[ruby-core:126871] [Ruby Bug#22387] str_shared_replace incorrectly recalculates termlen
Issue #22387 has been reported by rwstauner (Randy Stauner). ---------------------------------------- Bug #22387: str_shared_replace incorrectly recalculates termlen https://bugs.ruby-lang.org/issues/22387 * Author: rwstauner (Randy Stauner) * Status: Open * Backport: 3.3: UNKNOWN, 3.4: UNKNOWN, 4.0: REQUIRED ---------------------------------------- This ruby snippet crashes under ASan ```ruby s = ("\u{30AF}" * 7).encode("UTF-16LE").b s.force_encoding("UTF-16LE") s.encode!("UTF-8") # 21 bytes in a 22-byte malloc, capa now claims 22 s << "x" # fits, per capa, then NUL terminator written at [22] ``` str_shared_replace uses rb_enc_associate which recalculates termlen based on the old str even though the termlen of the new str was already used for the copy. We can just switch that to rb_enc_raw_set to fix. -- https://bugs.ruby-lang.org/
Issue #22387 has been updated by rwstauner (Randy Stauner). PR for master: https://github.com/ruby/ruby/pull/19103 ---------------------------------------- Bug #22387: str_shared_replace incorrectly recalculates termlen https://bugs.ruby-lang.org/issues/22387#change-119240 * Author: rwstauner (Randy Stauner) * Status: Open * Backport: 3.3: UNKNOWN, 3.4: UNKNOWN, 4.0: REQUIRED ---------------------------------------- This ruby snippet crashes under ASan ```ruby s = ("\u{30AF}" * 7).encode("UTF-16LE").b s.force_encoding("UTF-16LE") s.encode!("UTF-8") # 21 bytes in a 22-byte malloc, capa now claims 22 s << "x" # fits, per capa, then NUL terminator written at [22] ``` str_shared_replace uses rb_enc_associate which recalculates termlen based on the old str even though the termlen of the new str was already used for the copy. We can just switch that to rb_enc_raw_set to fix. -- https://bugs.ruby-lang.org/
Issue #22387 has been updated by rwstauner (Randy Stauner). bakport for 4.0: https://github.com/ruby/ruby/pull/19104 ---------------------------------------- Bug #22387: str_shared_replace incorrectly recalculates termlen https://bugs.ruby-lang.org/issues/22387#change-119241 * Author: rwstauner (Randy Stauner) * Status: Open * Backport: 3.3: UNKNOWN, 3.4: UNKNOWN, 4.0: REQUIRED ---------------------------------------- This ruby snippet crashes under ASan ```ruby s = ("\u{30AF}" * 7).encode("UTF-16LE").b s.force_encoding("UTF-16LE") s.encode!("UTF-8") # 21 bytes in a 22-byte malloc, capa now claims 22 s << "x" # fits, per capa, then NUL terminator written at [22] ``` str_shared_replace uses rb_enc_associate which recalculates termlen based on the old str even though the termlen of the new str was already used for the copy. We can just switch that to rb_enc_raw_set to fix. -- https://bugs.ruby-lang.org/
Issue #22387 has been updated by rwstauner (Randy Stauner). Backport changed from 3.3: UNKNOWN, 3.4: UNKNOWN, 4.0: REQUIRED to 3.3: UNKNOWN, 3.4: REQUIRED, 4.0: REQUIRED Backport PR for 3.4: https://github.com/ruby/ruby/pull/19105 ---------------------------------------- Bug #22387: str_shared_replace incorrectly recalculates termlen https://bugs.ruby-lang.org/issues/22387#change-119242 * Author: rwstauner (Randy Stauner) * Status: Open * Backport: 3.3: UNKNOWN, 3.4: REQUIRED, 4.0: REQUIRED ---------------------------------------- This ruby snippet crashes under ASan ```ruby s = ("\u{30AF}" * 7).encode("UTF-16LE").b s.force_encoding("UTF-16LE") s.encode!("UTF-8") # 21 bytes in a 22-byte malloc, capa now claims 22 s << "x" # fits, per capa, then NUL terminator written at [22] ``` str_shared_replace uses rb_enc_associate which recalculates termlen based on the old str even though the termlen of the new str was already used for the copy. We can just switch that to rb_enc_raw_set to fix. -- https://bugs.ruby-lang.org/
participants (1)
-
rwstauner (Randy Stauner)