[#1884] multiple exceptions for assert_raises — nobu.nokada@...

Hi,

14 messages 2003/12/04

[#1932] --enable-pthread broken? — Nathaniel Talbott <nathaniel@...>

[ruby-talk: 87759] and the surrounding thread seem to indicate that

29 messages 2003/12/11
[#1933] Re: --enable-pthread broken? — matz@... (Yukihiro Matsumoto) 2003/12/11

Hi,

[#1934] Re: --enable-pthread broken? — Nathaniel Talbott <nathaniel@...> 2003/12/11

On Dec 11, 2003, at 11:49, Yukihiro Matsumoto wrote:

[#1935] Re: --enable-pthread broken? — ts <decoux@...> 2003/12/11

>>>>> "N" == Nathaniel Talbott <nathaniel@talbott.ws> writes:

[#1937] Re: --enable-pthread broken? — nobu.nokada@... 2003/12/11

Hi,

[#1938] Re: --enable-pthread broken? — Nathaniel Talbott <nathaniel@...> 2003/12/12

On Dec 11, 2003, at 16:10, nobu.nokada@softhome.net wrote:

[#1939] Re: --enable-pthread broken? — matz@... (Yukihiro Matsumoto) 2003/12/12

Hi,

[#1941] Re: --enable-pthread broken? — matz@... (Yukihiro Matsumoto) 2003/12/12

Hi,

[#1943] Re: --enable-pthread broken? — Nathaniel Talbott <nathaniel@...> 2003/12/12

On Dec 11, 2003, at 20:48, Yukihiro Matsumoto wrote:

[#1953] Re: --enable-pthread broken? — matz@... (Yukihiro Matsumoto) 2003/12/13

Hi,

[#1959] Re: --enable-pthread broken? — ts <decoux@...> 2003/12/14

>>>>> "Y" == Yukihiro Matsumoto <matz@ruby-lang.org> writes:

[#1961] Re: --enable-pthread broken? — matz@... (Yukihiro Matsumoto) 2003/12/15

Hi,

[#1962] Re: --enable-pthread broken? — ts <decoux@...> 2003/12/15

>>>>> "Y" == Yukihiro Matsumoto <matz@ruby-lang.org> writes:

[#1936] Can't define +@ for Symbol (plus ruby install problem) — "T. Onoma" <transami@...>

I wanted to see if the +@ problem was fixed in 1.8.1 preview 3 but when I do

11 messages 2003/12/11

[#1973] Where to install documentation — Dave Thomas <dave@...>

Folks:

48 messages 2003/12/15
[#1982] Re: Where to install documentation — Eric Hodel <drbrain@...7.net> 2003/12/15

Dave Thomas (dave@pragprog.com) wrote:

[#1984] Re: Where to install documentation — Dave Thomas <dave@...> 2003/12/15

[#1991] Re: Where to install documentation — "Gavin Sinclair" <gsinclair@...> 2003/12/16

>

[#1992] Re: Where to install documentation — Dave Thomas <dave@...> 2003/12/16

[#2000] Re: Where to install documentation — Minero Aoki <aamine@...> 2003/12/16

Hi,

[#2002] Re: Where to install documentation — Dave Thomas <dave@...> 2003/12/16

[#2037] --enable-pthread still segfaults... — Nathaniel Talbott <nathaniel@...>

I've finally been able to test my application under load using the

25 messages 2003/12/23
[#2038] Re: --enable-pthread still segfaults... — matz@... (Yukihiro Matsumoto) 2003/12/23

Hi,

[#2039] Re: --enable-pthread still segfaults... — Nathaniel Talbott <nathaniel@...> 2003/12/23

On Dec 23, 2003, at 14:17, Yukihiro Matsumoto wrote:

[#2040] Re: --enable-pthread still segfaults... — matz@... (Yukihiro Matsumoto) 2003/12/23

Hi,

[#2041] Re: --enable-pthread still segfaults... — Nathaniel Talbott <nathaniel@...> 2003/12/23

On Dec 23, 2003, at 14:34, Yukihiro Matsumoto wrote:

[#2042] Re: --enable-pthread still segfaults... — matz@... (Yukihiro Matsumoto) 2003/12/23

Hi,

[#2043] Re: --enable-pthread still segfaults... — Nathaniel Talbott <nathaniel@...> 2003/12/23

On Dec 23, 2003, at 14:44, Yukihiro Matsumoto wrote:

[#2045] Re: --enable-pthread still segfaults... — matz@... (Yukihiro Matsumoto) 2003/12/23

Hi,

[#2046] Re: --enable-pthread still segfaults... — Nathaniel Talbott <nathaniel@...> 2003/12/23

> I'm afraid you're using old configure file. Can you wipe off old

[#2049] Re: --enable-pthread still segfaults... — Nathaniel Talbott <nathaniel@...> 2003/12/23

On Dec 23, 2003, at 15:18, Nathaniel Talbott wrote:

[#2050] Re: --enable-pthread still segfaults... — matz@... (Yukihiro Matsumoto) 2003/12/23

In message "Re: --enable-pthread still segfaults..."

[#2122] Bad interaction between timeout.rb and --enable-pthread — Nathaniel Talbott <nathaniel@...>

Here's a testcase that shows the problem:

13 messages 2003/12/31
[#2123] sleep is broken with --enable-pthread [Was: Bad interaction between timeout.rb and --enable-pthread] — Nathaniel Talbott <nathaniel@...> 2003/12/31

I should have reduced it more before posting...

[BUG] syck segfaults when used in rdoc

From: Alexander Bokovoy <a.bokovoy@...>
Date: 2003-12-28 14:36:10 UTC
List: ruby-core #2102
Greetings!

There is definitely a bug in Syck's emitter code in current 1.8.1 branch
(and in release too) which is easily reproduceable on GNU/Linux systems on
IA-32 when making a meta-information for 'ri' using 'rdoc' against Ruby
sources:

$ cd ~/cvs/ruby-1.8
$ gdb ruby
(gdb) run /usr/bin/rdoc --ri
 ... lots of output ...
Generating RI...

Program received signal SIGSEGV, Segmentation fault.
0x002d6d5c in memcpy () from /lib/libc.so.6
(gdb) bt full
#0  0x002d6d5c in memcpy () from /lib/libc.so.6
No symbol table info available.
#1  0x11d6e260 in ?? ()
No symbol table info available.
#2  0x01d8f12b in syck_emitter_simple (e=0x11d6e260, 
    str=0x12110d58 "\"[     [\\\"KeywordSearchRequest\\\",
    \\\"keywordSearchRequest\\\", [       [\\\"in\\\",
    \\\"KeywordSearchRequest\\\",        [::SOAP::SOAPStruct,
    \\\"http://soap.amazon.com\\\", \\\"KeywordRequest\\\"]],
    [\\\"retval\\\", "..., 
    len=9362) at emitter.c:317
No locals.
#3  0x01d9669f in syck_emitter_simple_write (self=1091645092,
	str=1091599272) at rubyext.c:1301
        emitter = (SyckEmitter *) 0x11d6e260
#4  0x0016fa6e in call_cfunc (func=0x1d96652
	<syck_emitter_simple_write>, recv=1091645092, len=1,
	argc=1, argv=0xbffeaac8)
    at eval.c:4938
No locals.

More stack frames are available but they are in Ruby code itself and look
fine.

When looking at (SyckEmitter*)e (0x11d6e260) we can see that bufpos is way
out of buffer, as well as marker itself:

(gdb) print *((struct _syck_emitter *)0x11d6e260)
$39 = {
  headless = 0, 
  seq_map = 0, 
  use_header = 0, 
  use_version = 0, 
  sort_keys = 0, 
  anchor_format = 0x0, 
  explicit_typing = 0, 
  best_width = 80, 
  block_style = block_arbitrary, 
  stage = doc_processing, 
  level = 3, 
  indent = 2, 
  ignore_id = 4, 
  markers = 0x11d6e310, 
  anchors = 0x0, 
  bufsize = 4096, 
  buffer = 0x12437588 "\"[
	  [\\\"KeywordSearchRequest\\\",
	  \\\"keywordSearchRequest\\\", [
          [\\\"in\\\",
	  \\\"KeywordSearchRequest\\\",
	  [::SOAP::SOAPStruct,
	  \\\"http://soap.amazon.com\\\",
	  \\\"KeywordRequest\\\"]],
	  [\\\"retval\\\", "..., 
  marker = 0x12438a1a
          "ap.amazon.com\\\",
          \\\"http://soap.amazon.com\\\"],
          [\\\"DirectorSearchRequest\\\",
          \\\"directorSearchRequest\\\", [
          [\\\"in\\\",
          \\\"DirectorSearchRequest\\\",
          [::SOAP::SOAPStruct,
          \\\"http://soap.amazon.co"..., 
  bufpos = 4423, 
  handler = 0x1d96396	<rb_syck_output_handler>, 
  bonus = 0x41112f30
}

GDB's output is formatted slightly to fit into the mail.

Syck's emitter.c code looks dangerous for me in those places --
syck_emitter_write() has no protection about 'rest' variable being
negative (which happened in the case due to buffer overrun) and
syck_emitter_flush()/syck_emitter_start_obj() have manipulations with
e->marker that can easily lead to buffer overrun.

Unfortunately, I have little time to explore those codepaths more before
February. I saw another bug report yesterday in ruby-talk@ for the same
bug.
-- 
/ Alexander Bokovoy
Samba Team                      http://www.samba.org/
ALT Linux Team                  http://www.altlinux.org/
Midgard Project Ry              http://www.midgard-project.org/

In This Thread

Prev Next