Re: [PATCH] 'data' mode for loadfile
[
Date Prev][
Date Next][
Thread Prev][
Thread Next]
[
Date Index]
[
Thread Index]
- Subject: Re: [PATCH] 'data' mode for loadfile
- From: steve donovan <steve.j.donovan@...>
- Date: 2014年3月17日 20:11:28 +0200
On Mon, Mar 17, 2014 at 6:10 PM, Ashwin Hirschi <lua-l@reflexis.com> wrote:
> But those of a paranoid persuasion should probably combine it with other
> techniques (like, good old-fashioned sandboxing and such):
Oh definitely yes - one _starts_ with a custom environment. And watch
out for the default metatable for strings. (pl.pretty has a load with
a 'paranoid' mode which does this)
But, as Roberto points out, there is always a way to cause upset and disaster.