Commit Graph

248 Commits

Author SHA1 Message Date
Yukihiro "Matz" Matsumoto 761493934e Mark whole root objects in final_marking_phase(); fix #3603
ref #1359 #1362
2017-04-17 16:06:18 +09:00
Yukihiro "Matz" Matsumoto 6dd1a570c2 Shared TT_ENV may need to be marked; fix #3550 2017-04-11 12:40:26 +09:00
Yukihiro "Matz" Matsumoto 0048dd118a Protect arguments from GC; fix #3597
GC may be called with OP_ENTER (especially when GC_STRESS is set).
2017-04-10 21:12:41 +09:00
Yukihiro "Matz" Matsumoto 5c114c91d4 Clear unused stack region that may refer freed objects; fix #3596 2017-04-10 09:46:09 +09:00
Yukihiro "Matz" Matsumoto 491d68bb30 Skip stack marking at all if c->stack is NULL. 2017-04-10 09:28:36 +09:00
Yukihiro "Matz" Matsumoto 7f37c2fc57 Use stderr for debug prints in DEBUG(); fix #3584 2017-04-05 12:38:38 +09:00
Yukihiro "Matz" Matsumoto b8461c8681 Protect ensure clause lambdas from GC; fix #3491 2017-04-03 18:38:49 +09:00
Yukihiro "Matz" Matsumoto 246db71139 Add struct REnv to union RVALUE; ref #3534 2017-04-03 18:01:17 +09:00
Yukihiro "Matz" Matsumoto ecee8c51b0 Avoid tracing shared TT_ENV object. 2017-03-04 18:53:36 +09:00
Yukihiro "Matz" Matsumoto 8efa7b00df Preallocate SystemStackError; ref #3421 2017-02-15 11:59:47 +09:00
Yukihiro "Matz" Matsumoto b277c58e78 Mark classes referenced from saved backtrace.
Maybe related to #3438
2017-02-08 16:31:37 +09:00
Yukihiro "Matz" Matsumoto 8f52b88ee7 No need to make env unshared in the finalization; fix #3425 2017-02-04 13:48:23 +09:00
Yukihiro "Matz" Matsumoto 8e0f231330 Mark mrb->backtrace.exc as GC root; fix #3388 2017-02-04 12:59:08 +09:00
Yukihiro "Matz" Matsumoto 3cc913490b Merge pull request #3329 from bouk/reuse
Mark all the built-in classes during GC sweep
2016-12-10 16:02:47 +09:00
Yukihiro "Matz" Matsumoto 0af170fbec gc.c: dead_slot is boolean; ref #3339 2016-12-10 15:34:32 +09:00
Kazuho Oku 2ef634edb5 do not destroy a page with an active TT_ENV (e.g. an env referred from TT_FIBER) 2016-12-10 15:11:07 +09:00
Kazuho Oku c2e749f878 fix issues of mrb_gc_unregister introduced in 09b1185
* fixes partial copy of objects in GC root array (due to missing `* sizeof(mrb_value)`)
* restores the behavior that permitted an unregistered object to be used as an argument
2016-12-08 10:27:07 +09:00
Bouke van der Bijl f7a891fa89 Mark all the built-in classes during GC sweep
Reported by https://hackerone.com/haquaman
2016-12-07 15:14:12 -05:00
Yukihiro "Matz" Matsumoto dffb4d82dc Add type check for cls before allocation 2016-12-06 11:40:49 +09:00
Yukihiro "Matz" Matsumoto 630733f346 check ttype before object allocation; fix #3294 2016-11-30 03:38:55 +09:00
Yukihiro "Matz" Matsumoto 9fc62d28d0 pre-allocate arena overflow error 2016-11-28 09:52:57 +09:00
Yukihiro "Matz" Matsumoto 9a126278b6 should not unshare() reclaimed env objects; fix #3230 2016-10-28 09:21:14 +09:00
Nobuyoshi Nakada 6511bfd79a Removed trailing spaces 2016-09-28 12:29:41 +09:00
Yuji Yamano 00faf3d317 Fix compilation error with GC_PROFILE. 2016-06-29 03:57:02 -04:00
Yukihiro "Matz" Matsumoto 09b11850a5 mrb_gc_unregister() to remove one registration; close #3160
when multiple mrb_gc_register() were called for the same object
2016-06-10 10:12:48 +09:00
Kouhei Sutou f1eb3aea11 Fix segmentation fault by backtrace and GC
GitHub: fix #3122

It reverts #3126. #3126 fixes the segmentation fault but generates
broken backtrace.

This change fixes the segmentation fault and generates correct
backtrace. The strategy of this change is "generating backtrace while
irep is alive".

/tmp/test.rb:
    def gen
      e0 = nil
      begin
        1.times {
          raise 'foobar'
        }
      rescue => e
        e0 = e
      end
      e0
    end

    e = gen
    GC.start
    gen
    GC.start

    puts e.backtrace.join("\n")

Run:

    % bin/mruby /tmp/test.rb
    /tmp/test.rb:5:in Object.gen
    /home/kou/work/ruby/mruby.kou/mrblib/numeric.rb:77:in Integral#times
    /tmp/test.rb:4:in Object.gen
    /tmp/test.rb:13

FYI:

    % ruby -v /tmp/test.rb
    ruby 2.3.0p0 (2015-12-25) [x86_64-linux-gnu]
    /tmp/test.rb:5:in `block in gen'
    /tmp/test.rb:4:in `times'
    /tmp/test.rb:4:in `gen'
    /tmp/test.rb:13:in `<main>'
2016-03-06 11:58:54 +09:00
Yukihiro "Matz" Matsumoto ec35e549ad need to free context when reclaiming fiber object in GC; fix #3109 2016-02-17 10:19:14 +09:00
Kouhei Sutou 1d84b3205a Fix SEGV on re-raising NoMemoryError
Think about the following Ruby script:

segv.rb:

    begin
      lambda do
        lambda do
          "x" * 1000 # NoMemoryError
        end.call
      end.call
    rescue
      raise
    end

If memory can't allocate after `"x" * 1000`, mruby crashes.

Because L_RAISE: block in mrb_vm_exec() calls mrb_env_unshare() via
cipop() and mrb_env_unshare() uses allocated memory without NULL check:

L_RAISE: block:

    L_RAISE:
      // ...
      while (ci[0].ridx == ci[-1].ridx) {
        cipop(mrb);
        // ...
      }

cipop():

    static void
    cipop(mrb_state *mrb)
    {
      struct mrb_context *c = mrb->c;

      if (c->ci->env) {
        mrb_env_unshare(mrb, c->ci->env);
      }

      c->ci--;
    }

mrb_env_unshare():

    MRB_API void
    mrb_env_unshare(mrb_state *mrb, struct REnv *e)
    {
      size_t len = (size_t)MRB_ENV_STACK_LEN(e);
      // p is NULL in this case
      mrb_value *p = (mrb_value *)mrb_malloc(mrb, sizeof(mrb_value)*len);

      MRB_ENV_UNSHARE_STACK(e);
      if (len > 0) {
        stack_copy(p, e->stack, len); // p is NULL but used. It causes SEGV.
      }
      e->stack = p;
      mrb_write_barrier(mrb, (struct RBasic *)e);
    }

To solve the SEGV, this change always raises NoMemoryError even when
realloc() is failed after the first NoMemoryError in
mrb_realloc(). mrb_unv_unshare() doesn't need to check NULL with this
change.

But it causes infinite loop in the following while:

    L_RAISE:
      // ...
      while (ci[0].ridx == ci[-1].ridx) {
        cipop(mrb);
        // ...
      }

Because cipop() never pops ci.

This change includes cipop() change. The change pops ci even when
mrb_unv_unshare() is failed by NoMemoryError.

This case can be reproduced by the following program:

    #include <stdlib.h>
    #include <mruby.h>
    #include <mruby/compile.h>

    static void *
    allocf(mrb_state *mrb, void *ptr, size_t size, void *ud)
    {
      static mrb_bool always_fail = FALSE;

      if (size == 1001) {
        always_fail = TRUE;
      }
      if (always_fail) {
        return NULL;
      }

      if (size == 0) {
        free(ptr);
        return NULL;
      } else {
        return realloc(ptr, size);
      }
    }

    int
    main(int argc, char **argv)
    {
      mrb_state *mrb;
      mrbc_context *c;
      FILE *file;

      mrb = mrb_open_allocf(allocf, NULL);
      c = mrbc_context_new(mrb);
      file = fopen(argv[1], "r");
      mrb_load_file_cxt(mrb, file, c);
      fclose(file);
      mrbc_context_free(mrb, c);
      mrb_close(mrb);

      return EXIT_SUCCESS;
    }

Try the following command lines:

    % cc -I include -L build/host/lib -O0 -g3 -o no-memory no-memory.c -lmruby -lm
    % ./no-memory segv.rb
2016-01-19 16:37:42 +09:00
Yukihiro "Matz" Matsumoto 3531fe179c GC must scan env from fibers even when it's not yet copied to heap; fix #3063 2015-12-31 00:11:37 +09:00
Yukihiro "Matz" Matsumoto 5c405dea3d include changed from by quotes ("") to by brackets (<>); close #3032 2015-11-27 17:48:23 +09:00
cremno e18e2a44f0 remove return
The return type of the mrb_objspace_each_objects function is void.
So this return statement with an expression is unnecessary and
also violates a constraint. From C99 §6.8.6.4:
>A return statement with an expression shall not appear
>in a function whose return type is void.
2015-11-06 18:13:38 +01:00
furunkel 0d8012f513 Merge upstream 2015-10-21 11:12:08 +02:00
furunkel 1c6b1d0155 Prefix mrb_gc_state enum members, make color defines private 2015-10-20 10:54:47 +02:00
furunkel 2b39d87fe8 Remove gc_ prefix of mrb_gc fields 2015-10-19 23:00:07 +02:00
furunkel 2f8b0f66bc Move MRB_GC_ARENA_SIZE to gc.h and fix compiler warnings 2015-10-19 22:43:09 +02:00
furunkel 5c093ed22b Remove segregated value struct declaration 2015-10-19 22:34:47 +02:00
furunkel 3ab2f9371e Clean up GC code 2015-10-19 22:29:43 +02:00
Yukihiro "Matz" Matsumoto 73dc32c670 add new functions mrb_gc_register/unregister; close #1411
some routines need to refer mruby objects (e.g. callbacks), in that case
you have to protect your objects from garbage collection. the new functions
mrb_gc_register() keeps those objects from GC. you have to remove your
objects using mrb_gc_unregister() when your C routines use mruby objects
any longer, otherwise objects will leak.
2015-09-22 00:15:29 +09:00
Corey Powell eb172c28d7 Applied gc patch to fix ORIGIN ICLASS method table leak
Based on the gc patch by ko1

https://github.com/ruby/ruby/commit/5922c954614e5947a548780bb3b894626affe6dd
2015-07-14 09:44:04 -05:00
Yukihiro "Matz" Matsumoto 83992ee163 cast MRB_ENV_STACK_LEN to (mrb_int); ref #2600 2014-10-02 17:59:01 +09:00
Tatsuhiko Kubo 5fa30aeaea Fix mismatches for MRB_API declarations. 2014-08-29 01:06:22 +09:00
Yukihiro "Matz" Matsumoto 7a25b53301 Merge pull request #2567 from cubicdaiya/issues/space_after_comma2
Add a missing space after ",".
2014-08-27 23:48:34 +09:00
Tatsuhiko Kubo 3202938099 Add a missing space after ",". 2014-08-27 19:13:40 +09:00
Tatsuhiko Kubo cc22ec85b9 Use mrb_malloc() instead of mrb_realloc(). 2014-08-27 18:58:26 +09:00
Tatsuhiko Kubo bf173b320f Remove discareded NULL checks. 2014-08-27 18:58:26 +09:00
Jun Hiroe 33ace171c4 Fix typo in gc.c 2014-08-07 21:16:32 +09:00
Yukihiro "Matz" Matsumoto 918d4dc85c Merge pull request #2512 from suzukaze/gc-state-root
Rename GC_STATE_NONE GC_STATE_ROOT
2014-08-07 00:01:31 +09:00
Jun Hiroe 5eb3a8caa6 Refactor incremental_sweep_phase() in gc.c 2014-08-06 23:22:05 +09:00
Jun Hiroe 21f583783d Rename GC_STATE_NONE GC_STATE_ROOT 2014-08-06 22:59:48 +09:00
Jun Hiroe 3569723ab3 Refactor obj_free() in gc.c 2014-08-05 23:16:01 +09:00