CodeQL raised seven high-severity alerts on this branch. Three were real, and the same secret was behind all of them: the Odoo master password, which db_restore appends to its command line as soon as the database declares one. The command itself was printed raw -- "print(arg)" -- so the password reached stdout, and any terminal capture with it. The probe output was logged raw too, and a refused attempt echoes the command it tried. Wider than that: the runner filtered the command it was about to run, but not what came back. A tool that reprints its own arguments -- "set -x", a traceback, odoo_bin.sh -- put the secret straight back into the terminal AND into the log file the sink writes. Every subprocess line now goes through the same filter as the command. The four remaining alerts sit on expressions already wrapped in redact_secrets(). CodeQL does not cross re.sub, so it cannot see the barrier; the mitigation is real and they are false positives. --- FR --- CodeQL a levé sept alertes de sévérité haute sur cette branche. Trois étaient réelles, et le même secret était derrière : le mot de passe maître d'Odoo, que db_restore ajoute à sa ligne de commande dès que la base en exige un. La commande elle-même était imprimée telle quelle — « print(arg) » — donc le mot de passe atteignait la sortie standard, et toute capture de terminal avec elle. La sortie de la sonde était journalisée brute également, et un essai refusé réaffiche la commande tentée. Plus large : le lanceur filtrait la commande qu'il allait exécuter, mais pas ce qui en revenait. Un outil qui réaffiche ses propres arguments — « set -x », une trace, odoo_bin.sh — remettait le secret dans le terminal ET dans le fichier de journal. Chaque ligne du sous-processus passe désormais par le même filtre que la commande. Les quatre alertes restantes portent sur des expressions déjà entourées de redact_secrets(). CodeQL ne franchit pas re.sub et ne voit donc pas la barrière ; la mitigation est réelle, ce sont des faux positifs. Assisted-by: Claude Opus 5 |
||
|---|---|---|
| .. | ||
| migrate | ||
| compare_backup.py | ||
| compare_database_application.py | ||
| db_drop_all.py | ||
| db_restore.py | ||
| delete_production.sh | ||
| download_remote.py | ||
| download_remote.sh | ||
| fix_mariadb_sql_example_1.py | ||
| get_module_list_from_database.py | ||
| get_repo_from_backup.py | ||
| get_repo_from_module.py | ||
| image_db.py | ||
| list_remote.py | ||
| mariadb_sql_example_1.sql | ||
| migrate_prod_to_test.sh | ||
| README.base.md | ||
| README.fr.md | ||
| README.md | ||
| restore_mariadb_sql_example_1.sh | ||
Database
This section is for code generator database migrator.
This configuration is for development environnement.
You need to install script ./script/install/install_dev_extra_ubuntu.sh.
Restore database
Run script to restore database:
./script/database/restore_mariadb_sql_example_1.sh