<?php
include_once $_SERVER['DOCUMENT_ROOT'] . '/include/shared-manual.inc';
$TOC = array();
$TOC_DEPRECATED = array();
$PARENTS = array();
include_once dirname(__FILE__) ."/toc/book.luasandbox.inc";
$setup = array (
  'home' => 
  array (
    0 => 'index.php',
    1 => 'PHP Manual',
  ),
  'head' => 
  array (
    0 => 'UTF-8',
    1 => 'uk',
  ),
  'this' => 
  array (
    0 => 'reference.luasandbox.differences.php',
    1 => 'Differences from Standard Lua',
    2 => 'Differences from Standard Lua',
  ),
  'up' => 
  array (
    0 => 'book.luasandbox.php',
    1 => 'LuaSandbox',
  ),
  'prev' => 
  array (
    0 => 'luasandbox.installation.php',
    1 => 'Встановлення',
  ),
  'next' => 
  array (
    0 => 'luasandbox.examples.php',
    1 => 'Приклади',
  ),
  'alternatives' => 
  array (
  ),
  'source' => 
  array (
    'lang' => 'en',
    'path' => 'reference/luasandbox/differences.xml',
  ),
  'history' => 
  array (
  ),
);
$setup["toc"] = $TOC;
$setup["toc_deprecated"] = $TOC_DEPRECATED;
$setup["parents"] = $PARENTS;
manual_setup($setup);

contributors($setup);

?>
<div id="reference.luasandbox.differences" class="chapter">
 <h1 class="title">Differences from Standard Lua</h1>


 <p class="para">
  LuaSandbox provides a sandboxed environment which differs in some ways from standard Lua 5.1.
 </p>

 <div class="simplesect" id="reference.luasandbox.differences.unavailable">
  <h3 class="title">Features that are not available</h3>
  <p class="para">
   <ul class="itemizedlist">
    <li class="listitem">
     <p class="para">
      <code class="literal">dofile()</code>, <code class="literal">loadfile()</code>, and the <code class="literal">io</code> package, as they allow direct filesystem access. If needed, filesystem access should be done via PHP callbacks.
     </p>
    </li>
    <li class="listitem">
     <p class="para">
      The <code class="literal">package</code> package, including <code class="literal">require()</code> and <code class="literal">module()</code>, as it depends heavily on direct filesystem access. A pure-Lua rewrite such as that used in the MediaWiki Scribunto extension may be used instead.
     </p>
    </li>
    <li class="listitem">
     <p class="para">
      <code class="literal">load()</code> and <code class="literal">loadstring()</code>, to allow for static analysis of Lua code.
     </p>
    </li>
    <li class="listitem">
     <p class="para">
      <code class="literal">print()</code>, since it outputs to standard output. If needed, output should be done via PHP callbacks.
     </p>
    </li>
    <li class="listitem">
     <p class="para">
      Most of the <code class="literal">os</code> package, as it allows manipulation of the process and executing of other processes.
     </p>
     <p class="para">
      <ul class="itemizedlist">
       <li class="listitem">
        <p class="para">
         <code class="literal">os.clock()</code>, <code class="literal">os.date()</code>, <code class="literal">os.difftime()</code>, and <code class="literal">os.time()</code> remain available.
        </p>
       </li>
      </ul>
     </p>
    </li>
    <li class="listitem">
     <p class="para">
      Most of the <code class="literal">debug</code> package, as it allows manipulation of Lua state and metadata in ways that can break sandboxing.
     </p>
     <p class="para">
      <ul class="itemizedlist">
       <li class="listitem">
        <p class="para">
         <code class="literal">debug.traceback()</code> remains available.
         </p>
       </li>
      </ul>
     </p>
    </li>
    <li class="listitem">
     <p class="para">
      <code class="literal">string.dump()</code>, as it may expose internal data.
     </p>
    </li>
    <li class="listitem">
     <p class="para">
      <code class="literal">collectgarbage()</code>, <code class="literal">gcinfo()</code>, and the <code class="literal">coroutine</code> package have not been reviewed for security.
     </p>
    </li>
   </ul>
  </p>
 </div>

 <div class="simplesect" id="reference.luasandbox.differences.modified">
  <h3 class="title">Features that have been modified</h3>
  <p class="para">
   <ul class="itemizedlist">
    <li class="listitem">
     <p class="para">
      <code class="literal">pcall()</code> and <code class="literal">xpcall()</code> cannot catch certain errors, particularly timeout errors.
     </p>
    </li>
    <li class="listitem">
     <p class="para">
      <code class="literal">tostring()</code> does not include pointer addresses.
     </p>
    </li>
    <li class="listitem">
     <p class="para">
      <code class="literal">string.match()</code> has been patched to limit the recursion depth and to periodically check for a timeout.
     </p>
    </li>
    <li class="listitem">
     <p class="para">
      <code class="literal">math.random()</code> and <code class="literal">math.randomseed()</code> are replaced with versions that don&#039;t share state with PHP&#039;s <code class="literal">rand()</code>.
     </p>
    </li>
    <li class="listitem">
     <p class="para">
      The Lua 5.2 <code class="literal">__pairs</code> and <code class="literal">__ipairs</code> metamethods are supported by <code class="literal">pairs()</code> and <code class="literal">ipairs()</code>.
     </p>
    </li>
   </ul>
  </p>
 </div>

</div>
<?php manual_footer($setup); ?>