Received: by 2002:a05:6a11:4021:0:0:0:0 with SMTP id ky33csp227976pxb; Wed, 22 Sep 2021 00:19:18 -0700 (PDT) X-Google-Smtp-Source: ABdhPJxJyA0vUlpWTDsOU3F4kSzANeBX2DjutEo4Eh0lHj5wuvdFqJ3FzMcHPGC8UfgCWj2ZZnbo X-Received: by 2002:a05:6638:ac1:: with SMTP id m1mr3537921jab.74.1632295158212; Wed, 22 Sep 2021 00:19:18 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1632295158; cv=none; d=google.com; s=arc-20160816; b=aAFvJtlzBw79GRY7PVAPNlgeZfKBsd1wsa9meuTsMs8fhJpRTVjhMVAbuL+ySKlAZz xAzWh7tnlDf0aJf9wI9Zh2Zxu3aaaz61xaf/FrnGrOG0DhAJJPPIuADGCmDI1aLva20x 7bzxldINX6tqWSHklo1CWYzKethSphJBrP/FHaL8//HbPZPEBEZvU0ftnR9dXg3hhl1e B2jr+mp4e/dbqKJRmivtX/KEt1pdMmzjmKov86iabrhjEusch7EubBt1Kg3pyDv92Url Ah+zZLFYLPltFtCyOOI8CJrjCHPxXq+DXLIWLaC2uM6hA7TAbq7jpnYoTnqDVKIMOUVM /MAg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:user-agent:organization:in-reply-to :content-disposition:mime-version:references:message-id:subject:cc :to:from:date:dkim-signature; bh=coK/0VcxdbzoryC3BXRoMc2Mlo5zQ8m5kDrPGFCMPxg=; b=H5N8sDKq5IhYMfQyl4AkLzGEEVfN4QcHpF/mTCTdS8n3WXsVR8cuxqStoRuzFaVfis z5v3r8Uv3K2XI5I1i3NmyoHLm1vOPYzrju2joQ0xlPyKLpnfrOTYMZsp027A60X/rBbu R50uwBh8O8YXldQ3yi+3/6bjrgi+MB4OOr+zB5S3v/3YIxi6rbEOwNbaYq4CrtuAuQN7 OJCRbXYo5InlIbjpLa1BodPZfSBgOIXaoi6CJgFOcYWvsnEPAyXcZZgeLc2ex0t/V5ZS ilGuUOOdMRwabEEk5L9MV7DvUtlZZgPPcy3lxl/ialIXYNh0Bhx0DiMCkOrVQyxAO3BR H/PA== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@codesynthesis.com header.s=mail1 header.b=I+TzQHQ8; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [23.128.96.18]) by mx.google.com with ESMTP id s10si1580419ioo.6.2021.09.22.00.19.06; Wed, 22 Sep 2021 00:19:18 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) client-ip=23.128.96.18; Authentication-Results: mx.google.com; dkim=pass header.i=@codesynthesis.com header.s=mail1 header.b=I+TzQHQ8; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S233075AbhIVHTV (ORCPT + 99 others); Wed, 22 Sep 2021 03:19:21 -0400 Received: from codesynthesis.com ([188.40.148.39]:49652 "EHLO codesynthesis.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232946AbhIVHTU (ORCPT ); Wed, 22 Sep 2021 03:19:20 -0400 Received: from brak.codesynthesis.com (197-255-152-207.static.adept.co.za [197.255.152.207]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by codesynthesis.com (Postfix) with ESMTPSA id B169D602A0; Wed, 22 Sep 2021 07:17:49 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=codesynthesis.com; s=mail1; t=1632295069; bh=c2UpXL4PSLygQM+bqjl2J+S9hO6kM62k4HRY4VC2ziQ=; h=Date:From:To:Subject:Message-ID:MIME-Version:From; b=I+TzQHQ8SZED5DYDOKTb1U637g23JhDwGOKKgQc+Nh4Vg4kp/9+cJM1teBEwe89xq C6A9l3iw/DA9T8wC0eZzkr/s45KFZ2w5lsVsxkAKHysug1B4QMb0Ia7KyZepX4NI3H fyBkk08gKYVOF3mw30GFJ5Ng1GnbHwn8qf4j7yud4tgt814e6M6NuuwYhdaF0Jxy4f IhLe9y9fiqEtTYz/P9f30/S7oZ69KNsiNyNyyhOxG4MlEnbGndjkX/PD1Jv6im/0Qs 8hk1pGsyfa18onu5yn11EnAYy+VeslqjT3Rk1F6vGxqml5k2szPFmL6EWbMFYhiZKn PvZwrsIrGcVOg== Received: by brak.codesynthesis.com (Postfix, from userid 1000) id 452951A800C4; Wed, 22 Sep 2021 09:17:44 +0200 (SAST) Date: Wed, 22 Sep 2021 09:17:44 +0200 From: Boris Kolpackov To: Richard Weinberger Cc: masahiroy@kernel.org, linux-kernel@vger.kernel.org, linux-kbuild@vger.kernel.org Subject: Re: [PATCH 2/2] kconfig: Deny command substitution in string values Message-ID: References: <20210920213957.1064-1-richard@nod.at> <20210920213957.1064-2-richard@nod.at> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20210920213957.1064-2-richard@nod.at> Organization: Code Synthesis User-Agent: Mutt/1.5.24 (2015-08-30) Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Richard Weinberger writes: > The post processed .config file will get included in shell > and makefiles. That depends on who you ask: a number of projects other than the Linux kernel use kconfig for configuration and some of them do neither of those. I also don't believe the Linux kernel sources .config in shell (but I may be wrong). > So make sure that a string does not contain > symbols that allow command substitution. > If such a malformed string is found, return empty string > and report it. So effectively it's now impossible to include ` or $ in kconfig string values. Seems like a major, backwards-incompatible restriction. I think if this is really desired, then it should be re-done with escaping (similar to ") rather than outright banning inconvenient characters.