blob: 792fb8eabdf6b4f561c402e2c9df86f9d274690d [file] [log] [blame]
Guido van Rossum40d1ea31995-08-04 03:59:03 +00001"""Restricted execution facilities.
Guido van Rossum9a22de11995-01-12 12:29:47 +00002
Guido van Rossumfdd45cb1996-05-28 23:07:17 +00003The class RExec exports methods r_exec(), r_eval(), r_execfile(), and
4r_import(), which correspond roughly to the built-in operations
Guido van Rossum40d1ea31995-08-04 03:59:03 +00005exec, eval(), execfile() and import, but executing the code in an
6environment that only exposes those built-in operations that are
7deemed safe. To this end, a modest collection of 'fake' modules is
8created which mimics the standard modules by the same names. It is a
9policy decision which built-in modules and operations are made
10available; this module provides a reasonable default, but derived
11classes can change the policies e.g. by overriding or extending class
12variables like ok_builtin_modules or methods like make_sys().
13
Guido van Rossum13833561995-08-07 20:19:27 +000014XXX To do:
15- r_open should allow writing tmp dir
16- r_exec etc. with explicit globals/locals? (Use rexec("exec ... in ...")?)
Guido van Rossum13833561995-08-07 20:19:27 +000017
Guido van Rossum40d1ea31995-08-04 03:59:03 +000018"""
19
20
Guido van Rossum9a22de11995-01-12 12:29:47 +000021import sys
Guido van Rossum40d1ea31995-08-04 03:59:03 +000022import __builtin__
23import os
Guido van Rossum40d1ea31995-08-04 03:59:03 +000024import ihooks
Guido van Rossum9a22de11995-01-12 12:29:47 +000025
Guido van Rossum9a22de11995-01-12 12:29:47 +000026
Guido van Rossum13833561995-08-07 20:19:27 +000027class FileBase:
28
Guido van Rossum3ec38f01998-03-26 22:10:50 +000029 ok_file_methods = ('fileno', 'flush', 'isatty', 'read', 'readline',
30 'readlines', 'seek', 'tell', 'write', 'writelines')
Guido van Rossum13833561995-08-07 20:19:27 +000031
32
33class FileWrapper(FileBase):
34
Guido van Rossum3ec38f01998-03-26 22:10:50 +000035 # XXX This is just like a Bastion -- should use that!
Guido van Rossumcd6aab91996-06-28 17:28:51 +000036
Guido van Rossum3ec38f01998-03-26 22:10:50 +000037 def __init__(self, f):
38 self.f = f
39 for m in self.ok_file_methods:
40 if not hasattr(self, m) and hasattr(f, m):
41 setattr(self, m, getattr(f, m))
42
43 def close(self):
44 self.flush()
Guido van Rossum13833561995-08-07 20:19:27 +000045
46
47TEMPLATE = """
48def %s(self, *args):
Guido van Rossum3ec38f01998-03-26 22:10:50 +000049 return apply(getattr(self.mod, self.name).%s, args)
Guido van Rossum13833561995-08-07 20:19:27 +000050"""
51
52class FileDelegate(FileBase):
53
Guido van Rossum3ec38f01998-03-26 22:10:50 +000054 def __init__(self, mod, name):
55 self.mod = mod
56 self.name = name
57
58 for m in FileBase.ok_file_methods + ('close',):
59 exec TEMPLATE % (m, m)
Guido van Rossum13833561995-08-07 20:19:27 +000060
61
Guido van Rossum40d1ea31995-08-04 03:59:03 +000062class RHooks(ihooks.Hooks):
Guido van Rossum9a22de11995-01-12 12:29:47 +000063
Guido van Rossumfdd45cb1996-05-28 23:07:17 +000064 def __init__(self, *args):
Guido van Rossum3ec38f01998-03-26 22:10:50 +000065 # Hacks to support both old and new interfaces:
66 # old interface was RHooks(rexec[, verbose])
67 # new interface is RHooks([verbose])
68 verbose = 0
69 rexec = None
70 if args and type(args[-1]) == type(0):
71 verbose = args[-1]
72 args = args[:-1]
73 if args and hasattr(args[0], '__class__'):
74 rexec = args[0]
75 args = args[1:]
76 if args:
77 raise TypeError, "too many arguments"
78 ihooks.Hooks.__init__(self, verbose)
79 self.rexec = rexec
Guido van Rossum9a22de11995-01-12 12:29:47 +000080
Guido van Rossumfdd45cb1996-05-28 23:07:17 +000081 def set_rexec(self, rexec):
Guido van Rossum3ec38f01998-03-26 22:10:50 +000082 # Called by RExec instance to complete initialization
83 self.rexec = rexec
Guido van Rossumfdd45cb1996-05-28 23:07:17 +000084
Guido van Rossum40d1ea31995-08-04 03:59:03 +000085 def is_builtin(self, name):
Guido van Rossum3ec38f01998-03-26 22:10:50 +000086 return self.rexec.is_builtin(name)
Guido van Rossum9a22de11995-01-12 12:29:47 +000087
Guido van Rossum40d1ea31995-08-04 03:59:03 +000088 def init_builtin(self, name):
Guido van Rossum3ec38f01998-03-26 22:10:50 +000089 m = __import__(name)
90 return self.rexec.copy_except(m, ())
Guido van Rossum9a22de11995-01-12 12:29:47 +000091
Guido van Rossum40d1ea31995-08-04 03:59:03 +000092 def init_frozen(self, name): raise SystemError, "don't use this"
93 def load_source(self, *args): raise SystemError, "don't use this"
94 def load_compiled(self, *args): raise SystemError, "don't use this"
Guido van Rossum8b3282b1998-06-29 20:32:57 +000095 def load_package(self, *args): raise SystemError, "don't use this"
Guido van Rossum40d1ea31995-08-04 03:59:03 +000096
Guido van Rossumfdd45cb1996-05-28 23:07:17 +000097 def load_dynamic(self, name, filename, file):
Guido van Rossum3ec38f01998-03-26 22:10:50 +000098 return self.rexec.load_dynamic(name, filename, file)
Guido van Rossum40d1ea31995-08-04 03:59:03 +000099
100 def add_module(self, name):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000101 return self.rexec.add_module(name)
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000102
103 def modules_dict(self):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000104 return self.rexec.modules
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000105
106 def default_path(self):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000107 return self.rexec.modules['sys'].path
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000108
109
110class RModuleLoader(ihooks.FancyModuleLoader):
111
Guido van Rossum13833561995-08-07 20:19:27 +0000112 def load_module(self, name, stuff):
113 file, filename, info = stuff
114 m = ihooks.FancyModuleLoader.load_module(self, name, stuff)
115 m.__filename__ = filename
116 return m
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000117
118
119class RModuleImporter(ihooks.ModuleImporter):
120
Guido van Rossum13833561995-08-07 20:19:27 +0000121 def reload(self, module, path=None):
122 if path is None and hasattr(module, '__filename__'):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000123 head, tail = os.path.split(module.__filename__)
124 path = [os.path.join(head, '')]
Guido van Rossum13833561995-08-07 20:19:27 +0000125 return ihooks.ModuleImporter.reload(self, module, path)
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000126
127
128class RExec(ihooks._Verbose):
129
130 """Restricted Execution environment."""
131
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000132 ok_path = tuple(sys.path) # That's a policy decision
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000133
Guido van Rossume7b9fde1996-09-25 18:47:39 +0000134 ok_builtin_modules = ('audioop', 'array', 'binascii',
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000135 'cmath', 'errno', 'imageop',
136 'marshal', 'math', 'md5', 'operator',
137 'parser', 'regex', 'pcre', 'rotor', 'select',
138 'strop', 'struct', 'time')
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000139
140 ok_posix_names = ('error', 'fstat', 'listdir', 'lstat', 'readlink',
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000141 'stat', 'times', 'uname', 'getpid', 'getppid',
142 'getcwd', 'getuid', 'getgid', 'geteuid', 'getegid')
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000143
144 ok_sys_names = ('ps1', 'ps2', 'copyright', 'version',
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000145 'platform', 'exit', 'maxint')
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000146
Guido van Rossum13833561995-08-07 20:19:27 +0000147 nok_builtin_names = ('open', 'reload', '__import__')
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000148
149 def __init__(self, hooks = None, verbose = 0):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000150 ihooks._Verbose.__init__(self, verbose)
151 # XXX There's a circular reference here:
152 self.hooks = hooks or RHooks(verbose)
153 self.hooks.set_rexec(self)
154 self.modules = {}
155 self.ok_dynamic_modules = self.ok_builtin_modules
156 list = []
157 for mname in self.ok_builtin_modules:
158 if mname in sys.builtin_module_names:
159 list.append(mname)
160 self.ok_builtin_modules = tuple(list)
161 self.set_trusted_path()
162 self.make_builtin()
163 self.make_initial_modules()
164 # make_sys must be last because it adds the already created
165 # modules to its builtin_module_names
166 self.make_sys()
167 self.loader = RModuleLoader(self.hooks, verbose)
168 self.importer = RModuleImporter(self.loader, verbose)
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000169
Guido van Rossumfdd45cb1996-05-28 23:07:17 +0000170 def set_trusted_path(self):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000171 # Set the path from which dynamic modules may be loaded.
172 # Those dynamic modules must also occur in ok_builtin_modules
173 self.trusted_path = filter(os.path.isabs, sys.path)
Guido van Rossumfdd45cb1996-05-28 23:07:17 +0000174
175 def load_dynamic(self, name, filename, file):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000176 if name not in self.ok_dynamic_modules:
177 raise ImportError, "untrusted dynamic module: %s" % name
178 if sys.modules.has_key(name):
179 src = sys.modules[name]
180 else:
181 import imp
182 src = imp.load_dynamic(name, filename, file)
183 dst = self.copy_except(src, [])
184 return dst
Guido van Rossumfdd45cb1996-05-28 23:07:17 +0000185
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000186 def make_initial_modules(self):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000187 self.make_main()
188 self.make_osname()
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000189
190 # Helpers for RHooks
191
192 def is_builtin(self, mname):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000193 return mname in self.ok_builtin_modules
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000194
195 # The make_* methods create specific built-in modules
196
197 def make_builtin(self):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000198 m = self.copy_except(__builtin__, self.nok_builtin_names)
199 m.__import__ = self.r_import
200 m.reload = self.r_reload
201 m.open = self.r_open
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000202
203 def make_main(self):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000204 m = self.add_module('__main__')
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000205
206 def make_osname(self):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000207 osname = os.name
208 src = __import__(osname)
209 dst = self.copy_only(src, self.ok_posix_names)
210 dst.environ = e = {}
211 for key, value in os.environ.items():
212 e[key] = value
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000213
214 def make_sys(self):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000215 m = self.copy_only(sys, self.ok_sys_names)
216 m.modules = self.modules
217 m.argv = ['RESTRICTED']
218 m.path = map(None, self.ok_path)
Guido van Rossumeeb64281998-07-09 13:52:38 +0000219 m.exc_info = self.r_exc_info
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000220 m = self.modules['sys']
221 l = self.modules.keys() + list(self.ok_builtin_modules)
222 l.sort()
223 m.builtin_module_names = tuple(l)
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000224
225 # The copy_* methods copy existing modules with some changes
226
227 def copy_except(self, src, exceptions):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000228 dst = self.copy_none(src)
229 for name in dir(src):
230 setattr(dst, name, getattr(src, name))
231 for name in exceptions:
232 try:
233 delattr(dst, name)
234 except AttributeError:
235 pass
236 return dst
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000237
238 def copy_only(self, src, names):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000239 dst = self.copy_none(src)
240 for name in names:
241 try:
242 value = getattr(src, name)
243 except AttributeError:
244 continue
245 setattr(dst, name, value)
246 return dst
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000247
248 def copy_none(self, src):
Guido van Rossum1f40cd61998-06-09 21:33:44 +0000249 m = self.add_module(src.__name__)
250 m.__doc__ = src.__doc__
251 return m
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000252
253 # Add a module -- return an existing module or create one
254
255 def add_module(self, mname):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000256 if self.modules.has_key(mname):
257 return self.modules[mname]
258 self.modules[mname] = m = self.hooks.new_module(mname)
259 m.__builtins__ = self.modules['__builtin__']
260 return m
Guido van Rossum9a22de11995-01-12 12:29:47 +0000261
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000262 # The r* methods are public interfaces
Guido van Rossum9a22de11995-01-12 12:29:47 +0000263
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000264 def r_exec(self, code):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000265 m = self.add_module('__main__')
266 exec code in m.__dict__
Guido van Rossum9a22de11995-01-12 12:29:47 +0000267
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000268 def r_eval(self, code):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000269 m = self.add_module('__main__')
270 return eval(code, m.__dict__)
Guido van Rossum9a22de11995-01-12 12:29:47 +0000271
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000272 def r_execfile(self, file):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000273 m = self.add_module('__main__')
274 return execfile(file, m.__dict__)
Guido van Rossum9a22de11995-01-12 12:29:47 +0000275
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000276 def r_import(self, mname, globals={}, locals={}, fromlist=[]):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000277 return self.importer.import_module(mname, globals, locals, fromlist)
Guido van Rossum9a22de11995-01-12 12:29:47 +0000278
Guido van Rossum13833561995-08-07 20:19:27 +0000279 def r_reload(self, m):
280 return self.importer.reload(m)
Guido van Rossumbebe5151995-08-09 02:32:08 +0000281
282 def r_unload(self, m):
283 return self.importer.unload(m)
Guido van Rossum13833561995-08-07 20:19:27 +0000284
285 # The s_* methods are similar but also swap std{in,out,err}
286
Guido van Rossumcd6aab91996-06-28 17:28:51 +0000287 def make_delegate_files(self):
Guido van Rossum13833561995-08-07 20:19:27 +0000288 s = self.modules['sys']
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000289 self.delegate_stdin = FileDelegate(s, 'stdin')
290 self.delegate_stdout = FileDelegate(s, 'stdout')
291 self.delegate_stderr = FileDelegate(s, 'stderr')
Guido van Rossumcd6aab91996-06-28 17:28:51 +0000292 self.restricted_stdin = FileWrapper(sys.stdin)
293 self.restricted_stdout = FileWrapper(sys.stdout)
294 self.restricted_stderr = FileWrapper(sys.stderr)
295
296 def set_files(self):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000297 if not hasattr(self, 'save_stdin'):
298 self.save_files()
299 if not hasattr(self, 'delegate_stdin'):
300 self.make_delegate_files()
Guido van Rossumcd6aab91996-06-28 17:28:51 +0000301 s = self.modules['sys']
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000302 s.stdin = self.restricted_stdin
303 s.stdout = self.restricted_stdout
304 s.stderr = self.restricted_stderr
305 sys.stdin = self.delegate_stdin
306 sys.stdout = self.delegate_stdout
307 sys.stderr = self.delegate_stderr
Guido van Rossumcd6aab91996-06-28 17:28:51 +0000308
309 def reset_files(self):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000310 self.restore_files()
Guido van Rossumcd6aab91996-06-28 17:28:51 +0000311 s = self.modules['sys']
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000312 self.restricted_stdin = s.stdin
313 self.restricted_stdout = s.stdout
314 self.restricted_stderr = s.stderr
315
Guido van Rossum13833561995-08-07 20:19:27 +0000316
317 def save_files(self):
318 self.save_stdin = sys.stdin
319 self.save_stdout = sys.stdout
320 self.save_stderr = sys.stderr
321
Guido van Rossumcd6aab91996-06-28 17:28:51 +0000322 def restore_files(self):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000323 sys.stdin = self.save_stdin
324 sys.stdout = self.save_stdout
325 sys.stderr = self.save_stderr
Guido van Rossum13833561995-08-07 20:19:27 +0000326
Guido van Rossume7b9fde1996-09-25 18:47:39 +0000327 def s_apply(self, func, args=(), kw=None):
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000328 self.save_files()
329 try:
330 self.set_files()
331 if kw:
332 r = apply(func, args, kw)
333 else:
334 r = apply(func, args)
Guido van Rossum13833561995-08-07 20:19:27 +0000335 finally:
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000336 self.restore_files()
Guido van Rossum13833561995-08-07 20:19:27 +0000337
338 def s_exec(self, *args):
339 self.s_apply(self.r_exec, args)
340
341 def s_eval(self, *args):
342 self.s_apply(self.r_eval, args)
343
344 def s_execfile(self, *args):
345 self.s_apply(self.r_execfile, args)
346
347 def s_import(self, *args):
348 self.s_apply(self.r_import, args)
349
350 def s_reload(self, *args):
351 self.s_apply(self.r_reload, args)
352
Guido van Rossumbebe5151995-08-09 02:32:08 +0000353 def s_unload(self, *args):
354 self.s_apply(self.r_unload, args)
355
Guido van Rossum13833561995-08-07 20:19:27 +0000356 # Restricted open(...)
357
358 def r_open(self, file, mode='r', buf=-1):
359 if mode not in ('r', 'rb'):
360 raise IOError, "can't open files for writing in restricted mode"
Guido van Rossumbebe5151995-08-09 02:32:08 +0000361 return open(file, mode, buf)
Guido van Rossum13833561995-08-07 20:19:27 +0000362
Guido van Rossumeeb64281998-07-09 13:52:38 +0000363 # Restricted version of sys.exc_info()
364
365 def r_exc_info(self):
366 ty, va, tr = sys.exc_info()
367 tr = None
368 return ty, va, tr
369
Guido van Rossum9a22de11995-01-12 12:29:47 +0000370
371def test():
Guido van Rossumeeb64281998-07-09 13:52:38 +0000372 import sys, getopt, traceback
373 opts, args = getopt.getopt(sys.argv[1:], 'vt:')
374 verbose = 0
375 trusted = []
376 for o, a in opts:
377 if o == '-v':
378 verbose = verbose+1
379 if o == '-t':
380 trusted.append(a)
381 r = RExec(verbose=verbose)
382 if trusted:
383 r.ok_builtin_modules = r.ok_builtin_modules + tuple(trusted)
384 if args:
385 r.modules['sys'].argv = args
386 r.modules['sys'].path.insert(0, os.path.dirname(args[0]))
387 else:
388 r.modules['sys'].path.insert(0, "")
389 fp = sys.stdin
390 if args and args[0] != '-':
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000391 try:
Guido van Rossumeeb64281998-07-09 13:52:38 +0000392 fp = open(args[0])
393 except IOError, msg:
394 print "%s: can't open file %s" % (sys.argv[0], `args[0]`)
395 return 1
396 if fp.isatty():
397 print "*** RESTRICTED *** Python", sys.version
398 print sys.copyright
399 while 1:
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000400 try:
Guido van Rossumeeb64281998-07-09 13:52:38 +0000401 try:
402 s = raw_input('>>> ')
403 except EOFError:
404 print
405 break
406 if s and s[0] != '#':
407 s = s + '\n'
408 c = compile(s, '<stdin>', 'single')
409 r.s_exec(c)
410 except SystemExit, n:
411 return n
412 except:
413 traceback.print_exc()
414 else:
415 text = fp.read()
416 fp.close()
417 c = compile(text, fp.name, 'exec')
418 try:
419 r.s_exec(c)
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000420 except SystemExit, n:
Guido van Rossumeeb64281998-07-09 13:52:38 +0000421 return n
Guido van Rossum3ec38f01998-03-26 22:10:50 +0000422 except:
423 traceback.print_exc()
Guido van Rossumeeb64281998-07-09 13:52:38 +0000424 return 1
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000425
Guido van Rossum9a22de11995-01-12 12:29:47 +0000426
427if __name__ == '__main__':
Guido van Rossumeeb64281998-07-09 13:52:38 +0000428 sys.exit(test())