From: "Florian Groß" Date: 2005-02-15T06:20:06+09:00 Subject: SecurityError on Method#call? (might be DRb specific) Moin. I've recently having trouble with these kind of errors: > SecurityError in Member#list > > Insecure operation `write' at level 4 I'm basically using .call on a DRb proxied method to invoke it. $SAFE is 0 in both the server and the client script. The proxy object isn't tainted. (I'm untainting it and doing a .tainted?() check that always returns false even before I untaint it.) The server is running in a CGI environment, but I think that's not relevant. The method comes from a Module defined in the source code in the usual way: module Handlers extend self def breakpoint_handler(workspace, message) ... end def eval_handler(code) ... end ... end And I'm setting them like this: service.eval_handler = Handlers.method(:eval_handler) So what I'm asking is: Is there any other reason why a method would suddenly be executed in a $SAFE == 4 context or a way a method could get tainted when running with $SAFE == 0 at all? I initially thought that this would not happen at all unless you manually set $SAFE, but it appears that this happens for tainted methods even in $SAFE == 0. I can not reproduce the problem locally, but some users of the breakpoint library where this trouble can reproduce it reliably, so I'll be able to pass along further questions. Thanks a lot for any information that might help with this problem. I'm unfortunately running out of ideas here... Regards, Florian Gross