From: ts Date: 2003-08-13T18:27:00+09:00 Subject: Re: $SAFE = 5 and Safe Ruby Misleading? >>>>> "D" == Dave Fayram writes: D> Which is why I'm curious what $SAFE = 4 is meant to do? It's easy to make it D> so that code runs in a box, what's difficult is to get data out of that box. Try something like this def a_verifier(str) Thread.new do $SAFE = 4 res = begin eval str rescue Exception $! end begin res = ::String.new(res.to_s) # add some test if you want rescue Exception "unknown error" end end.value # here you have a String object which is tainted # be carefull with it end the basic idea * protect it against any error to control the result * never trust the result : if you want a String, you explicitely create it with a method that you can trust (::String::new in my case) * never try to correct an error : in my case don't try to interpret the error in the second begin ... rescue ... end (it return "unknown error") Guy Decoux