Uploaded image for project: 'Ruby Driver'
  1. Ruby Driver
  2. RUBY-2034

Improve security of mongocryptd spawning

    XMLWordPrintable

    Details

    • Type: Improvement
    • Status: Closed
    • Priority: Minor - P4
    • Resolution: Fixed
    • Affects Version/s: None
    • Fix Version/s: 2.12.0.rc0
    • Component/s: None
    • Labels:
      None

      Description

      Instead of Process.spawn:

      • Try fork/exec to avoid the command being interpreted as shell command rather than process path
      • Test on jruby, expect failure to fork
      • Rescue fork error, assuming it is possible to tell the error is because fork is unsupported (jruby/windows) use Process.spawn
      • When Process.spawn is used, prohibit spaces and & in mcd path

        Attachments

          Activity

            People

            Assignee:
            oleg.pudeyev Oleg Pudeyev
            Reporter:
            oleg.pudeyev Oleg Pudeyev
            Participants:
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

              Dates

              Created:
              Updated:
              Resolved: