From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from shymkent.ilbers.de ([unix socket]) by shymkent (Cyrus 2.5.10-Debian-2.5.10-3+deb9u2) with LMTPA; Thu, 07 Aug 2025 15:47:36 +0200 X-Sieve: CMU Sieve 2.4 Received: from mail-wm1-f63.google.com (mail-wm1-f63.google.com [209.85.128.63]) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPS id 577DlZUX027533 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Thu, 7 Aug 2025 15:47:35 +0200 Received: by mail-wm1-f63.google.com with SMTP id 5b1f17b1804b1-456342238bcsf999945e9.3 for ; Thu, 07 Aug 2025 06:47:35 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1754574450; cv=pass; d=google.com; s=arc-20240605; b=EnfwXvN4JXogsesdiW4oAQSolJELrHXaf5pOtLa7+fhACbF5RHVwXTsJ/jpuRSgX6R YRtl3p2AcLDXtFlmMKLKrShZYpQByIExNRoRpouErmfe6DprB3EFnu9oiFhRz1Y5qpEi RF+/uBxrID6r9J3hKbsSApDhVS/VNlzo9ko7EAZX+4BqIvbqIBuANXOkbQcy7HpqrGtw lRoGQqhneHLqvzYVkASF1ySyyAGiE1e5iSuPKTHWoG0XCeUS7jotWJRm3SPu4thNJvLb n/odKK2MU9x4tCBWa8EV5ErdliX0pqA43CfC90PcpNQ1oBdSjSH4lByw78xjoIxTeiHi vRJQ== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:in-reply-to:content-disposition :mime-version:references:mail-followup-to:message-id:subject:to:from :date:sender:dkim-signature; bh=w0TBh3jMgdwjG8qH2hfy5pGfCZUQujQ9OJg8pEITUqU=; fh=e1OEhy7Fv7JUbGwHjR/k9uKxogWZQIHfwdcvCM2C6Ao=; b=cf44ecXhrlVYnRnfPrgr6BaVk/ZjhQx3yyr3JRBKy8hrqXEgu+qzZf40l7GR8DFYvs EP2mk64mMvdZUv03fyvbMib5mRyHyr0xhFTe3hirH5Ae/f3hqvoCeIJALj4Vhs9C+3+R y6Mo1v/CYc6zG8W6G/0Y/HCb7Mo7H2zDKWKOnK9gMQ2IEj6K3Q5t77mxJPsOrjQdGCvH 2jFKuX8SZg6Dz1ubAISlzRjPx5udC2kS07xW5gpcNiTMWF/n7CxCSQrkpMQoWseW1stU bUP7zZ7uHNfrBXc6Nj8jejCDAHPdakbPjLsI+fyJMe8j8tgms+/Jd2262Gy+XrxmC7+6 u3FA==; darn=ilbers.de ARC-Authentication-Results: i=2; gmr-mx.google.com; spf=pass (google.com: domain of ibr@radix50.net designates 85.214.156.166 as permitted sender) smtp.mailfrom=ibr@radix50.net DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20230601; t=1754574450; x=1755179250; darn=ilbers.de; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :list-id:mailing-list:precedence:x-original-authentication-results :x-original-sender:in-reply-to:content-disposition:mime-version :references:mail-followup-to:message-id:subject:to:from:date:sender :from:to:cc:subject:date:message-id:reply-to; bh=w0TBh3jMgdwjG8qH2hfy5pGfCZUQujQ9OJg8pEITUqU=; b=Z+6yXOF/Kq+bYYSReiqHBqS4xZoFzY3wXMJ17wuJ+CGp5F8fTicj81RdgPK9BNfUOO SIVWYoB4QePB8q7Qb6JyBc4ZB122Bgi/SPQ+eHHhNcLv+DXShutS+294MQOKDPOAMpTy cHYCov7/N39pIlnWS2yGw+lD+ruotroHX2edMVmDlyUxdCeLlEbITDsqmCcgwDJRiGd1 bdc9NRhoATUuhqrQCfGRn1uLsDmbjBEF39mV7BZgSdCM2DrpMRbOLGmpGhWojuoOGE9J tof0e6CsDIKI+IeR9YIJGWO4DrSQn5uptlfsZylq+Q56JQ+IHkukrBl4EcDLWBF4Gh+c oBVw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1754574450; x=1755179250; h=list-unsubscribe:list-subscribe:list-archive:list-help:list-post :x-spam-checked-in-group:list-id:mailing-list:precedence :x-original-authentication-results:x-original-sender:in-reply-to :content-disposition:mime-version:references:mail-followup-to :message-id:subject:to:from:date:x-beenthere:x-gm-message-state :sender:from:to:cc:subject:date:message-id:reply-to; bh=w0TBh3jMgdwjG8qH2hfy5pGfCZUQujQ9OJg8pEITUqU=; b=K5i1WA4nTGD5CRIe6jcX+YwgP8jJwtD5wTn++zZMm/9fl+AIoPES56/9Hyduy9GJ4u PleRfxfdhuzLwGnREh43WpxFy3kqegrWWY/ZpipuHAezulflTVP1MlU/YXu55LBMLw1e sZSn+qhbYKyq2JEVWEx7JxGhSqUfMdK+BmpWGfrZv+IPs3+xK8ri06JtVZAEWtahkSkl nojL0kBFSjA6lCXDQk3QY/78AbQ503RnK9bpDC9dHtwtX7uJ5VoB/qb+KGFtUfAiLXCR cJkKyhn4/9qEYa8302AKm7juxqsxFbIDq1IwzHN3sTw1dMZCTOC0oxYecuHyAA/9euv0 JFEA== Sender: isar-users@googlegroups.com X-Forwarded-Encrypted: i=2; AJvYcCVhKOy40rLuemWY5T8Br+An1iMXGJFV0RnRfaQ46nVpTnof6rC2zlQk7ZurtSKM1OOYukXI@ilbers.de X-Gm-Message-State: AOJu0YzkVhvynh37xoiD04b2VfBZiWRnDy+ASiWGg4MLbmSkSCDZsWyR R7PtrZwhjB5EOuUstkBqLgb6OKYuNwhm4+Z+M66O6OOPOajsjK+2blGN X-Google-Smtp-Source: AGHT+IGw7drQUQ5e2RpGn5Wp9JSKlJ5RwxxJi6W5tJZmFCt9gUn7P3PiwMReSNp8l2atdk6/dGOV6g== X-Received: by 2002:a05:600c:5391:b0:459:d7c4:9e28 with SMTP id 5b1f17b1804b1-459e9dce2dbmr26550115e9.0.1754574449563; Thu, 07 Aug 2025 06:47:29 -0700 (PDT) X-BeenThere: isar-users@googlegroups.com; h=AZMbMZdMbhu4L70rNkf2PrqI7EcIqkd/uYKDLM1bsVaZ1u2z1Q== Received: by 2002:a05:600c:4f49:b0:459:e1a3:c3bc with SMTP id 5b1f17b1804b1-459edd0467fls7281325e9.1.-pod-prod-09-eu; Thu, 07 Aug 2025 06:47:25 -0700 (PDT) X-Received: by 2002:a05:600c:1c18:b0:456:19be:5cc with SMTP id 5b1f17b1804b1-459e741fcebmr75108325e9.14.1754574445025; Thu, 07 Aug 2025 06:47:25 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1754574445; cv=none; d=google.com; s=arc-20240605; b=fhpfCvEWupHUwnWtllFMkbxyqsQSsbEVST0XG8Gq3cv2j260vLOEz3W/PzY4bEZ62t vrwxa1SlViWvH+jQLOA+lm59JzzmGFg7fHCpsbNnpG7RiOUN5TPVBqFR+V/WZpEqe/nz uwK146jLVkJv/3KDx3hJhQE1Z1Th/IwlylfRuD6ZPL1cnvMX30lejOGIjxVsZZj3CKEC fSxyf07DdZloIrtH2wypTZd2U20uKLyWM3AjxSLrp8g45YQ0w3SNAcINaXEKcCrKUia3 zPMUwVWE2z7aDqylJIh7S13KBVyN5nlXYQZuadOcw1QXUX6+UU+tREwgTgNnRnkQcYdd wm7A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=in-reply-to:content-disposition:mime-version:references :mail-followup-to:message-id:subject:to:from:date; bh=gHH9Z+S5p6Bav4Abhop4gcDy03zKwXttCUOgGNJZ63Y=; fh=7tclEdh7YbwSQowgJ6LNq720O7H5HTEaqj22NJWRE2E=; b=Tmh8AlVcLuObL1biOEpy65gF6TYozwEE9hbOhFLIRzQS7jbnsC1Y+MJyi5yMdzZU4d AekHSz3HRKnIXGcTnW84SmkW+icWrgpohmhhB9qw6Ckhwo2KDecoVP6D30kH2a2upxtB ydpPACt0HpnrBCKFDR1zjvRpgTZzlHaggyuU2gHe8ELpvF9YdLeBUNGYlZsqqcR9UQDt OHJ+aN9m9tqGGFUkQqrBfoA4SwqBAAQZQ1kdCmdsaoiuQ//C9B+UFNMSqYzGGcAp+LPq glv3vQrCpd6dcB0+WicsywVCKA+IOUb7r3oUuWjs8wWlZokCGZuLRPsdc+cYzq9zjJex XXZQ==; dara=google.com ARC-Authentication-Results: i=1; gmr-mx.google.com; spf=pass (google.com: domain of ibr@radix50.net designates 85.214.156.166 as permitted sender) smtp.mailfrom=ibr@radix50.net Received: from shymkent.ilbers.de (shymkent.ilbers.de. [85.214.156.166]) by gmr-mx.google.com with ESMTPS id 5b1f17b1804b1-459e35405f9si1427375e9.2.2025.08.07.06.47.24 for (version=TLS1_2 cipher=ECDHE-ECDSA-CHACHA20-POLY1305 bits=256/256); Thu, 07 Aug 2025 06:47:24 -0700 (PDT) Received-SPF: pass (google.com: domain of ibr@radix50.net designates 85.214.156.166 as permitted sender) client-ip=85.214.156.166; Received: from abai.de ([88.130.203.42]) (authenticated bits=0) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPSA id 577DlNcP027520 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Thu, 7 Aug 2025 15:47:24 +0200 Date: Thu, 7 Aug 2025 15:47:23 +0200 From: Baurzhan Ismagulov To: isar-users@googlegroups.com Subject: Re: [PATCH 1/1] image-accounts: directly pass arguments to openssl instead of shell Message-ID: Mail-Followup-To: isar-users@googlegroups.com References: <20250612155610.473593-1-felix.moessbauer@siemens.com> MIME-Version: 1.0 Content-Type: text/plain; charset="UTF-8" Content-Disposition: inline In-Reply-To: <20250612155610.473593-1-felix.moessbauer@siemens.com> X-Spam-Status: No, score=-4.6 required=5.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_EF,HEADER_FROM_DIFFERENT_DOMAINS, MAILING_LIST_MULTI,RCVD_IN_DNSWL_BLOCKED,RCVD_IN_MSPIKE_H2, RCVD_IN_RP_CERTIFIED,RCVD_IN_RP_RNBL,RCVD_IN_RP_SAFE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on shymkent.ilbers.de X-Original-Sender: ibr@radix50.net X-Original-Authentication-Results: gmr-mx.google.com; spf=pass (google.com: domain of ibr@radix50.net designates 85.214.156.166 as permitted sender) smtp.mailfrom=ibr@radix50.net Precedence: list Mailing-list: list isar-users@googlegroups.com; contact isar-users+owners@googlegroups.com List-ID: X-Spam-Checked-In-Group: isar-users@googlegroups.com X-Google-Group-Id: 914930254986 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , X-TUID: Za8oDmfhloOF On 2025-06-12 17:56, 'Felix Moessbauer' via isar-users wrote: > When hashing the password, the whole openssl command was passed as a > shell string instead of directly passing the individual arguments as-is. > Further, the arguments were not shell escaped. By that, passwords > containing a string were split into two individual arguments, breaking > the command (or silently set a different password if the remainder > itself was a valid argument). > > We fix this by passing the arguments as-is (as list) to bb.process.run. Applied to next, thanks. With kind regards, Baurzhan -- You received this message because you are subscribed to the Google Groups "isar-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to isar-users+unsubscribe@googlegroups.com. To view this discussion visit https://groups.google.com/d/msgid/isar-users/aJSua28PUuw69pbw%40abai.de.