blob: 975bee08d4175020ff04632d620364d2d5e6627b [file] [log] [blame]
Guido van Rossum40d1ea31995-08-04 03:59:03 +00001"""Restricted execution facilities.
Guido van Rossum9a22de11995-01-12 12:29:47 +00002
Guido van Rossumfdd45cb1996-05-28 23:07:17 +00003The class RExec exports methods r_exec(), r_eval(), r_execfile(), and
4r_import(), which correspond roughly to the built-in operations
Guido van Rossum40d1ea31995-08-04 03:59:03 +00005exec, eval(), execfile() and import, but executing the code in an
6environment that only exposes those built-in operations that are
7deemed safe. To this end, a modest collection of 'fake' modules is
8created which mimics the standard modules by the same names. It is a
9policy decision which built-in modules and operations are made
10available; this module provides a reasonable default, but derived
11classes can change the policies e.g. by overriding or extending class
12variables like ok_builtin_modules or methods like make_sys().
13
Guido van Rossum13833561995-08-07 20:19:27 +000014XXX To do:
15- r_open should allow writing tmp dir
16- r_exec etc. with explicit globals/locals? (Use rexec("exec ... in ...")?)
Guido van Rossum13833561995-08-07 20:19:27 +000017
Guido van Rossum40d1ea31995-08-04 03:59:03 +000018"""
19
20
Guido van Rossum9a22de11995-01-12 12:29:47 +000021import sys
Guido van Rossum40d1ea31995-08-04 03:59:03 +000022import __builtin__
23import os
24import marshal
25import ihooks
Guido van Rossum9a22de11995-01-12 12:29:47 +000026
Guido van Rossum9a22de11995-01-12 12:29:47 +000027
Guido van Rossum13833561995-08-07 20:19:27 +000028class FileBase:
29
30 ok_file_methods = ('fileno', 'flush', 'isatty', 'read', 'readline',
31 'readlines', 'seek', 'tell', 'write', 'writelines')
32
33
34class FileWrapper(FileBase):
35
36 def __init__(self, f):
37 self.f = f
38 for m in self.ok_file_methods:
39 if not hasattr(self, m):
40 setattr(self, m, getattr(f, m))
41
42 def close(f):
43 self.flush()
44
45
46TEMPLATE = """
47def %s(self, *args):
48 return apply(getattr(self.mod, self.name).%s, args)
49"""
50
51class FileDelegate(FileBase):
52
53 def __init__(self, mod, name):
54 self.mod = mod
55 self.name = name
56
57 for m in FileBase.ok_file_methods + ('close',):
58 exec TEMPLATE % (m, m)
59
60
Guido van Rossum40d1ea31995-08-04 03:59:03 +000061class RHooks(ihooks.Hooks):
Guido van Rossum9a22de11995-01-12 12:29:47 +000062
Guido van Rossumfdd45cb1996-05-28 23:07:17 +000063 def __init__(self, *args):
64 # Hacks to support both old and new interfaces:
65 # old interface was RHooks(rexec[, verbose])
66 # new interface is RHooks([verbose])
67 verbose = 0
68 rexec = None
69 if args and type(args[-1]) == type(0):
70 verbose = args[-1]
71 args = args[:-1]
72 if args and hasattr(args[0], '__class__'):
73 rexec = args[0]
74 args = args[1:]
75 if args:
76 raise TypeError, "too many arguments"
Guido van Rossum40d1ea31995-08-04 03:59:03 +000077 ihooks.Hooks.__init__(self, verbose)
78 self.rexec = rexec
Guido van Rossum9a22de11995-01-12 12:29:47 +000079
Guido van Rossumfdd45cb1996-05-28 23:07:17 +000080 def set_rexec(self, rexec):
81 # Called by RExec instance to complete initialization
82 self.rexec = rexec
83
Guido van Rossum40d1ea31995-08-04 03:59:03 +000084 def is_builtin(self, name):
85 return self.rexec.is_builtin(name)
Guido van Rossum9a22de11995-01-12 12:29:47 +000086
Guido van Rossum40d1ea31995-08-04 03:59:03 +000087 def init_builtin(self, name):
88 m = __import__(name)
89 return self.rexec.copy_except(m, ())
Guido van Rossum9a22de11995-01-12 12:29:47 +000090
Guido van Rossum40d1ea31995-08-04 03:59:03 +000091 def init_frozen(self, name): raise SystemError, "don't use this"
92 def load_source(self, *args): raise SystemError, "don't use this"
93 def load_compiled(self, *args): raise SystemError, "don't use this"
94
Guido van Rossumfdd45cb1996-05-28 23:07:17 +000095 def load_dynamic(self, name, filename, file):
96 return self.rexec.load_dynamic(name, filename, file)
Guido van Rossum40d1ea31995-08-04 03:59:03 +000097
98 def add_module(self, name):
99 return self.rexec.add_module(name)
100
101 def modules_dict(self):
102 return self.rexec.modules
103
104 def default_path(self):
105 return self.rexec.modules['sys'].path
106
107
108class RModuleLoader(ihooks.FancyModuleLoader):
109
Guido van Rossum13833561995-08-07 20:19:27 +0000110 def load_module(self, name, stuff):
111 file, filename, info = stuff
112 m = ihooks.FancyModuleLoader.load_module(self, name, stuff)
113 m.__filename__ = filename
114 return m
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000115
116
117class RModuleImporter(ihooks.ModuleImporter):
118
Guido van Rossum13833561995-08-07 20:19:27 +0000119 def reload(self, module, path=None):
120 if path is None and hasattr(module, '__filename__'):
Guido van Rossum18596001995-08-10 19:40:39 +0000121 head, tail = os.path.split(module.__filename__)
Guido van Rossum1035a891995-08-11 13:56:04 +0000122 path = [os.path.join(head, '')]
Guido van Rossum13833561995-08-07 20:19:27 +0000123 return ihooks.ModuleImporter.reload(self, module, path)
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000124
125
126class RExec(ihooks._Verbose):
127
128 """Restricted Execution environment."""
129
130 ok_path = tuple(sys.path) # That's a policy decision
131
Guido van Rossumbebe5151995-08-09 02:32:08 +0000132 ok_builtin_modules = ('array', 'binascii', 'audioop', 'imageop',
133 'marshal', 'math',
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000134 'md5', 'parser', 'regex', 'rotor', 'select',
135 'strop', 'struct', 'time')
136
137 ok_posix_names = ('error', 'fstat', 'listdir', 'lstat', 'readlink',
138 'stat', 'times', 'uname', 'getpid', 'getppid',
139 'getcwd', 'getuid', 'getgid', 'geteuid', 'getegid')
140
141 ok_sys_names = ('ps1', 'ps2', 'copyright', 'version',
142 'platform', 'exit', 'maxint')
143
Guido van Rossum13833561995-08-07 20:19:27 +0000144 nok_builtin_names = ('open', 'reload', '__import__')
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000145
146 def __init__(self, hooks = None, verbose = 0):
147 ihooks._Verbose.__init__(self, verbose)
148 # XXX There's a circular reference here:
Guido van Rossumfdd45cb1996-05-28 23:07:17 +0000149 self.hooks = hooks or RHooks(verbose)
150 self.hooks.set_rexec(self)
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000151 self.modules = {}
Guido van Rossumfdd45cb1996-05-28 23:07:17 +0000152 self.ok_dynamic_modules = self.ok_builtin_modules
153 list = []
154 for mname in self.ok_builtin_modules:
155 if mname in sys.builtin_module_names:
156 list.append(mname)
157 self.ok_builtin_modules = list
158 self.set_trusted_path()
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000159 self.make_builtin()
160 self.make_initial_modules()
161 # make_sys must be last because it adds the already created
162 # modules to its builtin_module_names
163 self.make_sys()
164 self.loader = RModuleLoader(self.hooks, verbose)
165 self.importer = RModuleImporter(self.loader, verbose)
166
Guido van Rossumfdd45cb1996-05-28 23:07:17 +0000167 def set_trusted_path(self):
168 # Set the path from which dynamic modules may be loaded.
169 # Those dynamic modules must also occur in ok_builtin_modules
170 self.trusted_path = filter(os.path.isabs, sys.path)
171
172 def load_dynamic(self, name, filename, file):
173 if name not in self.ok_dynamic_modules:
174 raise ImportError, "untrusted dynamic module: %s" % name
175 if sys.modules.has_key(name):
176 src = sys.modules[key]
177 else:
178 import imp
179 src = imp.load_dynamic(name, filename, file)
180 dst = self.copy_except(src, [])
181 return dst
182
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000183 def make_initial_modules(self):
184 self.make_main()
185 self.make_osname()
186
187 # Helpers for RHooks
188
189 def is_builtin(self, mname):
190 return mname in self.ok_builtin_modules
191
192 # The make_* methods create specific built-in modules
193
194 def make_builtin(self):
195 m = self.copy_except(__builtin__, self.nok_builtin_names)
196 m.__import__ = self.r_import
Guido van Rossum13833561995-08-07 20:19:27 +0000197 m.reload = self.r_reload
198 m.open = self.r_open
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000199
200 def make_main(self):
201 m = self.add_module('__main__')
202
203 def make_osname(self):
204 osname = os.name
205 src = __import__(osname)
206 dst = self.copy_only(src, self.ok_posix_names)
207 dst.environ = e = {}
208 for key, value in os.environ.items():
209 e[key] = value
210
211 def make_sys(self):
212 m = self.copy_only(sys, self.ok_sys_names)
213 m.modules = self.modules
214 m.argv = ['RESTRICTED']
215 m.path = map(None, self.ok_path)
216 m = self.modules['sys']
217 m.builtin_module_names = \
218 self.modules.keys() + self.ok_builtin_modules
219 m.builtin_module_names.sort()
220
221 # The copy_* methods copy existing modules with some changes
222
223 def copy_except(self, src, exceptions):
224 dst = self.copy_none(src)
225 for name in dir(src):
Guido van Rossumfdd45cb1996-05-28 23:07:17 +0000226 setattr(dst, name, getattr(src, name))
227 for name in exceptions:
228 try:
229 delattr(dst, name)
230 except KeyError:
231 pass
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000232 return dst
233
234 def copy_only(self, src, names):
235 dst = self.copy_none(src)
236 for name in names:
237 try:
238 value = getattr(src, name)
239 except AttributeError:
240 continue
241 setattr(dst, name, value)
242 return dst
243
244 def copy_none(self, src):
245 return self.add_module(src.__name__)
246
247 # Add a module -- return an existing module or create one
248
249 def add_module(self, mname):
250 if self.modules.has_key(mname):
251 return self.modules[mname]
252 self.modules[mname] = m = self.hooks.new_module(mname)
253 m.__builtins__ = self.modules['__builtin__']
Guido van Rossum9a22de11995-01-12 12:29:47 +0000254 return m
255
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000256 # The r* methods are public interfaces
Guido van Rossum9a22de11995-01-12 12:29:47 +0000257
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000258 def r_exec(self, code):
259 m = self.add_module('__main__')
260 exec code in m.__dict__
Guido van Rossum9a22de11995-01-12 12:29:47 +0000261
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000262 def r_eval(self, code):
263 m = self.add_module('__main__')
264 return eval(code, m.__dict__)
Guido van Rossum9a22de11995-01-12 12:29:47 +0000265
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000266 def r_execfile(self, file):
267 m = self.add_module('__main__')
268 return execfile(file, m.__dict__)
Guido van Rossum9a22de11995-01-12 12:29:47 +0000269
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000270 def r_import(self, mname, globals={}, locals={}, fromlist=[]):
271 return self.importer.import_module(mname, globals, locals, fromlist)
Guido van Rossum9a22de11995-01-12 12:29:47 +0000272
Guido van Rossum13833561995-08-07 20:19:27 +0000273 def r_reload(self, m):
274 return self.importer.reload(m)
Guido van Rossumbebe5151995-08-09 02:32:08 +0000275
276 def r_unload(self, m):
277 return self.importer.unload(m)
Guido van Rossum13833561995-08-07 20:19:27 +0000278
279 # The s_* methods are similar but also swap std{in,out,err}
280
281 def set_files(self):
282 s = self.modules['sys']
283 s.stdin = FileWrapper(sys.stdin)
284 s.stdout = FileWrapper(sys.stdout)
285 s.stderr = FileWrapper(sys.stderr)
286 sys.stdin = FileDelegate(s, 'stdin')
287 sys.stdout = FileDelegate(s, 'stdout')
288 sys.stderr = FileDelegate(s, 'stderr')
289
290 def save_files(self):
291 self.save_stdin = sys.stdin
292 self.save_stdout = sys.stdout
293 self.save_stderr = sys.stderr
294
295 def restore_files(files):
296 sys.stdin = self.save_sydin
297 sys.stdout = self.save_stdout
298 sys.stderr = self.save_stderr
299
300 def s_apply(self, func, *args, **kw):
301 self.save_files()
302 try:
303 self.set_files()
304 r = apply(func, args, kw)
305 finally:
306 self.restore_files()
307
308 def s_exec(self, *args):
309 self.s_apply(self.r_exec, args)
310
311 def s_eval(self, *args):
312 self.s_apply(self.r_eval, args)
313
314 def s_execfile(self, *args):
315 self.s_apply(self.r_execfile, args)
316
317 def s_import(self, *args):
318 self.s_apply(self.r_import, args)
319
320 def s_reload(self, *args):
321 self.s_apply(self.r_reload, args)
322
Guido van Rossumbebe5151995-08-09 02:32:08 +0000323 def s_unload(self, *args):
324 self.s_apply(self.r_unload, args)
325
Guido van Rossum13833561995-08-07 20:19:27 +0000326 # Restricted open(...)
327
328 def r_open(self, file, mode='r', buf=-1):
329 if mode not in ('r', 'rb'):
330 raise IOError, "can't open files for writing in restricted mode"
Guido van Rossumbebe5151995-08-09 02:32:08 +0000331 return open(file, mode, buf)
Guido van Rossum13833561995-08-07 20:19:27 +0000332
Guido van Rossum9a22de11995-01-12 12:29:47 +0000333
334def test():
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000335 import traceback
336 r = RExec(None, '-v' in sys.argv[1:])
337 print "*** RESTRICTED *** Python", sys.version
338 print sys.copyright
339 while 1:
340 try:
341 try:
342 s = raw_input('>>> ')
343 except EOFError:
344 print
345 break
346 if s and s[0] != '#':
347 s = s + '\n'
348 c = compile(s, '<stdin>', 'single')
349 r.r_exec(c)
350 except SystemExit, n:
351 sys.exit(n)
352 except:
353 traceback.print_exc()
354
Guido van Rossum9a22de11995-01-12 12:29:47 +0000355
356if __name__ == '__main__':
Guido van Rossum40d1ea31995-08-04 03:59:03 +0000357 test()