mirror of
https://github.com/AikidoSec/safe-chain.git
synced 2026-05-26 12:10:49 +00:00
Merge pull request #236 from uriel-ecosia/uc-python-spawn
Fix `safe-chain python` exiting quietly
This commit is contained in:
commit
5bab03991b
3 changed files with 39 additions and 14 deletions
|
|
@ -23,6 +23,7 @@ export async function main(args) {
|
||||||
process.on("uncaughtException", (error) => {
|
process.on("uncaughtException", (error) => {
|
||||||
ui.writeError(`Safe-chain: Uncaught exception: ${error.message}`);
|
ui.writeError(`Safe-chain: Uncaught exception: ${error.message}`);
|
||||||
ui.writeVerbose(`Stack trace: ${error.stack}`);
|
ui.writeVerbose(`Stack trace: ${error.stack}`);
|
||||||
|
ui.writeBufferedLogsAndStopBuffering();
|
||||||
process.exit(1);
|
process.exit(1);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|
@ -31,6 +32,7 @@ export async function main(args) {
|
||||||
if (reason instanceof Error) {
|
if (reason instanceof Error) {
|
||||||
ui.writeVerbose(`Stack trace: ${reason.stack}`);
|
ui.writeVerbose(`Stack trace: ${reason.stack}`);
|
||||||
}
|
}
|
||||||
|
ui.writeBufferedLogsAndStopBuffering();
|
||||||
process.exit(1);
|
process.exit(1);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|
@ -89,6 +91,7 @@ export async function main(args) {
|
||||||
return packageManagerResult.status;
|
return packageManagerResult.status;
|
||||||
} catch (/** @type any */ error) {
|
} catch (/** @type any */ error) {
|
||||||
ui.writeError("Failed to check for malicious packages:", error.message);
|
ui.writeError("Failed to check for malicious packages:", error.message);
|
||||||
|
ui.writeBufferedLogsAndStopBuffering();
|
||||||
|
|
||||||
// Returning the exit code back to the caller allows the promise
|
// Returning the exit code back to the caller allows the promise
|
||||||
// to be awaited in the bin files and return the correct exit code
|
// to be awaited in the bin files and return the correct exit code
|
||||||
|
|
|
||||||
|
|
@ -8,6 +8,7 @@ import fsSync from "node:fs";
|
||||||
import os from "node:os";
|
import os from "node:os";
|
||||||
import path from "node:path";
|
import path from "node:path";
|
||||||
import ini from "ini";
|
import ini from "ini";
|
||||||
|
import { spawn } from "child_process";
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Checks if this pip invocation should bypass safe-chain and spawn directly.
|
* Checks if this pip invocation should bypass safe-chain and spawn directly.
|
||||||
|
|
@ -16,7 +17,7 @@ import ini from "ini";
|
||||||
* @param {string[]} args - The arguments
|
* @param {string[]} args - The arguments
|
||||||
* @returns {boolean}
|
* @returns {boolean}
|
||||||
*/
|
*/
|
||||||
function shouldBypassSafeChain(command, args) {
|
export function shouldBypassSafeChain(command, args) {
|
||||||
if (command === PYTHON_COMMAND || command === PYTHON3_COMMAND) {
|
if (command === PYTHON_COMMAND || command === PYTHON3_COMMAND) {
|
||||||
// Check if args start with -m pip
|
// Check if args start with -m pip
|
||||||
if (args.length >= 2 && args[0] === "-m" && (args[1] === PIP_COMMAND || args[1] === PIP3_COMMAND)) {
|
if (args.length >= 2 && args[0] === "-m" && (args[1] === PIP_COMMAND || args[1] === PIP3_COMMAND)) {
|
||||||
|
|
@ -77,14 +78,16 @@ export async function runPip(command, args) {
|
||||||
if (shouldBypassSafeChain(command, args)) {
|
if (shouldBypassSafeChain(command, args)) {
|
||||||
ui.writeVerbose(`Safe-chain: Bypassing safe-chain for non-pip invocation: ${command} ${args.join(" ")}`);
|
ui.writeVerbose(`Safe-chain: Bypassing safe-chain for non-pip invocation: ${command} ${args.join(" ")}`);
|
||||||
// Spawn the ORIGINAL command with ORIGINAL args
|
// Spawn the ORIGINAL command with ORIGINAL args
|
||||||
const { spawn } = await import("child_process");
|
|
||||||
return new Promise((_resolve) => {
|
return new Promise((_resolve) => {
|
||||||
const proc = spawn(command, args, { stdio: "inherit" });
|
const proc = spawn(command, args, { stdio: "inherit" });
|
||||||
proc.on("exit", (/** @type {number | null} */ code) => {
|
proc.on("exit", (/** @type {number | null} */ code) => {
|
||||||
|
ui.writeVerbose(`${command} ${args.join(" ")} exited with status ${code}`);
|
||||||
|
ui.writeBufferedLogsAndStopBuffering();
|
||||||
process.exit(code ?? 0);
|
process.exit(code ?? 0);
|
||||||
});
|
});
|
||||||
proc.on("error", (/** @type {Error} */ err) => {
|
proc.on("error", (/** @type {Error} */ err) => {
|
||||||
ui.writeError(`Error executing command: ${err.message}`);
|
ui.writeError(`Error executing command: ${err.message}`);
|
||||||
|
ui.writeBufferedLogsAndStopBuffering();
|
||||||
process.exit(1);
|
process.exit(1);
|
||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
|
||||||
|
|
@ -7,6 +7,7 @@ import ini from "ini";
|
||||||
|
|
||||||
describe("runPipCommand environment variable handling", () => {
|
describe("runPipCommand environment variable handling", () => {
|
||||||
let runPip;
|
let runPip;
|
||||||
|
let shouldBypassSafeChain;
|
||||||
let capturedArgs = null;
|
let capturedArgs = null;
|
||||||
let customEnv = null;
|
let customEnv = null;
|
||||||
let capturedConfigContent = null; // Capture config file content before cleanup
|
let capturedConfigContent = null; // Capture config file content before cleanup
|
||||||
|
|
@ -56,6 +57,7 @@ describe("runPipCommand environment variable handling", () => {
|
||||||
|
|
||||||
const mod = await import("./runPipCommand.js");
|
const mod = await import("./runPipCommand.js");
|
||||||
runPip = mod.runPip;
|
runPip = mod.runPip;
|
||||||
|
shouldBypassSafeChain = mod.shouldBypassSafeChain;
|
||||||
});
|
});
|
||||||
|
|
||||||
afterEach(() => {
|
afterEach(() => {
|
||||||
|
|
@ -397,4 +399,21 @@ describe("runPipCommand environment variable handling", () => {
|
||||||
assert.ok(output.includes("proxy found in PIP_CONFIG_FILE"), "Should warn about proxy overwrite in output");
|
assert.ok(output.includes("proxy found in PIP_CONFIG_FILE"), "Should warn about proxy overwrite in output");
|
||||||
customEnv = null;
|
customEnv = null;
|
||||||
});
|
});
|
||||||
|
|
||||||
|
it("should bypass safe-chain for python correctly", async () => {
|
||||||
|
assert.strictEqual(shouldBypassSafeChain("python", []), true);
|
||||||
|
assert.strictEqual(shouldBypassSafeChain("python3", []), true);
|
||||||
|
|
||||||
|
assert.strictEqual(shouldBypassSafeChain("python", ["--version"]), true);
|
||||||
|
assert.strictEqual(shouldBypassSafeChain("python3", ["--version"]), true);
|
||||||
|
|
||||||
|
assert.strictEqual(shouldBypassSafeChain("python", ["-m", "http.server"]), true);
|
||||||
|
assert.strictEqual(shouldBypassSafeChain("python3", ["-m", "http.server"]), true);
|
||||||
|
|
||||||
|
assert.strictEqual(shouldBypassSafeChain("python", ["-m", "pip"]), false);
|
||||||
|
assert.strictEqual(shouldBypassSafeChain("python3", ["-m", "pip"]), false);
|
||||||
|
assert.strictEqual(shouldBypassSafeChain("python", ["-m", "pip3"]), false);
|
||||||
|
assert.strictEqual(shouldBypassSafeChain("python3", ["-m", "pip3"]), false);
|
||||||
|
});
|
||||||
|
|
||||||
});
|
});
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue