Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
feature: restrict symbols which can exit the interpreter process
* feature: restrict symbols which can exit the interpreter process Some symbols such as os.Exit or log.Fatal, which make the current process to exit, are now restricted. They are replaced by a version which panics instead of exiting, as panics are recovered by Eval. The restricted os.FindProcess version is identical to the original except it errors when trying to return the self process, in order to forbid killing or signaling the interpreter process from script. The os/exec symbols are available only through unrestricted package. The original symbols are stored in an unrestricted package, which requires an explicit Use, as for unsafe and syscall packages. The Use() interpreter method has been slightly modified to allow inplace updating of package symbols, allowing to replace some symbols but not the entire imported package. A command line option -unrestricted has been added to yaegi CLI to use the unrestricted symbols. Fixes #486. * fix: lint
- Loading branch information
Showing
18 changed files
with
220 additions
and
68 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,18 @@ | ||
package main | ||
|
||
import ( | ||
"fmt" | ||
"log" | ||
) | ||
|
||
func main() { | ||
defer func() { | ||
r := recover() | ||
fmt.Println("recover:", r) | ||
}() | ||
log.Fatal("log.Fatal does not exit") | ||
println("not printed") | ||
} | ||
|
||
// Output: | ||
// recover: log.Fatal does not exit |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,18 @@ | ||
package main | ||
|
||
import ( | ||
"fmt" | ||
"os" | ||
) | ||
|
||
func main() { | ||
defer func() { | ||
r := recover() | ||
fmt.Println("recover:", r) | ||
}() | ||
os.Exit(1) | ||
println("not printed") | ||
} | ||
|
||
// Output: | ||
// recover: os.Exit(1) |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,14 @@ | ||
package main | ||
|
||
import ( | ||
"fmt" | ||
"os" | ||
) | ||
|
||
func main() { | ||
p, err := os.FindProcess(os.Getpid()) | ||
fmt.Println(p, err) | ||
} | ||
|
||
// Output: | ||
// <nil> restricted |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,23 @@ | ||
package main | ||
|
||
import ( | ||
"bytes" | ||
"fmt" | ||
"log" | ||
) | ||
|
||
var ( | ||
buf bytes.Buffer | ||
logger = log.New(&buf, "logger: ", log.Lshortfile) | ||
) | ||
|
||
func main() { | ||
defer func() { | ||
r := recover() | ||
fmt.Println("recover:", r, buf.String()) | ||
}() | ||
logger.Fatal("test log") | ||
} | ||
|
||
// Output: | ||
// recover: test log logger: restricted.go:39: test log |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Oops, something went wrong.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Oops, something went wrong.
This file was deleted.
Oops, something went wrong.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Oops, something went wrong.
Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.
Oops, something went wrong.
This file was deleted.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,55 @@ | ||
package stdlib | ||
|
||
import ( | ||
"errors" | ||
"io" | ||
"log" | ||
"os" | ||
"strconv" | ||
) | ||
|
||
var errRestricted = errors.New("restricted") | ||
|
||
// osExit invokes panic instead of exit. | ||
func osExit(code int) { panic("os.Exit(" + strconv.Itoa(code) + ")") } | ||
|
||
// osFindProcess returns os.FindProcess, except for self process. | ||
func osFindProcess(pid int) (*os.Process, error) { | ||
if pid == os.Getpid() { | ||
return nil, errRestricted | ||
} | ||
return os.FindProcess(pid) | ||
} | ||
|
||
// The following functions call Panic instead of Fatal to avoid exit. | ||
func logFatal(v ...interface{}) { log.Panic(v...) } | ||
func logFatalf(f string, v ...interface{}) { log.Panicf(f, v...) } | ||
func logFatalln(v ...interface{}) { log.Panicln(v...) } | ||
|
||
type logLogger struct { | ||
l *log.Logger | ||
} | ||
|
||
// logNew Returns a wrapped logger. | ||
func logNew(out io.Writer, prefix string, flag int) *logLogger { | ||
return &logLogger{log.New(out, prefix, flag)} | ||
} | ||
|
||
// The following methods call Panic instead of Fatal to avoid exit. | ||
func (l *logLogger) Fatal(v ...interface{}) { l.l.Panic(v...) } | ||
func (l *logLogger) Fatalf(f string, v ...interface{}) { l.l.Panicf(f, v...) } | ||
func (l *logLogger) Fatalln(v ...interface{}) { l.l.Panicln(v...) } | ||
|
||
// The following methods just forward to wrapped logger. | ||
func (l *logLogger) Flags() int { return l.l.Flags() } | ||
func (l *logLogger) Output(d int, s string) error { return l.l.Output(d, s) } | ||
func (l *logLogger) Panic(v ...interface{}) { l.l.Panic(v...) } | ||
func (l *logLogger) Panicf(f string, v ...interface{}) { l.l.Panicf(f, v...) } | ||
func (l *logLogger) Panicln(v ...interface{}) { l.l.Panicln(v...) } | ||
func (l *logLogger) Prefix() string { return l.l.Prefix() } | ||
func (l *logLogger) Print(v ...interface{}) { l.l.Print(v...) } | ||
func (l *logLogger) Printf(f string, v ...interface{}) { l.l.Printf(f, v...) } | ||
func (l *logLogger) Println(v ...interface{}) { l.l.Println(v...) } | ||
func (l *logLogger) SetFlags(flag int) { l.l.SetFlags(flag) } | ||
func (l *logLogger) SetOutput(w io.Writer) { l.l.SetOutput(w) } | ||
func (l *logLogger) Writer() io.Writer { return l.l.Writer() } |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.