From c3397574ffcc7c9411deeeb34d1bb1f407cd87c4 Mon Sep 17 00:00:00 2001 From: Olivier Dony Date: Tue, 1 Jun 2010 10:28:29 +0200 Subject: [PATCH] [FIX] continuing implementation of safe_eval: fixed some evaluation contexts bzr revid: odo@openerp.com-20100601082829-n6iqqm8f0wuscvtm --- bin/tools/convert.py | 13 +++++++------ bin/tools/safe_eval.py | 13 +++++++++++-- 2 files changed, 18 insertions(+), 8 deletions(-) diff --git a/bin/tools/convert.py b/bin/tools/convert.py index 5fb20530408..7f318b377f2 100644 --- a/bin/tools/convert.py +++ b/bin/tools/convert.py @@ -404,7 +404,8 @@ form: module.record_id""" % (xml_id,) def ref(str_id): return self.id_get(cr, None, str_id) - context = eval(context) + + context=eval(context, locals_dict=locals()) # domain = eval(domain) # XXX need to test this line -> uid, active_id, active_ids, ... res = { @@ -652,14 +653,14 @@ form: module.record_id""" % (xml_id,) if key in brrec: return brrec[key] return dict.__getitem__(self2, key) - globals = d() - globals['floatEqual'] = self._assert_equals - globals['ref'] = ref - globals['_ref'] = ref + globals_dict = d() + globals_dict['floatEqual'] = self._assert_equals + globals_dict['ref'] = ref + globals_dict['_ref'] = ref for test in rec.findall('./test'): f_expr = test.get("expr",'').encode('utf-8') expected_value = _eval_xml(self, test, self.pool, cr, uid, self.idref, context=context) or True - expression_value = eval(f_expr, globals) + expression_value = eval(f_expr, globals_dict, nocopy=True) if expression_value != expected_value: # assertion failed self.assert_report.record_assertion(False, severity) msg = 'assertion "%s" failed!\n' \ diff --git a/bin/tools/safe_eval.py b/bin/tools/safe_eval.py index f1a2ca1b5e7..0fcc7a20eb9 100644 --- a/bin/tools/safe_eval.py +++ b/bin/tools/safe_eval.py @@ -193,8 +193,8 @@ except ImportError: -def safe_eval(expr, globals_dict=None, locals_dict=None, mode="eval"): - """safe_eval(expression[, globals[, locals[, mode]]]) -> value +def safe_eval(expr, globals_dict=None, locals_dict=None, mode="eval", nocopy=False): + """safe_eval(expression[, globals[, locals[, mode[, nocopy]]]]) -> result System-restricted Python expression evaluation @@ -216,6 +216,14 @@ def safe_eval(expr, globals_dict=None, locals_dict=None, mode="eval"): if globals_dict is None: globals_dict = {} + + # prevent altering the globals/locals from within the sandbox + # by taking a copy. + if not nocopy: + globals_dict = dict(globals_dict) + if locals_dict is not None: + locals_dict = dict(locals_dict) + globals_dict.update( __builtins__ = { 'True': True, @@ -230,6 +238,7 @@ def safe_eval(expr, globals_dict=None, locals_dict=None, mode="eval"): 'tuple': tuple, } ) + return eval(test_expr(expr,_SAFE_OPCODES, mode=mode), globals_dict, locals_dict)