3 ms·
I looked into it, and Lua allows limiting the environment when `load`ing -- through `env` argument since 5.2 or through setfenv before. I will add a helper func
by girvel 2y ago
I looked into it, and Lua allows limiting the environment when `load`ing -- through `env` argument since 5.2 or through setfenv before. I will add a helper function to produce a minimal needed environment for safe loading and a documentation page about safety.
- myrmidon 2y agoNote that loading (maliciously crafted) bytecode is generally not safe in Lua; sandboxing can be escaped in more ways than what's possible when loading plaintext sourcecode, and there are no full mitigations for this currently as far as I know (and would probably be highly interpreter/version sensitive anyway)-- the only "real" mitigation strategy is to just not `load` bytecode at all. But this is probably a non-issue for a lot of usecases. See e.g. https://gist.github.com/corsix/6575486 https://gist.github.com/corsix/6575486 https://www.corsix.org/content/malicious-luajit-bytecode https://www.corsix.org/content/malicious-luajit-bytecode
- girvel 2y agoThis is fascinating. I wonder if this issue exists in Lua5.2+, where there is no jit and `load` is able to restrict used environment.
- deleted 2y ago[deleted]
- myrmidon 2y agoYes, exists. Here is an example for 5.2: https://ia903205.us.archive.org/15/items/ARMArchitectureReferenceManual/EscapingTheLua5.2SandboxWithUntrustedBytecode.pdf https://ia903205.us.archive.org/15/items/ARMArchitectureRefe...