[前][次][番号順一覧][スレッド一覧]

ruby-changes:2209

From: ko1@a...
Date: 15 Oct 2007 09:58:26 +0900
Subject: [ruby-changes:2209] nobu - Ruby:r13700 (trunk, ruby_1_8): * marshal.c (r_bytes0): check if source has enough data.

nobu	2007-10-15 09:58:09 +0900 (Mon, 15 Oct 2007)

  New Revision: 13700

  Modified files:
    branches/ruby_1_8/ChangeLog
    branches/ruby_1_8/marshal.c
    branches/ruby_1_8/test/ruby/test_marshal.rb
    branches/ruby_1_8/version.h
    trunk/ChangeLog
    trunk/marshal.c
    trunk/test/ruby/test_marshal.rb
    trunk/version.h

  Log:
    * marshal.c (r_bytes0): check if source has enough data.
      [ruby-dev:32054]


  http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/trunk/version.h?r1=13700&r2=13699
  http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/branches/ruby_1_8/ChangeLog?r1=13700&r2=13699
  http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/trunk/ChangeLog?r1=13700&r2=13699
  http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/trunk/test/ruby/test_marshal.rb?r1=13700&r2=13699
  http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/trunk/marshal.c?r1=13700&r2=13699
  http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/branches/ruby_1_8/version.h?r1=13700&r2=13699
  http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/branches/ruby_1_8/marshal.c?r1=13700&r2=13699
  http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/branches/ruby_1_8/test/ruby/test_marshal.rb?r1=13700&r2=13699

Index: ChangeLog
===================================================================
--- ChangeLog	(revision 13699)
+++ ChangeLog	(revision 13700)
@@ -1,3 +1,8 @@
+Mon Oct 15 09:58:07 2007  Nobuyoshi Nakada  <nobu@r...>
+
+	* marshal.c (r_bytes0): check if source has enough data.
+	  [ruby-dev:32054]
+
 Mon Oct 15 01:15:09 2007  Tanaka Akira  <akr@f...>
 
 	* ext/socket/socket.c (s_accept_nonblock): make accepted fd
Index: version.h
===================================================================
--- version.h	(revision 13699)
+++ version.h	(revision 13700)
@@ -1,7 +1,7 @@
 #define RUBY_VERSION "1.9.0"
-#define RUBY_RELEASE_DATE "2007-10-14"
+#define RUBY_RELEASE_DATE "2007-10-15"
 #define RUBY_VERSION_CODE 190
-#define RUBY_RELEASE_CODE 20071014
+#define RUBY_RELEASE_CODE 20071015
 #define RUBY_PATCHLEVEL 0
 
 #define RUBY_VERSION_MAJOR 1
@@ -9,7 +9,7 @@
 #define RUBY_VERSION_TEENY 0
 #define RUBY_RELEASE_YEAR 2007
 #define RUBY_RELEASE_MONTH 10
-#define RUBY_RELEASE_DAY 14
+#define RUBY_RELEASE_DAY 15
 
 #ifdef RUBY_EXTERN
 RUBY_EXTERN const char ruby_version[];
Index: marshal.c
===================================================================
--- marshal.c	(revision 13699)
+++ marshal.c	(revision 13700)
@@ -929,7 +929,7 @@
 
     if (len == 0) return rb_str_new(0, 0);
     if (TYPE(arg->src) == T_STRING) {
-	if (RSTRING_LEN(arg->src) > arg->offset) {
+	if (RSTRING_LEN(arg->src) > arg->offset + len) {
 	    str = rb_str_new(RSTRING_PTR(arg->src)+arg->offset, len);
 	    arg->offset += len;
 	}
Index: test/ruby/test_marshal.rb
===================================================================
--- test/ruby/test_marshal.rb	(revision 13699)
+++ test/ruby/test_marshal.rb	(revision 13700)
@@ -52,4 +52,24 @@
       TestMarshal::StructInvalidMembers.members
     }
   end
+
+  class C
+    def initialize(str)
+      @str = str
+    end
+    def _dump(limit)
+      @str
+    end
+    def self._load(s)
+      new(s)
+    end
+  end
+
+  def test_too_long_string
+    (data = Marshal.dump(C.new("a")))[-2, 1] = "\003\377\377\377"
+    e = assert_raise(ArgumentError, "[ruby-dev:32054]") {
+      Marshal.load(data)
+    }
+    assert_equal("marshal data too short", e.message)
+  end
 end
Index: ruby_1_8/ChangeLog
===================================================================
--- ruby_1_8/ChangeLog	(revision 13699)
+++ ruby_1_8/ChangeLog	(revision 13700)
@@ -1,3 +1,8 @@
+Mon Oct 15 09:58:07 2007  Nobuyoshi Nakada  <nobu@r...>
+
+	* marshal.c (r_bytes0): check if source has enough data.
+	  [ruby-dev:32054]
+
 Mon Oct 15 01:15:09 2007  Tanaka Akira  <akr@f...>
 
 	* ext/socket/socket.c (s_accept_nonblock): make accepted fd
Index: ruby_1_8/version.h
===================================================================
--- ruby_1_8/version.h	(revision 13699)
+++ ruby_1_8/version.h	(revision 13700)
@@ -1,7 +1,7 @@
 #define RUBY_VERSION "1.8.6"
-#define RUBY_RELEASE_DATE "2007-10-14"
+#define RUBY_RELEASE_DATE "2007-10-15"
 #define RUBY_VERSION_CODE 186
-#define RUBY_RELEASE_CODE 20071014
+#define RUBY_RELEASE_CODE 20071015
 #define RUBY_PATCHLEVEL 5000
 
 #define RUBY_VERSION_MAJOR 1
@@ -9,7 +9,7 @@
 #define RUBY_VERSION_TEENY 6
 #define RUBY_RELEASE_YEAR 2007
 #define RUBY_RELEASE_MONTH 10
-#define RUBY_RELEASE_DAY 14
+#define RUBY_RELEASE_DAY 15
 
 #ifdef RUBY_EXTERN
 RUBY_EXTERN const char ruby_version[];
Index: ruby_1_8/marshal.c
===================================================================
--- ruby_1_8/marshal.c	(revision 13699)
+++ ruby_1_8/marshal.c	(revision 13700)
@@ -468,7 +468,7 @@
 	return;
     }
 
-    if (ivtbl = rb_generic_ivar_table(obj)) {
+    if ((ivtbl = rb_generic_ivar_table(obj)) != 0) {
 	w_byte(TYPE_IVAR, arg);
     }
     if (obj == Qnil) {
@@ -873,7 +873,7 @@
 
     if (len == 0) return rb_str_new(0, 0);
     if (TYPE(arg->src) == T_STRING) {
-	if (RSTRING(arg->src)->len > arg->offset) {
+	if (RSTRING(arg->src)->len > arg->offset + len) {
 	    str = rb_str_new(RSTRING(arg->src)->ptr+arg->offset, len);
 	    arg->offset += len;
 	}
Index: ruby_1_8/test/ruby/test_marshal.rb
===================================================================
--- ruby_1_8/test/ruby/test_marshal.rb	(revision 13699)
+++ ruby_1_8/test/ruby/test_marshal.rb	(revision 13700)
@@ -45,4 +45,24 @@
       assert_equal(a, b)
     }
   end
+
+  class C
+    def initialize(str)
+      @str = str
+    end
+    def _dump(limit)
+      @str
+    end
+    def self._load(s)
+      new(s)
+    end
+  end
+
+  def test_too_long_string
+    (data = Marshal.dump(C.new("a")))[-2, 1] = "\003\377\377\377"
+    e = assert_raise(ArgumentError, "[ruby-dev:32054]") {
+      Marshal.load(data)
+    }
+    assert_equal("marshal data too short", e.message)
+  end
 end

--
ML: ruby-changes@q...
Info: http://www.atdot.net/~ko1/quickml

[前][次][番号順一覧][スレッド一覧]