diff options
author | Serhiy Storchaka <storchaka@gmail.com> | 2016-12-02 06:42:43 (GMT) |
---|---|---|
committer | Serhiy Storchaka <storchaka@gmail.com> | 2016-12-02 06:42:43 (GMT) |
commit | daf82f7539218eb03385b51bffaceb6970fc76d8 (patch) | |
tree | 4e93f41e99f44087bec6f6f7b1498b473f43a259 /Objects | |
parent | 9bd44d6dab214ab17c5505aa445388ccf8695c87 (diff) | |
download | cpython-daf82f7539218eb03385b51bffaceb6970fc76d8.zip cpython-daf82f7539218eb03385b51bffaceb6970fc76d8.tar.gz cpython-daf82f7539218eb03385b51bffaceb6970fc76d8.tar.bz2 |
Issue #5322: Fixed setting __new__ to a PyCFunction inside Python code.
Original patch by Andreas Stührk.
Diffstat (limited to 'Objects')
-rw-r--r-- | Objects/typeobject.c | 28 |
1 files changed, 27 insertions, 1 deletions
diff --git a/Objects/typeobject.c b/Objects/typeobject.c index 932f9e9..69a996a 100644 --- a/Objects/typeobject.c +++ b/Objects/typeobject.c @@ -6304,7 +6304,33 @@ update_one_slot(PyTypeObject *type, slotdef *p) sanity checks and constructing a new argument list. Cut all that nonsense short -- this speeds up instance creation tremendously. */ - specific = (void *)type->tp_new; + PyObject *self = PyCFunction_GET_SELF(descr); + if (!self || !PyType_Check(self)) { + /* This should never happen because + tp_new_wrapper expects a type for self. + Use slot_tp_new which will call + tp_new_wrapper which will raise an + exception. */ + specific = (void *)slot_tp_new; + } + else { + specific = ((PyTypeObject *)self)->tp_new; + /* Check that the user does not do anything + silly and unsafe like object.__new__(dict). + To do this, we check that the most derived + base that's not a heap type is this type. */ + PyTypeObject *staticbase = type->tp_base; + while (staticbase && + (staticbase->tp_flags & Py_TPFLAGS_HEAPTYPE)) + staticbase = staticbase->tp_base; + if (staticbase && + staticbase->tp_new != specific) + /* Seems to be unsafe, better use + slot_tp_new which will call + tp_new_wrapper which will raise an + exception if it is unsafe. */ + specific = (void *)slot_tp_new; + } /* XXX I'm not 100% sure that there isn't a hole in this reasoning that requires additional sanity checks. I'll buy the first person to |