Repository navigation
fix(deps): bump pyo3 0.24 -> 0.29 for GHSA-36hh-v3qg-5jq4 (#838) - #839
Conversation
pyo3 < 0.29.0 has an out-of-bounds read in nth/nth_back for PyList and PyTuple iterators. Migrate the removed/renamed APIs: PyObject -> Py<PyAny>, Python::allow_threads -> detach, Python::with_gil -> attach, and opt out of the now-deprecated implicit FromPyObject derive on the result pyclasses (nothing extracts them by value). Closes #838
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Pro Plus Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (4)
Included review availability: Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe Python binding crate upgrades PyO3 to 0.29.0. It updates exported class conversion behavior, Python object types, GIL detachment calls, callback attachment, and context-manager signatures. ChangesPyO3 migration
Estimated code review effort: 3 (Moderate) | ~20 minutes Merge Risk: ⚪ Minimal · up to The PR updates PyO3 to patched 0.29.2 and adapts the binding while preserving its stated behavior; lint, formatting, and finder tests pass, and no actionable merge-blocking risk remains. Suggested reviewers: 🚥 Pre-merge checks | ✅ 3 | ❌ 2❌ Failed checks (1 warning, 1 inconclusive)
✅ Passed checks (3 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 36.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 30 functions across 3 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Closes #838
Root cause
crates/fff-python/Cargo.toml:23pinnedpyo3 = "0.24.0"(lock: 0.24.2,Cargo.lock:1866). GHSA-36hh-v3qg-5jq4 (high) coverspyo3 < 0.29.0: uncheckedindex + n/index - ninIterator::nth/DoubleEndedIterator::nth_backforBoundListIterator/BoundTupleIteratorwraps and passes the bounds check, giving an out-of-bounds read. No fff code path calls those methods, so this is hygiene, not an exploitable hole in fff.Fix
Bump to
pyo3 0.29(resolves 0.29.2) and migrate the API breakage across 0.25-0.29:PyObject->Py<PyAny>,Python::allow_threads->Python::detach,Python::with_gil->Python::attach. Also#[pyclass(skip_from_py_object)]on the result types — 0.29 deprecates the implicitFromPyObjectderive forClonepyclasses and the warning failsclippy -D warnings; nothing extracts these types by value (GrepCursoris taken as&GrepCursor), so skipping is behaviour-neutral and generates less code. No Python-visible API change.Steps to reproduce
Vulnerable version present on pre-fix
main:Expected: resolved pyo3 >= 0.29.0. Actual (pre-fix): 0.24.2, inside the advisory range:
Naive bump (issue body's patch, version only) does not build — this is what the source changes here are for:
How verified
tests/test_watch.pyerrors 10/11 withwatcher never became readyon this macOS box — verified identical on pre-fixmain(1 passed, 10 errorsboth before and after the bump), so it is a local environment issue, not a regression.Automated triage via Gustav. Honk-Honk 🪿
Summary by CodeRabbit
Compatibility
Performance and Reliability