mirror of
				https://github.com/MariaDB/server.git
				synced 2025-11-03 14:33:32 +03:00 
			
		
		
		
	- Implement --secure-file-priv=<dir> option that limits "load_file", "LOAD DATA" and "SELECT .. INTO OUTFILE" to work with files in specified dir. - Use above option for mysqld in mysql-test-run.pl
		
			
				
	
	
		
			99 lines
		
	
	
		
			2.6 KiB
		
	
	
	
		
			Plaintext
		
	
	
	
	
	
			
		
		
	
	
			99 lines
		
	
	
		
			2.6 KiB
		
	
	
	
		
			Plaintext
		
	
	
	
	
	
disable_query_log;
 | 
						|
-- source include/test_outfile.inc
 | 
						|
# Server are started in "var/master-data", so "../tmp" will be "var/tmp"
 | 
						|
eval set @tmpdir="../tmp";
 | 
						|
enable_query_log;
 | 
						|
-- source include/have_outfile.inc
 | 
						|
 | 
						|
#
 | 
						|
# test of into outfile|dumpfile
 | 
						|
#
 | 
						|
 | 
						|
--disable_warnings
 | 
						|
drop table if exists t1;
 | 
						|
--enable_warnings
 | 
						|
 | 
						|
create table t1 (`a` blob);
 | 
						|
insert into t1 values("hello world"),("Hello mars"),(NULL);
 | 
						|
disable_query_log;
 | 
						|
eval select * into outfile "../tmp/outfile-test.1" from t1;
 | 
						|
enable_query_log;
 | 
						|
select load_file(concat(@tmpdir,"/outfile-test.1"));
 | 
						|
disable_query_log;
 | 
						|
eval select * into dumpfile "../tmp/outfile-test.2" from t1 limit 1;
 | 
						|
enable_query_log;
 | 
						|
select load_file(concat(@tmpdir,"/outfile-test.2"));
 | 
						|
disable_query_log;
 | 
						|
eval select * into dumpfile "../tmp/outfile-test.3" from t1 where a is null;
 | 
						|
enable_query_log;
 | 
						|
select load_file(concat(@tmpdir,"/outfile-test.3"));
 | 
						|
 | 
						|
# the following should give errors
 | 
						|
 | 
						|
disable_query_log;
 | 
						|
--error 1086
 | 
						|
eval select * into outfile "../tmp/outfile-test.1" from t1;
 | 
						|
 | 
						|
--error 1086
 | 
						|
eval select * into dumpfile "../tmp/outfile-test.2" from t1;
 | 
						|
 | 
						|
--error 1086
 | 
						|
eval select * into dumpfile "../tmp/outfile-test.3" from t1;
 | 
						|
enable_query_log;
 | 
						|
select load_file(concat(@tmpdir,"/outfile-test.not-exist"));
 | 
						|
--exec rm $MYSQLTEST_VARDIR/tmp/outfile-test.1
 | 
						|
--exec rm $MYSQLTEST_VARDIR/tmp/outfile-test.2
 | 
						|
--exec rm $MYSQLTEST_VARDIR/tmp/outfile-test.3
 | 
						|
drop table t1;
 | 
						|
 | 
						|
# Bug#8191
 | 
						|
disable_query_log;
 | 
						|
eval select 1 into outfile "../tmp/outfile-test.4";
 | 
						|
enable_query_log;
 | 
						|
select load_file(concat(@tmpdir,"/outfile-test.4"));
 | 
						|
--exec rm $MYSQLTEST_VARDIR/tmp/outfile-test.4
 | 
						|
 | 
						|
#
 | 
						|
# Bug #5382: 'explain select into outfile' crashes the server
 | 
						|
#
 | 
						|
 | 
						|
CREATE TABLE t1 (a INT);
 | 
						|
EXPLAIN 
 | 
						|
  SELECT *
 | 
						|
  INTO OUTFILE '/tmp/t1.txt'
 | 
						|
  FIELDS TERMINATED BY ',' OPTIONALLY ENCLOSED BY '"' LINES TERMINATED BY '\r\n'
 | 
						|
  FROM t1;
 | 
						|
DROP TABLE t1;
 | 
						|
 | 
						|
# End of 4.1 tests
 | 
						|
 | 
						|
#
 | 
						|
# Bug#13202  SELECT * INTO OUTFILE ... FROM information_schema.schemata now fails
 | 
						|
#
 | 
						|
disable_query_log;
 | 
						|
eval SELECT * INTO OUTFILE "../tmp/outfile-test.4"
 | 
						|
FIELDS TERMINATED BY ',' OPTIONALLY ENCLOSED BY '"'
 | 
						|
FROM information_schema.schemata LIMIT 0, 5;
 | 
						|
# enable_query_log;
 | 
						|
--exec rm $MYSQLTEST_VARDIR/tmp/outfile-test.4
 | 
						|
 | 
						|
use information_schema;
 | 
						|
# disable_query_log;
 | 
						|
eval SELECT * INTO OUTFILE "../tmp/outfile-test.4"
 | 
						|
FIELDS TERMINATED BY ',' OPTIONALLY ENCLOSED BY '"'
 | 
						|
FROM schemata LIMIT 0, 5;
 | 
						|
enable_query_log;
 | 
						|
--exec rm $MYSQLTEST_VARDIR/tmp/outfile-test.4
 | 
						|
use test;
 | 
						|
 | 
						|
#
 | 
						|
# Bug#18628 mysql-test-run: security problem
 | 
						|
#
 | 
						|
# It should not be possible to write to a file outside of vardir
 | 
						|
create table t1(a int);
 | 
						|
--replace_result $MYSQL_TEST_DIR MYSQL_TEST_DIR
 | 
						|
--error 1290
 | 
						|
eval select * into outfile "$MYSQL_TEST_DIR/outfile-test1" from t1;
 | 
						|
drop table t1;
 | 
						|
 |