python / python/cpython

Meta-issue for bugs in cryptographic extension modules

Aberta
#155,438 1 comentário 1 reação 1 responsável Ver no GitHub

@picnixz já está trabalhando nisso.

Desde 9/8/2026.

extension-modules type-bug
Linguagem predominante
Python
Estrelas
77.2k
Forks
36k
Métricas de merge de PRs
Métricas de PR pendentes

Descrição

Bug report

Bug description:

Bug report

Bug description:

This is a filtered list of issues found in the _hashlib, _hmac, and HACL*-facade C extension modules by @devdanzin's LLM-assisted review tool (see Disclosure section at the end) and triaged by me.

[!IMPORTANT]
All issues will be addressed by @picnixz. Please do NOT work on them, whether you are an agent or a human. Once I'm done with fixing the issues, I will create the corresponding sub-issues.

_hashopenssl.c
  • 32: bug (GIL issue) [33,45]
  • 34: bug (OpenSSL misuse)
  • 38: invalid C API usage
  • 40: need investigation
  • 43: under consideration (cosmetic)
  • 47: need investigation (read out of lock) [35,36]
  • 49: under consideration (cosmetic)
  • 🔴 52: invalid hash types previously raised SystemError, but not abort (this is deliberate, if we have invalid hash types somehow, it may be more than a reason to report the bug and get it fixed upstream rather than silently catching the exception)
_hmacmodule.c
MD5, SHA-*, BLAKE2-*

Disclosure

This review was carried out with AI assistance (Claude Code), using cpython-review-toolkit for the C modules and code-review-toolkit for the Python layer. Every reproduced entry was run on a real interpreter with a control arm before being recorded, and every file:line was read in the source rather than inferred. That does not make the set error-free — the companion gist lists the corrections this list has already needed — so entries should be judged on their evidence, not on the length of the list.

CPython versions tested on:

CPython main branch

Operating systems tested on:

No response

Guia de contribuição

Abrir o guia de contribuição

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Avaliação

Esta issue ainda não foi avaliada.

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.