python / python/cpython

readline.c: Missing NULL check on PyLong_FromLong

オープン
#154,385 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

extension-modules type-crash
主要言語
Python
スター
77.2k
フォーク
35.9k
PR マージ指標
PR 指標を取得中

説明

Bug report

Bug description:

Original gist: https://gist.github.com/devdanzin/60aed55f44fba133ee2d34d46aa8d197

readline.c: Missing NULL check on PyLong_FromLong in setup_readline

Summary

PyLong_FromLong(0L) at lines 1418-1419 stored in begidx/endidx without NULL check. On OOM during module init, readline.get_begidx() does Py_NewRef(NULL) → segfault.

Reproducer

import _testcapi, sys
if "readline" in sys.modules: del sys.modules["readline"]
for n in range(1, 80):
    if "readline" in sys.modules: del sys.modules["readline"]
    _testcapi.set_nomemory(n, 0)
    try:
        import readline
        _testcapi.remove_mem_hooks()
        break
    except MemoryError:
        _testcapi.remove_mem_hooks()
    except ImportError:
        _testcapi.remove_mem_hooks()
    except:
        _testcapi.remove_mem_hooks()
# Assertion: obj != NULL in PyStackRef_FromPyObjectSteal

The original gist said we should check the result of PyLong_FromLong(0L), but I think this is a false positive, because 0 is small int and should not failed while creating a Python int object from it.

However there are other line of code in this file for calling PyLong_FromLong with begidx/endidx withoud check the result:

https://github.com/python/cpython/blob/d333e5aa59f6cc20198502f4ff50b14eabde9b8b/Modules/readline.c#L1330-L1331

I guess the LLM found a real bug but reported it at the wrong place. Either way, we should fix it.

CPython versions tested on:

CPython main branch

Operating systems tested on:

No response

Linked PRs
  • gh-154386

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

調査の方向性

Modules/readline.c の setup_readline 周辺と、1330-1331 行付近の PyLong_FromLong 呼び出しを読みます。まず提供された _testcapi memory-hook reproducer を実行し、関連付けられた PR gh-154386 を確認します。完了の条件は、影響を受ける out-of-memory パスで NULL オブジェクトが readline accessors に到達することがなくなり、関連する CPython テストが通過することです。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
c, python
領域
cli
issue の種類
バグ
難易度
3/5
見積もり時間
1〜2日
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
25/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。