Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 17 additions & 1 deletion pre_commit/clientlib.py
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,22 @@

check_string_regex = cfgv.check_and(cfgv.check_string, cfgv.check_regex)


def _check_log_file(val: str) -> None:
if val == '':
return
if os.path.isabs(val):
raise cfgv.ValidationError(
f'log_file must be a relative path, got absolute path: {val!r}',
)
if os.path.normpath(val).startswith('..'):
raise cfgv.ValidationError(
f'log_file must not reference a parent directory: {val!r}',
)


check_log_file = cfgv.check_and(cfgv.check_string, _check_log_file)

HOOK_TYPES = (
'commit-msg',
'post-checkout',
Expand Down Expand Up @@ -258,7 +274,7 @@ def check(self, dct: dict[str, Any]) -> None:
cfgv.Optional('pass_filenames', cfgv.check_bool, True),
cfgv.Optional('description', cfgv.check_string, ''),
cfgv.Optional('language_version', cfgv.check_string, C.DEFAULT),
cfgv.Optional('log_file', cfgv.check_string, ''),
cfgv.Optional('log_file', check_log_file, ''),
cfgv.Optional('require_serial', cfgv.check_bool, False),
StagesMigration('stages', []),
cfgv.Optional('verbose', cfgv.check_bool, False),
Expand Down
20 changes: 20 additions & 0 deletions tests/clientlib_test.py
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@
import pytest

import pre_commit.constants as C
from pre_commit.clientlib import _check_log_file
from pre_commit.clientlib import check_type_tag
from pre_commit.clientlib import CONFIG_HOOK_DICT
from pre_commit.clientlib import CONFIG_REPO_DICT
Expand Down Expand Up @@ -605,3 +606,22 @@ def test_manifest_v5_forward_compat(tmp_path):
f'=====> pre-commit version 5 is required but version {C.VERSION} '
f'is installed. Perhaps run `pip install --upgrade pre-commit`.'
)


@pytest.mark.parametrize('value', ('output.log', 'logs/hook.log', ''))
def test_check_log_file_valid(value):
_check_log_file(value)


@pytest.mark.parametrize(
'value',
(
'/tmp/evil.log',
'/etc/cron.d/malicious',
'../../../etc/passwd',
'../outside.log',
),
)
def test_check_log_file_invalid(value):
with pytest.raises(cfgv.ValidationError):
_check_log_file(value)
Loading