8000 bpo-39068 guard _b85chars2 initialization by drmonkeysee · Pull Request #17627 · python/cpython · GitHub
[go: up one dir, main page]

Skip to content

bpo-39068 guar 8000 d _b85chars2 initialization #17627

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 4 commits into from
Dec 31, 2020

Conversation

drmonkeysee
Copy link
Contributor
@drmonkeysee drmonkeysee commented Dec 16, 2019

Under multi-threading scenarios a race condition may occur where a thread sees an initialized _b85chars table but an uninitialized _b85chars2 table due to the guard only checking the first table.

This causes an exception like:

  File "/usr/lib/python3.6/base64.py", line 434, in b85encode
    return _85encode(b, _b85chars, _b85chars2, pad),
  File "/usr/lib/python3.6/base64.py", line 294, in _85encode
    for word in words],
  File "/usr/lib/python3.6/base64.py", line 294, in <listcomp>
    for word in words],
 "TypeError: 'NoneType' object is not subscriptable

https://bugs.python.org/issue39068

@the-knights-who-say-ni
Copy link

Hello, and thanks for your contribution!

I'm a bot set up to make sure that the project can legally accept this contribution by verifying everyone involved has signed the PSF contributor agreement (CLA).

Recognized GitHub username

We couldn't find a bugs.python.org (b.p.o) account corresponding to the following GitHub usernames:

@drmonkeysee

This might be simply due to a missing "GitHub Name" entry in one's b.p.o account settings. This is necessary for legal reasons before we can look at this contribution. Please follow the steps outlined in the CPython devguide to rectify this issue.

You can check yourself to see if the CLA has been received.

Thanks again for the contribution, we look forward to reviewing it!

@drmonkeysee drmonkeysee changed the title guard _b85chars2 table bpo-39068 guard _b85chars2 table Dec 16, 2019
@drmonkeysee drmonkeysee changed the title bpo-39068 guard _b85chars2 table bpo-39068 guard _b85chars2 initialization Dec 16, 2019
Lib/base64.py Outdated
@@ -430,6 +430,7 @@ def b85encode(b, pad=False):
# if the function is never called
if _b85chars is None:
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is enough to check if _b85chars2 is None here.

These checks are cheap, but they are performed at every b85encode() call. Lesser checks is better.

a85encode() should be updated too. And may be other functions if they initialize two or more globals.

Copy link
Contributor Author
@drmonkeysee drmonkeysee Dec 16, 2019

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

done. visually scanned the file for other cases but only found the additional one in a85encode().

@serhiy-storchaka
Copy link
Member

Please add a NEWS entry. Since it is your first contribution, add also your name in Misc/ACKS.

@serhiy-storchaka
Copy link
Member

Thank you for your contribution @drmonkeysee. Sorry for the delay, this ЗК fell out of my window of attention.

@serhiy-storchaka serhiy-storchaka added needs backport to 3.8 needs backport to 3.9 only security fixes type-bug An unexpected behavior, bug, or error labels Dec 31, 2020
@miss-islington
Copy link
Contributor

Thanks @drmonkeysee for the PR, and @serhiy-storchaka for merging it 🌮🎉.. I'm working now to backport this PR to: 3.8.
🐍🍒⛏🤖

@miss-islington
Copy link
Contributor

Thanks @drmonkeysee for the PR, and @serhiy-storchaka for merging it 🌮🎉.. I'm working now to backport this PR to: 3.9.
🐍🍒⛏🤖

miss-islington pushed a commit to miss-islington/cpython that referenced this pull request Dec 31, 2020
There was a race condition in base64 in lazy initialization of multiple globals.
(cherry picked from commit 9655434)

Co-authored-by: Brandon Stansbury <brandonrstansbury@gmail.com>
@bedevere-bot bedevere-bot removed the needs backport to 3.9 only security fixes label Dec 31, 2020
@bedevere-bot
Copy link

GH-24020 is a backport of this pull request to the 3.9 branch.

@miss-islington
Copy link
Contributor

Sorry, @drmonkeysee and @serhiy-storchaka, I could not cleanly backport this to 3.8 due to a conflict.
Please backport using cherry_picker on command line.
cherry_picker 9655434cca5dfbea97bf6d355aec028e840b289c 3.8

serhiy-storchaka pushed a commit to serhiy-storchaka/cpython that referenced this pull request Dec 31, 2020
There was a race condition in base64 in lazy initialization of multiple globals..
(cherry picked from commit 9655434)

Co-authored-by: Brandon Stansbury <brandonrstansbury@gmail.com>
@bedevere-bot
Copy link

GH-24022 is a backport of this pull request to the 3.8 branch.

@serhiy-storchaka serhiy-storchaka removed their assignment Dec 31, 2020
serhiy-storchaka added a commit that referenced this pull request Jan 1, 2021
There was a race condition in base64 in lazy initialization of multiple globals.
(cherry picked from commit 9655434)

Co-authored-by: Brandon Stansbury <brandonrstansbury@gmail.com>
@serhiy-storchaka serhiy-storchaka added the needs backport to 3.9 only security fixes label Jan 1, 2021
@miss-islington
Copy link
Contributor

Thanks @drmonkeysee for the PR, and @serhiy-storchaka for merging it 🌮🎉.. I'm working now to backport this PR to: 3.9.
🐍🍒⛏🤖

miss-islington pushed a commit to miss-islington/cpython that referenced this pull request Jan 1, 2021
There was a race condition in base64 in lazy initialization of multiple globals.
(cherry picked from commit 9655434)

Co-authored-by: Brandon Stansbury <brandonrstansbury@gmail.com>
@bedevere-bot
Copy link

GH-24051 is a backport of this pull request to the 3.9 branch.

@bedevere-bot bedevere-bot removed the needs backport to 3.9 only security fixes label Jan 1, 2021
miss-islington added a commit that referenced this pull request Jan 1, 2021
There was a race condition in base64 in lazy initialization of multiple globals.
(cherry picked from commit 9655434)

Co-authored-by: Brandon Stansbury <brandonrstansbury@gmail.com>
@drmonkeysee drmonkeysee deleted the base85-race-condition-fix branch January 4, 2021 19:28
adorilson pushed a commit to adorilson/cpython that referenced this pull request Mar 13, 2021
There was a race condition in base64 in lazy initialization of multiple globals.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type-bug An unexpected behavior, bug, or error
Projects
None yet
Development

Successfully merging this pull request may close these issues.

8 participants
0