Repository navigation
Conversation
…es subclass _Unpickler_ReadFromFile() resized the object returned by read() in place, which is invalid for a bytes subclass. Copy it into an exact bytes object first.
vstinner
left a comment
There was a problem hiding this comment.
I don't think that it's correct to convert a bytes subclass to bytes. I would prefer to raise TypeError and return NULL (set *bytes to NULL). It sounds weird to that that in the caller, _PyBytes_Resize() changes the argument type.
The issue has been seen in pickle.load() with special code designed to trigger the code. IMO pickle should be fixed to never pass bytes to _PyBytes_Resize(). Did the bug have been seen elsewhere so far?
In the current code, _PyBytes_Resize() calls PyObject_Realloc(v, PyBytesObject_SIZE + newsize) to resize the bytes subclass in-place. The allocated size is wrong, a subclass needs more bytes (see bytes_subtype_new()). So the current code does fail / crash. It confirms that no code can rely on passing bytes subclass to _PyBytes_Resize() since it doesn't work (fail / crash).
This reuses the test from #158846, but makes the change
_PyBytes_Resizeby avoiding the optimization for subclasses, and always returning exactbytes.