diff options
author | Antoine Pitrou <solipsis@pitrou.net> | 2013-04-15 21:55:14 +0200 |
---|---|---|
committer | Antoine Pitrou <solipsis@pitrou.net> | 2013-04-15 21:55:14 +0200 |
commit | af94051a933b7fbd9c63b0a45cfba5247d92ac14 (patch) | |
tree | 4a1d2acfb1267176d395e7e92c4a7fac6d57b3a8 | |
parent | acfc454c10ab2fe5dafd4c90a15eaae8cef214c2 (diff) | |
parent | 3034efdd298ad5f94a61f9f0e8ab0fee1d2d212e (diff) | |
download | cpython-git-af94051a933b7fbd9c63b0a45cfba5247d92ac14.tar.gz |
Issue #17710: Fix pickle raising a SystemError on bogus input.
-rw-r--r-- | Lib/pickle.py | 2 | ||||
-rw-r--r-- | Lib/test/pickletester.py | 8 | ||||
-rw-r--r-- | Misc/NEWS | 2 | ||||
-rw-r--r-- | Modules/_pickle.c | 8 |
4 files changed, 15 insertions, 5 deletions
diff --git a/Lib/pickle.py b/Lib/pickle.py index 998fce0a6b..a4acbe941e 100644 --- a/Lib/pickle.py +++ b/Lib/pickle.py @@ -903,7 +903,7 @@ class _Unpickler: orig = self.readline() rep = orig[:-1] # Strip outermost quotes - if rep[0] == rep[-1] and rep[0] in b'"\'': + if len(rep) >= 2 and rep[0] == rep[-1] and rep[0] in b'"\'': rep = rep[1:-1] else: raise ValueError("insecure string pickle") diff --git a/Lib/test/pickletester.py b/Lib/test/pickletester.py index 5d12375267..a72ab377c0 100644 --- a/Lib/test/pickletester.py +++ b/Lib/test/pickletester.py @@ -609,6 +609,14 @@ class AbstractPickleTests(unittest.TestCase): b"'abc\"", # open quote and close quote don't match b"'abc' ?", # junk after close quote b"'\\'", # trailing backslash + # Variations on issue #17710 + b"'", + b'"', + b"' ", + b"' ", + b"' ", + b"' ", + b'" ', # some tests of the quoting rules ## b"'abc\"\''", ## b"'\\\\a\'\'\'\\\'\\\\\''", @@ -42,6 +42,8 @@ Core and Builtins Library ------- +- Issue #17710: Fix pickle raising a SystemError on bogus input. + - Issue #17341: Include the invalid name in the error messages from re about invalid group names. diff --git a/Modules/_pickle.c b/Modules/_pickle.c index 146dccca44..2c83185dde 100644 --- a/Modules/_pickle.c +++ b/Modules/_pickle.c @@ -4205,7 +4205,7 @@ load_string(UnpicklerObject *self) if ((len = _Unpickler_Readline(self, &s)) < 0) return -1; - if (len < 3) + if (len < 2) return bad_readline(); if ((s = strdup(s)) == NULL) { PyErr_NoMemory(); @@ -4213,14 +4213,14 @@ load_string(UnpicklerObject *self) } /* Strip outermost quotes */ - while (s[len - 1] <= ' ') + while (len > 0 && s[len - 1] <= ' ') len--; - if (s[0] == '"' && s[len - 1] == '"') { + if (len > 1 && s[0] == '"' && s[len - 1] == '"') { s[len - 1] = '\0'; p = s + 1; len -= 2; } - else if (s[0] == '\'' && s[len - 1] == '\'') { + else if (len > 1 && s[0] == '\'' && s[len - 1] == '\'') { s[len - 1] = '\0'; p = s + 1; len -= 2; |