By default prevent cross slot operations in functions and scripts with # (#10615)
Adds the `allow-cross-slot-keys` flag to Eval scripts and Functions to allow scripts to access keys from multiple slots. The default behavior is now that they are not allowed to do that (unlike before). This is a breaking change for 7.0 release candidates (to be part of 7.0.0), but not for previous redis releases since EVAL without shebang isn't doing this check. Note that the check is done on both the keys declared by the EVAL / FCALL command arguments, and also the ones used by the script when making a `redis.call`. A note about the implementation, there seems to have been some confusion about allowing access to non local keys. I thought I missed something in our wider conversation, but Redis scripts do block access to non-local keys. So the issue was just about cross slots being accessed.
This commit is contained in:
@@ -64,6 +64,7 @@
|
||||
#define SCRIPT_READ_ONLY (1ULL<<5) /* indicate that the current script should only perform read commands */
|
||||
#define SCRIPT_ALLOW_OOM (1ULL<<6) /* indicate to allow any command even if OOM reached */
|
||||
#define SCRIPT_EVAL_MODE (1ULL<<7) /* Indicate that the current script called from legacy Lua */
|
||||
#define SCRIPT_ALLOW_CROSS_SLOT (1ULL<<8) /* Indicate that the current script may access keys from multiple slots */
|
||||
typedef struct scriptRunCtx scriptRunCtx;
|
||||
|
||||
struct scriptRunCtx {
|
||||
@@ -82,6 +83,7 @@ struct scriptRunCtx {
|
||||
#define SCRIPT_FLAG_ALLOW_STALE (1ULL<<2)
|
||||
#define SCRIPT_FLAG_NO_CLUSTER (1ULL<<3)
|
||||
#define SCRIPT_FLAG_EVAL_COMPAT_MODE (1ULL<<4) /* EVAL Script backwards compatible behavior, no shebang provided */
|
||||
#define SCRIPT_FLAG_ALLOW_CROSS_SLOT (1ULL<<5)
|
||||
|
||||
/* Defines a script flags */
|
||||
typedef struct scriptFlag {
|
||||
|
||||
Reference in New Issue
Block a user