Uh oh!
There was an error while loading. Please reload this page.
- Notifications
You must be signed in to change notification settings - Fork 34k
gh-98793: Fix typecheck in overlapped.c#98835
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
gh-98793: Fix typecheck in overlapped.c#98835
Uh oh!
There was an error while loading. Please reload this page.
Conversation
CharlieZhao95 commented Oct 29, 2022 • edited by bedevere-bot
Loading Uh oh!
There was an error while loading. Please reload this page.
edited by bedevere-bot
Uh oh!
There was an error while loading. Please reload this page.
Misc/NEWS.d/next/Library/2022-10-29-03-40-18.gh-issue-98793.WSPB4A.rst Outdated Show resolvedHide resolved
Uh oh!
There was an error while loading. Please reload this page.
…PB4A.rst Co-authored-by: Kumar Aditya <59607654+kumaraditya303@users.noreply.github.com>
kumaraditya303 commented Oct 29, 2022
This can potentially crash the interpreter so can be considered a security issue. The RMs should decide cc @pablogsal@ambv. |
gvanrossum commented Oct 29, 2022
Usually a crash is only a vulnerability if it can be exploited by sending an app that is using the API untrusted data. |
ambv commented Oct 29, 2022
Since it's complex to decide which crash can be triggered by user action, we usually treat crashers as potential vulnerabilities and patch them in security-only releases. We'd spend more time thinking about whether it's right to backport if the patch was overly complex or backwards incompatible. This isn't the case here so I'd backport to security-only releases, too. Such crashers rarely get CVE numbers and we don't automatically trigger a security release for them. We just bundle the fix with the next release that is triggered by a CVE. |
ambv commented Oct 29, 2022
The backports might be a bit involved due to Argument Clinic. I'll take care of those. |
miss-islington commented Oct 30, 2022
Thanks @CharlieZhao95 for the PR, and @gvanrossum for merging it 🌮🎉.. I'm working now to backport this PR to: 3.7, 3.8, 3.9, 3.10, 3.11. |
miss-islington commented Oct 30, 2022
Sorry @CharlieZhao95 and @gvanrossum, I had trouble checking out the |
miss-islington commented Oct 30, 2022
Sorry, @CharlieZhao95 and @gvanrossum, I could not cleanly backport this to |
miss-islington commented Oct 30, 2022
Sorry @CharlieZhao95 and @gvanrossum, I had trouble checking out the |
miss-islington commented Oct 30, 2022
Sorry, @CharlieZhao95 and @gvanrossum, I could not cleanly backport this to |
gvanrossum commented Oct 30, 2022
Okay @ambv go ahead with the backport! |
Co-authored-by: Kumar Aditya <59607654+kumaraditya303@users.noreply.github.com> (cherry picked from commit 3ac8c0a)
CharlieZhao95 commented Oct 31, 2022
It seems that for recent releases(3.11/3.10), backporting is not that complicated, and I will help with those backports as well :) |
Co-authored-by: Kumar Aditya <59607654+kumaraditya303@users.noreply.github.com> (cherry picked from commit 3ac8c0a)
bedevere-bot commented Oct 31, 2022
GH-98889 is a backport of this pull request to the 3.11 branch. |
bedevere-bot commented Oct 31, 2022
GH-98890 is a backport of this pull request to the 3.10 branch. |
bedevere-bot commented Oct 31, 2022
GH-98890 is a backport of this pull request to the 3.10 branch. |
hugovk commented Feb 18, 2025
Does this still need backporting to 3.9? If not, let's remove the backport label. |
serhiy-storchaka commented Aug 14, 2025
Reminder about backporting. @CharlieZhao95@gvanrossum |
StanFromIreland commented Oct 27, 2025
Little ping @ambv since the final release is nearing. |
ambv commented Oct 27, 2025
Thanks, @StanFromIreland. I'll do the backport. |
pythonGH-98890) (cherry picked from commit d3d1738) Co-authored-by: Charlie Zhao <zhaoyu_hit@qq.com> Co-authored-by: Kumar Aditya <59607654+kumaraditya303@users.noreply.github.com> (cherry picked from commit 3ac8c0a)
…GH-140825) (cherry picked from commit d3d1738) Co-authored-by: Charlie Zhao <zhaoyu_hit@qq.com> Co-authored-by: Kumar Aditya <59607654+kumaraditya303@users.noreply.github.com> Co-authored-by: Petr Viktorin <encukou@gmail.com>
serhiy-storchaka commented Dec 26, 2025
Was it backported to 3.9? |
serhiy-storchaka commented Dec 26, 2025
Hmm, for some reasons this was in the result of search for |
StanFromIreland commented Dec 26, 2025
It may have been cached, the label has since been removed. |
Fixes typecheck in
_overlapped.WSAConnectand_overlapped.Overlapped.WSASendTo.