erplibre/script/database
Mathieu Benoit 6cdbd528f3 [FIX] security: keep the master password out of the command line
Redacting what we print treats the symptom. The password was still an
argument, and /proc/<pid>/cmdline is readable by EVERY user on the
machine for as long as the command runs -- an exposure no filter reaches.

It now travels in MASTER_PWD. The probe sets it on the child it spawns;
once accepted it is placed in this process's environment, so every later
call inherits it without argv ever carrying it. /proc/<pid>/environ is
readable only by its owner.

Worth knowing for anyone reading the old code: the option was appended to
every invocation, but odoo's db command reads it in the drop branch
alone. list, restore and clone were carrying a secret they never used.

The redaction stays. It is the last line, not the first, and other
options still put secrets on command lines.

--- FR ---

Caviarder ce qu'on affiche traite le symptôme. Le mot de passe restait un
argument, et /proc/<pid>/cmdline est lisible par TOUT utilisateur de la
machine tant que la commande tourne — une exposition qu'aucun filtre
n'atteint.

Il voyage désormais dans MASTER_PWD. La sonde le pose sur l'enfant
qu'elle lance ; une fois accepté, il est placé dans l'environnement de ce
processus, si bien que tous les appels suivants en héritent sans qu'argv
le porte jamais. /proc/<pid>/environ n'est lisible que par son
propriétaire.

À savoir pour qui relit l'ancien code : l'option était ajoutée à chaque
invocation, alors que la commande db d'odoo ne la lit que dans la branche
drop. list, restore et clone portaient un secret dont ils ne faisaient
rien.

Le caviardage reste. Il est le dernier rempart, pas le premier, et
d'autres options mettent encore des secrets sur des lignes de commande.

Assisted-by: Claude Opus 5
2026-08-23 02:11:50 -04:00
..
migrate [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
compare_backup.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
compare_database_application.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
db_drop_all.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
db_restore.py [FIX] security: keep the master password out of the command line 2026-08-23 02:11:50 -04:00
delete_production.sh [UPD] script: move script git, manifest, database, poetry, install 2023-01-02 21:54:20 -05:00
download_remote.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
download_remote.sh [IMP] todo support odoo upgrade 2025-10-31 01:43:26 -04:00
fix_mariadb_sql_example_1.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
get_module_list_from_database.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
get_repo_from_backup.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
get_repo_from_module.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
image_db.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
list_remote.py [UPD] script Format 2026-03-14 23:26:31 -04:00
mariadb_sql_example_1.sql [UPD] makefile: improve test 2022-01-24 14:09:17 -05:00
migrate_prod_to_test.sh [IMP] refactoring to support multiple version of Odoo 2025-10-31 01:32:11 -04:00
README.base.md [ADD] Multilingual translation of all documentation (EN/FR) 2026-03-04 22:23:52 -05:00
README.fr.md [ADD] Multilingual translation of all documentation (EN/FR) 2026-03-04 22:23:52 -05:00
README.md [ADD] Multilingual translation of all documentation (EN/FR) 2026-03-04 22:23:52 -05:00
restore_mariadb_sql_example_1.sh [IMP] refactoring .venv.erplibre 2025-10-31 01:34:26 -04:00

Database

This section is for code generator database migrator.

This configuration is for development environnement.

You need to install script ./script/install/install_dev_extra_ubuntu.sh.

Restore database

Run script to restore database:

./script/database/restore_mariadb_sql_example_1.sh