Fix executing command with specifying an absolute path 71/201671/1 tizen_5.0 accepted/tizen/unified/20190319.051317 submit/tizen/20190319.000003 submit/tizen_5.0/20190401.053320
authorwansuyoo <wansu.yoo@samsung.com>
Mon, 18 Mar 2019 23:13:42 +0000 (08:13 +0900)
committerwansuyoo <wansu.yoo@samsung.com>
Mon, 18 Mar 2019 23:22:42 +0000 (08:22 +0900)
It's for fixing svace issue of WGID:410093 COMMAND_INJECTION

Change-Id: Ib2d41bff8ad86e3755847333719d5e8952fc7e40
Signed-off-by: wansuyoo <wansu.yoo@samsung.com>
src/setup_system.c

index 155671b5ec8ba98784a2c96a0d54f3588785f2e6..fdff19e804faf6e9255473655a46aaa61ebb71c6 100644 (file)
 #define GET_DOCKER_VERSION_CMD         "docker version --format '{{.Server.Version}}'"
 #define DEVICE_REBOOT_CMD              "sleep 5 && reboot"
 
-#define DOCKER_NETWORK_REMOVE_CMD                      "docker network rm $(docker network ls -q) && sleep 1"
-#define DOCKER_SERVICES_REMOVE_CMD                     "docker service rm $(docker service ls -q) && sleep 1"
-#define DOCKER_CONTAINERS_REMOVE_CMD           "docker rm -f $(docker ps -a -q) && sleep 1"
-#define DOCKER_IMAGES_REMOVE_CMD                       "docker rmi -f $(docker images -q) && sleep 1"
-#define DOCKER_SYSTEM_PRUNE_CMD                                "docker system prune --all --force --volumes && sleep 1"
+#define DOCKER_NETWORK_REMOVE_CMD                      "/usr/bin/docker network rm $(docker network ls -q) && sleep 1"
+#define DOCKER_SERVICES_REMOVE_CMD                     "/usr/bin/docker service rm $(docker service ls -q) && sleep 1"
+#define DOCKER_CONTAINERS_REMOVE_CMD           "/usr/bin/docker rm -f $(docker ps -a -q) && sleep 1"
+#define DOCKER_IMAGES_REMOVE_CMD                       "/usr/bin/docker rmi -f $(docker images -q) && sleep 1"
+#define DOCKER_SYSTEM_PRUNE_CMD                                "/usr/bin/docker system prune --all --force --volumes && sleep 1"
 
 #define DOCKER_DIRECTORY_PATH                  "/opt/beluga/var/lib/docker/"
 #define USER_CONTAINER_VOLUME_PATH             "/opt/beluga/uc/"