python / python/cpython

decimal: crash when a re-entrant __bool__ deallocates the Context during Context.flags assignment or comparison

Đang mở
#155,493 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

extension-modules type-crash
Ngôn ngữ chính
Python
Star
77.2k
Fork
35.9k
Chỉ số merge pull request
Chỉ số pull request đang chờ

Mô tả

Bug report

Context.flags (and traps) is a SignalDict that borrows a pointer to
flags owned by its Context. signaldict_setitem and
signaldict_richcompare read that pointer after calling back into Python
(PyObject_IsTrue, i.e. the value's __bool__), which can deallocate the
Context. gh-146011 cleared the borrowed pointer on Context teardown and
guarded signaldict_repr, but these two methods were left unguarded, so the
same teardown leaves them dereferencing a NULL pointer and crashing.

Assignment:

import decimal, gc
ctx = decimal.Context()
flags = ctx.flags
class Evil:
    def __bool__(self):
        global ctx; del ctx; gc.collect()
        return True
flags[decimal.InvalidOperation] = Evil()   # segfault

Comparison:

import decimal, gc
ctx = decimal.Context()
other = ctx.flags.copy()
class Evil:
    def __bool__(self):
        global ctx; del ctx; gc.collect()
        return True
other[decimal.InvalidOperation] = Evil()
ctx.flags == other                          # segfault

Both crash with SIGSEGV on current main; the affected code exists on 3.13+.

Linked PRs
  • gh-155494

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Hướng nghiên cứu

Bắt đầu với các entry point của module decimal là signaldict_setitem và signaldict_richcompare, sau đó tái hiện các ví dụ về phép gán và phép so sánh từ issue trên Python 3.13+. Hoàn tất khi cả hai trường hợp bool re-entrant không còn bị crash sau khi teardown Context; lưu ý rằng PR được liên kết gh-155494 đã bao phủ công việc này.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
python
Lĩnh vực
backend
Loại issue
Lỗi
Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Đặc tả rõ ràng
Mức phù hợp với người mới
25/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.