quote remote job paths in posix ssh command builders#70091
Open
Samin061 wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The POSIX builders in
remote_job.pyinterpolateRemoteJobPathsvalues into single-quoted shell words without escaping, so a single quote anywhere inremote_base_dircloses the quote and the rest of the value is parsed as commands that run on the remote host as the SSH connection user.remote_base_diris a template field, but_validate_base_dirruns in__init__against the un-rendered Jinja literal and never looks for shell metacharacters, so a value like{{ dag_run.conf['dir'] }}reaches the shell unchecked and someone who can only trigger a Dag run with config gets a shell on the target host. Quoting withshlex.quoteat each site matches what the Windows builders already do viaps_escape.All six POSIX builders are affected. The
_validate_job_dirprefix check on cleanup does not help, since a base dir that starts with/tmp/airflow-ssh-jobs/and then contains a quote still passes it:Added a parametrized regression that runs each builder's output through
shand asserts the injected marker is never created; it fails on all six before this change.Was generative AI tooling used to co-author this PR?
Generated-by: Claude Code (Opus 4.8) following the guidelines