From: Albert Chou Date: 2004-07-21T07:18:17+09:00 Subject: Re: Safe Ruby Environment ------_=_NextPart_001_01C46EA6.FBE45E81 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Maybe take inspiration from TCL's interp command (http://www.tcl.tk/man/tcl8.2.3/TclCmd/interp.htm), though that's a much heavier-weight solution? Al -----Original Message----- From: Michael Neumann [mailto:mneumann@ntecs.de]=20 Sent: Tuesday, July 20, 2004 2:04 PM To: ruby-talk ML Subject: Safe Ruby Environment Hi, Okay, there are the different $SAFE levels. But why not simply removing=20 dangerous methods, like: undef ` undef system undef require ... or replacing them by your own? I guess, this is as secure as any $SAFE level (of course it depends on=20 which methods you are removing). Or am I missing something? The problem=20 is that this way you can't run other "good" code next to your "bad" code (as it is possible with $SAFE). It would be very nice to execute some Ruby code in such a reduced=20 environment without affecting the other "good" code: env =3D Environment.new env.remove_method :system env.remove_constant :ENV env.remove_global "$0" ... env.eval dangerous_code # or env =3D Environment.fresh env.add_method :system env.add_constant :ENV, ENV ... BTW, is this possible to implement in Ruby or a C extension? I guess=20 not. Or would it work with two (or multiple) anonymous modules, one for=20 the good code, one for the bad code, and then by removing all=20 methods/constants/global variables outside those two modules? Regards, Michael ------_=_NextPart_001_01C46EA6.FBE45E81--