From: Philip Ross Date: 2009-04-16T04:05:39+09:00 Subject: SecurityError requiring gems and other files with $SAFE=1 in Ruby 1.9.1 I'm using my own compiled version of Ruby 1.9.1p0 on Debian etch. With $SAFE=1, I get the following error trying to require gems (in this example Rake, but I get the same error with other gems): >> $SAFE=1 => 1 >> require 'rake' SecurityError: Insecure operation - require from (irb):2:in `require' from (irb):2 from /usr/local/ruby/1.9/bin/irb:12:in `
' The Rake gem is installed in the usual place: >> $:.find {|s| s =~ /rake/} => "/usr/local/ruby/1.9.1-p0/lib/ruby/gems/1.9.1/gems/rake-0.8.4/bin" I get the same error trying to load an arbitrary file: >> $SAFE=1 => 1 >> require 'testing' SecurityError: Insecure operation - require from (irb):2:in `require' from (irb):2 from /usr/local/ruby/1.9/bin/irb:12:in `
' I've just tried with the latest Ruby snapshot version and this has the same issues, albeit with a (slightly) more helpful error message: >> $SAFE=1 => 1 >> require 'rake' SecurityError: cannot load from insecure path - /usr/local/ruby/snapshot/lib/ruby/gems/1.9.1/gems/rake-0.8.4/lib/rake.rb from (irb):2:in `require' from (irb):2 from /usr/local/ruby/snapshot/bin/irb:12:in `
' Could anyone tell me if this is the expected behaviour of Ruby 1.9? I couldn't find any information about safe mode that would suggest these SecurityErrors should be raised? Thanks, Phil