src/Pure/General/secure.ML
author wenzelm
Thu, 16 Nov 2006 01:07:25 +0100
changeset 21395 f34ac19659ae
parent 20992 05c3703cc6c5
child 21770 ea6f846d8c4b
permissions -rw-r--r--
moved some fundamental concepts to General/basics.ML;
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
20925
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
     1
(*  Title:      Pure/General/secure.ML
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
     2
    ID:         $Id$
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
     3
    Author:     Makarius
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
     4
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
     5
Secure critical operations.
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
     6
*)
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
     7
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
     8
signature SECURE =
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
     9
sig
20977
dbf1eca9b34e tuned signature;
wenzelm
parents: 20925
diff changeset
    10
  val set_secure: unit -> unit
20925
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    11
  val is_secure: unit -> bool
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    12
  val deny_secure: string -> unit
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    13
  val use: string -> unit
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    14
  val use_text: (string -> unit) * (string -> 'a) -> bool -> string -> unit
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    15
  val commit: unit -> unit
20992
05c3703cc6c5 added execute/system;
wenzelm
parents: 20977
diff changeset
    16
  val execute: string -> string
05c3703cc6c5 added execute/system;
wenzelm
parents: 20977
diff changeset
    17
  val system: string -> int
20925
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    18
end;
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    19
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    20
structure Secure: SECURE =
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    21
struct
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    22
20992
05c3703cc6c5 added execute/system;
wenzelm
parents: 20977
diff changeset
    23
(** secure flag **)
20925
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    24
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    25
val secure = ref false;
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    26
20977
dbf1eca9b34e tuned signature;
wenzelm
parents: 20925
diff changeset
    27
fun set_secure () = secure := true;
20925
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    28
fun is_secure () = ! secure;
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    29
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    30
fun deny_secure msg = deny (is_secure ()) msg;
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    31
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    32
20992
05c3703cc6c5 added execute/system;
wenzelm
parents: 20977
diff changeset
    33
(** critical operations **)
05c3703cc6c5 added execute/system;
wenzelm
parents: 20977
diff changeset
    34
05c3703cc6c5 added execute/system;
wenzelm
parents: 20977
diff changeset
    35
(* ML evaluation *)
20925
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    36
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    37
fun secure_mltext () = deny_secure "Cannot evaluate ML source in secure mode";
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    38
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    39
val orig_use = use;
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    40
val orig_use_text = use_text;
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    41
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    42
fun use file = (secure_mltext (); orig_use file);
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    43
fun use_text pr verbose txt = (secure_mltext (); orig_use_text pr verbose txt);
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    44
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    45
(*commit is dynamically bound!*)
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    46
fun commit () = orig_use_text Output.ml_output false "commit();";
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    47
20992
05c3703cc6c5 added execute/system;
wenzelm
parents: 20977
diff changeset
    48
05c3703cc6c5 added execute/system;
wenzelm
parents: 20977
diff changeset
    49
(* shell commands *)
05c3703cc6c5 added execute/system;
wenzelm
parents: 20977
diff changeset
    50
05c3703cc6c5 added execute/system;
wenzelm
parents: 20977
diff changeset
    51
fun secure_shell () = deny_secure "Cannot execute shell commands in secure mode";
05c3703cc6c5 added execute/system;
wenzelm
parents: 20977
diff changeset
    52
05c3703cc6c5 added execute/system;
wenzelm
parents: 20977
diff changeset
    53
val orig_execute = execute;
05c3703cc6c5 added execute/system;
wenzelm
parents: 20977
diff changeset
    54
val orig_system = system;
05c3703cc6c5 added execute/system;
wenzelm
parents: 20977
diff changeset
    55
05c3703cc6c5 added execute/system;
wenzelm
parents: 20977
diff changeset
    56
fun execute s = (secure_shell (); orig_execute s);
05c3703cc6c5 added execute/system;
wenzelm
parents: 20977
diff changeset
    57
fun system s = (secure_shell (); orig_system s);
05c3703cc6c5 added execute/system;
wenzelm
parents: 20977
diff changeset
    58
20925
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    59
end;
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    60
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    61
val use = Secure.use;
2d19e511fe2c Secure critical operations.
wenzelm
parents:
diff changeset
    62
val use_text = Secure.use_text;
20992
05c3703cc6c5 added execute/system;
wenzelm
parents: 20977
diff changeset
    63
val execute = Secure.execute;
05c3703cc6c5 added execute/system;
wenzelm
parents: 20977
diff changeset
    64
val system = Secure.system;