From: Paul Brannan Date: 2004-07-03T03:43:04+09:00 Subject: Re: ruby-dev summary 23763-23840 On Fri, Jul 02, 2004 at 08:08:42PM +0900, Minero Aoki wrote: > [ruby-dev:23814] $SAFE in Proc > [ruby-dev:23815] set_trace_func in safe mode > > Nobuyoshi Nakada posted two security considerations. > > 1. $SAFE=4 program can safely call a Proc object which is created > by $SAFE=0, and it runs in $SAFE=0. It causes `$SAFE downgrading'. > > -> Matz said that it is not a problem because Proc objects which > are created in $SAFE=0 environment should be trustable. > In other words, you should not load untrustable code in $SAFE<4. > > 2. set_trace_func should be prohibited in $SAFE>0. > > -> Matz stated that $SAFE>3 check is enough, > because we are trusting $SAFE<=3 codes. I'm not sure I agree. I don't think it should ever be possible to downgrade your $SAFE level without help from a thread that already has its $SAFE level downgraded, but it is: # "safe" thread t = Thread.new do Thread.current.abort_on_exception = true $SAFE = 1 set_trace_func proc { |x| b = x[4] safe = eval("$SAFE", b) if safe == 0 then # now we have a binding with $SAFE=0 and we can effectively # bypass $SAFE puts "got a binding with $SAFE=0!" set_trace_func nil end } sleep end # main thread sleep 1 I'd have to be malicious to write code like this, and potentially malicious code shouldn't be executed in $SAFE=1, but if explicitly setting $SAFE is disallowed, then so should the above code. Is there a practical use calling set_trace_func when $SAFE=1? Paul