Files
nltk--nltk/nltk/test/unit/test_weka_security.py
wehub-resource-sync 3454a55636
cffconvert / validate (push) Has been cancelled
ci-workflow / pre-commit (push) Has been cancelled
ci-workflow / Minimal NLTK Download Test (macos-latest) (push) Has been cancelled
ci-workflow / Minimal NLTK Download Test (ubuntu-latest) (push) Has been cancelled
ci-workflow / Minimal NLTK Download Test (windows-latest) (push) Has been cancelled
ci-workflow / Python 3.10 on macos-latest (push) Has been cancelled
ci-workflow / Python 3.11 on macos-latest (push) Has been cancelled
ci-workflow / Python 3.12 on macos-latest (push) Has been cancelled
ci-workflow / Python 3.13 on macos-latest (push) Has been cancelled
ci-workflow / Python 3.14 on macos-latest (push) Has been cancelled
ci-workflow / Python 3.14t on macos-latest (push) Has been cancelled
ci-workflow / Python 3.10 on ubuntu-latest (push) Has been cancelled
ci-workflow / Python 3.11 on ubuntu-latest (push) Has been cancelled
ci-workflow / Python 3.12 on ubuntu-latest (push) Has been cancelled
ci-workflow / Python 3.13 on ubuntu-latest (push) Has been cancelled
ci-workflow / Python 3.14 on ubuntu-latest (push) Has been cancelled
ci-workflow / Python 3.14t on ubuntu-latest (push) Has been cancelled
ci-workflow / Python 3.10 on windows-latest (push) Has been cancelled
ci-workflow / Python 3.11 on windows-latest (push) Has been cancelled
ci-workflow / Python 3.12 on windows-latest (push) Has been cancelled
ci-workflow / Python 3.13 on windows-latest (push) Has been cancelled
ci-workflow / Python 3.14 on windows-latest (push) Has been cancelled
chore: import upstream snapshot with attribution
2026-07-13 12:46:15 +08:00

55 lines
2.2 KiB
Python

"""Regression tests for the unverified-jar / search-path fix in the Weka wrapper.
``config_weka`` searched for ``weka.jar`` with the current working directory (".")
listed first in ``_weka_search``. A ``./weka.jar`` planted in the CWD by an
attacker would be selected over a system install and run via
``java -cp ./weka.jar weka.classifiers.bayes.NaiveBayes ...`` with no integrity
check -- arbitrary code execution (CWE-494, reachable via an untrusted search
path, CWE-426). The CWD is no longer searched; ``WEKAHOME`` or an explicit
``config_weka(classpath=...)`` must be used.
"""
import pytest
import nltk.classify.weka as weka
# Capture the real default search path at import time, before the autouse
# fixture neutralises it, so the regression assertion below can check it.
_DEFAULT_WEKA_SEARCH = list(weka._weka_search)
@pytest.fixture(autouse=True)
def _isolate(monkeypatch):
# config_weka() calls config_java() first; stub it so the search logic runs
# without a JVM, and reset the cached classpath around each test.
monkeypatch.setattr(weka, "config_java", lambda *a, **k: None)
monkeypatch.setattr(weka, "_weka_classpath", None)
# Neutralise the system search path so the outcome can't depend on a
# host-installed weka.jar (e.g. /usr/share/weka) on the test runner.
monkeypatch.setattr(weka, "_weka_search", [])
monkeypatch.delenv("WEKAHOME", raising=False)
def test_cwd_not_in_default_search_path():
"""The CWD must not be part of the default weka.jar search path."""
assert "." not in _DEFAULT_WEKA_SEARCH
assert "" not in _DEFAULT_WEKA_SEARCH
def test_cwd_weka_jar_is_not_picked_up(tmp_path, monkeypatch):
"""A ./weka.jar in the CWD must not be auto-selected."""
monkeypatch.chdir(tmp_path)
(tmp_path / "weka.jar").write_bytes(b"") # attacker-planted in the CWD
with pytest.raises(LookupError):
weka.config_weka()
assert weka._weka_classpath is None
def test_explicit_classpath_still_used(tmp_path):
"""An explicit classpath argument is still honoured."""
jar = tmp_path / "weka.jar"
jar.write_bytes(b"")
weka.config_weka(classpath=str(jar))
assert weka._weka_classpath == str(jar)