summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMichał Górny <mgorny@gentoo.org>2017-08-31 22:29:50 +0200
committerMichał Górny <mgorny@gentoo.org>2017-09-11 22:32:46 +0200
commitfb2459330cf226ee34d3875a1143531bd109aaf2 (patch)
tree5d8c479a30784631eaa632d25897ce1c445284e6
parentrepoman: Update --bug/--closes description for bugs.g.o hooks (diff)
downloadportage-fb2459330cf226ee34d3875a1143531bd109aaf2.tar.gz
portage-fb2459330cf226ee34d3875a1143531bd109aaf2.tar.bz2
portage-fb2459330cf226ee34d3875a1143531bd109aaf2.zip
ebuild.sh: Completely ban external commands in global scope
Set PATH to /dev/null when sourcing the ebuild for dependency resolution in order to prevent shell from finding external commands via PATH lookup. While this does not prevent executing programs via full path, it should catch the majority of accidental uses. Closes: https://github.com/gentoo/portage/pull/199 Reviewed-by: Zac Medico <zmedico@gentoo.org>
-rwxr-xr-xbin/ebuild.sh6
-rw-r--r--bin/isolated-functions.sh4
2 files changed, 9 insertions, 1 deletions
diff --git a/bin/ebuild.sh b/bin/ebuild.sh
index c23561651..94a44d534 100755
--- a/bin/ebuild.sh
+++ b/bin/ebuild.sh
@@ -80,8 +80,12 @@ else
done
unset funcs x
+ # prevent the shell from finding external executables
+ # note: we can't use empty because it implies current directory
+ _PORTAGE_ORIG_PATH=${PATH}
+ export PATH=/dev/null
command_not_found_handle() {
- die "Command not found while sourcing ebuild: ${*}"
+ die "External commands disallowed while sourcing ebuild: ${*}"
}
fi
diff --git a/bin/isolated-functions.sh b/bin/isolated-functions.sh
index e320f7132..b28e44f18 100644
--- a/bin/isolated-functions.sh
+++ b/bin/isolated-functions.sh
@@ -121,6 +121,10 @@ __helpers_die() {
}
die() {
+ # restore PATH since die calls basename & sed
+ # TODO: make it pure bash
+ [[ -n ${_PORTAGE_ORIG_PATH} ]] && PATH=${_PORTAGE_ORIG_PATH}
+
set +x # tracing only produces useless noise here
local IFS=$' \t\n'