Directly constructed subprocess pipe protocols segfault when callbacks use a non-process owner
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 52/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- python
- Lĩnh vực
- backend, operating-systems
Hướng nghiên cứu
Start by reproducing the three constructor-and-callback cases for ReadSubprocessPipeProto and WriteSubprocessPipeProto, then inspect their generated callbacks in uvloop/loop.c at the reported locations. Use the ASan/UBSan findings to trace invalid owner access, and verify that each case raises a Python exception instead of terminating the interpreter.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Summary
ReadSubprocessPipeProto and WriteSubprocessPipeProto accept ordinary integers as constructor arguments, after which the listed protocol callbacks terminate the interpreter.
I realize this is not a realistic input or usage pattern, but I would expect a Python exception rather than a process crash.
Versions
uvloop 0.22.1, CPython 3.12.3, Debian 12 x86_64, glibc 2.36
Reproducer
Each call below reproduces independently in a fresh process.
from uvloop.loop import ReadSubprocessPipeProto, WriteSubprocessPipeProto
ReadSubprocessPipeProto(1, 7).data_received(b"data")
WriteSubprocessPipeProto(1, 7).connection_lost(None)
WriteSubprocessPipeProto(1, 7).resume_writing()
Segmentation fault (core dumped)
ASan/UBSan result
I built uvloop 0.22.1 from source with Clang 18 using ASan and UBSan instrumentation.
ASan reports zero-page reads for data_received() and connection_lost() in their generated Cython callbacks:
ERROR: AddressSanitizer: SEGV on unknown address 0x0000000000e0
The signal is caused by a READ memory access.
#0 ReadSubprocessPipeProto.data_received
uvloop/loop.c:130047:177
SUMMARY: AddressSanitizer: SEGV
uvloop/loop.c:130047:177
The connection_lost() variant reports an equivalent read from address 0xd8 at uvloop/loop.c:129583.
For resume_writing(), UBSan first reports misaligned PyObject access in Py_INCREF at uvloop/loop.c:129886, and ASan then reports the resulting read fault.
The sanitizer processes exit with code 134 after ASan aborts.
I found this while fuzzing Python C extension modules.
- Ngôn ngữ chính
- Cython
- Star
- 11.9k
- Fork
- 615
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Hướng dẫn đóng góp
Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của MagicStack/uvloop
-
License not clear Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
MagicStack/uvloop#759 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
MagicStack/uvloop#741 · 2 reaction ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
MagicStack/uvloop#702 · 8 bình luận · 9 reaction ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 25/100
MagicStack/uvloop#766 ·
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 68/100
MagicStack/uvloop#763 ·
Tất cả issue của MagicStack/uvloop
Issue tương tự
-
bug customer-eng Durable Agents Inngest status: needs triage
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
-
integration: elevenlabs
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
home-assistant/core#182944 · 1 bình luận ·
-
ai-observability bug team/ai-observability
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
vicharanashala/fln#563 ·