mirror of
https://github.com/OrcaSlicer/OrcaSlicer.git
synced 2026-10-10 01:01:57 +00:00
fix: avoid substring denies in audit path keywords (#16243)
## Summary Fixes #15944. The plugin audit deny-list matched `secret`, `cert`, and `conf` as substrings of every path component. This blocked valid imports during plugin capability execution, for example `numpy/__config__.py`, because `conf` appeared inside the module filename. This PR changes deny keyword matching to use whole path components instead of substring matches. It keeps the intended protections for sensitive locations and config files, while allowing dependency and stdlib modules whose names merely contain those strings. ## Changes - Match denied path keywords as whole components instead of substrings. - Keep denying sensitive directory names such as: - `secret` - `secrets` - `cert` - `certs` - `certificate` - `certificates` - `conf` - `config` - Keep denying config files by extension: - `.conf` - `.ini` - Allow legitimate Python module/package paths such as: - `numpy/__config__.py` - `numpy/_core/_ufunc_config.py` - `configparser.py` - `sysconfig.py` - `logging/config.py` - `certifi/cacert.pem` - Include the denied target and reason in `PermissionError` messages when the audit hook blocks an operation. - Remove an unused `<memory>` include from `PluginAuditManager.hpp`. ## Why The previous substring matching caused false positives for common dependency and standard-library paths. It also made failures hard to diagnose because the Python exception did not include the refused path. The new behavior is narrower: it blocks sensitive path components and config file extensions without treating unrelated names like `__config__.py`, `configparser.py`, `Conference`, or `Concert` as secrets. ## Testing - Added/updated unit coverage in `tests/slic3rutils/test_plugin_audit.cpp` for: - whole-component keyword matches - `.conf` / `.ini` blocking - case-insensitive matching - false-positive paths from #15944 Plugin used for testing: [orca_audit_numpy_config_repro.py](https://github.com/user-attachments/files/33143848/orca_audit_numpy_config_repro.py)
This commit is contained in:
@@ -222,18 +222,19 @@ TEST_CASE("Plugin audit denies secret/certificate/config-like paths by keyword",
|
||||
CHECK(mgr.is_denied_path_keyword(fs::path("/resources/certificates/ca.pem")));
|
||||
}
|
||||
|
||||
SECTION("a 'conf'/'config' directory or file component is denied")
|
||||
SECTION("a 'conf'/'config' directory or config file component is denied")
|
||||
{
|
||||
CHECK(mgr.is_denied_path_keyword(fs::path("/plugin/conf/settings.json")));
|
||||
CHECK(mgr.is_denied_path_keyword(fs::path("/plugin/config/settings.json")));
|
||||
CHECK(mgr.is_denied_path_keyword(fs::path("/plugin/plugin.conf")));
|
||||
CHECK(mgr.is_denied_path_keyword(fs::path("/plugin/plugin.ini")));
|
||||
}
|
||||
|
||||
SECTION("matching is case-insensitive")
|
||||
{
|
||||
CHECK(mgr.is_denied_path_keyword(fs::path("/plugin/SECRETS/token.txt")));
|
||||
CHECK(mgr.is_denied_path_keyword(fs::path("/resources/CertBundle/ca.pem")));
|
||||
CHECK(mgr.is_denied_path_keyword(fs::path("/plugin/CONFIG.JSON")));
|
||||
CHECK(mgr.is_denied_path_keyword(fs::path("/resources/Certificates/ca.pem")));
|
||||
CHECK(mgr.is_denied_path_keyword(fs::path("/plugin/PLUGIN.CONF")));
|
||||
}
|
||||
|
||||
SECTION("matching is not limited to the base name -- any ancestor component counts")
|
||||
@@ -245,6 +246,14 @@ TEST_CASE("Plugin audit denies secret/certificate/config-like paths by keyword",
|
||||
{
|
||||
CHECK_FALSE(mgr.is_denied_path_keyword(fs::path("/plugin/output/model.gcode")));
|
||||
CHECK_FALSE(mgr.is_denied_path_keyword(fs::path("/plugin/storage/state.json")));
|
||||
CHECK_FALSE(mgr.is_denied_path_keyword(fs::path("/python/packages/cp312/numpy/__config__.py")));
|
||||
CHECK_FALSE(mgr.is_denied_path_keyword(fs::path("/python/packages/cp312/numpy/_core/_ufunc_config.py")));
|
||||
CHECK_FALSE(mgr.is_denied_path_keyword(fs::path("/python/Lib/configparser.py")));
|
||||
CHECK_FALSE(mgr.is_denied_path_keyword(fs::path("/python/Lib/sysconfig.py")));
|
||||
CHECK_FALSE(mgr.is_denied_path_keyword(fs::path("/python/Lib/logging/config.py")));
|
||||
CHECK_FALSE(mgr.is_denied_path_keyword(fs::path("/python/packages/cp312/certifi/cacert.pem")));
|
||||
CHECK_FALSE(mgr.is_denied_path_keyword(fs::path("/users/Conference/output.txt")));
|
||||
CHECK_FALSE(mgr.is_denied_path_keyword(fs::path("/users/Concert/output.txt")));
|
||||
}
|
||||
|
||||
SECTION("an empty path is not denied")
|
||||
|
||||
Reference in New Issue
Block a user