Commit Graph

382 Commits

Author SHA1 Message Date
Yukihiro "Matz" Matsumoto 736be0e98b Always keep block argument space in stack; fix #3469 2017-02-27 13:05:26 +09:00
Yukihiro "Matz" Matsumoto 1e5b5b14d7 Prohibit too deep mrb_funcall() recursion; ref #3421
`mrb_funcall()` recursion can cause stack overflow easily,
so recursion depth is now limited to MRB_FUNCALL_DEPTH_MAX,
which default value is 512.
2017-02-15 12:06:32 +09:00
Yukihiro "Matz" Matsumoto 8efa7b00df Preallocate SystemStackError; ref #3421 2017-02-15 11:59:47 +09:00
Yukihiro "Matz" Matsumoto 719f700adf Extend mruby stack when keep is bigger than room; fix #3421
But #3421 still cause stack overflow error due to infinite recursion.
To prevent overflow, we need to add different stack depth check.
2017-02-14 00:15:58 +09:00
Yukihiro "Matz" Matsumoto c2ddcd4517 Should handle break from funcall(); fix #3434
This issue was reported by https://hackerone.com/d4nny
2017-02-13 18:45:20 +09:00
Yukihiro "Matz" Matsumoto f198530444 Fixed too much value_copy() when block is not given; fix #3440
The issue was reported by https://hackerone.com/titanous
2017-02-13 18:18:09 +09:00
Yukihiro "Matz" Matsumoto 1f2d786e32 Avoid direct return from ecall(); fix #3441
There's incompatibility left for mruby.

When you return from `ensure` clause, mruby simply ignores the return
value.  CRuby returns from the method squashing the exception raised.

```
def f
  no_such_method() # NoMethodError
ensure
  return 22
end

p f() # CRuby prints `22`
```
2017-02-11 21:58:47 +09:00
Yukihiro "Matz" Matsumoto 642ab8ecda ecall() should preserve stack address referenced from ci[1].
OP_RETURN accesses ci[1]->stackent that might be broken; fix #3442
2017-02-11 18:13:39 +09:00
Yukihiro "Matz" Matsumoto af4d74fc7d Add MRB_TT_PROC check to OP_SUPER as well; fix #3432 2017-02-08 21:13:22 +09:00
Yukihiro "Matz" Matsumoto 76135e757f Check if m->env is NULL before dereferencing it; fix #3436 2017-02-08 19:01:09 +09:00
Yukihiro "Matz" Matsumoto f3d4ff16d3 Fixed a bug in ci address shifting; fix #3423
Dinko Galetic and Denis Kasak reported the issue and the fix.
(via https://hackerone.com/dgaletic).
2017-02-08 16:22:48 +09:00
Yukihiro "Matz" Matsumoto 48e0bbbfee Make eval to use trampoline technique; fix #3415
Now `eval()` can call Fiber.yield etc.
2017-02-04 16:19:31 +09:00
Yukihiro "Matz" Matsumoto ac88f85a9e Copy mrb_float values from pool when MRB_WORD_BOXING; ref #3396 2017-01-25 11:09:15 +09:00
Yukihiro "Matz" Matsumoto ffb5e5ab08 The ensure clause should keep its ci after its execution; fix #3406
This issue was reported by https://hackerone.com/ston3
2017-01-23 16:44:11 +09:00
Yukihiro "Matz" Matsumoto c48aef0b65 Stack position may be bigger than stack bottom; fix #3401
This issue was reported by https://hackerone.com/titanous
2017-01-21 18:01:12 +09:00
Yukihiro "Matz" Matsumoto fe0e45505b Initialize callinfo->acc; ref #3243 2017-01-18 17:53:08 +09:00
Yukihiro "Matz" Matsumoto 8d61f2120c Add proper given argument number in the wrong-number-argument error. 2017-01-12 23:14:35 +09:00
Yukihiro "Matz" Matsumoto a3571240e5 Add proper stack size calculation; fix #3398
This issue was reported by https://hackerone.com/ssarong
2017-01-12 23:08:58 +09:00
Yukihiro "Matz" Matsumoto db1bd078be Use temporary variable to avoid potential crash; fix #3387
This issue was original reported by https://hackerone.com/icanthack
https://hackerone.com/titanous suggested the solution.
`regs` may be reallocated in the function call.
2017-01-11 17:59:56 +09:00
Yukihiro "Matz" Matsumoto 06b2e6a76c Check if ci->target_class is NULL before dereferencing
close #3389
This issue was reported by https://hackerone.com/ston3
2017-01-11 11:30:52 +09:00
Yukihiro "Matz" Matsumoto f388b6d612 use size_t instead of int 2017-01-02 17:48:44 +09:00
Yukihiro "Matz" Matsumoto 270ea41b37 method_missing() may have CALL_MAXARGS-1 arguments; fix #3351
The issue was reported by https://hackerone.com/ston3
2016-12-30 22:09:32 +09:00
Yukihiro "Matz" Matsumoto df35076602 Restore callinfo offset in mrb_yield_with_class() 2016-12-13 17:17:47 +09:00
Yukihiro "Matz" Matsumoto 6ec14a2173 Merge pull request #3318 from bouk/splat-stack
Fix stack move segfaulting in OP_ARYCAT
2016-12-05 16:51:46 +09:00
Yukihiro "Matz" Matsumoto 8f510be211 Merge branch 'method-missing-segfault' of https://github.com/bouk/mruby into bouk-method-missing-segfault 2016-12-03 18:20:29 +09:00
Bouke van der Bijl 7d07466b43 Fix stack move segfaulting in OP_ARYCAT
Reported by https://hackerone.com/haquaman

Testcase (couldn't get it to work as a test):

def nil.b
  b *nil
end
nil.b
2016-12-01 15:23:31 -05:00
Francois Chagnon a384bcce35 Fix instances where return value of mrb_method_search_vm is unchecked
Reported by @charliesome
2016-11-24 10:51:29 -05:00
Bouke van der Bijl 4523aaec01 Fix segfault when defining class inside instance_exec on primitive 2016-11-24 10:06:15 -05:00
Yukihiro "Matz" Matsumoto 6c299aae67 fixed wrong stack adjustment for ensure clauses; fix #3175 2016-11-07 00:44:08 +09:00
Yukihiro "Matz" Matsumoto 0b8d8dd379 associate REnv to the executing block; fix #3214 2016-11-05 02:52:34 +09:00
Yukihiro "Matz" Matsumoto 6fd0e601cf Move to_proc conversion from OP_ENTER to OP_SENDB; fix #3227 2016-10-20 23:49:40 +09:00
Kazuaki Tanaka cb29c9b415 Fix return value type of bytecode_decoder 2016-09-20 23:15:49 +00:00
Kazuaki Tanaka 968ebac001 Bytecode decoder support, MRB_BYTECODE_DECODE_OPTION 2016-09-20 23:07:28 +00:00
yuri c9d4d96872 surpress warning when MRB_DISABLE_STDIO 2016-09-06 22:41:50 +09:00
ksss a5c2e95b10 Should clear method name
- Fix method name in top-level
- Fix SEGV when call Exception#backtrace if callinfo over CALLINFO_INIT_SIZE(32)
2016-09-05 21:58:08 +09:00
ksss 9dc820590f Should raise LocalJumpError when no block given 2016-07-14 13:03:25 +09:00
cremno 7453a5dfea use mrb_int_mul_overflow() 2016-05-10 19:12:02 +02:00
Kouhei Sutou 51cc35dc09 Remove needless assignment
d4ee409ae9 should remove this line.
2016-05-09 14:05:51 +09:00
Kenji Okimoto d4ee409ae9 Use stack directly
See https://github.com/mruby/mruby/pull/3142#issuecomment-201138873
2016-04-27 10:18:13 +09:00
Yukihiro "Matz" Matsumoto ae5b5ce575 vm.c: mrb_hash_set() may reallocate VM stack; close #3133 2016-04-11 14:11:44 +09:00
Kouhei Sutou c69cba2ad9 Add missing regs update
mrb_vm_define_class() may realloc() mrb->c->stack because it calls
mrb_funcall() for inherited hook. If mrb->c->stack is realloc()-ed, regs
refers orphan address.
2016-03-25 00:25:48 +09:00
Kouhei Sutou 1d84b3205a Fix SEGV on re-raising NoMemoryError
Think about the following Ruby script:

segv.rb:

    begin
      lambda do
        lambda do
          "x" * 1000 # NoMemoryError
        end.call
      end.call
    rescue
      raise
    end

If memory can't allocate after `"x" * 1000`, mruby crashes.

Because L_RAISE: block in mrb_vm_exec() calls mrb_env_unshare() via
cipop() and mrb_env_unshare() uses allocated memory without NULL check:

L_RAISE: block:

    L_RAISE:
      // ...
      while (ci[0].ridx == ci[-1].ridx) {
        cipop(mrb);
        // ...
      }

cipop():

    static void
    cipop(mrb_state *mrb)
    {
      struct mrb_context *c = mrb->c;

      if (c->ci->env) {
        mrb_env_unshare(mrb, c->ci->env);
      }

      c->ci--;
    }

mrb_env_unshare():

    MRB_API void
    mrb_env_unshare(mrb_state *mrb, struct REnv *e)
    {
      size_t len = (size_t)MRB_ENV_STACK_LEN(e);
      // p is NULL in this case
      mrb_value *p = (mrb_value *)mrb_malloc(mrb, sizeof(mrb_value)*len);

      MRB_ENV_UNSHARE_STACK(e);
      if (len > 0) {
        stack_copy(p, e->stack, len); // p is NULL but used. It causes SEGV.
      }
      e->stack = p;
      mrb_write_barrier(mrb, (struct RBasic *)e);
    }

To solve the SEGV, this change always raises NoMemoryError even when
realloc() is failed after the first NoMemoryError in
mrb_realloc(). mrb_unv_unshare() doesn't need to check NULL with this
change.

But it causes infinite loop in the following while:

    L_RAISE:
      // ...
      while (ci[0].ridx == ci[-1].ridx) {
        cipop(mrb);
        // ...
      }

Because cipop() never pops ci.

This change includes cipop() change. The change pops ci even when
mrb_unv_unshare() is failed by NoMemoryError.

This case can be reproduced by the following program:

    #include <stdlib.h>
    #include <mruby.h>
    #include <mruby/compile.h>

    static void *
    allocf(mrb_state *mrb, void *ptr, size_t size, void *ud)
    {
      static mrb_bool always_fail = FALSE;

      if (size == 1001) {
        always_fail = TRUE;
      }
      if (always_fail) {
        return NULL;
      }

      if (size == 0) {
        free(ptr);
        return NULL;
      } else {
        return realloc(ptr, size);
      }
    }

    int
    main(int argc, char **argv)
    {
      mrb_state *mrb;
      mrbc_context *c;
      FILE *file;

      mrb = mrb_open_allocf(allocf, NULL);
      c = mrbc_context_new(mrb);
      file = fopen(argv[1], "r");
      mrb_load_file_cxt(mrb, file, c);
      fclose(file);
      mrbc_context_free(mrb, c);
      mrb_close(mrb);

      return EXIT_SUCCESS;
    }

Try the following command lines:

    % cc -I include -L build/host/lib -O0 -g3 -o no-memory no-memory.c -lmruby -lm
    % ./no-memory segv.rb
2016-01-19 16:37:42 +09:00
Yukihiro "Matz" Matsumoto f7afe1d82a change mrb_run related API names; compatibility macros provided 2016-01-07 22:36:29 +09:00
Yukihiro "Matz" Matsumoto aec825a64c stack_extend before eval_under() 2016-01-04 10:22:38 +09:00
Yukihiro "Matz" Matsumoto aa1f668b80 instance_eval should pass the receiver as a block parameter; close #3029 2016-01-02 22:01:00 +09:00
Yukihiro "Matz" Matsumoto bd462c5edc mruby-fiber: fiber_switch() to use nesting VM when it's called from C API or mrb_funcall(); close #3056 2016-01-02 13:48:45 +09:00
Yukihiro "Matz" Matsumoto 3531fe179c GC must scan env from fibers even when it's not yet copied to heap; fix #3063 2015-12-31 00:11:37 +09:00
Kouhei Sutou a561bdb25f Support backtrace after method calls
GitHub: fix #2902, #2917

The current implementation traverses stack to retrieve backtrace. But
stack will be changed when some operations are occurred. It means that
backtrace may be broken after some operations.

This change (1) saves the minimum information to retrieve backtrace when
exception is raised and (2) restores backtrace from the minimum
information when backtrace is needed. It reduces overhead for creating
backtrace Ruby objects.

The space for the minimum information is reused by multiple
exceptions. So memory allocation isn't occurred for each exception.
2015-12-29 20:36:12 +09:00
Yukihiro "Matz" Matsumoto 5c405dea3d include changed from by quotes ("") to by brackets (<>); close #3032 2015-11-27 17:48:23 +09:00
Yukihiro "Matz" Matsumoto 4440566b95 DISABLE_STDIO/ENABLE_DEBUG macros to rename; close #3014
changes:
 * rename DISABLE_STDIO -> MRB_DISABLE_STDIO
 * rename ENABLE_DEBUG -> MRB_ENABLE_DEBUG_HOOK
 * no more opposite macro definitions (e.g. ENABLE_STDIO, DISABLE_DEBUG).
 * rewrite above macro references throughout the code.
 * update documents
2015-11-17 07:30:34 +09:00