mirror of
https://github.com/ocrmypdf/OCRmyPDF.git
synced 2026-08-01 08:00:54 -04:00
Writing the output PDF to stdout (ocrmypdf in.pdf -) previously relied on an honor system: no in-process code -- third-party libraries, plugins, or stray print() calls -- was supposed to write to stdout, enforced only indirectly. A single accidental write to fd 1 would silently corrupt the output PDF. Enforce this at the OS level. At CLI startup, before plugins load or any worker process/thread starts, save the real stdout via os.dup() and point fd 1 at stderr, so stray writes are diverted to stderr while only the final "produce the PDF" step writes to the preserved descriptor. Exposed as the opt-in public API function configure_stdout_protection(), mirroring configure_logging(); it is not enabled inside ocr() so in-process library users keep their own stdout. Also fix check_requested_output_file() to test the preserved real stdout for tty-ness, since after the redirect sys.stdout reports stderr's status. Fold unreleased v17.7.2 notes into v17.8.0.
92 lines
2.8 KiB
Python
92 lines
2.8 KiB
Python
# SPDX-FileCopyrightText: 2022 James R. Barlow
|
|
# SPDX-License-Identifier: MPL-2.0
|
|
|
|
from __future__ import annotations
|
|
|
|
import os
|
|
from subprocess import DEVNULL, PIPE, run
|
|
|
|
import pytest
|
|
|
|
from ocrmypdf.helpers import check_pdf
|
|
|
|
from .conftest import run_ocrmypdf
|
|
|
|
|
|
def test_stdin(ocrmypdf_exec, resources, outpdf):
|
|
input_file = str(resources / 'francais.pdf')
|
|
output_file = str(outpdf)
|
|
|
|
# Runs: ocrmypdf - output.pdf < testfile.pdf
|
|
with open(input_file, 'rb') as input_stream:
|
|
p_args = ocrmypdf_exec + [
|
|
'-',
|
|
output_file,
|
|
'--plugin',
|
|
'tests/plugins/tesseract_noop.py',
|
|
]
|
|
run(p_args, capture_output=True, stdin=input_stream, check=True)
|
|
|
|
|
|
def test_stdout(ocrmypdf_exec, resources, outpdf):
|
|
if 'COV_CORE_DATAFILE' in os.environ:
|
|
pytest.skip("Coverage uses stdout")
|
|
|
|
input_file = str(resources / 'francais.pdf')
|
|
output_file = str(outpdf)
|
|
|
|
# Runs: ocrmypdf francais.pdf - > test_stdout.pdf
|
|
with open(output_file, 'wb') as output_stream:
|
|
p_args = ocrmypdf_exec + [
|
|
input_file,
|
|
'-',
|
|
'--plugin',
|
|
'tests/plugins/tesseract_noop.py',
|
|
]
|
|
run(p_args, stdout=output_stream, stderr=PIPE, stdin=DEVNULL, check=True)
|
|
|
|
assert check_pdf(output_file)
|
|
|
|
|
|
def test_stdout_protected_from_pollution(ocrmypdf_exec, resources, outpdf):
|
|
if 'COV_CORE_DATAFILE' in os.environ:
|
|
pytest.skip("Coverage uses stdout")
|
|
|
|
input_file = str(resources / 'francais.pdf')
|
|
output_file = str(outpdf)
|
|
|
|
# A plugin deliberately writes garbage to stdout during the run. With stdout
|
|
# protection active, that garbage must be diverted to stderr and never reach
|
|
# the PDF we are writing to stdout.
|
|
with open(output_file, 'wb') as output_stream:
|
|
p_args = ocrmypdf_exec + [
|
|
input_file,
|
|
'-',
|
|
'--plugin',
|
|
'tests/plugins/tesseract_noop.py',
|
|
'--plugin',
|
|
'tests/plugins/stdout_polluter.py',
|
|
]
|
|
p = run(p_args, stdout=output_stream, stderr=PIPE, stdin=DEVNULL, check=True)
|
|
|
|
assert check_pdf(output_file), "PDF on stdout was corrupted"
|
|
with open(output_file, 'rb') as f:
|
|
assert b'POLLUTION' not in f.read(), "pollution leaked into the PDF"
|
|
assert b'POLLUTION' in p.stderr, "pollution was not diverted to stderr"
|
|
|
|
|
|
@pytest.mark.skipif(os.name == 'nt', reason='Windows does not support /dev/null')
|
|
def test_dev_null(resources):
|
|
if 'COV_CORE_DATAFILE' in os.environ:
|
|
pytest.skip("Coverage uses stdout")
|
|
|
|
p = run_ocrmypdf(
|
|
resources / 'trivial.pdf',
|
|
os.devnull,
|
|
'--force-ocr',
|
|
'--plugin',
|
|
'tests/plugins/tesseract_noop.py',
|
|
)
|
|
assert p.returncode == 0, "could not send output to /dev/null"
|
|
assert len(p.stdout) == 0, "wrote to stdout"
|