Merge pull request #29853 from schmitt-christopher/fix/certificate-import-path-quoting

Fix: Quote paths on import of native CA Certificates to support special chars in hosts home path
This commit is contained in:
Paul Holzinger 2026-10-01 13:51:07 +02:00 • committed by GitHub
commit 54afd0e512
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 31 additions and 1 deletions

View file

@ -12,6 +12,7 @@ import (
"go.podman.io/podman/v6/pkg/machine"
"go.podman.io/podman/v6/pkg/machine/define"
"go.podman.io/podman/v6/pkg/machine/vmconfigs"
"go.podman.io/storage/pkg/stringutils"
)
const (
@ -112,10 +113,14 @@ func copyFileToGuestAnchorsFolder(mc *vmconfigs.MachineConfig, guestFilePath str
mc.SSH.IdentityPath,
mc.Name,
mc.SSH.Port,
[]string{"sudo", "cp", guestFilePath, GuestAnchorsPath},
[]string{guestCopyCommand(guestFilePath)},
)
}
func guestCopyCommand(guestFilePath string) string {
return stringutils.ShellQuoteArguments([]string{"sudo", "cp", guestFilePath, GuestAnchorsPath})
}
// saveCertificatesToPEM exports the certificates in certs to a PEM file
func saveCertificatesToPEM(certs []*x509.Certificate, certsFilePath string) error {
certsFile, err := os.Create(certsFilePath)

View file

@ -0,0 +1,25 @@
package certificates
import (
"testing"
"github.com/stretchr/testify/assert"
)
func TestGuestCopyCommand(t *testing.T) {
const anchor = "/etc/pki/ca-trust/source/anchors"
tests := []struct {
name string
source string
want string
}{
{"plain", "/home/user/cert.pem", "sudo cp /home/user/cert.pem " + anchor},
{"space", "/home/First Last/cert.pem", "sudo cp '/home/First Last/cert.pem' " + anchor},
{"parenthesis", "/home/First(Last/cert.pem", "sudo cp '/home/First(Last/cert.pem' " + anchor},
}
for _, tt := range tests {
t.Run(tt.name, func(t *testing.T) {
assert.Equal(t, tt.want, guestCopyCommand(tt.source))
})
}
}