Skip to content

fix(deps): bump pyo3 0.24 -> 0.29 for GHSA-36hh-v3qg-5jq4 (#838) - #839

Merged
dmtrKovalenko merged 1 commit into
mainfrom
triage-bot/issue-838
Aug 30, 2026
Merged

dmtrKovalenko merged 1 commit into
mainfrom
triage-bot/issue-838

Conversation

@gustav-fff

@gustav-fff gustav-fff commented Aug 30, 2026 •

Copy link
Copy Markdown
Collaborator

Closes #838

Root cause

crates/fff-python/Cargo.toml:23 pinned pyo3 = "0.24.0" (lock: 0.24.2, Cargo.lock:1866). GHSA-36hh-v3qg-5jq4 (high) covers pyo3 < 0.29.0: unchecked index + n / index - n in Iterator::nth / DoubleEndedIterator::nth_back for BoundListIterator / BoundTupleIterator wraps and passes the bounds check, giving an out-of-bounds read. No fff code path calls those methods, so this is hygiene, not an exploitable hole in fff.

Fix

Bump to pyo3 0.29 (resolves 0.29.2) and migrate the API breakage across 0.25-0.29: PyObject -> Py<PyAny>, Python::allow_threads -> Python::detach, Python::with_gil -> Python::attach. Also #[pyclass(skip_from_py_object)] on the result types — 0.29 deprecates the implicit FromPyObject derive for Clone pyclasses and the warning fails clippy -D warnings; nothing extracts these types by value (GrepCursor is taken as &GrepCursor), so skipping is behaviour-neutral and generates less code. No Python-visible API change.

Steps to reproduce

Vulnerable version present on pre-fix main:

git checkout main
grep -n 'pyo3' crates/fff-python/Cargo.toml
# pyo3 = { version = "0.24.0", features = ["extension-module", "abi3-py310"] }
grep -A2 -n '^name = "pyo3"$' Cargo.lock
# Cargo.lock:1866: version = "0.24.2"

gh api /advisories/GHSA-36hh-v3qg-5jq4 \
  --jq '.severity, .vulnerabilities[0].vulnerable_version_range, .vulnerabilities[0].first_patched_version'

Expected: resolved pyo3 >= 0.29.0. Actual (pre-fix): 0.24.2, inside the advisory range:

high
< 0.29.0
0.29.0

Naive bump (issue body's patch, version only) does not build — this is what the source changes here are for:

crates/fff-python/src/finder.rs:277: error[E0412]: cannot find type `PyObject` in this scope
crates/fff-python/src/finder.rs:213: error[E0599]: no method named `allow_threads` found for struct `pyo3::Python<'py>`
crates/fff-python/src/finder.rs:773: error[E0599]: no function or associated item named `with_gil` found for struct `pyo3::Python<'py>`
error: could not compile `fff-python` (lib) due to 25 previous errors; 13 warnings emitted

How verified

cargo clippy --no-default-features --features zlob -- -D warnings   # clean
cargo fmt --all --check                                             # clean
cd packages/fff-python && uv sync --all-extras --no-install-project
uv run maturin develop && uv run pytest -q
# tests/test_finder.py: 17 passed (identical to pre-fix main)

tests/test_watch.py errors 10/11 with watcher never became ready on this macOS box — verified identical on pre-fix main (1 passed, 10 errors both before and after the bump), so it is a local environment issue, not a regression.

Automated triage via Gustav. Honk-Honk 🪿

Summary by CodeRabbit

  • Compatibility

    • Updated Python integration support for the latest PyO3 release.
    • Improved compatibility with current Python context managers and object handling.
  • Performance and Reliability

    • Modernized background-operation handling to release and reacquire Python’s interpreter lock safely.
    • Preserved existing search, scanning, watching, and indexing behavior.

pyo3 < 0.29.0 has an out-of-bounds read in nth/nth_back for PyList and
PyTuple iterators. Migrate the removed/renamed APIs: PyObject -> Py<PyAny>,
Python::allow_threads -> detach, Python::with_gil -> attach, and opt out of
the now-deprecated implicit FromPyObject derive on the result pyclasses
(nothing extracts them by value).

Closes #838
@coderabbitai

coderabbitai Bot commented Aug 30, 2026 •

Copy link
Copy Markdown

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: abc0eea4-eb3e-4e6c-8ee9-d6af2cf4bde5

📥 Commits

Reviewing files that changed from the base of the PR and between be043d7 and 00d126a.

⛔ Files ignored due to path filters (1)
  • Cargo.lock is excluded by !**/*.lock
📒 Files selected for processing (4)
  • crates/fff-python/Cargo.toml
  • crates/fff-python/src/finder.rs
  • crates/fff-python/src/types.rs
  • crates/fff-python/src/watch.rs

Included review availability: Your plan provides up to 10 included reviews per hour; 9 remain after this review.


📝 Walkthrough

Walkthrough

The Python binding crate upgrades PyO3 to 0.29.0. It updates exported class conversion behavior, Python object types, GIL detachment calls, callback attachment, and context-manager signatures.

Changes

PyO3 migration

Layer / File(s) Summary
PyO3 dependency upgrade
crates/fff-python/Cargo.toml
The PyO3 dependency changes from 0.24.0 to 0.29.0. Existing features remain enabled.
Python data contract updates
crates/fff-python/src/types.rs
Exported classes use skip_from_py_object. Mixed-search items use Vec<Py<PyAny>>.
GIL and context-manager API migration
crates/fff-python/src/finder.rs, crates/fff-python/src/watch.rs
Blocking FileFinder operations use py.detach. Watch callbacks use Python::attach. Context-manager parameters use Py<PyAny>.

Estimated code review effort: 3 (Moderate) | ~20 minutes

Merge Risk: ⚪ Minimal · up to 00d12

The PR updates PyO3 to patched 0.29.2 and adapts the binding while preserving its stated behavior; lint, formatting, and finder tests pass, and no actionable merge-blocking risk remains.

Suggested reviewers: dmtrkovalenko

🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (1 warning, 1 inconclusive)

Check name Status Explanation Resolution
Docstring Coverage ⚠️ Warning Docstring coverage is 36.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 30 functions across 3 files. (1 skipped: … Write docstrings for the functions missing them to satisfy the coverage threshold.
Linked Issues check ❓ Inconclusive The PR updates PyO3 to 0.29.0 and applies the required API migrations. Cargo.lock regeneration cannot be verified because Cargo.lock is excluded by the !**/*.lock path filter. Inspect Cargo.lock and confirm that it resolves PyO3 to version 0.29.0 or later.
✅ Passed checks (3 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly identifies the PyO3 dependency upgrade and the security advisory addressed.
Out of Scope Changes check ✅ Passed All reviewed changes support the PyO3 security upgrade and its compatibility migrations. No unrelated changes are shown.
Full details: Docstring Coverage

Explanation

Docstring coverage is 36.67% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 30 functions across 3 files. (1 skipped: 1 unsupported.)

  • Fix all pre-merge checks with AI
✨ Finishing Touches 💡 1
📝 Generate docstrings 💡
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch triage-bot/issue-838

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dmtrKovalenko
dmtrKovalenko merged commit 89e6118 into main Aug 30, 2026
53 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants