From cc6da5ead1ae3300c4ff1d630929b82395f8c032 Mon Sep 17 00:00:00 2001 From: Alexander Koshevoy Date: Mon, 27 Jan 2020 11:44:28 +0300 Subject: [PATCH] PY-40179 Listen for Python Console connections at localhost Do not bind to 0.0.0.0 as it is not secure. GitOrigin-RevId: 43336b93eba0619806ca2f0662c4030b82824727 --- .../console/PydevConsoleCommunicationServer.kt | 6 ++++-- .../python/console/PydevConsoleRunnerImpl.java | 8 +++++++- .../transport/server/TNettyServerTransport.kt | 15 +++++++-------- 3 files changed, 18 insertions(+), 11 deletions(-) diff --git a/python/src/com/jetbrains/python/console/PydevConsoleCommunicationServer.kt b/python/src/com/jetbrains/python/console/PydevConsoleCommunicationServer.kt index 14f8fff99a5c..bd7df97e3a99 100644 --- a/python/src/com/jetbrains/python/console/PydevConsoleCommunicationServer.kt +++ b/python/src/com/jetbrains/python/console/PydevConsoleCommunicationServer.kt @@ -22,7 +22,9 @@ import java.util.concurrent.locks.Lock import java.util.concurrent.locks.ReentrantLock import kotlin.concurrent.withLock -class PydevConsoleCommunicationServer(project: Project, port: Int) : PydevConsoleCommunication(project) { +class PydevConsoleCommunicationServer(project: Project, + host: String, + port: Int) : PydevConsoleCommunication(project) { private val serverTransport: TNettyServerTransport /** @@ -69,7 +71,7 @@ class PydevConsoleCommunicationServer(project: Project, port: Int) : PydevConsol val serverHandler = createPythonConsoleFrontendHandler() val serverProcessor = PythonConsoleFrontendService.Processor(serverHandler) //noinspection IOResourceOpenedButNotSafelyClosed - serverTransport = TNettyServerTransport(port) + serverTransport = TNettyServerTransport(host, port) server = TNettyServer(serverTransport, serverProcessor) } diff --git a/python/src/com/jetbrains/python/console/PydevConsoleRunnerImpl.java b/python/src/com/jetbrains/python/console/PydevConsoleRunnerImpl.java index ea700cd11f5c..f8f4dfb47d7c 100644 --- a/python/src/com/jetbrains/python/console/PydevConsoleRunnerImpl.java +++ b/python/src/com/jetbrains/python/console/PydevConsoleRunnerImpl.java @@ -105,6 +105,12 @@ import static com.intellij.execution.runners.AbstractConsoleRunnerWithHistory.re * @author traff, oleg */ public class PydevConsoleRunnerImpl implements PydevConsoleRunner { + /** + * The address that IDE uses to listen for incoming connections from Python + * Console script started in the "client mode". + */ + private static final String LOCALHOST = "localhost"; + public static final String WORKING_DIR_AND_PYTHON_PATHS = "WORKING_DIR_AND_PYTHON_PATHS"; public static final String CONSOLE_START_COMMAND = "import sys; print('Python %s on %s' % (sys.version, sys.platform))\n" + "sys.path.extend([" + WORKING_DIR_AND_PYTHON_PATHS + "])\n"; @@ -404,7 +410,7 @@ public class PydevConsoleRunnerImpl implements PydevConsoleRunner { Map envs = generalCommandLine.getEnvironment(); EncodingEnvironmentUtil.setLocaleEnvironmentIfMac(envs, generalCommandLine.getCharset()); - PydevConsoleCommunicationServer communicationServer = new PydevConsoleCommunicationServer(myProject, port); + PydevConsoleCommunicationServer communicationServer = new PydevConsoleCommunicationServer(myProject, LOCALHOST, port); myPydevConsoleCommunication = communicationServer; try { communicationServer.serve(); diff --git a/python/src/com/jetbrains/python/console/transport/server/TNettyServerTransport.kt b/python/src/com/jetbrains/python/console/transport/server/TNettyServerTransport.kt index 413a83edf881..7f4807b3a87d 100644 --- a/python/src/com/jetbrains/python/console/transport/server/TNettyServerTransport.kt +++ b/python/src/com/jetbrains/python/console/transport/server/TNettyServerTransport.kt @@ -27,10 +27,11 @@ import java.util.concurrent.TimeUnit import java.util.concurrent.atomic.AtomicBoolean /** - * + * @param host the hostname to bind Python Console server at + * @param port the port to bind Python Console server at */ -class TNettyServerTransport(port: Int) : TServerTransport() { - private val nettyServer: NettyServer = NettyServer(port) +class TNettyServerTransport(host: String, port: Int) : TServerTransport() { + private val nettyServer: NettyServer = NettyServer(host, port) @Throws(TTransportException::class) override fun listen() { @@ -65,7 +66,7 @@ class TNettyServerTransport(port: Int) : TServerTransport() { @Throws(InterruptedException::class) fun getReverseTransport(): TTransport = nettyServer.takeReverseTransport() - private class NettyServer(val port: Int) { + private class NettyServer(val host: String, val port: Int) { private val closed: AtomicBoolean = AtomicBoolean(false) private val acceptQueue: BlockingQueue = LinkedBlockingQueue() @@ -147,10 +148,8 @@ class TNettyServerTransport(port: Int) : TServerTransport() { // Bind and start to accept incoming connections. // We are ready to go now. What's left is to bind to the port and to - // start the server. Here, we bind to the port 8080 of all NICs (network - // interface cards) in the machine. You can now call the bind() method as - // many times as you want (with different bind addresses.) - b.bind(port).sync() // (7) + // start the server. + b.bind(host, port).sync() // (7) LOG.debug("Running Netty server on $port")