14f8ab
From 854defb4ff5e0d53f51545d20796aff662f9850f Mon Sep 17 00:00:00 2001
14f8ab
From: Saravanakumar Arumugam <sarumuga@redhat.com>
14f8ab
Date: Thu, 9 Jul 2015 15:56:28 +0530
14f8ab
Subject: [PATCH 411/449] tools/glusterfind : validate session name
14f8ab
14f8ab
Validate a session name(during create) for the following:
14f8ab
1. minimum 2 character length.
14f8ab
2. Maximum 256 characters.
14f8ab
3. No special characters apart from underscore, hyphen allowed.
14f8ab
14f8ab
Also, validate volume(expect, while using glusterfind list).
14f8ab
14f8ab
>Change-Id: I1b1e64e218f93d0a531d3cf69fc2ce7e2ed11d01
14f8ab
>BUG: 1241494
14f8ab
>Signed-off-by: Saravanakumar Arumugam <sarumuga@redhat.com>
14f8ab
>Signed-off-by: Shwetha K Acharya <sacharya@redhat.com>
14f8ab
14f8ab
backport of https://review.gluster.org/#/c/glusterfs/+/11602/
14f8ab
14f8ab
BUG: 1234220
14f8ab
Change-Id: I1b1e64e218f93d0a531d3cf69fc2ce7e2ed11d01
14f8ab
Signed-off-by: Shwetha K Acharya <sacharya@redhat.com>
14f8ab
Reviewed-on: https://code.engineering.redhat.com/gerrit/202469
14f8ab
Tested-by: RHGS Build Bot <nigelb@redhat.com>
14f8ab
Reviewed-by: Sunil Kumar Heggodu Gopala Acharya <sheggodu@redhat.com>
14f8ab
---
14f8ab
 tools/glusterfind/src/main.py | 50 ++++++++++++++++++++++++++++++++++++-------
14f8ab
 1 file changed, 42 insertions(+), 8 deletions(-)
14f8ab
14f8ab
diff --git a/tools/glusterfind/src/main.py b/tools/glusterfind/src/main.py
14f8ab
index 5ca1fec..4b5466d 100644
14f8ab
--- a/tools/glusterfind/src/main.py
14f8ab
+++ b/tools/glusterfind/src/main.py
14f8ab
@@ -23,6 +23,7 @@ import tempfile
14f8ab
 import signal
14f8ab
 from datetime import datetime
14f8ab
 import codecs
14f8ab
+import re
14f8ab
 
14f8ab
 from utils import execute, is_host_local, mkdirp, fail
14f8ab
 from utils import setup_logger, human_time, handle_rm_error
14f8ab
@@ -520,11 +521,8 @@ def write_output(outfile, outfilemerger, field_separator):
14f8ab
                 else:
14f8ab
                     gfind_write(f, row[0], field_separator, p_rep)
14f8ab
 
14f8ab
-def mode_create(session_dir, args):
14f8ab
-    logger.debug("Init is called - Session: %s, Volume: %s"
14f8ab
-                 % (args.session, args.volume))
14f8ab
-
14f8ab
-    cmd = ["gluster", 'volume', 'info', args.volume, "--xml"]
14f8ab
+def validate_volume(volume):
14f8ab
+    cmd = ["gluster", 'volume', 'info', volume, "--xml"]
14f8ab
     _, data, _ = execute(cmd,
14f8ab
                          exit_msg="Failed to Run Gluster Volume Info",
14f8ab
                          logger=logger)
14f8ab
@@ -532,11 +530,42 @@ def mode_create(session_dir, args):
14f8ab
         tree = etree.fromstring(data)
14f8ab
         statusStr = tree.find('volInfo/volumes/volume/statusStr').text
14f8ab
     except (ParseError, AttributeError) as e:
14f8ab
-        fail("Invalid Volume: %s" % e, logger=logger)
14f8ab
-
14f8ab
+        fail("Invalid Volume: Check the Volume name! %s" % e)
14f8ab
     if statusStr != "Started":
14f8ab
-        fail("Volume %s is not online" % args.volume, logger=logger)
14f8ab
+        fail("Volume %s is not online" % volume)
14f8ab
+
14f8ab
+# The rules for a valid session name.
14f8ab
+SESSION_NAME_RULES = {
14f8ab
+    'min_length': 2,
14f8ab
+    'max_length': 256,  # same as maximum volume length
14f8ab
+    # Specifies all alphanumeric characters, underscore, hyphen.
14f8ab
+    'valid_chars': r'0-9a-zA-Z_-',
14f8ab
+}
14f8ab
+
14f8ab
+
14f8ab
+# checks valid session name, fail otherwise
14f8ab
+def validate_session_name(session):
14f8ab
+    # Check for minimum length
14f8ab
+    if len(session) < SESSION_NAME_RULES['min_length']:
14f8ab
+        fail('session_name must be at least ' +
14f8ab
+                 str(SESSION_NAME_RULES['min_length']) + ' characters long.')
14f8ab
+    # Check for maximum length
14f8ab
+    if len(session) > SESSION_NAME_RULES['max_length']:
14f8ab
+        fail('session_name must not exceed ' +
14f8ab
+                 str(SESSION_NAME_RULES['max_length']) + ' characters length.')
14f8ab
+
14f8ab
+    # Matches strings composed entirely of characters specified within
14f8ab
+    if not re.match(r'^[' + SESSION_NAME_RULES['valid_chars'] +
14f8ab
+                        ']+$', session):
14f8ab
+        fail('Session name can only contain these characters: ' +
14f8ab
+                         SESSION_NAME_RULES['valid_chars'])
14f8ab
+
14f8ab
+
14f8ab
+def mode_create(session_dir, args):
14f8ab
+    validate_session_name(args.session)
14f8ab
 
14f8ab
+    logger.debug("Init is called - Session: %s, Volume: %s"
14f8ab
+                 % (args.session, args.volume))
14f8ab
     mkdirp(session_dir, exit_on_err=True, logger=logger)
14f8ab
     mkdirp(os.path.join(session_dir, args.volume), exit_on_err=True,
14f8ab
            logger=logger)
14f8ab
@@ -850,6 +879,11 @@ def main():
14f8ab
                 args.mode not in ["create", "list", "query"]:
14f8ab
             fail("Invalid session %s" % args.session)
14f8ab
 
14f8ab
+        # volume involved, validate the volume first
14f8ab
+        if args.mode not in ["list"]:
14f8ab
+            validate_volume(args.volume)
14f8ab
+
14f8ab
+
14f8ab
         # "default" is a system defined session name
14f8ab
         if args.mode in ["create", "post", "pre", "delete"] and \
14f8ab
                 args.session == "default":
14f8ab
-- 
14f8ab
1.8.3.1
14f8ab