2018-01-22 22:49:30 +00:00
|
|
|
// Copyright (c) 2018 GitHub, Inc.
|
|
|
|
// Use of this source code is governed by the MIT license that can be
|
|
|
|
// found in the LICENSE file.
|
|
|
|
|
2019-06-19 20:46:59 +00:00
|
|
|
#include "shell/app/command_line_args.h"
|
2021-09-03 21:16:33 +00:00
|
|
|
|
2024-09-05 02:27:34 +00:00
|
|
|
#include <algorithm>
|
2021-06-14 12:01:00 +00:00
|
|
|
#include <locale>
|
2018-01-22 22:49:30 +00:00
|
|
|
|
2021-09-03 21:16:33 +00:00
|
|
|
#include "sandbox/policy/switches.h"
|
|
|
|
#include "shell/common/options_switches.h"
|
|
|
|
|
2018-01-22 22:49:30 +00:00
|
|
|
namespace {
|
|
|
|
|
2024-09-05 02:27:34 +00:00
|
|
|
#if BUILDFLAG(IS_WIN)
|
|
|
|
constexpr auto DashDash = base::CommandLine::StringPieceType{L"--"};
|
|
|
|
#else
|
|
|
|
constexpr auto DashDash = base::CommandLine::StringPieceType{"--"};
|
|
|
|
#endif
|
|
|
|
|
|
|
|
// we say it's a URL arg if it starts with a URI scheme that:
|
|
|
|
// 1. starts with an alpha, and
|
|
|
|
// 2. contains no spaces, and
|
|
|
|
// 3. is longer than one char (to ensure it's not a Windows drive path)
|
|
|
|
bool IsUrlArg(const base::CommandLine::StringPieceType arg) {
|
|
|
|
const auto scheme_end = arg.find(':');
|
|
|
|
if (scheme_end == base::CommandLine::StringPieceType::npos)
|
|
|
|
return false;
|
|
|
|
|
|
|
|
const auto& c_locale = std::locale::classic();
|
|
|
|
const auto isspace = [&](auto ch) { return std::isspace(ch, c_locale); };
|
|
|
|
const auto scheme = arg.substr(0U, scheme_end);
|
|
|
|
return std::size(scheme) > 1U && std::isalpha(scheme.front(), c_locale) &&
|
|
|
|
std::ranges::none_of(scheme, isspace);
|
2018-01-22 22:49:30 +00:00
|
|
|
}
|
|
|
|
} // namespace
|
|
|
|
|
2019-06-19 21:23:04 +00:00
|
|
|
namespace electron {
|
2018-01-22 22:49:30 +00:00
|
|
|
|
2024-09-05 02:27:34 +00:00
|
|
|
// Check for CVE-2018-1000006 issues. Return true iff argv looks safe.
|
|
|
|
// Sample exploit: 'exodus://aaaaaaaaa" --gpu-launcher="cmd" --aaaaa='
|
|
|
|
// Prevent it by returning false if any arg except '--' follows a URL arg.
|
|
|
|
// More info at https://www.electronjs.org/blog/protocol-handler-fix
|
|
|
|
bool CheckCommandLineArguments(const base::CommandLine::StringVector& argv) {
|
2018-05-22 16:51:03 +00:00
|
|
|
bool block_args = false;
|
2024-09-05 02:27:34 +00:00
|
|
|
for (const auto& arg : argv) {
|
|
|
|
if (arg == DashDash)
|
2018-01-22 22:49:30 +00:00
|
|
|
break;
|
2024-09-05 02:27:34 +00:00
|
|
|
if (block_args)
|
2018-05-22 16:51:03 +00:00
|
|
|
return false;
|
2024-09-05 02:27:34 +00:00
|
|
|
if (IsUrlArg(arg))
|
2018-05-22 16:51:03 +00:00
|
|
|
block_args = true;
|
2018-01-22 22:49:30 +00:00
|
|
|
}
|
|
|
|
return true;
|
|
|
|
}
|
|
|
|
|
2021-09-03 21:16:33 +00:00
|
|
|
bool IsSandboxEnabled(base::CommandLine* command_line) {
|
|
|
|
return command_line->HasSwitch(switches::kEnableSandbox) ||
|
|
|
|
!command_line->HasSwitch(sandbox::policy::switches::kNoSandbox);
|
|
|
|
}
|
|
|
|
|
2019-06-19 21:23:04 +00:00
|
|
|
} // namespace electron
|