1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
|
# IVLE
# Copyright (C) 2007-2008 The University of Melbourne
#
# This program is free software; you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
# the Free Software Foundation; either version 2 of the License, or
# (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with this program; if not, write to the Free Software
# Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
# App: server
# Author: Tom Conway, Matt Giuca
# Date: 13/12/2007
# Serves content to the user (acting as a web server for students files).
# For most file types we just serve the static file, but
# for python files, we evaluate the python script inside
# our safe execution environment.
from common import (util, studpath)
import conf
import conf.app.server
import functools
import mimetypes
import os
import subprocess
def handle(req):
"""Handler for the Server application which serves pages."""
req.write_html_head_foot = False
# Get the username of the student whose work we are browsing, and the path
# on the local machine where the file is stored.
(user, path) = studpath.url_to_local(req.path)
if user is None:
# TODO: Nicer 404 message?
req.throw_error(req.HTTP_NOT_FOUND)
serve_file(req, user, path)
def serve_file(req, owner, filename):
"""Serves a file, using one of three possibilities: interpreting the file,
serving it directly, or denying it and returning a 403 Forbidden error.
No return value. Writes to req (possibly throwing a server error exception
using req.throw_error).
req: An IVLE request object.
owner: Username of the user who owns the file being served.
filename: Filename in the local file system.
"""
# First get the mime type of this file
# (Note that importing common.util has already initialised mime types)
(type, _) = mimetypes.guess_type(filename)
if type is None:
type = conf.app.server.default_mimetype
# If this type is to be interpreted
if type in conf.app.server.interpreters:
interp_name = conf.app.server.interpreters[type]
try:
# Get the interpreter function object
interp_object = interpreter_objects[interp_name]
except KeyError:
# TODO: Nicer 500 message (this is due to bad configuration in
# conf/app/server.py)
req.throw_error(req.HTTP_INTERNAL_SERVER_ERROR)
interpret_file(req, owner, filename, interp_object)
else:
# Otherwise, use the blacklist/whitelist to see if this file should be
# served or disallowed
if conf.app.server.blacklist_served_filetypes:
toserve = type not in conf.app.server.served_filetypes_blacklist
else:
toserve = type in conf.app.server.served_filetypes_whitelist
# toserve or not toserve
if not toserve:
# TODO: Nicer 403 message
req.throw_error(req.HTTP_FORBIDDEN)
else:
serve_file_direct(req, filename, type)
def interpret_file(req, owner, filename, interpreter):
"""Serves a file by interpreting it using one of IVLE's builtin
interpreters.
req: An IVLE request object.
owner: Username of the user who owns the file being served.
filename: Filename in the local file system.
interpreter: A function object to call.
"""
# Make sure the file exists (otherwise some interpreters may not actually
# complain).
# Don't test for execute permission, that will only be required for
# certain interpreters.
if not os.access(filename, os.R_OK):
req.throw_error(req.HTTP_NOT_FOUND)
return interpreter(filename, req)
def serve_file_direct(req, filename, type):
"""Serves a file by directly writing it out to the response.
req: An IVLE request object.
filename: Filename in the local file system.
type: String. Mime type to serve the file with.
"""
if not os.access(filename, os.R_OK):
req.throw_error(req.HTTP_NOT_FOUND)
req.content_type = type
req.sendfile(filename)
# Used to store mutable data
class Dummy:
pass
def execute_cgi(filename, studentprog, req):
"""
filename: Full path on the local system to the CGI wrapper program
being executed.
studentprog: Full path on the local system to the CGI student program
which will eventually be executed.
req: IVLE request object.
The called CGI wrapper application shall be called using popen and receive
the HTTP body on stdin. It shall receive the CGI environment variables to
its environment.
"""
# Get the student program's directory and execute it from that context.
slashloc = studentprog.rfind(os.sep)
if slashloc >= 0:
progdir = studentprog[0:slashloc]
else:
progdir = "/"
# TODO: Don't create a file if the body length is known to be 0
# Write the HTTP body to a temporary file so it can be passed as a *real*
# file to popen.
f = os.tmpfile()
body = req.read()
if body is not None:
f.write(body)
f.flush()
f.seek(0) # Rewind, for reading
pid = subprocess.Popen([filename, studentprog],
stdin=f, stdout=subprocess.PIPE, cwd=progdir)
# process_cgi_line: Reads a single line of CGI output and processes it.
# Prints to req, and also does fancy HTML warnings if Content-Type
# omitted.
cgiflags = Dummy()
cgiflags.got_cgi_header = False
cgiflags.started_cgi_body = False
cgiflags.wrote_html_warning = False
def process_cgi_line(line):
# FIXME? Issue with binary files (processing per-line?)
if cgiflags.started_cgi_body:
# FIXME: HTML escape text if wrote_html_warning
req.write(line)
else:
# Read CGI headers
if line.strip() == "" and cgiflags.got_cgi_header:
cgiflags.started_cgi_body = True
elif line.startswith("Content-Type:"):
req.content_type = line[13:].strip()
cgiflags.got_cgi_header = True
elif line.startswith("Location:"):
# TODO
cgiflags.got_cgi_header = True
elif line.startswith("Status:"):
# TODO
cgiflags.got_cgi_header = True
elif cgiflags.got_cgi_header:
# Invalid header
# TODO
req.write("Invalid header")
pass
else:
# Assume the user is not printing headers and give a warning
# about that.
# User program did not print header.
# Make a fancy HTML warning for them.
req.content_type = "text/html"
req.write("""<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
"http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head>
<meta http-equiv="Content-Type"
content="text/html; charset=utf-8" />
</head>
<body style="margin: 0; padding: 0; font-family: sans;">
<div style="background-color: #faa; border-bottom: 1px solid black;
padding: 8px;">
<p><strong>Warning</strong>: You did not print a "Content-Type" header.
CGI requires you to print some content type. You may wish to try:</p>
<pre style="margin-left: 1em">Content-Type: text/html</pre>
</div>
<div style="margin: 8px;">
<pre>
""")
cgiflags.got_cgi_header = True
cgiflags.wrote_html_warning = True
cgiflags.started_cgi_body = True
req.write(line)
# Read from the process's stdout into req
for line in pid.stdout:
process_cgi_line(line)
# If we wrote an HTML warning header, write the footer
if cgiflags.wrote_html_warning:
req.write("""</pre>
</div>
</body>
</html>""")
# Mapping of interpreter names (as given in conf/app/server.py) to
# interpreter functions.
interpreter_objects = {
'cgi-python'
: functools.partial(execute_cgi, '/usr/bin/python'),
# Should also have:
# cgi-generic
# python-server-page
}
|