Message318523
The documentation (https://docs.python.org/3/c-api/tuple.html) for `PyStructSequence_InitType` describes the function as follows:
> void PyStructSequence_InitType(PyTypeObject *type, PyStructSequence_Desc *desc)
> Initializes a struct sequence type `type` from `desc` in place.
And most of the time it does just that.
However, when running under python compiled in debug mode, the body of the function will contain the following code at the very beginning:
```
if (type->ob_base.ob_base._ob_next) {
_Py_ForgetReference((PyObject*)type);
}
```
Since `type` here is a preallocated but an uninitialized piece of memory, it may contain garbage data that when interpreted as a "live" PyObject will result in memory corruption or process crash.
Thus, either the description for the `PyStructSequence_InitType` method has to document that the `type` object must be zeroed-out before being passed to the method, or the call to `_Py_ForgetReference` be removed. |
|
Date |
User |
Action |
Args |
2018-06-03 06:37:33 | Pasha Stetsenko | set | recipients:
+ Pasha Stetsenko |
2018-06-03 06:37:33 | Pasha Stetsenko | set | messageid: <1528007853.29.0.592728768989.issue33742@psf.upfronthosting.co.za> |
2018-06-03 06:37:33 | Pasha Stetsenko | link | issue33742 messages |
2018-06-03 06:37:32 | Pasha Stetsenko | create | |
|