[PATCH] scripts/sbom: catch ValueError from malformed shell quoting

kadu04t posted 1 patch 6 days, 9 hours ago
There is a newer version of this series
.../savedcmd_parser/savedcmd_parser.py        |  2 +-
.../tests/cmd_graph/test_savedcmd_parser.py   | 25 +++++++++++++++++++
2 files changed, 26 insertions(+), 1 deletion(-)
[PATCH] scripts/sbom: catch ValueError from malformed shell quoting
Posted by kadu04t 6 days, 9 hours ago
parse_inputs_from_commands() only caught CmdParsingError and IndexError
when dispatching to command parsers, but several parsers call
shlex.split() internally, which raises ValueError on malformed shell
quoting (e.g. an unterminated quote). This exception was not caught,
so a single malformed build command would abort SBOM generation
entirely, even with fail_on_unknown_build_command=False, defeating the
purpose of tolerant mode.

Catch ValueError alongside CmdParsingError and IndexError so such
commands are logged as a warning/error and skipped instead of aborting
the whole run.

Add tests covering a malformed quoting command and a command missing a
required positional argument.

Signed-off-by: kadu04t <otakurack@gmail.com>
---
 .../savedcmd_parser/savedcmd_parser.py        |  2 +-
 .../tests/cmd_graph/test_savedcmd_parser.py   | 25 +++++++++++++++++++
 2 files changed, 26 insertions(+), 1 deletion(-)

diff --git a/scripts/sbom/sbom/cmd_graph/savedcmd_parser/savedcmd_parser.py b/scripts/sbom/sbom/cmd_graph/savedcmd_parser/savedcmd_parser.py
index 6a7ea4787aa1..d2ca842a7849 100644
--- a/scripts/sbom/sbom/cmd_graph/savedcmd_parser/savedcmd_parser.py
+++ b/scripts/sbom/sbom/cmd_graph/savedcmd_parser/savedcmd_parser.py
@@ -57,7 +57,7 @@ def parse_inputs_from_commands(
         try:
             inputs = matched_parser(single_command)
             input_files.extend(inputs)
-        except (CmdParsingError, IndexError) as e:
+        except (CmdParsingError, IndexError, ValueError) as e:
             log_error_or_warning(
                 "Skipped parsing command {single_command} because of command parsing error: {error_message}",
                 single_command=single_command,
diff --git a/scripts/sbom/tests/cmd_graph/test_savedcmd_parser.py b/scripts/sbom/tests/cmd_graph/test_savedcmd_parser.py
index a061a748e1bf..d7776f072e03 100644
--- a/scripts/sbom/tests/cmd_graph/test_savedcmd_parser.py
+++ b/scripts/sbom/tests/cmd_graph/test_savedcmd_parser.py
@@ -19,6 +19,31 @@ class TestSavedCmdParser(unittest.TestCase):
         errors = sbom_logging._error_logger._message_counts # type: ignore
         self.assertEqual(errors, {})
 
+    # Error handling tests
+    def test_malformed_shell_quoting(self):
+        command = 'gcc "unterminated'
+        with patch.object(sbom_logging, "warning") as warning:
+            parsed = parse_inputs_from_commands(command, fail_on_unknown_build_command=False)
+
+        self.assertEqual(parsed, [])
+        warning.assert_called_once_with(
+            "Skipped parsing command {single_command} because of command parsing error: {error_message}",
+            single_command=command,
+            error_message="No closing quotation",
+        )
+
+    def test_missing_positional_argument(self):
+        command = "objcopy"
+        with patch.object(sbom_logging, "warning") as warning:
+            parsed = parse_inputs_from_commands(command, fail_on_unknown_build_command=False)
+
+        self.assertEqual(parsed, [])
+        warning.assert_called_once_with(
+            "Skipped parsing command {single_command} because of command parsing error: {error_message}",
+            single_command=command,
+            error_message="list index out of range",
+        )
+
     # Compound command tests
     def test_dd_cat(self):
         cmd = "(dd if=arch/x86/boot/setup.bin bs=4k conv=sync status=none; cat arch/x86/boot/vmlinux.bin) >arch/x86/boot/bzImage"
-- 
2.54.0.windows.1
Re: [PATCH] scripts/sbom: catch ValueError from malformed shell quoting
Posted by Greg KH 5 days, 22 hours ago
On Sat, Jul 18, 2026 at 03:44:57PM -0300, kadu04t wrote:
> parse_inputs_from_commands() only caught CmdParsingError and IndexError
> when dispatching to command parsers, but several parsers call
> shlex.split() internally, which raises ValueError on malformed shell
> quoting (e.g. an unterminated quote). This exception was not caught,
> so a single malformed build command would abort SBOM generation
> entirely, even with fail_on_unknown_build_command=False, defeating the
> purpose of tolerant mode.

Do we have this today in the build system?

thanks,

greg k-h
Re: [PATCH] scripts/sbom: catch ValueError from malformed shell quoting
Posted by Carlos Sampaio Ribeiro 5 days, 20 hours ago
On Sun, Jul 19, 2026 at 02:24:17AM -0300, Greg KH wrote:
 > Do we have this today in the build system?

Sorry for my previous reply only to you.
I'm still learning the Linux kernel mailing list workflow.

The code path exists in the current implementation because the SBOM
generator parses the .cmd files generated by Kbuild.

However, I have not observed malformed .cmd files produced by a normal
kernel build. My intention with this patch was to make the parser behave
consistently in tolerant mode (fail_on_unknown_build_command=False) when
given malformed or corrupted inputs, rather than to fix an issue known to
occur during standard kernel builds.

Thanks,
Carlos
Re: [PATCH] scripts/sbom: catch ValueError from malformed shell quoting
Posted by Greg KH 5 days, 22 hours ago
On Sat, Jul 18, 2026 at 03:44:57PM -0300, kadu04t wrote:
> parse_inputs_from_commands() only caught CmdParsingError and IndexError
> when dispatching to command parsers, but several parsers call
> shlex.split() internally, which raises ValueError on malformed shell
> quoting (e.g. an unterminated quote). This exception was not caught,
> so a single malformed build command would abort SBOM generation
> entirely, even with fail_on_unknown_build_command=False, defeating the
> purpose of tolerant mode.
> 
> Catch ValueError alongside CmdParsingError and IndexError so such
> commands are logged as a warning/error and skipped instead of aborting
> the whole run.
> 
> Add tests covering a malformed quoting command and a command missing a
> required positional argument.
> 
> Signed-off-by: kadu04t <otakurack@gmail.com>

Hi,

This is the friendly patch-bot of Greg Kroah-Hartman.  You have sent him
a patch that has triggered this response.  He used to manually respond
to these common problems, but in order to save his sanity (he kept
writing the same thing over and over, yet to different people), I was
created.  Hopefully you will not take offence and will fix the problem
in your patch and resubmit it so that it can be accepted into the Linux
kernel tree.

You are receiving this message because of the following common error(s)
as indicated below:

- It looks like you did not use your "real" name for the patch on either
  the Signed-off-by: line, or the From: line (both of which have to
  match).  Please read the kernel file,
  Documentation/process/submitting-patches.rst for how to do this
  correctly.

If you wish to discuss this problem further, or you have questions about
how to resolve this issue, please feel free to respond to this email and
Greg will reply once he has dug out from the pending patches received
from other developers.

thanks,

greg k-h's patch email bot