Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

Evaluating expressions contained as strings

Tags:

common-lisp

I've a database which returns vaild CL expressions within double quotes.

Is it possible to convert these strings to expressions.

For example, I make a query from this DB via CLSQL and as a result it returns me:

"(foo a b)"

How should I convert this expression to:

(foo a b)

and further evaluate it?

like image 402
oakenshield1 Avatar asked Sep 30 '11 14:09

oakenshield1


1 Answers

* (read-from-string "(+ 1 2)")

(+ 1 2)
7

There is a security problem. See the variable *read-eval*.

* (read-from-string "#.(+ 1 2)")

3
9

You really need to make sure that *read-eval* is NIL, so that reading will not evaluate code.

* (let ((*read-eval* nil)) (read-from-string "#.(+ 1 2)"))

debugger invoked on a SB-INT:SIMPLE-READER-ERROR:
  can't read #. while *READ-EVAL* is NIL

Additionally calling EVAL on arbitrary input from a database is not a good idea.

Usually you want to make sure that the code does only call allowed functions.

like image 136
Rainer Joswig Avatar answered Sep 17 '22 14:09

Rainer Joswig