From 045fbc389f8cd075a0f26840f3f68f79b857a285 Mon Sep 17 00:00:00 2001 From: Mikael Voss Date: Wed, 19 Mar 2025 18:00:44 +0100 Subject: [PATCH] nixos/tmpfiles: properly escape argument option MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The systemd.tmpfiles.settings....argument option may contain arbitrary strings. This could allow intentional or unintentional introduction of new configuration lines. The argument field cannot be quoted, C‐style \xNN escape sequences are however permitted. By escaping whitespace and newline characters, the issue can be mitigated. --- .../modules/system/boot/systemd/tmpfiles.nix | 30 +++++++++++++++++-- 1 file changed, 28 insertions(+), 2 deletions(-) diff --git a/nixos/modules/system/boot/systemd/tmpfiles.nix b/nixos/modules/system/boot/systemd/tmpfiles.nix index b35fe9573fc9..d5541be0e966 100644 --- a/nixos/modules/system/boot/systemd/tmpfiles.nix +++ b/nixos/modules/system/boot/systemd/tmpfiles.nix @@ -18,6 +18,14 @@ let inherit elemType placeholder; }; + escapeArgument = lib.strings.escapeC [ + "\t" + "\n" + "\r" + " " + "\\" + ]; + settingsOption = { description = '' Declare systemd-tmpfiles rules to create, delete, and clean up volatile @@ -126,7 +134,7 @@ let # generates a single entry for a tmpfiles.d rule settingsEntryToRule = path: entry: '' - '${entry.type}' '${path}' '${entry.mode}' '${entry.user}' '${entry.group}' '${entry.age}' ${entry.argument} + '${entry.type}' '${path}' '${entry.mode}' '${entry.user}' '${entry.group}' '${entry.age}' ${escapeArgument entry.argument} ''; # generates a list of tmpfiles.d rules from the attrs (paths) under tmpfiles.settings. @@ -199,7 +207,25 @@ in "boot.initrd.systemd.storePaths will lead to errors in the future." "Found these problematic files: ${lib.concatStringsSep ", " paths}" ] - ); + ) + ++ (lib.flatten ( + lib.mapAttrsToList ( + name: paths: + lib.mapAttrsToList ( + path: entries: + lib.mapAttrsToList ( + type': entry: + lib.optional (lib.match ''.*\\([nrt]|x[0-9A-Fa-f]{2}).*'' entry.argument != null) ( + lib.concatStringsSep " " [ + "The argument option of ${name}.${type'}.${path} appears to" + "contain escape sequences, which will be escaped again." + "Unescape them if this is not intended: \"${entry.argument}\"" + ] + ) + ) entries + ) paths + ) cfg.settings + )); systemd.additionalUpstreamSystemUnits = [ "systemd-tmpfiles-clean.service"