Fix: Make script_pyapi_bpy_driver_secure_eval pass with python >3.11

This commits add three new opcodes to the secure opcode list.
These are:
RETURN_CONST
POP_JUMP_IF_FALSE
CALL_INTRINSIC_1

I removed the "f''" test as that now only uses the RESUME and
RETURN_CONST opcodes.

Pull Request: https://projects.blender.org/blender/blender/pulls/150650
This commit is contained in:
Sebastian Parborg 2025-11-27 15:01:08 +01:00 • committed by Sebastian Parborg
parent 6ebe4a10ec
commit 2c35db495c
2 changed files with 7 additions and 2 deletions

View file

@ -307,7 +307,7 @@ static void pydriver_error(ChannelDriver *driver, const PathResolvedRNA *anim_rn
static bool is_opcode_secure(const int opcode)
{
/* TODO(@ideasman42): Handle intrinsic opcodes (`CALL_INTRINSIC_1` & `CALL_INTRINSIC_2`).
/* TODO(@ideasman42): Handle intrinsic opcodes (`CALL_INTRINSIC_2`).
* For Python 3.12. */
# define OK_OP(op) \
@ -377,6 +377,11 @@ static bool is_opcode_secure(const int opcode)
OK_OP(POP_JUMP_BACKWARD_IF_TRUE)
# endif
# if PY_VERSION_HEX >= 0x030c0000
OK_OP(RETURN_CONST)
OK_OP(POP_JUMP_IF_FALSE)
OK_OP(CALL_INTRINSIC_1)
# endif
/* Special cases. */
OK_OP(LOAD_CONST) /* Ok because constants are accepted. */
OK_OP(LOAD_NAME) /* Ok, because `PyCodeObject.names` is checked. */

View file

@ -164,7 +164,7 @@ class TestRejectLiteralFStrings(unittest.TestCase, TestExprMixIn_Reject):
# F-String's are not supported as `BUILD_STRING` op-code is disabled,
# while it may be safe to enable that needs to be double-checked.
# Further it doesn't seem useful for typical math expressions used in drivers.
expressions = ("f''", "f'{1}'", "f'{\"_\"}'")
expressions = ("f'{1}'", "f'{\"_\"}'")
class TestRejectModuleAccess(unittest.TestCase, TestExprMixIn_Reject):