jenkinsci / jenkinsci/workflow-durable-task-step-plugin
[JENKINS-44231] Safely pass args to sh step
- Dominant language
- Java
- Stars
- 46
- Forks
- 110
- PR merge metrics
- No merged PRs in 30d
Description
As a Jenkins user, I'll like to use sh semantics to execute commands with args.
I believe Jenkins needs an args: parameter for the sh pipeline step, right now we have script:, returnStdout: and returnStatus: both useful to avoid messing around with shell redirection. However, is clearly impossible or at least difficult to have clean (and secure) executions with sh if they involve string interpolations, maybe Jenkins should do this automatically, but I'm not sure if that kind of magic could be counter productive, I rather depend on args.
Like:
sh(script: "echo", args: ["hello", "world", env.MY_ENV, my_other_def])
or a new pipeline step to avoid overloading sh with different behaviour
command(name: "echo", args: ["hello", "world", env.MY_ENV, my_other_def])
On both cases echo the program, not the shell built-in should be executed, Jenkins should look for the program on the system's $PATH / %PATH% but also an absolute path should be supported too, like a regular Groovy execute() on a List.
["/bin/echo", "foo", "bar"].execute()
Is not common to have Groovy's execute() allowed on Jenkins sandboxed environment, probably for very good reasons.
Also even if execute() is allowed on the Jenkins sandbox, sh semantics are way more convenient.
For reference:
def proc = ['ls', '/meh'].execute()
println proc.getText()
println proc.exitValue() != 0
Where is stderr?
---
Originally reported by andresvia, imported from: Safely pass args to sh step
Raw content of original issue
As a Jenkins user, I'll like to use sh semantics to execute commands with args.
I believe Jenkins needs an args: parameter for the sh pipeline step, right now we have script:, returnStdout: and returnStatus: both useful to avoid messing around with shell redirection. However, is clearly impossible or at least difficult to have clean (and secure) executions with sh if they involve string interpolations, maybe Jenkins should do this automatically, but I'm not sure if that kind of magic could be counter productive, I rather depend on args.
Like:
sh(script: "echo", args: ["hello", "world", env.MY_ENV, my_other_def])or a new pipeline step to avoid overloading sh with different behaviour
command(name: "echo", args: ["hello", "world", env.MY_ENV, my_other_def])On both cases echo the program, not the shell built-in should be executed, Jenkins should look for the program on the system's $PATH / %PATH% but also an absolute path should be supported too, like a regular Groovy execute() on a List.
["/bin/echo", "foo", "bar"].execute()Is not common to have Groovy's execute() allowed on Jenkins sandboxed environment, probably for very good reasons.
Also even if execute() is allowed on the Jenkins sandbox, sh semantics are way more convenient.
For reference:
def proc = ['ls', '/meh'].execute()
println proc.getText()
println proc.exitValue() != 0Where is stderr?
Contributor guide
Assessment
This issue has not been assessed yet.