Handle exceptions - #807
Open
david-a-wheeler wants to merge 2 commits into
Open
Conversation
This commit fixes crashes that can occur after garbage collection compaction, and adds a test for it (the test fails before the fix, and succeeds afterwards). Without this commit, GC compaction can lead to crashes. Ruby 2.7+ supports GC compaction (GC.compact), which can move objects in memory to reduce fragmentation. The rb_redcarpet_rndr struct stores Ruby VALUE references (link_attributes, self, base_class) as raw C pointers. When compaction moves these objects, the pointers become stale, causing segfaults or "T_IMEMO" errors on next use. This commit fixes this problem in the standard Ruby way. It registers a dcompact callback via Ruby's TypedData API. When GC compaction runs, Ruby calls this callback, allowing us to update each VALUE pointer using rb_gc_location() to its new address. The callback is conditionally compiled only when rb_gc_location is available (Ruby 2.7+), maintaining backward compatibility. Co-authored-by: David A. Wheeler <dwheeler@dwheeler.com> Co-authored-by: Claude <noreply@anthropic.com> Signed-off-by: David A. Wheeler <dwheeler@dwheeler.com>
Ruby callbacks can raise exceptions which use longjmp, bypassing C cleanup
code. This could leave work_bufs in an inconsistent state, causing assertion
failures on subsequent renders.
In addition, it's possible for the internal state to be corrupted
at *least* if there are multiple threads sharing an object
(and possibly other causes), which can quickly lead to an application
crash.
Changes:
- Use rb_ensure() to guarantee cleanup runs even if exception occurs
- Add sd_markdown_cleanup() to free render-time allocations and reset state
- Replace C assertions with detection that raises Ruby exception
- If work_bufs imbalance detected after render, raise informative exception
(indicates threading bug or undiscovered code path) and clean up
so that the problem is visible *but* the caller can keep going
(e.g., log the problem or even try to continue).
- There's a weird formatting of "else nb_p--; i++;" that is misleading.
At this point only the "else" branch can run, but this still triggers
compiler warnings. Change it to the clearer "else { nb_p--; i++; }".
The fix ensures:
1. Exceptions in callbacks propagate to caller properly
2. State is always reset so next render works
3. Work buffer imbalances are reported as Ruby exceptions, not C crashes
Co-Authored-By: David A. Wheeler <dwheeler@dwheeler.com>
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Signed-off-by: David A. Wheeler <dwheeler@dwheeler.com>
Author
|
This handles exceptions in the renderer (by raising exceptions), and also raises an exception instead of crashing if there's an internal state problem. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.