diff --git a/pkg/machine/certificates/certificates.go b/pkg/machine/certificates/certificates.go index 6e205d9349..27f1ba3a16 100644 --- a/pkg/machine/certificates/certificates.go +++ b/pkg/machine/certificates/certificates.go @@ -12,6 +12,7 @@ import ( "go.podman.io/podman/v6/pkg/machine" "go.podman.io/podman/v6/pkg/machine/define" "go.podman.io/podman/v6/pkg/machine/vmconfigs" + "go.podman.io/storage/pkg/stringutils" ) const ( @@ -112,10 +113,14 @@ func copyFileToGuestAnchorsFolder(mc *vmconfigs.MachineConfig, guestFilePath str mc.SSH.IdentityPath, mc.Name, mc.SSH.Port, - []string{"sudo", "cp", guestFilePath, GuestAnchorsPath}, + []string{guestCopyCommand(guestFilePath)}, ) } +func guestCopyCommand(guestFilePath string) string { + return stringutils.ShellQuoteArguments([]string{"sudo", "cp", guestFilePath, GuestAnchorsPath}) +} + // saveCertificatesToPEM exports the certificates in certs to a PEM file func saveCertificatesToPEM(certs []*x509.Certificate, certsFilePath string) error { certsFile, err := os.Create(certsFilePath) diff --git a/pkg/machine/certificates/certificates_copy_test.go b/pkg/machine/certificates/certificates_copy_test.go new file mode 100644 index 0000000000..7d37d8dad0 --- /dev/null +++ b/pkg/machine/certificates/certificates_copy_test.go @@ -0,0 +1,25 @@ +package certificates + +import ( + "testing" + + "github.com/stretchr/testify/assert" +) + +func TestGuestCopyCommand(t *testing.T) { + const anchor = "/etc/pki/ca-trust/source/anchors" + tests := []struct { + name string + source string + want string + }{ + {"plain", "/home/user/cert.pem", "sudo cp /home/user/cert.pem " + anchor}, + {"space", "/home/First Last/cert.pem", "sudo cp '/home/First Last/cert.pem' " + anchor}, + {"parenthesis", "/home/First(Last/cert.pem", "sudo cp '/home/First(Last/cert.pem' " + anchor}, + } + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + assert.Equal(t, tt.want, guestCopyCommand(tt.source)) + }) + } +}