Skip to content

Keep the bounds test's unchecked reads inside an array it owns - #13

Merged
Goykhman merged 5 commits into
Goykhman:mainfrom
nelson2005:upstream-pr/bounds-test-reads-owned-memory
Sep 30, 2026
Merged

Goykhman merged 5 commits into
Goykhman:mainfrom
nelson2005:upstream-pr/bounds-test-reads-owned-memory

Conversation

@nelson2005

Copy link
Copy Markdown
Collaborator

test_jit_options_reach_the_is_null_decorators failed on the Windows cell of main after #12 went in (job) and passed when it was re-run. The child that runs without bounds checking exited 0xC0000005, an access violation.

The script built a one-byte bitmap and asked for bit 100000, so without bounds checking is_null and unpack_booleans read 12.5 KB past the array, and the test asserted that they returned. What lies behind a one-byte array is the allocator's business. It was readable in 86 of the 87 Windows jobs that have run the test, here and on my fork.

Now the bitmap is the first byte of an array that holds every byte the calls reach. With bounds checking on both calls still raise IndexError, the check being against the bitmap's one byte. With it off they read memory the array owns. The test still fails when the options stop reaching the decorators in is_null.py, and the crash reproduces on Linux with the bitmap on the last byte of a page and unreadable pages behind it.

The test's comment named all three of is_null.py's decorators and its script exercised two, and of the options it observed only the two that show. It now checks the cache option on each of the three, off and on, and reads nogil, which shows on none of them, back from the three dispatchers. The catalogue has an entry per decorator, each hard-coded uncached, and two more that only the new legs catch: the cache option dropped for unpack_booleans alone, and every option but cache and boundscheck dropped.

…a one-byte array they hit an unmapped page on Windows
…e options test; it named three and exercised two
…oded uncached; the one entry it had was killed by four older tests without the new legs
…the three decorator entries were killed by older tests as well
…the options test; forwarding only cache and boundscheck kept the suite green
Copilot AI balanced review requested due to automatic review settings September 30, 2026 15:56

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@Goykhman
Goykhman merged commit 2af2c6d into Goykhman:main Sep 30, 2026
7 checks passed
@nelson2005
nelson2005 deleted the upstream-pr/bounds-test-reads-owned-memory branch October 1, 2026 20:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants