3 ms·
The disagreement is as to who it is easy for; the author seems to only consider programmers by trade and then blame some notion of propagating a legacy of unsaf
by Normal_gaussian 5y ago
The disagreement is as to who it is easy for; the author seems to only consider programmers by trade and then blame some notion of propagating a legacy of unsafe calls.
Every language the author lists as vulnerable was intended, at launch, to be used both as a serious programming language as well as program launching glue or by non-career programmers for things that aren't production grade applications.
The only language I can think of that is explicitly an application development language is Rust, and as the author mentions this vuln is not present.
And as a note, the alternative to exec in NodeJS are keeping execFile and using these ~10 lines [1] or using spawn directly with these 216 lines [2]. I barely trust myself to reliably reproduce those.
[1] https://github.com/nodejs/node/blob/df25424b9195d3122452989582a6988d1ea342a2/lib/child_process.js#L184-L229 https://github.com/nodejs/node/blob/df25424b9195d31224529895...
[2] https://github.com/nodejs/node/blob/df25424b9195d3122452989582a6988d1ea342a2/lib/child_process.js#L279-L495 https://github.com/nodejs/node/blob/df25424b9195d31224529895...
- laumars 5y agoThe need for APIs to not have non-obvious side effects is especially important for non-career developers as they’re less likely to be aware of said side effects. So your argument is actually a strong reason for exec() not to fork /bin/sh
- Normal_gaussian 5y agoYou are not wrong, but this was included on the original post > Of course it should really be called 'runInShell'