Skip to content

toolbox.sh contains problematic use of eval #1842

Description

@wileyhy

Describe the bug
The following code block can be found in /etc/profile.d/toolbox.sh:

eval $(
          if [ -f /etc/os-release ]; then
              . /etc/os-release
          else
              . /usr/lib/os-release
          fi

          echo ID="$ID"
          echo PRETTY_NAME="\"$PRETTY_NAME\""
          echo VARIANT_ID="$VARIANT_ID"
      )

I wanted to know which files were being sourced when my terminal sessions start up, so I added the following code to the top of my ~/.bashrc:

# Be loud about which files are sourced.
function . ()
{
  local gG
  for gG in "$@"
  do  
    printf '\n\n%s\n\n\n' "<<  +  >>  ~/${BASH_SOURCE[0]##*/}: sourcing ${gG}"
    builtin . "${gG}"
  done
}
function source ()
{
  local hH
  for hH in "$@"
  do  
    printf '\n\n%s\n\n\n' "<<  +  >>  ~/${BASH_SOURCE[0]##*/}: sourcing ${hH}"
    builtin source "${hH}"
  done
}

The technique is called "command shadowing." The purpose here is diagnostic. It seemed like an efficient option. That addition produced something probably unintended:

+++ toolbox_welcome_stub=/home/liveuser/.config/toolbox/toolbox-welcome-shown
++++ '[' -f /etc/os-release ']'
++++ . /etc/os-release
++++ local gG
++++ for gG in "$@"
++++ printf '\n\n%s\n\n\n' '<<  +  >>  ~/.bashrc: sourcing /etc/os-release'
++++ builtin . /etc/os-release
+++++ NAME='Fedora Linux'
+++++ VERSION='44 (Workstation Edition)'
+++++ RELEASE_TYPE=stable
+++++ ID=fedora
+++++ VERSION_ID=44
+++++ VERSION_CODENAME=
+++++ PRETTY_NAME='Fedora Linux 44 (Workstation Edition)'
+++++ ANSI_COLOR='0;38;2;60;110;180'
+++++ LOGO=fedora-logo-icon
+++++ CPE_NAME=cpe:/o:fedoraproject:fedora:44
+++++ DEFAULT_HOSTNAME=fedora
+++++ HOME_URL=https://fedoraproject.org/
+++++ DOCUMENTATION_URL=https://docs.fedoraproject.org/en-US/fedora/f44/
+++++ SUPPORT_URL=https://ask.fedoraproject.org/
+++++ BUG_REPORT_URL=https://bugzilla.redhat.com/
+++++ REDHAT_BUGZILLA_PRODUCT=Fedora
+++++ REDHAT_BUGZILLA_PRODUCT_VERSION=44
+++++ REDHAT_SUPPORT_PRODUCT=Fedora
+++++ REDHAT_SUPPORT_PRODUCT_VERSION=44
+++++ SUPPORT_END=2027-05-19
+++++ VARIANT='Workstation Edition'
+++++ VARIANT_ID=workstation
++++ echo ID=fedora
++++ echo 'PRETTY_NAME="Fedora Linux 44 (Workstation Edition)"'
++++ echo VARIANT_ID=workstation
+++ eval '<<' + '>>' '~/.bashrc:' sourcing /etc/os-release ID=fedora 'PRETTY_NAME="Fedora' Linux 44 '(Workstation' 'Edition)"' VARIANT_ID=workstation
bash: warning: here-document at line 13 delimited by end-of-file (wanted `+')
++++ sourcing /etc/os-release ID=fedora 'PRETTY_NAME=Fedora Linux 44 (Workstation Edition)' VARIANT_ID=workstation
bash: sourcing: command not found
+++ '[' -f /run/ostree-booted ']'
+++ '[' -f /run/.containerenv ']'
+++ unset ID

Expected behaviour
I expected for the output of my commands not to accidentally be reused as input.

Actual behaviour
The code as published was used in a way that the original author did not anticipate.

Screenshots
NA

Output of toolbox --version (v0.0.90+)
0.3

Toolbx package info (rpm -q toolbox)
toolbox-0.3-4.fc44.x86_64

Output of podman version
Client: Podman Engine
Version: 5.8.4
API Version: 5.8.4
Go Version: go1.26.4-X:nodwarf5
Git Commit: 5431df23c742e5edea35bef34eed696f4db0106b
Built: Thu Jun 25 17:00:00 2026
Build Origin: Fedora Project
OS/Arch: linux/amd64```

Podman package info (rpm -q podman)
podman-5.8.4-1.fc44.x86_64

Info about your OS
Fedora 44 Workstation

Additional context
In Bash, and in shell historically, I believe, function names can be nearly anything: name collisions are expected.

[liveuser@canis-major ~]$ type -a rm
rm is aliased to 'rm -i'
rm is a function
rm () 
{ 
    command -p rm --preserve-root=all --one-file-system "$@"
}
rm is /usr/bin/rm
[liveuser@canis-major ~]$ touch foo
[liveuser@canis-major ~]$ ls -l foo
-rw-r--r--. 1 liveuser liveuser 0 Sep  9 22:52 foo
[liveuser@canis-major ~]$ set -x; rm foo; set +x
+ rm -i foo
+ command -p rm --preserve-root=all --one-file-system -i foo
rm: remove regular empty file 'foo'? y
+ set +x

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    1. BugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions