Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: msgpack/msgpack-python
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: main
Choose a base ref
...
head repository: afonsojanu/msgpack-python
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: main
Choose a head ref
Checking mergeability… Don’t worry, you can still create the pull request.
  • 1 commit
  • 3 files changed
  • 1 contributor

Commits on Sep 4, 2026

  1. Refuse to resize the packer buffer while a memoryview is exported

    Packer.pack() checks for existing buffer exports before it starts, but
    nothing stopped a default() callback from calling getbuffer() partway
    through the same call and then having the packer grow its buffer to
    fit the rest of the object. msgpack_pack_write() reallocates through
    PyMem_Realloc without checking whether anything holds a live view onto
    the old allocation, so a growth mid-pack can move the buffer out from
    under an export that's still considered valid from Python's side. An
    ASan build turns this into a textbook heap-use-after-free the moment
    anything reads through the export afterward.
    
    Moved the exports counter into the msgpack_packer C struct itself
    (previously it only lived on the Cython Packer object, invisible to
    the plain C write path) and made msgpack_pack_write raise BufferError
    instead of reallocating whenever exports is nonzero and the buffer
    needs to grow. This is the same error _check_exports() already raises
    for every other buffer-mutating method, just reachable from the one
    code path that runs in the middle of a pack() call rather than at its
    start.
    
    Fixes GH-733.
    afonsojanu committed Sep 4, 2026
    Configuration menu
    Copy the full SHA
    8ed8226 View commit details
    Browse the repository at this point in the history
Loading