[PR #6787] [MERGED] [client] Reject leading hyphen in getent input to prevent flag injection #29896

Closed
opened 2026-08-05 08:09:20 -04:00 by saavagebueno · 0 comments
Owner

📋 Pull Request Information

Original PR: https://github.com/netbirdio/netbird/pull/6787
Author: @lixmal
Created: 7/15/2026
Status: Merged
Merged: 7/17/2026
Merged by: @lixmal

Base: 0.74.7-branchHead: worktree-harden-getent-flag-injection


📝 Commits (1)

  • 9494db0 Reject leading hyphen in getent input to prevent flag injection

📊 Changes

2 files changed (+9 additions, -1 deletions)

View changed files

📝 client/ssh/server/getent_unix.go (+6 -1)
📝 client/ssh/server/getent_unix_test.go (+3 -0)

📄 Description

Describe your changes

Defense-in-depth hardening of the input validation that guards the getent passwd and id -G commands in the embedded SSH server. This is not an exploitable issue: SSH login usernames are already validated by validateUsername (which rejects leading hyphens) before any lookup runs, so a flag-like value never reaches these commands today. This change adds a second guard at the sink itself so the protection no longer depends solely on the caller validating first.

  • Reject a leading hyphen in validateGetentInput, so input can never be parsed as a command-line flag by getent/id
  • Add regression tests covering leading-hyphen inputs

Stack

Checklist

  • Is it a bug fix
  • Is a typo/documentation fix
  • Is a feature enhancement
  • It is a refactor
  • Created tests that fail without the change (if possible)
  • This change does not modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — OR I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See CONTRIBUTING.md.

By submitting this pull request, you confirm that you have read and agree to the terms of the Contributor License Agreement.

Documentation

Select exactly one:

  • I added/updated documentation for this change
  • Documentation is not needed for this change (explain why)

Internal hardening of existing input validation with no user-facing change.

Docs PR URL (required if "docs added" is checked)

Paste the PR link from https://github.com/netbirdio/docs here:

https://github.com/netbirdio/docs/pull/__

Summary by CodeRabbit

  • Bug Fixes
    • Improved username validation by rejecting inputs starting with “-”.
    • Made the model allowlist guardrail fail closed when model metadata is missing/empty, returning HTTP 403 with the correct deny details.
  • Reliability Improvements
    • Improved connection/key recovery behavior after repeated handshake timeouts and across key rotation/expiry.
    • QUIC listener now accepts new sessions without being blocked by slow pre-auth handshakes.
  • Mobile
    • Updated login to load persisted profile state when a configuration path is provided.
  • Testing / E2E
    • Expanded end-to-end guardrail and Bedrock request coverage with new harness methods and tests.

🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.

## 📋 Pull Request Information **Original PR:** https://github.com/netbirdio/netbird/pull/6787 **Author:** [@lixmal](https://github.com/lixmal) **Created:** 7/15/2026 **Status:** ✅ Merged **Merged:** 7/17/2026 **Merged by:** [@lixmal](https://github.com/lixmal) **Base:** `0.74.7-branch` ← **Head:** `worktree-harden-getent-flag-injection` --- ### 📝 Commits (1) - [`9494db0`](https://github.com/netbirdio/netbird/commit/9494db011ddac63f829e5894cd913eb52e6ac81e) Reject leading hyphen in getent input to prevent flag injection ### 📊 Changes **2 files changed** (+9 additions, -1 deletions) <details> <summary>View changed files</summary> 📝 `client/ssh/server/getent_unix.go` (+6 -1) 📝 `client/ssh/server/getent_unix_test.go` (+3 -0) </details> ### 📄 Description ## Describe your changes Defense-in-depth hardening of the input validation that guards the `getent passwd` and `id -G` commands in the embedded SSH server. This is **not** an exploitable issue: SSH login usernames are already validated by `validateUsername` (which rejects leading hyphens) before any lookup runs, so a flag-like value never reaches these commands today. This change adds a second guard at the sink itself so the protection no longer depends solely on the caller validating first. - Reject a leading hyphen in `validateGetentInput`, so input can never be parsed as a command-line flag by `getent`/`id` - Add regression tests covering leading-hyphen inputs ## Issue ticket number and link ## Stack <!-- branch-stack --> ### Checklist - [x] Is it a bug fix - [ ] Is a typo/documentation fix - [ ] Is a feature enhancement - [ ] It is a refactor - [x] Created tests that fail without the change (if possible) - [x] This change does **not** modify the public API, gRPC protocols, functionality behavior, CLI / service flags, or introduce a new feature — **OR** I have discussed it with the NetBird team beforehand (link the issue / Slack thread in the description). See [CONTRIBUTING.md](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTING.md#discuss-changes-with-the-netbird-team-first). > By submitting this pull request, you confirm that you have read and agree to the terms of the [Contributor License Agreement](https://github.com/netbirdio/netbird/blob/main/CONTRIBUTOR_LICENSE_AGREEMENT.md). ## Documentation Select exactly one: - [ ] I added/updated documentation for this change - [x] Documentation is **not needed** for this change (explain why) Internal hardening of existing input validation with no user-facing change. ### Docs PR URL (required if "docs added" is checked) Paste the PR link from https://github.com/netbirdio/docs here: https://github.com/netbirdio/docs/pull/__ <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Bug Fixes** * Improved username validation by rejecting inputs starting with “-”. * Made the model allowlist guardrail fail closed when model metadata is missing/empty, returning HTTP 403 with the correct deny details. * **Reliability Improvements** * Improved connection/key recovery behavior after repeated handshake timeouts and across key rotation/expiry. * QUIC listener now accepts new sessions without being blocked by slow pre-auth handshakes. * **Mobile** * Updated login to load persisted profile state when a configuration path is provided. * **Testing / E2E** * Expanded end-to-end guardrail and Bedrock request coverage with new harness methods and tests. <!-- end of auto-generated comment: release notes by coderabbit.ai --> --- <sub>🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.</sub>
saavagebueno added the pull-request label 2026-08-05 08:09:20 -04:00
Sign in to join this conversation.
No Label pull-request
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#29896