ruby-changes:2209
From: ko1@a...
Date: 15 Oct 2007 09:58:26 +0900
Subject: [ruby-changes:2209] nobu - Ruby:r13700 (trunk, ruby_1_8): * marshal.c (r_bytes0): check if source has enough data.
nobu 2007-10-15 09:58:09 +0900 (Mon, 15 Oct 2007) New Revision: 13700 Modified files: branches/ruby_1_8/ChangeLog branches/ruby_1_8/marshal.c branches/ruby_1_8/test/ruby/test_marshal.rb branches/ruby_1_8/version.h trunk/ChangeLog trunk/marshal.c trunk/test/ruby/test_marshal.rb trunk/version.h Log: * marshal.c (r_bytes0): check if source has enough data. [ruby-dev:32054] http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/trunk/version.h?r1=13700&r2=13699 http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/branches/ruby_1_8/ChangeLog?r1=13700&r2=13699 http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/trunk/ChangeLog?r1=13700&r2=13699 http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/trunk/test/ruby/test_marshal.rb?r1=13700&r2=13699 http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/trunk/marshal.c?r1=13700&r2=13699 http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/branches/ruby_1_8/version.h?r1=13700&r2=13699 http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/branches/ruby_1_8/marshal.c?r1=13700&r2=13699 http://svn.ruby-lang.org/cgi-bin/viewvc.cgi/branches/ruby_1_8/test/ruby/test_marshal.rb?r1=13700&r2=13699 Index: ChangeLog =================================================================== --- ChangeLog (revision 13699) +++ ChangeLog (revision 13700) @@ -1,3 +1,8 @@ +Mon Oct 15 09:58:07 2007 Nobuyoshi Nakada <nobu@r...> + + * marshal.c (r_bytes0): check if source has enough data. + [ruby-dev:32054] + Mon Oct 15 01:15:09 2007 Tanaka Akira <akr@f...> * ext/socket/socket.c (s_accept_nonblock): make accepted fd Index: version.h =================================================================== --- version.h (revision 13699) +++ version.h (revision 13700) @@ -1,7 +1,7 @@ #define RUBY_VERSION "1.9.0" -#define RUBY_RELEASE_DATE "2007-10-14" +#define RUBY_RELEASE_DATE "2007-10-15" #define RUBY_VERSION_CODE 190 -#define RUBY_RELEASE_CODE 20071014 +#define RUBY_RELEASE_CODE 20071015 #define RUBY_PATCHLEVEL 0 #define RUBY_VERSION_MAJOR 1 @@ -9,7 +9,7 @@ #define RUBY_VERSION_TEENY 0 #define RUBY_RELEASE_YEAR 2007 #define RUBY_RELEASE_MONTH 10 -#define RUBY_RELEASE_DAY 14 +#define RUBY_RELEASE_DAY 15 #ifdef RUBY_EXTERN RUBY_EXTERN const char ruby_version[]; Index: marshal.c =================================================================== --- marshal.c (revision 13699) +++ marshal.c (revision 13700) @@ -929,7 +929,7 @@ if (len == 0) return rb_str_new(0, 0); if (TYPE(arg->src) == T_STRING) { - if (RSTRING_LEN(arg->src) > arg->offset) { + if (RSTRING_LEN(arg->src) > arg->offset + len) { str = rb_str_new(RSTRING_PTR(arg->src)+arg->offset, len); arg->offset += len; } Index: test/ruby/test_marshal.rb =================================================================== --- test/ruby/test_marshal.rb (revision 13699) +++ test/ruby/test_marshal.rb (revision 13700) @@ -52,4 +52,24 @@ TestMarshal::StructInvalidMembers.members } end + + class C + def initialize(str) + @str = str + end + def _dump(limit) + @str + end + def self._load(s) + new(s) + end + end + + def test_too_long_string + (data = Marshal.dump(C.new("a")))[-2, 1] = "\003\377\377\377" + e = assert_raise(ArgumentError, "[ruby-dev:32054]") { + Marshal.load(data) + } + assert_equal("marshal data too short", e.message) + end end Index: ruby_1_8/ChangeLog =================================================================== --- ruby_1_8/ChangeLog (revision 13699) +++ ruby_1_8/ChangeLog (revision 13700) @@ -1,3 +1,8 @@ +Mon Oct 15 09:58:07 2007 Nobuyoshi Nakada <nobu@r...> + + * marshal.c (r_bytes0): check if source has enough data. + [ruby-dev:32054] + Mon Oct 15 01:15:09 2007 Tanaka Akira <akr@f...> * ext/socket/socket.c (s_accept_nonblock): make accepted fd Index: ruby_1_8/version.h =================================================================== --- ruby_1_8/version.h (revision 13699) +++ ruby_1_8/version.h (revision 13700) @@ -1,7 +1,7 @@ #define RUBY_VERSION "1.8.6" -#define RUBY_RELEASE_DATE "2007-10-14" +#define RUBY_RELEASE_DATE "2007-10-15" #define RUBY_VERSION_CODE 186 -#define RUBY_RELEASE_CODE 20071014 +#define RUBY_RELEASE_CODE 20071015 #define RUBY_PATCHLEVEL 5000 #define RUBY_VERSION_MAJOR 1 @@ -9,7 +9,7 @@ #define RUBY_VERSION_TEENY 6 #define RUBY_RELEASE_YEAR 2007 #define RUBY_RELEASE_MONTH 10 -#define RUBY_RELEASE_DAY 14 +#define RUBY_RELEASE_DAY 15 #ifdef RUBY_EXTERN RUBY_EXTERN const char ruby_version[]; Index: ruby_1_8/marshal.c =================================================================== --- ruby_1_8/marshal.c (revision 13699) +++ ruby_1_8/marshal.c (revision 13700) @@ -468,7 +468,7 @@ return; } - if (ivtbl = rb_generic_ivar_table(obj)) { + if ((ivtbl = rb_generic_ivar_table(obj)) != 0) { w_byte(TYPE_IVAR, arg); } if (obj == Qnil) { @@ -873,7 +873,7 @@ if (len == 0) return rb_str_new(0, 0); if (TYPE(arg->src) == T_STRING) { - if (RSTRING(arg->src)->len > arg->offset) { + if (RSTRING(arg->src)->len > arg->offset + len) { str = rb_str_new(RSTRING(arg->src)->ptr+arg->offset, len); arg->offset += len; } Index: ruby_1_8/test/ruby/test_marshal.rb =================================================================== --- ruby_1_8/test/ruby/test_marshal.rb (revision 13699) +++ ruby_1_8/test/ruby/test_marshal.rb (revision 13700) @@ -45,4 +45,24 @@ assert_equal(a, b) } end + + class C + def initialize(str) + @str = str + end + def _dump(limit) + @str + end + def self._load(s) + new(s) + end + end + + def test_too_long_string + (data = Marshal.dump(C.new("a")))[-2, 1] = "\003\377\377\377" + e = assert_raise(ArgumentError, "[ruby-dev:32054]") { + Marshal.load(data) + } + assert_equal("marshal data too short", e.message) + end end -- ML: ruby-changes@q... Info: http://www.atdot.net/~ko1/quickml