“Yeah… I was very tired that night.”
The (un)installation bug from the previous post was an overeager directory delete, but a more common problem I’ve seen is this one. Here’s an example from iTunes 2.0:
The installer tries to erase a previous version of iTunes using (with root privileges) the
rm -rfcommand. However it doesn’t take into account that volume names can contain spaces. […]When the diskname (partition name) starts with a space the following happens:
rm -rf /Volumes/ harddiskname/iTunes.app 2> /dev/nullSo
rmremoves/Volumes(all mount points!) and a nonexistent pathharddiskname/iTunes.app, but no errors are displayed because they are /dev/nulled.
And a very similar thing a decade later, from Steam’s Linux installer:
I launched Steam. It did not launch, it offered to let me browse, and still could not find it when I pointed to the new location. Steam crashed. I restarted it.
It re-installed itself and everything looked great. Until I looked and saw that steam had apparently deleted everything owned by my user recursively from the root directory. Including my 3TB external drive I back everything up to that was mounted under /media.
The culprit was identified by another user a few messages down:
rm -rf "$STEAMROOT/"*could be evaluated asrm -rf "/"* if $STEAMROOTis empty
These are the sort of classic user-generated content meets string concatenation/interpolation bugs that haunt engineers’s dreams.
The solution: If a user gives you a string, you have to wrap it as safely as possible so that it could never break apart into pieces in transit.
So you wrap the path with quotation marks. (I believe you can actually do this everywhere in Linux – cd "/usr/local" will work as well as cd /usr/local – except no one ever does so as it’s quite annoying.) But then, a string with quotation marks would escape containment, so you have to escape those by changing " to \". And then, naturally, you also have to escape any freefloating backslashes to \\.
Of course, there are usually functions that take care of all of the above; you just have to remember to use them, as well as think about the edge cases like a variable being empty to begin with.
This all is a distant version of SQL injection – perhaps most well-known from this XKCD comic – and a more modern prompt injection. There’s even a version of it in UI design:
Here, the wrapping isn’t for security reasons, but to help people understand where the command ends and the string begins. But this introduces a new challenge, as any type of visual wrapping – quotation marks, bolding, italicization – can draw undue attention to the string itself. So, sometimes you just leave it be and hope for the best:
But let’s go back to the installation issues. I bet there are were tons more string interpolation and escaping bugs that we simply never learned about. Yet, as users of a project called Bumblebee learned in 2011, nothing beats the destructive power of a simple typo.
The best way to start here is with the summary of the fix to the bug, because that is the best encapsulation of the story:
Yeah, you read it right.
Here’s the original bug report:
An extra space at line 351:
rm -rf /usr /lib/nvidia-current/xorg/xorg
causes the install.sh script to do anrm -rfon the/usrdirectory for people installing in ubuntu.Totally uncool dude!!! The script deletes everything under
/usr. I just had to reinstall linux on my pc to recover.Removing the space will fix this. Probably should do it quickly!!!
Reader, the bug was fixed quickly.