13527 Commits

Author SHA1 Message Date
mimaki 1bec339230 Update version and release date. (mruby 3.1.0 (2022-05-12)) 3.1.0 2022-05-12 12:19:10 +09:00
Yukihiro "Matz" Matsumoto 242a7f14e0 mruby3.1.md: update fixed CVE list. 2022-05-10 20:32:04 +09:00
Yukihiro "Matz" Matsumoto f13db72d26 load.c: add data boundary check for broken compiled binary. 2022-05-10 20:11:17 +09:00
Yukihiro "Matz" Matsumoto b82065aa92 load.c: should check if length of irep sections are valid. 2022-05-10 20:11:17 +09:00
Yukihiro "Matz" Matsumoto 11679e3f3a vm.c: check if target_class is NULL (when prepended).
Address CVE-2022-1427
2022-05-10 20:11:17 +09:00
Yukihiro "Matz" Matsumoto 82d3b3d11b vm.c: target class may be NULL.
Address CVE-2022-1201
2022-05-10 20:11:17 +09:00
Yukihiro "Matz" Matsumoto 2cbfc2f350 vm.c: vm.c: stack may be reallocated in functions calls; aaa28a5
`mrb_range_new()` also calls VM recursively.

Address CVE-2022-1106
2022-05-10 20:11:16 +09:00
Yukihiro "Matz" Matsumoto 6db4a58fbd vm.c: stack may be reallocated in functions calls.
Probably due to recursive VM calls via `mrb_funcall()`.

Address CVE-2022-1071
2022-05-10 19:24:46 +09:00
Yukihiro "Matz" Matsumoto 96cfde3488 fiber.c: should pack 15+ arguments in an array.
Address CVE-2022-0890
2022-05-10 19:24:46 +09:00
Yukihiro "Matz" Matsumoto 2e48070ab6 codegen.c: adjust stack position for OP_SUPER instruction.
Address CVE-2022-0632
2022-05-10 16:34:19 +09:00
Yukihiro "Matz" Matsumoto d823045af4 vm.c: packed arguments length may be zero for send method.
Address CVE-2022-0631
2022-05-10 16:32:03 +09:00
Yukihiro "Matz" Matsumoto c9ab1e601d codegen.c: fixed a bug in hash code generation with !val.
Address CVE-2022-0481
2022-05-10 14:56:53 +09:00
Yukihiro "Matz" Matsumoto beef5d37ad codegen.c: no OP_HASHADD required when val is false.
Address CVE-2022-0326
2022-05-10 14:55:58 +09:00
Yukihiro "Matz" Matsumoto 15f597e835 class.c: add obj->c check before prepare_singleton_class().
Address CVE-2022-0240
2022-05-10 14:54:45 +09:00
Yukihiro "Matz" Matsumoto 84b0ba3f8d doc/mruby3.1.md: update for the release. 2022-05-09 17:46:26 +09:00
mimaki 7d3bc5c3d7 Update version to 3.1.0RC2. 3.1.0-rc2 2022-03-31 15:17:17 +09:00
Yukihiro "Matz" Matsumoto f71d389649 codegen.c: fix the negative division regression; fix #5678 2022-03-31 13:05:06 +09:00
Yukihiro "Matz" Matsumoto eaadc5e79f parse.y: empty here-doc delimiter caused infinite loop; fix #5676 2022-03-31 13:01:27 +09:00
Yukihiro "Matz" Matsumoto c627e3b2ab codegen.c: fix a bug in super with keyword arguments; fix #5660 2022-03-31 13:00:34 +09:00
Yukihiro "Matz" Matsumoto 9424e4d4cf parse.y: revert 9e064f2; fix #5647
Need to declare unnamed parameter when argument decomposition used.
2022-03-31 12:59:44 +09:00
Yukihiro "Matz" Matsumoto 64d3f4c730 vm.c: need to adjust argument after packing keyword args; fix #5632
It was caused by #5628.
2022-03-31 12:58:48 +09:00
mimaki 6f2efebbb9 Merge commit '7e7f1b2' into stable 3.1.0-rc 2022-01-17 21:36:52 +09:00
Yukihiro "Matz" Matsumoto 7e7f1b2f1d parse.y: numbered parameters should not appear on toplevel.
Toplevel includes the top of the method/class/module definitions.
2022-01-11 14:52:05 +09:00
Yukihiro "Matz" Matsumoto 3a30cc27da parse.y: move numbered parameter indexing to lexer. 2022-01-11 14:49:41 +09:00
Yukihiro "Matz" Matsumoto 5dfbfb3ecd parse.y: p->nvar (numbered argument index list) may be NULL. 2022-01-10 15:44:15 +09:00
Yukihiro "Matz" Matsumoto 8c7b995962 AUTHORS: update entries [ci skip] 2022-01-10 12:33:01 +09:00
Yukihiro "Matz" Matsumoto 69b1667b5b Merge pull request #5630 from dearblue/dumps
Fixes file header in src/{cdump,dump}.c [ci skip]
2022-01-09 21:46:40 +09:00
dearblue 178daf1a75 Fixes file header in src/{cdump,dump}.c [ci skip]
The file headers were pointing to each other's files.
2022-01-09 16:30:06 +09:00
mimaki f29924c838 Update version to 3.1.0RC. 2022-01-07 14:15:50 +09:00
Yukihiro "Matz" Matsumoto 696589cf27 Merge pull request #5628 from dearblue/super-kwargs
Fixing keyword arguments with `super`
2022-01-06 10:05:05 +09:00
Yukihiro "Matz" Matsumoto b1fc0dd5a4 Merge pull request #5629 from dearblue/nanbox
Allows handling of unaligned cptrs for `MRB_NAN_BOXING`
2022-01-06 10:02:49 +09:00
Yukihiro "Matz" Matsumoto dfa21f2e58 class.c: cancel #5620 which is no longer needed since #5622
This reverts commit d3b7601af9.
2022-01-05 19:40:55 +09:00
Yukihiro "Matz" Matsumoto aaa3bd0e80 mrbc.c: simplify place holder functions; #5622 2022-01-05 19:39:39 +09:00
Yukihiro "Matz" Matsumoto c088af87b8 object.c: Call functions directly from mrb_ensure_int_type(); #5622 2022-01-05 19:00:14 +09:00
dearblue 88b1654725 Allows handling of unaligned cptrs for MRB_NAN_BOXING
It seems to be preferable to be able to handle pointers of type `char` as well.
For this purpose, `mrb_nanbox_tt_inline` has been reorganized.

- `MRB_NANBOX_TT_POINTER` has been split into `MRB_NANBOX_TT_OBJECT` and `MRB_NANBOX_TT_CPTR`
- `MRB_NANBOX_TT_SYMBOL` has been merged into `MRB_NANBOX_TT_MISC`
2022-01-05 17:23:35 +09:00
dearblue 55b2e45a26 Fixing keyword arguments with super
fix #5627
2022-01-05 16:40:13 +09:00
Yukihiro "Matz" Matsumoto d34e1cb84c Merge pull request #5623 from dearblue/more-presym
Improves presym scanning
2022-01-04 11:54:09 +09:00
Yukihiro "Matz" Matsumoto 6c68b516ff Merge pull request #5624 from dearblue/powerof2
Assert that `MRB_METHOD_CACHE_SIZE` is a power of 2
2022-01-04 11:51:00 +09:00
Yukihiro "Matz" Matsumoto 5c75dc9edc Merge pull request #5625 from dearblue/proc_new
Assign after `mrb_irep_incref()` in `mrb_proc_new()`
2022-01-03 08:54:01 +09:00
Yukihiro "Matz" Matsumoto 4e0b162253 Merge pull request #5622 from dearblue/to_f
Call functions directly from `mrb_ensure_float_type()`
2022-01-02 18:04:18 +09:00
Yukihiro "Matz" Matsumoto ab4baba283 Merge pull request #5620 from dearblue/adjust-stacks
Adjusting the stack for after it enters the virtual machine
2022-01-02 18:01:53 +09:00
dearblue bee9665400 Assign after mrb_irep_incref() in mrb_proc_new()
ref. 28ccc664e5
2022-01-02 16:43:43 +09:00
dearblue 82a1b00eb6 Assert that MRB_METHOD_CACHE_SIZE is a power of 2
The `mrb_static_assert_powerof2()` macro has been introduced for this purpose.
2022-01-02 14:59:55 +09:00
dearblue f2d19aaaac Improves presym scanning
The main purpose is to increase the chances of finding presym and to prevent errors due to C++11 lambda expressions.

- The argument to receive the class may be written, for example, `mrb_class_get()`.
- The argument that receives the implementation function of the method may be a C++ lambda expression.
  In this case, if multiple variable declarations are separated by colons, the preprocessor will recognize them as argument delimiters and report an error.
  This patch prevents it from happening.

  ```c++
  // When preprocessing...
  func([] { int x, y, z; })
    // ^^^^^^^^^^          1st argument?
    //             ^       2nd argument?
    //                ^^^^ 3rd argument?
  ```
2022-01-02 11:52:19 +09:00
Yukihiro "Matz" Matsumoto 28ccc664e5 proc.c: should not reference irep when copying failed.
It may cause broken reference count numbers.
2022-01-01 21:02:58 +09:00
dearblue ac22a63ae3 Call functions directly from mrb_ensure_float_type()
ref. commit 7f40b645d2

Currently, the build configurations `MRB_USE_COMPLEX` and `MRB_USE_RATIONAL` are not listed in the documentation.
In other words, they are hidden settings.
They are defined in `mrbgems/mruby-{complex,rational}/mrbgem.rake`.
So this patch assumes that it is safe to refer to these functions in core-gems directly from core functions.

However, applications that link with `libmruby_core.a` will have compatibility issues.
In fact, `mrbgems/mruby-bin-mrbc` links with `libmruby_core.a`, so I had to prepare a dummy function.
2021-12-31 19:12:11 +09:00
Yukihiro "Matz" Matsumoto 3de9ddfb39 vm.c: use prepare_missing in mrb_funcall_with_block
Remove code duplication.
2021-12-31 18:15:41 +09:00
Yukihiro "Matz" Matsumoto 5ca17c2dce Merge pull request #5621 from dearblue/ci-cygwin
Extend the Cygwin CI time limit to 15 minutes.
2021-12-31 16:32:33 +09:00
Yukihiro "Matz" Matsumoto 9fc26eacd1 Merge pull request #5619 from dearblue/properties
Get object properties after `mrb_get_args()`
2021-12-31 15:28:11 +09:00
Yukihiro "Matz" Matsumoto b9e1b9b328 numeric.c: merge mrb_as_float implementation to mrb_ensure_float_type.
Since they are basically duplicated functionality. `mrb_as_float` is now
a macro defined using `mrb_ensure_float_type`; #5620
2021-12-31 15:14:37 +09:00