`mailbox.MH.__setitem__()` can destroy a message when replacement fails
还没有人认领这个 Issue。
- 主要语言
- Python
- 星标
- 77.2k
- 派生
- 35.9k
- PR 合并指标
- PR 指标待抓取
描述
Bug description:
Summary
`When mailbox.MH replaces an existing message with an invalid str, it correctly raises ValueError, but the original message file may already have been truncated to empty. In other words, the replacement fails while also destroying the existing message content, resulting in data loss.
Affected public API: mailbox.MH.__setitem__().
Minimal reproducer
Run this against CPython before the fix:
import mailbox
import tempfile
with tempfile.TemporaryDirectory() as path:
box = mailbox.MH(path)
key = box.add(b"Subject: original\n\noriginal body\n")
original = box.get_bytes(key)
try:
box[key] = "Subject: caf\u00e9\n\nreplacement body\n"
except ValueError as exc:
print(type(exc).__name__, exc)
print("in-memory:", box.get_bytes(key))
box.close()
reopened = mailbox.MH(path)
print("reopened:", reopened.get_bytes(key))
assert reopened.get_bytes(key) == original
Actual result before the fix:
ValueError String input must be ASCII-only; use bytes or a Message instead
in-memory: b''
reopened: b''
AssertionError
Expected result:
ValueError String input must be ASCII-only; use bytes or a Message instead
in-memory: b'Subject: original\n\noriginal body\n'
reopened: b'Subject: original\n\noriginal body\n'
The same problem occurs if a file-like message object raises while it is being read: the old message is replaced with the bytes written before the exception.
Root cause
MH.__setitem__() performed these operations in this order:
open existing message
-> open the same path with O_TRUNC
-> serialize the replacement with _dump_message()
-> propagate a serialization error
O_TRUNC changes the existing message file before _dump_message() validates or fully reads the replacement. For a non-ASCII str, _dump_message() calls _string_to_bytes() and raises ValueError immediately, leaving the already truncated file in place. There is no rollback path.
CPython versions tested on:
CPython main branch
Operating systems tested on:
Linux
Linked PRs
- gh-156313
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
从 mailbox.MH.setitem() 和 _dump_message() 开始,然后在 CPython 的 mailbox 测试中运行 issue 中的最小复现程序。完成标准是:替换非 ASCII 字符串失败或替换会引发异常的类文件消息时,内存中的原始消息和重新打开的原始消息都保持不变。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- python
- 领域
- backend
- Issue 类型
- 缺陷
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 活跃度
- 停滞
- 描述清晰度
- 描述清楚
- 新手友好度
- 35/100