チケット #199 が報告されました。 (by Anonymous)

----------------------------------------
Bug #199: Possible patches for critical segfaults and vulnerabilities available for review in ruby-talk
http://redmine.ruby-lang.org/issues/show/199

起票者: Anonymous
ステータス: Open
優先度: Immediate
担当者: 
カテゴリ: 
Target version: 


All currently available official versions of MRI Ruby are either vulnerable, failing with segmentation faults, or change the API in ways that make it impossible to run critical Ruby libraries such as Rails 2.0 and RSpec.

There are currently two unofficial patches submitted by ruby-talk members that seem to fix these problems:
* http://www.ruby-forum.com/topic/157034#693292
* http://www.ruby-forum.com/topic/157034#693303

One is a backport of fixes to 1.8.6p111 by Stanislav Sedov and Hongli Lai. The other is a fix to 1.8.6p230 by Smartleaf which reverts a recent patch that's causing segmentation faults. I've attached these files to this ticket.

I've personally confirmed that both of these work as well as the stock 1.8.6p111 in running the Rails 2.0, RSpec 1.1.4, and RubySpec test suites. However, I do not understand the C patches well enough to be able to help with them myself.

Can one of the Ruby maintainers please review these patches and join in the discussion at ruby-talk or the online thread at http://www.ruby-forum.com/topic/157034 ?

Thank you!

-igal


----------------------------------------
You have received this notification because you have either subscribed to it, or are involved in it.
To change your notification preferences, please click here: http://redmine.ruby-lang.org/my/account