Jail.php 15 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537
  1. <?php
  2. /**
  3. * @copyright Copyright (c) 2016, ownCloud, Inc.
  4. *
  5. * @author Christoph Wurst <christoph@winzerhof-wurst.at>
  6. * @author J0WI <J0WI@users.noreply.github.com>
  7. * @author Julius Härtl <jus@bitgrid.net>
  8. * @author Lukas Reschke <lukas@statuscode.ch>
  9. * @author Morris Jobke <hey@morrisjobke.de>
  10. * @author Robin Appelman <robin@icewind.nl>
  11. * @author Roeland Jago Douma <roeland@famdouma.nl>
  12. * @author Tigran Mkrtchyan <tigran.mkrtchyan@desy.de>
  13. *
  14. * @license AGPL-3.0
  15. *
  16. * This code is free software: you can redistribute it and/or modify
  17. * it under the terms of the GNU Affero General Public License, version 3,
  18. * as published by the Free Software Foundation.
  19. *
  20. * This program is distributed in the hope that it will be useful,
  21. * but WITHOUT ANY WARRANTY; without even the implied warranty of
  22. * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
  23. * GNU Affero General Public License for more details.
  24. *
  25. * You should have received a copy of the GNU Affero General Public License, version 3,
  26. * along with this program. If not, see <http://www.gnu.org/licenses/>
  27. *
  28. */
  29. namespace OC\Files\Storage\Wrapper;
  30. use OC\Files\Cache\Wrapper\CacheJail;
  31. use OC\Files\Cache\Wrapper\JailPropagator;
  32. use OC\Files\Filesystem;
  33. use OCP\Files\Storage\IStorage;
  34. use OCP\Files\Storage\IWriteStreamStorage;
  35. use OCP\Lock\ILockingProvider;
  36. /**
  37. * Jail to a subdirectory of the wrapped storage
  38. *
  39. * This restricts access to a subfolder of the wrapped storage with the subfolder becoming the root folder new storage
  40. */
  41. class Jail extends Wrapper {
  42. /**
  43. * @var string
  44. */
  45. protected $rootPath;
  46. /**
  47. * @param array $arguments ['storage' => $storage, 'root' => $root]
  48. *
  49. * $storage: The storage that will be wrapper
  50. * $root: The folder in the wrapped storage that will become the root folder of the wrapped storage
  51. */
  52. public function __construct($arguments) {
  53. parent::__construct($arguments);
  54. $this->rootPath = $arguments['root'];
  55. }
  56. public function getUnjailedPath($path) {
  57. return trim(Filesystem::normalizePath($this->rootPath . '/' . $path), '/');
  58. }
  59. /**
  60. * This is separate from Wrapper::getWrapperStorage so we can get the jailed storage consistently even if the jail is inside another wrapper
  61. */
  62. public function getUnjailedStorage() {
  63. return $this->storage;
  64. }
  65. public function getJailedPath($path) {
  66. $root = rtrim($this->rootPath, '/') . '/';
  67. if ($path !== $this->rootPath && strpos($path, $root) !== 0) {
  68. return null;
  69. } else {
  70. $path = substr($path, strlen($this->rootPath));
  71. return trim($path, '/');
  72. }
  73. }
  74. public function getId() {
  75. return parent::getId();
  76. }
  77. /**
  78. * see https://www.php.net/manual/en/function.mkdir.php
  79. *
  80. * @param string $path
  81. * @return bool
  82. */
  83. public function mkdir($path) {
  84. return $this->getWrapperStorage()->mkdir($this->getUnjailedPath($path));
  85. }
  86. /**
  87. * see https://www.php.net/manual/en/function.rmdir.php
  88. *
  89. * @param string $path
  90. * @return bool
  91. */
  92. public function rmdir($path) {
  93. return $this->getWrapperStorage()->rmdir($this->getUnjailedPath($path));
  94. }
  95. /**
  96. * see https://www.php.net/manual/en/function.opendir.php
  97. *
  98. * @param string $path
  99. * @return resource|false
  100. */
  101. public function opendir($path) {
  102. return $this->getWrapperStorage()->opendir($this->getUnjailedPath($path));
  103. }
  104. /**
  105. * see https://www.php.net/manual/en/function.is_dir.php
  106. *
  107. * @param string $path
  108. * @return bool
  109. */
  110. public function is_dir($path) {
  111. return $this->getWrapperStorage()->is_dir($this->getUnjailedPath($path));
  112. }
  113. /**
  114. * see https://www.php.net/manual/en/function.is_file.php
  115. *
  116. * @param string $path
  117. * @return bool
  118. */
  119. public function is_file($path) {
  120. return $this->getWrapperStorage()->is_file($this->getUnjailedPath($path));
  121. }
  122. /**
  123. * see https://www.php.net/manual/en/function.stat.php
  124. * only the following keys are required in the result: size and mtime
  125. *
  126. * @param string $path
  127. * @return array|bool
  128. */
  129. public function stat($path) {
  130. return $this->getWrapperStorage()->stat($this->getUnjailedPath($path));
  131. }
  132. /**
  133. * see https://www.php.net/manual/en/function.filetype.php
  134. *
  135. * @param string $path
  136. * @return bool
  137. */
  138. public function filetype($path) {
  139. return $this->getWrapperStorage()->filetype($this->getUnjailedPath($path));
  140. }
  141. /**
  142. * see https://www.php.net/manual/en/function.filesize.php
  143. * The result for filesize when called on a folder is required to be 0
  144. */
  145. public function filesize($path): false|int|float {
  146. return $this->getWrapperStorage()->filesize($this->getUnjailedPath($path));
  147. }
  148. /**
  149. * check if a file can be created in $path
  150. *
  151. * @param string $path
  152. * @return bool
  153. */
  154. public function isCreatable($path) {
  155. return $this->getWrapperStorage()->isCreatable($this->getUnjailedPath($path));
  156. }
  157. /**
  158. * check if a file can be read
  159. *
  160. * @param string $path
  161. * @return bool
  162. */
  163. public function isReadable($path) {
  164. return $this->getWrapperStorage()->isReadable($this->getUnjailedPath($path));
  165. }
  166. /**
  167. * check if a file can be written to
  168. *
  169. * @param string $path
  170. * @return bool
  171. */
  172. public function isUpdatable($path) {
  173. return $this->getWrapperStorage()->isUpdatable($this->getUnjailedPath($path));
  174. }
  175. /**
  176. * check if a file can be deleted
  177. *
  178. * @param string $path
  179. * @return bool
  180. */
  181. public function isDeletable($path) {
  182. return $this->getWrapperStorage()->isDeletable($this->getUnjailedPath($path));
  183. }
  184. /**
  185. * check if a file can be shared
  186. *
  187. * @param string $path
  188. * @return bool
  189. */
  190. public function isSharable($path) {
  191. return $this->getWrapperStorage()->isSharable($this->getUnjailedPath($path));
  192. }
  193. /**
  194. * get the full permissions of a path.
  195. * Should return a combination of the PERMISSION_ constants defined in lib/public/constants.php
  196. *
  197. * @param string $path
  198. * @return int
  199. */
  200. public function getPermissions($path) {
  201. return $this->getWrapperStorage()->getPermissions($this->getUnjailedPath($path));
  202. }
  203. /**
  204. * see https://www.php.net/manual/en/function.file_exists.php
  205. *
  206. * @param string $path
  207. * @return bool
  208. */
  209. public function file_exists($path) {
  210. return $this->getWrapperStorage()->file_exists($this->getUnjailedPath($path));
  211. }
  212. /**
  213. * see https://www.php.net/manual/en/function.filemtime.php
  214. *
  215. * @param string $path
  216. * @return int|bool
  217. */
  218. public function filemtime($path) {
  219. return $this->getWrapperStorage()->filemtime($this->getUnjailedPath($path));
  220. }
  221. /**
  222. * see https://www.php.net/manual/en/function.file_get_contents.php
  223. *
  224. * @param string $path
  225. * @return string|false
  226. */
  227. public function file_get_contents($path) {
  228. return $this->getWrapperStorage()->file_get_contents($this->getUnjailedPath($path));
  229. }
  230. /**
  231. * see https://www.php.net/manual/en/function.file_put_contents.php
  232. *
  233. * @param string $path
  234. * @param mixed $data
  235. * @return int|float|false
  236. */
  237. public function file_put_contents($path, $data) {
  238. return $this->getWrapperStorage()->file_put_contents($this->getUnjailedPath($path), $data);
  239. }
  240. /**
  241. * see https://www.php.net/manual/en/function.unlink.php
  242. *
  243. * @param string $path
  244. * @return bool
  245. */
  246. public function unlink($path) {
  247. return $this->getWrapperStorage()->unlink($this->getUnjailedPath($path));
  248. }
  249. /**
  250. * see https://www.php.net/manual/en/function.rename.php
  251. *
  252. * @param string $source
  253. * @param string $target
  254. * @return bool
  255. */
  256. public function rename($source, $target) {
  257. return $this->getWrapperStorage()->rename($this->getUnjailedPath($source), $this->getUnjailedPath($target));
  258. }
  259. /**
  260. * see https://www.php.net/manual/en/function.copy.php
  261. *
  262. * @param string $source
  263. * @param string $target
  264. * @return bool
  265. */
  266. public function copy($source, $target) {
  267. return $this->getWrapperStorage()->copy($this->getUnjailedPath($source), $this->getUnjailedPath($target));
  268. }
  269. /**
  270. * see https://www.php.net/manual/en/function.fopen.php
  271. *
  272. * @param string $path
  273. * @param string $mode
  274. * @return resource|bool
  275. */
  276. public function fopen($path, $mode) {
  277. return $this->getWrapperStorage()->fopen($this->getUnjailedPath($path), $mode);
  278. }
  279. /**
  280. * get the mimetype for a file or folder
  281. * The mimetype for a folder is required to be "httpd/unix-directory"
  282. *
  283. * @param string $path
  284. * @return string|bool
  285. */
  286. public function getMimeType($path) {
  287. return $this->getWrapperStorage()->getMimeType($this->getUnjailedPath($path));
  288. }
  289. /**
  290. * see https://www.php.net/manual/en/function.hash.php
  291. *
  292. * @param string $type
  293. * @param string $path
  294. * @param bool $raw
  295. * @return string|bool
  296. */
  297. public function hash($type, $path, $raw = false) {
  298. return $this->getWrapperStorage()->hash($type, $this->getUnjailedPath($path), $raw);
  299. }
  300. /**
  301. * see https://www.php.net/manual/en/function.free_space.php
  302. *
  303. * @param string $path
  304. * @return int|float|bool
  305. */
  306. public function free_space($path) {
  307. return $this->getWrapperStorage()->free_space($this->getUnjailedPath($path));
  308. }
  309. /**
  310. * search for occurrences of $query in file names
  311. *
  312. * @param string $query
  313. * @return array|bool
  314. */
  315. public function search($query) {
  316. return $this->getWrapperStorage()->search($query);
  317. }
  318. /**
  319. * see https://www.php.net/manual/en/function.touch.php
  320. * If the backend does not support the operation, false should be returned
  321. *
  322. * @param string $path
  323. * @param int $mtime
  324. * @return bool
  325. */
  326. public function touch($path, $mtime = null) {
  327. return $this->getWrapperStorage()->touch($this->getUnjailedPath($path), $mtime);
  328. }
  329. /**
  330. * get the path to a local version of the file.
  331. * The local version of the file can be temporary and doesn't have to be persistent across requests
  332. *
  333. * @param string $path
  334. * @return string|false
  335. */
  336. public function getLocalFile($path) {
  337. return $this->getWrapperStorage()->getLocalFile($this->getUnjailedPath($path));
  338. }
  339. /**
  340. * check if a file or folder has been updated since $time
  341. *
  342. * @param string $path
  343. * @param int $time
  344. * @return bool
  345. *
  346. * hasUpdated for folders should return at least true if a file inside the folder is add, removed or renamed.
  347. * returning true for other changes in the folder is optional
  348. */
  349. public function hasUpdated($path, $time) {
  350. return $this->getWrapperStorage()->hasUpdated($this->getUnjailedPath($path), $time);
  351. }
  352. /**
  353. * get a cache instance for the storage
  354. *
  355. * @param string $path
  356. * @param \OC\Files\Storage\Storage|null (optional) the storage to pass to the cache
  357. * @return \OC\Files\Cache\Cache
  358. */
  359. public function getCache($path = '', $storage = null) {
  360. if (!$storage) {
  361. $storage = $this->getWrapperStorage();
  362. }
  363. $sourceCache = $this->getWrapperStorage()->getCache($this->getUnjailedPath($path), $storage);
  364. return new CacheJail($sourceCache, $this->rootPath);
  365. }
  366. /**
  367. * get the user id of the owner of a file or folder
  368. *
  369. * @param string $path
  370. * @return string
  371. */
  372. public function getOwner($path) {
  373. return $this->getWrapperStorage()->getOwner($this->getUnjailedPath($path));
  374. }
  375. /**
  376. * get a watcher instance for the cache
  377. *
  378. * @param string $path
  379. * @param \OC\Files\Storage\Storage (optional) the storage to pass to the watcher
  380. * @return \OC\Files\Cache\Watcher
  381. */
  382. public function getWatcher($path = '', $storage = null) {
  383. if (!$storage) {
  384. $storage = $this;
  385. }
  386. return $this->getWrapperStorage()->getWatcher($this->getUnjailedPath($path), $storage);
  387. }
  388. /**
  389. * get the ETag for a file or folder
  390. *
  391. * @param string $path
  392. * @return string|false
  393. */
  394. public function getETag($path) {
  395. return $this->getWrapperStorage()->getETag($this->getUnjailedPath($path));
  396. }
  397. public function getMetaData($path) {
  398. return $this->getWrapperStorage()->getMetaData($this->getUnjailedPath($path));
  399. }
  400. /**
  401. * @param string $path
  402. * @param int $type \OCP\Lock\ILockingProvider::LOCK_SHARED or \OCP\Lock\ILockingProvider::LOCK_EXCLUSIVE
  403. * @param \OCP\Lock\ILockingProvider $provider
  404. * @throws \OCP\Lock\LockedException
  405. */
  406. public function acquireLock($path, $type, ILockingProvider $provider) {
  407. $this->getWrapperStorage()->acquireLock($this->getUnjailedPath($path), $type, $provider);
  408. }
  409. /**
  410. * @param string $path
  411. * @param int $type \OCP\Lock\ILockingProvider::LOCK_SHARED or \OCP\Lock\ILockingProvider::LOCK_EXCLUSIVE
  412. * @param \OCP\Lock\ILockingProvider $provider
  413. */
  414. public function releaseLock($path, $type, ILockingProvider $provider) {
  415. $this->getWrapperStorage()->releaseLock($this->getUnjailedPath($path), $type, $provider);
  416. }
  417. /**
  418. * @param string $path
  419. * @param int $type \OCP\Lock\ILockingProvider::LOCK_SHARED or \OCP\Lock\ILockingProvider::LOCK_EXCLUSIVE
  420. * @param \OCP\Lock\ILockingProvider $provider
  421. */
  422. public function changeLock($path, $type, ILockingProvider $provider) {
  423. $this->getWrapperStorage()->changeLock($this->getUnjailedPath($path), $type, $provider);
  424. }
  425. /**
  426. * Resolve the path for the source of the share
  427. *
  428. * @param string $path
  429. * @return array
  430. */
  431. public function resolvePath($path) {
  432. return [$this->getWrapperStorage(), $this->getUnjailedPath($path)];
  433. }
  434. /**
  435. * @param IStorage $sourceStorage
  436. * @param string $sourceInternalPath
  437. * @param string $targetInternalPath
  438. * @return bool
  439. */
  440. public function copyFromStorage(IStorage $sourceStorage, $sourceInternalPath, $targetInternalPath) {
  441. if ($sourceStorage === $this) {
  442. return $this->copy($sourceInternalPath, $targetInternalPath);
  443. }
  444. return $this->getWrapperStorage()->copyFromStorage($sourceStorage, $sourceInternalPath, $this->getUnjailedPath($targetInternalPath));
  445. }
  446. /**
  447. * @param IStorage $sourceStorage
  448. * @param string $sourceInternalPath
  449. * @param string $targetInternalPath
  450. * @return bool
  451. */
  452. public function moveFromStorage(IStorage $sourceStorage, $sourceInternalPath, $targetInternalPath) {
  453. if ($sourceStorage === $this) {
  454. return $this->rename($sourceInternalPath, $targetInternalPath);
  455. }
  456. return $this->getWrapperStorage()->moveFromStorage($sourceStorage, $sourceInternalPath, $this->getUnjailedPath($targetInternalPath));
  457. }
  458. public function getPropagator($storage = null) {
  459. if (isset($this->propagator)) {
  460. return $this->propagator;
  461. }
  462. if (!$storage) {
  463. $storage = $this;
  464. }
  465. $this->propagator = new JailPropagator($storage, \OC::$server->getDatabaseConnection());
  466. return $this->propagator;
  467. }
  468. public function writeStream(string $path, $stream, int $size = null): int {
  469. $storage = $this->getWrapperStorage();
  470. if ($storage->instanceOfStorage(IWriteStreamStorage::class)) {
  471. /** @var IWriteStreamStorage $storage */
  472. return $storage->writeStream($this->getUnjailedPath($path), $stream, $size);
  473. } else {
  474. $target = $this->fopen($path, 'w');
  475. [$count, $result] = \OC_Helper::streamCopy($stream, $target);
  476. fclose($stream);
  477. fclose($target);
  478. return $count;
  479. }
  480. }
  481. public function getDirectoryContent($directory): \Traversable {
  482. return $this->getWrapperStorage()->getDirectoryContent($this->getUnjailedPath($directory));
  483. }
  484. }