5 ms·
Be careful with exec and eval in Python
- IgorPartola 16y agoIs there any reason why you would want to use exec or eval? In any language? I have never seen the need for it, but have seen plenty of very poor uses of eval in PHP and JavaScript. Are there any legitimate ones, aside from writing a debugger of some kind?
- amalcon 16y agoI've seen it used in JavaScript for compression before, on the same theory as one of those installers that starts off by unpacking itself. That's not as important now that everything gzips. I've also used it myself on occasion in quick-and-dirty scripts, but never in production code. It's just too easy to make a small mistake and blow your security wide open.
- IgorPartola 16y agoI guess that is one case I can see it being used: where actual manipulation of the source code is the only way to get the job done.
- the_mitsuhiko 16y agoIn Python versions older than 2.6 and on Google appengine it's the only reliable way to generate bytecode. For things like template engines this is important to not add extra overhead over an already slow language.
- IgorPartola 16y agoThat seems like a terrible approach to me. If your application's bottleneck is in parsing templates, either everything else is really fast or you have way too many complex templates. Maybe caching is a better strategy in that case. Then again, for a variety of reasons I have decided not to touch GAE if I can help it.
- the_mitsuhiko 16y ago> If your application's bottleneck is in parsing templates, either everything else is really fast or you have way too many complex templates. There are countless of examples where the template engine is the bottleneck of an application. If you are doubting that, I welcome you to try it yourself. Benchmarking Django's templates and Genshi is an eye opening experience. :)
- m0th87 16y agoProof is in the pudding. Where's the pudding? :) From a quick google search, they seem pretty comparable. And in fact Django oftentimes wins. http://genshi.edgewall.org/wiki/GenshiPerformance http://genshi.edgewall.org/wiki/GenshiPerformance http://stackoverflow.com/questions/1324238/what-is-the-fastest-template-system-for-python http://stackoverflow.com/questions/1324238/what-is-the-faste...
- the_mitsuhiko 16y agoNever trust a benchmark you didn't run yourself. A realistic Genshi template is butt slow. More than a handful function calls per byte emitted is not uncommon. Regarding Django it become a lot slower when they introduced automatic escaping and loop item unpacking a while ago. I have seen many people switching from Django templates to Jinja2 especially because of the increased performance.
- thezilch 16y agoI believe Mitsuhiko was trying to draw comparisons of Django or Genshi engines to those of Jinja2 or Mako. There was a well depicted article, year(s) back, showing (profiling) where Django templating was losing a lot of work, compared to Jinja. Unfortunately, the article appears to have fallen off pocoo.org, but you can find the HN discussion at the following: http://news.ycombinator.com/item?id=726461 http://news.ycombinator.com/item?id=726461
- m0th87 16y agoI don't see it as so much of a performance issue as a usability issue. Tornado uses eval for parsing templates. The nice effect of this is that you write Python snippets in your templates rather than learning an entirely new DSL for it (like in Django). It's pretty nice as long you're disciplined enough to not put business logic in the templates.
- btilly 16y agoIt is useful for autogenerated code. Which is a big sledgehammer that should only be swung carefully. But one use case is that you can have a DSL that you convert into code in your target language that you then eval. Given the ease of going horribly wrong with this strategy, I strongly recommend only using it in cases where it is obviously a huge win. Such cases are not non-existent, but they are rare.
- japherwocky 16y agoThe only good use I've seen for turning a template into a callable bit of code for performance.
- jashkenas 16y agoHere's a JavaScript example of such a templating function: http://documentcloud.github.com/underscore/docs/underscore.html#section-97 http://documentcloud.github.com/underscore/docs/underscore.h...
- Symmetry 16y agoI've used it in Matlab to get around the lack of first class functions and function pointers.
- IgorPartola 16y agoHeh. Clever, and I suppose nobody would be trying to find security vulnerabilities in Matlab scripts.
- dagw 16y agoI was just about to post the exact same thing. I guess it must be a more common technique than I imagined.
- Panoramix 16y agoIt can be somewhat handy when working in interactive mode, though it has a very informal feel to it. One (bad) example would go along the lines of: >>> def f(x): ... if x in dir(scipy): ... print eval("scipy." + x + "(2)") ... >>> f("sin") 0.909297426826 Then you can let the user plot whatever function they want.
- IgorPartola 16y agoCan't you use scipy.__dict__ to look up the function name in this case? scipy.__dict__[x](2)
- bobbyi 16y agoIt would be preferable to use getattr(scipy, x) rather than reaching inside the internals of the object (module).
- kingkilr 16y agogetattr(scipy, x)(2)
- wzdd 16y agoShort answer: no. Long answer: I have used it as part of a function that generates functions when I was writing an AST-generating portion of a parser. You need to make a bunch of similar functions, so you make a list of tuples containing all the bits that differ between the functions, then write a generator function which converts these strings into real Python functions which you can then eval in global context. Surprisingly enough this actually made the code more readable and easier to maintain. :) But that is literally the only time I have ever thought it was a good idea -- and that's in code where I completely control the data going to exec(), in code that will never be in an Internet-facing arrangement.
- getsat 16y agoRuby typically uses it pretty heavily (and to great effect) alongside its metaprogramming capabilities.
- kgo 16y agoHow about a REPL? http://svn.python.org/view/python/tags/r271/Lib/code.py?revision=86833&view=markup http://svn.python.org/view/python/tags/r271/Lib/code.py?revi...
- Scaevolus 16y agoI use compile/eval in an IRC bot I wrote (http://github.com/rmmh/skybot http://github.com/rmmh/skybot) for plugins. It lets me do hot-reloading of updated files, easily examine the namespace to find functions marked with various decorators, and not litter the plugin directory with unnecessary .pyc files. The builtin imp module has problems with reloading already-loaded modules, and I might have been able to do some weird hacks with __import__ to make it work like I wanted, but when the core functionality boils down to 3 lines of code, why bother?
- algorias 16y agoexec is useful to create a scripting environment inside a GUI application, without the need for separate processes/interpreters. Not without its issues, but works well enough for relatively simple needs.
- IgorPartola 16y agoA nugget from an old version of WordPress: eval('$v_result = '.$p_options[PCLZIP_CB_PRE_EXTRACT].'(PCLZIP_CB_PRE_EXTRACT, $v_local_header);')