Repository navigation
segfault in mmap object when using __index__ method that closes the mmap #103987
Description
Activity
- addedtype-crashA hard crash of the interpreter, possibly with a core dumpA hard crash of the interpreter, possibly with a core dump
on Apr 29, 2023 - addedextension-modulesC modules in the Modules dirC modules in the Modules dir
on Apr 29, 2023 Yes, adding
CHECK_VALID(NULL);right afterPy_ssize_t i = PyNumber_AsSsize_t(item, PyExc_IndexError);seems like a reasonale check.@cfbolz would you like to send a PR? :)
heh, in principle yes, but I am currently busy doing an equivalent fix in pypy ;-)
Hi @sobolevn I can create a PR, I guess it's a one-line change , I don't know whether we need to modify some test or not
@Agent-Hellboy yes, adding regression tests for crashes is a must :)
okay, Thanks, let me explore
I guess this is the expected outputTraceback (most recent call last): File "/home/proshan/play_python/my_cpython/cpython/b.py", line 15, in <module> print(m[X()]) ~^^^^^ ValueError: mmap closed or invalidYes, looks correct to me
that's what I went with too. there's an interesting corner case with this kind of code:
... m = mmap.mmap(...) m.close() m["abc"]
should this give a TypeError because of the invalid index type? or an error that the mmap is closed (as it does now)? if the latter, you would have to check twice whether the mmap is closed.
or an error that the mmap is closed (as it does now)?
I think that's the case, because other exceptions might break users' code (unlikely, but possible).
Reacted by CF Bolz-Tereick- added a commit that references this issue
on Apr 29, 2023 - added3.11only security fixesonly security fixes3.12only security fixesonly security fixes3.13only security fixesonly security fixes
on May 12, 2023 - added a commit that references this issue
on May 12, 2023 - added a commit that references this issue
on May 20, 2023 Thanks everyone!
The following (artificial) code segfaults CPython (I tried a bunch of versions, including git main) on my x86 Ubuntu Linux 22.10:
The problem is this code in
mmapmodule.cthe
CHECK_VALID(NULL)call which checks whether the mmap object is closed happens before thePyNumber_AsSsize_tcall which closes the object (and similarly for the slice handling which happens further down).Linked PRs