/
usr
/
share
/
doc
/
python2-docs
/
html
/
library
/
/usr/share/doc/python2-docs/html/library
mkdir
upload
Name
Size
Mode
Actions
2to3.html
59507
0644
edit
dl
rm
abc.html
25826
0644
edit
dl
rm
aepack.html
14164
0644
edit
dl
rm
aetools.html
16389
0644
edit
dl
rm
aetypes.html
21021
0644
edit
dl
rm
aifc.html
25064
0644
edit
dl
rm
al.html
18672
0644
edit
dl
rm
allos.html
35297
0644
edit
dl
rm
anydbm.html
18124
0644
edit
dl
rm
archiving.html
10078
0644
edit
dl
rm
argparse.html
263616
0644
edit
dl
rm
array.html
31855
0644
edit
dl
rm
ast.html
38167
0644
edit
dl
rm
asynchat.html
33930
0644
edit
dl
rm
asyncore.html
40631
0644
edit
dl
rm
atexit.html
18455
0644
edit
dl
rm
audioop.html
34252
0644
edit
dl
rm
autogil.html
8733
0644
edit
dl
rm
base64.html
21862
0644
edit
dl
rm
basehttpserver.html
37441
0644
edit
dl
rm
bastion.html
11798
0644
edit
dl
rm
bdb.html
41395
0644
edit
dl
rm
binascii.html
22997
0644
edit
dl
rm
binhex.html
11309
0644
edit
dl
rm
bisect.html
24666
0644
edit
dl
rm
bsddb.html
28589
0644
edit
dl
rm
bz2.html
29048
0644
edit
dl
rm
calendar.html
41762
0644
edit
dl
rm
carbon.html
51998
0644
edit
dl
rm
cd.html
30033
0644
edit
dl
rm
cgi.html
55922
0644
edit
dl
rm
cgihttpserver.html
14026
0644
edit
dl
rm
cgitb.html
12263
0644
edit
dl
rm
chunk.html
15899
0644
edit
dl
rm
cmath.html
28365
0644
edit
dl
rm
cmd.html
29042
0644
edit
dl
rm
code.html
26959
0644
edit
dl
rm
codecs.html
118258
0644
edit
dl
rm
codeop.html
15898
0644
edit
dl
rm
collections.html
147647
0644
edit
dl
rm
colorpicker.html
8035
0644
edit
dl
rm
colorsys.html
11919
0644
edit
dl
rm
commands.html
15516
0644
edit
dl
rm
compileall.html
18621
0644
edit
dl
rm
compiler.html
75897
0644
edit
dl
rm
configparser.html
67751
0644
edit
dl
rm
constants.html
13979
0644
edit
dl
rm
contextlib.html
22777
0644
edit
dl
rm
cookie.html
41854
0644
edit
dl
rm
cookielib.html
91032
0644
edit
dl
rm
copy.html
13004
0644
edit
dl
rm
copy_reg.html
14691
0644
edit
dl
rm
crypt.html
10647
0644
edit
dl
rm
crypto.html
7761
0644
edit
dl
rm
csv.html
76456
0644
edit
dl
rm
ctypes.html
264575
0644
edit
dl
rm
curses.ascii.html
24873
0644
edit
dl
rm
curses.html
167501
0644
edit
dl
rm
curses.panel.html
15824
0644
edit
dl
rm
custominterp.html
8026
0644
edit
dl
rm
datatypes.html
18015
0644
edit
dl
rm
datetime.html
253438
0644
edit
dl
rm
dbhash.html
16825
0644
edit
dl
rm
dbm.html
13507
0644
edit
dl
rm
debug.html
10703
0644
edit
dl
rm
decimal.html
222315
0644
edit
dl
rm
development.html
14828
0644
edit
dl
rm
difflib.html
91975
0644
edit
dl
rm
dircache.html
12299
0644
edit
dl
rm
dis.html
84156
0644
edit
dl
rm
distribution.html
7679
0644
edit
dl
rm
distutils.html
10152
0644
edit
dl
rm
dl.html
17668
0644
edit
dl
rm
doctest.html
185883
0644
edit
dl
rm
docxmlrpcserver.html
17573
0644
edit
dl
rm
dumbdbm.html
15549
0644
edit
dl
rm
dummy_thread.html
10065
0644
edit
dl
rm
dummy_threading.html
8934
0644
edit
dl
rm
easydialogs.html
33124
0644
edit
dl
rm
email-examples.html
47424
0644
edit
dl
rm
email.charset.html
29424
0644
edit
dl
rm
email.encoders.html
12847
0644
edit
dl
rm
email.errors.html
17952
0644
edit
dl
rm
email.generator.html
23141
0644
edit
dl
rm
email.header.html
29108
0644
edit
dl
rm
email.html
55722
0644
edit
dl
rm
email.iterators.html
12623
0644
edit
dl
rm
email.message.html
70189
0644
edit
dl
rm
email.mime.html
31655
0644
edit
dl
rm
email.parser.html
35142
0644
edit
dl
rm
email.utils.html
27076
0644
edit
dl
rm
ensurepip.html
18327
0644
edit
dl
rm
errno.html
40246
0644
edit
dl
rm
exceptions.html
63693
0644
edit
dl
rm
fcntl.html
26245
0644
edit
dl
rm
filecmp.html
23997
0644
edit
dl
rm
fileformats.html
9653
0644
edit
dl
rm
fileinput.html
27071
0644
edit
dl
rm
filesys.html
10866
0644
edit
dl
rm
fl.html
56525
0644
edit
dl
rm
fm.html
13009
0644
edit
dl
rm
fnmatch.html
16258
0644
edit
dl
rm
formatter.html
37371
0644
edit
dl
rm
fpectl.html
16879
0644
edit
dl
rm
fpformat.html
11455
0644
edit
dl
rm
fractions.html
24888
0644
edit
dl
rm
framework.html
36934
0644
edit
dl
rm
frameworks.html
7551
0644
edit
dl
rm
ftplib.html
49577
0644
edit
dl
rm
functions.html
205640
0644
edit
dl
rm
functools.html
29645
0644
edit
dl
rm
future_builtins.html
14477
0644
edit
dl
rm
gc.html
28423
0644
edit
dl
rm
gdbm.html
17805
0644
edit
dl
rm
gensuitemodule.html
12574
0644
edit
dl
rm
getopt.html
25280
0644
edit
dl
rm
getpass.html
11426
0644
edit
dl
rm
gettext.html
84971
0644
edit
dl
rm
gl.html
24342
0644
edit
dl
rm
glob.html
14430
0644
edit
dl
rm
grp.html
11316
0644
edit
dl
rm
gzip.html
20576
0644
edit
dl
rm
hashlib.html
25467
0644
edit
dl
rm
heapq.html
34890
0644
edit
dl
rm
hmac.html
14374
0644
edit
dl
rm
hotshot.html
20147
0644
edit
dl
rm
htmllib.html
27682
0644
edit
dl
rm
htmlparser.html
42433
0644
edit
dl
rm
httplib.html
70932
0644
edit
dl
rm
i18n.html
10047
0644
edit
dl
rm
ic.html
18654
0644
edit
dl
rm
idle.html
42148
0644
edit
dl
rm
imageop.html
16099
0644
edit
dl
rm
imaplib.html
58515
0644
edit
dl
rm
imgfile.html
12732
0644
edit
dl
rm
imghdr.html
12238
0644
edit
dl
rm
imp.html
37603
0644
edit
dl
rm
importlib.html
8926
0644
edit
dl
rm
imputil.html
33563
0644
edit
dl
rm
index.html
79088
0644
edit
dl
rm
inspect.html
56823
0644
edit
dl
rm
internet.html
26138
0644
edit
dl
rm
intro.html
9353
0644
edit
dl
rm
io.html
113701
0644
edit
dl
rm
ipc.html
16598
0644
edit
dl
rm
itertools.html
125397
0644
edit
dl
rm
jpeg.html
13757
0644
edit
dl
rm
json.html
73678
0644
edit
dl
rm
keyword.html
8210
0644
edit
dl
rm
language.html
11687
0644
edit
dl
rm
linecache.html
11416
0644
edit
dl
rm
locale.html
61576
0644
edit
dl
rm
logging.config.html
80045
0644
edit
dl
rm
logging.handlers.html
80194
0644
edit
dl
rm
logging.html
110254
0644
edit
dl
rm
mac.html
23376
0644
edit
dl
rm
macos.html
16129
0644
edit
dl
rm
macosa.html
14080
0644
edit
dl
rm
macostools.html
16898
0644
edit
dl
rm
macpath.html
8386
0644
edit
dl
rm
mailbox.html
171121
0644
edit
dl
rm
mailcap.html
14132
0644
edit
dl
rm
markup.html
19862
0644
edit
dl
rm
marshal.html
19456
0644
edit
dl
rm
math.html
44015
0644
edit
dl
rm
md5.html
15123
0644
edit
dl
rm
mhlib.html
24123
0644
edit
dl
rm
mimetools.html
21206
0644
edit
dl
rm
mimetypes.html
30634
0644
edit
dl
rm
mimewriter.html
16078
0644
edit
dl
rm
mimify.html
15279
0644
edit
dl
rm
miniaeframe.html
13109
0644
edit
dl
rm
misc.html
7236
0644
edit
dl
rm
mm.html
9570
0644
edit
dl
rm
mmap.html
30832
0644
edit
dl
rm
modulefinder.html
18096
0644
edit
dl
rm
modules.html
9017
0644
edit
dl
rm
msilib.html
57853
0644
edit
dl
rm
msvcrt.html
21232
0644
edit
dl
rm
multifile.html
26256
0644
edit
dl
rm
multiprocessing.html
414535
0644
edit
dl
rm
mutex.html
12147
0644
edit
dl
rm
netdata.html
18379
0644
edit
dl
rm
netrc.html
14021
0644
edit
dl
rm
new.html
13177
0644
edit
dl
rm
nis.html
11502
0644
edit
dl
rm
nntplib.html
45689
0644
edit
dl
rm
numbers.html
40636
0644
edit
dl
rm
numeric.html
14292
0644
edit
dl
rm
operator.html
93622
0644
edit
dl
rm
optparse.html
250109
0644
edit
dl
rm
os.html
240195
0644
edit
dl
rm
os.path.html
43402
0644
edit
dl
rm
ossaudiodev.html
45594
0644
edit
dl
rm
othergui.html
9403
0644
edit
dl
rm
parser.html
42558
0644
edit
dl
rm
pdb.html
38603
0644
edit
dl
rm
persistence.html
15676
0644
edit
dl
rm
pickle.html
109684
0644
edit
dl
rm
pickletools.html
11475
0644
edit
dl
rm
pipes.html
19685
0644
edit
dl
rm
pkgutil.html
27367
0644
edit
dl
rm
platform.html
31599
0644
edit
dl
rm
plistlib.html
18344
0644
edit
dl
rm
popen2.html
27601
0644
edit
dl
rm
poplib.html
24320
0644
edit
dl
rm
posix.html
16626
0644
edit
dl
rm
posixfile.html
21387
0644
edit
dl
rm
pprint.html
32207
0644
edit
dl
rm
profile.html
72788
0644
edit
dl
rm
pty.html
10195
0644
edit
dl
rm
pwd.html
12388
0644
edit
dl
rm
pyclbr.html
15812
0644
edit
dl
rm
pydoc.html
13650
0644
edit
dl
rm
pyexpat.html
80886
0644
edit
dl
rm
python.html
12854
0644
edit
dl
rm
py_compile.html
11932
0644
edit
dl
rm
queue.html
26856
0644
edit
dl
rm
quopri.html
12739
0644
edit
dl
rm
random.html
42722
0644
edit
dl
rm
re.html
155985
0644
edit
dl
rm
readline.html
37383
0644
edit
dl
rm
repr.html
21778
0644
edit
dl
rm
resource.html
28286
0644
edit
dl
rm
restricted.html
12366
0644
edit
dl
rm
rexec.html
40566
0644
edit
dl
rm
rfc822.html
46408
0644
edit
dl
rm
rlcompleter.html
14460
0644
edit
dl
rm
robotparser.html
13403
0644
edit
dl
rm
runpy.html
21925
0644
edit
dl
rm
sched.html
19878
0644
edit
dl
rm
scrolledtext.html
9728
0644
edit
dl
rm
select.html
44090
0644
edit
dl
rm
sets.html
40151
0644
edit
dl
rm
sgi.html
10371
0644
edit
dl
rm
sgmllib.html
34464
0644
edit
dl
rm
sha.html
13062
0644
edit
dl
rm
shelve.html
29955
0644
edit
dl
rm
shlex.html
35033
0644
edit
dl
rm
shutil.html
45454
0644
edit
dl
rm
signal.html
34023
0644
edit
dl
rm
simplehttpserver.html
20351
0644
edit
dl
rm
simplexmlrpcserver.html
37794
0644
edit
dl
rm
site.html
26887
0644
edit
dl
rm
smtpd.html
13587
0644
edit
dl
rm
smtplib.html
47054
0644
edit
dl
rm
sndhdr.html
10993
0644
edit
dl
rm
socket.html
116414
0644
edit
dl
rm
socketserver.html
76430
0644
edit
dl
rm
someos.html
16472
0644
edit
dl
rm
spwd.html
11163
0644
edit
dl
rm
sqlite3.html
150014
0644
edit
dl
rm
ssl.html
202453
0644
edit
dl
rm
stat.html
34597
0644
edit
dl
rm
statvfs.html
11326
0644
edit
dl
rm
stdtypes.html
298144
0644
edit
dl
rm
string.html
120219
0644
edit
dl
rm
stringio.html
20061
0644
edit
dl
rm
stringprep.html
17729
0644
edit
dl
rm
strings.html
15905
0644
edit
dl
rm
struct.html
44896
0644
edit
dl
rm
subprocess.html
110447
0644
edit
dl
rm
sun.html
7253
0644
edit
dl
rm
sunau.html
30011
0644
edit
dl
rm
sunaudio.html
19236
0644
edit
dl
rm
symbol.html
8140
0644
edit
dl
rm
symtable.html
25871
0644
edit
dl
rm
sys.html
110996
0644
edit
dl
rm
sysconfig.html
26299
0644
edit
dl
rm
syslog.html
19737
0644
edit
dl
rm
tabnanny.html
11393
0644
edit
dl
rm
tarfile.html
88728
0644
edit
dl
rm
telnetlib.html
27782
0644
edit
dl
rm
tempfile.html
31903
0644
edit
dl
rm
termios.html
17309
0644
edit
dl
rm
test.html
57030
0644
edit
dl
rm
textwrap.html
30135
0644
edit
dl
rm
thread.html
21486
0644
edit
dl
rm
threading.html
86655
0644
edit
dl
rm
time.html
63798
0644
edit
dl
rm
timeit.html
40529
0644
edit
dl
rm
tix.html
50582
0644
edit
dl
rm
tk.html
26568
0644
edit
dl
rm
tkinter.html
84316
0644
edit
dl
rm
token.html
20999
0644
edit
dl
rm
tokenize.html
20607
0644
edit
dl
rm
trace.html
28668
0644
edit
dl
rm
traceback.html
40900
0644
edit
dl
rm
ttk.html
108515
0644
edit
dl
rm
tty.html
9753
0644
edit
dl
rm
turtle.html
230483
0644
edit
dl
rm
types.html
29833
0644
edit
dl
rm
undoc.html
24680
0644
edit
dl
rm
unicodedata.html
20186
0644
edit
dl
rm
unittest.html
225021
0644
edit
dl
rm
unix.html
11223
0644
edit
dl
rm
urllib.html
68266
0644
edit
dl
rm
urllib2.html
113380
0644
edit
dl
rm
urlparse.html
43474
0644
edit
dl
rm
user.html
12707
0644
edit
dl
rm
userdict.html
32069
0644
edit
dl
rm
uu.html
11810
0644
edit
dl
rm
uuid.html
30137
0644
edit
dl
rm
warnings.html
50950
0644
edit
dl
rm
wave.html
24894
0644
edit
dl
rm
weakref.html
38808
0644
edit
dl
rm
webbrowser.html
26565
0644
edit
dl
rm
whichdb.html
9499
0644
edit
dl
rm
windows.html
9817
0644
edit
dl
rm
winsound.html
20466
0644
edit
dl
rm
wsgiref.html
88384
0644
edit
dl
rm
xdrlib.html
33018
0644
edit
dl
rm
xml.dom.html
97877
0644
edit
dl
rm
xml.dom.minidom.html
43230
0644
edit
dl
rm
xml.dom.pulldom.html
13835
0644
edit
dl
rm
xml.etree.elementtree.html
111804
0644
edit
dl
rm
xml.html
18007
0644
edit
dl
rm
xml.sax.handler.html
41877
0644
edit
dl
rm
xml.sax.html
23458
0644
edit
dl
rm
xml.sax.reader.html
44802
0644
edit
dl
rm
xml.sax.utils.html
16087
0644
edit
dl
rm
xmlrpclib.html
69191
0644
edit
dl
rm
zipfile.html
62227
0644
edit
dl
rm
zipimport.html
22769
0644
edit
dl
rm
zlib.html
31230
0644
edit
dl
rm
_winreg.html
64631
0644
edit
dl
rm
__builtin__.html
11069
0644
edit
dl
rm
__future__.html
14688
0644
edit
dl
rm
__main__.html
7512
0644
edit
dl
rm
Edit:
/usr/share/doc/python2-docs/html/library/rexec.html
(40566B)
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="X-UA-Compatible" content="IE=Edge" /> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <title>30.1. rexec — Restricted execution framework — Python 2.7.16 documentation</title> <link rel="stylesheet" href="../_static/classic.css" type="text/css" /> <link rel="stylesheet" href="../_static/pygments.css" type="text/css" /> <script type="text/javascript" id="documentation_options" data-url_root="../" src="../_static/documentation_options.js"></script> <script type="text/javascript" src="../_static/jquery.js"></script> <script type="text/javascript" src="../_static/underscore.js"></script> <script type="text/javascript" src="../_static/doctools.js"></script> <script type="text/javascript" src="../_static/sidebar.js"></script> <link rel="search" type="application/opensearchdescription+xml" title="Search within Python 2.7.16 documentation" href="../_static/opensearch.xml"/> <link rel="author" title="About these documents" href="../about.html" /> <link rel="index" title="Index" href="../genindex.html" /> <link rel="search" title="Search" href="../search.html" /> <link rel="copyright" title="Copyright" href="../copyright.html" /> <link rel="next" title="30.2. Bastion — Restricting access to objects" href="bastion.html" /> <link rel="prev" title="30. Restricted Execution" href="restricted.html" /> <link rel="shortcut icon" type="image/png" href="../_static/py.png" /> <link rel="canonical" href="https://docs.python.org/2/library/rexec.html" /> <script type="text/javascript" src="../_static/copybutton.js"></script> </head><body> <div class="related" role="navigation" aria-label="related navigation"> <h3>Navigation</h3> <ul> <li class="right" style="margin-right: 10px"> <a href="../genindex.html" title="General Index" accesskey="I">index</a></li> <li class="right" > <a href="../py-modindex.html" title="Python Module Index" >modules</a> |</li> <li class="right" > <a href="bastion.html" title="30.2. Bastion — Restricting access to objects" accesskey="N">next</a> |</li> <li class="right" > <a href="restricted.html" title="30. Restricted Execution" accesskey="P">previous</a> |</li> <li><img src="../_static/py.png" alt="" style="vertical-align: middle; margin-top: -1px"/></li> <li><a href="https://www.python.org/">Python</a> »</li> <li> <a href="../index.html">Python 2.7.16 documentation</a> » </li> <li class="nav-item nav-item-1"><a href="index.html" >The Python Standard Library</a> »</li> <li class="nav-item nav-item-2"><a href="restricted.html" accesskey="U">30. Restricted Execution</a> »</li> </ul> </div> <div class="document"> <div class="documentwrapper"> <div class="bodywrapper"> <div class="body" role="main"> <div class="section" id="module-rexec"> <span id="rexec-restricted-execution-framework"></span><h1>30.1. <a class="reference internal" href="#module-rexec" title="rexec: Basic restricted execution framework. (deprecated)"><code class="xref py py-mod docutils literal notranslate"><span class="pre">rexec</span></code></a> — Restricted execution framework<a class="headerlink" href="#module-rexec" title="Permalink to this headline">¶</a></h1> <div class="deprecated"> <p><span class="versionmodified">Deprecated since version 2.6: </span>The <a class="reference internal" href="#module-rexec" title="rexec: Basic restricted execution framework. (deprecated)"><code class="xref py py-mod docutils literal notranslate"><span class="pre">rexec</span></code></a> module has been removed in Python 3.</p> </div> <div class="versionchanged"> <p><span class="versionmodified">Changed in version 2.3: </span>Disabled module.</p> </div> <div class="admonition warning"> <p class="first admonition-title">Warning</p> <p class="last">The documentation has been left in place to help in reading old code that uses the module.</p> </div> <p>This module contains the <a class="reference internal" href="#rexec.RExec" title="rexec.RExec"><code class="xref py py-class docutils literal notranslate"><span class="pre">RExec</span></code></a> class, which supports <code class="xref py py-meth docutils literal notranslate"><span class="pre">r_eval()</span></code>, <code class="xref py py-meth docutils literal notranslate"><span class="pre">r_execfile()</span></code>, <code class="xref py py-meth docutils literal notranslate"><span class="pre">r_exec()</span></code>, and <code class="xref py py-meth docutils literal notranslate"><span class="pre">r_import()</span></code> methods, which are restricted versions of the standard Python functions <a class="reference internal" href="functions.html#eval" title="eval"><code class="xref py py-meth docutils literal notranslate"><span class="pre">eval()</span></code></a>, <a class="reference internal" href="functions.html#execfile" title="execfile"><code class="xref py py-meth docutils literal notranslate"><span class="pre">execfile()</span></code></a> and the <a class="reference internal" href="../reference/simple_stmts.html#exec"><code class="xref std std-keyword docutils literal notranslate"><span class="pre">exec</span></code></a> and <a class="reference internal" href="../reference/simple_stmts.html#import"><code class="xref std std-keyword docutils literal notranslate"><span class="pre">import</span></code></a> statements. Code executed in this restricted environment will only have access to modules and functions that are deemed safe; you can subclass <a class="reference internal" href="#rexec.RExec" title="rexec.RExec"><code class="xref py py-class docutils literal notranslate"><span class="pre">RExec</span></code></a> to add or remove capabilities as desired.</p> <div class="admonition warning"> <p class="first admonition-title">Warning</p> <p class="last">While the <a class="reference internal" href="#module-rexec" title="rexec: Basic restricted execution framework. (deprecated)"><code class="xref py py-mod docutils literal notranslate"><span class="pre">rexec</span></code></a> module is designed to perform as described below, it does have a few known vulnerabilities which could be exploited by carefully written code. Thus it should not be relied upon in situations requiring “production ready” security. In such situations, execution via sub-processes or very careful “cleansing” of both code and data to be processed may be necessary. Alternatively, help in patching known <a class="reference internal" href="#module-rexec" title="rexec: Basic restricted execution framework. (deprecated)"><code class="xref py py-mod docutils literal notranslate"><span class="pre">rexec</span></code></a> vulnerabilities would be welcomed.</p> </div> <div class="admonition note"> <p class="first admonition-title">Note</p> <p class="last">The <a class="reference internal" href="#rexec.RExec" title="rexec.RExec"><code class="xref py py-class docutils literal notranslate"><span class="pre">RExec</span></code></a> class can prevent code from performing unsafe operations like reading or writing disk files, or using TCP/IP sockets. However, it does not protect against code using extremely large amounts of memory or processor time.</p> </div> <dl class="class"> <dt id="rexec.RExec"> <em class="property">class </em><code class="descclassname">rexec.</code><code class="descname">RExec</code><span class="sig-paren">(</span><span class="optional">[</span><em>hooks</em><span class="optional">[</span>, <em>verbose</em><span class="optional">]</span><span class="optional">]</span><span class="sig-paren">)</span><a class="headerlink" href="#rexec.RExec" title="Permalink to this definition">¶</a></dt> <dd><p>Returns an instance of the <a class="reference internal" href="#rexec.RExec" title="rexec.RExec"><code class="xref py py-class docutils literal notranslate"><span class="pre">RExec</span></code></a> class.</p> <p><em>hooks</em> is an instance of the <code class="xref py py-class docutils literal notranslate"><span class="pre">RHooks</span></code> class or a subclass of it. If it is omitted or <code class="docutils literal notranslate"><span class="pre">None</span></code>, the default <code class="xref py py-class docutils literal notranslate"><span class="pre">RHooks</span></code> class is instantiated. Whenever the <a class="reference internal" href="#module-rexec" title="rexec: Basic restricted execution framework. (deprecated)"><code class="xref py py-mod docutils literal notranslate"><span class="pre">rexec</span></code></a> module searches for a module (even a built-in one) or reads a module’s code, it doesn’t actually go out to the file system itself. Rather, it calls methods of an <code class="xref py py-class docutils literal notranslate"><span class="pre">RHooks</span></code> instance that was passed to or created by its constructor. (Actually, the <a class="reference internal" href="#rexec.RExec" title="rexec.RExec"><code class="xref py py-class docutils literal notranslate"><span class="pre">RExec</span></code></a> object doesn’t make these calls — they are made by a module loader object that’s part of the <a class="reference internal" href="#rexec.RExec" title="rexec.RExec"><code class="xref py py-class docutils literal notranslate"><span class="pre">RExec</span></code></a> object. This allows another level of flexibility, which can be useful when changing the mechanics of <a class="reference internal" href="../reference/simple_stmts.html#import"><code class="xref std std-keyword docutils literal notranslate"><span class="pre">import</span></code></a> within the restricted environment.)</p> <p>By providing an alternate <code class="xref py py-class docutils literal notranslate"><span class="pre">RHooks</span></code> object, we can control the file system accesses made to import a module, without changing the actual algorithm that controls the order in which those accesses are made. For instance, we could substitute an <code class="xref py py-class docutils literal notranslate"><span class="pre">RHooks</span></code> object that passes all filesystem requests to a file server elsewhere, via some RPC mechanism such as ILU. Grail’s applet loader uses this to support importing applets from a URL for a directory.</p> <p>If <em>verbose</em> is true, additional debugging output may be sent to standard output.</p> </dd></dl> <p>It is important to be aware that code running in a restricted environment can still call the <a class="reference internal" href="sys.html#sys.exit" title="sys.exit"><code class="xref py py-func docutils literal notranslate"><span class="pre">sys.exit()</span></code></a> function. To disallow restricted code from exiting the interpreter, always protect calls that cause restricted code to run with a <a class="reference internal" href="../reference/compound_stmts.html#try"><code class="xref std std-keyword docutils literal notranslate"><span class="pre">try</span></code></a>/<a class="reference internal" href="../reference/compound_stmts.html#except"><code class="xref std std-keyword docutils literal notranslate"><span class="pre">except</span></code></a> statement that catches the <a class="reference internal" href="exceptions.html#exceptions.SystemExit" title="exceptions.SystemExit"><code class="xref py py-exc docutils literal notranslate"><span class="pre">SystemExit</span></code></a> exception. Removing the <a class="reference internal" href="sys.html#sys.exit" title="sys.exit"><code class="xref py py-func docutils literal notranslate"><span class="pre">sys.exit()</span></code></a> function from the restricted environment is not sufficient — the restricted code could still use <code class="docutils literal notranslate"><span class="pre">raise</span> <span class="pre">SystemExit</span></code>. Removing <a class="reference internal" href="exceptions.html#exceptions.SystemExit" title="exceptions.SystemExit"><code class="xref py py-exc docutils literal notranslate"><span class="pre">SystemExit</span></code></a> is not a reasonable option; some library code makes use of this and would break were it not available.</p> <div class="admonition seealso"> <p class="first admonition-title">See also</p> <dl class="last docutils"> <dt><a class="reference external" href="http://grail.sourceforge.net/">Grail Home Page</a></dt> <dd>Grail is a Web browser written entirely in Python. It uses the <a class="reference internal" href="#module-rexec" title="rexec: Basic restricted execution framework. (deprecated)"><code class="xref py py-mod docutils literal notranslate"><span class="pre">rexec</span></code></a> module as a foundation for supporting Python applets, and can be used as an example usage of this module.</dd> </dl> </div> <div class="section" id="rexec-objects"> <span id="id1"></span><h2>30.1.1. RExec Objects<a class="headerlink" href="#rexec-objects" title="Permalink to this headline">¶</a></h2> <p><a class="reference internal" href="#rexec.RExec" title="rexec.RExec"><code class="xref py py-class docutils literal notranslate"><span class="pre">RExec</span></code></a> instances support the following methods:</p> <dl class="method"> <dt id="rexec.RExec.r_eval"> <code class="descclassname">RExec.</code><code class="descname">r_eval</code><span class="sig-paren">(</span><em>code</em><span class="sig-paren">)</span><a class="headerlink" href="#rexec.RExec.r_eval" title="Permalink to this definition">¶</a></dt> <dd><p><em>code</em> must either be a string containing a Python expression, or a compiled code object, which will be evaluated in the restricted environment’s <a class="reference internal" href="__main__.html#module-__main__" title="__main__: The environment where the top-level script is run."><code class="xref py py-mod docutils literal notranslate"><span class="pre">__main__</span></code></a> module. The value of the expression or code object will be returned.</p> </dd></dl> <dl class="method"> <dt id="rexec.RExec.r_exec"> <code class="descclassname">RExec.</code><code class="descname">r_exec</code><span class="sig-paren">(</span><em>code</em><span class="sig-paren">)</span><a class="headerlink" href="#rexec.RExec.r_exec" title="Permalink to this definition">¶</a></dt> <dd><p><em>code</em> must either be a string containing one or more lines of Python code, or a compiled code object, which will be executed in the restricted environment’s <a class="reference internal" href="__main__.html#module-__main__" title="__main__: The environment where the top-level script is run."><code class="xref py py-mod docutils literal notranslate"><span class="pre">__main__</span></code></a> module.</p> </dd></dl> <dl class="method"> <dt id="rexec.RExec.r_execfile"> <code class="descclassname">RExec.</code><code class="descname">r_execfile</code><span class="sig-paren">(</span><em>filename</em><span class="sig-paren">)</span><a class="headerlink" href="#rexec.RExec.r_execfile" title="Permalink to this definition">¶</a></dt> <dd><p>Execute the Python code contained in the file <em>filename</em> in the restricted environment’s <a class="reference internal" href="__main__.html#module-__main__" title="__main__: The environment where the top-level script is run."><code class="xref py py-mod docutils literal notranslate"><span class="pre">__main__</span></code></a> module.</p> </dd></dl> <p>Methods whose names begin with <code class="docutils literal notranslate"><span class="pre">s_</span></code> are similar to the functions beginning with <code class="docutils literal notranslate"><span class="pre">r_</span></code>, but the code will be granted access to restricted versions of the standard I/O streams <code class="docutils literal notranslate"><span class="pre">sys.stdin</span></code>, <code class="docutils literal notranslate"><span class="pre">sys.stderr</span></code>, and <code class="docutils literal notranslate"><span class="pre">sys.stdout</span></code>.</p> <dl class="method"> <dt id="rexec.RExec.s_eval"> <code class="descclassname">RExec.</code><code class="descname">s_eval</code><span class="sig-paren">(</span><em>code</em><span class="sig-paren">)</span><a class="headerlink" href="#rexec.RExec.s_eval" title="Permalink to this definition">¶</a></dt> <dd><p><em>code</em> must be a string containing a Python expression, which will be evaluated in the restricted environment.</p> </dd></dl> <dl class="method"> <dt id="rexec.RExec.s_exec"> <code class="descclassname">RExec.</code><code class="descname">s_exec</code><span class="sig-paren">(</span><em>code</em><span class="sig-paren">)</span><a class="headerlink" href="#rexec.RExec.s_exec" title="Permalink to this definition">¶</a></dt> <dd><p><em>code</em> must be a string containing one or more lines of Python code, which will be executed in the restricted environment.</p> </dd></dl> <dl class="method"> <dt id="rexec.RExec.s_execfile"> <code class="descclassname">RExec.</code><code class="descname">s_execfile</code><span class="sig-paren">(</span><em>code</em><span class="sig-paren">)</span><a class="headerlink" href="#rexec.RExec.s_execfile" title="Permalink to this definition">¶</a></dt> <dd><p>Execute the Python code contained in the file <em>filename</em> in the restricted environment.</p> </dd></dl> <p><a class="reference internal" href="#rexec.RExec" title="rexec.RExec"><code class="xref py py-class docutils literal notranslate"><span class="pre">RExec</span></code></a> objects must also support various methods which will be implicitly called by code executing in the restricted environment. Overriding these methods in a subclass is used to change the policies enforced by a restricted environment.</p> <dl class="method"> <dt id="rexec.RExec.r_import"> <code class="descclassname">RExec.</code><code class="descname">r_import</code><span class="sig-paren">(</span><em>modulename</em><span class="optional">[</span>, <em>globals</em><span class="optional">[</span>, <em>locals</em><span class="optional">[</span>, <em>fromlist</em><span class="optional">]</span><span class="optional">]</span><span class="optional">]</span><span class="sig-paren">)</span><a class="headerlink" href="#rexec.RExec.r_import" title="Permalink to this definition">¶</a></dt> <dd><p>Import the module <em>modulename</em>, raising an <a class="reference internal" href="exceptions.html#exceptions.ImportError" title="exceptions.ImportError"><code class="xref py py-exc docutils literal notranslate"><span class="pre">ImportError</span></code></a> exception if the module is considered unsafe.</p> </dd></dl> <dl class="method"> <dt id="rexec.RExec.r_open"> <code class="descclassname">RExec.</code><code class="descname">r_open</code><span class="sig-paren">(</span><em>filename</em><span class="optional">[</span>, <em>mode</em><span class="optional">[</span>, <em>bufsize</em><span class="optional">]</span><span class="optional">]</span><span class="sig-paren">)</span><a class="headerlink" href="#rexec.RExec.r_open" title="Permalink to this definition">¶</a></dt> <dd><p>Method called when <a class="reference internal" href="functions.html#open" title="open"><code class="xref py py-func docutils literal notranslate"><span class="pre">open()</span></code></a> is called in the restricted environment. The arguments are identical to those of <a class="reference internal" href="functions.html#open" title="open"><code class="xref py py-func docutils literal notranslate"><span class="pre">open()</span></code></a>, and a file object (or a class instance compatible with file objects) should be returned. <a class="reference internal" href="#rexec.RExec" title="rexec.RExec"><code class="xref py py-class docutils literal notranslate"><span class="pre">RExec</span></code></a>’s default behaviour is allow opening any file for reading, but forbidding any attempt to write a file. See the example below for an implementation of a less restrictive <a class="reference internal" href="#rexec.RExec.r_open" title="rexec.RExec.r_open"><code class="xref py py-meth docutils literal notranslate"><span class="pre">r_open()</span></code></a>.</p> </dd></dl> <dl class="method"> <dt id="rexec.RExec.r_reload"> <code class="descclassname">RExec.</code><code class="descname">r_reload</code><span class="sig-paren">(</span><em>module</em><span class="sig-paren">)</span><a class="headerlink" href="#rexec.RExec.r_reload" title="Permalink to this definition">¶</a></dt> <dd><p>Reload the module object <em>module</em>, re-parsing and re-initializing it.</p> </dd></dl> <dl class="method"> <dt id="rexec.RExec.r_unload"> <code class="descclassname">RExec.</code><code class="descname">r_unload</code><span class="sig-paren">(</span><em>module</em><span class="sig-paren">)</span><a class="headerlink" href="#rexec.RExec.r_unload" title="Permalink to this definition">¶</a></dt> <dd><p>Unload the module object <em>module</em> (remove it from the restricted environment’s <code class="docutils literal notranslate"><span class="pre">sys.modules</span></code> dictionary).</p> </dd></dl> <p>And their equivalents with access to restricted standard I/O streams:</p> <dl class="method"> <dt id="rexec.RExec.s_import"> <code class="descclassname">RExec.</code><code class="descname">s_import</code><span class="sig-paren">(</span><em>modulename</em><span class="optional">[</span>, <em>globals</em><span class="optional">[</span>, <em>locals</em><span class="optional">[</span>, <em>fromlist</em><span class="optional">]</span><span class="optional">]</span><span class="optional">]</span><span class="sig-paren">)</span><a class="headerlink" href="#rexec.RExec.s_import" title="Permalink to this definition">¶</a></dt> <dd><p>Import the module <em>modulename</em>, raising an <a class="reference internal" href="exceptions.html#exceptions.ImportError" title="exceptions.ImportError"><code class="xref py py-exc docutils literal notranslate"><span class="pre">ImportError</span></code></a> exception if the module is considered unsafe.</p> </dd></dl> <dl class="method"> <dt id="rexec.RExec.s_reload"> <code class="descclassname">RExec.</code><code class="descname">s_reload</code><span class="sig-paren">(</span><em>module</em><span class="sig-paren">)</span><a class="headerlink" href="#rexec.RExec.s_reload" title="Permalink to this definition">¶</a></dt> <dd><p>Reload the module object <em>module</em>, re-parsing and re-initializing it.</p> </dd></dl> <dl class="method"> <dt id="rexec.RExec.s_unload"> <code class="descclassname">RExec.</code><code class="descname">s_unload</code><span class="sig-paren">(</span><em>module</em><span class="sig-paren">)</span><a class="headerlink" href="#rexec.RExec.s_unload" title="Permalink to this definition">¶</a></dt> <dd><p>Unload the module object <em>module</em>.</p> </dd></dl> </div> <div class="section" id="defining-restricted-environments"> <span id="rexec-extension"></span><h2>30.1.2. Defining restricted environments<a class="headerlink" href="#defining-restricted-environments" title="Permalink to this headline">¶</a></h2> <p>The <a class="reference internal" href="#rexec.RExec" title="rexec.RExec"><code class="xref py py-class docutils literal notranslate"><span class="pre">RExec</span></code></a> class has the following class attributes, which are used by the <a class="reference internal" href="../reference/datamodel.html#object.__init__" title="object.__init__"><code class="xref py py-meth docutils literal notranslate"><span class="pre">__init__()</span></code></a> method. Changing them on an existing instance won’t have any effect; instead, create a subclass of <a class="reference internal" href="#rexec.RExec" title="rexec.RExec"><code class="xref py py-class docutils literal notranslate"><span class="pre">RExec</span></code></a> and assign them new values in the class definition. Instances of the new class will then use those new values. All these attributes are tuples of strings.</p> <dl class="attribute"> <dt id="rexec.RExec.nok_builtin_names"> <code class="descclassname">RExec.</code><code class="descname">nok_builtin_names</code><a class="headerlink" href="#rexec.RExec.nok_builtin_names" title="Permalink to this definition">¶</a></dt> <dd><p>Contains the names of built-in functions which will <em>not</em> be available to programs running in the restricted environment. The value for <a class="reference internal" href="#rexec.RExec" title="rexec.RExec"><code class="xref py py-class docutils literal notranslate"><span class="pre">RExec</span></code></a> is <code class="docutils literal notranslate"><span class="pre">('open',</span> <span class="pre">'reload',</span> <span class="pre">'__import__')</span></code>. (This gives the exceptions, because by far the majority of built-in functions are harmless. A subclass that wants to override this variable should probably start with the value from the base class and concatenate additional forbidden functions — when new dangerous built-in functions are added to Python, they will also be added to this module.)</p> </dd></dl> <dl class="attribute"> <dt id="rexec.RExec.ok_builtin_modules"> <code class="descclassname">RExec.</code><code class="descname">ok_builtin_modules</code><a class="headerlink" href="#rexec.RExec.ok_builtin_modules" title="Permalink to this definition">¶</a></dt> <dd><p>Contains the names of built-in modules which can be safely imported. The value for <a class="reference internal" href="#rexec.RExec" title="rexec.RExec"><code class="xref py py-class docutils literal notranslate"><span class="pre">RExec</span></code></a> is <code class="docutils literal notranslate"><span class="pre">('audioop',</span> <span class="pre">'array',</span> <span class="pre">'binascii',</span> <span class="pre">'cmath',</span> <span class="pre">'errno',</span> <span class="pre">'imageop',</span> <span class="pre">'marshal',</span> <span class="pre">'math',</span> <span class="pre">'md5',</span> <span class="pre">'operator',</span> <span class="pre">'parser',</span> <span class="pre">'regex',</span> <span class="pre">'select',</span> <span class="pre">'sha',</span> <span class="pre">'_sre',</span> <span class="pre">'strop',</span> <span class="pre">'struct',</span> <span class="pre">'time')</span></code>. A similar remark about overriding this variable applies — use the value from the base class as a starting point.</p> </dd></dl> <dl class="attribute"> <dt id="rexec.RExec.ok_path"> <code class="descclassname">RExec.</code><code class="descname">ok_path</code><a class="headerlink" href="#rexec.RExec.ok_path" title="Permalink to this definition">¶</a></dt> <dd><p>Contains the directories which will be searched when an <a class="reference internal" href="../reference/simple_stmts.html#import"><code class="xref std std-keyword docutils literal notranslate"><span class="pre">import</span></code></a> is performed in the restricted environment. The value for <a class="reference internal" href="#rexec.RExec" title="rexec.RExec"><code class="xref py py-class docutils literal notranslate"><span class="pre">RExec</span></code></a> is the same as <code class="docutils literal notranslate"><span class="pre">sys.path</span></code> (at the time the module is loaded) for unrestricted code.</p> </dd></dl> <dl class="attribute"> <dt id="rexec.RExec.ok_posix_names"> <code class="descclassname">RExec.</code><code class="descname">ok_posix_names</code><a class="headerlink" href="#rexec.RExec.ok_posix_names" title="Permalink to this definition">¶</a></dt> <dd><p>Contains the names of the functions in the <a class="reference internal" href="os.html#module-os" title="os: Miscellaneous operating system interfaces."><code class="xref py py-mod docutils literal notranslate"><span class="pre">os</span></code></a> module which will be available to programs running in the restricted environment. The value for <a class="reference internal" href="#rexec.RExec" title="rexec.RExec"><code class="xref py py-class docutils literal notranslate"><span class="pre">RExec</span></code></a> is <code class="docutils literal notranslate"><span class="pre">('error',</span> <span class="pre">'fstat',</span> <span class="pre">'listdir',</span> <span class="pre">'lstat',</span> <span class="pre">'readlink',</span> <span class="pre">'stat',</span> <span class="pre">'times',</span> <span class="pre">'uname',</span> <span class="pre">'getpid',</span> <span class="pre">'getppid',</span> <span class="pre">'getcwd',</span> <span class="pre">'getuid',</span> <span class="pre">'getgid',</span> <span class="pre">'geteuid',</span> <span class="pre">'getegid')</span></code>.</p> </dd></dl> <dl class="attribute"> <dt id="rexec.RExec.ok_sys_names"> <code class="descclassname">RExec.</code><code class="descname">ok_sys_names</code><a class="headerlink" href="#rexec.RExec.ok_sys_names" title="Permalink to this definition">¶</a></dt> <dd><p>Contains the names of the functions and variables in the <a class="reference internal" href="sys.html#module-sys" title="sys: Access system-specific parameters and functions."><code class="xref py py-mod docutils literal notranslate"><span class="pre">sys</span></code></a> module which will be available to programs running in the restricted environment. The value for <a class="reference internal" href="#rexec.RExec" title="rexec.RExec"><code class="xref py py-class docutils literal notranslate"><span class="pre">RExec</span></code></a> is <code class="docutils literal notranslate"><span class="pre">('ps1',</span> <span class="pre">'ps2',</span> <span class="pre">'copyright',</span> <span class="pre">'version',</span> <span class="pre">'platform',</span> <span class="pre">'exit',</span> <span class="pre">'maxint')</span></code>.</p> </dd></dl> <dl class="attribute"> <dt id="rexec.RExec.ok_file_types"> <code class="descclassname">RExec.</code><code class="descname">ok_file_types</code><a class="headerlink" href="#rexec.RExec.ok_file_types" title="Permalink to this definition">¶</a></dt> <dd><p>Contains the file types from which modules are allowed to be loaded. Each file type is an integer constant defined in the <a class="reference internal" href="imp.html#module-imp" title="imp: Access the implementation of the import statement."><code class="xref py py-mod docutils literal notranslate"><span class="pre">imp</span></code></a> module. The meaningful values are <code class="xref py py-const docutils literal notranslate"><span class="pre">PY_SOURCE</span></code>, <code class="xref py py-const docutils literal notranslate"><span class="pre">PY_COMPILED</span></code>, and <code class="xref py py-const docutils literal notranslate"><span class="pre">C_EXTENSION</span></code>. The value for <a class="reference internal" href="#rexec.RExec" title="rexec.RExec"><code class="xref py py-class docutils literal notranslate"><span class="pre">RExec</span></code></a> is <code class="docutils literal notranslate"><span class="pre">(C_EXTENSION,</span> <span class="pre">PY_SOURCE)</span></code>. Adding <code class="xref py py-const docutils literal notranslate"><span class="pre">PY_COMPILED</span></code> in subclasses is not recommended; an attacker could exit the restricted execution mode by putting a forged byte-compiled file (<code class="file docutils literal notranslate"><span class="pre">.pyc</span></code>) anywhere in your file system, for example by writing it to <code class="file docutils literal notranslate"><span class="pre">/tmp</span></code> or uploading it to the <code class="file docutils literal notranslate"><span class="pre">/incoming</span></code> directory of your public FTP server.</p> </dd></dl> </div> <div class="section" id="an-example"> <h2>30.1.3. An example<a class="headerlink" href="#an-example" title="Permalink to this headline">¶</a></h2> <p>Let us say that we want a slightly more relaxed policy than the standard <a class="reference internal" href="#rexec.RExec" title="rexec.RExec"><code class="xref py py-class docutils literal notranslate"><span class="pre">RExec</span></code></a> class. For example, if we’re willing to allow files in <code class="file docutils literal notranslate"><span class="pre">/tmp</span></code> to be written, we can subclass the <a class="reference internal" href="#rexec.RExec" title="rexec.RExec"><code class="xref py py-class docutils literal notranslate"><span class="pre">RExec</span></code></a> class:</p> <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="k">class</span> <span class="nc">TmpWriterRExec</span><span class="p">(</span><span class="n">rexec</span><span class="o">.</span><span class="n">RExec</span><span class="p">):</span> <span class="k">def</span> <span class="nf">r_open</span><span class="p">(</span><span class="bp">self</span><span class="p">,</span> <span class="n">file</span><span class="p">,</span> <span class="n">mode</span><span class="o">=</span><span class="s1">'r'</span><span class="p">,</span> <span class="n">buf</span><span class="o">=-</span><span class="mi">1</span><span class="p">):</span> <span class="k">if</span> <span class="n">mode</span> <span class="ow">in</span> <span class="p">(</span><span class="s1">'r'</span><span class="p">,</span> <span class="s1">'rb'</span><span class="p">):</span> <span class="k">pass</span> <span class="k">elif</span> <span class="n">mode</span> <span class="ow">in</span> <span class="p">(</span><span class="s1">'w'</span><span class="p">,</span> <span class="s1">'wb'</span><span class="p">,</span> <span class="s1">'a'</span><span class="p">,</span> <span class="s1">'ab'</span><span class="p">):</span> <span class="c1"># check filename: must begin with /tmp/</span> <span class="k">if</span> <span class="n">file</span><span class="p">[:</span><span class="mi">5</span><span class="p">]</span><span class="o">!=</span><span class="s1">'/tmp/'</span><span class="p">:</span> <span class="k">raise</span> <span class="ne">IOError</span><span class="p">(</span><span class="s2">"can't write outside /tmp"</span><span class="p">)</span> <span class="k">elif</span> <span class="p">(</span><span class="n">string</span><span class="o">.</span><span class="n">find</span><span class="p">(</span><span class="n">file</span><span class="p">,</span> <span class="s1">'/../'</span><span class="p">)</span> <span class="o">>=</span> <span class="mi">0</span> <span class="ow">or</span> <span class="n">file</span><span class="p">[:</span><span class="mi">3</span><span class="p">]</span> <span class="o">==</span> <span class="s1">'../'</span> <span class="ow">or</span> <span class="n">file</span><span class="p">[</span><span class="o">-</span><span class="mi">3</span><span class="p">:]</span> <span class="o">==</span> <span class="s1">'/..'</span><span class="p">):</span> <span class="k">raise</span> <span class="ne">IOError</span><span class="p">(</span><span class="s2">"'..' in filename forbidden"</span><span class="p">)</span> <span class="k">else</span><span class="p">:</span> <span class="k">raise</span> <span class="ne">IOError</span><span class="p">(</span><span class="s2">"Illegal open() mode"</span><span class="p">)</span> <span class="k">return</span> <span class="nb">open</span><span class="p">(</span><span class="n">file</span><span class="p">,</span> <span class="n">mode</span><span class="p">,</span> <span class="n">buf</span><span class="p">)</span> </pre></div> </div> <p>Notice that the above code will occasionally forbid a perfectly valid filename; for example, code in the restricted environment won’t be able to open a file called <code class="file docutils literal notranslate"><span class="pre">/tmp/foo/../bar</span></code>. To fix this, the <code class="xref py py-meth docutils literal notranslate"><span class="pre">r_open()</span></code> method would have to simplify the filename to <code class="file docutils literal notranslate"><span class="pre">/tmp/bar</span></code>, which would require splitting apart the filename and performing various operations on it. In cases where security is at stake, it may be preferable to write simple code which is sometimes overly restrictive, instead of more general code that is also more complex and may harbor a subtle security hole.</p> </div> </div> </div> </div> </div> <div class="sphinxsidebar" role="navigation" aria-label="main navigation"> <div class="sphinxsidebarwrapper"> <h3><a href="../contents.html">Table Of Contents</a></h3> <ul> <li><a class="reference internal" href="#">30.1. <code class="docutils literal notranslate"><span class="pre">rexec</span></code> — Restricted execution framework</a><ul> <li><a class="reference internal" href="#rexec-objects">30.1.1. RExec Objects</a></li> <li><a class="reference internal" href="#defining-restricted-environments">30.1.2. Defining restricted environments</a></li> <li><a class="reference internal" href="#an-example">30.1.3. An example</a></li> </ul> </li> </ul> <h4>Previous topic</h4> <p class="topless"><a href="restricted.html" title="previous chapter">30. Restricted Execution</a></p> <h4>Next topic</h4> <p class="topless"><a href="bastion.html" title="next chapter">30.2. <code class="docutils literal notranslate"><span class="pre">Bastion</span></code> — Restricting access to objects</a></p> <div role="note" aria-label="source link"> <h3>This Page</h3> <ul class="this-page-menu"> <li><a href="../_sources/library/rexec.rst.txt" rel="nofollow">Show Source</a></li> </ul> </div> <div id="searchbox" style="display: none" role="search"> <h3>Quick search</h3> <div class="searchformwrapper"> <form class="search" action="../search.html" method="get"> <input type="text" name="q" /> <input type="submit" value="Go" /> <input type="hidden" name="check_keywords" value="yes" /> <input type="hidden" name="area" value="default" /> </form> </div> </div> <script type="text/javascript">$('#searchbox').show(0);</script> </div> </div> <div class="clearer"></div> </div> <div class="related" role="navigation" aria-label="related navigation"> <h3>Navigation</h3> <ul> <li class="right" style="margin-right: 10px"> <a href="../genindex.html" title="General Index" >index</a></li> <li class="right" > <a href="../py-modindex.html" title="Python Module Index" >modules</a> |</li> <li class="right" > <a href="bastion.html" title="30.2. Bastion — Restricting access to objects" >next</a> |</li> <li class="right" > <a href="restricted.html" title="30. Restricted Execution" >previous</a> |</li> <li><img src="../_static/py.png" alt="" style="vertical-align: middle; margin-top: -1px"/></li> <li><a href="https://www.python.org/">Python</a> »</li> <li> <a href="../index.html">Python 2.7.16 documentation</a> » </li> <li class="nav-item nav-item-1"><a href="index.html" >The Python Standard Library</a> »</li> <li class="nav-item nav-item-2"><a href="restricted.html" >30. Restricted Execution</a> »</li> </ul> </div> <div class="footer"> © <a href="../copyright.html">Copyright</a> 1990-2019, Python Software Foundation. <br /> The Python Software Foundation is a non-profit corporation. <a href="https://www.python.org/psf/donations/">Please donate.</a> <br /> Last updated on Mar 27, 2019. <a href="../bugs.html">Found a bug</a>? <br /> Created using <a href="http://sphinx.pocoo.org/">Sphinx</a> 1.7.6. </div> </body> </html>
Save
cmd:
run