From: Brian Candler Date: 2010-04-06T19:27:47+09:00 Subject: Re: $SAFE=0 for setuid? BTW, here's exactly what happens (ruby.c): static void init_ids() { uid = (int)getuid(); euid = (int)geteuid(); gid = (int)getgid(); egid = (int)getegid(); #ifdef VMS uid |= gid << 16; euid |= egid << 16; #endif if (uid && (euid != uid || egid != gid)) { rb_set_safe_level(1); } } That is: if the real uid is not root, and either the effective uid different to the real uid or the effective gid is different to the real gid, then set $SAFE to 1. But notice that $SAFE level 1 only means "Ruby disallows the use of tainted data by potentially dangerous operations". So maybe what you should do is go with the flow, and carefully validate and untaint all data which comes from external sources. Maybe ruby pcap will work if you do this. See http://www.ruby-doc.org/docs/ProgrammingRuby/html/taint.html for more info. -- Posted via http://www.ruby-forum.com/.