From: Robert Thau Date: 2008-06-24T23:29:15+09:00 Subject: Re: Ruby 1.9.0/1.8.7/1.8.6/1.8.5 new releases (Security Fix) Igal Koshevoy wrote: > > As far as I can tell, both of these patches provide a working version of > MRI Ruby. Stanislav and Hongli's p111 backport relies on them having > correctly cherry-picked the right fixes. Smartleaf's p230 fix relies on > the rest of that Ruby version to be correct, and I have some concerns > about other lurking bugs if they shipped a version with such an obvious > flaw. > > How do we choose between these? Well, if we want the Japanese team to be more rigorous in applying test suites in testing their stuff... we've got the test suites too. That said, coverage is probably less than perfect, and the silence is somewhat troublesome to me too. (BTW, in an earlier note, you asked for someone with C expertise to audit my p230_fixit_patch.txt. Well, it should be fairly easy to verify that it reverts class.c to an earlier --- and apparently less broken --- state; it's quite literally the output of "svn diff". Figuring out what went wrong with the change it reverts is more difficult. It requires not only knowledge of C, but also knowledge of the macros and data structures of pre-1.9 MRI. And while I'm pretty good with C, I think, I'm not nearly so good with MRI internals. I found the problem not by auditing the code, but by doing a simple bisection search of the ruby_1_8_6 branch of the main svn repository, looking for the first revision that blew up "rake test"). Robert Thau rst AT {alum,ai}.mit.edu -- Posted via http://www.ruby-forum.com/.