PY-40179 Listen for Python Console connections at localhost

Do not bind to 0.0.0.0 as it is not secure.

GitOrigin-RevId: 43336b93eba0619806ca2f0662c4030b82824727
This commit is contained in:
Alexander Koshevoy
2020-01-30 13:40:58 +00:00
committed by intellij-monorepo-bot
parent a0e751cc6e
commit cc6da5ead1
3 changed files with 18 additions and 11 deletions
@@ -22,7 +22,9 @@ import java.util.concurrent.locks.Lock
import java.util.concurrent.locks.ReentrantLock
import kotlin.concurrent.withLock
class PydevConsoleCommunicationServer(project: Project, port: Int) : PydevConsoleCommunication(project) {
class PydevConsoleCommunicationServer(project: Project,
host: String,
port: Int) : PydevConsoleCommunication(project) {
private val serverTransport: TNettyServerTransport
/**
@@ -69,7 +71,7 @@ class PydevConsoleCommunicationServer(project: Project, port: Int) : PydevConsol
val serverHandler = createPythonConsoleFrontendHandler()
val serverProcessor = PythonConsoleFrontendService.Processor<PythonConsoleFrontendService.Iface>(serverHandler)
//noinspection IOResourceOpenedButNotSafelyClosed
serverTransport = TNettyServerTransport(port)
serverTransport = TNettyServerTransport(host, port)
server = TNettyServer(serverTransport, serverProcessor)
}
@@ -105,6 +105,12 @@ import static com.intellij.execution.runners.AbstractConsoleRunnerWithHistory.re
* @author traff, oleg
*/
public class PydevConsoleRunnerImpl implements PydevConsoleRunner {
/**
* The address that IDE uses to listen for incoming connections from Python
* Console script started in the "client mode".
*/
private static final String LOCALHOST = "localhost";
public static final String WORKING_DIR_AND_PYTHON_PATHS = "WORKING_DIR_AND_PYTHON_PATHS";
public static final String CONSOLE_START_COMMAND = "import sys; print('Python %s on %s' % (sys.version, sys.platform))\n" +
"sys.path.extend([" + WORKING_DIR_AND_PYTHON_PATHS + "])\n";
@@ -404,7 +410,7 @@ public class PydevConsoleRunnerImpl implements PydevConsoleRunner {
Map<String, String> envs = generalCommandLine.getEnvironment();
EncodingEnvironmentUtil.setLocaleEnvironmentIfMac(envs, generalCommandLine.getCharset());
PydevConsoleCommunicationServer communicationServer = new PydevConsoleCommunicationServer(myProject, port);
PydevConsoleCommunicationServer communicationServer = new PydevConsoleCommunicationServer(myProject, LOCALHOST, port);
myPydevConsoleCommunication = communicationServer;
try {
communicationServer.serve();
@@ -27,10 +27,11 @@ import java.util.concurrent.TimeUnit
import java.util.concurrent.atomic.AtomicBoolean
/**
*
* @param host the hostname to bind Python Console server at
* @param port the port to bind Python Console server at
*/
class TNettyServerTransport(port: Int) : TServerTransport() {
private val nettyServer: NettyServer = NettyServer(port)
class TNettyServerTransport(host: String, port: Int) : TServerTransport() {
private val nettyServer: NettyServer = NettyServer(host, port)
@Throws(TTransportException::class)
override fun listen() {
@@ -65,7 +66,7 @@ class TNettyServerTransport(port: Int) : TServerTransport() {
@Throws(InterruptedException::class)
fun getReverseTransport(): TTransport = nettyServer.takeReverseTransport()
private class NettyServer(val port: Int) {
private class NettyServer(val host: String, val port: Int) {
private val closed: AtomicBoolean = AtomicBoolean(false)
private val acceptQueue: BlockingQueue<TTransport> = LinkedBlockingQueue()
@@ -147,10 +148,8 @@ class TNettyServerTransport(port: Int) : TServerTransport() {
// Bind and start to accept incoming connections.
// We are ready to go now. What's left is to bind to the port and to
// start the server. Here, we bind to the port 8080 of all NICs (network
// interface cards) in the machine. You can now call the bind() method as
// many times as you want (with different bind addresses.)
b.bind(port).sync() // (7)
// start the server.
b.bind(host, port).sync() // (7)
LOG.debug("Running Netty server on $port")