]> granicus.if.org Git - python/commitdiff
Issue #8651: PyArg_Parse*() functions raise an OverflowError if the file
authorVictor Stinner <victor.stinner@haypocalc.com>
Mon, 21 Mar 2011 02:22:50 +0000 (03:22 +0100)
committerVictor Stinner <victor.stinner@haypocalc.com>
Mon, 21 Mar 2011 02:22:50 +0000 (03:22 +0100)
doesn't have PY_SSIZE_T_CLEAN define and the size doesn't fit in an int
(length bigger than 2^31-1 bytes).

Lib/test/test_xml_etree_c.py
Misc/NEWS
Python/getargs.c

index 71973ed234793f6a20a1b7ac862ee9742bd06414..c48276afa31df89a4ca5fe919ffae29b4fea139f 100644 (file)
@@ -4,6 +4,8 @@ import doctest
 import sys
 
 from test import support
+from test.support import precisionbigmemtest, _2G
+import unittest
 
 ET = support.import_module('xml.etree.cElementTree')
 
@@ -212,9 +214,25 @@ def bug_1534630():
     '<tag />'
     """
 
+class MiscTests(unittest.TestCase):
+    # Issue #8651.
+    @support.precisionbigmemtest(size=support._2G + 100, memuse=1)
+    def test_length_overflow(self, size):
+        if size < support._2G + 100:
+            self.skipTest("not enough free memory, need at least 2 GB")
+        data = b'x' * size
+        parser = ET.XMLParser()
+        try:
+            self.assertRaises(OverflowError, parser.feed, data)
+        finally:
+            data = None
+
+
 def test_main():
     from test import test_xml_etree_c
     support.run_doctest(test_xml_etree_c, verbosity=True)
 
+    support.run_unittest(MiscTests)
+
 if __name__ == '__main__':
     test_main()
index 461afd7df9688fa774bb58089dd247e217b9be80..fca77ef65e3bb6351f5e7f83ccf7b9696bffcfb9 100644 (file)
--- a/Misc/NEWS
+++ b/Misc/NEWS
@@ -10,6 +10,10 @@ What's New in Python 3.1.4?
 Core and Builtins
 -----------------
 
+- Issue #8651: PyArg_Parse*() functions raise an OverflowError if the file
+  doesn't have PY_SSIZE_T_CLEAN define and the size doesn't fit in an int
+  (length bigger than 2^31-1 bytes).
+
 - Issue #11450: Don't truncate hg version info in Py_GetBuildInfo() when
   there are many tags (e.g. when using mq).  Patch by Nadeem Vawda.
 
index 686eac532f69a077a6b86df468334f9337542297..0009b35426339028b3af46e5231323de60d7c5dd 100644 (file)
@@ -613,7 +613,17 @@ convertsimple(PyObject *arg, const char **p_format, va_list *p_va, int flags,
 #define FETCH_SIZE      int *q=NULL;Py_ssize_t *q2=NULL;\
     if (flags & FLAG_SIZE_T) q2=va_arg(*p_va, Py_ssize_t*); \
     else q=va_arg(*p_va, int*);
-#define STORE_SIZE(s)   if (flags & FLAG_SIZE_T) *q2=s; else *q=s;
+#define STORE_SIZE(s)   \
+    if (flags & FLAG_SIZE_T) \
+        *q2=s; \
+    else { \
+        if (INT_MAX < s) { \
+            PyErr_SetString(PyExc_OverflowError, \
+                "size does not fit in an int"); \
+            return converterr("", arg, msgbuf, bufsize); \
+        } \
+        *q=s; \
+    }
 #define BUFFER_LEN      ((flags & FLAG_SIZE_T) ? *q2:*q)
 
     const char *format = *p_format;