From e944f9e6f638388bd5c983cfe37bd654ec04b98a Mon Sep 17 00:00:00 2001 From: Dominik Csapak Date: Thu, 21 Dec 2023 13:05:08 +0100 Subject: [PATCH] fix #4811: rule db: test regex validity on save and warn only when it's an invalid regex on execution, because users may have previously had such rules. Otherwise, pmg-smtp-filter will restart every time it encounters such a rule. When testing, 'die' if the regex execution 'warns', so that users cannot enter a semi-invalid or very wrong regex like '^*foo$'. do so for every rule type that uses a regex to match Signed-off-by: Dominik Csapak [S.I.: add short comment in test_regex sub ] Signed-off-by: Stoiko Ivanov --- src/PMG/RuleDB/ArchiveFilter.pm | 6 ++++++ src/PMG/RuleDB/ContentTypeFilter.pm | 7 +++++++ src/PMG/RuleDB/MatchArchiveFilename.pm | 7 +++++++ src/PMG/RuleDB/MatchField.pm | 4 +--- src/PMG/RuleDB/MatchFilename.pm | 12 +++++++++--- src/PMG/RuleDB/WhoRegex.pm | 10 +++++++++- src/PMG/Utils.pm | 12 ++++++++++++ 7 files changed, 51 insertions(+), 7 deletions(-) diff --git a/src/PMG/RuleDB/ArchiveFilter.pm b/src/PMG/RuleDB/ArchiveFilter.pm index 6d91556..3d9890c 100644 --- a/src/PMG/RuleDB/ArchiveFilter.pm +++ b/src/PMG/RuleDB/ArchiveFilter.pm @@ -48,6 +48,12 @@ sub parse_entity { my $res; + # test regex for validity + eval { "" =~ m|$self->{field_value}|; }; + if (my $err = $@) { + warn "invalid regex: $err\n"; + return $res; + } # match subtypes? We currently do exact matches only. if (my $id = $entity->head->mime_attr ('x-proxmox-tmp-aid')) { diff --git a/src/PMG/RuleDB/ContentTypeFilter.pm b/src/PMG/RuleDB/ContentTypeFilter.pm index 76fc1ce..0199311 100644 --- a/src/PMG/RuleDB/ContentTypeFilter.pm +++ b/src/PMG/RuleDB/ContentTypeFilter.pm @@ -60,6 +60,13 @@ sub parse_entity { my $res; + # test regex for validity + eval { "" =~ m|$self->{field_value}|; }; + if (my $err = $@) { + warn "invalid regex: $err\n"; + return $res; + } + # match subtypes? We currently do exact matches only. if (my $id = $entity->head->mime_attr ('x-proxmox-tmp-aid')) { diff --git a/src/PMG/RuleDB/MatchArchiveFilename.pm b/src/PMG/RuleDB/MatchArchiveFilename.pm index 2ef3543..5b1cb6d 100644 --- a/src/PMG/RuleDB/MatchArchiveFilename.pm +++ b/src/PMG/RuleDB/MatchArchiveFilename.pm @@ -25,6 +25,13 @@ sub parse_entity { my $res; + # test regex for validity + eval { "" =~ m|^$self->{fname}$|i; }; + if (my $err = $@) { + warn "invalid regex: $err\n"; + return $res; + } + if (my $id = $entity->head->mime_attr('x-proxmox-tmp-aid')) { chomp $id; diff --git a/src/PMG/RuleDB/MatchField.pm b/src/PMG/RuleDB/MatchField.pm index 177a283..ee1851a 100644 --- a/src/PMG/RuleDB/MatchField.pm +++ b/src/PMG/RuleDB/MatchField.pm @@ -71,9 +71,7 @@ sub save { my $regex = $self->{field_value}; - # test regex for validity - eval { "" =~ /$regex/i; }; - die "invalid regex: $@\n" if $@; + PMG::Utils::test_regex($regex); my $new_value = "$self->{field}:$regex"; $new_value =~ s/\\/\\\\/g; diff --git a/src/PMG/RuleDB/MatchFilename.pm b/src/PMG/RuleDB/MatchFilename.pm index c9cdbe0..90f8654 100644 --- a/src/PMG/RuleDB/MatchFilename.pm +++ b/src/PMG/RuleDB/MatchFilename.pm @@ -58,6 +58,9 @@ sub save { defined($self->{ogroup}) || die "undefined ogroup: ERROR"; my $new_value = $self->{fname}; + + PMG::Utils::test_regex("^${new_value}\$"); + $new_value =~ s/\\/\\\\/g; $new_value = encode('UTF-8', $new_value); @@ -91,9 +94,12 @@ sub parse_entity { chomp $id; if (my $value = PMG::Utils::extract_filename($entity->head)) { - if ($value =~ m|^$self->{fname}$|i) { - push @$res, $id; - } + eval { + if ($value =~ m|^$self->{fname}$|i) { + push @$res, $id; + } + }; + warn "invalid regex: $@\n" if $@; } } diff --git a/src/PMG/RuleDB/WhoRegex.pm b/src/PMG/RuleDB/WhoRegex.pm index 5c13604..03405bc 100644 --- a/src/PMG/RuleDB/WhoRegex.pm +++ b/src/PMG/RuleDB/WhoRegex.pm @@ -60,6 +60,9 @@ sub save { defined($self->{address}) || die "undefined address: ERROR"; my $adr = $self->{address}; + + PMG::Utils::test_regex("^${adr}\$"); + $adr =~ s/\\/\\\\/g; $adr = encode('UTF-8', $adr); @@ -100,7 +103,12 @@ sub who_match { my $t = $self->address; - return $addr =~ m/^$t$/i; + my $res; + eval { + $res = $addr =~ m/^$t$/i; + }; + warn "invalid regex: $@\n" if $@; + return $res; } sub address { diff --git a/src/PMG/Utils.pm b/src/PMG/Utils.pm index 342c48d..12b3ed5 100644 --- a/src/PMG/Utils.pm +++ b/src/PMG/Utils.pm @@ -1579,4 +1579,16 @@ sub try_decode_utf8 { return eval { decode('UTF-8', $data, 1) } // $data; } +sub test_regex { + my ($regex) = @_; + + # some errors in regex only create warnings e.g. m/^*foo/ others actually cause a + # die e.g. m/*foo/ - treat a warn die here + local $SIG{__WARN__} = sub { die @_ }; + eval { "" =~ m/$regex/i; }; + die "invalid regex: $@\n" if $@; + + return undef; +} + 1; -- 2.39.2