Fixed a potential way to escape the Lua Plugin sandbox (#5846)
This commit is contained in:
@@ -6,6 +6,7 @@
|
|||||||
- Minor: Treat all browsers starting with `firefox` as a Firefox browser. (#5805)
|
- Minor: Treat all browsers starting with `firefox` as a Firefox browser. (#5805)
|
||||||
- Minor: Remove incognito browser support for `opera/launcher` (this should no longer be a thing). (#5805)
|
- Minor: Remove incognito browser support for `opera/launcher` (this should no longer be a thing). (#5805)
|
||||||
- Minor: Remove incognito browser support for `iexplore`, because internet explorer is EOL. (#5810)
|
- Minor: Remove incognito browser support for `iexplore`, because internet explorer is EOL. (#5810)
|
||||||
|
- Bugfix: Fixed a potential way to escape the Lua Plugin sandbox. (#5846)
|
||||||
- Bugfix: Fixed a crash relating to Lua HTTP. (#5800)
|
- Bugfix: Fixed a crash relating to Lua HTTP. (#5800)
|
||||||
- Bugfix: Fixed a crash that could occur on Linux and macOS when clicking "Install" from the update prompt. (#5818)
|
- Bugfix: Fixed a crash that could occur on Linux and macOS when clicking "Install" from the update prompt. (#5818)
|
||||||
- Bugfix: Fixed missing word wrap in update popup. (#5811)
|
- Bugfix: Fixed missing word wrap in update popup. (#5811)
|
||||||
|
|||||||
@@ -264,6 +264,11 @@ void g_print(ThisPluginState L, sol::variadic_args args)
|
|||||||
logHelper(L, L.plugin(), stream, args);
|
logHelper(L, L.plugin(), stream, args);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
void package_loadlib(sol::variadic_args args)
|
||||||
|
{
|
||||||
|
throw std::runtime_error("package.loadlib: this function is a stub!");
|
||||||
|
}
|
||||||
|
|
||||||
} // namespace chatterino::lua::api
|
} // namespace chatterino::lua::api
|
||||||
// NOLINTEND(*vararg)
|
// NOLINTEND(*vararg)
|
||||||
#endif
|
#endif
|
||||||
|
|||||||
@@ -128,6 +128,8 @@ void c2_later(ThisPluginState L, sol::protected_function callback, int time);
|
|||||||
// These ones are global
|
// These ones are global
|
||||||
sol::variadic_results g_load(ThisPluginState s, sol::object data);
|
sol::variadic_results g_load(ThisPluginState s, sol::object data);
|
||||||
void g_print(ThisPluginState L, sol::variadic_args args);
|
void g_print(ThisPluginState L, sol::variadic_args args);
|
||||||
|
|
||||||
|
void package_loadlib(sol::variadic_args args);
|
||||||
// NOLINTEND(readability-identifier-naming)
|
// NOLINTEND(readability-identifier-naming)
|
||||||
|
|
||||||
// This is for require() exposed as an element of package.searchers
|
// This is for require() exposed as an element of package.searchers
|
||||||
|
|||||||
@@ -244,6 +244,9 @@ void PluginController::initSol(sol::state_view &lua, Plugin *plugin)
|
|||||||
io.set_function("write", &lua::api::io_write);
|
io.set_function("write", &lua::api::io_write);
|
||||||
io.set_function("popen", &lua::api::io_popen);
|
io.set_function("popen", &lua::api::io_popen);
|
||||||
io.set_function("tmpfile", &lua::api::io_tmpfile);
|
io.set_function("tmpfile", &lua::api::io_tmpfile);
|
||||||
|
|
||||||
|
sol::table package = g["package"];
|
||||||
|
package.set_function("loadlib", &lua::api::package_loadlib);
|
||||||
}
|
}
|
||||||
|
|
||||||
void PluginController::load(const QFileInfo &index, const QDir &pluginDir,
|
void PluginController::load(const QFileInfo &index, const QDir &pluginDir,
|
||||||
|
|||||||
Reference in New Issue
Block a user