Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[HPR-1281] core: Fix custom plugin loading in current working directory #12544

Merged
merged 3 commits into from
Aug 1, 2023

Conversation

nywilken
Copy link
Contributor

@nywilken nywilken commented Jul 27, 2023

  • Update plugin loading for current directory

Starting with Go 1.19 the loading of binaries from the current working directory was
deemed as a possible security problem. Thus the use of exec.Command or exec.LookPath no longer resolves an executable within the current working directory. This change updates the discover logic to return absolute paths for any discovered plugin, which is called directly when passed to exec.Command or exec.LookPath. By doing this Packer is able to load a custom plugin sitting in the current working directory as it did in version prior to v1.9.2.

  • Update plugin discover logic

When copying a plugin's checksum file (packer-plugin-*_SHA256SUM) installed by packer plugins install or packer init into a separate directory the file may be copied with the executable bit turned out. If unchanged after the copy Packer would discover the checksum file as a possible plugin match and error when trying to execute describe on the plugin look a like. This change adds a checksum file test to the plugin matching logic. If the discovered plugin name is a checksum it is excluded from the discovered plugin list.

Closes #12543

@nywilken nywilken requested a review from a team as a code owner July 27, 2023 20:11
@nywilken nywilken force-pushed the nywilken/cwd-plugin-loading-fix branch 2 times, most recently from fa6d6d1 to 48a933c Compare July 27, 2023 20:18
@nywilken nywilken added the backport/1.9.x Backport PR changes to `release/1.9.x` label Jul 27, 2023
@nywilken nywilken changed the title nywilken/cwd plugin loading fix core: Fix custom plugin loading in current working directory Jul 27, 2023
Copy link
Contributor

@lbajolet-hashicorp lbajolet-hashicorp left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM, good catch for the checksum issue and the go 1.19 change

nywilken added 3 commits July 28, 2023 13:05
Starting with Go 1.19 the loading of binaries from the current working directory was
deemed as a possible security problem. Thus the use of exec.Command or exec.LookPath no longer resolves
an executable within the current working directory. This change updates the discover logic to return absolute
paths for any discovered plugin, which is called directly when passed to exec.Command or exec.LookPath. By doing
this Packer is able to load a custom plugin sitting in the current working directory as it did in version prior to v1.9.2.
When copying a plugin's checksum file (packer-plugin-*_SHA256SUM) installed by `packer plugins install` or `packer init`
into a separate directory the file may be copied with the executable bit turned out. If unchanged after the copy, Packer would
discover the checksum file as a possible plugin match and error when trying to execute describe on the plugin look a like. This change
adds a checksum file test to the plugin matching logic. If the discovered plugin name is a checksum it is excluded from the discovered plugin list.
* Add test case for loading plugin in CWD
* Add test case to validate checksume files are ignored
* Update Discover to include CWD "." in PluginFolders if KnowPluginFolders is unset
@nywilken nywilken force-pushed the nywilken/cwd-plugin-loading-fix branch from e5b026a to 2f698e8 Compare July 28, 2023 17:05
Copy link
Contributor

@JenGoldstrich JenGoldstrich left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tested this locally and was able to run my locally built plugins

@nywilken nywilken merged commit 848039d into main Aug 1, 2023
@nywilken nywilken deleted the nywilken/cwd-plugin-loading-fix branch August 1, 2023 20:21
@nywilken nywilken changed the title core: Fix custom plugin loading in current working directory [HPR-1281] core: Fix custom plugin loading in current working directory Aug 2, 2023
@github-actions
Copy link

github-actions bot commented Sep 2, 2023

I'm going to lock this pull request because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active issues.
If you have found a problem that seems related to this change, please open a new issue and complete the issue template so we can capture all the details necessary to investigate further.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Sep 2, 2023
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
backport/1.9.x Backport PR changes to `release/1.9.x` bug regression
Projects
None yet
Development

Successfully merging this pull request may close these issues.

Packer 1.9.2 is unable to find a custom plugin on the current working directory
3 participants