From: Eric Hodel Date: 2007-01-23T04:18:08+09:00 Subject: Re: mod_ruby, require, and $SAFE On Jan 22, 2007, at 09:20, yermej@gmail.com wrote: > When running under mod_ruby with the default $SAFE == 1, a file > containing only this: > > require 'active_record' > > will give a 500 response with the error: > > mod_ruby: error in ruby > mod_ruby: /usr/lib64/ruby/site_ruby/1.8/rubygems/source_index.rb:73:in > `read': Insecure operation - read (SecurityError) > > I think this is happening because whatever is loaded from > active_record > is tainted and then can't be used to do the requires that > active_record > needs to do. That could be way off though. > > I'm aware of the RubySafeLevel apache directive, but is there a > reasonable way to keep $SAFE == 1 and still be able to require > active_record? What version of RubyGems are you using? -- Eric Hodel - drbrain@segment7.net - http://blog.segment7.net I LIT YOUR GEM ON FIRE!