Commit af321fc6 authored by idle sign's avatar idle sign

`file:` directive sandboxed.

parent a5dadcf0
...@@ -128,7 +128,10 @@ class ConfigHandler(object): ...@@ -128,7 +128,10 @@ class ConfigHandler(object):
@classmethod @classmethod
def _parse_file(cls, value): def _parse_file(cls, value):
"""Represents value as a string, allowing including text """Represents value as a string, allowing including text
from nearest files using include(). from nearest files using `file:` directive.
Directive is sandboxed and won't reach anything outside
directory with setup.py.
Examples: Examples:
include: LICENSE include: LICENSE
...@@ -144,7 +147,14 @@ class ConfigHandler(object): ...@@ -144,7 +147,14 @@ class ConfigHandler(object):
if not value.startswith(include_directive): if not value.startswith(include_directive):
return value return value
current_directory = os.getcwd()
filepath = value.replace(include_directive, '').strip() filepath = value.replace(include_directive, '').strip()
filepath = os.path.abspath(filepath)
if not filepath.startswith(current_directory):
raise DistutilsOptionError(
'`file:` directive can not access %s' % filepath)
if os.path.isfile(filepath): if os.path.isfile(filepath):
with io.open(filepath, encoding='utf-8') as f: with io.open(filepath, encoding='utf-8') as f:
......
...@@ -86,6 +86,18 @@ class TestMetadata: ...@@ -86,6 +86,18 @@ class TestMetadata:
assert metadata.name == 'fake_name' assert metadata.name == 'fake_name'
assert metadata.keywords == ['one', 'two'] assert metadata.keywords == ['one', 'two']
def test_file_sandboxed(self, tmpdir):
fake_env(
tmpdir,
'[metadata]\n'
'long_description = file: ../../README\n'
)
with get_dist(tmpdir, parse=False) as dist:
with pytest.raises(DistutilsOptionError):
dist.parse_config_files() # file: out of sandbox
def test_aliases(self, tmpdir): def test_aliases(self, tmpdir):
fake_env( fake_env(
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment