Req #41657 [Opn->Sus]: Would like to eval() in a separate code space

From: Date: Sun, 08 Apr 2018 21:08:01 +0000
Subject: Req #41657 [Opn->Sus]: Would like to eval() in a separate code space
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214657@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=41657&edit=1

 ID:                 41657
 Updated by:         cmb@php.net
 Reported by:        timothy dot j dot gustafson at gmail dot com
 Summary:            Would like to eval() in a separate code space
-Status:             Open
+Status:             Suspended
 Type:               Feature/Change Request
 Package:            Unknown/Other Function
 Operating System:   FreeBSD 6.2
 PHP Version:        5.2.3
 Block user comment: N
 Private report:     N

 New Comment:

Well, there is already Runkit_Sandbox[1].  Moving similar
functionality to the core would certainly require the RFC
process[2].  Anybody is welcome to start it.  For the time being,
I'm suspending this ticket.

[1] <http://www.php.net/manual/en/runkit.sandbox.php>
[2] <https://wiki.php.net/rfc/howto>


Previous Comments:
------------------------------------------------------------------------
[2007-06-11 19:14:57] timothy dot j dot gustafson at gmail dot com

Description:
------------
I think it would be handy if there were a version of eval() that executed the code specified in a
separate code space from the primary PHP execution.  This would be tremendously handy when
you're executing code from an untrusted source, for example if you wanted to create some sort
of plug-in system for your web app that would allow the user's code to be executed on the web
server, but in a more controlled environment than the main PHP script itself.

When the user's code gets executed, it should not have access to any variables, other than
perhaps the superglobals.  It would be really nice if you could also specify a different php.ini
file for this "virtual" execution, so you could do things like set open_basedir and
disable_functions.

Reproduce code:
---------------
None!

Expected result:
----------------
None!

Actual result:
--------------
None!


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=41657&edit=1


Thread (2 messages)

« previous php.bugs (#214657) next »