Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Don't allow Alan games to call system() #772

Merged
merged 1 commit into from
Mar 27, 2023

Conversation

cspiegel
Copy link
Contributor

There is apparently an Alan statement called "system" which just passes a string through to the host's system() function. I can't find any documentation on this statement, but from the code it looks like completely arbitrary strings can be passed, which is incredibly dangerous. Ban these calls in Gargoyle.

There is apparently an Alan statement called "system" which just passes
a string through to the host's system() function. I can't find any
documentation on this statement, but from the code it looks like
completely arbitrary strings can be passed, which is incredibly
dangerous. Ban these calls in Gargoyle.
@cspiegel cspiegel merged commit de2005f into garglk:master Mar 27, 2023
@cspiegel cspiegel deleted the alan-no-external-calls branch March 27, 2023 18:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant