From: Tobias Reif Date: 2002-04-06T20:15:18+09:00 Subject: Re: Is eval a code/design smell? Sean Middleditch wrote: > If eval() is running faster than your schema->lib functions, then I > would simply say your functions are too slow. ^,^ ?? I'm not using eval. I'm saving the generated lib as a file; then each time I use it, require 'it'. Sure this (b) is faster than generating the lib each time (a); don't you think so? a) Jelly parsing the XSD; extracting documentation, generating modules, generating classes, generating methods, etc. versus b) Ruby loading the lib > I still don't see why Ruby shouldn't provide methods for quickly, > easily, and powerfully constructing classes at runtime with sending > untrustable content to the parsing engine. You mean "without"? Anyways: perhaps this would be a nice feature. Any syntax ideas? I mean: keep eval, but offer something safer (more restricted) for "evaling" Ruby code. (?) > Because, I can just imagine > someone downloading a schema from the web that has an embedded > kernel.system('rm -rf $HOME/') - This would not matter, AFAICS. Depending on where it would be embedded, it would end up in RDoc, doing no harm. If you want to deal with downloaded files containing rm -rf, then I don't see away other than reading each and every line of code that you run, with human eyes. 1. Why would someone embed 'rm -rf into an XSD? 2. It would be much more likely to cause harm if it were embedded in a Ruby file ;) > if you provide a schema in non-code > format, you mean non- Ruby code? > that can be parsed in a safe manner that checks for this stuff. Could I insert some safe level statement into the generated libs? I mean, if you're really concerened about security, then I welcome practical help. > If you need to dump arbitrary objects (that might be valid to have a > command to delete your home directory) it would probably be cleaner > anyways to be able to serialize the bytecode/tree nodes, and store > those; Why? Then any unsecure/dangerous code would be obfuscated. This is contradicory to what you want. I want to keep the generated libs readable, so people can read/modify/check them before running them). > it would load even faster, You mean everyone should provide their libs as bytecode only? Then we're back to pre open source days. Tobi -- Neither simple nor complex matters are to be complicated.