aio-libs / aio-libs/multidict

multidict C Extension Analysis Report

Offen
#1,306 2 Kommentare 1 Reaktion 1 zugewiesene Person Beansprucht von @Vizonex Auf GitHub ansehen
bug reproducer: present
Vorherrschende Sprache
Python
Sterne
492
Forks
129
Ø Merge
14 Std. 28 Min.
Gemergte PRs (30 T.)
35

Beschreibung

I ran a [code analysis tool](https://github.com/devdanzin/cext-review-toolkit) I'm developing on multidict and it generated an interesting report: https://gist.github.com/devdanzin/a36588ae7e2b73f0d85f8a925fb13b3d. It contains issue descriptions, suggested fixes, and reproducers for some of the issues.

From the summary:

> The most critical finding is a **double-free/use-after-free in `md_contains`** and a **crash from swapped format string arguments** in `_err_cannot_fetch`. The iterator and view types are also missing the heap type lifecycle management (`Py_VISIT(Py_TYPE(self))`) that the main dict types correctly implement.

I hope it helps.

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.