[systemd-devel] Antw: Re: Antw: [EXT] Re: Q: journal logging and "{xyz}"

Ulrich Windl Ulrich.Windl at rz.uni-regensburg.de
Mon Dec 27 12:25:50 UTC 2021


>>> Wols Lists <antlists at youngman.org.uk> schrieb am 27.12.2021 um 13:18 in
Nachricht <8802ee4d-230d-8013-553d-8615515ce4ae at youngman.org.uk>:
> On 27/12/2021 12:09, Ulrich Windl wrote:
>> Well, but why write "Failed to kill unit \x7b__SERVICE__\x7d.service" when
>> "unit {__SERVICE__} has an invalid name" (the message I'd suggest)?
>> 
>> I mean: I see no problem_outputting_  the original service name, especially
>> when it's considered to be an invalid name.
> 
> I guess it's seen as a possible attack vector.

Well, usually I wouldn't consider braces to be "evil" characters (unless used in LOG4J, maybe).

> 
> It's not paranoia if they really are out to get you.
> 
> Cheers,
> Wol






More information about the systemd-devel mailing list