Unescaped paths produce invalid launchd plist XML #6

Closed
opened 2026-08-11 10:25:48 +00:00 by aav · 0 comments
Owner

plist() (src/platform/macos.rs:163) interpolates the binary and config paths into XML without escaping, so a path containing & or < produces a malformed plist that launchd rejects.

Failure scenario: a config lives at a path with an ampersand, e.g. /usr/local/etc/silta 1&2/forwards.toml (root-owned, so it passes the safety check). setup --persistent writes a plist whose <string> contains a bare &, which is invalid XML; launchd silently refuses to load it at boot. After the next reboot the interface is never recreated, every dedicated-address forward fails, and nothing points at the unloadable plist as the cause.

Fix direction: XML-escape the interpolated paths (&, <, >, ", ') before writing the plist.

Source: high-effort code review, CONFIRMED. Area: setup/platform.

`plist()` (src/platform/macos.rs:163) interpolates the binary and config paths into XML without escaping, so a path containing `&` or `<` produces a malformed plist that launchd rejects. **Failure scenario:** a config lives at a path with an ampersand, e.g. `/usr/local/etc/silta 1&2/forwards.toml` (root-owned, so it passes the safety check). `setup --persistent` writes a plist whose `<string>` contains a bare `&`, which is invalid XML; launchd silently refuses to load it at boot. After the next reboot the interface is never recreated, every dedicated-address forward fails, and nothing points at the unloadable plist as the cause. **Fix direction:** XML-escape the interpolated paths (&, <, >, ", ') before writing the plist. Source: high-effort code review, CONFIRMED. Area: setup/platform.
aav self-assigned this 2026-08-11 10:27:24 +00:00
aav closed this issue 2026-08-11 11:03:14 +00:00
Sign in to join this conversation.
No milestone
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
carvers/silta#6
No description provided.