mirror of
https://github.com/ruby/ruby.git
synced 2022-11-09 12:17:21 -05:00
merge revision(s) r46778: [Backport #10019]
* pack.c (encodes): fix buffer overrun by tail_lf. Thanks to Mamoru Tasaka and Tomas Hoger. [ruby-core:63604] [Bug #10019] git-svn-id: svn+ssh://ci.ruby-lang.org/ruby/branches/ruby_2_1@46806 b2dd03c8-39d4-4d8f-98ff-823fe69b080e
This commit is contained in:
parent
5643bc5ae0
commit
5c1a69452b
4 changed files with 19 additions and 4 deletions
|
|
@ -1,3 +1,8 @@
|
|||
Sun Jul 13 22:52:43 2014 Nobuyoshi Nakada <nobu@ruby-lang.org>
|
||||
|
||||
* pack.c (encodes): fix buffer overrun by tail_lf. Thanks to
|
||||
Mamoru Tasaka and Tomas Hoger. [ruby-core:63604] [Bug #10019]
|
||||
|
||||
Sun Jul 13 22:44:05 2014 Nobuyoshi Nakada <nobu@ruby-lang.org>
|
||||
|
||||
* ext/thread/thread.c (undumpable): ConditionVariable and Queue
|
||||
|
|
|
|||
8
pack.c
8
pack.c
|
|
@ -946,7 +946,8 @@ static const char b64_table[] =
|
|||
static void
|
||||
encodes(VALUE str, const char *s, long len, int type, int tail_lf)
|
||||
{
|
||||
char buff[4096];
|
||||
enum {buff_size = 4096, encoded_unit = 4};
|
||||
char buff[buff_size + 1]; /* +1 for tail_lf */
|
||||
long i = 0;
|
||||
const char *trans = type == 'u' ? uu_table : b64_table;
|
||||
char padding;
|
||||
|
|
@ -959,7 +960,7 @@ encodes(VALUE str, const char *s, long len, int type, int tail_lf)
|
|||
padding = '=';
|
||||
}
|
||||
while (len >= 3) {
|
||||
while (len >= 3 && sizeof(buff)-i >= 4) {
|
||||
while (len >= 3 && buff_size-i >= encoded_unit) {
|
||||
buff[i++] = trans[077 & (*s >> 2)];
|
||||
buff[i++] = trans[077 & (((*s << 4) & 060) | ((s[1] >> 4) & 017))];
|
||||
buff[i++] = trans[077 & (((s[1] << 2) & 074) | ((s[2] >> 6) & 03))];
|
||||
|
|
@ -967,7 +968,7 @@ encodes(VALUE str, const char *s, long len, int type, int tail_lf)
|
|||
s += 3;
|
||||
len -= 3;
|
||||
}
|
||||
if (sizeof(buff)-i < 4) {
|
||||
if (buff_size-i < encoded_unit) {
|
||||
rb_str_buf_cat(str, buff, i);
|
||||
i = 0;
|
||||
}
|
||||
|
|
@ -987,6 +988,7 @@ encodes(VALUE str, const char *s, long len, int type, int tail_lf)
|
|||
}
|
||||
if (tail_lf) buff[i++] = '\n';
|
||||
rb_str_buf_cat(str, buff, i);
|
||||
if ((size_t)i > sizeof(buff)) rb_bug("encodes() buffer overrun");
|
||||
}
|
||||
|
||||
static const char hex_table[] = "0123456789ABCDEF";
|
||||
|
|
|
|||
|
|
@ -550,6 +550,14 @@ EXPECTED
|
|||
assert_equal(["\0"], "AA\n".unpack("m"))
|
||||
assert_equal(["\0"], "AA=\n".unpack("m"))
|
||||
assert_equal(["\0\0"], "AAA\n".unpack("m"))
|
||||
|
||||
bug10019 = '[ruby-core:63604] [Bug #10019]'
|
||||
size = ((4096-4)/4*3+1)
|
||||
assert_separately(%W[- #{size} #{bug10019}], <<-'end;')
|
||||
size = ARGV.shift.to_i
|
||||
bug = ARGV.shift
|
||||
assert_equal(size, ["a"*size].pack("m#{size+2}").unpack("m")[0].size, bug)
|
||||
end;
|
||||
end
|
||||
|
||||
def test_pack_unpack_m0
|
||||
|
|
|
|||
|
|
@ -1,6 +1,6 @@
|
|||
#define RUBY_VERSION "2.1.2"
|
||||
#define RUBY_RELEASE_DATE "2014-07-13"
|
||||
#define RUBY_PATCHLEVEL 170
|
||||
#define RUBY_PATCHLEVEL 171
|
||||
|
||||
#define RUBY_RELEASE_YEAR 2014
|
||||
#define RUBY_RELEASE_MONTH 7
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue