`ZstdCompressionWriter()` constructs successfully but leads to `segmentation fault`
Maintainer thường phản hồi trong vòng 2 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 3/5
- Thời gian dự kiến
- 1-2 ngày
- Mức phù hợp với người mới
- 76/100
Hướng nghiên cứu
Trước tiên, hãy chạy Python reproducer, sau đó kiểm tra c-ext/compressionwriter.c:64 và c-ext/decompressionwriter.c:50 cùng với các đường dẫn khởi tạo writer. So sánh hành vi của C extension với CFFI backend đối với việc khởi tạo không có đối số. Hoàn thành khi việc khởi tạo trực tiếp không còn để lại các trường nội bộ NULL có thể truy cập và tạo ra một Python exception thay vì gây ra segfault.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
I've been fuzzing Python C extension modules for a small research project.
I found a sanitizer issue which is a null-pointer dereference in ZstdCompressionWriter_memory_size.
I reproduced it with the binary wheel from a plain pip install zstandard.
The process terminates with SIGSEGV there as well.
I'm not sure whether zero-argument construction of this type is considered supported (calling ZstdCompressionWriter() with no arguments),
but since it currently terminates the interpreter rather than raising a Python exception, I thought it was worth reporting.
Versions
zstandard 0.25.0, cext backend, CPython 3.12, Linux x86_64.
Reproducer
import zstandard
w = zstandard.ZstdCompressionWriter() # succeeds
w.memory_size() # SIGSEGV
Five calls across the two writer types behave the same way, each from a fresh direct construction:
| class | methods that segfault |
|---|---|
ZstdCompressionWriter |
memory_size(), close(), flush() |
ZstdDecompressionWriter |
memory_size(), flush() |
Sanitizer build
Same call, zstandard built with -fsanitize=address,undefined:
c-ext/compressionwriter.c:64:65: runtime error:
member access within null pointer of type 'ZstdCompressor'
SUMMARY: UndefinedBehaviorSanitizer: undefined-behavior
c-ext/compressionwriter.c:64:65
AddressSanitizer: SEGV on unknown address 0x000000000020
#0 ZstdCompressionWriter_memory_size c-ext/compressionwriter.c:64:65
ZstdDecompressionWriter.memory_size() reports the equivalent at
c-ext/decompressionwriter.c:50:67.
Expected behavior
I think that direct construction should be rejected with a Python exception, as it is by the CFFI backend.
Under PYTHON_ZSTANDARD_IMPORT_POLICY=cffi the same construction is refused outright:
TypeError: ZstdCompressionWriter.__init__() missing 5 required positional
arguments: 'compressor', 'writer', 'source_size', 'write_size',
and 'write_return_read'
Actual behavior
The C extension permits construction with no arguments, leaving internal fields NULL.
Several methods dereference those fields and terminate the process with SIGSEGV.
Although these objects are normally obtained through stream_writer(), I wonder whether the C extension should reject zero-argument construction, as the CFFI backend already does, rather than produce an uninitialized object.
- Ngôn ngữ chính
- C
- Star
- 641
- Fork
- 117
- Merge trung bình
- 1 ngày 14 giờ
- Pull request đã merge (30 ngày)
- 5
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của indygreg/python-zstandard
-
`multi_decompress_to_buffer([])` terminates the process with SIGFPECó thể đã có người làm @mikamikasuki đã nhận 6 ngày trước. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
indygreg/python-zstandard#335 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 76/100
indygreg/python-zstandard#295 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 64/100
indygreg/python-zstandard#345 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 55/100
indygreg/python-zstandard#334 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 54/100
indygreg/python-zstandard#333 ·
Maintainer thường phản hồi trong vòng 2 ngày
Tất cả issue của indygreg/python-zstandard
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
mypaint/libmypaint#209 ·
-
[LOGO] Keenetic OSCó thể đã có người làm @Ivan-Alone đã nhận hôm nay. Đang mởlogo request
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
fastfetch-cli/fastfetch#2646 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
rc_runtime_activate_richpresence leaves a half-initialised entry when the buffer allocation failsĐang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
RetroAchievements/rcheevos#558 ·
-
good first issue priority:low type:docs
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
crazy-goat/php-fpm-ng#920 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100