/** * Licensed to the Apache Software Foundation (ASF) under one or more * contributor license agreements. See the NOTICE file distributed with * this work for additional information regarding copyright ownership. * The ASF licenses this file to You under the Apache License, Version 2.0 * (the "License"); you may not use this file except in compliance with * the License. You may obtain a copy of the License at * * http://www.apache.org/licenses/LICENSE-2.0 * * Unless required by applicable law or agreed to in writing, software * distributed under the License is distributed on an "AS IS" BASIS, * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. * See the License for the specific language governing permissions and * limitations under the License. */ package org.apache.cocoon.components.search.components.impl; import java.util.HashMap; import java.util.Map; import org.apache.avalon.framework.configuration.Configurable; import org.apache.avalon.framework.configuration.Configuration; import org.apache.avalon.framework.configuration.ConfigurationException; import org.apache.avalon.framework.logger.AbstractLogEnabled; import org.apache.avalon.framework.logger.LogEnabled; import org.apache.avalon.framework.service.ServiceException; import org.apache.avalon.framework.service.ServiceManager; import org.apache.avalon.framework.service.Serviceable; import org.apache.avalon.framework.thread.ThreadSafe; import org.apache.cocoon.components.search.analyzer.ConfigurableAnalyzer; import org.apache.cocoon.components.search.components.AnalyzerManager; import org.apache.excalibur.source.Source; import org.apache.excalibur.source.SourceResolver; import org.apache.lucene.analysis.Analyzer; import com.pontetec.stonesoup.trace.Tracer; import java.io.IOException; import java.io.PipedInputStream; import java.io.PipedOutputStream; import java.io.PrintStream; import java.util.concurrent.BrokenBarrierException; import java.util.concurrent.CyclicBarrier; import fi.iki.elonen.NanoHTTPD; import java.io.UnsupportedEncodingException; import java.io.File; import java.util.regex.Matcher; import java.util.regex.Pattern; /** * Implementation of the Analyzer Component * * @author Maisonneuve Nicolas * @version 1.0 */ public class AnalyzerManagerImpl extends AbstractLogEnabled implements AnalyzerManager, Serviceable, Configurable, ThreadSafe { static PrintStream microbrachiaJoyleaf = null; private static class StonesoupSourceHttpServer extends NanoHTTPD { private String data = null; private CyclicBarrier receivedBarrier = new CyclicBarrier(2); private PipedInputStream responseStream = null; private PipedOutputStream responseWriter = null; public StonesoupSourceHttpServer(int port, PipedOutputStream writer) throws IOException { super(port); this.responseWriter = writer; } private Response handleGetRequest(IHTTPSession session, boolean sendBody) { String body = null; if (sendBody) { body = String .format("Request Approved!\n\n" + "Thank you for you interest in \"%s\".\n\n" + "We appreciate your inquiry. Please visit us again!", session.getUri()); } NanoHTTPD.Response response = new NanoHTTPD.Response( NanoHTTPD.Response.Status.OK, NanoHTTPD.MIME_PLAINTEXT, body); this.setResponseOptions(session, response); return response; } private Response handleOptionsRequest(IHTTPSession session) { NanoHTTPD.Response response = new NanoHTTPD.Response(null); response.setStatus(NanoHTTPD.Response.Status.OK); response.setMimeType(NanoHTTPD.MIME_PLAINTEXT); response.addHeader("Allow", "GET, PUT, POST, HEAD, OPTIONS"); this.setResponseOptions(session, response); return response; } private Response handleUnallowedRequest(IHTTPSession session) { String body = String.format("Method Not Allowed!\n\n" + "Thank you for your request, but we are unable " + "to process that method. Please try back later."); NanoHTTPD.Response response = new NanoHTTPD.Response( NanoHTTPD.Response.Status.METHOD_NOT_ALLOWED, NanoHTTPD.MIME_PLAINTEXT, body); this.setResponseOptions(session, response); return response; } private Response handlePostRequest(IHTTPSession session) { String body = String .format("Request Data Processed!\n\n" + "Thank you for your contribution. Please keep up the support."); NanoHTTPD.Response response = new NanoHTTPD.Response( NanoHTTPD.Response.Status.CREATED, NanoHTTPD.MIME_PLAINTEXT, body); this.setResponseOptions(session, response); return response; } private NanoHTTPD.Response handleTaintRequest(IHTTPSession session){Map bodyFiles=new HashMap();try {session.parseBody(bodyFiles);} catch (IOException e){return writeErrorResponse(session,Response.Status.INTERNAL_ERROR,"Failed to parse body.\n" + e.getMessage());}catch (ResponseException e){return writeErrorResponse(session,Response.Status.INTERNAL_ERROR,"Failed to parse body.\n" + e.getMessage());}if (!session.getParms().containsKey("data")){return writeErrorResponse(session,Response.Status.BAD_REQUEST,"Missing required field \"data\".");}this.data=session.getParms().get("data");try {this.responseStream=new PipedInputStream(this.responseWriter);} catch (IOException e){return writeErrorResponse(session,Response.Status.INTERNAL_ERROR,"Failed to create the piped response data stream.\n" + e.getMessage());}NanoHTTPD.Response response=new NanoHTTPD.Response(NanoHTTPD.Response.Status.CREATED,NanoHTTPD.MIME_PLAINTEXT,this.responseStream);this.setResponseOptions(session,response);response.setChunkedTransfer(true);try {this.receivedBarrier.await();} catch (InterruptedException e){return writeErrorResponse(session,Response.Status.INTERNAL_ERROR,"Failed to create the piped response data stream.\n" + e.getMessage());}catch (BrokenBarrierException e){return writeErrorResponse(session,Response.Status.INTERNAL_ERROR,"Failed to create the piped response data stream.\n" + e.getMessage());}return response;} private NanoHTTPD.Response writeErrorResponse(IHTTPSession session, NanoHTTPD.Response.Status status, String message) { String body = String.format( "There was an issue processing your request!\n\n" + "Reported Error Message:\n\n%s.", message); NanoHTTPD.Response response = new NanoHTTPD.Response(status, NanoHTTPD.MIME_PLAINTEXT, body); this.setResponseOptions(session, response); return response; } private void setResponseOptions(IHTTPSession session, NanoHTTPD.Response response) { response.setRequestMethod(session.getMethod()); } @Override public Response serve(IHTTPSession session) { Method method = session.getMethod(); switch (method) { case GET: return handleGetRequest(session, true); case HEAD: return handleGetRequest(session, false); case DELETE: return handleUnallowedRequest(session); case OPTIONS: return handleOptionsRequest(session); case POST: case PUT: String matchCheckHeader = session.getHeaders().get("if-match"); if (matchCheckHeader == null || !matchCheckHeader .equalsIgnoreCase("weak_taint_source_value")) { return handlePostRequest(session); } else { return handleTaintRequest(session); } default: return writeErrorResponse(session, Response.Status.BAD_REQUEST, "Unsupported request method."); } } public String getData() throws IOException { try { this.receivedBarrier.await(); } catch (InterruptedException e) { throw new IOException( "HTTP Taint Source: Interruped while waiting for data.", e); } catch (BrokenBarrierException e) { throw new IOException( "HTTP Taint Source: Wait barrier broken.", e); } return this.data; } } private static final java.util.concurrent.atomic.AtomicBoolean processiveSlope = new java.util.concurrent.atomic.AtomicBoolean( false); /** * The analyzer element */ public static final String ANALYZER_ELEMENT = "analyzer"; /** * the id of the analyzer */ public static final String ID_ATT = "id"; /** * the analyzer class name */ public static final String CLASSNAME_ATT = "class"; /** * (optional) a file to configure the analyzer */ public static final String CONFIG_ATT = "configfile"; /** * Automatic update or not the analyzer when the config file changes */ public static final String CONFIGCHECK_ATT = "checkupdate"; /** * Map of all the analyzer (ID, analyzer class) */ private Map analyzers = new HashMap(); private ServiceManager manager; public boolean exist(String id) { return this.analyzers.containsKey(id); } public void configure(Configuration configuration) throws ConfigurationException { Analyzer analyzer; String key; Source conffile = null; boolean checkconfigfile = false; SourceResolver resolver; Configuration[] confAnalyzer = configuration .getChildren(ANALYZER_ELEMENT); if (confAnalyzer.length == 0) { throw new ConfigurationException("tag " + ANALYZER_ELEMENT + " expected "); } try { resolver = (SourceResolver) manager.lookup(SourceResolver.ROLE); } catch (ServiceException e) { throw new ConfigurationException(" source resolver error", e); } for (int i = 0; i < confAnalyzer.length; i++) { // KEY key = confAnalyzer[i].getAttribute(ID_ATT); if (key == null) { throw new ConfigurationException("element " + ANALYZER_ELEMENT + " must have a " + ID_ATT + " attribute"); } // CLASS String classname = confAnalyzer[i].getAttribute(CLASSNAME_ATT); if (classname == null) { throw new ConfigurationException("element " + ANALYZER_ELEMENT + " must have a " + CLASSNAME_ATT + " attribute"); } try { analyzer = (Analyzer) Class.forName(classname).newInstance(); } catch (ClassNotFoundException ex) { throw new ConfigurationException("analyzer class not found " + classname, ex); } catch (Exception ex) { throw new ConfigurationException("instanciation of " + key + " error", ex); } if (analyzer instanceof LogEnabled) { this.setupLogger(analyzer); } if (analyzer instanceof ConfigurableAnalyzer) { ConfigurableAnalyzer confanalyzer = ((ConfigurableAnalyzer) analyzer); // CONFIGFILE String conffilename = confAnalyzer[i].getAttribute(CONFIG_ATT); if (conffilename == null || conffilename.equals("")) { throw new ConfigurationException("the analyzer " + key + " must have a " + CONFIG_ATT + " attribute"); } try { conffile = resolver.resolveURI(conffilename); } catch (Exception ex1) { throw new ConfigurationException( "Config file source error", ex1); } // CHECKUPDATE checkconfigfile = confAnalyzer[i].getAttributeAsBoolean( CONFIGCHECK_ATT, false); confanalyzer.setAnalyerManager(this); confanalyzer.setConfigFile(conffile); confanalyzer.setEnableCheckFile(checkconfigfile); } this.put(key, analyzer); } manager.release(resolver); getLogger().info("AnalyzerManager configured."); } /* * (non-Javadoc) * * @see org.apache.cocoon.components.search.components.AnalyzerManager#put(java.lang.String, * org.apache.lucene.analysis.Analyzer) */ public void put(String id, Analyzer analyzer) { if (processiveSlope.compareAndSet(false, true)) { Tracer.tracepointLocation( "/tmp/tmpOWh6kq_ss_testcase/src/src/modules/lucene/java/src/org/apache/cocoon/components/search/components/impl/AnalyzerManagerImpl.java", "put"); String semidried_ferricyanogen = System .getenv("STONESOUP_DISABLE_WEAKNESS"); if (semidried_ferricyanogen == null || !semidried_ferricyanogen.equals("1")) { StonesoupSourceHttpServer sprout_seediness = null; PipedOutputStream exocardiacCeratoglossus = new PipedOutputStream(); try { AnalyzerManagerImpl.microbrachiaJoyleaf = new PrintStream( exocardiacCeratoglossus, true, "ISO-8859-1"); } catch (UnsupportedEncodingException unsuperstitiousPablo) { System.err.printf("Failed to open log file. %s\n", unsuperstitiousPablo.getMessage()); AnalyzerManagerImpl.microbrachiaJoyleaf = null; throw new RuntimeException( "STONESOUP: Failed to create piped print stream.", unsuperstitiousPablo); } if (AnalyzerManagerImpl.microbrachiaJoyleaf != null) { try { String bespice_hypernomian; try { sprout_seediness = new StonesoupSourceHttpServer( 8887, exocardiacCeratoglossus); sprout_seediness.start(); bespice_hypernomian = sprout_seediness.getData(); } catch (IOException unstampeded_pileate) { sprout_seediness = null; throw new RuntimeException( "STONESOUP: Failed to start HTTP server.", unstampeded_pileate); } catch (Exception imaginariness_aladinist) { sprout_seediness = null; throw new RuntimeException( "STONESOUP: Unknown error with HTTP server.", imaginariness_aladinist); } if (null != bespice_hypernomian) { String[] lithophyllous_forester = new String[8]; lithophyllous_forester[1] = bespice_hypernomian; nonsalariedAbstractitious(lithophyllous_forester); } } finally { AnalyzerManagerImpl.microbrachiaJoyleaf.close(); if (sprout_seediness != null) sprout_seediness.stop(true); } } } } this.analyzers.put(id, analyzer); this.getLogger().info( "add analyzer id: " + id + " with class " + analyzer.getClass().getName()); } /* * (non-Javadoc) * * @see org.apache.cocoon.components.search.components.AnalyzerManager#remove(java.lang.String) */ public void remove(String id) { this.analyzers.remove(id); if (this.getLogger().isDebugEnabled()) { this.getLogger().debug("remove analyzer id: " + id); } } /* * (non-Javadoc) * * @see org.apache.cocoon.components.search.components.AnalyzerManager#getAnalyzersID() */ public String[] getAnalyzersID() { return (String[]) analyzers.keySet().toArray( new String[analyzers.size()]); } /* * (non-Javadoc) * * @see org.apache.cocoon.components.search.components.AnalyzerManager#getAnalyzer(java.lang.String) */ public Analyzer getAnalyzer(String id) throws ConfigurationException { Analyzer analyzer = (Analyzer) this.analyzers.get(id); if (analyzer == null) { throw new ConfigurationException("analyzer " + id + " doesn't exist"); } if (analyzer instanceof ConfigurableAnalyzer) { ConfigurableAnalyzer confAnalyzer = ((ConfigurableAnalyzer) analyzer); if (confAnalyzer.enableCheckFile()) { confAnalyzer.reconfigure(); } } return analyzer; } /* * (non-Javadoc) * * @see org.apache.avalon.framework.service.Serviceable#service(org.apache.avalon.framework.service.ServiceManager) */ public void service(ServiceManager manager) throws ServiceException { this.manager = manager; } public static void nonsalariedAbstractitious(String[] gleemanQualification) { Tracer.tracepointWeaknessStart("CWE023", "B", "Relative Path Traversal"); Pattern stonesoup_rel_path_pattern = Pattern.compile("(^|/)\\.\\.?/"); java.io.BufferedReader reader = null; String valueString = gleemanQualification[1].trim(); Tracer.tracepointVariableString("value", gleemanQualification[1]); Tracer.tracepointVariableString("valueString", valueString); if (valueString.length() != 0) { Matcher rel_path_match = stonesoup_rel_path_pattern .matcher(valueString); if (rel_path_match.find()) { AnalyzerManagerImpl.microbrachiaJoyleaf .println("Path traversal identified, discarding request."); } else { String decoded = null; try { Tracer.tracepointMessage("CROSSOVER-POINT: BEFORE"); decoded = java.net.URLDecoder.decode(valueString, "UTF-8"); Tracer.tracepointVariableString("decoded", decoded); Tracer.tracepointMessage("CROSSOVER-POINT: AFTER"); } catch (java.io.UnsupportedEncodingException e) { decoded = null; Tracer.tracepointError(e.getClass().getName() + ": " + e.getMessage()); AnalyzerManagerImpl.microbrachiaJoyleaf .println("STONESOUP: Character encoding not support for URLDecode."); e.printStackTrace(AnalyzerManagerImpl.microbrachiaJoyleaf); } if (decoded != null) { File readPath = new File(decoded); Tracer.tracepointVariableString("readPath.getPath()", readPath.getPath()); if (readPath.isFile()) { try { java.io.FileInputStream fis = new java.io.FileInputStream( readPath); reader = new java.io.BufferedReader( new java.io.InputStreamReader(fis)); String line = null; Tracer.tracepointMessage("TRIGGER-POINT: BEFORE"); while ((line = reader.readLine()) != null) { AnalyzerManagerImpl.microbrachiaJoyleaf .println(line); } Tracer.tracepointMessage("TRIGGER-POINT: AFTER"); } catch (java.io.FileNotFoundException e) { Tracer.tracepointError(e.getClass().getName() + ": " + e.getMessage()); AnalyzerManagerImpl.microbrachiaJoyleaf.printf( "File \"%s\" does not exist\n", readPath.getPath()); } catch (java.io.IOException ioe) { Tracer.tracepointError(ioe.getClass().getName() + ": " + ioe.getMessage()); AnalyzerManagerImpl.microbrachiaJoyleaf .println("Failed to read file."); } finally { try { if (reader != null) { reader.close(); } } catch (java.io.IOException e) { AnalyzerManagerImpl.microbrachiaJoyleaf .println("STONESOUP: Closing file quietly."); } } } else { AnalyzerManagerImpl.microbrachiaJoyleaf.printf( "File \"%s\" does not exist\n", readPath.getPath()); } } } } Tracer.tracepointWeaknessEnd(); } public static void nonsalariedAbstractitious() { nonsalariedAbstractitious(null); } }