crossinterp: Segfault in `check_missing___main___attr` if AttributeError args are not normal

Đang mở
#156,121 0 bình luận 1 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
35/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Đình trệ
Công nghệ
c, python
Lĩnh vực
backend

Hướng nghiên cứu

Bắt đầu trong Python/crossinterp.c tại check_missing___main___attr, như được xác định trong báo cáo, và tái hiện cả trường hợp AttributeError với lone-surrogate lẫn trường hợp AttributeError với đối số không phải chuỗi. Xác minh rằng các đối số ngoại lệ không đúng định dạng không còn gây ra segfault và hành vi gọi cross-interpreter hiện có vẫn được giữ nguyên; gh-156128 đã được liên kết với issue này.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

extension-modules topic-subinterpreters type-crash

Crash report

What happened?

crossinterp doesn't do much checking on the arguments of the passed-in exception, allowing lone surrogate unicode, or non-str arguments cause segfaults:

Lone surrogate example:

from concurrent import interpreters
import __main__

x = 1

def f():
    return x  # forces pickle fallback

f.__name__ = f.__qualname__ = "\ud800"
setattr(__main__, "\ud800", f)

interp = interpreters.create()
interp.call(f)
> ./python.exe temp/crossinterp.py
fish: Job 1, './python.exe temp/crossinterp.py' terminated by signal SIGSEGV (Address boundary error)

Non-str argument example (a bit more convoluted):

from concurrent import interpreters

x = 1

def f():
    return x  # forces pickle fallback

interp = interpreters.create()
interp.exec("""
import pickle

def loads(data):
    raise AttributeError(42)

pickle.loads = loads
""")
interp.call(f)
> ./python.exe temp/crossinterp-2.py
fish: Job 1, './python.exe temp/crossinterp-2…' terminated by signal SIGSEGV (Address boundary error)

This is because check_missing___main___attr doesn't check the result of PyUnicode_AsUTF8 before passing it to strncmp, so if the object is not a PyUnicode object or if it can't be converted to utf8, you get a crash:

https://github.com/python/cpython/blob/91d71dd67074d4599b6bd49cc933f41f8bd57058/Python/crossinterp.c#L666-669

The fix should cover both cases, I guess:

A PyUnicode_Check on msgobj, and then a check that the PyUnicode_AsUTF8 return is valid.

CPython versions tested on:

CPython main branch

Operating systems tested on:

macOS

Output from running 'python -VV' on the command line:

Python 3.16.0a0 (heads/main:e8158d1a02d, Aug 20 2026, 15:09:24) [Clang 21.0.0 (clang-2100.3.27.1)]

Linked PRs
  • gh-156128
Ngôn ngữ chính
Python
Star
77.2k
Fork
36k
Merge trung bình
1 ngày 9 giờ
Pull request đã merge (30 ngày)
558

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của python/cpython

Tất cả issue của python/cpython

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.