From: Igor Munkin via Tarantool-patches <tarantool-patches@dev.tarantool.org> To: Sergey Kaplun <skaplun@tarantool.org> Cc: tarantool-patches@dev.tarantool.org Subject: Re: [Tarantool-patches] [PATCH luajit v2] Fix frame traversal for __gc handler frames. Date: Tue, 23 Nov 2021 15:57:38 +0300 [thread overview] Message-ID: <YZzlQjVA3J667Ul6@tarantool.org> (raw) In-Reply-To: <20211119164157.18344-1-skaplun@tarantool.org> Sergey, Thanks for the fixes! LGTM, with a tiny nit. On 19.11.21, Sergey Kaplun wrote: > From: Mike Pall <mike> > > Reported by Changochen. > > (cherry picked from 53f82e6e2e858a0a62fd1a2ff47e9866693382e6) > > A cframe unwinding is missed for a C protected frame during a search for > an error function to handle a runtime error. It leads to undefined > behaviour or crash, when raising a runtime error on stack with the CP > frame before an error function handler (for example, an error in __gc > handler). > > This patch adds missing unwinding for CP frame. > > Sergey Kaplun: > * added the description and the test for the problem > --- > > LuaJIT issue: https://github.com/LuaJIT/LuaJIT/issues/601 > Branch: https://github.com/tarantool/luajit/tree/skaplun/gh-noticket-fix-gc-finderrfunc > Tarantool branch: https://github.com/tarantool/tarantool/tree/skaplun/gh-noticket-fix-gc-finderrfunc > > Changes in v2: > * Create CP and C stack manually in LuaC > > src/lj_err.c | 1 + > test/tarantool-tests/CMakeLists.txt | 1 + > .../lj-601-fix-gc-finderrfunc.test.lua | 35 ++++++++++++ > .../lj-601-fix-gc-finderrfunc/CMakeLists.txt | 1 + > .../lj-601-fix-gc-finderrfunc/mixcframe.c | 55 +++++++++++++++++++ > 5 files changed, 93 insertions(+) > create mode 100644 test/tarantool-tests/lj-601-fix-gc-finderrfunc.test.lua > create mode 100644 test/tarantool-tests/lj-601-fix-gc-finderrfunc/CMakeLists.txt > create mode 100644 test/tarantool-tests/lj-601-fix-gc-finderrfunc/mixcframe.c > <snipped> > diff --git a/test/tarantool-tests/lj-601-fix-gc-finderrfunc.test.lua b/test/tarantool-tests/lj-601-fix-gc-finderrfunc.test.lua > new file mode 100644 > index 00000000..d4c44489 > --- /dev/null > +++ b/test/tarantool-tests/lj-601-fix-gc-finderrfunc.test.lua > @@ -0,0 +1,35 @@ <snipped> > +local a = newproxy(true) > +getmetatable(a).__gc = function() > + -- Function to raise error via `lj_err_run()` inside __gc. > + error('raise error in __gc') > +end > +-- luacheck: no unused > +a = nil > + > +-- We need to get the following Lua stack format when raise an > +-- error: > +-- + L->stack > +-- | ... > +-- | CP -- any C protected frame. > +-- | ...[L/LP/V]... > +-- | C -- any C frame. > +-- | ...[L/LP/V]... > +-- | CP (with inherited errfunc) -- __gc frame. > +-- V > +-- Enter in the C to call CP func. Call `lua_gc()` inside. Minor: I'd adjust this comment the following way: | -- Enter in the C land to call a function in a protected C frame | -- (CP). Spoil host stack (and ergo cframe area) and later call | -- Lua C function, triggering full GC cycle in a non-protected | -- frame. As a result, error is raised in __gc metamethod above. Fixed, squashed, force-pushed to the branch. Diff is below: ================================================================================ diff --git a/test/tarantool-tests/lj-601-fix-gc-finderrfunc.test.lua b/test/tarantool-tests/lj-601-fix-gc-finderrfunc.test.lua index d4c44489..2122c7a0 100644 --- a/test/tarantool-tests/lj-601-fix-gc-finderrfunc.test.lua +++ b/test/tarantool-tests/lj-601-fix-gc-finderrfunc.test.lua @@ -29,7 +29,10 @@ a = nil -- | ...[L/LP/V]... -- | CP (with inherited errfunc) -- __gc frame. -- V --- Enter in the C to call CP func. Call `lua_gc()` inside. +-- Enter in the C land to call a function in a protected C frame +-- (CP). Spoil host stack (and ergo cframe area) and later call +-- Lua C function, triggering full GC cycle in a non-protected +-- frame. As a result, error is raised in __gc metamethod above. test:ok(mixcframe.test_handle_err(), 'error in __gc is successfully handled') os.exit(test:check() and 0 or 1) ================================================================================ > +test:ok(mixcframe.test_handle_err(), 'error in __gc is successfully handled') > + > +os.exit(test:check() and 0 or 1) <snipped> > -- > 2.31.0 > -- Best regards, IM
next prev parent reply other threads:[~2021-11-23 12:58 UTC|newest] Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top 2021-11-19 16:41 Sergey Kaplun via Tarantool-patches 2021-11-23 12:57 ` Igor Munkin via Tarantool-patches [this message] 2021-11-23 22:00 ` Igor Munkin via Tarantool-patches
Reply instructions: You may reply publicly to this message via plain-text email using any one of the following methods: * Save the following mbox file, import it into your mail client, and reply-to-all from there: mbox Avoid top-posting and favor interleaved quoting: https://en.wikipedia.org/wiki/Posting_style#Interleaved_style * Reply using the --to, --cc, and --in-reply-to switches of git-send-email(1): git send-email \ --in-reply-to=YZzlQjVA3J667Ul6@tarantool.org \ --to=tarantool-patches@dev.tarantool.org \ --cc=imun@tarantool.org \ --cc=skaplun@tarantool.org \ --subject='Re: [Tarantool-patches] [PATCH luajit v2] Fix frame traversal for __gc handler frames.' \ /path/to/YOUR_REPLY https://kernel.org/pub/software/scm/git/docs/git-send-email.html * If your mail client supports setting the In-Reply-To header via mailto: links, try the mailto: link
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox