indygreg / indygreg/python-zstandard

`ZstdCompressionWriter()` constructs successfully but leads to `segmentation fault`

Offen
#331 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

Vorherrschende Sprache
C
Sterne
642
Forks
116
Ø Merge
1 T. 14 Std.
Gemergte PRs (30 T.)
5

Beschreibung

I've been fuzzing Python C extension modules for a small research project.
I found a sanitizer issue which is a null-pointer dereference in ZstdCompressionWriter_memory_size.

I reproduced it with the binary wheel from a plain pip install zstandard.
The process terminates with SIGSEGV there as well.

I'm not sure whether zero-argument construction of this type is considered supported (calling ZstdCompressionWriter() with no arguments),
but since it currently terminates the interpreter rather than raising a Python exception, I thought it was worth reporting.

Versions

zstandard 0.25.0, cext backend, CPython 3.12, Linux x86_64.

Reproducer
import zstandard

w = zstandard.ZstdCompressionWriter()   # succeeds
w.memory_size()                         # SIGSEGV

Five calls across the two writer types behave the same way, each from a fresh direct construction:

class methods that segfault
ZstdCompressionWriter memory_size(), close(), flush()
ZstdDecompressionWriter memory_size(), flush()
Sanitizer build

Same call, zstandard built with -fsanitize=address,undefined:

c-ext/compressionwriter.c:64:65: runtime error:
    member access within null pointer of type 'ZstdCompressor'
SUMMARY: UndefinedBehaviorSanitizer: undefined-behavior
    c-ext/compressionwriter.c:64:65

AddressSanitizer: SEGV on unknown address 0x000000000020
    #0 ZstdCompressionWriter_memory_size  c-ext/compressionwriter.c:64:65

ZstdDecompressionWriter.memory_size() reports the equivalent at
c-ext/decompressionwriter.c:50:67.

Expected behavior

I think that direct construction should be rejected with a Python exception, as it is by the CFFI backend.

Under PYTHON_ZSTANDARD_IMPORT_POLICY=cffi the same construction is refused outright:

TypeError: ZstdCompressionWriter.__init__() missing 5 required positional
arguments: 'compressor', 'writer', 'source_size', 'write_size',
and 'write_return_read'
Actual behavior

The C extension permits construction with no arguments, leaving internal fields NULL.
Several methods dereference those fields and terminate the process with SIGSEGV.


Although these objects are normally obtained through stream_writer(), I wonder whether the C extension should reject zero-argument construction, as the CFFI backend already does, rather than produce an uninitialized object.

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Führe zuerst den Python-Reproducer aus und untersuche dann c-ext/compressionwriter.c:64 und c-ext/decompressionwriter.c:50 zusammen mit den Pfaden zur Writer-Konstruktion. Vergleiche das Verhalten der C-Erweiterung bei der Konstruktion ohne Argumente mit dem CFFI-Backend. Die Aufgabe ist abgeschlossen, wenn die direkte Konstruktion keine erreichbaren internen NULL-Felder mehr hinterlässt und statt eines Segmentation Faults eine Python-Ausnahme auslöst.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
c, python
Bereich
backend
Issue-Typ
Bug
Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Aktivitätsstatus
Ruhig
Klarheit
Klar beschrieben
Anfängerfreundlichkeit
76/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.