Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Prevent the password of SYS and SYSTEM password leak #246

Merged

Conversation

nblxa
Copy link
Contributor

@nblxa nblxa commented Sep 3, 2022

Setting the tracing -x flag in Bash causes all interpolated shell commands to be printed into stdout including the randomly generated SYS and SYSTEM passwords. This may let readers of image build logs gain elevated access to databases provisioned by El Carro.

This PR temporarily disables the bash tracing for the duration of the CDB creation, then resumes tracing again.

…I logs when building a seeded database image.
@google-oss-prow
Copy link

Hi @nblxa. Thanks for your PR.

I'm waiting for a GoogleCloudPlatform member to verify that this patch is reasonable to test. If it is, they should reply with /ok-to-test on its own line. Until that is done, I will not automatically test new commits in this PR, but the usual testing commands by org members will still work. Regular contributors should join the org to skip this step.

Once the patch is verified, the new status will be reflected by the ok-to-test label.

I understand the commands that are listed here.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

@akinfermo
Copy link
Collaborator

/ok-to-test

Copy link
Collaborator

@akinfermo akinfermo left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for this improvement! LGTM!

@google-oss-prow
Copy link

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: akinfermo, nblxa

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@akinfermo akinfermo added the enhancement New feature or request label Sep 5, 2022
@nblxa
Copy link
Contributor Author

nblxa commented Sep 6, 2022

Thanks, @akinfermo! As I have no write access to the repo, I let you guys merge.

@akinfermo akinfermo merged commit 2e044dc into GoogleCloudPlatform:main Sep 6, 2022
@nblxa nblxa deleted the feauture/prevent-db-password-leak branch September 7, 2022 09:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants