Enable some more bandit checks (#30857)

* Enable B108 (hardcoded tmp dir), address findings

* Enable B602 (subprocess popen with shell), address findings

* Enable B604 (start process with shell), address findings

* Enable B306 (mktemp), B307 (eval), and B325 (tempnam), no issues to address
This commit is contained in:
Ville Skyttä
2020-01-20 18:44:55 +02:00
committed by GitHub
parent 6cf20fc7fa
commit 5e2ba2eb77
21 changed files with 110 additions and 91 deletions
@@ -91,7 +91,7 @@ class CommandCover(CoverDevice):
"""Execute the actual commands."""
_LOGGER.info("Running command: %s", command)
success = subprocess.call(command, shell=True) == 0
success = subprocess.call(command, shell=True) == 0 # nosec # shell by design
if not success:
_LOGGER.error("Command failed: %s", command)
@@ -104,7 +104,9 @@ class CommandCover(CoverDevice):
_LOGGER.info("Running state command: %s", command)
try:
return_value = subprocess.check_output(command, shell=True)
return_value = subprocess.check_output(
command, shell=True # nosec # shell by design
)
return return_value.strip().decode("utf-8")
except subprocess.CalledProcessError:
_LOGGER.error("Command failed: %s", command)
@@ -33,7 +33,10 @@ class CommandLineNotificationService(BaseNotificationService):
"""Send a message to a command line."""
try:
proc = subprocess.Popen(
self.command, universal_newlines=True, stdin=subprocess.PIPE, shell=True
self.command,
universal_newlines=True,
stdin=subprocess.PIPE,
shell=True, # nosec # shell by design
)
proc.communicate(input=message)
if proc.returncode != 0:
@@ -168,15 +168,14 @@ class CommandSensorData:
if rendered_args == args:
# No template used. default behavior
shell = True
pass
else:
# Template used. Construct the string used in the shell
command = str(" ".join([prog] + shlex.split(rendered_args)))
shell = True
try:
_LOGGER.debug("Running command: %s", command)
return_value = subprocess.check_output(
command, shell=shell, timeout=self.timeout
command, shell=True, timeout=self.timeout # nosec # shell by design
)
self.value = return_value.strip().decode("utf-8")
except subprocess.CalledProcessError:
@@ -94,7 +94,7 @@ class CommandSwitch(SwitchDevice):
"""Execute the actual commands."""
_LOGGER.info("Running command: %s", command)
success = subprocess.call(command, shell=True) == 0
success = subprocess.call(command, shell=True) == 0 # nosec # shell by design
if not success:
_LOGGER.error("Command failed: %s", command)
@@ -107,7 +107,9 @@ class CommandSwitch(SwitchDevice):
_LOGGER.info("Running state command: %s", command)
try:
return_value = subprocess.check_output(command, shell=True)
return_value = subprocess.check_output(
command, shell=True # nosec # shell by design
)
return return_value.strip().decode("utf-8")
except subprocess.CalledProcessError:
_LOGGER.error("Command failed: %s", command)
@@ -116,7 +118,7 @@ class CommandSwitch(SwitchDevice):
def _query_state_code(command):
"""Execute state command for return code."""
_LOGGER.info("Running state command: %s", command)
return subprocess.call(command, shell=True) == 0
return subprocess.call(command, shell=True) == 0 # nosec # shell by design
@property
def should_poll(self):
+2 -1
View File
@@ -10,6 +10,7 @@ import voluptuous as vol
from homeassistant.const import CONF_NAME, CONF_PASSWORD, CONF_USERNAME
from homeassistant.helpers import discovery
import homeassistant.helpers.config_validation as cv
from homeassistant.helpers.storage import STORAGE_DIR
_LOGGER = logging.getLogger(__name__)
@@ -54,7 +55,7 @@ CONFIG_SCHEMA = vol.Schema(
def setup(hass, config):
"""Create the ViCare component."""
conf = config[DOMAIN]
params = {"token_file": "/tmp/vicare_token.save"}
params = {"token_file": hass.config.path(STORAGE_DIR, "vicare_token.save")}
if conf.get(CONF_CIRCUIT) is not None:
params["circuit"] = conf[CONF_CIRCUIT]
+1 -1
View File
@@ -34,7 +34,7 @@ def x10_command(command):
def get_unit_status(code):
"""Get on/off status for given unit."""
output = check_output(f"heyu onstate {code}", shell=True)
output = check_output(["heyu", "onstate", code])
return int(output.decode("utf-8")[0])
+1 -1
View File
@@ -25,7 +25,7 @@ _LOGGER = logging.getLogger(__name__)
DEFAULT_BRAND = "YI Home Camera"
DEFAULT_PASSWORD = ""
DEFAULT_PATH = "/tmp/sd/record"
DEFAULT_PATH = "/tmp/sd/record" # nosec
DEFAULT_PORT = 21
DEFAULT_USERNAME = "root"
DEFAULT_ARGUMENTS = "-pred 1"