wikimedia /
mediawiki
This project does not seem to handle request data directly as such no vulnerable execution paths were found.
include, or for example
via PHP's auto-loading mechanism.
These results are based on our legacy PHP analysis, consider migrating to our new PHP analysis engine instead. Learn more
| 1 | <?php |
||
| 2 | /** |
||
| 3 | * Send SQL queries from the specified file to the database, performing |
||
| 4 | * variable replacement along the way. |
||
| 5 | * |
||
| 6 | * This program is free software; you can redistribute it and/or modify |
||
| 7 | * it under the terms of the GNU General Public License as published by |
||
| 8 | * the Free Software Foundation; either version 2 of the License, or |
||
| 9 | * (at your option) any later version. |
||
| 10 | * |
||
| 11 | * This program is distributed in the hope that it will be useful, |
||
| 12 | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
||
| 13 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
||
| 14 | * GNU General Public License for more details. |
||
| 15 | * |
||
| 16 | * You should have received a copy of the GNU General Public License along |
||
| 17 | * with this program; if not, write to the Free Software Foundation, Inc., |
||
| 18 | * 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA. |
||
| 19 | * http://www.gnu.org/copyleft/gpl.html |
||
| 20 | * |
||
| 21 | * @file |
||
| 22 | * @ingroup Maintenance |
||
| 23 | */ |
||
| 24 | |||
| 25 | require_once __DIR__ . '/Maintenance.php'; |
||
| 26 | |||
| 27 | /** |
||
| 28 | * Maintenance script that sends SQL queries from the specified file to the database. |
||
| 29 | * |
||
| 30 | * @ingroup Maintenance |
||
| 31 | */ |
||
| 32 | class MwSql extends Maintenance { |
||
| 33 | public function __construct() { |
||
| 34 | parent::__construct(); |
||
| 35 | $this->addDescription( 'Send SQL queries to a MediaWiki database. ' . |
||
| 36 | 'Takes a file name containing SQL as argument or runs interactively.' ); |
||
| 37 | $this->addOption( 'query', |
||
| 38 | 'Run a single query instead of running interactively', false, true ); |
||
| 39 | $this->addOption( 'cluster', 'Use an external cluster by name', false, true ); |
||
| 40 | $this->addOption( 'wikidb', |
||
| 41 | 'The database wiki ID to use if not the current one', false, true ); |
||
| 42 | $this->addOption( 'replicadb', |
||
| 43 | 'Replica DB server to use instead of the master DB (can be "any")', false, true ); |
||
| 44 | } |
||
| 45 | |||
| 46 | public function execute() { |
||
|
0 ignored issues
–
show
|
|||
| 47 | global $IP; |
||
| 48 | |||
| 49 | // We wan't to allow "" for the wikidb, meaning don't call select_db() |
||
| 50 | $wiki = $this->hasOption( 'wikidb' ) ? $this->getOption( 'wikidb' ) : false; |
||
| 51 | // Get the appropriate load balancer (for this wiki) |
||
| 52 | if ( $this->hasOption( 'cluster' ) ) { |
||
| 53 | $lb = wfGetLBFactory()->getExternalLB( $this->getOption( 'cluster' ), $wiki ); |
||
| 54 | } else { |
||
| 55 | $lb = wfGetLB( $wiki ); |
||
| 56 | } |
||
| 57 | // Figure out which server to use |
||
| 58 | $replicaDB = $this->getOption( 'replicadb', $this->getOption( 'slave', '' ) ); |
||
| 59 | if ( $replicaDB === 'any' ) { |
||
| 60 | $index = DB_REPLICA; |
||
| 61 | } elseif ( $replicaDB != '' ) { |
||
| 62 | $index = null; |
||
| 63 | $serverCount = $lb->getServerCount(); |
||
| 64 | for ( $i = 0; $i < $serverCount; ++$i ) { |
||
| 65 | if ( $lb->getServerName( $i ) === $replicaDB ) { |
||
| 66 | $index = $i; |
||
| 67 | break; |
||
| 68 | } |
||
| 69 | } |
||
| 70 | if ( $index === null ) { |
||
| 71 | $this->error( "No replica DB server configured with the name '$replicaDB'.", 1 ); |
||
| 72 | } |
||
| 73 | } else { |
||
| 74 | $index = DB_MASTER; |
||
| 75 | } |
||
| 76 | |||
| 77 | /** @var Database $db DB handle for the appropriate cluster/wiki */ |
||
| 78 | $db = $lb->getConnection( $index, [], $wiki ); |
||
| 79 | if ( $replicaDB != '' && $db->getLBInfo( 'master' ) !== null ) { |
||
| 80 | $this->error( "The server selected ({$db->getServer()}) is not a replica DB.", 1 ); |
||
| 81 | } |
||
| 82 | |||
| 83 | if ( $index === DB_MASTER ) { |
||
| 84 | $updater = DatabaseUpdater::newForDB( $db, true, $this ); |
||
| 85 | $db->setSchemaVars( $updater->getSchemaVars() ); |
||
| 86 | } |
||
| 87 | |||
| 88 | if ( $this->hasArg( 0 ) ) { |
||
| 89 | $file = fopen( $this->getArg( 0 ), 'r' ); |
||
| 90 | if ( !$file ) { |
||
| 91 | $this->error( "Unable to open input file", true ); |
||
| 92 | } |
||
| 93 | |||
| 94 | $error = $db->sourceStream( $file, null, [ $this, 'sqlPrintResult' ] ); |
||
| 95 | if ( $error !== true ) { |
||
| 96 | $this->error( $error, true ); |
||
| 97 | } else { |
||
| 98 | exit( 0 ); |
||
| 99 | } |
||
| 100 | } |
||
| 101 | |||
| 102 | if ( $this->hasOption( 'query' ) ) { |
||
| 103 | $query = $this->getOption( 'query' ); |
||
| 104 | $this->sqlDoQuery( $db, $query, /* dieOnError */ true ); |
||
| 105 | wfWaitForSlaves(); |
||
| 106 | return; |
||
| 107 | } |
||
| 108 | |||
| 109 | if ( |
||
| 110 | function_exists( 'readline_add_history' ) && |
||
| 111 | Maintenance::posix_isatty( 0 /*STDIN*/ ) |
||
| 112 | ) { |
||
| 113 | $historyFile = isset( $_ENV['HOME'] ) ? |
||
| 114 | "{$_ENV['HOME']}/.mwsql_history" : "$IP/maintenance/.mwsql_history"; |
||
| 115 | readline_read_history( $historyFile ); |
||
| 116 | } else { |
||
| 117 | $historyFile = null; |
||
| 118 | } |
||
| 119 | |||
| 120 | $wholeLine = ''; |
||
| 121 | $newPrompt = '> '; |
||
| 122 | $prompt = $newPrompt; |
||
| 123 | $doDie = !Maintenance::posix_isatty( 0 ); |
||
| 124 | while ( ( $line = Maintenance::readconsole( $prompt ) ) !== false ) { |
||
| 125 | if ( !$line ) { |
||
| 126 | # User simply pressed return key |
||
| 127 | continue; |
||
| 128 | } |
||
| 129 | $done = $db->streamStatementEnd( $wholeLine, $line ); |
||
| 130 | |||
| 131 | $wholeLine .= $line; |
||
| 132 | |||
| 133 | if ( !$done ) { |
||
| 134 | $wholeLine .= ' '; |
||
| 135 | $prompt = ' -> '; |
||
| 136 | continue; |
||
| 137 | } |
||
| 138 | if ( $historyFile ) { |
||
| 139 | # Delimiter is eated by streamStatementEnd, we add it |
||
| 140 | # up in the history (bug 37020) |
||
| 141 | readline_add_history( $wholeLine . ';' ); |
||
| 142 | readline_write_history( $historyFile ); |
||
| 143 | } |
||
| 144 | $this->sqlDoQuery( $db, $wholeLine, $doDie ); |
||
| 145 | $prompt = $newPrompt; |
||
| 146 | $wholeLine = ''; |
||
| 147 | } |
||
| 148 | wfWaitForSlaves(); |
||
| 149 | } |
||
| 150 | |||
| 151 | protected function sqlDoQuery( IDatabase $db, $line, $dieOnError ) { |
||
| 152 | try { |
||
| 153 | $res = $db->query( $line ); |
||
| 154 | $this->sqlPrintResult( $res, $db ); |
||
| 155 | } catch ( DBQueryError $e ) { |
||
| 156 | $this->error( $e, $dieOnError ); |
||
| 157 | } |
||
| 158 | } |
||
| 159 | |||
| 160 | /** |
||
| 161 | * Print the results, callback for $db->sourceStream() |
||
| 162 | * @param ResultWrapper $res The results object |
||
| 163 | * @param IDatabase $db |
||
| 164 | */ |
||
| 165 | public function sqlPrintResult( $res, $db ) { |
||
| 166 | if ( !$res ) { |
||
| 167 | // Do nothing |
||
| 168 | return; |
||
| 169 | } elseif ( is_object( $res ) && $res->numRows() ) { |
||
| 170 | foreach ( $res as $row ) { |
||
| 171 | $this->output( print_r( $row, true ) ); |
||
| 172 | } |
||
| 173 | } else { |
||
| 174 | $affected = $db->affectedRows(); |
||
| 175 | $this->output( "Query OK, $affected row(s) affected\n" ); |
||
| 176 | } |
||
| 177 | } |
||
| 178 | |||
| 179 | /** |
||
| 180 | * @return int DB_TYPE constant |
||
| 181 | */ |
||
| 182 | public function getDbType() { |
||
| 183 | return Maintenance::DB_ADMIN; |
||
| 184 | } |
||
| 185 | } |
||
| 186 | |||
| 187 | $maintClass = "MwSql"; |
||
| 188 | require_once RUN_MAINTENANCE_IF_MAIN; |
||
| 189 |
Instead of super-globals, we recommend to explicitly inject the dependencies of your class. This makes your code less dependent on global state and it becomes generally more testable: