gh-158583: Fix uninitialized memory read in bytes.fromhex() - #158584
Conversation
|
bytes.fromhex() was modified in Python 3.14 to accept more types; Python 3.13 only accepts str. So the undefined behavior was introduced in Python 3.14. So far, before me running Valgrind, nobody reported the issue. So I'm not sure if it's needed to add a Changelog entry. The modified code is tested by |
|
In Python 3.13, reading
|
|
I'm also curious why only Valgrind reports the issue. In the CI, we are running the Python test suite on Python built with Address Sanitizer. This build doesn't detect usage of uninitialized memory? |
|
Apparently, when |
We only run with ASan and UBSan, however neither track uninitialised memory. We'd have to run with MSan. Edit: I went off on a little tangent, but I wrote a patch to add MSan to the CI: #158625 |
There was a problem hiding this comment.
Oh well spotted! I removed the dead code.
|
Also, I think we should add an entry, it's a bug fix after all. |
Oh, implementation details can be very surprising sometimes :-D
Sure, I added two tests to test the two modified code paths, using an array created from a list. I tested manually that the two tests are detected by Valgrind without the fix: |
Ok, I added a Changelog entry. I also removed dead code. |
StanFromIreland
left a comment
There was a problem hiding this comment.
LGTM, just two little nits.
|
Thanks @vstinner for the PR 🌮🎉.. I'm working now to backport this PR to: 3.14, 3.15. |
|
GH-158691 is a backport of this pull request to the 3.15 branch. |
|
GH-158692 is a backport of this pull request to the 3.14 branch. |
|
Merged. Thanks for reviews! |
Uh oh!
There was an error while loading. Please reload this page.