[前][次][番号順一覧][スレッド一覧]

ruby-changes:40793

From: nobu <ko1@a...>
Date: Thu, 3 Dec 2015 16:02:27 +0900 (JST)
Subject: [ruby-changes:40793] nobu:r52872 (trunk): string.c: should not taint fstring

nobu	2015-12-03 16:02:19 +0900 (Thu, 03 Dec 2015)

  New Revision: 52872

  http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&revision=52872

  Log:
    string.c: should not taint fstring
    
    * string.c (rb_obj_as_string): fstring should not be infected.
      TODO: other frozen strings also may not be.

  Modified files:
    trunk/ChangeLog
    trunk/string.c
    trunk/test/ruby/test_object.rb
Index: ChangeLog
===================================================================
--- ChangeLog	(revision 52871)
+++ ChangeLog	(revision 52872)
@@ -1,3 +1,8 @@ https://github.com/ruby/ruby/blob/trunk/ChangeLog#L1
+Thu Dec  3 16:02:17 2015  Nobuyoshi Nakada  <nobu@r...>
+
+	* string.c (rb_obj_as_string): fstring should not be infected.
+	  TODO: other frozen strings also may not be.
+
 Thu Dec  3 15:39:21 2015  SHIBATA Hiroshi  <hsbt@r...>
 
 	* lib/scanf.rb: fixed double words typo.
Index: string.c
===================================================================
--- string.c	(revision 52871)
+++ string.c	(revision 52872)
@@ -1247,7 +1247,9 @@ rb_obj_as_string(VALUE obj) https://github.com/ruby/ruby/blob/trunk/string.c#L1247
     str = rb_funcall(obj, idTo_s, 0);
     if (!RB_TYPE_P(str, T_STRING))
 	return rb_any_to_s(obj);
-    OBJ_INFECT(str, obj);
+    if (!FL_SET(str, RSTRING_FSTR) && FL_ABLE(obj))
+	/* fstring must not be tainted, at least */
+	OBJ_INFECT_RAW(str, obj);
     return str;
 }
 
Index: test/ruby/test_object.rb
===================================================================
--- test/ruby/test_object.rb	(revision 52871)
+++ test/ruby/test_object.rb	(revision 52872)
@@ -755,6 +755,15 @@ class TestObject < Test::Unit::TestCase https://github.com/ruby/ruby/blob/trunk/test/ruby/test_object.rb#L755
       end
     EOS
     assert_match(/\bToS\u{3042}:/, x)
+
+    name = "X".freeze
+    x = Object.new.taint
+    class<<x;self;end.class_eval {define_method(:to_s) {name}}
+    assert_same(name, x.to_s)
+    assert_not_predicate(name, :tainted?)
+    assert_raise(RuntimeError) {name.taint}
+    assert_equal("X", [x].join(""))
+    assert_not_predicate(name, :tainted?)
   end
 
   def test_inspect

--
ML: ruby-changes@q...
Info: http://www.atdot.net/~ko1/quickml/

[前][次][番号順一覧][スレッド一覧]