[ 
https://issues.apache.org/jira/browse/THRIFT-6062?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Jens Geyer resolved THRIFT-6062.
--------------------------------
    Fix Version/s: 0.26.0
         Assignee: Jens Geyer
       Resolution: Fixed

> Smalltalk compiler crashes (stack overflow) on recursive struct types
> ---------------------------------------------------------------------
>
>                 Key: THRIFT-6062
>                 URL: https://issues.apache.org/jira/browse/THRIFT-6062
>             Project: Thrift
>          Issue Type: Bug
>          Components: Smalltalk - Compiler
>    Affects Versions: 0.24.0
>            Reporter: Jens Geyer
>            Assignee: Jens Geyer
>            Priority: Major
>             Fix For: 0.26.0
>
>          Time Spent: 20m
>  Remaining Estimate: 0h
>
> The Smalltalk generator inline-expands nested struct (de)serialization: when 
> generating the read/write code for a struct-typed field, {{write_val}} / 
> {{read_val}} emit {{struct_writer}} / {{struct_reader}} for the field's type 
> *inline* (compiler/cpp/src/thrift/generate/t_st_generator.cc). There is no 
> base case or visited-set guard for this expansion, so a self- or 
> mutually-recursive struct type makes the generator recurse until the C++ call 
> stack overflows, crashing with SIGSEGV.
> Struct read/write code is only emitted inside service send/recv methods, so 
> the crash occurs when a recursive type is reachable from a service.
> h3. Reproduction
> Minimal self-recursive type:
> {code}
> struct RecTree { 1: list<RecTree> children, 2: i16 item }
> service S { RecTree echo(1: RecTree t) }
> {code}
> {code}
> $ thrift --gen st recur.thrift
> Segmentation fault (core dumped)
> {code}
> Mutually recursive types ({{CoRec}} / {{CoRec2}}) crash the same way, as does 
> test/Recursive.thrift. A finite, non-recursive chain of distinct struct types 
> generates correctly, so the trigger is specifically type recursion (not depth 
> alone).
> h3. Notes
> * Reproduced with the 0.24.0 compiler.
> * This is a separate, pre-existing limitation surfaced while adding a runtime 
> recursion-depth limit to the Smalltalk library (THRIFT-6052): because 
> recursive types cannot be generated at all, that limit can currently only be 
> exercised through a finite chain of distinct struct types.
> * A fix would bound or restructure the inline expansion, e.g. emit per-struct 
> read/write helper methods and call them, rather than textually inlining 
> nested struct serialization.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to