From: Rudolf Polzer Date: 2003-08-13T03:44:32+09:00 Subject: Re: $SAFE = 5 and Safe Ruby Misleading? Scripsit ille �Dave Fayram� : > djd15@cwru.edu wrote: > > $SAFE allows you to contain malicious code and > > keep it from damaging the system, but if you allow > > code to be passed out to a trusted environment, > > then I think the burden would be on you to make > > sure somehow that the object isn't malicious (not > > that that's even possible, like you've said). > > > > It seems to me that what you're asking would take > > a very complex security system (Java's system is > > quite complex and it doesn't get it right), and > > I don't think $SAFE was designed to cover it. > > Yeah. There is no way to check. Further, there is no way to even be sure your > data from even a simple case is secure? Pass out a string? No, that won't > work, they overrided =~. Badness. A hash is just as bad. It's almost > impossiboe to detect a really devious person doing this, since they could > uncode and execute highly obfuscated strings. Hm... what about: str = /.*/m.match(str)[0] BTW, why this: irb(main):001:0> a = "Hello" => "Hello" irb(main):002:0> class << a irb(main):003:1> def =~(x) irb(main):004:2> p [:you, :lose] irb(main):005:2> end irb(main):006:1> end => nil irb(main):007:0> a =~ /./ => 0 irb(main):008:0> a.=~ /./ [:you, :lose] => nil What did I do wrong? -- 0 >Array { 0 >c 0 >n { >p { >a { >c } { *c } *a set === IF XCALL } { # ~\ { &Array >n } { } *n 0 === IF VCALL *p 1 - &n } *p 0 == IF XCALL } } # \ >Array &Array >a " another " set 17 &a " hacker" set 23 &a Folth set # _/ \_ 42 &a get 23 &a get 42 &a get 17 &a Just PRINT PRINT PRINT PRINT ; ; PRINTLN