aio-libs / aio-libs/multidict

multidict C Extension Analysis Report

Ouverte
#1,306 2 commentaires 1 réaction 1 personne assignée Réclamée par @Vizonex Voir sur GitHub
bug reproducer: present
Langage dominant
Python
Étoiles
492
Forks
129
Merge moyen
14 h 28 min
PR mergées (30 j)
35

Description

I ran a [code analysis tool](https://github.com/devdanzin/cext-review-toolkit) I'm developing on multidict and it generated an interesting report: https://gist.github.com/devdanzin/a36588ae7e2b73f0d85f8a925fb13b3d. It contains issue descriptions, suggested fixes, and reproducers for some of the issues.

From the summary:

> The most critical finding is a **double-free/use-after-free in `md_contains`** and a **crash from swapped format string arguments** in `_err_cannot_fetch`. The iterator and view types are also missing the heap type lifecycle management (`Py_VISIT(Py_TYPE(self))`) that the main dict types correctly implement.

I hope it helps.

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.