From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-vs1-f53.google.com (mail-vs1-f53.google.com [209.85.217.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5926D1F936 for ; Sun, 19 Jul 2026 08:19:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.217.53 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784449165; cv=none; b=maHHrN/JabuDyFf0A5ctx5ifMkb/oNTtGS7a7u+o2j0wfoeYGjlWvQKDj8aJApkENmcASu01ndl5cxrg6DxLKh5vQI73V+boJPmTzB35g5JgqWBFYQEA4ixlK44uWA0X02Ig3yhYsqHBd0/rw1oqoFpP9kniGovscChL3RPU05c= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784449165; c=relaxed/simple; bh=Jmb8xshYyHrkjH9K5+tv2cs73c6nwL0Gccz5Qzf/2EA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=uMVLNfNb1UhQFnIAA3W7EuCMz0ndzpHE+MXCc+XupFgSUxsKHsz4f9RhkzQCV6srgV5UmvVJQJrGFIg+yP4TJffXjkSAqzpVk4pa20qSNnGLj9FftXvfBLLOmrRKzWktmkMgdbRaevPSxkL2ygqL6/bjIg2FZ63Fzn/G3jz2TTM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=DnVJtgIO; arc=none smtp.client-ip=209.85.217.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="DnVJtgIO" Received: by mail-vs1-f53.google.com with SMTP id ada2fe7eead31-737de52625cso4090567137.3 for ; Sun, 19 Jul 2026 01:19:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784449163; x=1785053963; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=dks8766VQGsV9U1hoEzrOxNHRO3orydWswiE1tHPKtM=; b=DnVJtgIOnC9P6e92/DmQTZdjw9hxEdNaiwb3aTX5P+JTVBzEEFQsyVFmCpwBf4eHbc ykIL/IojvkBLEYxvSd2HclEBp5FByF9wiTGiWZjr/I1p8/RCZDtBpUFdX3hDTPh77FNQ YE0tENjX9uEGyvKhBf4n4eq5gvUvalit8YaTAp7EX4mGLB/NNxbhrcXTyi/F5T+QNqJj H+ISjtBTB0IVSHtSdbD3wtm1K1LbTJVW/b5iydKgbjrmEyjLtYy6Gro8QdfLLNaC3Y1P ew2JlI2t0J85FpB5oO2Le6v/2U/SwVyGOt7SPZCHqxqD87J6V8N1jDxvQtWgjXRxYEON klXg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784449163; x=1785053963; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=dks8766VQGsV9U1hoEzrOxNHRO3orydWswiE1tHPKtM=; b=T3/2/S5cohbBSLTCI0WoRtCSYSOWhf1cCAxwNG06tHxLvPvP8cVPSLwL+i+PURU3F7 HLZJXS2RhU+RgTWs03q7plVyHilBlGCseOYRirzMiO/kTZNWAuy9d0QG8MypF01rMyZK WXWpDfJ10xZn8p2q7uyKWxkw5R/O9zh74+P0d1ltTLYXZL7bkK7vy/XwbiA1Vt2KgTvZ wpbvzq8Psrun72/LmuMCWqW8AKb0sYXZIwrAPt4osPRpx0EzKKZyhSkTNcTWw81RoYEA eIcH+mnXO1LCGIU/hxKMJd7WW6UqO09UF/jlRm+efeHeoD+wlkbnkVN1dDln0fkTzgKa UOvw== X-Forwarded-Encrypted: i=1; AHgh+RoLeBBAb6oP2AJukt7D8vomy8Y4nWZ3om6IN14NAKRuayZnAeMj2F3FAbFWhZOhCpMJ5kRQS0Me8oDR4Nw=@vger.kernel.org X-Gm-Message-State: AOJu0Yx7qnGteDOXb46FE3eF+kp4cUPjKOvfQ47p/tK8P+yv4SjcCEFB RDiew4YC7H/A7OQzS0SHoDFPX+Ne3PLVIGOQg71XtawVSN5eOnpNGHEHIt+H8UI0 X-Gm-Gg: AfdE7ckSVkb6pwKZpnIzmLjU4RYo1azCFoa0zPqAHgqeQE47OW1K7niqq4VoFMXzt6K belYl69rW1Zdx54UTf4AONrrLDqzqEpG19u53odjbKo98Oj7BzFQ+yCSZNMmeeBDkkL2WsG8B8n oMVs0f0YbsoRnHLIQxHiLDWNxywrs+EDb6XpnnT2PXMhr5tuWgBY+6MOO0E0vT/fpyyofvQaJj4 qkze4bwNgY7OtsxSM5kve0ViG9eRuNK7+TVQQ0tuE705bx7SjbSsTqnX/tx8KhBx6z9Jv/pYUFz 4fGZOAueqMV+I+MgKZ/MgpSo0zZL6wEfqVTO2FPNWb79SnBOivTiIlnlTMjIklKJBNbWJ0rg0EG 8+Suen9QUGJrkqT/Fa12GoSSvL0mfGPNvrgwOfjyxb8MtxnMkUrscjc1SCiPmuSCACgJwqCVAGz cJ6Q== X-Received: by 2002:a05:6102:b0a:b0:737:bfe6:3b03 with SMTP id ada2fe7eead31-747534a3bcfmr2617549137.7.1784449163186; Sun, 19 Jul 2026 01:19:23 -0700 (PDT) Received: from SadCat ([2804:164:c700:90e0:8131:b062:953a:e434]) by smtp.gmail.com with ESMTPSA id ada2fe7eead31-747581e8f0esm4238657137.10.2026.07.19.01.19.20 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 19 Jul 2026 01:19:21 -0700 (PDT) From: Carlos Sampaio Ribeiro To: Greg KH Cc: luis.augenstein@tngtech.com, maximilian.huber@tngtech.com, linux-kernel@vger.kernel.org Subject: [PATCH v2] scripts/sbom: catch ValueError from malformed shell quoting Date: Sun, 19 Jul 2026 05:18:59 -0300 Message-ID: <20260719081859.1001-1-otakurack@gmail.com> X-Mailer: git-send-email 2.54.0.windows.1 In-Reply-To: <2026071902-overfed-stunner-b086@gregkh> References: <2026071902-overfed-stunner-b086@gregkh> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit parse_inputs_from_commands() only caught CmdParsingError and IndexError when dispatching to command parsers, but several parsers call shlex.split() internally, which raises ValueError on malformed shell quoting (e.g. an unterminated quote). This exception was not caught, so a single malformed build command would abort SBOM generation entirely, even with fail_on_unknown_build_command=False, defeating the purpose of tolerant mode. The issue was found while reviewing the exception handling around the saved-command parser after running its existing tests. It can be reproduced with: parse_inputs_from_commands('gcc "unterminated', fail_on_unknown_build_command=False) Catch ValueError alongside CmdParsingError and IndexError so such commands are logged as a warning/error and skipped instead of aborting the whole run. Add tests covering malformed shell quoting and a missing positional argument. Signed-off-by: Carlos Sampaio Ribeiro --- Changes in v2: - Use my real name in the From and Signed-off-by fields. - Explain how the missing ValueError handling was found. .../savedcmd_parser/savedcmd_parser.py | 2 +- .../tests/cmd_graph/test_savedcmd_parser.py | 25 +++++++++++++++++++ 2 files changed, 26 insertions(+), 1 deletion(-) diff --git a/scripts/sbom/sbom/cmd_graph/savedcmd_parser/savedcmd_parser.py b/scripts/sbom/sbom/cmd_graph/savedcmd_parser/savedcmd_parser.py index 6a7ea4787aa1..d2ca842a7849 100644 --- a/scripts/sbom/sbom/cmd_graph/savedcmd_parser/savedcmd_parser.py +++ b/scripts/sbom/sbom/cmd_graph/savedcmd_parser/savedcmd_parser.py @@ -57,7 +57,7 @@ def parse_inputs_from_commands( try: inputs = matched_parser(single_command) input_files.extend(inputs) - except (CmdParsingError, IndexError) as e: + except (CmdParsingError, IndexError, ValueError) as e: log_error_or_warning( "Skipped parsing command {single_command} because of command parsing error: {error_message}", single_command=single_command, diff --git a/scripts/sbom/tests/cmd_graph/test_savedcmd_parser.py b/scripts/sbom/tests/cmd_graph/test_savedcmd_parser.py index a061a748e1bf..d7776f072e03 100644 --- a/scripts/sbom/tests/cmd_graph/test_savedcmd_parser.py +++ b/scripts/sbom/tests/cmd_graph/test_savedcmd_parser.py @@ -19,6 +19,31 @@ class TestSavedCmdParser(unittest.TestCase): errors = sbom_logging._error_logger._message_counts # type: ignore self.assertEqual(errors, {}) + # Error handling tests + def test_malformed_shell_quoting(self): + command = 'gcc "unterminated' + with patch.object(sbom_logging, "warning") as warning: + parsed = parse_inputs_from_commands(command, fail_on_unknown_build_command=False) + + self.assertEqual(parsed, []) + warning.assert_called_once_with( + "Skipped parsing command {single_command} because of command parsing error: {error_message}", + single_command=command, + error_message="No closing quotation", + ) + + def test_missing_positional_argument(self): + command = "objcopy" + with patch.object(sbom_logging, "warning") as warning: + parsed = parse_inputs_from_commands(command, fail_on_unknown_build_command=False) + + self.assertEqual(parsed, []) + warning.assert_called_once_with( + "Skipped parsing command {single_command} because of command parsing error: {error_message}", + single_command=command, + error_message="list index out of range", + ) + # Compound command tests def test_dd_cat(self): cmd = "(dd if=arch/x86/boot/setup.bin bs=4k conv=sync status=none; cat arch/x86/boot/vmlinux.bin) >arch/x86/boot/bzImage" -- 2.54.0.windows.1