All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] scripts/sbom: catch ValueError from malformed shell quoting
@ 2026-07-18 18:44 kadu04t
  2026-07-19  5:24 ` Greg KH
  2026-07-19  5:24 ` Greg KH
  0 siblings, 2 replies; 6+ messages in thread
From: kadu04t @ 2026-07-18 18:44 UTC (permalink / raw)
  To: luis.augenstein; +Cc: maximilian.huber, gregkh, linux-kernel, kadu04t

parse_inputs_from_commands() only caught CmdParsingError and IndexError
when dispatching to command parsers, but several parsers call
shlex.split() internally, which raises ValueError on malformed shell
quoting (e.g. an unterminated quote). This exception was not caught,
so a single malformed build command would abort SBOM generation
entirely, even with fail_on_unknown_build_command=False, defeating the
purpose of tolerant mode.

Catch ValueError alongside CmdParsingError and IndexError so such
commands are logged as a warning/error and skipped instead of aborting
the whole run.

Add tests covering a malformed quoting command and a command missing a
required positional argument.

Signed-off-by: kadu04t <otakurack@gmail.com>
---
 .../savedcmd_parser/savedcmd_parser.py        |  2 +-
 .../tests/cmd_graph/test_savedcmd_parser.py   | 25 +++++++++++++++++++
 2 files changed, 26 insertions(+), 1 deletion(-)

diff --git a/scripts/sbom/sbom/cmd_graph/savedcmd_parser/savedcmd_parser.py b/scripts/sbom/sbom/cmd_graph/savedcmd_parser/savedcmd_parser.py
index 6a7ea4787aa1..d2ca842a7849 100644
--- a/scripts/sbom/sbom/cmd_graph/savedcmd_parser/savedcmd_parser.py
+++ b/scripts/sbom/sbom/cmd_graph/savedcmd_parser/savedcmd_parser.py
@@ -57,7 +57,7 @@ def parse_inputs_from_commands(
         try:
             inputs = matched_parser(single_command)
             input_files.extend(inputs)
-        except (CmdParsingError, IndexError) as e:
+        except (CmdParsingError, IndexError, ValueError) as e:
             log_error_or_warning(
                 "Skipped parsing command {single_command} because of command parsing error: {error_message}",
                 single_command=single_command,
diff --git a/scripts/sbom/tests/cmd_graph/test_savedcmd_parser.py b/scripts/sbom/tests/cmd_graph/test_savedcmd_parser.py
index a061a748e1bf..d7776f072e03 100644
--- a/scripts/sbom/tests/cmd_graph/test_savedcmd_parser.py
+++ b/scripts/sbom/tests/cmd_graph/test_savedcmd_parser.py
@@ -19,6 +19,31 @@ class TestSavedCmdParser(unittest.TestCase):
         errors = sbom_logging._error_logger._message_counts # type: ignore
         self.assertEqual(errors, {})
 
+    # Error handling tests
+    def test_malformed_shell_quoting(self):
+        command = 'gcc "unterminated'
+        with patch.object(sbom_logging, "warning") as warning:
+            parsed = parse_inputs_from_commands(command, fail_on_unknown_build_command=False)
+
+        self.assertEqual(parsed, [])
+        warning.assert_called_once_with(
+            "Skipped parsing command {single_command} because of command parsing error: {error_message}",
+            single_command=command,
+            error_message="No closing quotation",
+        )
+
+    def test_missing_positional_argument(self):
+        command = "objcopy"
+        with patch.object(sbom_logging, "warning") as warning:
+            parsed = parse_inputs_from_commands(command, fail_on_unknown_build_command=False)
+
+        self.assertEqual(parsed, [])
+        warning.assert_called_once_with(
+            "Skipped parsing command {single_command} because of command parsing error: {error_message}",
+            single_command=command,
+            error_message="list index out of range",
+        )
+
     # Compound command tests
     def test_dd_cat(self):
         cmd = "(dd if=arch/x86/boot/setup.bin bs=4k conv=sync status=none; cat arch/x86/boot/vmlinux.bin) >arch/x86/boot/bzImage"
-- 
2.54.0.windows.1


^ permalink raw reply related	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-07-19  8:19 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-18 18:44 [PATCH] scripts/sbom: catch ValueError from malformed shell quoting kadu04t
2026-07-19  5:24 ` Greg KH
2026-07-19  5:24 ` Greg KH
2026-07-19  7:41   ` Carlos Sampaio Ribeiro
     [not found]   ` <CAGf2LZe-8bRdsRJO2CzbTcOE5X9oDUDzYTRZQM+hLUH5gg8-mQ@mail.gmail.com>
2026-07-19  7:42     ` Greg KH
2026-07-19  8:18       ` [PATCH v2] " Carlos Sampaio Ribeiro

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.