[#78633] ruby/spec needs help from CRuby committers — Benoit Daloze <eregontp@...>

Currently, ruby/spec is maintained mostly by individuals and enjoys the

13 messages 2016/12/13

[ruby-core:78505] [Ruby trunk Bug#13002] Hash calculations no longer using universal hashing

From: nobu@...
Date: 2016-12-06 07:20:15 UTC
List: ruby-core #78505
Issue #13002 has been updated by Nobuyoshi Nakada.


Martin D端rst wrote:
> Nobu - One thing I don't understand is why there wasn't any test failure on CI because there is a test that checks for bug #9318.

`strong_p` argument was used only for `String`s, but the test covered only special constants, as its name.
I added tests.

----------------------------------------
Bug #13002: Hash calculations no longer using universal hashing
https://bugs.ruby-lang.org/issues/13002#change-61887

* Author: Martin D端rst
* Status: Closed
* Priority: Normal
* Assignee: Yui NARUSE
* ruby -v: ruby 2.4.0dev (2016-12-02 trunk 56965) [x86_64-cygwin]
* Backport: 2.1: DONTNEED, 2.2: DONTNEED, 2.3: DONTNEED
----------------------------------------
When preparing for my lecture on hash tables last week, I found that Ruby trunk doesn't do universal hashing anymore. See http://events.ccc.de/congress/2011/Fahrplan/attachments/2007_28C3_Effective_DoS_on_web_application_platforms.pdf for background.

I contacted security@ruby-lang.org, but was told by Shugo that because trunk is not a published version, we can talk about it publicly.

Shugo also said that the change was introduced in r56650.

Following is some output from two different versions of Ruby that show the problem:

On Ruby 2.2.3, different hash value for the same number every time Ruby is restarted:

C:\Users\duerst>ruby -v
ruby 2.2.3p173 (2015-08-18 revision 51636) [i386-mingw32]

C:\Users\duerst>ruby -e 'puts 12345678.hash'
611647260

C:\Users\duerst>ruby -e 'puts 12345678.hash'
-844752827

C:\Users\duerst>ruby -e 'puts 12345678.hash'
387106497

On Ruby trunk, always the same value:

duerst@Arnisee /cygdrive/c/Data/ruby
$ ruby -v
ruby 2.4.0dev (2016-12-02 trunk 56965) [x86_64-cygwin]

duerst@Arnisee /cygdrive/c/Data/ruby
$ ruby -e 'puts 12345678.hash'
1846311797112760547

duerst@Arnisee /cygdrive/c/Data/ruby
$ ruby -e 'puts 12345678.hash'
1846311797112760547

duerst@Arnisee /cygdrive/c/Data/ruby
$ ruby -e 'puts 12345678.hash'
1846311797112760547


---Files--------------------------------
switching_hash_removal.patch (9.21 KB)


-- 
https://bugs.ruby-lang.org/

Unsubscribe: <mailto:ruby-core-request@ruby-lang.org?subject=unsubscribe>
<http://lists.ruby-lang.org/cgi-bin/mailman/options/ruby-core>

In This Thread

Prev Next