From: Lennon Day-Reynolds Date: 2004-06-26T02:40:44+09:00 Subject: Re: Is it considered Harmful? The point of this whole thread, though, is that adding #become and #class= to the language would effectively make Ruby code as potentially unsafe as C. Look at the .NET CLR -- they have "unsafe" blocks, in which you can do raw pointer-based operations, but which mark the entire assembly (a compiled module) as unsafe, and therefore platform (and perhaps even OS version) specific. I agree 100% that "pure Ruby" code should be safe from hard crashes and as platform-independent as possible. It's pretty good in that arena now, and I'd like to see it continue to improve, not get worse. Question: does the current implementation for $SAFE block imports of native modules at some level? Lennon P.S.: Okay, I just RTFM, and think I found the answer to my question above. Just in case anyone's interested: Answer: According to Pickaxe, at $SAFE=2, no loads are allowed from tainted path strings, and at $SAFE=3, all object are created tainted. That should mean that any code eval'd at $SAFE=3 or higher won't be able to import at all, but modules that were already loaded should still be available via 'require' (since 'load', not 'require' is the checked method), right? On Sat, 26 Jun 2004 02:25:42 +0900, Sean O'Dell wrote: > > > On Friday 25 June 2004 10:11, Lennon Day-Reynolds wrote: > > [snip] > > > > > No code should "expect" data to be there that isn't. If a C extension > > > wraps a native C struct as a Ruby object with Make_Struct, then when it > > > unwraps it, and gets nothing or a NULL pointer, it shouldn't continue to > > > try and use it. That's sloppy coding. > > > > > > Sean O'Dell > > > > I agree with you about it being sloppy programming, but then again, > > part of the reason that I write code in Ruby (and Python, Java, C#, > > Perl, etc.) is so that I can be a little sloppy, without getting > > segfaults or buffer overruns. Programming in C seems to consist mostly > > of wrapping unsafe calls in error checks and handlers; I would hate to > > see Ruby become similarly burdened due to low-level hacks like #class= > > or #become entering the langauge core. > > I was actually speaking of Ruby C code, not so much Ruby script code. Ruby > should be stable even in exceptional circumstances, although you might not > get the results you're after. It still shouldn't crash. C code shouldn't > use internal data without performing some checks, especially if the data > makes the rounds to other libraries/extensions and such. > > Sean O'Dell > >