From: Matthew Kerwin Date: 2013-02-06T13:05:58+09:00 Subject: Re: Symbol.defined? --f46d04287a17eccf0c04d5066c6d Content-Type: text/plain; charset=ISO-8859-1 On 6 February 2013 12:43, Student Jr wrote: > When a symbol is defined, the memory used to store the symbol is > permanently lost. If one is parsing external input, this makes one's > application vulnerable to DOS. > > Secondarily, if while parsing external input, one refuses to make new > symbols blindly, then the symbol list is something over which one has > direct control, and it can be trusted in some situations to speed > processing. I see. If there's a logical distinction between externally- and internally-defined symbols, you could override the entrypoint (your deserialiser or whatever) to build a hash of String=>Symbol pairs. That way instead of using `Symbol.all_symbols.any?{|sym| sym.to_s == string}` you could use `my_hash.has_key? string`. Not sure how you'd ever populate said hash, though. Trusted entrypoints or something. However if you want to reuse existing symbols you'd have to have a way to prepopulate and continuously update the hash. I can think of a bunch of klugey ways to get it to work, but I'm not proud of any of them. I imagine it should be relatively easy* to define a new native singleton method `defined?` on Symbol... There's obviously a legitimate use-case; I think it would be worth making a feature request for this. * I'm not a core contributor. -- Matthew Kerwin, B.Sc (CompSci) (Hons) http://matthew.kerwin.net.au/ ABN: 59-013-727-651 "You'll never find a programming language that frees you from the burden of clarifying your ideas." - xkcd --f46d04287a17eccf0c04d5066c6d Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable
On 6 February 2013 12:43, Student Jr <= ;lists@ruby-forum= .com> wrote:
When a symbol is defined, the memory used to= store the symbol is
permanently lost. =A0If one is parsing external input, this makes one's=
application vulnerable to DOS.

Secondarily, if while parsing external input, one refuses to make new
symbols blindly, then the symbol list is something over which one has
direct control, and it can be trusted in some situations to speed
processing.

I see.

<= div class=3D"gmail_extra" style>If there's a logical distinction betwee= n externally- and internally-defined symbols, you could override the entryp= oint (your deserialiser or whatever) to build a hash of String=3D>Symbol= pairs. That way instead of using `Symbol.all_symbols.any?{|sym| sym.to_s = =3D=3D string}` you could use `my_hash.has_key? string`. =A0Not sure how yo= u'd ever populate said hash, though. =A0Trusted entrypoints or somethin= g.

Howev= er if you want to reuse existing symbols you'd have to have a way to pr= epopulate and continuously update the hash. =A0I can think of a bunch of kl= ugey ways to get it to work, but I'm not proud of any of them.

I imagine it should be relatively easy= * to define a new native singleton method `defined?` on Symbol... =A0There&= #39;s obviously a legitimate use-case; I think it would be worth making a f= eature request for this.

* I'm not a core contributor.
--
=A0= Matthew Kerwin, B.Sc (CompSci) (Hons)
=A0 http://matthew.kerwin.net.au/
=A0 ABN= : 59-013-727-651

=A0 "You'll never find a programming language that frees
= =A0 you from the burden of clarifying your ideas." - xkcd
--f46d04287a17eccf0c04d5066c6d--