Commit Graph

13890 Commits

Author SHA1 Message Date
Yukihiro "Matz" Matsumoto ce141b1332 string.rb (each_line): should not use [] reference.
Use `byteslice` instead.
2022-05-19 10:14:59 +09:00
Yukihiro "Matz" Matsumoto 19e4287d8b Merge pull request #5710 from suetanvil-misc/project-gemdecl-path-arg-flat
Fix `conf.gem path:` build_config argument.
2022-05-19 10:07:07 +09:00
Chris Reuter b297809b51 Fix conf.gem path: build_config argument.
The mrbgem guide (`doc/guides/mrbgems.md`) documents the `path:`
argument for `conf.gem` as being used to point to the root directory
of a gem when that gem is retrieved via git but is located in a
subdirectory of the checkout.

The actual code does not do this.  Instead, it treats path as (mostly)
identical to the `gemdir:` argument; that is, it points to a local
directory containing the gem.

This change fixes this by making `path:` behave as documented.
2022-05-18 14:02:47 -04:00
Yukihiro "Matz" Matsumoto 2cd966abc7 Merge pull request #5708 from jbampton/fix-spelling
Fix spelling
2022-05-18 07:50:00 +09:00
John Bampton 73580c49c4 Fix spelling 2022-05-17 19:47:54 +10:00
Yukihiro "Matz" Matsumoto f8b9464118 string.rb (each_line): use byteindex for performance; fix #4522
Character-wise String#index method calculate UTF-8 character width
numerous times if the string is long.
2022-05-17 07:18:44 +09:00
Yukihiro "Matz" Matsumoto 960da4ded4 cdump.c: should dump zero symbol (skip) too.
Zero symbol in the symbol table now means anonymous arguments.
2022-05-16 16:39:56 +09:00
Yukihiro "Matz" Matsumoto c2648ad95d string.c: add byteindex and byterindex methods. 2022-05-16 16:00:00 +09:00
Yukihiro "Matz" Matsumoto 8c985ff851 string.c (mrb_str_index_m): no need to align the position; ref #4569 2022-05-16 14:17:21 +09:00
Yukihiro "Matz" Matsumoto 0299ccf6c7 parse.y: allow inner anonymous block argument. 2022-05-16 14:17:21 +09:00
Yukihiro "Matz" Matsumoto 0a52f171aa mruby-random/random.c: factored out Random argument retrieval. 2022-05-16 14:17:20 +09:00
Yukihiro "Matz" Matsumoto 4283e2a950 Merge pull request #5707 from mruby/stable
Merge mruby 3.1.0
2022-05-13 07:38:26 +09:00
mimaki b3c04d036e Merge master branch. 2022-05-12 19:59:10 +09:00
Yukihiro "Matz" Matsumoto 6c6d8a98fa codedump.c: avoid printing 'local variable names:' header.
If there is no local variable defined in `irep`.
2022-05-12 19:14:40 +09:00
mimaki 1bec339230 Update version and release date. (mruby 3.1.0 (2022-05-12)) 3.1.0 2022-05-12 12:19:10 +09:00
Yukihiro "Matz" Matsumoto 257d16181d mruby3.2.md: add fixed CVE list. 2022-05-11 07:09:27 +09:00
Yukihiro "Matz" Matsumoto 090303568c mruby3.2.md: use dash instead of asterisk for itemize. 2022-05-11 07:08:39 +09:00
Yukihiro "Matz" Matsumoto 3ee10ccc63 mruby3.1.md: update fixed CVE list. 2022-05-11 07:06:36 +09:00
Yukihiro "Matz" Matsumoto 242a7f14e0 mruby3.1.md: update fixed CVE list. 2022-05-10 20:32:04 +09:00
Yukihiro "Matz" Matsumoto f13db72d26 load.c: add data boundary check for broken compiled binary. 2022-05-10 20:11:17 +09:00
Yukihiro "Matz" Matsumoto b82065aa92 load.c: should check if length of irep sections are valid. 2022-05-10 20:11:17 +09:00
Yukihiro "Matz" Matsumoto 11679e3f3a vm.c: check if target_class is NULL (when prepended).
Address CVE-2022-1427
2022-05-10 20:11:17 +09:00
Yukihiro "Matz" Matsumoto 82d3b3d11b vm.c: target class may be NULL.
Address CVE-2022-1201
2022-05-10 20:11:17 +09:00
Yukihiro "Matz" Matsumoto 2cbfc2f350 vm.c: vm.c: stack may be reallocated in functions calls; aaa28a5
`mrb_range_new()` also calls VM recursively.

Address CVE-2022-1106
2022-05-10 20:11:16 +09:00
Yukihiro "Matz" Matsumoto 6db4a58fbd vm.c: stack may be reallocated in functions calls.
Probably due to recursive VM calls via `mrb_funcall()`.

Address CVE-2022-1071
2022-05-10 19:24:46 +09:00
Yukihiro "Matz" Matsumoto 96cfde3488 fiber.c: should pack 15+ arguments in an array.
Address CVE-2022-0890
2022-05-10 19:24:46 +09:00
Yukihiro "Matz" Matsumoto 2e48070ab6 codegen.c: adjust stack position for OP_SUPER instruction.
Address CVE-2022-0632
2022-05-10 16:34:19 +09:00
Yukihiro "Matz" Matsumoto d823045af4 vm.c: packed arguments length may be zero for send method.
Address CVE-2022-0631
2022-05-10 16:32:03 +09:00
Yukihiro "Matz" Matsumoto c9ab1e601d codegen.c: fixed a bug in hash code generation with !val.
Address CVE-2022-0481
2022-05-10 14:56:53 +09:00
Yukihiro "Matz" Matsumoto beef5d37ad codegen.c: no OP_HASHADD required when val is false.
Address CVE-2022-0326
2022-05-10 14:55:58 +09:00
Yukihiro "Matz" Matsumoto 15f597e835 class.c: add obj->c check before prepare_singleton_class().
Address CVE-2022-0240
2022-05-10 14:54:45 +09:00
Yukihiro "Matz" Matsumoto 6189a90933 github/workflow: remove Cygwin build from Github Actions.
It often cross the 15 minutes timeout limit, so we just give up for now.
2022-05-10 14:02:16 +09:00
Yukihiro "Matz" Matsumoto fc4e9cdf81 mruby-test-inline-struct/inline.c: add type cast from void* to char*. 2022-05-09 18:57:26 +09:00
Yukihiro "Matz" Matsumoto eafc4b3f96 doc/mruby3.1.md: update for the 3.1 release. 2022-05-09 17:49:53 +09:00
Yukihiro "Matz" Matsumoto 84b0ba3f8d doc/mruby3.1.md: update for the release. 2022-05-09 17:46:26 +09:00
Yukihiro "Matz" Matsumoto 04d160f90b mruby-test-inline-struct/inline.c: add a comment about istruct protection. 2022-05-08 23:14:20 +09:00
Yukihiro "Matz" Matsumoto 8c2dbb761f mruby-test-inline-struct/inline.c: add mrb_istruct_p() checks. 2022-05-08 23:09:14 +09:00
Yukihiro "Matz" Matsumoto 45f61e3879 class.c (mrb_get_args): remove I specifier (istruct); close #5706 2022-05-07 17:35:45 +09:00
Yukihiro "Matz" Matsumoto 457abf4c9e error.c: now mrb_exc_mesg_get() returns a string or nil. 2022-05-06 16:45:17 +09:00
Yukihiro "Matz" Matsumoto 38b69b6014 error.c: protect mrb_print_error() from exceptions.
Now the function can be called when `mrb->jmp` is not set.
2022-05-06 16:26:31 +09:00
Yukihiro "Matz" Matsumoto c3e4ee0bf2 error.c: store error message converted as a string.
This is controversial since this change alters the `raise` behavior.
Previously, when an object that cannot be converted to a string, it just
ignore message when it's printed (using `Exception#inspect`). But after
this change, `raise` (more precisly `Exception.new`) raises TypeError
exception. I think the new behavior is clearer, more intuitive.
2022-05-06 16:21:39 +09:00
Yukihiro "Matz" Matsumoto d40822b148 Merge pull request #5705 from dearblue/adjust-stack
Introduce `mrb_stack_extend_adjust()`
2022-05-05 13:04:44 +09:00
dearblue c32cac6e59 Introduce mrb_stack_extend_adjust()
If necessary, adjust the pointer on the VM stack after `mrb_stack_extend()`.
2022-05-04 09:13:56 +09:00
Yukihiro "Matz" Matsumoto 50b1ded350 mruby-random/random.c: use rand_i() extensively. 2022-05-04 08:07:02 +09:00
Yukihiro "Matz" Matsumoto 49b8cef31f Merge pull request #5703 from dearblue/random-getargs
Strict acquisition of the `Random` class given by `mrb_get_args()`
2022-05-03 19:27:11 +09:00
dearblue 9b9424fe32 Strict acquisition of the Random class given by mrb_get_args()
This is to prevent data corruption of the substituted `Random` instance.
If the `Object::Random` constants are redefined to a different `MRB_TT_ISTRUCT` object class, they can pass `mrb_get_args()` validation.

The following is an example of how the `Array#shuffle` method rewrites the data of a non `Random` instance.

```c
// code.c

#include <mruby.h>
#include <mruby/class.h>
#include <mruby/compile.h>
#include <mruby/istruct.h>

#define EVAL_LIT(MRB, ...) mrb_load_string((MRB), #__VA_ARGS__)

static mrb_value
fake_initialize(mrb_state *mrb, mrb_value self)
{
  char *p = ISTRUCT_PTR(self);

  for (int i = 0; i < ISTRUCT_DATA_SIZE; i++) {
    p[i] = 'A' + i;
  }

  return self;
}

static mrb_value
fake_to_bytes(mrb_state *mrb, mrb_value self)
{
  const char *p = ISTRUCT_PTR(self);
  return mrb_str_new(mrb, p, ISTRUCT_DATA_SIZE);
}

int
main(int argc, char *argv[])
{
  mrb_state *mrb = mrb_open();

  struct RClass *fake = mrb_define_class(mrb, "Fake", mrb->object_class);
  MRB_SET_INSTANCE_TT(fake, MRB_TT_ISTRUCT);
  mrb_define_method(mrb, fake, "initialize", fake_initialize, MRB_ARGS_NONE());
  mrb_define_method(mrb, fake, "to_bytes", fake_to_bytes, MRB_ARGS_NONE());

  EVAL_LIT(mrb,
    Random = Fake \n
    fake = Fake.new \n
    p [fake, fake.to_bytes] \n
    p a = (1..10).to_a \n
    p a.shuffle(fake) \n
    p [fake, fake.to_bytes]
  );

  mrb_close(mrb);

  return 0;
}
```

```console
% `bin/mruby-config --cc --cflags --ldflags` code.c `bin/mruby-config --libs`
% ./a.out
[#<Fake:0x8007d8f20>, "ABCDEFGHIJKLMNOPQRSTUVWX"]
[1, 2, 3, 4, 5, 6, 7, 8, 9, 10]
[1, 7, 8, 10, 2, 6, 9, 3, 4, 5]
[#<Fake:0x8007d8f20>, "\xe81{\v\fM\xb0D<\x99\xb1V+l\x84\x86QRSTUVWX"]
```
2022-05-03 13:35:29 +09:00
Yukihiro "Matz" Matsumoto 23ce122fc2 vm.c (mrb_funcall_with_block): copy argv before prepare_missing(); fix #5704
Since prepare_missing() may call `missing` method internally.
2022-05-02 18:59:38 +09:00
Yukihiro "Matz" Matsumoto 651c872a71 Merge branch 'dearblue-exception' 2022-05-01 20:01:04 +09:00
Yukihiro "Matz" Matsumoto 06c4c76be8 Merge branch 'exception' of https://github.com/dearblue/mruby into dearblue-exception 2022-05-01 20:00:37 +09:00
Yukihiro "Matz" Matsumoto a243cf4d68 codedump.c: adjust integer size.
* uint32_t and ptrdiff_t
* uint16_t and uint8_t
2022-04-30 16:51:38 +09:00