Commit Graph

5916 Commits

Author SHA1 Message Date
dearblue 0955539cf9 Fix use-after-free in mrb_ary_delete()
`mrb_equal()` may call `obj.==` method internally.
Therefore, using an unupdated pointer and length after `mrb_equal()` could result in a read/write to an invalid address.

Fresh properties must always be obtained regardless of the result of `mrb_equal()`.
Also, `ary_modify()` must be called each time before writing.

ref. #6339
2024-09-13 21:44:56 +09:00
Yukihiro "Matz" Matsumoto 6e44c0bc91 vm.c (argnum_error): merge declaration and initialization 2024-09-13 07:27:17 +09:00
Yukihiro "Matz" Matsumoto 704ad87150 Merge pull request #6338 from dearblue/proc-align 2024-09-12 06:43:42 +09:00
Yukihiro "Matz" Matsumoto 0972c84773 array.c (mrb_ary_delete): protect return value; fix #6339
The C local variable is not protected from GC, so we use the function
mrb_gc_protect() to keep the value. We also keep the arena position by
mrb_gc_arena_save(), then restoring the position for every new return
value, to minimize arena size.

Small cosmetic changes (pre-increment to post-increment) are also made
in this commit.
2024-09-09 14:57:32 +09:00
Yukihiro "Matz" Matsumoto 2d871fb1ef vm.c (catch_handler_find): merge declaration and initialization 2024-09-09 07:10:50 +09:00
Yukihiro "Matz" Matsumoto a3aff8f437 vm.c (mrb_yield_cont): merge declaration and initialization 2024-09-07 08:36:02 +09:00
Yukihiro "Matz" Matsumoto 1f9fa06119 array.c: no need to assert if blk is a Proc; ref #6344
Since `blk` always comes from `mrb_get_args`, it should always be either
`nil` or a Proc.
2024-09-05 15:26:09 +09:00
leviongit 020cfa9283 prefer using mrb_yield to call block arguments 2024-09-04 20:44:51 +02:00
dearblue e476d9a344 Need to restore the GC arena after some function calls
When calling `mrb_equal()` or `mrb_funcall()` family functions, the GC arena should be restored if the loop is repeated by a non-immediate return value.

In my opinion, restoring the GC arena is unnecessary when a non-immediate (true) value causes the function to return (e.g. the `mrb_ary_index_m()` function).

The patch does not take into account the case of recursive calls and may be incomplete.
2024-09-03 21:29:06 +09:00
Yukihiro "Matz" Matsumoto 96cf9ba230 vm.c (mrb_yield_with_class): merge declaration and initialization 2024-09-03 11:58:20 +09:00
Yukihiro "Matz" Matsumoto 4062069679 gc.c (gc_arena_keep): revert 2 commits regarding arena allocation; #6329
We assumed there's no need for gc_arena_keep() when MRB_GC_FIXED_ARENA
is set.  But it turned out that gc_protect() still can cause use-after-free
with fixed arena.

Revert "gc.c (gc_protect): should not call gc_arena_keep twice from allocation"

This reverts commit 28ece4ed8b.

Revert "gc.c (gc_arena_keep): reorganized for MRB_GC_FIXED_ARENA; ref #6329"

This reverts commit 33dd623a02.
2024-09-02 23:00:09 +09:00
Yukihiro "Matz" Matsumoto 6c4dbe8584 vm.c (eval_under): unify declaration and initialization of variables 2024-09-02 11:52:32 +09:00
Yukihiro "Matz" Matsumoto 472f699ee6 vm.c (mrb_f_send): unify declaration and initialization of variables 2024-09-01 22:29:46 +09:00
dearblue 42513d61fd Need to place static proc objects into 8-byte alignments
Static proc objects defined as methods may be placed in 4-byte alignments in 32-bit environments.
This may be misinterpreted as an immediate value depending on the address.

Since C11 and C++11 have additional language features for byte alignment, corresponding compilers use them to define the `mrb_alignas()` macro.
For earlier compilers, they use their own extensions to define the `mrb_alignas()` macro.

GCC supports `__attribute__((aligned(alignment)))` since at least version 2.95.3 (1999).
https://gcc.gnu.org/onlinedocs/gcc-2.95.3/gcc_4.html#IDX305
According to GPT-4, support was added in version 2.7 (1995).

It is not known which version of Visual C++ added support for `__declspec(align(n))`.
According to GPT-4, at least Visual C++ 6.0 (1998) seems to support it.
Also, the documentation of past Intel C/C++ compilers that support `__declspec(align(n))` makes reference to support with Visual C++ 4.2 (1996).
https://www.intel.com/content/dam/www/public/ijkk/jp/ja/documents/developer/ccomp40j.pdf
2024-09-01 20:28:34 +09:00
Yukihiro "Matz" Matsumoto 56c3d748fb Merge pull request #6335 from dearblue/OP_RETURN 2024-08-30 10:53:58 +09:00
Yukihiro "Matz" Matsumoto 6de3009606 Merge pull request #6328 from dearblue/env-obj_free 2024-08-28 16:40:04 +09:00
Yukihiro "Matz" Matsumoto 540d976f7f array.c (sort_cmp): mrb_cmp() may return -2 for errors 2024-08-27 22:36:24 +09:00
dearblue 7ec5d47a91 Add return_ci in CHECKPOINT_MAIN() of OP_RETURN
For role clarity, distinguish between `ci` and `return_ci`.
2024-08-27 21:39:09 +09:00
Yukihiro "Matz" Matsumoto 28ece4ed8b gc.c (gc_protect): should not call gc_arena_keep twice from allocation 2024-08-27 11:03:14 +09:00
Yukihiro "Matz" Matsumoto ef5ae1c629 Merge pull request #6333 from dearblue/heap_p 2024-08-26 05:49:49 +09:00
Yukihiro "Matz" Matsumoto 33dd623a02 gc.c (gc_arena_keep): reorganized for MRB_GC_FIXED_ARENA; ref #6329 2024-08-26 05:47:28 +09:00
Yukihiro "Matz" Matsumoto b9c93673f9 Merge pull request #6329 from dearblue/mrb_obj_alloc 2024-08-26 05:40:12 +09:00
Yukihiro "Matz" Matsumoto 325c918464 class.c: use mrb_unboxed_type where obj is not immediate for sure 2024-08-26 05:33:19 +09:00
dearblue 98fdfe1037 Reduce the number of branch instructions in the heap_p()
As far as `gcc -S` for several CPU architectures has confirmed, it reduces the number of branch instructions by one.
2024-08-25 20:35:41 +09:00
dearblue 1c5839fb01 Fix use-after-free in mrb_obj_alloc()
When GC occurs during the expansion of the GC arena by `gc_protect()` in `mrb_obj_alloc()`, the object page just allocated by `add_heap()` is released.
Therefore, as soon as control returns from `gc_protect()`, there is a possibility of illegal writing or reading to the address just released.

This issue was discovered during the investigation of #6326.
2024-08-25 10:55:15 +09:00
dearblue 13571402d2 Add a precondition to call mrb_env_unshare().
The following assertions can be added to omit the `if` block

  - env object must be non-null
  - env object must be in a shared state with the stack

The current caller is believed to satisfy the condition.
2024-08-24 17:30:54 +09:00
dearblue 22b1ac9070 Fix use-after-free in obj_free() for env objects
A reference to an invalid address might occur in `is_dead()` of `obj_free()` called from `incremental_sweep_phase()`.
This would happen if the heap page was freed ahead of time in the same `incremental_sweep_phase()`.

fixed #6326
2024-08-24 16:46:27 +09:00
Yukihiro "Matz" Matsumoto f35000f2a9 array.c (sort_cmp): comparing objects may be freed by GC; #6326
If comparing function (block or `<=>`) modifies the sorting array and GC
happens after the modification, objects passed to comparison may be
freed by GC.
2024-08-23 22:29:45 +09:00
Yukihiro "Matz" Matsumoto 58c70834d9 array.c (srot_cmp): need modify check after mrb_cmp as well; #6326
mrb_cmp() may also modify the sorting array internally.
2024-08-22 07:49:16 +09:00
Yukihiro "Matz" Matsumoto 752ebe6b7f array.c (mrb_ary_sort_bang): check if array is modified in blocks
This address at least part of #6326. CRuby copied the array internally,
but mruby avoid copying to reserve memory.
2024-08-21 18:31:46 +09:00
Yukihiro "Matz" Matsumoto 4b9f567821 vm.c (exec_irep): unify declaration and initialization 2024-08-20 12:49:45 +09:00
Yukihiro "Matz" Matsumoto 98440e095f vm.c (mrb_ci_nregs): unify declaration and initialization 2024-08-20 10:39:12 +09:00
Yukihiro "Matz" Matsumoto 44908e5cba mruby-rational: support bigint numerators & denominators 2024-08-16 15:12:03 +09:00
Yukihiro "Matz" Matsumoto 479259b4e1 Merge pull request #6324 from dearblue/localjump_error 2024-08-16 06:22:32 +09:00
dearblue 9d0617f27b Remove localjump_error()
Suppress heap allocation for strings.
2024-08-15 10:27:53 +09:00
Yukihiro "Matz" Matsumoto dfe2dbcde6 class.c (init_copy): need to copy float numbers in some cases
If `MRB_BOXING_WORD` and `MRB_WORDBOXING_NO_FLOAT_TRANCATE` is defined,
float numbers are packed in the heap object. We need to copy them
explicitly.
2024-08-15 09:57:56 +09:00
Yukihiro "Matz" Matsumoto 16f5000794 Merge pull request #6320 from dearblue/OP_BREAK 2024-08-14 18:02:34 +09:00
Yukihiro "Matz" Matsumoto c853dc4090 vm.c (funcall): move va_list declaration right before va_start() 2024-08-12 22:57:05 +09:00
dearblue 682583a609 Shrinking the code in OP_BREAK and OP_RETURN_BLK
- Can refer directly to `proc->e.env` after `MRB_PROC_ENV_P()`.
  - Can omit `MRB_ENV_ONSTACK_P()` since `mrb->c` is never NULL and can be directly compared to `env->cxt`.
  - Can avoid `goto` by putting the code block that raises the `LocalJumpError` at the end.
2024-08-12 20:54:55 +09:00
Yukihiro "Matz" Matsumoto 22eb7e87af vm.c (uvenv): move declaration to initialization 2024-08-11 23:45:40 +09:00
Yukihiro "Matz" Matsumoto 7ca60a0964 vm.c (stack_extend_alloc): move variable declaration to initialization 2024-08-10 21:57:51 +09:00
Yukihiro "Matz" Matsumoto a267dfd76b vm.c (OP_CLASS,OP_MODULE): combine declarations with initializers 2024-08-08 06:11:52 +09:00
Yukihiro "Matz" Matsumoto 22ec76f46c vm.c (OP_RANGE_INC): remove unnecessary local variable 2024-08-08 06:10:35 +09:00
Yukihiro "Matz" Matsumoto 320c757186 Merge pull request #6318 from dearblue/shrink-vm-vars
Shrink variables in `mrb_vm_exec()`
2024-08-06 12:21:36 +09:00
Yukihiro "Matz" Matsumoto aad2aacf25 range.c (mrb_get_values_at): support bigint too 2024-08-05 16:35:41 +09:00
Yukihiro "Matz" Matsumoto e8bb03da40 numeric.rb (step): iterate over integers even if end is a float
It used to check all `start`, `end` and `step`. If either of them are
float number, `#step` iterated over float number. Now we don't check the
type of `end` argument.
2024-08-03 13:35:09 +09:00
Yukihiro "Matz" Matsumoto 6d6e26661d gc.c: remove unnecessary argument from add_gray_list() 2024-08-02 21:14:58 +09:00
Yukihiro "Matz" Matsumoto 3324773f56 gc.c (mrb_gc_register): protect obj from GC during execution
Because `mrb_ary_new()` and `mrb_ary_push()` can cause GC; fix #6317
2024-08-02 04:52:11 +09:00
dearblue 822e3fdfd7 Remove pool and syms variables in mrb_vm_exec()
Can be referenced by traversing through the `irep` pointer.
2024-07-31 22:27:04 +09:00
dearblue f2a139a616 Avoid assignments to pc and proc parameters in mrb_vm_exec()
Introduce the `ci` variable instead and refer to it indirectly.
2024-07-31 22:27:04 +09:00