From 3181ad7b369b01ce08d3a06a6de53703f6f4be07 Mon Sep 17 00:00:00 2001 From: SiddharthSanch <111047247+SiddharthSanch@users.noreply.github.com> Date: Wed, 23 Sep 2026 15:04:51 +0530 Subject: [PATCH] cloud-setup-databases: shell-escape values passed to EncryptionCLI processEncryptionStuff()'s encrypt() built the java EncryptionCLI command by hand-wrapping each dynamic value in literal double quotes, then handed the joined string to runCmd(), which runs it through `subprocess.Popen(..., shell=True)`. Double quotes do not stop the shell from expanding "$..." inside them, so a password like `pa$sword` is silently truncated to `pa` before it ever reaches EncryptionCLI, and the wrong value gets encrypted into db.properties. Use shlex.quote() instead of manual double-quote wrapping for the jar path, the value being encrypted, and the management server secret key. shlex.quote() produces shell-safe quoting for arbitrary values, including but not limited to '$'. Verified with a standalone reproduction that shells out the same way runCmd() does: with the old double-quote wrapping, a password of `pa$sword` arrives at the child process as `pa`; with shlex.quote(), it arrives intact as `pa$sword`. Fixes: #14186 Signed-off-by: SiddharthSanch <111047247+SiddharthSanch@users.noreply.github.com> --- setup/bindir/cloud-setup-databases.in | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/setup/bindir/cloud-setup-databases.in b/setup/bindir/cloud-setup-databases.in index eb68c1e0181e..a853788b3f7b 100755 --- a/setup/bindir/cloud-setup-databases.in +++ b/setup/bindir/cloud-setup-databases.in @@ -21,6 +21,7 @@ import os import sys import subprocess import glob +import shlex from random import choice import string from optparse import OptionParser @@ -418,8 +419,13 @@ for example: def processEncryptionStuff(self): def encrypt(value): - cmd = ['java','-classpath','"' + self.encryptionJarPath + '"','com.cloud.utils.crypt.EncryptionCLI','-i','"' + value + '"', '-p', '"' + - self.mgmtsecretkey + '"', self.encryptorVersion] + # runCmd() joins this list with spaces and runs it through a shell, so each + # dynamic value must be shell-escaped with shlex.quote() rather than hand-wrapped + # in double quotes: double quotes still let the shell expand "$..." in the value + # (e.g. a password of pa$sword is truncated to pa), silently corrupting it. + cmd = ['java', '-classpath', shlex.quote(self.encryptionJarPath), + 'com.cloud.utils.crypt.EncryptionCLI', '-i', shlex.quote(value), + '-p', shlex.quote(self.mgmtsecretkey), self.encryptorVersion] return str(runCmd(cmd)).strip('\r\n') def saveMgmtServerSecretKey():