jenkinsci / jenkinsci/workflow-durable-task-step-plugin

[JENKINS-44231] Safely pass args to sh step

Open
#527 15 comments 0 reactions 0 assignees View on GitHub
component:workflow-durable-task-step-plugin imported-jira-issue jira-type:story priority:major resolution:unresolved
Dominant language
Java
Stars
46
Forks
110
PR merge metrics
No merged PRs in 30d

Description

As a Jenkins user, I'll like to use sh semantics to execute commands with args.

I believe Jenkins needs an args: parameter for the sh pipeline step, right now we have script:, returnStdout: and returnStatus: both useful to avoid messing around with shell redirection. However, is clearly impossible or at least difficult to have clean (and secure) executions with sh if they involve string interpolations, maybe Jenkins should do this automatically, but I'm not sure if that kind of magic could be counter productive, I rather depend on args.

Like:

sh(script: "echo", args: ["hello", "world", env.MY_ENV, my_other_def])

or a new pipeline step to avoid overloading sh with different behaviour

command(name: "echo", args: ["hello", "world", env.MY_ENV, my_other_def])

On both cases echo the program, not the shell built-in should be executed, Jenkins should look for the program on the system's $PATH / %PATH% but also an absolute path should be supported too, like a regular Groovy execute() on a List.

["/bin/echo", "foo", "bar"].execute()

Is not common to have Groovy's execute() allowed on Jenkins sandboxed environment, probably for very good reasons.

Also even if execute() is allowed on the Jenkins sandbox, sh semantics are way more convenient.

For reference:

def proc = ['ls', '/meh'].execute()

println proc.getText()
println proc.exitValue() != 0

Where is stderr?

---
Originally reported by andresvia, imported from: Safely pass args to sh step


  • status: Open
  • priority: Major
  • component(s): workflow-durable-task-step-plugin
  • label(s): sh, step
  • resolution: Unresolved
  • votes: 20
  • watchers: 23
  • imported: 20251212-090250

Raw content of original issue

As a Jenkins user, I'll like to use sh semantics to execute commands with args.

I believe Jenkins needs an args: parameter for the sh pipeline step, right now we have script:, returnStdout: and returnStatus: both useful to avoid messing around with shell redirection. However, is clearly impossible or at least difficult to have clean (and secure) executions with sh if they involve string interpolations, maybe Jenkins should do this automatically, but I'm not sure if that kind of magic could be counter productive, I rather depend on args.

Like:



sh(script: "echo", args: ["hello", "world", env.MY_ENV, my_other_def])


or a new pipeline step to avoid overloading sh with different behaviour



command(name: "echo", args: ["hello", "world", env.MY_ENV, my_other_def])


On both cases echo the program, not the shell built-in should be executed, Jenkins should look for the program on the system's $PATH / %PATH% but also an absolute path should be supported too, like a regular Groovy execute() on a List.



["/bin/echo", "foo", "bar"].execute()


Is not common to have Groovy's execute() allowed on Jenkins sandboxed environment, probably for very good reasons.

Also even if execute() is allowed on the Jenkins sandbox, sh semantics are way more convenient.

For reference:



def proc = ['ls', '/meh'].execute()

println proc.getText()
println proc.exitValue() != 0


Where is stderr?

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.