Commit Graph

5266 Commits

Author SHA1 Message Date
Yukihiro "Matz" Matsumoto a0c02e0a64 Merge pull request #5765 from dearblue/mrb_env_unshare
Improve out-of-memory tolerance of `mrb_env_unshare()`
2022-08-06 16:03:11 +09:00
Yukihiro "Matz" Matsumoto a7c3d59971 kernel.c (mrb_obj_hash): generate hash value for big-integers. 2022-08-06 06:43:41 +09:00
Yukihiro "Matz" Matsumoto 6d683785f9 etc.c: use mrb_byte_hash instead of simple hash function. 2022-08-06 06:43:41 +09:00
Yukihiro "Matz" Matsumoto 61f447e5df string.c (mrb_byte_hash): separate byte hashing functions. 2022-08-06 06:43:41 +09:00
dearblue 5bc15dd69b Fixed assertion in ARGUMENT_NORMALIZE() for bidx.
It should be compared to the `irep->nregs` value as is.

At the same time, discovered problems have been fixed.
2022-08-04 22:43:06 +09:00
Yukihiro "Matz" Matsumoto 51f404be33 Merge pull request #5768 from dearblue/hash-expansion
Fix property between `ar_set()` and `ht_init()`.
2022-08-01 17:37:25 +09:00
Yukihiro "Matz" Matsumoto c32a8a71e9 Merge pull request #5767 from dearblue/fiber-gc
Fix `SIGSEGV` caused by GC during fiber initialization
2022-08-01 17:17:29 +09:00
Yukihiro "Matz" Matsumoto dd00724f30 Merge pull request #5766 from dearblue/red-write-barrier
Ignore `MRB_GC_RED` objects in `mrb_field_write_barrier()`
2022-08-01 17:15:54 +09:00
Yukihiro "Matz" Matsumoto 9dfbcbae7b object.c (mrb_equal): support big-integers. 2022-08-01 16:26:02 +09:00
Yukihiro "Matz" Matsumoto 4fb018d407 object.c (mrb_equal): shortcut per object comparison.
To reduce the chance to call mrb_funcall(), which is heavy and
unfriendly to fiber context switches.
2022-08-01 16:24:48 +09:00
Yukihiro "Matz" Matsumoto 585d80e0a7 numeric.c (num_eql): move eql? definition to Numeric class.
We no longer need Float#eql? etc.
2022-08-01 16:20:35 +09:00
dearblue 2d9ecc660e Fix property between ar_set() and ht_init().
If GC occurs in `mrb_realloc()` in `ht_init()` called from `ar_set()`, the following inconsistency occurs:
- If `h_ht_on()` is called before `mrb_realloc()`, `hash->hsh.ht` is referenced instead of `hash->hsh.ea` during GC.
- If the pointer is changed by `ea_adjust()` in `ar_set()`, `hash->hsh.ea` (`hash->hsh.ht`) is referenced in GC before the change.

These modifications can be resolved by changing the order of processing.

However, if a `NoMemoryError` exception is raised, it is presumed that the size of the "AR" will be exceeded and the unintended state will continue.
To prevent this, elements should be added after they have been converted to "HT".
2022-07-30 23:20:48 +09:00
dearblue a82a3533e6 Fix SIGSEGV caused by GC during fiber initialization
GC may occur in the `c->stbase = mrb_malloc()` part of the `fiber_init()` function.
The `SIGSEGV` happens because it references the `c->ci->stack` field without checking `c->ci`.
This is caused by #5272.
2022-07-30 22:32:02 +09:00
dearblue 2eefee0d6a Ignore MRB_GC_RED objects in mrb_field_write_barrier() 2022-07-30 22:32:01 +09:00
dearblue be3c0e5f4f Improve out-of-memory tolerance of mrb_env_unshare()
Exception raising can now be controlled by the caller.

The main purpose on this patch is:

- Suppress exceptions from `obj_free()` in `src/gc.c` with `mrb_env_unshare()`.

- Consider the possibility that calls to `mrb_malloc()` may cause `e` objects to be subject to GC.

  When control is returned to `mrb_env_unshare()`, `struct free_obj::next` in the same offset as `struct REnv::stack` is rewritten.
  Unexpected results then occur when the object is reused.
  Also, if `mrb_heap_page` containing an `e` object is freed, it may cause `SIGSEGV` at that point.

- Protects the value of the stack on `callinfo` that just exits if GC occurs inside `mrb_env_unshare()`.

  ```ruby
  def m
    b = -> { b }
  end

  p m.call
  # => print block object, not nil
  ```

  This patch does not raise a `NoMemoryError` exception in `mrb_env_unshare()` and can detect that error.
  Thus, the problem fixed in # 3087 is not resurrected.

Also, it may seem that this patch should suppress exceptions raised by `cipop()` during `mrb_protect_error()` and `mrb_vm_exec()` unwinds.
However, `mrb_callinfo::u.env` by `CINFO_DIRECT` is not seen to be set.
So in that case `mrb_env_unshare()` is assumed to be originally exception-free.
2022-07-30 22:32:00 +09:00
dearblue 2e6d2abf09 Removed unnecessary ISO section numbers for Kernel.puts [ci skip]
The `Kernel.puts` method is defined in the `mrbgems/mruby-print/mrblib/print.rb` file.
2022-07-30 11:54:23 +09:00
Yukihiro "Matz" Matsumoto b77b8f4deb numeric.c (flo_ceil_floor): negate after converting integer to float.
Otherwise integer negate may overflow.
2022-07-30 09:08:42 +09:00
Yukihiro "Matz" Matsumoto 9d774bc011 numeric.c (flo_ceil_floor): return bigint if possible. 2022-07-30 09:08:02 +09:00
Yukihiro "Matz" Matsumoto eb392cb643 numeric.c (mrb_float_to_integer): check for RangeError.
Otherwise flo_to_i raises FloatDomainError instead.
2022-07-30 09:06:49 +09:00
Yukihiro "Matz" Matsumoto e4bcd8a96a numeric.c (mrb_float_to_integer): unify with flo_to_i(). 2022-07-30 09:05:21 +09:00
Yukihiro "Matz" Matsumoto 5af98f2088 numeric.c (flo_ceil_floor): add exact number check. 2022-07-30 09:01:24 +09:00
Yukihiro "Matz" Matsumoto b8d3bc0eae numeric.c: move FloatDomainError description to the sufficient place. 2022-07-30 08:46:06 +09:00
Yukihiro "Matz" Matsumoto 6da34fa735 numeric.c (int_div): add checks for division by zero. 2022-07-29 17:48:02 +09:00
Yukihiro "Matz" Matsumoto d0780c0525 vm.c: should cast bigint length to unsigned.
Otherwise length>127 would be considered as negative.
2022-07-28 15:21:32 +09:00
Yukihiro "Matz" Matsumoto 3d1b5d2b06 Merge pull request #5754 from artichoke/lopopolo/class-name-use-after-free
Fix possible use after free in `mrb_class_find_path`
2022-07-25 15:41:07 +09:00
Yukihiro "Matz" Matsumoto 13d909bd3c array.c: new configuration MRB_ARY_LENGTH_MAX.
The default value is 2**17 entries. If you want to avoid the limitation,
set this value to 0.
2022-07-25 10:58:02 +09:00
Yukihiro "Matz" Matsumoto c4cb416460 string.c: new configuration MRB_STR_LENGTH_MAX.
The default value is 1MB. If you want to avoid the limitation, set this
value to 0.
2022-07-25 10:58:02 +09:00
Ryan Lopopolo 547d465340 Fix possible use after free in mrb_class_find_path
`mrb_class_find_path` resolves a `char*` pointer to a class name string
by calling `mrb_class_name`. It then allocates a new string with
capacity 40 to copy that `char*` into.

https://github.com/mruby/mruby/blob/e04184185ab43b94980550e850d8813a415fa438/src/variable.c#L1111-L1112

`mrb_class_name` resolves the class name via `class_name_str`, which
returns an `mrb_value` with type tag `MRB_TT_STRING` and backed by an
`RString*`. Then `mrb_class_name` extracts the `RSTRING_PTR`:

https://github.com/mruby/mruby/blob/e04184185ab43b94980550e850d8813a415fa438/src/class.c#L2133-L2134

That `RString*`-backed `mrb_value` ultimately comes from `mrb_class_path`
which resolves the string from the symbol table:

https://github.com/mruby/mruby/blob/e04184185ab43b94980550e850d8813a415fa438/src/class.c#L2111

The allocation of the target `str` after resolving the class name
`mrb_value` and extracting its pointer is fragile and assumes the
`RString*` is "static". If the `RString*` is not static, the
interleaving of extracting the `RSTRING_PTR` followed by a subsequent
allocation might result in the class name `mrb_value` being garbage
collected, which will leave the extracted pointer invalid.

Fix this bad interleaving by allocating the destination string first
before taking a raw pointer to an `RString*`.
2022-07-24 09:33:51 -07:00
Yukihiro "Matz" Matsumoto a3f2470907 Merge pull request #5749 from dearblue/patch-5565
Corrected the number of registers in the `Class#new` method
2022-07-18 09:26:34 +09:00
Yukihiro "Matz" Matsumoto 0e530dbb63 numeric.c: fix smallint op bigint error in bitwise logical operators. 2022-07-18 08:29:52 +09:00
dearblue c621d3cb95 Corrected the number of registers in the Class#new method
`OP_SEND R4 :allocate 0` requires an an invisible `nil` block to `R5`.
If `R5` is not allocated, this can lead to unexpected results due to buffer overflow.
This problem is caused by #5565.

ref. commit 33792c2a02
2022-07-17 10:38:53 +09:00
Yukihiro "Matz" Matsumoto 37c2f080f0 numeric.c (int_to_s): should not bypass base range check. 2022-07-12 14:48:36 +09:00
Yukihiro "Matz" Matsumoto bae11ef689 complex.c (mrb_complex_copy): allow copying of complex numbers. 2022-07-11 11:25:31 +09:00
Yukihiro "Matz" Matsumoto 67f47c9b42 rational.c (mrb_rational_copy): allow copying of rational numbers. 2022-07-11 11:19:22 +09:00
Yukihiro "Matz" Matsumoto 3ebb55b75f bigint.c (mrb_bint_copy): allow dup operation for bigints. 2022-07-11 11:02:27 +09:00
Yukihiro "Matz" Matsumoto 48b43af37f numeric.c (mrb_div_int_value): should support integer overflow.
Especially in `MRB_INT_MIN/-1` which is bigger than MRB_INT_MAX.
2022-07-09 15:21:45 +09:00
Yukihiro "Matz" Matsumoto fa0ff7cf86 numeric.c: better error message (Float -> Integer). 2022-07-09 15:13:52 +09:00
Yukihiro "Matz" Matsumoto 7de03cbb68 numeric.c: add mrb_noreturn qualifier to error functions.
- mrb_int_zerodiv()
- mrb_int_overflow()
2022-07-09 15:12:37 +09:00
Yukihiro "Matz" Matsumoto e1980d7596 numeric.c (mrb_div_int): separate the function in two.
- mrb_div_int() does integer division in Ruby way (mdiv)
  returns mrb_int
- mrb_div_int_value() division with zero div and overflow checks.
  returns mrb_value
2022-07-09 14:38:18 +09:00
Yukihiro "Matz" Matsumoto a2f0fd81e6 numeric.c (mrb_int_mul): fix error message (Float -> Integer). 2022-07-09 10:45:44 +09:00
Yukihiro "Matz" Matsumoto 8d34981530 numeric.c: avoid mathematical operations for simple cases. 2022-07-09 10:45:11 +09:00
Yukihiro "Matz" Matsumoto 960021e519 numeric.c (cmpnum): call mrb_bigint_cmp() if v1 is bigint, not v2. 2022-07-08 21:57:05 +09:00
Yukihiro "Matz" Matsumoto b5538eded1 vm.c (OP_ENTER): need to protect kdict from GC; ref #5741 2022-07-06 14:57:06 +09:00
Yukihiro "Matz" Matsumoto 8fed80f5eb vm.c (OP_ENTER): protect kdict from GC; ref #5741 2022-07-06 14:29:14 +09:00
Yukihiro "Matz" Matsumoto 4225ae4176 vm.c (OP_ENTER): need to update ci->nk when kd is set; fix #5741 2022-07-06 13:57:12 +09:00
Yukihiro "Matz" Matsumoto 7e8a4212fb vm.c: refactor OP_ENTER code; ref #5741 2022-07-06 13:37:29 +09:00
Yukihiro "Matz" Matsumoto 82a419cde3 vm.c (mrb_ci_kdict): should return -1 when no kargs given; ref #5741 2022-07-06 13:37:20 +09:00
Yukihiro "Matz" Matsumoto 638356af03 class.c (mc_clear_by_id): clear method cache with method id specified. 2022-07-05 17:39:36 +09:00
Yukihiro "Matz" Matsumoto a99e4a926d class.c (mrb_mc_clear_by_class): simplify method cache clear condition. 2022-07-05 17:39:30 +09:00
Yukihiro "Matz" Matsumoto 1e7012f8c1 class.c (mrb_class_inherited): no need to clear method cache.
Since the function is only called for a newly created class, there is no
need to modify the method cache here.
2022-07-04 21:47:19 +09:00