Skip to content

Quote and escape values in generated mysql option file - #672

Merged
AJaccP merged 1 commit into
mainfrom
aditya/mysql-quote-option-file-values
Sep 24, 2026
Merged

AJaccP merged 1 commit into
mainfrom
aditya/mysql-quote-option-file-values

Conversation

@AJaccP

@AJaccP AJaccP commented Sep 24, 2026

Copy link
Copy Markdown
Contributor

Overview

configFileEntry wrote values into the generated my.cnf verbatim, but MySQL's option-file parser treats # as starting a comment anywhere on a line, so a password of #4b became password=#4b and was read back as empty — the client authenticated with no password and the server answered ERROR 1045 (28000): Access denied ... (using password: NO). Backslashes, surrounding whitespace, pre-quoted values and line breaks were corrupted the same way, across all five fields, and every case failed silently.

Values are now quoted with backslashes, double quotation marks and line breaks escaped; since that changes ordinary values too, the expected provisioner output moves to its own fixture (provision.cnf) and mysql.cnf stays unquoted as the file the importer reads.

Type of change

  • Created a new plugin
  • Improved an existing plugin
  • Fixed a bug in an existing plugin
  • Improved contributor utilities or experience

Related Issue(s)

How To Test

Unit tests, including a regression test for the reported bug:

go test ./plugins/mysql/ -v

TestConfigFileEntryRoundTripsThroughMySQL asserts that the value the client reads back out of the generated file equals the value the item holds, across 21 values covering #, backslashes, whitespace, line breaks and pre-quoted values. It checks the round trip rather than the exact file text because MySQL accepts more than one correct encoding.

End to end with the CLI, using the password from the issue:

op plugin init mysql    # store #4b as the password
mysql -e 'SELECT 1'

This failed with Access denied ... (using password: NO) before the change and should now connect. back\slash and a password with a trailing space are worth trying too.

Changelog

The MySQL plugin now quotes and escapes the values it writes to the generated my.cnf, so passwords containing #, backslashes, or surrounding whitespace no longer fail to authenticate.

@AJaccP
AJaccP requested a review from JillRegan September 24, 2026 17:53
@AJaccP
AJaccP merged commit 19eac03 into main Sep 24, 2026
3 checks passed
@AJaccP
AJaccP deleted the aditya/mysql-quote-option-file-values branch September 24, 2026 18:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

mysql plugin will not work with certain string in password

2 participants