aboutsummaryrefslogtreecommitdiffhomepage
path: root/scripts/linters/src/Linters/NoDirectEnvAccess.php
blob: 5276279ab02972edff65b400c16d9514ca98adfc (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
<?php

declare(strict_types=1);

namespace Shirabe\Lint\Linters;

use Shirabe\Lint\Linter;
use Shirabe\Lint\Support\FileFinder;
use Shirabe\Lint\Support\Paths;

final class NoDirectEnvAccess implements Linter
{
    private const BANNED_ENV_FUNCTIONS = ['var', 'var_os', 'vars', 'vars_os', 'set_var', 'remove_var'];

    public function name(): string
    {
        return 'no_direct_env_access';
    }

    public function failureIntro(): string
    {
        return "Found direct access to the process environment.\n"
            . "PHP reads and writes environment variables through three storages that are not kept in\n"
            . "sync with each other, and each has its own counterpart in `shirabe_php_shim`:\n"
            . "`getenv`/`getenv_all`/`putenv`/`putenv_clear`, `PHP_ENV`, and `PHP_SERVER`.\n"
            . 'Port whichever one the PHP source uses; see `docs/dev/env-vars-porting.md`:';
    }

    public function check(string $rootDir, array $excludes): array
    {
        $errors = [];

        foreach (FileFinder::rustFiles($rootDir) as $path) {
            $relative = Paths::relativeTo($rootDir, $path);
            if (in_array($relative, $excludes, true)) {
                continue;
            }

            array_push($errors, ...$this->findEnvAccesses($path, $relative));
        }

        return $errors;
    }

    /** @return list<string> */
    private function findEnvAccesses(string $path, string $relative): array
    {
        $errors = [];
        $names = implode('|', self::BANNED_ENV_FUNCTIONS);

        foreach (file($path) as $idx => $raw) {
            $code = explode('//', $raw, 2)[0];

            if (preg_match_all("/\bstd::env::({$names})\b/", $code, $m)) {
                foreach ($m[1] as $name) {
                    $errors[] = "{$relative}:" . ($idx + 1) . ": use of `std::env::{$name}`";
                }
            }

            if (preg_match_all('/\bstd::env::\{([^}]*)\}/', $code, $m)) {
                foreach ($m[1] as $group) {
                    foreach (explode(',', $group) as $entry) {
                        $name = preg_split('/\s+as\s+/', trim($entry))[0];
                        if (!in_array($name, self::BANNED_ENV_FUNCTIONS, true)) {
                            continue;
                        }
                        $errors[] = "{$relative}:" . ($idx + 1) . ": import of `std::env::{$name}`";
                    }
                }
            }
        }

        return array_values(array_unique($errors));
    }
}