mirror of
https://github.com/mruby/mruby
synced 2026-06-08 16:11:16 +00:00
Squashed commit of the following:
commit 2d7d545c4c4bfce7fdcbcbe9baaeb437915742f0 Merge: 625a1249b178914bAuthor: Yukihiro "Matz" Matsumoto <matz@ruby.or.jp> Date: Fri Jun 5 14:35:13 2020 +0900 Merge branch 'fix-mrb_open-with-nomem' of https://github.com/dearblue/mruby into dearblue-fix-mrb_open-with-nomem commitb178914b11Author: dearblue <dearblue@users.noreply.github.com> Date: Sat Jan 19 22:22:44 2019 +0900 Fix invalid pointer free inside other heap's block 1. `e = mrb_obj_alloc(...)` 2. `e->stack = mrb->c->stack` (`mrb->c->stack` is anywhere in the range `stbase...stend`) 3. And raised exception by `mrb_malloc()`! 4. `mrb_free(e->stack)` by GC part (wrong free) commit52e3d5d858Author: dearblue <dearblue@users.noreply.github.com> Date: Sat Jan 19 21:55:36 2019 +0900 Fix memory leak for temporary symbols when out of memory commit4c5499b88eAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 11:42:07 2019 +0900 Fix uninitialized pointer dereference for debug section commit8e993167deAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 11:41:09 2019 +0900 Fix memory leak for temporary filenames when out of memory commit8b422577e6Author: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 10:57:51 2019 +0900 Fix memory leak for irep when out of memory commit6b35ebf49aAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 10:55:50 2019 +0900 Fix uninitialized pointer dereference when do not finished initializing irep commit2531f2631eAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 10:48:15 2019 +0900 Fix NULL pointer dereference when do not finished initializing irep commite2d6896ebaAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sat Jan 19 12:54:19 2019 +0900 Fix memory leak for irep when out of memory by `mrb_proc_new()` commitb6214ff8a0Author: dearblue <dearblue@users.noreply.github.com> Date: Sat Jan 19 12:53:07 2019 +0900 Fix memory leak for `khash_t` in `kh_init_size()` when out of memory by `kh_alloc()` commit19162dd6c1Author: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 02:15:07 2019 +0900 Fix memory leak for symbol string when out of memory in `kh_put()` commit15e67297ffAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 02:12:24 2019 +0900 Fix keep wrong symbol index when out of memory commit3f8e2b3752Author: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 02:08:13 2019 +0900 Fix keep wrong symbol capacity when out of memory commita3cfe755abAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sat Jan 19 10:11:37 2019 +0900 Fix NULL pointer dereference `mrb->c` by `mark_context()` commitd9c7b6be6eAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 15:25:09 2019 +0900 Fix protect exception for print error message commit100642750eAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 11:59:02 2019 +0900 Protect exception for mruby core initialization commit7a0418304eAuthor: dearblue <dearblue@users.noreply.github.com> Date: Fri Jan 18 20:38:27 2019 +0900 Fix memory leak for string object when out of memory The `mrb_str_pool()` function has a path to call `malloc()` twice. If occurs `NoMemoryError` exception in second `malloc()`, first `malloc()` pointer is not freed. commitfef1c152ceAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sat Jan 19 13:05:09 2019 +0900 Fix stack overflow when out of memory As a result of this change, no backtrace information is set for NoMemoryError (`mrb->nomem_err`). Detailes: When generating a backtrace, called `mrb_intern_lit()`, `mrb_str_new_cstr()` and `mrb_obj_iv_set()` function with `exc_debug_info()` function in `src/error.c`. If a `NoMemoryError` exception occurs at this time, the `exc_debug_info()` function will be called again, and in the same way `NoMemoryError` exception raised will result in an infinite loop to occurs stack overflow (and SIGSEGV). commitda7d7f881bAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 12:00:38 2019 +0900 Fix NULL pointer dereference `mrb->nomem_err` when not initialized Add internal functions (not `static`): * `mrb_raise_nomemory()` * `mrb_core_init_abort()`
This commit is contained in:
+57
-5
@@ -185,6 +185,16 @@ mrb_exc_set(mrb_state *mrb, mrb_value exc)
|
||||
}
|
||||
}
|
||||
|
||||
static mrb_noreturn void
|
||||
exc_throw(mrb_state *mrb, mrb_value exc)
|
||||
{
|
||||
if (!mrb->jmp) {
|
||||
mrb_p(mrb, exc);
|
||||
abort();
|
||||
}
|
||||
MRB_THROW(mrb->jmp);
|
||||
}
|
||||
|
||||
MRB_API mrb_noreturn void
|
||||
mrb_exc_raise(mrb_state *mrb, mrb_value exc)
|
||||
{
|
||||
@@ -197,11 +207,7 @@ mrb_exc_raise(mrb_state *mrb, mrb_value exc)
|
||||
}
|
||||
mrb_exc_set(mrb, exc);
|
||||
}
|
||||
if (!mrb->jmp) {
|
||||
mrb_p(mrb, exc);
|
||||
abort();
|
||||
}
|
||||
MRB_THROW(mrb->jmp);
|
||||
exc_throw(mrb, exc);
|
||||
}
|
||||
|
||||
MRB_API mrb_noreturn void
|
||||
@@ -550,6 +556,52 @@ mrb_argnum_error(mrb_state *mrb, mrb_int argc, int min, int max)
|
||||
#undef FMT
|
||||
}
|
||||
|
||||
void mrb_core_init_printabort(void);
|
||||
|
||||
int
|
||||
mrb_core_init_protect(mrb_state *mrb, void (*body)(mrb_state *, void *), void *opaque)
|
||||
{
|
||||
struct mrb_jmpbuf *prev_jmp = mrb->jmp;
|
||||
struct mrb_jmpbuf c_jmp;
|
||||
int err = 1;
|
||||
|
||||
MRB_TRY(&c_jmp) {
|
||||
mrb->jmp = &c_jmp;
|
||||
body(mrb, opaque);
|
||||
err = 0;
|
||||
} MRB_CATCH(&c_jmp) {
|
||||
if (mrb->exc) {
|
||||
mrb_p(mrb, mrb_obj_value(mrb->exc));
|
||||
mrb->exc = NULL;
|
||||
}
|
||||
else {
|
||||
mrb_core_init_printabort();
|
||||
}
|
||||
} MRB_END_EXC(&c_jmp);
|
||||
|
||||
mrb->jmp = prev_jmp;
|
||||
|
||||
return err;
|
||||
}
|
||||
|
||||
mrb_noreturn void
|
||||
mrb_core_init_abort(mrb_state *mrb)
|
||||
{
|
||||
mrb->exc = NULL;
|
||||
exc_throw(mrb, mrb_nil_value());
|
||||
}
|
||||
|
||||
mrb_noreturn void
|
||||
mrb_raise_nomemory(mrb_state *mrb)
|
||||
{
|
||||
if (mrb->nomem_err) {
|
||||
mrb_exc_raise(mrb, mrb_obj_value(mrb->nomem_err));
|
||||
}
|
||||
else {
|
||||
mrb_core_init_abort(mrb);
|
||||
}
|
||||
}
|
||||
|
||||
void
|
||||
mrb_init_exception(mrb_state *mrb)
|
||||
{
|
||||
|
||||
Reference in New Issue
Block a user