[Date Prev][Date Next][Thread Prev][Thread Next]
[Date Index]
[Thread Index]
- Subject: Re: [PATCH] 'data' mode for loadfile
- From: steve donovan <steve.j.donovan@...>
- Date: Mon, 17 Mar 2014 20:11:28 +0200
On Mon, Mar 17, 2014 at 6:10 PM, Ashwin Hirschi <lua-l@reflexis.com> wrote:
> But those of a paranoid persuasion should probably combine it with other
> techniques (like, good old-fashioned sandboxing and such):
Oh definitely yes - one _starts_ with a custom environment. And watch
out for the default metatable for strings. (pl.pretty has a load with
a 'paranoid' mode which does this)
But, as Roberto points out, there is always a way to cause upset and disaster.