Unescaped paths produce invalid launchd plist XML #6
Labels
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
carvers/silta#6
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
plist()(src/platform/macos.rs:163) interpolates the binary and config paths into XML without escaping, so a path containing&or<produces a malformed plist that launchd rejects.Failure scenario: a config lives at a path with an ampersand, e.g.
/usr/local/etc/silta 1&2/forwards.toml(root-owned, so it passes the safety check).setup --persistentwrites a plist whose<string>contains a bare&, which is invalid XML; launchd silently refuses to load it at boot. After the next reboot the interface is never recreated, every dedicated-address forward fails, and nothing points at the unloadable plist as the cause.Fix direction: XML-escape the interpolated paths (&, <, >, ", ') before writing the plist.
Source: high-effort code review, CONFIRMED. Area: setup/platform.