aws / aws/amazon-ssm-agent

SSM Inventory dataprovider doesn't handle control+M characters in the output

Open
#492 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
1.2k
Forks
357
PR merge metrics
No merged PRs in 30d

Description

We use Inspector and the Systems Manager agent to gather software inventory for vulnerability management.
Out of nearly 500 instances we have 2 that EC2 instances that show as \"Not Scanning - No Inventory\" in the Inspector console. One of the instances is i-0af550653d52d6e8f in this AWS account. I checked Systems Manager Fleet Manager and everything looks okay. I am able to successfully connect to this instance via Session Manager so I know the agent is operational and has the SSM IAM permissions.

On the system itself, I see the following errors in /var/log/amazon/ssm/errors.log:

2023-01-04 18:13:31 ERROR [collectPlatformDependentApplicationData @ dataProvider_unix.go.147] [ssm-document-worker] [cb96ae82-641a-499b-99d0-5d36d1b220af.2023-01-04T18-13-30.885Z] [DataBackend] [pluginName=aws:softwareInventory] [aws:softwareInventory] Failed to gather inventory data for AWS:Application: Unable to convert query output to ApplicationData - invalid character '\\r' in string literal
2023-01-04 18:13:31 ERROR [getApplicationData @ dataProvider_unix.go.348] [ssm-document-worker] [cb96ae82-641a-499b-99d0-5d36d1b220af.2023-01-04T18-13-30.885Z] [DataBackend] [pluginName=aws:softwareInventory] [aws:softwareInventory] Unable to convert query output to ApplicationData - invalid character '\\r' in string literal

It looks like the agent is having trouble parsing a package name because it is finding a \\r character in it.

Furthur investivation showed that the java-jdk installed on the machine has a ctrol+M character which looks like this:
```
This is a helper package that creates /usr/share/javascript and enables it in
the Apache and Lighttpd webserver.","PackageId":"javascript-common_11_all.deb"},{"Name":"jdk-11","Publisher":"jdk-download-help_ww ","Version":"11.0.16.1-1","ApplicationType":"java","Architecture":"amd64","Url":"","Summary":"Java Platform Standard Edition Development Kit^M
The Java Platform Standard Edition Development Kit (JDK) includes both the runtime environment (Java virtual machine, the Java platform classes and supporting files) and development tools (compilers, debuggers, tool libraries and other tools). The JDK is a development environment for building applications, applets and components that can be deployed with the Java Platform Standard Edition Runtime Environment.","PackageId":"jdk-11_11.0.16.1-1_amd64.deb"},{"Name":"keyutils","Publisher":"Christian Kastner ","Version":"1.5.9-9","ApplicationType":"admin","Architecture":"amd64","Url":"http://people.redhat.com/~dhowells/keyutils/","Summary":"Linux Key Management Utilities
K
```

Contributor guide

Open the contributing guide

Research direction

Start in dataProvider_unix.go at collectPlatformDependentApplicationData around line 147 and getApplicationData around line 348, using the errors.log messages as the entry points. Reproduce inventory parsing with the control+M character shown in the package Summary. Done means the affected inventory output no longer fails with the invalid '\r' parse error.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, go, linux
Domain
backend, cloud, operating-systems
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.