Message385410
I agree with Victor, we should not be attempting to build a sandbox.
https://www.python.org/dev/peps/pep-0578/#why-not-a-sandbox
Preventing access to global variables is next to impossible. Adding more and more hooks to prevent access to globals, merely adds the illusion of security. Sooner or later, someone will find a path to globals that would have a serious impact on performance to block.
We should assume that globals are accessible from user code, and write the audit function accordingly. Either in C or using a closure. |
|
Date |
User |
Action |
Args |
2021-01-21 11:53:07 | Mark.Shannon | set | recipients:
+ Mark.Shannon, vstinner, christian.heimes, steve.dower, ammar2, lunixbochs2 |
2021-01-21 11:53:07 | Mark.Shannon | set | messageid: <1611229987.38.0.389502725439.issue42800@roundup.psfhosted.org> |
2021-01-21 11:53:07 | Mark.Shannon | link | issue42800 messages |
2021-01-21 11:53:07 | Mark.Shannon | create | |
|