diff --git a/releaseNote.md b/releaseNote.md index 7f1e2e539..d3b0f87a8 100644 --- a/releaseNote.md +++ b/releaseNote.md @@ -2,6 +2,7 @@ ## Bugs - Fixed an issue where container environment variables names or values could escape the docker command (#2108) +- Sanitize Windows ENVs (#2280) ## Windows x64 diff --git a/src/Runner.Sdk/ProcessInvoker.cs b/src/Runner.Sdk/ProcessInvoker.cs index 78a9f2dd2..43117ef47 100644 --- a/src/Runner.Sdk/ProcessInvoker.cs +++ b/src/Runner.Sdk/ProcessInvoker.cs @@ -264,7 +264,17 @@ namespace GitHub.Runner.Sdk { foreach (KeyValuePair kvp in environment) { +#if OS_WINDOWS + string tempKey = String.IsNullOrWhiteSpace(kvp.Key) ? kvp.Key : kvp.Key.Split('\0')[0]; + string tempValue = String.IsNullOrWhiteSpace(kvp.Value) ? kvp.Value : kvp.Value.Split('\0')[0]; + if(!String.IsNullOrWhiteSpace(tempKey)) + { + _proc.StartInfo.Environment[tempKey] = tempValue; + } +#else _proc.StartInfo.Environment[kvp.Key] = kvp.Value; + +#endif } } diff --git a/src/Test/L0/ProcessInvokerL0.cs b/src/Test/L0/ProcessInvokerL0.cs index 629abb0a0..3f0985175 100644 --- a/src/Test/L0/ProcessInvokerL0.cs +++ b/src/Test/L0/ProcessInvokerL0.cs @@ -129,7 +129,76 @@ namespace GitHub.Runner.Common.Tests } } } +#if OS_WINDOWS + [Fact] + [Trait("Level", "L0")] + [Trait("Category", "Common")] + public async Task SetTestEnvWithNullInKey() + { + using (TestHostContext hc = new(this)) + { + Tracing trace = hc.GetTrace(); + Int32 exitCode = -1; + var processInvoker = new ProcessInvokerWrapper(); + processInvoker.Initialize(hc); + var stdout = new List(); + var stderr = new List(); + processInvoker.OutputDataReceived += (object sender, ProcessDataReceivedEventArgs e) => + { + trace.Info(e.Data); + stdout.Add(e.Data); + }; + processInvoker.ErrorDataReceived += (object sender, ProcessDataReceivedEventArgs e) => + { + trace.Info(e.Data); + stderr.Add(e.Data); + }; + + exitCode = await processInvoker.ExecuteAsync("", "cmd.exe", "/c \"echo %TEST%\"", new Dictionary() { { "TEST\0second", "first" } }, CancellationToken.None); + + + trace.Info("Exit Code: {0}", exitCode); + Assert.Equal(0, exitCode); + Assert.Equal("first", stdout.First(x => !string.IsNullOrWhiteSpace(x))); + + } + } + + [Fact] + [Trait("Level", "L0")] + [Trait("Category", "Common")] + public async Task SetTestEnvWithNullInValue() + { + using (TestHostContext hc = new(this)) + { + Tracing trace = hc.GetTrace(); + + Int32 exitCode = -1; + var processInvoker = new ProcessInvokerWrapper(); + processInvoker.Initialize(hc); + var stdout = new List(); + var stderr = new List(); + processInvoker.OutputDataReceived += (object sender, ProcessDataReceivedEventArgs e) => + { + trace.Info(e.Data); + stdout.Add(e.Data); + }; + processInvoker.ErrorDataReceived += (object sender, ProcessDataReceivedEventArgs e) => + { + trace.Info(e.Data); + stderr.Add(e.Data); + }; + + exitCode = await processInvoker.ExecuteAsync("", "cmd.exe", "/c \"echo %TEST%\"", new Dictionary() { { "TEST", "first\0second" } }, CancellationToken.None); + + trace.Info("Exit Code: {0}", exitCode); + Assert.Equal(0, exitCode); + Assert.Equal("first", stdout.First(x => !string.IsNullOrWhiteSpace(x))); + + } + } +#endif [Fact] [Trait("Level", "L0")] [Trait("Category", "Common")] diff --git a/src/runnerversion b/src/runnerversion index 2b89a8478..60991c945 100644 --- a/src/runnerversion +++ b/src/runnerversion @@ -1 +1 @@ -2.289.4 +2.289.5