jw-pkg/test/unit/python/jw/pkg/lib/ec/ssh
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Jan Lindemann dc101a5a7f
All checks were successful
CI / Packaging - Kali Linux (pull_request) Successful in 4m10s
CI / Packaging - OpenSUSE Tumbleweed (pull_request) Successful in 4m21s
CI / Packaging test (pull_request) Successful in 0s
CI / Packaging - Kali Linux (push) Successful in 4m3s
CI / Packaging - OpenSUSE Tumbleweed (push) Successful in 4m32s
CI / Packaging test (push) Successful in 0s
lib.ec.ssh.Exec: Fix askpass script
__init_askpass() embeds the password verbatim in a generated bash script,
with a newline included inside the double quotes of the echo -n. The
askpass program therefore always appends a newline to the password, and
any password containing quotes or shell metacharacters either breaks the
script or injects commands into it.

Embed the password as base64 and decode it with printf piped into base64
-d, so the script is safe for any password and prints the password exactly,
byte for byte.

Make __del__() idempotent: it deletes the environment variables and the
script file, so a second call, e.g. an explicit one followed by garbage
collection, raises KeyError and FileNotFoundError.

Add a unit test that executes the generated script and compares its output
with the password byte for byte.

Signed-off-by: Jan Lindemann <jan@janware.com>
Assisted-by: unsloth/Qwen3.8-27B-GGUF:Q4_K_M with pi.dev v0.85.1
2026-09-14 20:32:14 +02:00
..
Exec lib.ec.ssh.Exec: Fix askpass script 2026-09-14 20:32:14 +02:00
Makefile lib.ec.ssh.Exec: Fix askpass script 2026-09-14 20:32:14 +02:00