Skip to content

fix(fspy): read the whole shebang line - #788

Open
lifeiscontent wants to merge 2 commits into
voidzero-dev:mainfrom
lifeiscontent:fix/fspy-long-shebang
Open

lifeiscontent wants to merge 2 commits into
voidzero-dev:mainfrom
lifeiscontent:fix/fspy-long-shebang

Conversation

@lifeiscontent

Copy link
Copy Markdown
Contributor

Motivation

fspy reads only the first 128 bytes of a script to find its interpreter. A script whose interpreter path is longer than 126 bytes runs fine on its own, but under a cached task the path gets cut short. The exec then fails with ENOENT, or runs whatever lives at the shorter path.

Changes

  • Read as much of the line as the kernel does: 512 bytes on macOS, 256 on Linux. I checked both limits by running scripts on macOS and in a Linux container.
  • Where the kernel refuses a script, return ENOEXEC instead of running a truncated path. That covers macOS with no newline in the first 512 bytes, and Linux when the interpreter path itself doesn't fit.
  • Unit tests for the limits on both platforms, plus an fspy test that runs a script with a 200-byte interpreter path.

fspy read only the first 128 bytes of a script to find its interpreter, so
an interpreter path longer than 126 bytes was cut short. The traced exec then
ran the truncated path, which fails or runs a different program, while the
same script runs fine without tracing.

Read as much as the kernel does instead: 512 bytes on macOS and 256 on
Linux. Where the kernel refuses a line that doesn't fit, return ENOEXEC
like it does rather than running a truncated path.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant