From: "peterzhu2118 (Peter Zhu) via ruby-core" Date: 2026-10-07T14:33:24+00:00 Subject: [ruby-core:126983] [Ruby Bug#22410] `IO#external_encoding` / `IO#internal_encoding` segfault on an uninitialized IO Issue #22410 has been updated by peterzhu2118 (Peter Zhu). Backport changed from 3.3: UNKNOWN, 3.4: UNKNOWN, 4.0: UNKNOWN to 3.3: WONTFIX, 3.4: DONTNEED, 4.0: DONTNEED Thank you for the bug report. I have a fix here: https://github.com/ruby/ruby/pull/19252 ---------------------------------------- Bug #22410: `IO#external_encoding` / `IO#internal_encoding` segfault on an uninitialized IO https://bugs.ruby-lang.org/issues/22410#change-119378 * Author: 0599jiangyc@gmail.com (Yuancheng Jiang) * Status: Open * Backport: 3.3: WONTFIX, 3.4: DONTNEED, 4.0: DONTNEED ---------------------------------------- The following code: ```ruby IO.allocate.external_encoding ``` (also `IO.allocate.internal_encoding`, or any `IO`/`File` subclass whose `initialize` does not call `super`, e.g. `class A < IO; def initialize(*) = nil; end; A.new.external_encoding`; `Marshal.dump` of such an object reaches the same code via `encoding_name`.) Resulted in this output: ``` io_min.rb:1: [BUG] Segmentation fault at 0x0000000000000068 ruby 4.1.0dev (2026-10-07) +PRISM [x86_64-linux] -- Ruby level backtrace information ---------------------------------------- io_min.rb:1:in '
' io_min.rb:1:in 'external_encoding' -- C level backtrace information ------------------------------------------- (rb_bug_for_fatal_signal+0x3b8) error.c:1183 (sigsegv+0x97) signal.c:982 libc.so.6 (rb_io_external_encoding+0x8d) io.c:13775 (vm_call_cfunc_with_frame_+0x27b) ../vm_insnhelper.c:3906 (vm_call_method_each_type+0x24a) ../vm_insnhelper.c:4898 (vm_call_method+0x39f) (vm_exec_core+0x113bc) ../vm_insnhelper.c:6285 (rb_vm_exec+0x242) vm.c:2909 (rb_ec_exec_node+0x56) eval.c:300 (ruby_run_node) eval.c:338 ``` `rb_io_external_encoding` and `rb_io_internal_encoding` read `RFILE(rb_io_taint_check(io))->fptr` and dereference it without `rb_io_check_initialized`/`GetOpenFile`, so `fptr == NULL` crashes. Other IO methods raise `IOError (uninitialized stream)` here. Also reproduces on a plain release build (Ubuntu's ruby 3.2.3). To reproduce: ``` ruby ./min.rb ``` Commit: ``` 3296d5c99ce005e4698fb27a405e01d766ad2647 (2026-09-15); also reproduced on master 9ce0df671980d669cbab8afc48124c7453897533 (2026-10-07) ``` Build configuration: ``` ../configure --disable-install-doc CC=clang-18 cflags="-fsanitize=address -fno-omit-frame-pointer -DUSE_MN_THREADS=0" cppflags="-DRUBY_DEBUG=1" optflags="-O1" debugflags="-g" ``` Operating System: ``` Ubuntu 24.04.4 LTS (x86_64), clang 18.1.3 ``` *This bug was found by [fusion-fuzz](https://github.com/fusion-fuzz/fusion-fuzz)* -- https://bugs.ruby-lang.org/ ______________________________________________ ruby-core mailing list -- ruby-core@ml.ruby-lang.org To unsubscribe send an email to ruby-core-leave@ml.ruby-lang.org ruby-core info -- https://ml.ruby-lang.org/mailman3/lists/ruby-core.ml.ruby-lang.org/