[ruby-core:105681] [Ruby master Bug#18255] ioctl zeroes the last buffer byte
From:
"nobu (Nobuyoshi Nakada)" <noreply@...>
Date:
2021-10-19 13:58:09 UTC
List:
ruby-core #105681
Issue #18255 has been updated by nobu (Nobuyoshi Nakada).
Backport changed from 2.6: UNKNOWN, 2.7: UNKNOWN, 3.0: UNKNOWN to 2.6: REQUIRED, 2.7: REQUIRED, 3.0: REQUIRED
Status changed from Feedback to Open
Found the bug.
Does this patch fix it?
```diff
diff --git a/io.c b/io.c
index 50c9fea62c9..052155205d6 100644
--- a/io.c
+++ b/io.c
@@ -10143,8 +10143,8 @@ setup_narg(ioctl_req_t cmd, VALUE *argp, int io_p)
/* expand for data + sentinel. */
if (slen < len+1) {
rb_str_resize(arg, len+1);
- MEMZERO(RSTRING_PTR(arg)+slen, char, len-slen);
- slen = len+1;
+ RSTRING_GETMEM(arg, ptr, slen);
+ MEMZERO(ptr+slen, char, len-slen);
}
/* a little sanity check here */
ptr = RSTRING_PTR(arg);
```
----------------------------------------
Bug #18255: ioctl zeroes the last buffer byte
https://bugs.ruby-lang.org/issues/18255#change-94181
* Author: vihai (Daniele Orlandi)
* Status: Open
* Priority: Normal
* Backport: 2.6: REQUIRED, 2.7: REQUIRED, 3.0: REQUIRED
----------------------------------------
Hello,
I'm running ruby 2.7.4p191 on an armv7 linux and experimenting with GPIO_GET_LINEHANDLE_IOCTL ioctl.
The ioctl sanity check is triggered as if the buffer was too small however the size of the buffer passed to ioctl is correct.
```
io.rb:116:in `ioctl': return value overflowed string (ArgumentError)
```
If I append at least one byte to the buffer the ioctl does not raise an exception.
It seems that the last byte of the buffer is zeroed:
```
puts "SIZE=#{req.bytesize}"
req = req + "XXXXXXXXXX".b
puts req.unpack("H*")
fd.ioctl(GPIO_GET_LINEHANDLE_IOCTL, req)
puts req.unpack("H*")
```
```
SIZE=364
[...]0000000000000058585858585858585858
[...]0000000600000058585858585858585800
```
I checked with a C program and the ioctl does not actually touch the buffer beyond the expected 364 bytes.
The ioctl number does encode 364 as size:
```
#include <stdio.h>
#include <linux/gpio.h>
void main()
{
printf("SIZE=%d", _IOC_SIZE(GPIO_GET_LINEHANDLE_IOCTL));
}
```
```
SIZE=364
```
--
https://bugs.ruby-lang.org/
Unsubscribe: <mailto:ruby-core-request@ruby-lang.org?subject=unsubscribe>
<http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-core>