multidict C Extension Analysis Report
Open
bug
reproducer: present
- Dominant language
- Python
- Stars
- 492
- Forks
- 129
- Avg merge
- 14h 28m
- Merged PRs (30d)
- 35
Description
I ran a [code analysis tool](https://github.com/devdanzin/cext-review-toolkit) I'm developing on multidict and it generated an interesting report: https://gist.github.com/devdanzin/a36588ae7e2b73f0d85f8a925fb13b3d. It contains issue descriptions, suggested fixes, and reproducers for some of the issues.
From the summary:
> The most critical finding is a **double-free/use-after-free in `md_contains`** and a **crash from swapped format string arguments** in `_err_cannot_fetch`. The iterator and view types are also missing the heap type lifecycle management (`Py_VISIT(Py_TYPE(self))`) that the main dict types correctly implement.
I hope it helps.
Contributor guide
Assessment
This issue has not been assessed yet.