]> granicus.if.org Git - zfs/commit
Restrict zpool iostat/status -c to search path
authorGiuseppe Di Natale <dinatale2@users.noreply.github.com>
Mon, 24 Jul 2017 18:53:59 +0000 (11:53 -0700)
committerBrian Behlendorf <behlendorf1@llnl.gov>
Mon, 24 Jul 2017 18:53:59 +0000 (11:53 -0700)
commitd6bcf7ff5e97df3195d34269b1b72952b4a00778
tree1ed95841987537672e5e81bb5e089a2d9aea5b5a
parentb6e5c40382a52206f48cb26cc20ed85294e1b0a9
Restrict zpool iostat/status -c to search path

zpool iostat/status -c is supposed to be restricted
by its search path, but currently isn't. To prevent
arbitrary scripts from being executed, disallow '/'
from commands.

Reviewed-by: Brian Behlendorf <behlendorf1@llnl.gov>
Reviewed-by: Tony Hutter <hutter2@llnl.gov>
Reviewed-by: George Melikov <mail@gmelikov.ru>
Reviewed-by: Ned Bass <bass6@llnl.gov>
Signed-off-by: Giuseppe Di Natale <dinatale2@llnl.gov>
Closes #6353
Closes #6359
cmd/zpool/zpool_iter.c
man/man8/zpool.8