gc.collect()
self.assertTrue(gc.is_tracked(next(it)))
+ def test_store_evilattr(self):
+ class EvilAttr:
+ def __init__(self, d):
+ self.d = d
+
+ def __del__(self):
+ if 'attr' in self.d:
+ del self.d['attr']
+ gc.collect()
+
+ class Obj:
+ pass
+
+ obj = Obj()
+ obj.__dict__ = {}
+ for _ in range(10):
+ obj.attr = EvilAttr(obj.__dict__)
+
def test_str_nonstr(self):
# cpython uses a different lookup function if the dict only contains
# `str` keys. Make sure the unoptimized path is used when a non-`str`
--- /dev/null
+Fix a potential use-after-free in ``STORE_ATTR_WITH_HINT``.
uint64_t new_version = _PyDict_NotifyEvent(interp, PyDict_EVENT_MODIFIED, mp, key, value);
STORE_SPLIT_VALUE(mp, ix, Py_NewRef(value));
mp->ma_version_tag = new_version;
+ // old_value should be DECREFed after GC track checking is done, if not, it could raise a segmentation fault,
+ // when dict only holds the strong reference to value in ep->me_value.
Py_DECREF(old_value);
}
ASSERT_CONSISTENT(mp);
new_version = _PyDict_NotifyEvent(tstate->interp, PyDict_EVENT_MODIFIED, dict, name, value);
ep->me_value = value;
}
- Py_DECREF(old_value);
- STAT_INC(STORE_ATTR, hit);
/* Ensure dict is GC tracked if it needs to be */
if (!_PyObject_GC_IS_TRACKED(dict) && _PyObject_GC_MAY_BE_TRACKED(value)) {
_PyObject_GC_TRACK(dict);
}
- /* PEP 509 */
- dict->ma_version_tag = new_version;
+ dict->ma_version_tag = new_version; // PEP 509
+ // old_value should be DECREFed after GC track checking is done, if not, it could raise a segmentation fault,
+ // when dict only holds the strong reference to value in ep->me_value.
+ Py_DECREF(old_value);
+ STAT_INC(STORE_ATTR, hit);
Py_DECREF(owner);
}
new_version = _PyDict_NotifyEvent(tstate->interp, PyDict_EVENT_MODIFIED, dict, name, value);
ep->me_value = value;
}
- Py_DECREF(old_value);
- STAT_INC(STORE_ATTR, hit);
/* Ensure dict is GC tracked if it needs to be */
if (!_PyObject_GC_IS_TRACKED(dict) && _PyObject_GC_MAY_BE_TRACKED(value)) {
_PyObject_GC_TRACK(dict);
}
- /* PEP 509 */
- dict->ma_version_tag = new_version;
+ dict->ma_version_tag = new_version; // PEP 509
+ // old_value should be DECREFed after GC track checking is done, if not, it could raise a segmentation fault,
+ // when dict only holds the strong reference to value in ep->me_value.
+ Py_DECREF(old_value);
+ STAT_INC(STORE_ATTR, hit);
Py_DECREF(owner);
stack_pointer += -2;
DISPATCH();