Skip to content

fix(policy): single-quote the policy name in the exported client.rb - #259

Merged
tas50 merged 1 commit into
mainfrom
fix/policy-export-client-rb-quoting
Sep 24, 2026
Merged

tas50 merged 1 commit into
mainfrom
fix/policy-export-client-rb-quoting

Conversation

@tas50

@tas50 tas50 commented Sep 24, 2026

Copy link
Copy Markdown
Collaborator

cinc policy export wrote the generated client.rb with policy_name %q. Go's %q produces a Ruby double-quoted string, which interpolates #{...}. The policy name comes straight from the lock file (only checked for non-empty), so a lock named #{system("...")} ran arbitrary Ruby when cinc-client -z loaded the export.

The fix quotes the name with a single-quoted Ruby literal, the same way node bootstrap already quotes its client.rb values. That helper moves from cli/remote into a small shared cli/rubylit package so both generators use one implementation.

Test plan

  • New TestClientRBDoesNotInterpolatePolicyName fails before the fix (output contained policy_name "web#{system(\"id\")}'x") and passes after
  • TestQuote covers interpolation, quotes, backslashes, empty
  • go test ./cli/rubylit/ ./cli/policyfile/ ./cli/remote/, go vet, gofmt clean

policy export wrote `policy_name %q`, and Go's %q is a Ruby double-quoted
string, which interpolates #{...}. The name comes from the lock file, so a
lock named `#{system("...")}` ran code when cinc-client -z loaded the
export. Quote it the way bootstrap already quotes its client.rb values,
now shared as cli/rubylit.

Signed-off-by: Tim Smith <tsmith84@proton.me>
@tas50
tas50 merged commit 3f327fd into main Sep 24, 2026
6 checks passed
@tas50
tas50 deleted the fix/policy-export-client-rb-quoting branch September 24, 2026 05:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant