Yukihiro "Matz" Matsumoto
f13db72d26
load.c: add data boundary check for broken compiled binary.
2022-05-10 20:11:17 +09:00
Yukihiro "Matz" Matsumoto
b82065aa92
load.c: should check if length of irep sections are valid.
2022-05-10 20:11:17 +09:00
Yukihiro "Matz" Matsumoto
11679e3f3a
vm.c: check if target_class is NULL (when prepended).
...
Address CVE-2022-1427
2022-05-10 20:11:17 +09:00
Yukihiro "Matz" Matsumoto
82d3b3d11b
vm.c: target class may be NULL.
...
Address CVE-2022-1201
2022-05-10 20:11:17 +09:00
Yukihiro "Matz" Matsumoto
2cbfc2f350
vm.c: vm.c: stack may be reallocated in functions calls; aaa28a5
...
`mrb_range_new()` also calls VM recursively.
Address CVE-2022-1106
2022-05-10 20:11:16 +09:00
Yukihiro "Matz" Matsumoto
6db4a58fbd
vm.c: stack may be reallocated in functions calls.
...
Probably due to recursive VM calls via `mrb_funcall()`.
Address CVE-2022-1071
2022-05-10 19:24:46 +09:00
Yukihiro "Matz" Matsumoto
d823045af4
vm.c: packed arguments length may be zero for send method.
...
Address CVE-2022-0631
2022-05-10 16:32:03 +09:00
Yukihiro "Matz" Matsumoto
15f597e835
class.c: add obj->c check before prepare_singleton_class().
...
Address CVE-2022-0240
2022-05-10 14:54:45 +09:00
Yukihiro "Matz" Matsumoto
64d3f4c730
vm.c: need to adjust argument after packing keyword args; fix #5632
...
It was caused by #5628 .
2022-03-31 12:58:48 +09:00
dearblue
178daf1a75
Fixes file header in src/{cdump,dump}.c [ci skip]
...
The file headers were pointing to each other's files.
2022-01-09 16:30:06 +09:00
Yukihiro "Matz" Matsumoto
696589cf27
Merge pull request #5628 from dearblue/super-kwargs
...
Fixing keyword arguments with `super`
2022-01-06 10:05:05 +09:00
Yukihiro "Matz" Matsumoto
dfa21f2e58
class.c: cancel #5620 which is no longer needed since #5622
...
This reverts commit d3b7601af9 .
2022-01-05 19:40:55 +09:00
Yukihiro "Matz" Matsumoto
c088af87b8
object.c: Call functions directly from mrb_ensure_int_type(); #5622
2022-01-05 19:00:14 +09:00
dearblue
55b2e45a26
Fixing keyword arguments with super
...
fix #5627
2022-01-05 16:40:13 +09:00
Yukihiro "Matz" Matsumoto
5c75dc9edc
Merge pull request #5625 from dearblue/proc_new
...
Assign after `mrb_irep_incref()` in `mrb_proc_new()`
2022-01-03 08:54:01 +09:00
Yukihiro "Matz" Matsumoto
4e0b162253
Merge pull request #5622 from dearblue/to_f
...
Call functions directly from `mrb_ensure_float_type()`
2022-01-02 18:04:18 +09:00
Yukihiro "Matz" Matsumoto
ab4baba283
Merge pull request #5620 from dearblue/adjust-stacks
...
Adjusting the stack for after it enters the virtual machine
2022-01-02 18:01:53 +09:00
dearblue
bee9665400
Assign after mrb_irep_incref() in mrb_proc_new()
...
ref. 28ccc664e5
2022-01-02 16:43:43 +09:00
Yukihiro "Matz" Matsumoto
28ccc664e5
proc.c: should not reference irep when copying failed.
...
It may cause broken reference count numbers.
2022-01-01 21:02:58 +09:00
dearblue
ac22a63ae3
Call functions directly from mrb_ensure_float_type()
...
ref. commit 7f40b645d2
Currently, the build configurations `MRB_USE_COMPLEX` and `MRB_USE_RATIONAL` are not listed in the documentation.
In other words, they are hidden settings.
They are defined in `mrbgems/mruby-{complex,rational}/mrbgem.rake`.
So this patch assumes that it is safe to refer to these functions in core-gems directly from core functions.
However, applications that link with `libmruby_core.a` will have compatibility issues.
In fact, `mrbgems/mruby-bin-mrbc` links with `libmruby_core.a`, so I had to prepare a dummy function.
2021-12-31 19:12:11 +09:00
Yukihiro "Matz" Matsumoto
3de9ddfb39
vm.c: use prepare_missing in mrb_funcall_with_block
...
Remove code duplication.
2021-12-31 18:15:41 +09:00
Yukihiro "Matz" Matsumoto
9fc26eacd1
Merge pull request #5619 from dearblue/properties
...
Get object properties after `mrb_get_args()`
2021-12-31 15:28:11 +09:00
Yukihiro "Matz" Matsumoto
b9e1b9b328
numeric.c: merge mrb_as_float implementation to mrb_ensure_float_type.
...
Since they are basically duplicated functionality. `mrb_as_float` is now
a macro defined using `mrb_ensure_float_type`; #5620
2021-12-31 15:14:37 +09:00
Yukihiro "Matz" Matsumoto
566a8d3fcb
object.c: add conversion to Float from Rational, Complex; #5620
2021-12-31 15:13:04 +09:00
Yukihiro "Matz" Matsumoto
7f40b645d2
numeric.c: mrb_as_float should not call to_f for generic objects.
...
It should only call `to_f` for Rational and Complex numbers.
Ref #5540 #5613 #5620
2021-12-31 10:54:28 +09:00
Yukihiro "Matz" Matsumoto
eea418bcce
class.c, variable,c: replace size_t by int.
...
That reduce memory consumption by iv/mt tables.
2021-12-31 10:54:28 +09:00
dearblue
d3b7601af9
Adjusting the stack for after it enters the virtual machine
...
ref. #5613 .
I mentioned in #5540 that there was no reentrant to the virtual machine, but in fact it was still a possibility at that point.
Also, the variable `ci` needs to be recalculated at the same time.
2021-12-30 22:45:19 +09:00
dearblue
a137ef12f9
Get object properties after mrb_get_args()
...
ref. #5613
I checked with Valgrind, and the methods that can cause use-after-free are `Array#rotate`, `Array#rotate!`, and `String#byteslice`.
Since `String#rindex` uses `RSTRING_LEN()` indirectly inside the function, no reference to the out-of-bounds range is generated.
2021-12-30 22:34:22 +09:00
Yukihiro "Matz" Matsumoto
77f4a8b669
object.c: move string to float conversion to mrb_f_float.
2021-12-29 16:58:05 +09:00
Yukihiro "Matz" Matsumoto
66a099b1b3
string.c: reorganize str_convert_range using mrb_ensure_int_type
2021-12-29 16:44:35 +09:00
Yukihiro "Matz" Matsumoto
b6d31810fe
string.c: use mrb_as_int macro.
2021-12-29 16:39:56 +09:00
Yukihiro "Matz" Matsumoto
4f297ac29c
object.c: introduce mrb_ensure_{int,float}_type.
...
Since `mrb_to_integer` and `mrb_to_float` does not convert the object
but checks types, they are named so by historical reason. We introduced
properly named functions.
This commit obsoletes the following functions:
* mrb_to_integer()
* mrb_to_int()
* mrb_to_float()
Use `mrb_ensure_int_type()` instead for the first 2 functions. Use
`mrb_ensure_float_type()` for the last.
2021-12-29 16:39:29 +09:00
Yukihiro "Matz" Matsumoto
b6283978c5
object.c: avoid implicit to_i and to_f calls.
...
mruby have removed `to_int` implicit conversion, so `mrb_to_integer`
should not call `to_i` for conversion.
2021-12-29 16:21:29 +09:00
Yukihiro "Matz" Matsumoto
27d1e0132a
array.c: fix mrb_ary_shift_m initialization bug.
...
The `ARY_PTR` and `ARY_LEN` may be modified in `mrb_get_args`.
2021-12-29 15:50:28 +09:00
Yukihiro "Matz" Matsumoto
6de0fcbda2
class.c: remove mt_elem structure to avoid alignment gaps.
2021-12-27 11:15:34 +09:00
Yukihiro "Matz" Matsumoto
a388d609ae
variable.c: need to initialize size of iv table.
2021-12-27 10:55:17 +09:00
Yukihiro "Matz" Matsumoto
a42b676ae9
vm.c: fix a half-baked implementation of OP_SETIDX; ref #5608
2021-12-20 17:45:10 +09:00
Yukihiro "Matz" Matsumoto
5774a7a38b
codedump.c: adjust the position of local variable labels.
2021-12-20 17:44:31 +09:00
Yukihiro "Matz" Matsumoto
a3d240c2ed
Merge pull request #5599 from dearblue/loss-digits
...
Avoid losing the upper digits for mruby binary
2021-12-15 23:07:13 +09:00
Yukihiro "Matz" Matsumoto
f5e10c5a79
proc.c: add mrb_state argument to mrb_proc_copy().
...
The function may invoke the garbage collection and it requires
`mrb_state` to run.
2021-12-14 13:35:18 +09:00
dearblue
fa33a5bb0c
Avoid losing the upper digits for mruby binary
...
- `rlen` keeps 16 bits.
- `ilen` keeps 32 bits.
Note that this change will break mruby binary format compatibility.
2021-12-13 22:58:57 +09:00
Yukihiro "Matz" Matsumoto
7b84fd4ce8
variable.c: resurrect size member in iv_tbl.
...
The existence of this member reduces memory and execution time.
2021-12-13 10:29:15 +09:00
Yukihiro "Matz" Matsumoto
786156d48c
class.c: increase first allocated page size.
2021-12-13 10:29:15 +09:00
Yukihiro "Matz" Matsumoto
bd4268210e
class.c: implement method cache (off by default).
2021-12-13 10:29:15 +09:00
Yukihiro "Matz" Matsumoto
d2a904c884
vm.c (check_method_noarg): the value at kidx may not be a hash.
2021-12-08 16:43:02 +09:00
Yukihiro "Matz" Matsumoto
c593e3e30a
vm.c: use check_method_noarg() to reduce code duplication; ref #5584
2021-12-08 16:42:23 +09:00
Yukihiro "Matz" Matsumoto
5bad1c7429
vm.c: fix mrb_ci_kidx.
...
It used to return wrong value for 14 positional arguments.
2021-12-08 16:22:24 +09:00
Yukihiro "Matz" Matsumoto
0b6b042fe8
variable.c: fix clang integer warning.
2021-12-08 13:27:10 +09:00
Yukihiro "Matz" Matsumoto
9935cf1aef
variable.c: avoid redundant iv scan in mrb_mod_cv_set().
...
Now `iv_get()` returns `pos+1` if it finds the entry, so you don't need
to call `iv_put()`. You can replace the entry value by assigning to
`t->ptr[pos-1]`.
2021-12-07 08:19:16 +09:00
Yukihiro "Matz" Matsumoto
e5810db1ad
variable.c: reduce array access in iv hash table.
2021-12-04 10:43:58 +09:00