T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:100- Finding
Unsafe and Incorrect Positional Argument Handling in Docker Commands
- Content
View full analysis
" docker top $2 2>/dev/null || echo 'Container not found' } cmd_logs() { local container="${2:-}" local lines="${3:-}" [ -z "$container" ] && die "Usage: $SCRIPT_NAME logs " docker logs --tail ${3:-50} $2 2>/dev/null } cmd_inspect() { local container="${2:-}" [ -z "$container" ] && die "Usage: $SCRIPT_NAME inspect " docker inspect $2 2>/dev/null | python3 -c 'import json,sys;d=json.load(sys.stdin)[0];print("Name:",d["Name"]);print("State:",d["State"]["Status"])' 2>/dev/null } ``` The command dispatcher removes the subcommand before invoking each handler: ```bash case "$cmd" in list) shift; cmd_list "$@" ;; stats) shift; cmd_stats "$@" ;; top) shift; cmd_top "$@" ;; logs) shift; cmd_logs "$@" ;; inspect) shift; cmd_inspect "$@" ;; cleanup) shift; cmd_cleanup "$@" ;; esac ``` ### Technical Analysis After `main` executes `shift`, the first user-supplied command argument becomes `$1`. However, `cmd_top` and `cmd_inspect` retrieve the container from `$2`, while `cmd_logs` retrieves the container from `$2` and the line count from `$3`. Consequently, documented invocations are interpreted incorrectly: - `script.sh top my-container` leaves `$2` empty and fails the validation check. - `script.sh inspect my-container` leaves `$2` empty and fails. - `script.sh logs my-container 100` treats `100` as the container and defaults the log count to 50. The variables are subsequently expanded without quotes and without an option terminator. Shell metacharacters introduced through parameter expansion are not reparsed as shell synt ...[truncated 1557 chars]- Remediation
View remediation
" local container="$1" docker top -- "$container" } cmd_logs() { [ "$#" -ge 1 ] && [ "$#" -le 2 ] || die "Usage: $SCRIPT_NAME logs [lines]" local container="$1" local lines="${2:-50}" [[ "$lines" =~ ^[1-9][0-9]*$ ]] || die "Log line count must be a positive integer" docker logs --tail "$lines" -- "$container" } cmd_inspect() { [ "$#" -eq 1 ] || die "Usage: $SCRIPT_NAME inspect " local container="$1" docker inspect -- "$container" | python3 -c 'import json,sys; d=json.load(sys.stdin)[0]; print("Name:",d["Name"]); print("State:",d["State"]["Status"])' } ``` Compatibility of `--` should be verified against the minimum supported Docker CLI version. ]]>
