[#119000] [Ruby master Bug#20710] Reducing Hash allocation introduces large performance degradation (probably related to VWA) — "pocke (Masataka Kuwabara) via ruby-core" <ruby-core@...>

Issue #20710 has been reported by pocke (Masataka Kuwabara).

6 messages 2024/09/02

[#119033] [Ruby master Bug#20713] Ruby 3.3.5 triggers a deprecation warning with `require "json"` — "Bo98 (Bo Anderson) via ruby-core" <ruby-core@...>

Issue #20713 has been reported by Bo98 (Bo Anderson).

7 messages 2024/09/04

[#119041] [Ruby master Bug#20714] Handle optional dependencies in `bundled_gems.rb` — "Earlopain (A S) via ruby-core" <ruby-core@...>

Issue #20714 has been reported by Earlopain (A S).

31 messages 2024/09/04

[#119074] [Ruby master Bug#20716] Different instance_method behavior in Ruby 2.7 and Ruby 3.x — "natton (Tien Truong) via ruby-core" <ruby-core@...>

Issue #20716 has been reported by natton (Tien Truong).

13 messages 2024/09/06

[#119145] [Ruby master Misc#20728] Propose Eileen Uchitelle as a core committer — "kddnewton (Kevin Newton) via ruby-core" <ruby-core@...>

Issue #20728 has been reported by kddnewton (Kevin Newton).

14 messages 2024/09/12

[#119168] [Ruby master Feature#20738] Removing a specific entry from a hash literal — "ursm (Keita Urashima) via ruby-core" <ruby-core@...>

Issue #20738 has been reported by ursm (Keita Urashima).

16 messages 2024/09/13

[#119199] [Ruby master Bug#20742] Trying to assign to a variable in statement modifier should emit a warning — "esad (Esad Hajdarevic) via ruby-core" <ruby-core@...>

SXNzdWUgIzIwNzQyIGhhcyBiZWVuIHJlcG9ydGVkIGJ5IGVzYWQgKEVzYWQgSGFqZGFyZXZpYyku

7 messages 2024/09/15

[#119208] [Ruby master Bug#20745] IO::Buffer#copy triggers UB when src/dest buffers overlap — "hanazuki (Kasumi Hanazuki) via ruby-core" <ruby-core@...>

Issue #20745 has been reported by hanazuki (Kasumi Hanazuki).

8 messages 2024/09/16

[#119239] [Ruby master Feature#20750] Expose ruby_thread_has_gvl_p in ruby/thread.h — "kbrock (Keenan Brock) via ruby-core" <ruby-core@...>

Issue #20750 has been reported by kbrock (Keenan Brock).

8 messages 2024/09/17

[#119248] [Ruby master Bug#20752] IO::Buffer#slice fails to copy readonly flag, allowing writes into frozen String — "hanazuki (Kasumi Hanazuki) via ruby-core" <ruby-core@...>

Issue #20752 has been reported by hanazuki (Kasumi Hanazuki).

7 messages 2024/09/18

[#119301] [Ruby master Bug#20761] [DOC] `RubyVM::AbstractSyntaxTree.of` examples raise because parser is prism by default — "Earlopain (A S) via ruby-core" <ruby-core@...>

Issue #20761 has been reported by Earlopain (A S).

11 messages 2024/09/26

[#119335] [Ruby master Bug#20770] A *new* pipe operator proposal — "AlexandreMagro (Alexandre Magro) via ruby-core" <ruby-core@...>

Issue #20770 has been reported by AlexandreMagro (Alexandre Magro).

56 messages 2024/09/29

[ruby-core:119011] [Ruby master Bug#20691] Use-after-free in WeakKeyMap#clear

From: "k0kubun (Takashi Kokubun) via ruby-core" <ruby-core@...>
Date: 2024-09-02 10:11:15 UTC
List: ruby-core #119011
Issue #20691 has been updated by k0kubun (Takashi Kokubun).

Backport changed from 3.1: DONTNEED, 3.2: DONTNEED, 3.3: REQUIRED to 3.1: DONTNEED, 3.2: DONTNEED, 3.3: DONE

ruby_3_3 commit:ac8d50e52ebc2d2684914e56548a64a65830c16a.

----------------------------------------
Bug #20691: Use-after-free in WeakKeyMap#clear
https://bugs.ruby-lang.org/issues/20691#change-109586

* Author: peterzhu2118 (Peter Zhu)
* Status: Closed
* Backport: 3.1: DONTNEED, 3.2: DONTNEED, 3.3: DONE
----------------------------------------
GitHub PR: https://github.com/ruby/ruby/pull/11437

If the WeakKeyMap has been marked but sweeping hasn't started yet and we cann WeakKeyMap#clear, then there could be a use-after-free because we do not call rb_gc_remove_weak to remove the key from the GC.

For example, the following code triggers use-after-free errors in Valgrind:

```ruby
map = ObjectSpace::WeakKeyMap.new

1_000.times do
  1_000.times do
    map[Object.new] = nil
  end

  map.clear
end
```

Output from Valgrind:

```
==61230== Invalid read of size 8
==61230==    at 0x25CAF8: gc_update_weak_references (default.c:5593)
==61230==    by 0x25CAF8: gc_marks_finish (default.c:5641)
==61230==    by 0x26031C: gc_marks_continue (default.c:5987)
==61230==    by 0x26031C: gc_continue (default.c:2255)
==61230==    by 0x2605FC: newobj_cache_miss (default.c:2589)
==61230==    by 0x26111F: newobj_alloc (default.c:2622)
==61230==    by 0x26111F: rb_gc_impl_new_obj (default.c:2701)
==61230==    by 0x26111F: newobj_of (gc.c:890)
==61230==    by 0x26111F: rb_wb_protected_newobj_of (gc.c:917)
==61230==    by 0x2DE218: rb_class_allocate_instance (object.c:131)
==61230==    by 0x2E32A8: class_call_alloc_func (object.c:2141)
==61230==    by 0x2E32A8: rb_class_alloc (object.c:2113)
==61230==    by 0x2E32A8: rb_class_new_instance_pass_kw (object.c:2172)
==61230==    by 0x4296BC: vm_call_cfunc_with_frame_ (vm_insnhelper.c:3788)
==61230==    by 0x44A9CD: vm_sendish (vm_insnhelper.c:5955)
==61230==    by 0x44A9CD: vm_exec_core (insns.def:898)
==61230==    by 0x43A0E4: rb_vm_exec (vm.c:2564)
==61230==    by 0x2341B4: rb_ec_exec_node (eval.c:281)
==61230==    by 0x236258: ruby_run_node (eval.c:319)
==61230==    by 0x15D665: rb_main (main.c:43)
==61230==    by 0x15D665: main (main.c:62)
==61230==  Address 0x2159cb00 is 0 bytes inside a block of size 8 free'd
==61230==    at 0x4849B2C: free (vg_replace_malloc.c:989)
==61230==    by 0x248EF1: rb_gc_impl_free (default.c:8512)
==61230==    by 0x248EF1: rb_gc_impl_free (default.c:8493)
==61230==    by 0x248EF1: ruby_sized_xfree.constprop.0 (gc.c:4178)
==61230==    by 0x4627EC: wkmap_free_table_i (weakmap.c:652)
==61230==    by 0x3A54AF: apply_functor (st.c:1633)
==61230==    by 0x3A54AF: st_general_foreach (st.c:1543)
==61230==    by 0x3A54AF: rb_st_foreach (st.c:1640)
==61230==    by 0x46203C: wkmap_clear (weakmap.c:973)
==61230==    by 0x4296BC: vm_call_cfunc_with_frame_ (vm_insnhelper.c:3788)
==61230==    by 0x44A9CD: vm_sendish (vm_insnhelper.c:5955)
==61230==    by 0x44A9CD: vm_exec_core (insns.def:898)
==61230==    by 0x43A0E4: rb_vm_exec (vm.c:2564)
==61230==    by 0x2341B4: rb_ec_exec_node (eval.c:281)
==61230==    by 0x236258: ruby_run_node (eval.c:319)
==61230==    by 0x15D665: rb_main (main.c:43)
==61230==    by 0x15D665: main (main.c:62)
==61230==  Block was alloc'd at
==61230==    at 0x484680F: malloc (vg_replace_malloc.c:446)
==61230==    by 0x25C68E: rb_gc_impl_malloc (default.c:8527)
==61230==    by 0x4622E9: wkmap_aset_replace (weakmap.c:817)
==61230==    by 0x3A4D02: rb_st_update (st.c:1487)
==61230==    by 0x4623E4: wkmap_aset (weakmap.c:854)
==61230==    by 0x4296BC: vm_call_cfunc_with_frame_ (vm_insnhelper.c:3788)
==61230==    by 0x44A9CD: vm_sendish (vm_insnhelper.c:5955)
==61230==    by 0x44A9CD: vm_exec_core (insns.def:898)
==61230==    by 0x43A0E4: rb_vm_exec (vm.c:2564)
==61230==    by 0x2341B4: rb_ec_exec_node (eval.c:281)
==61230==    by 0x236258: ruby_run_node (eval.c:319)
==61230==    by 0x15D665: rb_main (main.c:43)
==61230==    by 0x15D665: main (main.c:62)
==61230==
==61230== Invalid write of size 8
==61230==    at 0x25CB3B: gc_update_weak_references (default.c:5598)
==61230==    by 0x25CB3B: gc_marks_finish (default.c:5641)
==61230==    by 0x26031C: gc_marks_continue (default.c:5987)
==61230==    by 0x26031C: gc_continue (default.c:2255)
==61230==    by 0x2605FC: newobj_cache_miss (default.c:2589)
==61230==    by 0x26111F: newobj_alloc (default.c:2622)
==61230==    by 0x26111F: rb_gc_impl_new_obj (default.c:2701)
==61230==    by 0x26111F: newobj_of (gc.c:890)
==61230==    by 0x26111F: rb_wb_protected_newobj_of (gc.c:917)
==61230==    by 0x2DE218: rb_class_allocate_instance (object.c:131)
==61230==    by 0x2E32A8: class_call_alloc_func (object.c:2141)
==61230==    by 0x2E32A8: rb_class_alloc (object.c:2113)
==61230==    by 0x2E32A8: rb_class_new_instance_pass_kw (object.c:2172)
==61230==    by 0x4296BC: vm_call_cfunc_with_frame_ (vm_insnhelper.c:3788)
==61230==    by 0x44A9CD: vm_sendish (vm_insnhelper.c:5955)
==61230==    by 0x44A9CD: vm_exec_core (insns.def:898)
==61230==    by 0x43A0E4: rb_vm_exec (vm.c:2564)
==61230==    by 0x2341B4: rb_ec_exec_node (eval.c:281)
==61230==    by 0x236258: ruby_run_node (eval.c:319)
==61230==    by 0x15D665: rb_main (main.c:43)
==61230==    by 0x15D665: main (main.c:62)
==61230==  Address 0x2159cb00 is 0 bytes inside a block of size 8 free'd
==61230==    at 0x4849B2C: free (vg_replace_malloc.c:989)
==61230==    by 0x248EF1: rb_gc_impl_free (default.c:8512)
==61230==    by 0x248EF1: rb_gc_impl_free (default.c:8493)
==61230==    by 0x248EF1: ruby_sized_xfree.constprop.0 (gc.c:4178)
==61230==    by 0x4627EC: wkmap_free_table_i (weakmap.c:652)
==61230==    by 0x3A54AF: apply_functor (st.c:1633)
==61230==    by 0x3A54AF: st_general_foreach (st.c:1543)
==61230==    by 0x3A54AF: rb_st_foreach (st.c:1640)
==61230==    by 0x46203C: wkmap_clear (weakmap.c:973)
==61230==    by 0x4296BC: vm_call_cfunc_with_frame_ (vm_insnhelper.c:3788)
==61230==    by 0x44A9CD: vm_sendish (vm_insnhelper.c:5955)
==61230==    by 0x44A9CD: vm_exec_core (insns.def:898)
==61230==    by 0x43A0E4: rb_vm_exec (vm.c:2564)
==61230==    by 0x2341B4: rb_ec_exec_node (eval.c:281)
==61230==    by 0x236258: ruby_run_node (eval.c:319)
==61230==    by 0x15D665: rb_main (main.c:43)
==61230==    by 0x15D665: main (main.c:62)
==61230==  Block was alloc'd at
==61230==    at 0x484680F: malloc (vg_replace_malloc.c:446)
==61230==    by 0x25C68E: rb_gc_impl_malloc (default.c:8527)
==61230==    by 0x4622E9: wkmap_aset_replace (weakmap.c:817)
==61230==    by 0x3A4D02: rb_st_update (st.c:1487)
==61230==    by 0x4623E4: wkmap_aset (weakmap.c:854)
==61230==    by 0x4296BC: vm_call_cfunc_with_frame_ (vm_insnhelper.c:3788)
==61230==    by 0x44A9CD: vm_sendish (vm_insnhelper.c:5955)
==61230==    by 0x44A9CD: vm_exec_core (insns.def:898)
==61230==    by 0x43A0E4: rb_vm_exec (vm.c:2564)
==61230==    by 0x2341B4: rb_ec_exec_node (eval.c:281)
==61230==    by 0x236258: ruby_run_node (eval.c:319)
==61230==    by 0x15D665: rb_main (main.c:43)
==61230==    by 0x15D665: main (main.c:62)
```



-- 
https://bugs.ruby-lang.org/
 ______________________________________________
 ruby-core mailing list -- ruby-core@ml.ruby-lang.org
 To unsubscribe send an email to ruby-core-leave@ml.ruby-lang.org
 ruby-core info -- https://ml.ruby-lang.org/mailman3/lists/ruby-core.ml.ruby-lang.org/


In This Thread

Prev Next