From: Nikolai Weibull Date: 2013-03-24T06:42:00+09:00 Subject: [ruby-core:53685] Re: [ruby-core:53680] Re: [ruby-core:53679] Why doesn’t String#+ return an untrusted result if self or other is untrusted? On Sat, Mar 23, 2013 at 8:30 PM, KOSAKI Motohiro wrote: > On Sat, Mar 23, 2013 at 2:45 PM, Nikolai Weibull wrote: >> Why doesn���t String#+ return an untrusted result if self or other is untrusted? >> >> Only taint is inherited. >> >> Also, I can���t really find any documentation on the difference between >> taint and untrust. > > IIUC, untrusted mean an object was created from untrusted code (i.e. $SAFE >=3). > taint mean the data is derived from other tainted data or IO source. OK, so the reasoning then is that since String#+ creates a result that contains data from outside of the receiver, untrust isn���t inherited, whereas with String#slice and String#downcase the whole result comes from an untrusted source and thus untrust is inherited. > That said, when trusted code (i.e. $SAFE=0) call String#+, ruby assume caller > understand what String#+ does. Yes, though it���s not documented anywhere and understanding what I described above doesn���t seem very obvious (if it���s even the case that I���ve understood it correctly)