegment "--suffix" "$1" "$2" "$3" } # setEnv KEY VALUE @@ -323,6 +325,14 @@ assertValidEnvName() { esac } +assertNoEmptySegment() { + local flag="$1" env="$2" sep="$3" val="$4" + [ -n "$sep" ] || return 0 + if [[ "$sep$val$sep" == *"$sep$sep"* ]]; then + printf '\n%s\n' "#error $flag $env would introduce an empty PATH-like segment (empty, or a leading/trailing/doubled \`$sep\`). This is interpreted as \"search the current directory\" by shells, execvp() and the dynamic linker, see https://github.com/NixOS/nixpkgs/security/advisories/GHSA-p7v3-pr2c-8584. Guard the value with e.g. lib.optionalString (list != [])." + fi +} + setSepSurroundCheck() { printf '%s' "\ int is_surrounded_by_sep(char *env, char *ptr, unsigned long len, char *sep) {