Commit Graph
5 Commits
Author SHA1 Message Date
Ian Chua 86ff2a9de7 fix: avoid substring denies in audit path keywords (#16243)
## Summary

   Fixes #15944.

   The plugin audit deny-list matched `secret`, `cert`, and
 `conf` as substrings of every path component. This blocked
 valid imports during plugin capability execution, for example
 `numpy/__config__.py`, because `conf` appeared inside the
 module filename.

   This PR changes deny keyword matching to use whole path
 components instead of substring matches. It keeps the
 intended protections for sensitive locations and config
 files, while allowing dependency and stdlib modules whose
 names merely contain those strings.

   ## Changes

   - Match denied path keywords as whole components instead of
 substrings.
   - Keep denying sensitive directory names such as:
     - `secret`
     - `secrets`
     - `cert`
     - `certs`
     - `certificate`
     - `certificates`
     - `conf`
     - `config`
   - Keep denying config files by extension:
     - `.conf`
     - `.ini`
   - Allow legitimate Python module/package paths such as:
     - `numpy/__config__.py`
     - `numpy/_core/_ufunc_config.py`
     - `configparser.py`
     - `sysconfig.py`
     - `logging/config.py`
     - `certifi/cacert.pem`
   - Include the denied target and reason in `PermissionError`
 messages when the audit hook blocks an operation.
   - Remove an unused `<memory>` include from
 `PluginAuditManager.hpp`.

   ## Why

   The previous substring matching caused false positives for
 common dependency and standard-library paths. It also made
 failures hard to diagnose because the Python exception did
 not include the refused path.

   The new behavior is narrower: it blocks sensitive path
 components and config file extensions without treating
 unrelated names like `__config__.py`, `configparser.py`,
 `Conference`, or `Concert` as secrets.

   ## Testing

   - Added/updated unit coverage in
 `tests/slic3rutils/test_plugin_audit.cpp` for:
     - whole-component keyword matches
     - `.conf` / `.ini` blocking
     - case-insensitive matching
     - false-positive paths from #15944

Plugin used for testing:

[orca_audit_numpy_config_repro.py](https://github.com/user-attachments/files/33143848/orca_audit_numpy_config_repro.py)
2026-10-09 15:20:38 +08:00
HanifKoh 84657ff11e Add Missing Includes Across the Remaining Sources and Tests (#16071)
* Ignore Clipper, libpng, mcut and Boost.Polygon Internals in clang-tidy

Each only works through a wrapper or umbrella header: libslic3r/clipper.hpp or clipper_z.hpp configure Clipper before including it, png.h pulls in libpng's config headers, and Boost.Polygon's headers only compile through polygon.hpp or voronoi.hpp.

* Ignore minilzo's Config Headers in clang-tidy

lzoconf.h and lzodefs.h are internal to minilzo.h, which is what the code includes.

* Add Missing Includes Across the Remaining Sources and Tests

Covers src/slic3r/Utils, src/slic3r/plugin, src/slic3r/Config, src/libvgcode, src/dev-utils, src/OrcaSlicer.cpp and tests/, the directories left after src/slic3r/GUI and src/libslic3r. Generated with clang-tidy misc-include-cleaner. libvgcode's own headers are included by relative path as in the rest of that library, and Catch2 and pybind11 with angle brackets as elsewhere in the repo.

* Make the GUI and Test Headers Compile on Their Own

Each now includes, or forward-declares, what it uses instead of relying on what its includers happened to include first. Headers that only compile on one platform, or that nothing built includes, are left alone.

* Keep Windows and nanosvg Setup Ahead of the Added Includes

OrcaSlicer.cpp and several tests set _WIN32_WINNT, WIN32_LEAN_AND_MEAN or NOMINMAX before including Windows.h, and the profile validator defines NANOSVG_IMPLEMENTATION before any libslic3r header. The added includes had landed above those blocks, which broke the Windows build.

* Add the GUI Includes the First Pass Missed

Covers headers that only became editable once they compiled on their own, and wx symbols whose suggested header changed as the clang-tidy ignore list grew after the src/slic3r/GUI pass.

* Keep the Added Test Includes Below the NOMINMAX Guard

test_marchingsquares.cpp and test_texture_displacement.cpp had includes inside #ifndef NOMINMAX, which the tests inherit as defined on Windows from libslic3r, so those were skipped there. .clang-tidy also ignores the MSVC STL and UCRT internals, Boost.Multiprecision's fwd.hpp and CPython's Windows include directory, as in #16068.
2026-10-03 13:45:21 +08:00
Ian Chua f6f68573b6 fix: add resources folder to the allowed roots as readonly 2026-08-14 14:48:57 +08:00
Ian Chua 2169b72c94 fix: update tests 2026-07-28 19:28:58 +08:00
SoftFever 88fb89b5eb Plugin audit (#14821)
* Block plugins from reading or writing app config and cloud credentials

Add a denied-filename registry to the plugin audit sandbox, seeded with OrcaSlicer's config (.conf/.ini) and the cloud refresh-token file. The deny is checked above the loading-mode read exemption and the allowed roots, so a plugin cannot reach these files even though they sit inside data_dir(), which is itself an allowed root. Case-insensitive prefix matching also covers the .bak/.tmp companions that hold the same data, and os.rename/os.remove are hooked alongside open so the files cannot be deleted or clobbered either.
2026-07-18 01:24:44 +08:00