Skip to content

Commit ca73dcf

Browse files
committed
fix(helm): reject boolean sandbox UID and GID
Signed-off-by: Eric Curtin <eric.curtin@docker.com>
1 parent 6a07ea8 commit ca73dcf

2 files changed

Lines changed: 16 additions & 1 deletion

File tree

‎deploy/helm/openshell/templates/_helpers.tpl‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -384,11 +384,12 @@ Render a sandbox UID/GID chart value as an integer, or nothing when unset.
384384
Takes a dict with `name` (the values key, for errors) and `value`. The bounds
385385
match openshell_policy::MIN_SANDBOX_UID..=MAX_SANDBOX_UID. Helm parses YAML
386386
numbers as float64, so the integer conversion also avoids `2e+09` rendering.
387+
Booleans are rejected because they would otherwise convert to 1 or 0.
387388
*/}}
388389
{{- define "openshell.sandboxId" -}}
389390
{{- if not (or (kindIs "invalid" .value) (eq (toString .value) "")) -}}
390391
{{- $id := int64 .value -}}
391-
{{- if or (ne (float64 .value) (float64 $id)) (lt $id 1) (gt $id 4294967294) -}}
392+
{{- if or (kindIs "bool" .value) (ne (float64 .value) (float64 $id)) (lt $id 1) (gt $id 4294967294) -}}
392393
{{- fail (printf "%s must be an integer between 1 and 4294967294" .name) -}}
393394
{{- end -}}
394395
{{- $id -}}

‎deploy/helm/openshell/tests/gateway_sandbox_identity_test.yaml‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -77,3 +77,17 @@ tests:
7777
asserts:
7878
- failedTemplate:
7979
errorPattern: "server.sandboxUid must be an integer between 1 and 4294967294"
80+
81+
- it: rejects a boolean sandbox UID
82+
set:
83+
server.sandboxUid: true
84+
asserts:
85+
- failedTemplate:
86+
errorPattern: "server.sandboxUid must be an integer between 1 and 4294967294"
87+
88+
- it: rejects a boolean sandbox GID
89+
set:
90+
server.sandboxGid: true
91+
asserts:
92+
- failedTemplate:
93+
errorPattern: "server.sandboxGid must be an integer between 1 and 4294967294"

0 commit comments

Comments
 (0)