FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

`_imp.get_frozen_object` possible incorrect use of `PyBUF_READ` · Issue #114685 · python/cpython · GitHub

Repository navigation

_imp.get_frozen_object possible incorrect use of PyBUF_READ #114685

Description

Bug report

It is documented that PyBUF_READ should be used with memoryview objects. But, it is used in PyObject_GetBuffer:

if (PyObject_GetBuffer(dataobj, &buf, PyBUF_READ) != 0) {

Other similar places that access .buf and .len just use PyBUF_SIMPLE, which I think we should use here as well.

I will send a PR.

Originally found by @serhiy-storchaka in #114669 (comment)

Linked PRs

Activity

  1. added
    type-bugAn unexpected behavior, bug, or error
    interpreter-core(Objects, Python, Grammar, and Parser dirs)
    on Jan 28, 2024
  2. self-assigned this
    on Jan 28, 2024
  3. added a commit that references this issue on Jan 28, 2024
  4. serhiy-storchaka commented on Jan 28, 2024

    Member

    Other question, why it was not caught in tests? Does PyObject_GetBuffer() ignore unknown flags or this code was never executed?

  5. sobolevn commented on Jan 29, 2024

    MemberAuthor

    PyObject_GetBuffer() expects a numeric flag, but it uses bitflag model with example logic:

        if (!REQ_FORMAT(flags)) {
            /* NULL indicates that the buffer's data type has been cast to 'B'.
               view->itemsize is the _previous_ itemsize. If shape is present,
               the equality product(shape) * itemsize = len still holds at this
               point. The equality calcsize(format) = itemsize does _not_ hold
               from here on! */
            view->format = NULL;
        }
        if (REQ_C_CONTIGUOUS(flags) && !MV_C_CONTIGUOUS(baseflags)) {
            PyErr_SetString(PyExc_BufferError,
                "memoryview: underlying buffer is not C-contiguous");
            return -1;
        }
        if (REQ_F_CONTIGUOUS(flags) && !MV_F_CONTIGUOUS(baseflags)) {
            PyErr_SetString(PyExc_BufferError,
                "memoryview: underlying buffer is not Fortran contiguous");
            return -1;
        }
        if (REQ_ANY_CONTIGUOUS(flags) && !MV_ANY_CONTIGUOUS(baseflags)) {
            PyErr_SetString(PyExc_BufferError,
                "memoryview: underlying buffer is not contiguous");
            return -1;
        }

    PyBYF_READ is equal to 256, so it just contains all the features. PyBUF_SIMPLE is just 0, so no extras.

  6. added a commit that references this issue on Jan 29, 2024
  7. added 2 commits that reference this issue on Jan 29, 2024
  8. added 4 commits that reference this issue on Jan 29, 2024
  9. serhiy-storchaka commented on Jan 31, 2024

    Member

    Unfortunately the value of PyBUF_READ intersects with PyBUF_INDIRECT, PyBUF_FULL and PyBUF_FULL_RO, so we cannot just ban this bit. But fortunately other values has other bits set, so this error is still distinguishable.

  10. sobolevn commented on Jan 31, 2024

    MemberAuthor

    What about PyBuffer_FillInfo(Py_buffer *view, PyObject *obj, void *buf, Py_ssize_t len, int readonly, int flags)? Do we need to check flags there as well?

  11. serhiy-storchaka commented on Jan 31, 2024

    Member

    Maybe. We do not have examples of the misuse in this case, and it is much less used, but a similar error is possible here too.

  12. sobolevn commented on Jan 31, 2024

    MemberAuthor

    I will send an example PR, so we can decide 👍

  13. added 2 commits that reference this issue on Jan 31, 2024
  14. added a commit that references this issue on Feb 4, 2024
  15. added 3 commits that reference this issue on Feb 11, 2024
  16. added a commit that references this issue on Feb 14, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

interpreter-core(Objects, Python, Grammar, and Parser dirs)type-bugAn unexpected behavior, bug, or error

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions


    Back | FazBrowse Home | New Git URL