Repository navigation
Conversation
| wrapper = self.TextIOWrapper( | ||
| self.BufferedReader(raw), encoding="utf-8") | ||
| method = getattr(wrapper, method_name) | ||
| self.assertEqual(method(), "ab\n") |
There was a problem hiding this comment.
Can you check that wrapper is actually detached? Maybe get wrapper.buffer and expect PyExc_ValueError("underlying buffer has been detached")?
There was a problem hiding this comment.
@ ashm-dev: You didn't reply to my request.
|
I will need a couple more days to look at this, it seems like this is more invasive than necessary to me and makes a number of not needed for the core UAF bug report. |
|
For gh-157364 I think the bug, and solution, is actually in Buffered I/O. This PR changes Text I/O to keep one more reference, which may also be needed. The issue though is that Buffered I/O has an internal allocation which it passes as an argument to the Raw I/O That makes two pieces to fix here:
|
|
Thanks for looking into this, @cmaloney! Regarding point 1: passing mbuf->master = *info;
mbuf->master.obj = NULL;Because of this, the resulting Regarding point 2: CPython method calls via |
|
For 1: The |
|
I don't understand well how _bufferedreader_raw_read_getbuffer() works. How is it different from the current PyBuffer_FillInfo() + PyMemoryView_FromBuffer() code? |
|
The key difference is reference ownership:
We can't use standard |
|
I have been triaging some old I/O bugs and came across gh-60198 which is exactly the BufferedReader memoryview bug here. That could be pulled out as a separate smaller PR that is likely quicker to land with its own NEWS. I think this should have two news entries: one the io.TexTIOWrapper keeping a reference to I don't like adding the two new members to In the TextIO the Incref and decref living in very different functions I'm not a big fan of... I would much rather keep |
|
@vstinner @cmaloney I narrowed this PR to the TextIOWrapper fix for gh-157364. I removed the BufferedReader change and added the requested check that the wrapper is detached after |
| } | ||
| self->buffer = NULL; | ||
| self->detached = 1; | ||
| Py_CLEAR(self->buffer); |
There was a problem hiding this comment.
Nitpick: why moving this line after setting self->detached = 1;? If there is not specific reason, please move back the buffer assignment one line above.
| wrapper = self.TextIOWrapper( | ||
| self.BufferedReader(raw), encoding="utf-8") | ||
| method = getattr(wrapper, method_name) | ||
| self.assertEqual(method(), "ab\n") |
There was a problem hiding this comment.
@ ashm-dev: You didn't reply to my request.
Just a general remark: you're making many large changes on this PR. It's not easy to follow these changes. |
Uh oh!
There was an error while loading. Please reload this page.