printSchema runs kubectl get --raw /openapi/v2 and unmarshals stdout.
The json.Unmarshal error is discarded, not even assigned to _:
var jsonSchema map[string]interface{}
output := stdout.Bytes()
json.Unmarshal(output, &jsonSchema)
output, _ = json.MarshalIndent(jsonSchema, "", " ")
When kubectl succeeds but the response is not JSON, for example an auth
portal or corporate proxy returning HTML, jsonSchema is left nil,
MarshalIndent renders it as null, and the command prints that and exits
0:
$ kustomize openapi fetch
null
$ echo $?
0
The function already guards the two neighbouring failures, kubectl
exiting non-zero and empty stdout, and both reuse the errMsg advice.
Only "kubectl succeeded but returned something that is not a schema"
was unguarded, so a scripted fetch writes null to a file and nothing
notices.
After the fix the same input reports the parse error alongside the
existing advice and exits 1. A valid schema still round-trips unchanged
in both --format=json and --format=yaml.
Signed-off-by: Pragalva Sapkota <sapkotapragalva@gmail.com>
Add tests that place a stub kubectl on PATH and verify that invalid
JSON from a successful kubectl fails without writing null, that valid
JSON is printed indented, and that --format=yaml still succeeds.
The invalid JSON case fails until the parse error is reported.
Signed-off-by: Pragalva Sapkota <sapkotapragalva@gmail.com>
WrapErrorWithFile reads the path and index annotations into local
variables, then passes those values back through meta.Annotations as if
they were keys. The second lookup almost always misses, so every error
returned by inpututil.MapInputs and MapInputsE is prefixed with " []: "
instead of naming the file and document that failed.
The legacy fallback for the index also read LegacyPathAnnotation rather
than LegacyIndexAnnotation, so resources carrying only the legacy
annotations resolved the index to the file path.
Use the values that were already resolved, and read the index from
LegacyIndexAnnotation. This matches kioutil.GetFileAnnotations, which
resolves the same pair of annotations correctly.
Adds a test for the internal and legacy annotation forms; the package
previously had none.
Signed-off-by: Pragalva Sapkota <sapkotapragalva@gmail.com>
Motivation:
HelmChart.AsHelmArgs() appends ReleaseName as the first bare
positional argument to `helm template`, and pullCommand() appends
Name as a bare positional argument to `helm pull` (when a repo is
set and the chart isn't already cached locally). Neither value is
preceded by a `--` delimiter before being handed to exec.Command.
Helm's own flag parser does not distinguish a bare positional
argument from a flag: if a kustomization.yaml sets, for example,
releaseName: --post-renderer=./evil.sh, helm interprets that as a
--post-renderer flag rather than a release name, and executes the
attacker-supplied script during `kustomize build --enable-helm`
(or `kubectl kustomize --enable-helm`). This is a real,
demonstrated flag-injection path reachable from an untrusted
kustomization.yaml plus --enable-helm; it is not a claim about
every possible helm argument, only the two fields that are passed
as bare positionals. Other HelmChart fields (Namespace, ValuesFile,
KubeVersion, etc.) are passed as `--flag value` pairs, where helm's
pflag-based parser consumes the very next token as the flag's value
regardless of its content, so they are not exploitable the same way
and are out of scope for this change.
Approach:
Reject a releaseName or name that starts with '-' in validateArgs(),
which runs during Config() before any helm subprocess is spawned.
The check is added to the plugin source
(plugin/builtin/helmchartinflationgenerator/HelmChartInflationGenerator.go)
and mirrored into the generated copy
(api/internal/builtins/HelmChartInflationGenerator.go) via
`go generate .` (pluginator), matching how this plugin is normally
maintained. A small test harness helper,
ErrorFromLoadAndRunGenerator, was added to
api/testutils/kusttest/harnessenhanced.go, modeled on the existing
ErrorFromLoadAndRunTransformer helper, so the new tests can assert
on the Config()-time validation error without needing an actual
helm binary installed.
Validation:
- `cd api && go build ./... && go vet ./...` pass.
- `cd plugin/builtin/helmchartinflationgenerator && go vet ./...`
passes. (`go build ./...` in that directory fails with "function
main is undeclared" both before and after this change; it's a
//go:generate pluginator source file compiled specially, not a
standalone main package, so plain `go build` there is not
meaningful.)
- Added TestHelmChartInflationGeneratorRejectsFlagLikeReleaseName
and TestHelmChartInflationGeneratorRejectsFlagLikeChartName in
plugin/builtin/helmchartinflationgenerator/HelmChartInflationGenerator_test.go.
Verified both fail-then-pass: with each new HasPrefix check
temporarily removed, `go test ./... -run
TestHelmChartInflationGeneratorRejectsFlagLike... -v` fails with
an "unable to run: helmV3 ... executable file not found" error,
proving execution reaches the real helm subprocess call with the
injected flag; restoring the check makes the same test pass with
the expected "must not start with '-'" error, confirming
validation now happens before any subprocess is spawned.
- `go test ./types/... ./testutils/... ./internal/builtins/...` in
api/ pass. `go test ./krusty/...` has one unrelated pre-existing
failure, TestAddManagedbyLabel, which fails identically on
unmodified master: it expects a version string baked in via
-ldflags during `make test` that plain `go test` does not set.
- golangci-lint v1.64.8 (the version pinned in hack/go.mod, matching
what CI's `make lint` installs) run against the changed packages
is clean.
Report: https://github.com/kubernetes-sigs/kustomize/issues/6241
Signed-off-by: Pujitha Paladugu <10557236+pujitha24@users.noreply.github.com>
Assisted-by: claude-sonnet-5 (via Claude Code)
The default images field spec covers spec/volumes[]/image/reference
under Pod and PodTemplateSpec, but CronJob's Image Volume under
spec/jobTemplate/spec/template/spec was missing from the list. This
adds the missing path.