Browse Source

Fixed bug of long strings in binary chunks

When "undumping" a long string, the function 'LoadVector' can call the
reader function, which can run the garbage collector, which can collect
the string being read. So, the string must be anchored during the call
to 'LoadVector'. (This commit also fixes the identation in 'l_alloc'.)
v5.3 v5.3.6
Roberto Ierusalimschy 4 years ago
parent
commit
75ea9ccbea
  1. 8
      lauxlib.c
  2. 10
      lundump.c

8
lauxlib.c

@ -1013,10 +1013,10 @@ static void *l_alloc (void *ud, void *ptr, size_t osize, size_t nsize) {
} }
else { /* cannot fail when shrinking a block */ else { /* cannot fail when shrinking a block */
void *newptr = realloc(ptr, nsize); void *newptr = realloc(ptr, nsize);
if (newptr == NULL && ptr != NULL && nsize <= osize) if (newptr == NULL && ptr != NULL && nsize <= osize)
return ptr; /* keep the original block */ return ptr; /* keep the original block */
else /* no fail or not shrinking */ else /* no fail or not shrinking */
return newptr; /* use the new block */ return newptr; /* use the new block */
} }
} }

10
lundump.c

@ -86,6 +86,7 @@ static lua_Integer LoadInteger (LoadState *S) {
static TString *LoadString (LoadState *S, Proto *p) { static TString *LoadString (LoadState *S, Proto *p) {
lua_State *L = S->L;
size_t size = LoadByte(S); size_t size = LoadByte(S);
TString *ts; TString *ts;
if (size == 0xFF) if (size == 0xFF)
@ -95,13 +96,16 @@ static TString *LoadString (LoadState *S, Proto *p) {
else if (--size <= LUAI_MAXSHORTLEN) { /* short string? */ else if (--size <= LUAI_MAXSHORTLEN) { /* short string? */
char buff[LUAI_MAXSHORTLEN]; char buff[LUAI_MAXSHORTLEN];
LoadVector(S, buff, size); LoadVector(S, buff, size);
ts = luaS_newlstr(S->L, buff, size); ts = luaS_newlstr(L, buff, size);
} }
else { /* long string */ else { /* long string */
ts = luaS_createlngstrobj(S->L, size); ts = luaS_createlngstrobj(L, size);
setsvalue2s(L, L->top, ts); /* anchor it ('loadVector' can GC) */
luaD_inctop(L);
LoadVector(S, getstr(ts), size); /* load directly in final place */ LoadVector(S, getstr(ts), size); /* load directly in final place */
L->top--; /* pop string */
} }
luaC_objbarrier(S->L, p, ts); luaC_objbarrier(L, p, ts);
return ts; return ts;
} }

Loading…
Cancel
Save