Commit 737c67e1 authored by Benjamin Peterson's avatar Benjamin Peterson

check for overflows in permutations() and product() (closes #23363, closes #23364)

parent 9ce2bba5
...@@ -284,6 +284,13 @@ class TestBasicOps(unittest.TestCase): ...@@ -284,6 +284,13 @@ class TestBasicOps(unittest.TestCase):
self.assertEqual(result, list(permutations(values, None))) # test r as None self.assertEqual(result, list(permutations(values, None))) # test r as None
self.assertEqual(result, list(permutations(values))) # test default r self.assertEqual(result, list(permutations(values))) # test default r
@test_support.bigaddrspacetest
def test_permutations_overflow(self):
with self.assertRaises(OverflowError):
permutations("A", 2**30)
with self.assertRaises(OverflowError):
permutations("A", 2, 2**30)
@test_support.impl_detail("tuple reuse is specific to CPython") @test_support.impl_detail("tuple reuse is specific to CPython")
def test_permutations_tuple_reuse(self): def test_permutations_tuple_reuse(self):
self.assertEqual(len(set(map(id, permutations('abcde', 3)))), 1) self.assertEqual(len(set(map(id, permutations('abcde', 3)))), 1)
...@@ -702,6 +709,11 @@ class TestBasicOps(unittest.TestCase): ...@@ -702,6 +709,11 @@ class TestBasicOps(unittest.TestCase):
args = map(iter, args) args = map(iter, args)
self.assertEqual(len(list(product(*args))), expected_len) self.assertEqual(len(list(product(*args))), expected_len)
@test_support.bigaddrspacetest
def test_product_overflow(self):
with self.assertRaises(OverflowError):
product(["a"]*(2**16), repeat=2**16)
@test_support.impl_detail("tuple reuse is specific to CPython") @test_support.impl_detail("tuple reuse is specific to CPython")
def test_product_tuple_reuse(self): def test_product_tuple_reuse(self):
self.assertEqual(len(set(map(id, product('abc', 'def')))), 1) self.assertEqual(len(set(map(id, product('abc', 'def')))), 1)
......
...@@ -18,6 +18,10 @@ Core and Builtins ...@@ -18,6 +18,10 @@ Core and Builtins
Library Library
------- -------
- Issue #23363: Fix possible overflow in itertools.permutations.
- Issue #23364: Fix possible overflow in itertools.product.
- Issue #23365: Fixed possible integer overflow in - Issue #23365: Fixed possible integer overflow in
itertools.combinations_with_replacement. itertools.combinations_with_replacement.
......
...@@ -1842,8 +1842,17 @@ product_new(PyTypeObject *type, PyObject *args, PyObject *kwds) ...@@ -1842,8 +1842,17 @@ product_new(PyTypeObject *type, PyObject *args, PyObject *kwds)
} }
} }
assert(PyTuple_Check(args)); assert(PyTuple_CheckExact(args));
nargs = (repeat == 0) ? 0 : PyTuple_GET_SIZE(args); if (repeat == 0) {
nargs = 0;
} else {
nargs = PyTuple_GET_SIZE(args);
if (repeat > PY_SSIZE_T_MAX/sizeof(Py_ssize_t) ||
nargs > PY_SSIZE_T_MAX/(repeat * sizeof(Py_ssize_t))) {
PyErr_SetString(PyExc_OverflowError, "repeat argument too large");
return NULL;
}
}
npools = nargs * repeat; npools = nargs * repeat;
indices = PyMem_Malloc(npools * sizeof(Py_ssize_t)); indices = PyMem_Malloc(npools * sizeof(Py_ssize_t));
...@@ -2603,6 +2612,11 @@ permutations_new(PyTypeObject *type, PyObject *args, PyObject *kwds) ...@@ -2603,6 +2612,11 @@ permutations_new(PyTypeObject *type, PyObject *args, PyObject *kwds)
goto error; goto error;
} }
if (n > PY_SSIZE_T_MAX/sizeof(Py_ssize_t) ||
r > PY_SSIZE_T_MAX/sizeof(Py_ssize_t)) {
PyErr_SetString(PyExc_OverflowError, "parameters too large");
goto error;
}
indices = PyMem_Malloc(n * sizeof(Py_ssize_t)); indices = PyMem_Malloc(n * sizeof(Py_ssize_t));
cycles = PyMem_Malloc(r * sizeof(Py_ssize_t)); cycles = PyMem_Malloc(r * sizeof(Py_ssize_t));
if (indices == NULL || cycles == NULL) { if (indices == NULL || cycles == NULL) {
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment