2014-08-14 16:20:19 +00:00
|
|
|
# This list was intially created by analyzing the last three months (51
|
|
|
|
# modules) committed to Metasploit Framework. Many, many older modules
|
|
|
|
# will have offenses, but this should at least provide a baseline for
|
|
|
|
# new modules.
|
|
|
|
#
|
|
|
|
# Updates to this file should include a 'Description' parameter for any
|
|
|
|
# explaination needed.
|
|
|
|
|
|
|
|
# inherit_from: .rubocop_todo.yml
|
|
|
|
|
2017-08-02 11:18:02 +00:00
|
|
|
AllCops:
|
|
|
|
TargetRubyVersion: 2.2
|
|
|
|
|
2014-11-11 21:06:43 +00:00
|
|
|
Metrics/ClassLength:
|
2014-08-14 16:20:19 +00:00
|
|
|
Description: 'Most Metasploit modules are quite large. This is ok.'
|
|
|
|
Enabled: true
|
|
|
|
Exclude:
|
|
|
|
- 'modules/**/*'
|
|
|
|
|
2018-05-07 19:02:22 +00:00
|
|
|
Style/ClassAndModuleChildren:
|
|
|
|
Enabled: false
|
|
|
|
Description: 'Forced nesting is harmful for grepping and general code comprehension'
|
|
|
|
|
2017-07-24 13:15:35 +00:00
|
|
|
Metrics/AbcSize:
|
|
|
|
Enabled: false
|
|
|
|
Description: 'This is often a red-herring'
|
|
|
|
|
|
|
|
Metrics/CyclomaticComplexity:
|
|
|
|
Enabled: false
|
|
|
|
Description: 'This is often a red-herring'
|
|
|
|
|
|
|
|
Metrics/PerceivedComplexity:
|
|
|
|
Enabled: false
|
|
|
|
Description: 'This is often a red-herring'
|
|
|
|
|
2018-05-07 15:19:15 +00:00
|
|
|
Style/TernaryParentheses:
|
|
|
|
Enabled: false
|
|
|
|
Description: 'This outright produces bugs'
|
|
|
|
|
2017-07-24 13:15:35 +00:00
|
|
|
Style/FrozenStringLiteralComment:
|
|
|
|
Enabled: false
|
|
|
|
Description: 'We cannot support this yet without a lot of things breaking'
|
|
|
|
|
2017-08-14 03:29:29 +00:00
|
|
|
Style/RedundantReturn:
|
|
|
|
Description: 'This often looks weird when mixed with actual returns, and hurts nothing'
|
|
|
|
Enabled: false
|
|
|
|
|
2018-05-07 19:02:22 +00:00
|
|
|
Style/NumericPredicate:
|
|
|
|
Description: 'This adds no efficiency nor space saving'
|
|
|
|
Enabled: false
|
|
|
|
|
2014-08-14 16:20:19 +00:00
|
|
|
Style/Documentation:
|
|
|
|
Enabled: true
|
|
|
|
Description: 'Most Metasploit modules do not have class documentation.'
|
|
|
|
Exclude:
|
|
|
|
- 'modules/**/*'
|
|
|
|
|
2017-08-14 03:29:29 +00:00
|
|
|
Layout/IndentHeredoc:
|
2017-08-01 19:44:22 +00:00
|
|
|
Enabled: false
|
|
|
|
Description: 'We need to leave this disabled for Ruby 2.2 compat, remove in 2018'
|
|
|
|
|
|
|
|
Style/GuardClause:
|
|
|
|
Enabled: false
|
|
|
|
Description: 'This often introduces bugs in tested code'
|
|
|
|
|
2017-08-03 05:26:04 +00:00
|
|
|
Style/NegatedIf:
|
|
|
|
Enabled: false
|
|
|
|
Description: 'This often introduces bugs in tested code'
|
|
|
|
|
2017-08-01 20:19:13 +00:00
|
|
|
Style/ConditionalAssignment:
|
|
|
|
Enabled: false
|
|
|
|
Description: 'This is confusing for folks coming from other languages'
|
|
|
|
|
2014-08-14 16:20:19 +00:00
|
|
|
Style/Encoding:
|
|
|
|
Enabled: true
|
|
|
|
Description: 'We prefer binary to UTF-8.'
|
|
|
|
EnforcedStyle: 'when_needed'
|
|
|
|
|
2014-11-11 21:06:43 +00:00
|
|
|
Metrics/LineLength:
|
2014-08-14 16:20:19 +00:00
|
|
|
Description: >-
|
|
|
|
Metasploit modules often pattern match against very
|
|
|
|
long strings when identifying targets.
|
|
|
|
Enabled: true
|
|
|
|
Max: 180
|
|
|
|
|
2014-11-11 21:06:43 +00:00
|
|
|
Metrics/MethodLength:
|
2014-08-14 16:20:19 +00:00
|
|
|
Enabled: true
|
|
|
|
Description: >-
|
|
|
|
While the style guide suggests 10 lines, exploit definitions
|
|
|
|
often exceed 200 lines.
|
|
|
|
Max: 300
|
|
|
|
|
2014-07-21 21:22:15 +00:00
|
|
|
# Basically everything in metasploit needs binary encoding, not UTF-8.
|
|
|
|
# Disable this here and enforce it through msftidy
|
|
|
|
Style/Encoding:
|
|
|
|
Enabled: false
|
|
|
|
|
2014-11-11 21:06:43 +00:00
|
|
|
# %q() is super useful for long strings split over multiple lines and
|
|
|
|
# is very common in module constructors for things like descriptions
|
|
|
|
Style/UnneededPercentQ:
|
|
|
|
Enabled: false
|
|
|
|
|
2014-08-14 16:20:19 +00:00
|
|
|
Style/NumericLiterals:
|
|
|
|
Enabled: false
|
|
|
|
Description: 'This often hurts readability for exploit-ish code.'
|
|
|
|
|
2018-03-14 19:17:37 +00:00
|
|
|
Layout/AlignParameters:
|
|
|
|
Enabled: true
|
|
|
|
EnforcedStyle: 'with_fixed_indentation'
|
|
|
|
Description: 'initialize method of every module has fixed indentation for Name, Description, etc'
|
2014-08-14 16:20:19 +00:00
|
|
|
|
|
|
|
Style/StringLiterals:
|
|
|
|
Enabled: false
|
|
|
|
Description: 'Single vs double quote fights are largely unproductive.'
|
|
|
|
|
|
|
|
Style/WordArray:
|
|
|
|
Enabled: false
|
2014-07-18 17:26:55 +00:00
|
|
|
Description: 'Metasploit prefers consistent use of []'
|
|
|
|
|
2018-05-07 19:02:22 +00:00
|
|
|
Style/IfUnlessModifier:
|
|
|
|
Enabled: false
|
|
|
|
Description: 'This style might save a couple of lines, but often makes code less clear'
|
|
|
|
|
2014-07-18 17:26:55 +00:00
|
|
|
Style/RedundantBegin:
|
|
|
|
Exclude:
|
|
|
|
# this pattern is very common and somewhat unavoidable
|
|
|
|
# def run_host(ip)
|
|
|
|
# begin
|
|
|
|
# ...
|
|
|
|
# rescue ...
|
|
|
|
# ...
|
|
|
|
# ensure
|
|
|
|
# disconnect
|
|
|
|
# end
|
|
|
|
# end
|
|
|
|
- 'modules/**/*'
|
|
|
|
|
|
|
|
Documentation:
|
|
|
|
Exclude:
|
|
|
|
- 'modules/**/*'
|