Python: add opcodes for boolean/None expressions in secure driver eval

Support for additional opcodes in driver bytecode security check:

- COPY
- TO_BOOL
- POP_JUMP_IF_TRUE
- POP_JUMP_IF_NONE
- POP_JUMP_IF_NOT_NONE
- LOAD_FAST_AND_CLEAR
- LOAD_FAST_LOAD_FAST
- STORE_FAST_LOAD_FAST
- STORE_FAST_STORE_FAST
- LOAD_FAST_BORROW
- LOAD_FAST_BORROW_LOAD_FAST_BORROW

These are all stack manipulation, conditional jumps, or local variable
access opcodes - categories already considered safe in the security
model.

Includes tests for the new opcodes.

Ref !153476
This commit is contained in:
Campbell Barton 2026-01-27 21:26:56 +00:00
parent 887c178f97
commit 0d6d7480b9
2 changed files with 42 additions and 1 deletions

View file

@ -157,6 +157,33 @@ class TestAcceptMathFunctionsComplex(unittest.TestCase, TestExprMixIn_Accept):
expressions = ("-(sin(pi) ** 2) / 2", "floor(22 / 7)", "ceil(pi + 1)")
class TestAcceptBooleanShortCircuit(unittest.TestCase, TestExprMixIn_Accept):
# Enables fallback values and conditional logic in drivers, e.g. `value and value * 2`.
expressions = (
"pi and e",
"pi and e and tau",
"pi or e",
"pi or e or tau",
"pi and e or tau",
"pi or e and tau",
# Combined with `not` operator.
"not pi or e",
# Combined with comparison.
"pi > 0 and e",
"pi if pi > e else e",
)
class TestAcceptNoneCheck(unittest.TestCase, TestExprMixIn_Accept):
# Enables `None` safe expressions in drivers, e.g. `value if value is not None else 0`.
expressions = (
"pi if pi is not None else e",
"e if pi is None else pi",
"pi if pi is not None else (e if e is not None else tau)",
"(pi if pi is not None else 0) and e", # Combined with boolean short-circuit.
)
# -----------------------------------------------------------------------------
# Tests (Reject)