mirror of
https://github.com/davidhalter/jedi.git
synced 2026-10-05 03:18:47 +08:00
Do not trust code execution settings from .jedi/project.json (#2108)
get_default_project() loads the first .jedi/project.json above the analysed file, which can be part of a checked out repository. Its environment_path was executed with safe=False and its load_unsafe_extensions was honoured. Loaded projects now check the binary like find_virtualenvs and ignore load_unsafe_extensions.
This commit is contained in:
1 parent
5c37b736a3
commit
112d255414
3 files changed
+45
-2
No files matched your search
@@ -1,4 +1,5 @@
|
||||
import os
|
||||
import sys
|
||||
from pathlib import Path
|
||||
|
||||
import pytest
|
||||
@@ -6,6 +7,7 @@ import pytest
|
||||
from ..helpers import get_example_dir, set_cwd, root_dir, test_dir
|
||||
from jedi import Interpreter
|
||||
from jedi.api import Project, get_default_project
|
||||
from jedi.api.environment import InvalidPythonEnvironment
|
||||
from jedi.api.project import _is_potential_project, _CONTAINS_POTENTIAL_PROJECT
|
||||
|
||||
|
||||
@@ -54,6 +56,33 @@ def test_load_save_project(tmpdir):
|
||||
assert loaded.added_sys_path == ['/foo']
|
||||
|
||||
|
||||
def test_load_project_checks_environment_path(tmpdir, monkeypatch):
|
||||
# The project file can be part of a checked out repository, so the binary
|
||||
# it points to has to pass the same check as in find_virtualenvs.
|
||||
monkeypatch.setattr('jedi.api.environment._is_safe', lambda executable_path: False)
|
||||
|
||||
def _get_subprocess(self):
|
||||
raise RuntimeError('Should not get called!')
|
||||
|
||||
monkeypatch.setattr('jedi.api.environment.Environment._get_subprocess',
|
||||
_get_subprocess)
|
||||
|
||||
Project(tmpdir.strpath, environment_path=sys.executable).save()
|
||||
with pytest.raises(InvalidPythonEnvironment):
|
||||
Project.load(tmpdir.strpath).get_environment()
|
||||
|
||||
|
||||
def test_load_project_safe_environment_path(tmpdir):
|
||||
Project(tmpdir.strpath, environment_path=sys.executable).save()
|
||||
environment = Project.load(tmpdir.strpath).get_environment()
|
||||
assert environment.executable == sys.executable
|
||||
|
||||
|
||||
def test_load_project_ignores_unsafe_extensions(tmpdir):
|
||||
Project(tmpdir.strpath, load_unsafe_extensions=True).save()
|
||||
assert Project.load(tmpdir.strpath).load_unsafe_extensions is False
|
||||
|
||||
|
||||
@pytest.mark.parametrize(
|
||||
'string, full_names, kwargs', [
|
||||
('test_load_save_project', ['test_api.test_project.test_load_save_project'], {}),
|
||||
|
||||
Reference in new issue
Block a user