Commit 12b3eda
### Rationale for this change
`rb_memory_view_get()` callers may pass a non-zero-initialized `rb_memory_view_t`. `primitive_array_get()` and `buffer_get()` did not initialize `item_desc.components` and `item_desc.length`, which could cause `rb_memory_view_release()` to attempt to free an invalid pointer and abort the process.
### What changes are included in this PR?
This change initializes `item_desc.components` and `item_desc.length` in both `primitive_array_get()` and `buffer_get()`.
It also adds regression tests that verify releasing a memory view with a non-zero-initialized `rb_memory_view_t` does not crash for both `Arrow::Int32Array` and `Arrow::Buffer`.
### Are these changes tested?
Yes. Added regression tests in `test-memory-view.rb` that reproduced the crash before this change and pass after the fix.
### Are there any user-facing changes?
No.
**This PR contains a "Critical Fix".**
This change fixes a crash that could occur when `rb_memory_view_release()` is called with a memory view whose `item_desc` members were not initialized.
* GitHub Issue: #45187
Lead-authored-by: Aaditya Srinivasan <aadityasri03@gmail.com>
Co-authored-by: Sutou Kouhei <kou@cozmixng.org>
Signed-off-by: Sutou Kouhei <kou@clear-code.com>
1 parent f3f65df commit 12b3eda
2 files changed
Lines changed: 56 additions & 6 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
| 34 | + | |
34 | 35 | | |
35 | 36 | | |
36 | 37 | | |
| |||
220 | 221 | | |
221 | 222 | | |
222 | 223 | | |
| 224 | + | |
223 | 225 | | |
224 | 226 | | |
225 | 227 | | |
| |||
231 | 233 | | |
232 | 234 | | |
233 | 235 | | |
234 | | - | |
235 | | - | |
236 | | - | |
237 | 236 | | |
238 | 237 | | |
239 | 238 | | |
| |||
258 | 257 | | |
259 | 258 | | |
260 | 259 | | |
| 260 | + | |
261 | 261 | | |
262 | 262 | | |
263 | 263 | | |
| |||
275 | 275 | | |
276 | 276 | | |
277 | 277 | | |
278 | | - | |
279 | | - | |
280 | | - | |
281 | 278 | | |
282 | 279 | | |
283 | 280 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
431 | 431 | | |
432 | 432 | | |
433 | 433 | | |
| 434 | + | |
| 435 | + | |
| 436 | + | |
| 437 | + | |
| 438 | + | |
| 439 | + | |
| 440 | + | |
| 441 | + | |
| 442 | + | |
| 443 | + | |
| 444 | + | |
| 445 | + | |
| 446 | + | |
| 447 | + | |
| 448 | + | |
| 449 | + | |
| 450 | + | |
| 451 | + | |
| 452 | + | |
| 453 | + | |
| 454 | + | |
| 455 | + | |
| 456 | + | |
| 457 | + | |
| 458 | + | |
| 459 | + | |
| 460 | + | |
| 461 | + | |
| 462 | + | |
| 463 | + | |
| 464 | + | |
| 465 | + | |
| 466 | + | |
| 467 | + | |
| 468 | + | |
| 469 | + | |
| 470 | + | |
| 471 | + | |
| 472 | + | |
| 473 | + | |
| 474 | + | |
| 475 | + | |
| 476 | + | |
| 477 | + | |
| 478 | + | |
| 479 | + | |
| 480 | + | |
| 481 | + | |
| 482 | + | |
| 483 | + | |
| 484 | + | |
| 485 | + | |
| 486 | + | |
434 | 487 | | |
0 commit comments