File: //opt/cloudlinux/venv/lib/python3.11/site-packages/clwpos/wp_config.py
# coding=utf-8
# Copyright © Cloud Linux GmbH & Cloud Linux Software, Inc 2010-2021 All Rights Reserved
#
# Licensed under CLOUD LINUX LICENSE AGREEMENT
# http://cloudlinux.com/docs/LICENSE.TXT
"""Module for work with wp_config.php"""
from __future__ import absolute_import, print_function
import io
import os
import stat
from pathlib import Path
from typing import List
WP_CONFIG_SUFFIX = 'wp-config.php'
# A wp-config.php is a small PHP file (a few KiB in practice). Cap the read well
# above any legitimate config so a tenant cannot make root buffer a huge/sparse
# file planted at the path; this read runs as root over tenant-owned input.
MAX_WP_CONFIG_BYTES = 1024 * 1024
def path(abs_wp_path: str) -> Path:
"""
Return path to wp-config.php file.
"""
return Path(abs_wp_path, WP_CONFIG_SUFFIX)
def read(abs_wp_path: str) -> List[str]:
"""
Read wp-config.php located in specified WP path.
The file is tenant-owned, so open it with O_NOFOLLOW (reject a symlinked
final component) and O_NONBLOCK (open() cannot block on a FIFO with no
writer), fstat the opened fd to require a regular file (reject
FIFO/device/socket/dir), and bound the actual read to MAX_WP_CONFIG_BYTES.
The fstat st_size is only a fast-reject of an already-oversized file; it
does not bound the read, because a tenant can grow (append to) the file
after the fstat but before/while the bytes are consumed, so the read itself
must be hard-capped: pull at most MAX_WP_CONFIG_BYTES + 1 bytes and reject
if the file yielded more than the cap (a grown/sparse file), rather than
returning a truncated config that would corrupt the file on write-back.
The bytes are then split into lines exactly as the previous
open(errors='surrogateescape').readlines() did (universal-newline text
decode), so a small regular config returns the identical list of lines.
Because the type check is on the actually-opened fd it also closes the
stat-vs-open TOCTOU window. A symlinked path or a non-regular/oversized file
raises OSError, matching the missing/unreadable semantics of the previous
bare open() so callers' error handling is intact.
"""
fd = os.open(path(abs_wp_path), os.O_RDONLY | os.O_NOFOLLOW | os.O_NONBLOCK)
try:
st = os.fstat(fd)
if not stat.S_ISREG(st.st_mode):
raise OSError(f'wp-config.php at {path(abs_wp_path)} is not a regular file')
if st.st_size > MAX_WP_CONFIG_BYTES:
raise OSError(f'wp-config.php at {path(abs_wp_path)} exceeds {MAX_WP_CONFIG_BYTES} bytes')
# Bound the read itself: st_size above only fast-rejects an
# already-large file, but a tenant can grow the file after the fstat,
# so pull at most MAX + 1 bytes (never buffering more) and reject if the
# file grew past the cap rather than returning a truncated config.
limit = MAX_WP_CONFIG_BYTES + 1
chunks = []
remaining = limit
while remaining > 0:
chunk = os.read(fd, remaining)
if not chunk:
break
chunks.append(chunk)
remaining -= len(chunk)
finally:
os.close(fd)
raw = b''.join(chunks)
if len(raw) > MAX_WP_CONFIG_BYTES:
raise OSError(f'wp-config.php at {path(abs_wp_path)} exceeds {MAX_WP_CONFIG_BYTES} bytes')
# Reproduce the previous open(errors='surrogateescape').readlines() output
# byte-for-byte from the bounded bytes (same universal-newline text decode).
with io.TextIOWrapper(io.BytesIO(raw), errors='surrogateescape') as f:
return f.readlines()