TIP 120: Restricted DDE Services

Author:         Pat Thoyts <[email protected]>
State:          Final
Type:           Project
Vote:           Done
Created:        04-Dec-2002
Tcl-Version:    8.5
Tcl-Ticket:     649859


This TIP will enhance the DDE package for use with safe interpreters and allow programmer control of the commands exposed by the DDE service.


By default the Tcl DDE service exposes all of the commands and variables available in the interpreter to all DDE clients. This is not always desirable. One solution might be to load the package into a safe slave interpreter and use [interp alias] to expose the required commands. Unfortunately the package doesn't support loading into safe interpreters.

Proposed Changes

Firstly, this TIP proposes a -handler option to the [dde servername] sub-command. The argument for this option should be the name of a procedure that will authenticate and evaluate DDE requests.

Secondly, the DDE package should be enhanced to be capable of providing a service within a safe interpreter.

New Option

The new syntax will be dde servername ?-handler command? servername. To permit introspection we will accept dde servername -handler which will return the handler name (if any). If a servername must be defined using an initial hyphen then the standard '--' separator can be used.

The dde request is appended to the handler command (which may be a list) and then evaluated in the global context. This ensures that all unsafe elements will not be evaluated before the handler code has a chance to examine them. So

 proc handler {request} {
    if {[string match "info *" $request} {
       uplevel #0 [lindex $request 0] [lrange $request 1 end]
    } else
       return -code error "permission denied"

The above handler will permit [info vars] but will fail when trying [info vars ; bad_proc] with info complaining about the wrong number of parameters. Passing a single string means that we can handle standard dde styles of requests, for instance 'Open("c:\Program Files\prog.exe")' which would not usefully convert into a list.

Safe DDE

The dde package should support loading within a safe interpreter but with the following constraints.

Reference Implementation

See the SourceForge Feature Request at https://sourceforge.net/tracker/index.php?func=detail&aid=649859&group\_id=10894&atid=310894


 # Provide a handler that only allows the [info] command
 # Note: This runs in the master interp.
 proc restricted_handler {request} {
    if {[string match "info *" $request} {
       uplevel #0 [lindex $request 0] [lrange $request 1 end]
    } else
       return -code error "permission denied"

 # Create a safe slave interpreter and expose as a DDE service.
 safe::interpCreate slave
 slave invokehidden load tcldde12d.dll Dde
 slave invokehidden dde servername -handler dde_cmd SafeSlave
 interp alias slave dde_cmd {} restricted_handler

 # If testing in tclsh...
 set ::_waiting 0 ; after 20000 {set ::_waiting 1} ; vwait ::_waiting


There should be no change to current users of this package unless they are using a server name beginning with a hyphen. In this case they will need to insert '--' before the server name.


This document is hereby placed in the public domain.