nishat-06 opened a new pull request, #8706:
URL: https://github.com/apache/hadoop/pull/8706

   ### Description of PR
   
   `HadoopArchiveLogs.generateScript` writes the per-application `user` and 
`appId` values into the generated bash script inside double quotes with no 
escaping. `user` is the per-user log directory name taken from the remote root 
log dir listing (`checkFilesAndSeedApps`), and that directory is world-writable 
on a shared cluster, so a directory name containing a double quote plus shell 
metacharacters breaks out of the `user="..."` assignment. The script is then 
run by the archive-logs tool under the yarn/mapred service account, so the 
crafted name executes as that account. This quotes each interpolated value 
(`appId`, `user`, `workingDir`, `remoteRootLogDir`, `suffix`) with 
`Shell.bashQuote`, the same helper already used for shell interpolation in 
`Shell` and `ShellBasedIdMapping`. `appId` is additionally constrained by the 
later `ApplicationId.fromString` parse, but `user` is not validated anywhere, 
so it is the reachable vector.
   
   No JIRA is filed yet since I don't have a JIRA account; happy to update the 
title and commit to lead with the issue key once one is created.
   
   ### How was this patch tested?
   
   Added `testGenerateScriptQuotesUntrustedValues`, which feeds a user 
directory name carrying an embedded quote and `;touch ...` and asserts the 
value is emitted as a single bash-quoted token. It fails on the current code 
and passes after the change. Updated `testGenerateScript` for the quoted 
output, ran the `TestHadoopArchiveLogs` suite on JDK 17 (7/7 green), and 
checkstyle on the touched files is clean.
   
   ### For code changes:
   
   - [ ] Does the title of this PR start with the corresponding JIRA issue id 
(e.g. 'HADOOP-17799. Your PR title ...')?
   - [ ] Object storage: Have the integration tests been executed and the 
endpoint
         declared according to the connector-specific documentation? *Note: 
Automated CI
         testing doesn't cover all cases so manual testing with cloud storage 
is still
         required.*
   - [ ] If adding new dependencies to the code, are these dependencies 
licensed in a way that is compatible for inclusion under [ASF 
2.0](http://www.apache.org/legal/resolved.html#category-a)?
   - [ ] If applicable, have you updated the `LICENSE`, `LICENSE-binary`, 
`NOTICE-binary` files?
   
   ### AI Tooling
   
   If an AI tool was used:
   
   - [ ] The PR includes the phrase "Contains content generated by <tool>"
         where <tool> is the name of the AI tool used.
   - [ ] My use of AI contributions follows the ASF legal policy
         https://www.apache.org/legal/generative-tooling.html
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to