Skip to content

Commit

Permalink
Merge pull request #18839 from owncloud/autoloader-supersecure
Browse files Browse the repository at this point in the history
Restrict autoloaded paths to loaded apps (and other enhancements)
  • Loading branch information
MorrisJobke committed Sep 6, 2015
2 parents 24f5f50 + 0fac2e3 commit c57595b
Show file tree
Hide file tree
Showing 5 changed files with 56 additions and 15 deletions.
6 changes: 4 additions & 2 deletions lib/autoloader.php
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,8 @@

namespace OC;

use \OCP\AutoloadNotAllowedException;

class Autoloader {
private $useGlobalClassPath = true;

Expand Down Expand Up @@ -58,7 +60,7 @@ public function __construct(array $validRoots) {
* @param string $root
*/
public function addValidRoot($root) {
$this->validRoots[] = $root;
$this->validRoots[] = stream_resolve_include_path($root);
}

/**
Expand Down Expand Up @@ -129,7 +131,7 @@ protected function isValidPath($fullPath) {
return true;
}
}
throw new \Exception('Path not allowed: '. $fullPath);
throw new AutoloadNotAllowedException($fullPath);
}

/**
Expand Down
4 changes: 0 additions & 4 deletions lib/base.php
Original file line number Diff line number Diff line change
Expand Up @@ -552,10 +552,6 @@ public static function init() {
exit();
}

foreach(OC::$APPSROOTS as $appRoot) {
self::$loader->addValidRoot($appRoot['path']);
}

// setup the basic server
self::$server = new \OC\Server(\OC::$WEBROOT);
\OC::$server->getEventLogger()->log('autoloader', 'Autoloader', $loaderStart, $loaderEnd);
Expand Down
3 changes: 2 additions & 1 deletion lib/private/app.php
Original file line number Diff line number Diff line change
Expand Up @@ -105,7 +105,6 @@ public static function loadApps($types = null) {
ob_start();
foreach ($apps as $app) {
if ((is_null($types) or self::isType($app, $types)) && !in_array($app, self::$loadedApps)) {
self::$loadedApps[] = $app;
self::loadApp($app);
}
}
Expand All @@ -122,6 +121,8 @@ public static function loadApps($types = null) {
* @throws \OC\NeedsUpdateException
*/
public static function loadApp($app, $checkUpgrade = true) {
self::$loadedApps[] = $app;
\OC::$loader->addValidRoot(self::getAppPath($app));
if (is_file(self::getAppPath($app) . '/appinfo/app.php')) {
\OC::$server->getEventLogger()->start('load_app_' . $app, 'Load app: ' . $app);
if ($checkUpgrade and self::shouldUpgrade($app)) {
Expand Down
22 changes: 14 additions & 8 deletions lib/private/backgroundjob/joblist.php
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,7 @@
namespace OC\BackgroundJob;

use OCP\BackgroundJob\IJobList;
use OCP\AutoloadNotAllowedException;

class JobList implements IJobList {
/**
Expand Down Expand Up @@ -185,15 +186,20 @@ private function buildJob($row) {
/**
* @var Job $job
*/
if (!class_exists($class)) {
// job from disabled app or old version of an app, no need to do anything
return null;
try {
if (!class_exists($class)) {
// job from disabled app or old version of an app, no need to do anything
return null;
}
$job = new $class();
$job->setId($row['id']);
$job->setLastRun($row['last_run']);
$job->setArgument(json_decode($row['argument'], true));
return $job;
} catch (AutoloadNotAllowedException $e) {
// job is from a disabled app, ignore
}
$job = new $class();
$job->setId($row['id']);
$job->setLastRun($row['last_run']);
$job->setArgument(json_decode($row['argument'], true));
return $job;
return null;
}

/**
Expand Down
36 changes: 36 additions & 0 deletions lib/public/autoloadnotallowedexception.php
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
<?php
/**
* @author Robin McCorkell <[email protected]>
*
* @copyright Copyright (c) 2015, ownCloud, Inc.
* @license AGPL-3.0
*
* This code is free software: you can redistribute it and/or modify
* it under the terms of the GNU Affero General Public License, version 3,
* as published by the Free Software Foundation.
*
* This program is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
* GNU Affero General Public License for more details.
*
* You should have received a copy of the GNU Affero General Public License, version 3,
* along with this program. If not, see <http://www.gnu.org/licenses/>
*/

namespace OCP;

/**
* Exception for when a not allowed path is attempted to be autoloaded
* @since 8.2.0
*/
class AutoloadNotAllowedException extends \DomainException {
/**
* @param string $path
* @since 8.2.0
*/
public function __construct($path) {
parent::__construct('Autoload path not allowed: '.$path);
}
}

0 comments on commit c57595b

Please sign in to comment.