Skip to content

fix(unikernels): reject single quotes in Linux init args - #898

Closed
Anand-240 wants to merge 1 commit into
urunc-dev:mainfrom
Anand-240:fix/linux-cmdline-quote-escaping
Closed

fix(unikernels): reject single quotes in Linux init args#898
Anand-240 wants to merge 1 commit into
urunc-dev:mainfrom
Anand-240:fix/linux-cmdline-quote-escaping

Conversation

@Anand-240

@Anand-240 Anand-240 commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Description

parseCmdLine() in pkg/unikontainers/unikernels/linux.go wraps
multi-word arguments in single quotes so urunit can recover argument
boundaries from the guest's boot cmdline. It does this with plain
string concatenation and does not escape quote characters already
present in the argument.

If an argument contains both a space and a single quote, for example
sh -c "echo it's broken", the wrap produces an unbalanced quote
sequence such as 'sh' 'echo it's broken', which corrupts the token
boundaries that urunit parses out of /proc/cmdline. The guest init
process can then receive the wrong arguments with no error surfaced to
the user.

Since urunit's own cmdline parser lives outside this repo and its
escaping rules are not known here, this change rejects arguments
containing a single quote with a clear error instead of guessing an
escaping scheme that might not match what urunit actually supports.

Related issues

Changes

  • pkg/unikontainers/unikernels/linux.go: parseCmdLine now returns an
    error when an argument contains a single quote, before attempting to
    wrap it.
  • pkg/unikontainers/unikernels/linux_test.go: new table driven tests
    covering the empty cmdline case, single word app, multi word
    argument quoting, and the new rejection behavior for quoted
    arguments.

How was this tested?

  • go test ./pkg/unikontainers/unikernels/... -run TestLinux -v passes (5/5 subtests)
  • go build ./pkg/unikontainers/unikernels/... succeeds

LLM usage

Claude (Anthropic, model: claude-sonnet-5) was used to trace the
quoting bug and help put this fix together. Reviewed and tested by me
before opening this PR, per the project's LLM policy.

Checklist

  • I have read the contribution guide.
  • The linter passes locally (make lint). Not run locally, no
    golangci-lint setup available in this environment; deferring to CI.
  • The e2e tests of at least one tool pass locally. Not run
    locally; deferring to CI.
  • If LLMs were used: I have read the llm policy.

@netlify

netlify Bot commented Aug 3, 2026

Copy link
Copy Markdown

Deploy Preview for urunc ready!

Name Link
🔨 Latest commit d96724e
🔍 Latest deploy log https://app.netlify.com/projects/urunc/deploys/6a79f748d210040008153498
😎 Deploy Preview https://deploy-preview-898--urunc.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

parseCmdLine() wrapped multi-word arguments in unescaped single quotes
for urunit compatibility. An argument containing both a space and a
single quote, for example sh -c "echo it's broken", produced an
unbalanced quote sequence, corrupting the token-boundary parsing that
urunit performs on /proc/cmdline and causing the guest init process to
receive the wrong arguments.

Since urunit's cmdline parser lives outside this repo and its escaping
semantics are unknown, reject arguments containing a single quote with
a clear error instead of guessing an escaping scheme.

Fixes: urunc-dev#897
Signed-off-by: Anand-240 <anandprakashsrivastava68@gmail.com>
@Anand-240
Anand-240 force-pushed the fix/linux-cmdline-quote-escaping branch from 244b483 to d96724e Compare August 10, 2026 16:07
@Anand-240 Anand-240 changed the title fix(unikernels): reject single quotes in Linux init args to prevent boot-cmdline corruption fix(unikernels): reject single quotes in Linux init args Aug 10, 2026
@Anand-240

Copy link
Copy Markdown
Contributor Author

Closing this since #897 was marked invalid. As I said on the issue, happy to follow your call on it.

@Anand-240 Anand-240 closed this Aug 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

do-not-merge invalid This doesn't seem right

Projects

None yet

2 participants