\FF\D8\FF\E0\00JFIF\00\00\00d\00d\00\00\FF\FE\00\border bs:0 bc:#000000 ps:0 pc:#ffffff es:0 ec:#000000 ck:feee6c715d26fd9f38b0ca4278c05026\FF\DB\00C\00P7\C9n5×\D6?\BDê\9Ds\EBp\9F[`8m\B7)o\B5\E8\E6I\99\FE3]]A2\BA\8Cw\D6E\93\\DEv\C8\009\F2\F1NI?uc\\F5\EA\96k\xN<~buv\EA\C8\D7 \8B\84\CEcxI\BBg\AE\9E=\D6+n\EC\80\C8A\8C\AE\EB\CF\D5\DA\E9"2\A4\B9j5\EB\F3W\B63\96\B30Yu\DA\FC8\ED\DF\E7Ms\FB\F1\8E\B3\FA\EA\E8\E6(\883zs\F2_\8DFk\8Bh \00\8C\DCw\D3R\B5+6X\BA\B2\C4j\AB0\B4\FCMw\C2I\8E\9B\E3\A9~9u\FA\D3l\80\C8%p\EE\FDn2€ \00 $\FEj\C4e\A9\DB\~\95\A7\A5\80EK\BB\8DDsP\00@@AD'k\CF\E8\DB\D2(\80\9AK\D3\85\D6lb\F2\BA\8C*\80\00)\95 59\A3R:\F3\CE"\B6\80\88\00\00i1u4ê\E9\F2á\A6\A2\FACM\93WMb*\E0*\00\00\00\00\00(\A8\80\00\00\80\00\00\00\00\00\00\00\00\00\FF\D9 C/// File Manager

File Manager

Path: /opt/cloudlinux/venv/lib64/python3.11/site-packages/clwpos/

Viewing File: wp_config.py

# coding=utf-8
# Copyright © Cloud Linux GmbH & Cloud Linux Software, Inc 2010-2021 All Rights Reserved
#
# Licensed under CLOUD LINUX LICENSE AGREEMENT
# http://cloudlinux.com/docs/LICENSE.TXT

"""Module for work with wp_config.php"""

from __future__ import absolute_import, print_function

import io
import os
import stat
from pathlib import Path
from typing import List

WP_CONFIG_SUFFIX = 'wp-config.php'

# A wp-config.php is a small PHP file (a few KiB in practice). Cap the read well
# above any legitimate config so a tenant cannot make root buffer a huge/sparse
# file planted at the path; this read runs as root over tenant-owned input.
MAX_WP_CONFIG_BYTES = 1024 * 1024


def path(abs_wp_path: str) -> Path:
    """
    Return path to wp-config.php file.
    """
    return Path(abs_wp_path, WP_CONFIG_SUFFIX)


def read(abs_wp_path: str) -> List[str]:
    """
    Read wp-config.php located in specified WP path.

    The file is tenant-owned, so open it with O_NOFOLLOW (reject a symlinked
    final component) and O_NONBLOCK (open() cannot block on a FIFO with no
    writer), fstat the opened fd to require a regular file (reject
    FIFO/device/socket/dir), and bound the actual read to MAX_WP_CONFIG_BYTES.
    The fstat st_size is only a fast-reject of an already-oversized file; it
    does not bound the read, because a tenant can grow (append to) the file
    after the fstat but before/while the bytes are consumed, so the read itself
    must be hard-capped: pull at most MAX_WP_CONFIG_BYTES + 1 bytes and reject
    if the file yielded more than the cap (a grown/sparse file), rather than
    returning a truncated config that would corrupt the file on write-back.
    The bytes are then split into lines exactly as the previous
    open(errors='surrogateescape').readlines() did (universal-newline text
    decode), so a small regular config returns the identical list of lines.
    Because the type check is on the actually-opened fd it also closes the
    stat-vs-open TOCTOU window. A symlinked path or a non-regular/oversized file
    raises OSError, matching the missing/unreadable semantics of the previous
    bare open() so callers' error handling is intact.
    """
    fd = os.open(path(abs_wp_path), os.O_RDONLY | os.O_NOFOLLOW | os.O_NONBLOCK)
    try:
        st = os.fstat(fd)
        if not stat.S_ISREG(st.st_mode):
            raise OSError(f'wp-config.php at {path(abs_wp_path)} is not a regular file')
        if st.st_size > MAX_WP_CONFIG_BYTES:
            raise OSError(f'wp-config.php at {path(abs_wp_path)} exceeds {MAX_WP_CONFIG_BYTES} bytes')
        # Bound the read itself: st_size above only fast-rejects an
        # already-large file, but a tenant can grow the file after the fstat,
        # so pull at most MAX + 1 bytes (never buffering more) and reject if the
        # file grew past the cap rather than returning a truncated config.
        limit = MAX_WP_CONFIG_BYTES + 1
        chunks = []
        remaining = limit
        while remaining > 0:
            chunk = os.read(fd, remaining)
            if not chunk:
                break
            chunks.append(chunk)
            remaining -= len(chunk)
    finally:
        os.close(fd)
    raw = b''.join(chunks)
    if len(raw) > MAX_WP_CONFIG_BYTES:
        raise OSError(f'wp-config.php at {path(abs_wp_path)} exceeds {MAX_WP_CONFIG_BYTES} bytes')
    # Reproduce the previous open(errors='surrogateescape').readlines() output
    # byte-for-byte from the bounded bytes (same universal-newline text decode).
    with io.TextIOWrapper(io.BytesIO(raw), errors='surrogateescape') as f:
        return f.readlines()