Skip to content

Commit ce53491

Browse files
authored
fix: shell quote system package names in Dockerfile templates and image commands (#5583)
* fix: shell quote system package names in Dockerfile templates and image commands Signed-off-by: Frost Ming <[email protected]> * fix: specify xgboost version constraint in FRAMEWORK_DEPENDENCIES Signed-off-by: Frost Ming <[email protected]> --------- Signed-off-by: Frost Ming <[email protected]>
1 parent 1ee719a commit ce53491

8 files changed

Lines changed: 41 additions & 6 deletions

File tree

‎noxfile.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@
3535
"sklearn": ["scikit-learn"],
3636
"tensorflow": ["tensorflow"],
3737
"torchscript": [],
38-
"xgboost": ["xgboost", "scikit-learn<1.6"],
38+
"xgboost": ["xgboost<3.2", "scikit-learn<1.6"],
3939
"detectron": ["detectron2"],
4040
"transformers": ["transformers", "tokenizer"],
4141
}

‎src/_bentoml_sdk/images.py‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@
33
import hashlib
44
import logging
55
import platform
6+
import shlex
67
import shutil
78
import subprocess
89
import sys
@@ -84,7 +85,7 @@ def system_packages(self, *packages: str) -> t.Self:
8485
)
8586
self.commands.append(
8687
CONTAINER_METADATA[self.distro]["install_command"].format(
87-
packages=" ".join(packages)
88+
packages=" ".join(shlex.quote(package) for package in packages)
8889
)
8990
)
9091
return self

‎src/bentoml/_internal/container/frontend/dockerfile/templates/base_alpine.j2‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ ENV ENV /root/.bashrc
1111
{% if __options__system_packages is not none %}
1212
# Install user-defined system package
1313
{% call common.RUN(__enable_buildkit__) -%} {{ common.mount_cache("/var/cache/apk") }} {% endcall -%} set -eux \
14-
apk add --update {{ __options__system_packages | join(' ') }}
14+
apk add --update {{ __options__system_packages | map('bash_quote') | join(' ') }}
1515
{% endif -%}
1616
{% endblock %}
1717

‎src/bentoml/_internal/container/frontend/dockerfile/templates/base_amazonlinux.j2‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,7 +15,7 @@ USER root
1515
{% if __options__system_packages is not none %}
1616
# Install user-defined system package
1717
{% call common.RUN(__enable_buildkit__) -%} {{ common.mount_cache("/var/cache/yum") }} {% endcall -%} set -eux && \
18-
yum install -y {{ __options__system_packages | join(' ') }}
18+
yum install -y {{ __options__system_packages | map('bash_quote') | join(' ') }}
1919
{% endif -%}
2020
RUN ln -sf /usr/bin/python{{ __options__python_version }} /usr/bin/python3 && \
2121
ln -sf /usr/bin/pip{{ __options__python_version }} /usr/bin/pip3

‎src/bentoml/_internal/container/frontend/dockerfile/templates/base_debian.j2‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -10,5 +10,5 @@ RUN rm -f /etc/apt/apt.conf.d/docker-clean; echo 'Binary::apt::APT::Keep-Downloa
1010
{% call common.RUN(__enable_buildkit__) -%} {{ common.mount_cache(__lib_apt__) }} {{ common.mount_cache(__cache_apt__) }} {% endcall -%} set -eux && \
1111
apt-get update -y && \
1212
apt-get install -q -y -o Dpkg::Options::=--force-confdef --no-install-recommends --allow-remove-essential \
13-
ca-certificates gnupg2 bash build-essential curl {% if __options__system_packages is not none %}{{ __options__system_packages | join(' ') }}{% endif %}
13+
ca-certificates gnupg2 bash build-essential curl {% if __options__system_packages is not none %}{{ __options__system_packages | map('bash_quote') | join(' ') }}{% endif %}
1414
{% endblock %}

‎src/bentoml/_internal/container/frontend/dockerfile/templates/base_ubi8.j2‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,6 @@ USER root
99
{% if __options__system_packages is not none %}
1010
# Install user-defined system package
1111
{% call common.RUN(__enable_buildkit__) -%} {{ common.mount_cache("/var/cache/yum") }} {% endcall -%} set -eux && \
12-
yum install -y {{ __options__system_packages | join(' ') }}
12+
yum install -y {{ __options__system_packages | map('bash_quote') | join(' ') }}
1313
{% endif -%}
1414
{% endblock %}
Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
from __future__ import annotations
2+
3+
from _bentoml_sdk.images import Image
4+
5+
6+
def test_image_system_packages_are_shell_quoted() -> None:
7+
image = Image(distro="debian")
8+
9+
image.system_packages("libpq-dev", "package name", "foo$(touch /tmp/pwned)")
10+
11+
assert image.commands[-1] == (
12+
"apt-get install -q -y -o Dpkg::Options::=--force-confdef "
13+
"libpq-dev 'package name' 'foo$(touch /tmp/pwned)'"
14+
)
Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
from __future__ import annotations
2+
3+
from bentoml._internal.bento.build_config import CondaOptions
4+
from bentoml._internal.bento.build_config import DockerOptions
5+
from bentoml._internal.container.generate import generate_containerfile
6+
7+
8+
def test_generate_containerfile_quotes_system_packages(tmp_path) -> None:
9+
dockerfile = generate_containerfile(
10+
DockerOptions(
11+
distro="debian",
12+
python_version="3.11",
13+
system_packages=["libpq-dev", "package name", "foo$(touch /tmp/pwned)"],
14+
),
15+
str(tmp_path),
16+
conda=CondaOptions(),
17+
bento_fs=tmp_path,
18+
)
19+
20+
assert "libpq-dev 'package name' 'foo$(touch /tmp/pwned)'" in dockerfile

0 commit comments

Comments
 (0)