Fixed bug of long strings in binary chunks

When "undumping" a long string, the function 'LoadVector' can call the
reader function, which can run the garbage collector, which can collect
the string being read. So, the string must be anchored during the call
to 'LoadVector'. (This commit also fixes the identation in 'l_alloc'.)
This commit is contained in:
Roberto Ierusalimschy 2020-08-18 14:48:43 -03:00
parent 5027298b46
commit 75ea9ccbea
2 changed files with 11 additions and 7 deletions

View File

@ -1013,10 +1013,10 @@ static void *l_alloc (void *ud, void *ptr, size_t osize, size_t nsize) {
} }
else { /* cannot fail when shrinking a block */ else { /* cannot fail when shrinking a block */
void *newptr = realloc(ptr, nsize); void *newptr = realloc(ptr, nsize);
if (newptr == NULL && ptr != NULL && nsize <= osize) if (newptr == NULL && ptr != NULL && nsize <= osize)
return ptr; /* keep the original block */ return ptr; /* keep the original block */
else /* no fail or not shrinking */ else /* no fail or not shrinking */
return newptr; /* use the new block */ return newptr; /* use the new block */
} }
} }

View File

@ -86,6 +86,7 @@ static lua_Integer LoadInteger (LoadState *S) {
static TString *LoadString (LoadState *S, Proto *p) { static TString *LoadString (LoadState *S, Proto *p) {
lua_State *L = S->L;
size_t size = LoadByte(S); size_t size = LoadByte(S);
TString *ts; TString *ts;
if (size == 0xFF) if (size == 0xFF)
@ -95,13 +96,16 @@ static TString *LoadString (LoadState *S, Proto *p) {
else if (--size <= LUAI_MAXSHORTLEN) { /* short string? */ else if (--size <= LUAI_MAXSHORTLEN) { /* short string? */
char buff[LUAI_MAXSHORTLEN]; char buff[LUAI_MAXSHORTLEN];
LoadVector(S, buff, size); LoadVector(S, buff, size);
ts = luaS_newlstr(S->L, buff, size); ts = luaS_newlstr(L, buff, size);
} }
else { /* long string */ else { /* long string */
ts = luaS_createlngstrobj(S->L, size); ts = luaS_createlngstrobj(L, size);
setsvalue2s(L, L->top, ts); /* anchor it ('loadVector' can GC) */
luaD_inctop(L);
LoadVector(S, getstr(ts), size); /* load directly in final place */ LoadVector(S, getstr(ts), size); /* load directly in final place */
L->top--; /* pop string */
} }
luaC_objbarrier(S->L, p, ts); luaC_objbarrier(L, p, ts);
return ts; return ts;
} }