ruby-changes:40793
From: nobu <ko1@a...>
Date: Thu, 3 Dec 2015 16:02:27 +0900 (JST)
Subject: [ruby-changes:40793] nobu:r52872 (trunk): string.c: should not taint fstring
nobu 2015-12-03 16:02:19 +0900 (Thu, 03 Dec 2015) New Revision: 52872 http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&revision=52872 Log: string.c: should not taint fstring * string.c (rb_obj_as_string): fstring should not be infected. TODO: other frozen strings also may not be. Modified files: trunk/ChangeLog trunk/string.c trunk/test/ruby/test_object.rb Index: ChangeLog =================================================================== --- ChangeLog (revision 52871) +++ ChangeLog (revision 52872) @@ -1,3 +1,8 @@ https://github.com/ruby/ruby/blob/trunk/ChangeLog#L1 +Thu Dec 3 16:02:17 2015 Nobuyoshi Nakada <nobu@r...> + + * string.c (rb_obj_as_string): fstring should not be infected. + TODO: other frozen strings also may not be. + Thu Dec 3 15:39:21 2015 SHIBATA Hiroshi <hsbt@r...> * lib/scanf.rb: fixed double words typo. Index: string.c =================================================================== --- string.c (revision 52871) +++ string.c (revision 52872) @@ -1247,7 +1247,9 @@ rb_obj_as_string(VALUE obj) https://github.com/ruby/ruby/blob/trunk/string.c#L1247 str = rb_funcall(obj, idTo_s, 0); if (!RB_TYPE_P(str, T_STRING)) return rb_any_to_s(obj); - OBJ_INFECT(str, obj); + if (!FL_SET(str, RSTRING_FSTR) && FL_ABLE(obj)) + /* fstring must not be tainted, at least */ + OBJ_INFECT_RAW(str, obj); return str; } Index: test/ruby/test_object.rb =================================================================== --- test/ruby/test_object.rb (revision 52871) +++ test/ruby/test_object.rb (revision 52872) @@ -755,6 +755,15 @@ class TestObject < Test::Unit::TestCase https://github.com/ruby/ruby/blob/trunk/test/ruby/test_object.rb#L755 end EOS assert_match(/\bToS\u{3042}:/, x) + + name = "X".freeze + x = Object.new.taint + class<<x;self;end.class_eval {define_method(:to_s) {name}} + assert_same(name, x.to_s) + assert_not_predicate(name, :tainted?) + assert_raise(RuntimeError) {name.taint} + assert_equal("X", [x].join("")) + assert_not_predicate(name, :tainted?) end def test_inspect -- ML: ruby-changes@q... Info: http://www.atdot.net/~ko1/quickml/