Repository navigation
mmap lacks error handling (SEH) on Windows which can lead to interpreter crashes #118209
Description
Activity
- addedtype-crashA hard crash of the interpreter, possibly with a core dumpA hard crash of the interpreter, possibly with a core dump
on Apr 24, 2024 - addedextension-modulesC modules in the Modules dirC modules in the Modules dir
on Apr 24, 2024 Posted this on the PR, but repeating here:
One other possibility may be to protect
PyBytes_FromStringinternally, which could cut off an entire class of crashes instead of just one. Thoughts?On POSIX, the
mmaptype doesn't currently support handling synchronousSIGSEGVorSIGBUSsignals generated by an error while reading or writing in the address range of a memory-mapped file. That requires a handler set bysigaction()that's configured withSA_SIGINFOin order to be able to check whether the faultingsi_addris in the range of the mapped file.Is it premature to implement SEH or VEH support for this on Windows, given nothing similar is currently implemented on POSIX?
Is it premature to implement SEH or VEH support for this on Windows, given nothing similar is currently implemented on POSIX?
Something has to be implemented first, and the likelihood of finding someone capable of doing both is pretty slim.
I think we're best to implement one first, but in a way that's easily adapted to support other platforms (e.g. my
safe_memcpysuggestion on the PR). That way another contributor has the framework for adding platform support, and we don't have to force collaboration or conflict resolution too early.Reacted by Eryk Sun- added a commit that references this issue
on May 10, 2024 - added a commit that references this issue
on May 10, 2024 Thanks for the contribution! This is now merged into 3.13 for beta 2.
If someone would like to add POSIX/signal support, please feel free, but let's do it on a new issue. Similarly with any additional operations that we can protect using SEH.
Crash report
What happened?
mmapreads and writes require structured exception handling (SEH) for correct handling of errors (like hardware read issues, or disk full write issues) on Windows. See https://learn.microsoft.com/en-us/windows/win32/api/memoryapi/nf-memoryapi-mapviewoffile#remarks for a description of the possible exceptions and https://learn.microsoft.com/en-us/windows/win32/memory/reading-and-writing-from-a-file-view for how to handle them.I found this issue when trying to read a file from a corrupt hdd. A normal
open().read()would raise aOSError: [Errno 22] Invalid argumentexception. Whereas doing the same usingmmapcrashes the interpreter.I only tested on Windows 7 and Python 3.8, but from looking at the Microsoft docs and the Python source code, this issue should exist for all Windows versions and the latest Python source. (I don't have access to the broken file from a newer machine)
I think there is nothing here which guards against these errors
cpython/Modules/mmapmodule.c
Lines 294 to 313 in 2584082
CPython versions tested on:
3.8
Operating systems tested on:
Windows
Output from running 'python -VV' on the command line:
No response
Linked PRs