Potential Integer Overflow in mark_stacks function
还没有人认领这个 Issue。
- 主要语言
- Python
- 星标
- 77.2k
- 派生
- 35.9k
- PR 合并指标
- PR 指标待抓取
描述
There is a potential signed integer overflow in the expression:
https://github.com/python/cpython/blob/132b6bc98f47a4d897dead8635b5a50a0baee485/Objects/frameobject.c#L1365
This occurs in the loop:
https://github.com/python/cpython/blob/132b6bc98f47a4d897dead8635b5a50a0baee485/Objects/frameobject.c#L1329
len is derived from a Py_SIZE cast, and it can possibly be INT_MAX:
https://github.com/python/cpython/blob/132b6bc98f47a4d897dead8635b5a50a0baee485/Objects/frameobject.c#L1728-L1730
It means that sum can theoretically exceed INT_MAX if len is near the limit, triggering undefined behavior due to signed integer overflow.
Linked PRs
- gh-132773
- gh-132830
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
从 Objects/frameobject.c 中的 mark_stacks 开始,重点查看第 1329 行附近的循环和第 1365 行附近的表达式;跟踪 len 在第 1728-1730 行是如何得出的。完成的标准是:当 len 接近 INT_MAX 时,该计算不再允许 signed overflow,并且已根据链接的 PR gh-132773 和 gh-132830 检查其行为。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- c, python
- 领域
- compilers
- Issue 类型
- 缺陷
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 活跃度
- 停滞
- 描述清晰度
- 描述清楚
- 新手友好度
- 35/100