From: Brian Candler Date: 2003-08-29T05:49:26+09:00 Subject: Re: Specification of Ruby regex? On Thu, Aug 28, 2003 at 12:46:33AM +0900, Hal Fulton wrote: > >In Ruby, ^ and $ match the start and end of *lines* not strings. > >Multiline mode only tweaks whether . matches newline or not. So > >using Brian's example: > > > > a = "srand\n`rm -rf /`" > > a.untaint if /^[a-z]+$/ =~ a # matches "srand" > > eval a # BOOM! > > Quite right, thank you. > > But in nearly all cases, I have a string that has no newlines. In that case you are fine. But if a string is coming from an untrusted source - and a HTML FORM is a classic example of that - you cannot always be so sure. The behaviour is also important for strings which have a newline at the end, which is a common case in Ruby. I have just tried this again, and it appears to have changed between ruby-1.6.8 and ruby-1.8.0: a = "hello\n" a.sub!(/[\r\n]+$/,'') In Ruby 1.6.8, "a" contains "hello\n" after this. In Ruby 1.8.0, "a" contains "hello" [ruby-1.6.8] irb(main):001:0> "abc\n" =~ /c$/ => 2 irb(main):002:0> "abc\n" =~ /c\n$/ => nil [ruby-1.8.0] irb(main):003:0> "abc\n" =~ /c$/ => 2 irb(main):004:0> "abc\n" =~ /c\n$/ => 2 Regards, Brian.