View source with raw comments or as raw
    1/*  Part of SWI-Prolog
    2
    3    Author:        Jan Wielemaker
    4    E-mail:        J.Wielemaker@vu.nl
    5    WWW:           http://www.swi-prolog.org
    6    Copyright (c)  2014-2015, VU University Amsterdam
    7    All rights reserved.
    8
    9    Redistribution and use in source and binary forms, with or without
   10    modification, are permitted provided that the following conditions
   11    are met:
   12
   13    1. Redistributions of source code must retain the above copyright
   14       notice, this list of conditions and the following disclaimer.
   15
   16    2. Redistributions in binary form must reproduce the above copyright
   17       notice, this list of conditions and the following disclaimer in
   18       the documentation and/or other materials provided with the
   19       distribution.
   20
   21    THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
   22    "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
   23    LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
   24    FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
   25    COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
   26    INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
   27    BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
   28    LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER
   29    CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
   30    LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN
   31    ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
   32    POSSIBILITY OF SUCH DAMAGE.
   33*/
   34
   35:- module(modules,
   36          [ in_temporary_module/3               % ?Module, :Setup, :Goal
   37          ]).

Module utility predicates

*/

   43:- meta_predicate
   44    in_temporary_module(?, 0, 0).
 in_temporary_module(?Module, :Setup, :Goal)
Run Goal on temporary loaded sources and discard the module and loaded predicates after completion. This predicate performs the following steps:
  1. If Module is unbound, create a unique identifier for it.
  2. Turn Module into a temporary module using set_module/1. Note that this requires the module to be non-existent or empty. If Module is specified, it should typically be set to a unique value as obtained from e.g. uuid/1.
  3. Run Setup in the context of Module.
  4. If setup succeeded possible choice points are discarded and Goal is started.

The logical result of this predicate is the same as `(Setup@Module -> Goal@Module)`, i.e., both Setup and Goal are resolved relative to the current module, but executed in the context of Module. If Goal must be called in Module, use call(Goal).

The module and all its predicates are destroyed after Goal terminates, as defined by setup_call_cleanup/3.

Discussion This predicate is intended to load programs in an isolated environment and reclaim all resources. This unfortunately is incomplete:

See also
- library(sandbox) determines whether unknown goals are safe to call.
- load_files/2 offers the option sandboxed(true) to load code from unknown sources safely.
   86in_temporary_module(Module, Setup, Goal) :-
   87    setup_call_cleanup(
   88        prepare_temporary_module(Module),
   89        (   @(Setup, Module)
   90        ->  @(Goal,  Module)
   91        ),
   92        '$destroy_module'(Module)).
   93
   94prepare_temporary_module(Module) :-
   95    var(Module),
   96    !,
   97    (   repeat,
   98        I is random(1<<63),
   99        atom_concat('tmp-', I, Module),
  100        catch(set_module(Module:class(temporary)),
  101              error(permission_error(_,_,_),_), fail)
  102    ->  true
  103    ).
  104prepare_temporary_module(Module) :-
  105    set_module(Module:class(temporary))