3 ms·
Is it possible to embed Gravity in my C/C++ project and safely run untrusted Gravity code? The Lua implementation supports the creation of sandboxes to run unt
by bakery2k 8y ago
Is it possible to embed Gravity in my C/C++ project and safely run untrusted Gravity code?
The Lua implementation supports the creation of sandboxes to run untrusted scripts, but this is a feature that other embeddable languages (e.g. Wren, Python) don't seem to support.
I feel like this would be a basic requirement - or is it common to embed a scripting language without limiting what scripts are able to do?
- SlowRobotAhead 8y agoAgreed, on my searching a VM to run foreign code is limited. You need a system that can run compiled code in order to be efficient, and interpreted is much more common but then you run into FFI issues. As to serialization of an interpreted it’s annoying that on embedded I’d have to send the letters “f” “o” “o” “(“ “x” “)” “;” which obviously kills some of the point here. mJS does the VM and FFI part OK, but I didn’t like some of the way it handled JS types coming back to C, it wasn’t clear for example that a C defined value passed in would return as a signed JS/NaN until converted.
- stormbrew 8y agoI think the issue is really just that effective sandboxing is really really hard to pull off right without also severely limiting the capabilities of the language/environment in undesirable ways, even for simple applications. Given that most of these things are volunteer projects and making strong claims about security is dangerous when you can't back it up, it's a tricky space most projects just don't want to touch.
- kevin_thibedeau 8y agoTcl is the granddaddy of embeddable scripting languages. It has had safe sub-interpreters for untrusted code for quite a while. They were added back when it had a shot of being a contender against JavaScript and safe script evaluation was deemed necessary.
- rkeene2 8y agoTcl supports this, and many systems use it: https://www.tcl.tk/man/tcl8.6/TclCmd/safe.htm https://www.tcl.tk/man/tcl8.6/TclCmd/safe.htm