nishat-06 opened a new pull request, #8706:
URL: https://github.com/apache/hadoop/pull/8706
### Description of PR
`HadoopArchiveLogs.generateScript` writes the per-application `user` and
`appId` values into the generated bash script inside double quotes with no
escaping. `user` is the per-user log directory name taken from the remote root
log dir listing (`checkFilesAndSeedApps`), and that directory is world-writable
on a shared cluster, so a directory name containing a double quote plus shell
metacharacters breaks out of the `user="..."` assignment. The script is then
run by the archive-logs tool under the yarn/mapred service account, so the
crafted name executes as that account. This quotes each interpolated value
(`appId`, `user`, `workingDir`, `remoteRootLogDir`, `suffix`) with
`Shell.bashQuote`, the same helper already used for shell interpolation in
`Shell` and `ShellBasedIdMapping`. `appId` is additionally constrained by the
later `ApplicationId.fromString` parse, but `user` is not validated anywhere,
so it is the reachable vector.
No JIRA is filed yet since I don't have a JIRA account; happy to update the
title and commit to lead with the issue key once one is created.
### How was this patch tested?
Added `testGenerateScriptQuotesUntrustedValues`, which feeds a user
directory name carrying an embedded quote and `;touch ...` and asserts the
value is emitted as a single bash-quoted token. It fails on the current code
and passes after the change. Updated `testGenerateScript` for the quoted
output, ran the `TestHadoopArchiveLogs` suite on JDK 17 (7/7 green), and
checkstyle on the touched files is clean.
### For code changes:
- [ ] Does the title of this PR start with the corresponding JIRA issue id
(e.g. 'HADOOP-17799. Your PR title ...')?
- [ ] Object storage: Have the integration tests been executed and the
endpoint
declared according to the connector-specific documentation? *Note:
Automated CI
testing doesn't cover all cases so manual testing with cloud storage
is still
required.*
- [ ] If adding new dependencies to the code, are these dependencies
licensed in a way that is compatible for inclusion under [ASF
2.0](http://www.apache.org/legal/resolved.html#category-a)?
- [ ] If applicable, have you updated the `LICENSE`, `LICENSE-binary`,
`NOTICE-binary` files?
### AI Tooling
If an AI tool was used:
- [ ] The PR includes the phrase "Contains content generated by <tool>"
where <tool> is the name of the AI tool used.
- [ ] My use of AI contributions follows the ASF legal policy
https://www.apache.org/legal/generative-tooling.html
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]