| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | """Restricted execution facilities.
 | 
					
						
							| 
									
										
										
										
											1995-01-12 12:29:47 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1996-05-28 23:07:17 +00:00
										 |  |  | The class RExec exports methods r_exec(), r_eval(), r_execfile(), and | 
					
						
							|  |  |  | r_import(), which correspond roughly to the built-in operations | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | exec, eval(), execfile() and import, but executing the code in an | 
					
						
							|  |  |  | environment that only exposes those built-in operations that are | 
					
						
							|  |  |  | deemed safe.  To this end, a modest collection of 'fake' modules is | 
					
						
							|  |  |  | created which mimics the standard modules by the same names.  It is a | 
					
						
							|  |  |  | policy decision which built-in modules and operations are made | 
					
						
							|  |  |  | available; this module provides a reasonable default, but derived | 
					
						
							|  |  |  | classes can change the policies e.g. by overriding or extending class | 
					
						
							|  |  |  | variables like ok_builtin_modules or methods like make_sys(). | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-08-07 20:19:27 +00:00
										 |  |  | XXX To do: | 
					
						
							|  |  |  | - r_open should allow writing tmp dir | 
					
						
							|  |  |  | - r_exec etc. with explicit globals/locals? (Use rexec("exec ... in ...")?) | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | """
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | import sys | 
					
						
							| 
									
										
										
										
											1995-01-12 12:29:47 +00:00
										 |  |  | import __builtin__ | 
					
						
							|  |  |  | import os | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | import ihooks | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2001-02-15 22:15:14 +00:00
										 |  |  | __all__ = ["RExec"] | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-08-07 20:19:27 +00:00
										 |  |  | class FileBase: | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |     ok_file_methods = ('fileno', 'flush', 'isatty', 'read', 'readline', | 
					
						
							|  |  |  |             'readlines', 'seek', 'tell', 'write', 'writelines') | 
					
						
							| 
									
										
										
										
											1995-08-07 20:19:27 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | class FileWrapper(FileBase): | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |     # XXX This is just like a Bastion -- should use that! | 
					
						
							| 
									
										
										
										
											1996-06-28 17:28:51 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |     def __init__(self, f): | 
					
						
							|  |  |  |         self.f = f | 
					
						
							|  |  |  |         for m in self.ok_file_methods: | 
					
						
							|  |  |  |             if not hasattr(self, m) and hasattr(f, m): | 
					
						
							|  |  |  |                 setattr(self, m, getattr(f, m)) | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     def close(self): | 
					
						
							|  |  |  |         self.flush() | 
					
						
							| 
									
										
										
										
											1995-08-07 20:19:27 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | TEMPLATE = """
 | 
					
						
							|  |  |  | def %s(self, *args): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         return apply(getattr(self.mod, self.name).%s, args) | 
					
						
							| 
									
										
										
										
											1995-08-07 20:19:27 +00:00
										 |  |  | """
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | class FileDelegate(FileBase): | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |     def __init__(self, mod, name): | 
					
						
							|  |  |  |         self.mod = mod | 
					
						
							|  |  |  |         self.name = name | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     for m in FileBase.ok_file_methods + ('close',): | 
					
						
							|  |  |  |         exec TEMPLATE % (m, m) | 
					
						
							| 
									
										
										
										
											1995-08-07 20:19:27 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | class RHooks(ihooks.Hooks): | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											1996-05-28 23:07:17 +00:00
										 |  |  |     def __init__(self, *args): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         # Hacks to support both old and new interfaces: | 
					
						
							|  |  |  |         # old interface was RHooks(rexec[, verbose]) | 
					
						
							|  |  |  |         # new interface is RHooks([verbose]) | 
					
						
							|  |  |  |         verbose = 0 | 
					
						
							|  |  |  |         rexec = None | 
					
						
							|  |  |  |         if args and type(args[-1]) == type(0): | 
					
						
							|  |  |  |             verbose = args[-1] | 
					
						
							|  |  |  |             args = args[:-1] | 
					
						
							|  |  |  |         if args and hasattr(args[0], '__class__'): | 
					
						
							|  |  |  |             rexec = args[0] | 
					
						
							|  |  |  |             args = args[1:] | 
					
						
							|  |  |  |         if args: | 
					
						
							|  |  |  |             raise TypeError, "too many arguments" | 
					
						
							|  |  |  |         ihooks.Hooks.__init__(self, verbose) | 
					
						
							|  |  |  |         self.rexec = rexec | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1996-05-28 23:07:17 +00:00
										 |  |  |     def set_rexec(self, rexec): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         # Called by RExec instance to complete initialization | 
					
						
							|  |  |  |         self.rexec = rexec | 
					
						
							| 
									
										
										
										
											1996-05-28 23:07:17 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  |     def is_builtin(self, name): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         return self.rexec.is_builtin(name) | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     def init_builtin(self, name): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         m = __import__(name) | 
					
						
							|  |  |  |         return self.rexec.copy_except(m, ()) | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     def init_frozen(self, name): raise SystemError, "don't use this" | 
					
						
							|  |  |  |     def load_source(self, *args): raise SystemError, "don't use this" | 
					
						
							|  |  |  |     def load_compiled(self, *args): raise SystemError, "don't use this" | 
					
						
							| 
									
										
										
										
											1998-06-29 20:32:57 +00:00
										 |  |  |     def load_package(self, *args): raise SystemError, "don't use this" | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1996-05-28 23:07:17 +00:00
										 |  |  |     def load_dynamic(self, name, filename, file): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         return self.rexec.load_dynamic(name, filename, file) | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     def add_module(self, name): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         return self.rexec.add_module(name) | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     def modules_dict(self): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         return self.rexec.modules | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     def default_path(self): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         return self.rexec.modules['sys'].path | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											1998-09-21 14:53:26 +00:00
										 |  |  | # XXX Backwards compatibility | 
					
						
							|  |  |  | RModuleLoader = ihooks.FancyModuleLoader | 
					
						
							|  |  |  | RModuleImporter = ihooks.ModuleImporter | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | class RExec(ihooks._Verbose): | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     """Restricted Execution environment.""" | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |     ok_path = tuple(sys.path)           # That's a policy decision | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1996-09-25 18:47:39 +00:00
										 |  |  |     ok_builtin_modules = ('audioop', 'array', 'binascii', | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |                           'cmath', 'errno', 'imageop', | 
					
						
							|  |  |  |                           'marshal', 'math', 'md5', 'operator', | 
					
						
							|  |  |  |                           'parser', 'regex', 'pcre', 'rotor', 'select', | 
					
						
							| 
									
										
										
										
											2001-06-22 18:19:16 +00:00
										 |  |  |                           'sha', '_sre', 'strop', 'struct', 'time') | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     ok_posix_names = ('error', 'fstat', 'listdir', 'lstat', 'readlink', | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |                       'stat', 'times', 'uname', 'getpid', 'getppid', | 
					
						
							|  |  |  |                       'getcwd', 'getuid', 'getgid', 'geteuid', 'getegid') | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     ok_sys_names = ('ps1', 'ps2', 'copyright', 'version', | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |                     'platform', 'exit', 'maxint') | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2001-09-13 21:01:29 +00:00
										 |  |  |     nok_builtin_names = ('open', 'file', 'reload', '__import__') | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     def __init__(self, hooks = None, verbose = 0): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         ihooks._Verbose.__init__(self, verbose) | 
					
						
							|  |  |  |         # XXX There's a circular reference here: | 
					
						
							|  |  |  |         self.hooks = hooks or RHooks(verbose) | 
					
						
							|  |  |  |         self.hooks.set_rexec(self) | 
					
						
							|  |  |  |         self.modules = {} | 
					
						
							|  |  |  |         self.ok_dynamic_modules = self.ok_builtin_modules | 
					
						
							|  |  |  |         list = [] | 
					
						
							|  |  |  |         for mname in self.ok_builtin_modules: | 
					
						
							|  |  |  |             if mname in sys.builtin_module_names: | 
					
						
							|  |  |  |                 list.append(mname) | 
					
						
							|  |  |  |         self.ok_builtin_modules = tuple(list) | 
					
						
							|  |  |  |         self.set_trusted_path() | 
					
						
							|  |  |  |         self.make_builtin() | 
					
						
							|  |  |  |         self.make_initial_modules() | 
					
						
							|  |  |  |         # make_sys must be last because it adds the already created | 
					
						
							|  |  |  |         # modules to its builtin_module_names | 
					
						
							|  |  |  |         self.make_sys() | 
					
						
							|  |  |  |         self.loader = RModuleLoader(self.hooks, verbose) | 
					
						
							|  |  |  |         self.importer = RModuleImporter(self.loader, verbose) | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1996-05-28 23:07:17 +00:00
										 |  |  |     def set_trusted_path(self): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         # Set the path from which dynamic modules may be loaded. | 
					
						
							|  |  |  |         # Those dynamic modules must also occur in ok_builtin_modules | 
					
						
							|  |  |  |         self.trusted_path = filter(os.path.isabs, sys.path) | 
					
						
							| 
									
										
										
										
											1996-05-28 23:07:17 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     def load_dynamic(self, name, filename, file): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         if name not in self.ok_dynamic_modules: | 
					
						
							|  |  |  |             raise ImportError, "untrusted dynamic module: %s" % name | 
					
						
							|  |  |  |         if sys.modules.has_key(name): | 
					
						
							|  |  |  |             src = sys.modules[name] | 
					
						
							|  |  |  |         else: | 
					
						
							|  |  |  |             import imp | 
					
						
							|  |  |  |             src = imp.load_dynamic(name, filename, file) | 
					
						
							|  |  |  |         dst = self.copy_except(src, []) | 
					
						
							|  |  |  |         return dst | 
					
						
							| 
									
										
										
										
											1996-05-28 23:07:17 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  |     def make_initial_modules(self): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         self.make_main() | 
					
						
							|  |  |  |         self.make_osname() | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     # Helpers for RHooks | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     def is_builtin(self, mname): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         return mname in self.ok_builtin_modules | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     # The make_* methods create specific built-in modules | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     def make_builtin(self): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         m = self.copy_except(__builtin__, self.nok_builtin_names) | 
					
						
							|  |  |  |         m.__import__ = self.r_import | 
					
						
							|  |  |  |         m.reload = self.r_reload | 
					
						
							| 
									
										
										
										
											2001-09-13 21:01:29 +00:00
										 |  |  |         m.open = m.file = self.r_open | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     def make_main(self): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         m = self.add_module('__main__') | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     def make_osname(self): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         osname = os.name | 
					
						
							|  |  |  |         src = __import__(osname) | 
					
						
							|  |  |  |         dst = self.copy_only(src, self.ok_posix_names) | 
					
						
							|  |  |  |         dst.environ = e = {} | 
					
						
							|  |  |  |         for key, value in os.environ.items(): | 
					
						
							|  |  |  |             e[key] = value | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     def make_sys(self): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         m = self.copy_only(sys, self.ok_sys_names) | 
					
						
							|  |  |  |         m.modules = self.modules | 
					
						
							|  |  |  |         m.argv = ['RESTRICTED'] | 
					
						
							|  |  |  |         m.path = map(None, self.ok_path) | 
					
						
							| 
									
										
										
										
											1998-07-09 13:52:38 +00:00
										 |  |  |         m.exc_info = self.r_exc_info | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         m = self.modules['sys'] | 
					
						
							|  |  |  |         l = self.modules.keys() + list(self.ok_builtin_modules) | 
					
						
							|  |  |  |         l.sort() | 
					
						
							|  |  |  |         m.builtin_module_names = tuple(l) | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     # The copy_* methods copy existing modules with some changes | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     def copy_except(self, src, exceptions): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         dst = self.copy_none(src) | 
					
						
							|  |  |  |         for name in dir(src): | 
					
						
							|  |  |  |             setattr(dst, name, getattr(src, name)) | 
					
						
							|  |  |  |         for name in exceptions: | 
					
						
							|  |  |  |             try: | 
					
						
							|  |  |  |                 delattr(dst, name) | 
					
						
							|  |  |  |             except AttributeError: | 
					
						
							|  |  |  |                 pass | 
					
						
							|  |  |  |         return dst | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     def copy_only(self, src, names): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         dst = self.copy_none(src) | 
					
						
							|  |  |  |         for name in names: | 
					
						
							|  |  |  |             try: | 
					
						
							|  |  |  |                 value = getattr(src, name) | 
					
						
							|  |  |  |             except AttributeError: | 
					
						
							|  |  |  |                 continue | 
					
						
							|  |  |  |             setattr(dst, name, value) | 
					
						
							|  |  |  |         return dst | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     def copy_none(self, src): | 
					
						
							| 
									
										
										
										
											1998-06-09 21:33:44 +00:00
										 |  |  |         m = self.add_module(src.__name__) | 
					
						
							|  |  |  |         m.__doc__ = src.__doc__ | 
					
						
							|  |  |  |         return m | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     # Add a module -- return an existing module or create one | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     def add_module(self, mname): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         if self.modules.has_key(mname): | 
					
						
							|  |  |  |             return self.modules[mname] | 
					
						
							|  |  |  |         self.modules[mname] = m = self.hooks.new_module(mname) | 
					
						
							|  |  |  |         m.__builtins__ = self.modules['__builtin__'] | 
					
						
							|  |  |  |         return m | 
					
						
							| 
									
										
										
										
											1995-01-12 12:29:47 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  |     # The r* methods are public interfaces | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     def r_exec(self, code): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         m = self.add_module('__main__') | 
					
						
							|  |  |  |         exec code in m.__dict__ | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     def r_eval(self, code): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         m = self.add_module('__main__') | 
					
						
							|  |  |  |         return eval(code, m.__dict__) | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     def r_execfile(self, file): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         m = self.add_module('__main__') | 
					
						
							|  |  |  |         return execfile(file, m.__dict__) | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     def r_import(self, mname, globals={}, locals={}, fromlist=[]): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         return self.importer.import_module(mname, globals, locals, fromlist) | 
					
						
							| 
									
										
										
										
											1995-01-12 12:29:47 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-08-07 20:19:27 +00:00
										 |  |  |     def r_reload(self, m): | 
					
						
							|  |  |  |         return self.importer.reload(m) | 
					
						
							| 
									
										
										
										
											1995-08-09 02:32:08 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     def r_unload(self, m): | 
					
						
							|  |  |  |         return self.importer.unload(m) | 
					
						
							| 
									
										
										
										
											2001-01-15 01:18:21 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-08-07 20:19:27 +00:00
										 |  |  |     # The s_* methods are similar but also swap std{in,out,err} | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											1996-06-28 17:28:51 +00:00
										 |  |  |     def make_delegate_files(self): | 
					
						
							|  |  |  |         s = self.modules['sys'] | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         self.delegate_stdin = FileDelegate(s, 'stdin') | 
					
						
							|  |  |  |         self.delegate_stdout = FileDelegate(s, 'stdout') | 
					
						
							|  |  |  |         self.delegate_stderr = FileDelegate(s, 'stderr') | 
					
						
							| 
									
										
										
										
											1996-06-28 17:28:51 +00:00
										 |  |  |         self.restricted_stdin = FileWrapper(sys.stdin) | 
					
						
							|  |  |  |         self.restricted_stdout = FileWrapper(sys.stdout) | 
					
						
							|  |  |  |         self.restricted_stderr = FileWrapper(sys.stderr) | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-08-07 20:19:27 +00:00
										 |  |  |     def set_files(self): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         if not hasattr(self, 'save_stdin'): | 
					
						
							|  |  |  |             self.save_files() | 
					
						
							|  |  |  |         if not hasattr(self, 'delegate_stdin'): | 
					
						
							|  |  |  |             self.make_delegate_files() | 
					
						
							| 
									
										
										
										
											1995-08-07 20:19:27 +00:00
										 |  |  |         s = self.modules['sys'] | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         s.stdin = self.restricted_stdin | 
					
						
							|  |  |  |         s.stdout = self.restricted_stdout | 
					
						
							|  |  |  |         s.stderr = self.restricted_stderr | 
					
						
							|  |  |  |         sys.stdin = self.delegate_stdin | 
					
						
							|  |  |  |         sys.stdout = self.delegate_stdout | 
					
						
							|  |  |  |         sys.stderr = self.delegate_stderr | 
					
						
							| 
									
										
										
										
											1996-06-28 17:28:51 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     def reset_files(self): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         self.restore_files() | 
					
						
							| 
									
										
										
										
											1996-06-28 17:28:51 +00:00
										 |  |  |         s = self.modules['sys'] | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         self.restricted_stdin = s.stdin | 
					
						
							|  |  |  |         self.restricted_stdout = s.stdout | 
					
						
							|  |  |  |         self.restricted_stderr = s.stderr | 
					
						
							| 
									
										
										
										
											2001-01-15 01:18:21 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-08-07 20:19:27 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  |     def save_files(self): | 
					
						
							|  |  |  |         self.save_stdin = sys.stdin | 
					
						
							|  |  |  |         self.save_stdout = sys.stdout | 
					
						
							|  |  |  |         self.save_stderr = sys.stderr | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											1996-06-28 17:28:51 +00:00
										 |  |  |     def restore_files(self): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         sys.stdin = self.save_stdin | 
					
						
							|  |  |  |         sys.stdout = self.save_stdout | 
					
						
							|  |  |  |         sys.stderr = self.save_stderr | 
					
						
							| 
									
										
										
										
											2001-01-15 01:18:21 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1996-09-25 18:47:39 +00:00
										 |  |  |     def s_apply(self, func, args=(), kw=None): | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         self.save_files() | 
					
						
							|  |  |  |         try: | 
					
						
							|  |  |  |             self.set_files() | 
					
						
							|  |  |  |             if kw: | 
					
						
							|  |  |  |                 r = apply(func, args, kw) | 
					
						
							|  |  |  |             else: | 
					
						
							|  |  |  |                 r = apply(func, args) | 
					
						
							| 
									
										
										
										
											1995-08-07 20:19:27 +00:00
										 |  |  |         finally: | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |             self.restore_files() | 
					
						
							| 
									
										
										
										
											2001-06-18 12:33:36 +00:00
										 |  |  |         return r | 
					
						
							| 
									
										
										
										
											2001-01-15 01:18:21 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-08-07 20:19:27 +00:00
										 |  |  |     def s_exec(self, *args): | 
					
						
							| 
									
										
										
										
											2001-06-18 12:33:36 +00:00
										 |  |  |         return self.s_apply(self.r_exec, args) | 
					
						
							| 
									
										
										
										
											2001-01-15 01:18:21 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-08-07 20:19:27 +00:00
										 |  |  |     def s_eval(self, *args): | 
					
						
							| 
									
										
										
										
											2001-06-18 12:33:36 +00:00
										 |  |  |         return self.s_apply(self.r_eval, args) | 
					
						
							| 
									
										
										
										
											2001-01-15 01:18:21 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-08-07 20:19:27 +00:00
										 |  |  |     def s_execfile(self, *args): | 
					
						
							| 
									
										
										
										
											2001-06-18 12:33:36 +00:00
										 |  |  |         return self.s_apply(self.r_execfile, args) | 
					
						
							| 
									
										
										
										
											2001-01-15 01:18:21 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-08-07 20:19:27 +00:00
										 |  |  |     def s_import(self, *args): | 
					
						
							| 
									
										
										
										
											2001-06-18 12:33:36 +00:00
										 |  |  |         return self.s_apply(self.r_import, args) | 
					
						
							| 
									
										
										
										
											2001-01-15 01:18:21 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-08-07 20:19:27 +00:00
										 |  |  |     def s_reload(self, *args): | 
					
						
							| 
									
										
										
										
											2001-06-18 12:33:36 +00:00
										 |  |  |         return self.s_apply(self.r_reload, args) | 
					
						
							| 
									
										
										
										
											2001-01-15 01:18:21 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-08-09 02:32:08 +00:00
										 |  |  |     def s_unload(self, *args): | 
					
						
							| 
									
										
										
										
											2001-06-18 12:33:36 +00:00
										 |  |  |         return self.s_apply(self.r_unload, args) | 
					
						
							| 
									
										
										
										
											2001-01-15 01:18:21 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-08-07 20:19:27 +00:00
										 |  |  |     # Restricted open(...) | 
					
						
							| 
									
										
										
										
											2001-01-15 01:18:21 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-08-07 20:19:27 +00:00
										 |  |  |     def r_open(self, file, mode='r', buf=-1): | 
					
						
							|  |  |  |         if mode not in ('r', 'rb'): | 
					
						
							|  |  |  |             raise IOError, "can't open files for writing in restricted mode" | 
					
						
							| 
									
										
										
										
											1995-08-09 02:32:08 +00:00
										 |  |  |         return open(file, mode, buf) | 
					
						
							| 
									
										
										
										
											1995-08-07 20:19:27 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1998-07-09 13:52:38 +00:00
										 |  |  |     # Restricted version of sys.exc_info() | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |     def r_exc_info(self): | 
					
						
							|  |  |  |         ty, va, tr = sys.exc_info() | 
					
						
							|  |  |  |         tr = None | 
					
						
							|  |  |  |         return ty, va, tr | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-01-12 12:29:47 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  | def test(): | 
					
						
							| 
									
										
										
										
											2001-08-13 15:58:26 +00:00
										 |  |  |     import getopt, traceback | 
					
						
							| 
									
										
										
										
											1998-07-09 13:52:38 +00:00
										 |  |  |     opts, args = getopt.getopt(sys.argv[1:], 'vt:') | 
					
						
							|  |  |  |     verbose = 0 | 
					
						
							|  |  |  |     trusted = [] | 
					
						
							|  |  |  |     for o, a in opts: | 
					
						
							|  |  |  |         if o == '-v': | 
					
						
							|  |  |  |             verbose = verbose+1 | 
					
						
							|  |  |  |         if o == '-t': | 
					
						
							|  |  |  |             trusted.append(a) | 
					
						
							|  |  |  |     r = RExec(verbose=verbose) | 
					
						
							|  |  |  |     if trusted: | 
					
						
							|  |  |  |         r.ok_builtin_modules = r.ok_builtin_modules + tuple(trusted) | 
					
						
							|  |  |  |     if args: | 
					
						
							|  |  |  |         r.modules['sys'].argv = args | 
					
						
							|  |  |  |         r.modules['sys'].path.insert(0, os.path.dirname(args[0])) | 
					
						
							|  |  |  |     else: | 
					
						
							|  |  |  |         r.modules['sys'].path.insert(0, "") | 
					
						
							|  |  |  |     fp = sys.stdin | 
					
						
							|  |  |  |     if args and args[0] != '-': | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         try: | 
					
						
							| 
									
										
										
										
											1998-07-09 13:52:38 +00:00
										 |  |  |             fp = open(args[0]) | 
					
						
							|  |  |  |         except IOError, msg: | 
					
						
							|  |  |  |             print "%s: can't open file %s" % (sys.argv[0], `args[0]`) | 
					
						
							|  |  |  |             return 1 | 
					
						
							|  |  |  |     if fp.isatty(): | 
					
						
							|  |  |  |         print "*** RESTRICTED *** Python", sys.version | 
					
						
							| 
									
										
										
										
											2001-08-13 15:58:26 +00:00
										 |  |  |         print 'Type "help", "copyright", "credits" or "license" ' \ | 
					
						
							|  |  |  |               'for more information.' | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											1998-07-09 13:52:38 +00:00
										 |  |  |         while 1: | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |             try: | 
					
						
							| 
									
										
										
										
											1998-07-09 13:52:38 +00:00
										 |  |  |                 try: | 
					
						
							|  |  |  |                     s = raw_input('>>> ') | 
					
						
							|  |  |  |                 except EOFError: | 
					
						
							|  |  |  |                     print | 
					
						
							|  |  |  |                     break | 
					
						
							|  |  |  |                 if s and s[0] != '#': | 
					
						
							|  |  |  |                     s = s + '\n' | 
					
						
							|  |  |  |                     c = compile(s, '<stdin>', 'single') | 
					
						
							|  |  |  |                     r.s_exec(c) | 
					
						
							|  |  |  |             except SystemExit, n: | 
					
						
							|  |  |  |                 return n | 
					
						
							|  |  |  |             except: | 
					
						
							|  |  |  |                 traceback.print_exc() | 
					
						
							|  |  |  |     else: | 
					
						
							|  |  |  |         text = fp.read() | 
					
						
							|  |  |  |         fp.close() | 
					
						
							|  |  |  |         c = compile(text, fp.name, 'exec') | 
					
						
							|  |  |  |         try: | 
					
						
							|  |  |  |             r.s_exec(c) | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         except SystemExit, n: | 
					
						
							| 
									
										
										
										
											1998-07-09 13:52:38 +00:00
										 |  |  |             return n | 
					
						
							| 
									
										
										
										
											1998-03-26 22:10:50 +00:00
										 |  |  |         except: | 
					
						
							|  |  |  |             traceback.print_exc() | 
					
						
							| 
									
										
										
										
											1998-07-09 13:52:38 +00:00
										 |  |  |             return 1 | 
					
						
							| 
									
										
										
										
											1995-08-04 03:59:03 +00:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											1995-01-12 12:29:47 +00:00
										 |  |  | 
 | 
					
						
							|  |  |  | if __name__ == '__main__': | 
					
						
							| 
									
										
										
										
											1998-07-09 13:52:38 +00:00
										 |  |  |     sys.exit(test()) |