From: Dave Fayram Date: 2003-08-13T00:30:17+09:00 Subject: Re: $SAFE = 5 and Safe Ruby Misleading? On Monday, August 11, 2003, at 4:35 PM, Brian Candler wrote: > So someone cannot send you a general Ruby object, unless you were to > explicitly unmarshal it, and they cannot directly touch your Ruby > run-time > environment. If they could, they could redefine ENV to return whatever > they > like, or they could simply override methods in your classes to do > whatever > they liked. Well, what if I took in code, say from a semi-trusted source. Let's say an IRC bot (because I helped a friend write one). Originally, the bot would have been able to accept strings from arbitrary users which would be evaluated as Ruby. The strings would return some value. It was a really interesting idea for such a lame domain. But, you can't do that. They don't even have to modify core classes. They need to modify one instance one one class. This is the case where $SAFE = 4 is misleading. It also makes me wonder, what is the point of it? If you can't output from such a block in any way that wouldn't risk the integrity of the system, what does it DO? It seems to me the PURPOSE of $SAFE = 4 is to make it so you can run untrusted code without fear of it modifying the core environment. For example, in the Programming Ruby book's CGI example, what's to say that the string didn't look innocuous, but return an object who's .to_html or .to_str didn't just rm * again? I suppose with such a simple expression, it's easier, but more complex it would be impossible. Basically, can I evaluate something in a $SAFE = 4 thread, then get it out and work with it meaningfully? The only way I can think of is to try analyzing it in a $SAFE = 3 thread, where an object can't untaint itself, but doing so for an object would be pretty much impossible. Anyone have any suggestions on how I mi -- Dave Fayram kirindave@lensmen.net Developer / Idealist --