]> git.ipfire.org Git - thirdparty/Python/cpython.git/commitdiff
GH-96569: Add two NULL checks to avoid undefined behavior. (GH-96585)
authorMark Shannon <mark@hotpy.org>
Tue, 6 Sep 2022 15:45:43 +0000 (16:45 +0100)
committerGitHub <noreply@github.com>
Tue, 6 Sep 2022 15:45:43 +0000 (16:45 +0100)
Include/internal/pycore_frame.h
Misc/NEWS.d/next/Core and Builtins/2022-09-05-16-43-44.gh-issue-96569.9lmTCC.rst [new file with mode: 0644]
Python/pystate.c

index decaafd141e9e1e301fe12099ae8a7e84350a2a5..5bd0a7f2f517effac80eea1bc9c75233999bca23 100644 (file)
@@ -190,11 +190,16 @@ _PyFrame_FastToLocalsWithError(_PyInterpreterFrame *frame);
 void
 _PyFrame_LocalsToFast(_PyInterpreterFrame *frame, int clear);
 
-
 static inline bool
 _PyThreadState_HasStackSpace(PyThreadState *tstate, int size)
 {
-    return tstate->datastack_top + size < tstate->datastack_limit;
+    assert(
+        (tstate->datastack_top == NULL && tstate->datastack_limit == NULL)
+        ||
+        (tstate->datastack_top != NULL && tstate->datastack_limit != NULL)
+    );
+    return tstate->datastack_top != NULL &&
+        size < tstate->datastack_limit - tstate->datastack_top;
 }
 
 extern _PyInterpreterFrame *
diff --git a/Misc/NEWS.d/next/Core and Builtins/2022-09-05-16-43-44.gh-issue-96569.9lmTCC.rst b/Misc/NEWS.d/next/Core and Builtins/2022-09-05-16-43-44.gh-issue-96569.9lmTCC.rst
new file mode 100644 (file)
index 0000000..4734d3d
--- /dev/null
@@ -0,0 +1 @@
+Remove two cases of undefined behavoir, by adding NULL checks.
index a11f1622ecd4ab5ed25412326f7ed10762e1e8be..1c96f4f75f29a6d28ccbc42acab5de22e81d923f 100644 (file)
@@ -2195,15 +2195,12 @@ _PyInterpreterFrame *
 _PyThreadState_PushFrame(PyThreadState *tstate, size_t size)
 {
     assert(size < INT_MAX/sizeof(PyObject *));
-    PyObject **base = tstate->datastack_top;
-    PyObject **top = base + size;
-    if (top >= tstate->datastack_limit) {
-        base = push_chunk(tstate, (int)size);
+    if (_PyThreadState_HasStackSpace(tstate, (int)size)) {
+        _PyInterpreterFrame *res = (_PyInterpreterFrame *)tstate->datastack_top;
+        tstate->datastack_top += size;
+        return res;
     }
-    else {
-        tstate->datastack_top = top;
-    }
-    return (_PyInterpreterFrame *)base;
+    return (_PyInterpreterFrame *)push_chunk(tstate, (int)size);
 }
 
 void