fix(tunnel): stop quoting WorkingDirectory in generated systemd unit

systemd (verified on Ubuntu 20.04 / systemd 245 with systemd-analyze
verify) treats the quoted value as part of the path and rejects the
unit with: WorkingDirectory= path is not absolute: "/etc/aether-tunnel".
This made aether-tunnel setup fail after a seemingly successful
one-line install, so remote proxy nodes never came online.

WorkingDirectory= takes the rest of the line as the path, so spaces in
the working directory stay intact unquoted; newline/specifier injection
is already rejected by validate_service_unit_path. ExecStart= and
Environment= keep their existing quoting.

Updates #817 (proxy node section; reproduced there with the full
systemd-analyze verify output).
This commit is contained in:
李昊桐
2026-10-04 23:25:56 +08:00
parent 54fbcc25a1
commit 12d58327a1
+8 -2
View File
@@ -340,7 +340,12 @@ fn render_systemd_unit(
validate_service_unit_path(working_dir, "working directory")?;
let exe_path = systemd_quote(exe_path);
let working_dir = systemd_quote(working_dir);
// systemd treats a quoted WorkingDirectory value as part of the path
// (systemd-analyze reports `path is not absolute: "/etc/aether-tunnel"`),
// so this directive must stay unquoted. The directive takes the rest of
// the line as the path, so values with spaces stay intact, and
// validate_service_unit_path rejects newline/specifier injection.
let working_dir = working_dir.to_string();
let config_env = systemd_quote(&format!("AETHER_TUNNEL_CONFIG={config_path}"));
Ok(format!(
"[Unit]\n\
@@ -980,7 +985,8 @@ mod tests {
assert!(unit.contains(
r#"Environment="AETHER_TUNNEL_CONFIG=/var/lib/aether tunnel/config\\\\node.toml""#
));
assert!(unit.contains(r#"WorkingDirectory="/var/lib/aether tunnel""#));
assert!(unit.contains("WorkingDirectory=/var/lib/aether tunnel\n"));
assert!(!unit.contains("WorkingDirectory=\""));
assert_eq!(systemd_quote("a\\b\"c"), r#""a\\b\"c""#);
}