Repository navigation
Keep the bounds test's unchecked reads inside an array it owns - #36
nelson2005 wants to merge 5 commits into
Conversation
…a one-byte array they hit an unmapped page on Windows
…e options test; it named three and exercised two
…oded uncached; the one entry it had was killed by four older tests without the new legs
…the three decorator entries were killed by older tests as well
…the options test; forwarding only cache and boundscheck kept the suite green
MiniMax Code ReviewLet me analyze this pull request to understand what changes are being made and why.Summary of Changes1.
|
|
From the fake Slim Shady: On the review of
Nothing to change. |
|
From the fake Slim Shady: Closing unmerged. Everything here landed upstream through Goykhman#13, merged as 2af2c6d, and fork main takes it through the |
test_jit_options_reach_the_is_null_decoratorsfailed on the Windows cell of upstream's main after Goykhman#12 went in (job) and passed when it was re-run. The child that runs without bounds checking exited 0xC0000005, an access violation.The script built a one-byte bitmap and asked for bit 100000, so without bounds checking
is_nullandunpack_booleansread 12.5 KB past the array, and the test asserted that they returned. What lies behind a one-byte array is the allocator's business. It was readable in 86 of the 87 Windows jobs that have run the test, here and upstream.Now the bitmap is the first byte of an array that holds every byte the calls reach. With bounds checking on both calls still raise
IndexError, the check being against the bitmap's one byte. With it off they read memory the array owns. The test still fails when the options stop reaching the decorators inis_null.py, and the crash reproduces on Linux with the bitmap on the last byte of a page and unreadable pages behind it.The test's comment named all three of
is_null.py's decorators and its script exercised two, and of the options it observed only the two that show. It now checks the cache option on each of the three, off and on, and readsnogil, which shows on none of them, back from the three dispatchers. The catalogue has an entry per decorator, each hard-coded uncached, and two more that only the new legs catch: the cache option dropped forunpack_booleansalone, and every option but cache and boundscheck dropped.