Repository navigation
Conversation
…es subclass _Unpickler_ReadFromFile() resized the object returned by read() in place, which is invalid for a bytes subclass. Copy it into an exact bytes object first.
|
Could we verify that every possible path to |
|
Four |
|
Closing, since the decision is to keep the documented behaviour. Thanks for the review. |
pickle.load()crashes when a file object'sread()returns abytessubclass and the data is large enough to need several reads._Unpickler_ReadFromFile()grows the result with_PyBytes_Resize(), which is only valid for exactbytes. The fix copies a subclass instance into an exactbytesobject first. A regression test and a NEWS entry are included.The new test segfaults on a debug build without the fix and passes with it. test_pickle, test_pickletools, test_copyreg and test_picklebuffer pass.
AI disclosure: written with Claude Code assistance; I reviewed the change and ran the tests.
Fixes #158841.
AI-assisted: I used Claude Code to help write this change. I reviewed it and ran test_pickle, test_pickletools, test_copyreg and test_picklebuffer on a debug build.