[Python-checkins] cpython (merge 3.3 -> 3.4): merge 3.3 (#23369)

benjamin.peterson python-checkins at python.org
Mon Feb 2 00:02:56 CET 2015


https://hg.python.org/cpython/rev/4f47509d7417
changeset:   94439:4f47509d7417
branch:      3.4
parent:      94435:24e3371cec2d
parent:      94438:8699b3085db3
user:        Benjamin Peterson <benjamin at python.org>
date:        Sun Feb 01 17:59:49 2015 -0500
summary:
  merge 3.3 (#23369)

files:
  Lib/test/test_json/test_encode_basestring_ascii.py |   9 +++++-
  Misc/NEWS                                          |   3 ++
  Modules/_json.c                                    |  15 +++++++--
  3 files changed, 22 insertions(+), 5 deletions(-)


diff --git a/Lib/test/test_json/test_encode_basestring_ascii.py b/Lib/test/test_json/test_encode_basestring_ascii.py
--- a/Lib/test/test_json/test_encode_basestring_ascii.py
+++ b/Lib/test/test_json/test_encode_basestring_ascii.py
@@ -1,5 +1,6 @@
 from collections import OrderedDict
 from test.test_json import PyTest, CTest
+from test.support import bigaddrspacetest
 
 
 CASES = [
@@ -41,4 +42,10 @@
 
 
 class TestPyEncodeBasestringAscii(TestEncodeBasestringAscii, PyTest): pass
-class TestCEncodeBasestringAscii(TestEncodeBasestringAscii, CTest): pass
+class TestCEncodeBasestringAscii(TestEncodeBasestringAscii, CTest):
+    @bigaddrspacetest
+    def test_overflow(self):
+        s = "\uffff"*((2**32)//6 + 1)
+        with self.assertRaises(OverflowError):
+            self.json.encoder.encode_basestring_ascii(s)
+
diff --git a/Misc/NEWS b/Misc/NEWS
--- a/Misc/NEWS
+++ b/Misc/NEWS
@@ -50,6 +50,9 @@
 Library
 -------
 
+- Issue #23369: Fixed possible integer overflow in
+  _json.encode_basestring_ascii.
+
 - Issue #23353: Fix the exception handling of generators in
   PyEval_EvalFrameEx(). At entry, save or swap the exception state even if
   PyEval_EvalFrameEx() is called with throwflag=0. At exit, the exception state
diff --git a/Modules/_json.c b/Modules/_json.c
--- a/Modules/_json.c
+++ b/Modules/_json.c
@@ -182,17 +182,24 @@
     /* Compute the output size */
     for (i = 0, output_size = 2; i < input_chars; i++) {
         Py_UCS4 c = PyUnicode_READ(kind, input, i);
-        if (S_CHAR(c))
-            output_size++;
+        Py_ssize_t d;
+        if (S_CHAR(c)) {
+            d = 1;
+        }
         else {
             switch(c) {
             case '\\': case '"': case '\b': case '\f':
             case '\n': case '\r': case '\t':
-                output_size += 2; break;
+                d = 2; break;
             default:
-                output_size += c >= 0x10000 ? 12 : 6;
+                d = c >= 0x10000 ? 12 : 6;
             }
         }
+        if (output_size > PY_SSIZE_T_MAX - d) {
+            PyErr_SetString(PyExc_OverflowError, "string is too long to escape");
+            return NULL;
+        }
+        output_size += d;
     }
 
     rval = PyUnicode_New(output_size, 127);

-- 
Repository URL: https://hg.python.org/cpython


More information about the Python-checkins mailing list