From: Igal Koshevoy Date: 2008-06-24T17:29:48+09:00 Subject: Re: Ruby 1.9.0/1.8.7/1.8.6/1.8.5 new releases (Security Fix) We may have a winner! Can someone with a good understanding of C please audit the patch below? It seems to make 1.8.6p230 work correctly. It reverts Matz's "should copy cref as well" patch, and I'm not clear on what that was intended to do. Robert Thau wrote: > FWIW, I managed to get 1.8.6p230 all the way through a Rails 2.0 > app test suite without segfaults or glibc "corrupted memory" > complaints with the patch here: > > http://dev.smartleaf.com/misc/p230_fixit_patch.txt > > This reverts changeset 17222 from the ruby_1_8_6 branch of the > main svn repository, which doesn't *look* security-related, at > least at first blush (though it may be a failed backport from > another line of development). I ran this against the Rails 2.0 and RSpec 1.1.4 test suites, no seg faults, no glibc errs, and the same set of tests succeeded/passed between this patched version and the stock p111. It ran fine against automateit 0.80607 and the various Rails apps I tried. This is good. > As always, your milage may vary --- but I'm hoping this helps > someone with more detailed knowledge of MRI innards figure out > what's going on. Same here. Thanks much for posting this! Does anyone know how to contact the smartleaf folks and get them into this discussion? -igal -- Posted via http://www.ruby-forum.com/.