Fixed rindex calling into mrb_equal bug

Fixed by Alex Snaps and reported by Mathieu Leduc-Hamel,
both from shopify.com.  Thank you!
This commit is contained in:
Yukihiro "Matz" Matsumoto
2016-11-16 02:10:44 +09:00
parent 242b219471
commit 1f554ff854
2 changed files with 16 additions and 1 deletions
+4 -1
View File
@@ -868,13 +868,16 @@ static mrb_value
mrb_ary_rindex_m(mrb_state *mrb, mrb_value self)
{
mrb_value obj;
mrb_int i;
mrb_int i, len;
mrb_get_args(mrb, "o", &obj);
for (i = RARRAY_LEN(self) - 1; i >= 0; i--) {
if (mrb_equal(mrb, RARRAY_PTR(self)[i], obj)) {
return mrb_fixnum_value(i);
}
if (i > (len = RARRAY_LEN(self))) {
i = len;
}
}
return mrb_nil_value();
}
+12
View File
@@ -347,3 +347,15 @@ assert("Array (Longish inline array)") do
ary.each {|p| h[p.class] += 1}
assert_equal({Array=>200}, h)
end
assert("Array#rindex") do
class Sneaky
def ==(*)
$a.clear
$a.replace([1])
false
end
end
$a = [2, 3, 4, 5, 6, 7, 8, 9, 10, Sneaky.new]
assert_equal 0, $a.rindex(1)
end