object.h: fix MRB_OBJ_SHAPED_P false positive on 32-bit Hash

MRB_FL_OBJ_SHAPED uses bit 5 of flags, which on 32-bit conflicts
with Hash's ea_n_used field (bits 5-9). A Hash with entries would
falsely match MRB_OBJ_SHAPED_P, causing SEGV when its iv pointer
was misinterpreted as mrb_shaped_iv. Add tt == MRB_TT_OBJECT check
to the predicate.

Co-authored-by: Claude <noreply@anthropic.com>
This commit is contained in:
Yukihiro "Matz" Matsumoto
2026-02-27 11:06:04 +09:00
parent 59e1fe29d6
commit 07a4b755fb
+4 -2
View File
@@ -25,9 +25,11 @@ struct RBasic {
#define mrb_frozen_p(o) ((o)->frozen)
/* Object shape flag -- when set, obj->iv is shaped, not iv_tbl* */
/* Bit 5: avoids conflict with MRB_INSTANCE_TT_MASK (bits 0-4) */
/* Bit 5: avoids conflict with MRB_INSTANCE_TT_MASK (bits 0-4);
but conflicts with MRB_HASH_AR_EA_N_USED on 32-bit, so the
predicate must also check tt to avoid false positives */
#define MRB_FL_OBJ_SHAPED (1 << 5)
#define MRB_OBJ_SHAPED_P(o) ((o)->flags & MRB_FL_OBJ_SHAPED)
#define MRB_OBJ_SHAPED_P(o) ((o)->tt == MRB_TT_OBJECT && ((o)->flags & MRB_FL_OBJ_SHAPED))
struct RObject {
MRB_OBJECT_HEADER;