mirror of
https://github.com/mruby/mruby
synced 2026-06-08 16:11:16 +00:00
f1523d2404
commit 2d7d545c4c4bfce7fdcbcbe9baaeb437915742f0 Merge: 625a1249b178914bAuthor: Yukihiro "Matz" Matsumoto <matz@ruby.or.jp> Date: Fri Jun 5 14:35:13 2020 +0900 Merge branch 'fix-mrb_open-with-nomem' of https://github.com/dearblue/mruby into dearblue-fix-mrb_open-with-nomem commitb178914b11Author: dearblue <dearblue@users.noreply.github.com> Date: Sat Jan 19 22:22:44 2019 +0900 Fix invalid pointer free inside other heap's block 1. `e = mrb_obj_alloc(...)` 2. `e->stack = mrb->c->stack` (`mrb->c->stack` is anywhere in the range `stbase...stend`) 3. And raised exception by `mrb_malloc()`! 4. `mrb_free(e->stack)` by GC part (wrong free) commit52e3d5d858Author: dearblue <dearblue@users.noreply.github.com> Date: Sat Jan 19 21:55:36 2019 +0900 Fix memory leak for temporary symbols when out of memory commit4c5499b88eAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 11:42:07 2019 +0900 Fix uninitialized pointer dereference for debug section commit8e993167deAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 11:41:09 2019 +0900 Fix memory leak for temporary filenames when out of memory commit8b422577e6Author: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 10:57:51 2019 +0900 Fix memory leak for irep when out of memory commit6b35ebf49aAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 10:55:50 2019 +0900 Fix uninitialized pointer dereference when do not finished initializing irep commit2531f2631eAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 10:48:15 2019 +0900 Fix NULL pointer dereference when do not finished initializing irep commite2d6896ebaAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sat Jan 19 12:54:19 2019 +0900 Fix memory leak for irep when out of memory by `mrb_proc_new()` commitb6214ff8a0Author: dearblue <dearblue@users.noreply.github.com> Date: Sat Jan 19 12:53:07 2019 +0900 Fix memory leak for `khash_t` in `kh_init_size()` when out of memory by `kh_alloc()` commit19162dd6c1Author: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 02:15:07 2019 +0900 Fix memory leak for symbol string when out of memory in `kh_put()` commit15e67297ffAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 02:12:24 2019 +0900 Fix keep wrong symbol index when out of memory commit3f8e2b3752Author: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 02:08:13 2019 +0900 Fix keep wrong symbol capacity when out of memory commita3cfe755abAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sat Jan 19 10:11:37 2019 +0900 Fix NULL pointer dereference `mrb->c` by `mark_context()` commitd9c7b6be6eAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 15:25:09 2019 +0900 Fix protect exception for print error message commit100642750eAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 11:59:02 2019 +0900 Protect exception for mruby core initialization commit7a0418304eAuthor: dearblue <dearblue@users.noreply.github.com> Date: Fri Jan 18 20:38:27 2019 +0900 Fix memory leak for string object when out of memory The `mrb_str_pool()` function has a path to call `malloc()` twice. If occurs `NoMemoryError` exception in second `malloc()`, first `malloc()` pointer is not freed. commitfef1c152ceAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sat Jan 19 13:05:09 2019 +0900 Fix stack overflow when out of memory As a result of this change, no backtrace information is set for NoMemoryError (`mrb->nomem_err`). Detailes: When generating a backtrace, called `mrb_intern_lit()`, `mrb_str_new_cstr()` and `mrb_obj_iv_set()` function with `exc_debug_info()` function in `src/error.c`. If a `NoMemoryError` exception occurs at this time, the `exc_debug_info()` function will be called again, and in the same way `NoMemoryError` exception raised will result in an infinite loop to occurs stack overflow (and SIGSEGV). commitda7d7f881bAuthor: dearblue <dearblue@users.noreply.github.com> Date: Sun Jan 20 12:00:38 2019 +0900 Fix NULL pointer dereference `mrb->nomem_err` when not initialized Add internal functions (not `static`): * `mrb_raise_nomemory()` * `mrb_core_init_abort()`
218 lines
6.0 KiB
C
218 lines
6.0 KiB
C
#include <string.h>
|
|
#include <mruby.h>
|
|
#include <mruby/irep.h>
|
|
#include <mruby/debug.h>
|
|
|
|
static mrb_irep_debug_info_file*
|
|
get_file(mrb_irep_debug_info *info, uint32_t pc)
|
|
{
|
|
mrb_irep_debug_info_file **ret;
|
|
int32_t count;
|
|
|
|
if (pc >= info->pc_count) { return NULL; }
|
|
/* get upper bound */
|
|
ret = info->files;
|
|
count = info->flen;
|
|
while (count > 0) {
|
|
int32_t step = count / 2;
|
|
mrb_irep_debug_info_file **it = ret + step;
|
|
if (!(pc < (*it)->start_pos)) {
|
|
ret = it + 1;
|
|
count -= step + 1;
|
|
}
|
|
else { count = step; }
|
|
}
|
|
|
|
--ret;
|
|
|
|
/* check returning file exists inside debug info */
|
|
mrb_assert(info->files <= ret && ret < (info->files + info->flen));
|
|
/* check pc is within the range of returning file */
|
|
mrb_assert((*ret)->start_pos <= pc &&
|
|
pc < (((ret + 1 - info->files) < info->flen)
|
|
? (*(ret+1))->start_pos : info->pc_count));
|
|
|
|
return *ret;
|
|
}
|
|
|
|
static mrb_debug_line_type
|
|
select_line_type(const uint16_t *lines, size_t lines_len)
|
|
{
|
|
size_t line_count = 0;
|
|
int prev_line = -1;
|
|
size_t i;
|
|
for (i = 0; i < lines_len; ++i) {
|
|
if (lines[i] != prev_line) {
|
|
++line_count;
|
|
}
|
|
}
|
|
return (sizeof(uint16_t) * lines_len) <= (sizeof(mrb_irep_debug_info_line) * line_count)
|
|
? mrb_debug_line_ary : mrb_debug_line_flat_map;
|
|
}
|
|
|
|
MRB_API char const*
|
|
mrb_debug_get_filename(mrb_state *mrb, mrb_irep *irep, ptrdiff_t pc)
|
|
{
|
|
if (irep && pc >= 0 && pc < irep->ilen) {
|
|
mrb_irep_debug_info_file* f = NULL;
|
|
if (!irep->debug_info) return NULL;
|
|
else if ((f = get_file(irep->debug_info, (uint32_t)pc))) {
|
|
return mrb_sym_name_len(mrb, f->filename_sym, NULL);
|
|
}
|
|
}
|
|
return NULL;
|
|
}
|
|
|
|
MRB_API int32_t
|
|
mrb_debug_get_line(mrb_state *mrb, mrb_irep *irep, ptrdiff_t pc)
|
|
{
|
|
if (irep && pc >= 0 && pc < irep->ilen) {
|
|
mrb_irep_debug_info_file* f = NULL;
|
|
if (!irep->debug_info) {
|
|
return -1;
|
|
}
|
|
else if ((f = get_file(irep->debug_info, (uint32_t)pc))) {
|
|
switch (f->line_type) {
|
|
case mrb_debug_line_ary:
|
|
mrb_assert(f->start_pos <= pc && pc < (f->start_pos + f->line_entry_count));
|
|
return f->lines.ary[pc - f->start_pos];
|
|
|
|
case mrb_debug_line_flat_map: {
|
|
/* get upper bound */
|
|
mrb_irep_debug_info_line *ret = f->lines.flat_map;
|
|
uint32_t count = f->line_entry_count;
|
|
while (count > 0) {
|
|
int32_t step = count / 2;
|
|
mrb_irep_debug_info_line *it = ret + step;
|
|
if (!(pc < it->start_pos)) {
|
|
ret = it + 1;
|
|
count -= step + 1;
|
|
}
|
|
else { count = step; }
|
|
}
|
|
|
|
--ret;
|
|
|
|
/* check line entry pointer range */
|
|
mrb_assert(f->lines.flat_map <= ret && ret < (f->lines.flat_map + f->line_entry_count));
|
|
/* check pc range */
|
|
mrb_assert(ret->start_pos <= pc &&
|
|
pc < (((uint32_t)(ret + 1 - f->lines.flat_map) < f->line_entry_count)
|
|
? (ret+1)->start_pos : irep->debug_info->pc_count));
|
|
|
|
return ret->line;
|
|
}
|
|
}
|
|
}
|
|
}
|
|
return -1;
|
|
}
|
|
|
|
MRB_API mrb_irep_debug_info*
|
|
mrb_debug_info_alloc(mrb_state *mrb, mrb_irep *irep)
|
|
{
|
|
static const mrb_irep_debug_info initial = { 0, 0, NULL };
|
|
mrb_irep_debug_info *ret;
|
|
|
|
mrb_assert(!irep->debug_info);
|
|
ret = (mrb_irep_debug_info *)mrb_malloc(mrb, sizeof(*ret));
|
|
*ret = initial;
|
|
irep->debug_info = ret;
|
|
return ret;
|
|
}
|
|
|
|
MRB_API mrb_irep_debug_info_file*
|
|
mrb_debug_info_append_file(mrb_state *mrb, mrb_irep_debug_info *d,
|
|
const char *filename, uint16_t *lines,
|
|
uint32_t start_pos, uint32_t end_pos)
|
|
{
|
|
mrb_irep_debug_info_file *f;
|
|
uint32_t file_pc_count;
|
|
size_t fn_len;
|
|
uint32_t i;
|
|
|
|
if (!d) return NULL;
|
|
if (start_pos == end_pos) return NULL;
|
|
|
|
mrb_assert(filename);
|
|
mrb_assert(lines);
|
|
|
|
if (d->flen > 0) {
|
|
const char *fn = mrb_sym_name_len(mrb, d->files[d->flen - 1]->filename_sym, NULL);
|
|
if (strcmp(filename, fn) == 0)
|
|
return NULL;
|
|
}
|
|
|
|
f = (mrb_irep_debug_info_file*)mrb_malloc(mrb, sizeof(*f));
|
|
d->files = (mrb_irep_debug_info_file**)(
|
|
d->files
|
|
? mrb_realloc(mrb, d->files, sizeof(mrb_irep_debug_info_file*) * (d->flen + 1))
|
|
: mrb_malloc(mrb, sizeof(mrb_irep_debug_info_file*)));
|
|
d->files[d->flen++] = f;
|
|
|
|
file_pc_count = end_pos - start_pos;
|
|
|
|
f->start_pos = start_pos;
|
|
d->pc_count = end_pos;
|
|
|
|
fn_len = strlen(filename);
|
|
f->filename_sym = mrb_intern(mrb, filename, fn_len);
|
|
|
|
f->line_type = select_line_type(lines + start_pos, end_pos - start_pos);
|
|
f->lines.ptr = NULL;
|
|
|
|
switch (f->line_type) {
|
|
case mrb_debug_line_ary:
|
|
f->line_entry_count = file_pc_count;
|
|
f->lines.ary = (uint16_t*)mrb_malloc(mrb, sizeof(uint16_t) * file_pc_count);
|
|
for (i = 0; i < file_pc_count; ++i) {
|
|
f->lines.ary[i] = lines[start_pos + i];
|
|
}
|
|
break;
|
|
|
|
case mrb_debug_line_flat_map: {
|
|
uint16_t prev_line = 0;
|
|
mrb_irep_debug_info_line m;
|
|
f->lines.flat_map = (mrb_irep_debug_info_line*)mrb_malloc(mrb, sizeof(mrb_irep_debug_info_line) * 1);
|
|
f->line_entry_count = 0;
|
|
for (i = 0; i < file_pc_count; ++i) {
|
|
if (lines[start_pos + i] == prev_line) { continue; }
|
|
|
|
f->lines.flat_map = (mrb_irep_debug_info_line*)mrb_realloc(
|
|
mrb, f->lines.flat_map,
|
|
sizeof(mrb_irep_debug_info_line) * (f->line_entry_count + 1));
|
|
m.start_pos = start_pos + i;
|
|
m.line = lines[start_pos + i];
|
|
f->lines.flat_map[f->line_entry_count] = m;
|
|
|
|
/* update */
|
|
++f->line_entry_count;
|
|
prev_line = lines[start_pos + i];
|
|
}
|
|
} break;
|
|
|
|
default: mrb_assert(0); break;
|
|
}
|
|
|
|
return f;
|
|
}
|
|
|
|
MRB_API void
|
|
mrb_debug_info_free(mrb_state *mrb, mrb_irep_debug_info *d)
|
|
{
|
|
uint32_t i;
|
|
|
|
if (!d) { return; }
|
|
|
|
if (d->files) {
|
|
for (i = 0; i < d->flen; ++i) {
|
|
if (d->files[i]) {
|
|
mrb_free(mrb, d->files[i]->lines.ptr);
|
|
mrb_free(mrb, d->files[i]);
|
|
}
|
|
}
|
|
mrb_free(mrb, d->files);
|
|
}
|
|
mrb_free(mrb, d);
|
|
}
|