Repository navigation
Use of uninitialized pointer in Argument Clinic generated code #97728
Copy link
Copy link
Closed
Labels
3.10 (EOL)end of lifeend of life3.11only security fixesonly security fixes3.12only security fixesonly security fixesOS-windowstopic-argument-clinictype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or errortype-crashA hard crash of the interpreter, possibly with a core dumpA hard crash of the interpreter, possibly with a core dump
Description
Activity
- addedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or errorneeds backport to 3.10only security fixesonly security fixestype-crashA hard crash of the interpreter, possibly with a core dumpA hard crash of the interpreter, possibly with a core dumpneeds backport to 3.11only security fixesonly security fixes
on Oct 2, 2022 Seems that for now it only affects the Windows code.
I have found this bug when tried to use Argument Clinic for OS agnostic code which converts arguments to
wchar_t *(ingetpath.c).These needs to be fixed if
_winapi.CreateJunction()is used as a fallback foros.symlink()when creating a compatibility link such as "bin -> Scripts". More here: #97586 (comment).- added3.11only security fixesonly security fixes3.10 (EOL)end of lifeend of life3.12only security fixesonly security fixesand removedneeds backport to 3.10only security fixesonly security fixesneeds backport to 3.11only security fixesonly security fixes
on Oct 2, 2022 - added 5 commits that reference this issue
on Oct 3, 2022 - added a commit that references this issue
on Oct 3, 2022 Fixed by #97729
Metadata
Metadata
Assignees
Labels
3.10 (EOL)end of lifeend of life3.11only security fixesonly security fixes3.12only security fixesonly security fixesOS-windowstopic-argument-clinictype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or errortype-crashA hard crash of the interpreter, possibly with a core dumpA hard crash of the interpreter, possibly with a core dump
The code generated for the Py_UNICODE converter (and derived converter LPCWSTR) looks like:
If parsing fails,
PyMem_Free()is called for uninitialized variable.It is the only converter with non-trivial cleanup which does not have a mandatory initializer.