Skip to content

scoop-gen(.sh) : whitespace bugs #7404

Description

@wileyhy

Describe the bug

Filenames can include whitespace, so when word splitting is used erroneous values can be assigned to the script's positional parameters.

A clear and concise description of what the bug is. Include version by typing gh --version.
(installed from dnf:)
gh version 2.27.0 (2023-04-11)
https://github.com/cli/cli/releases/tag/v2.27.0

  1. On the command line the script could parse json-file as multiple parameters, while the script doesn't check for the correct number of positional parameters.
  2. On lines 5 & 6, the script's positional parameters $1 and $2 are allowed to be the null byte.

Steps to reproduce the behavior

  1. Type this '...'
    git clone 'https://github.com/cli/cli'

bug 1:

Note whitespace in the filename.

clear; set -x; f="~/json file"; cat ~/gh_2.4.0_checksums.txt | ./cli-2.27.0/script/scoop-gen v2.4.0 $f; set -

bug 2:

clear
set -x
set --
set -- '' 'foo'
echo "$#"
echo "$@"
printf '%s' "$1" | od -tx1z
printf '%s' "$1" | cat -Aen
echo "${1?}" # tests for variable unset
echo "${1:?}" # tests for variable unset or null
set -

  1. View the output '....'

bug 1:

  • f='~/json file'
  • ./cli-2.27.0/script/scoop-gen v2.4.0 '~/json' file
  • cat /home/liveuser/gh_2.4.0_checksums.txt
    ./cli-2.27.0/script/scoop-gen: line 29: /json: No such file or directory
  • set -

bug 2:

  • set --
  • set -- '' foo
  • echo 2
    2
  • echo '' foo
    foo
  • od -tx1z
  • printf %s ''
    0000000
  • cat -Aen
  • printf %s ''
  • echo ''

bash: 1: parameter null or not set
...

  1. See error

bug 1:

./cli-2.27.0/script/scoop-gen: line 29: /json: No such file or directory

bug 2:

bash: 1: parameter null or not set

Patches

Bug 1: add near top of file

[[ "$#" -eq 2 ]] || { echo "scoop-gen: cli args"; exit 1;}

Bug 2: at lines 5 and 6, add some colons before the question marks

tagname="${1:?}"
jsonfile="${2:?}"

Activity

  1. wileyhy commented on May 3, 2023

    @wileyhy
    Author

    Additionally, I noticed how the checksums file includes windows_arm64 while scoop-gen has just amd64 and 386.

  2. wileyhy commented on May 3, 2023

    @wileyhy
    Author

    Alternatively, for handling two or more positional parameters, after word splitting, including null bytes.

    while :; do if [[ -n "${1:?}" ]]; then tagname="$1"; shift; break; else shift; fi; done
    jsonfile="${*:?}"; [[ -f "${jsonfile}" ]] || { echo "scoop-gen: cli args"; exit 1;}

    Thx

  3. added
    priority-3Affects a small number of users or is largely cosmetic
    and removed on May 3, 2023
  4. mislav commented on May 4, 2023

    @mislav
    Contributor

    Hi, we've not recommended that people install from our own scoop bucket since late 2020: #2478

    Since gh can be installed from the "main" bucket, ours was essentially deprecated and updated only for people who were already using it. Since lately, we have stopped updating it: #7324

    So instead of maintaining the scoop-gen script further, we will be deleting it instead. I'll close this issue when that's done.

  5. added
    coreThis issue is not accepting PRs from outside contributors
    and removed on May 4, 2023
  6. wileyhy commented on May 4, 2023

    @wileyhy
    Author

    Okay

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingcoreThis issue is not accepting PRs from outside contributorspriority-3Affects a small number of users or is largely cosmetic

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions