gh-145261: multiprocessing.shared_memory: fix ShareableList corruption for multi-byte strings and null bytes#145266
Conversation
…and bytes with trailing nulls
ShareableList had two bugs:
1. Used character count len(item) instead of byte count
len(item.encode('utf-8')) for string slot allocation, causing
UnicodeDecodeError with multi-byte UTF-8 characters.
2. Used rstrip(b'\x00') to recover bytes values, which stripped
legitimate trailing null bytes.
Fix uses UTF-8 byte length for string allocation and stores the actual
byte length in the format metadata for bytes values, so retrieval reads
exactly the right number of bytes without needing rstrip.
|
Most changes to Python require a NEWS entry. Add one using the blurb_it web app or the blurb command-line tool. If this change has little impact on Python users, wait for a maintainer to apply the |
The bug where ShareableList stripped trailing null bytes has been fixed in Python 3.15. Update documentation to: - Note the fix with versionchanged directive - Update doctest to show correct behavior (nulls preserved) - Clarify workaround is only needed for Python 3.14 and earlier - Reference both original issue python#106939 and fix issue python#145261 Fixes failing doctest in CI where expected output showed old buggy behavior instead of corrected behavior.
Extended the fix to remove rstrip from strings as well and store actual byte lengths for both strings and bytes in format metadata.
Updated format string assertions and test data to match the new behavior where strings are stored with their actual UTF-8 byte length instead of being padded to 8 bytes minimum.
…servation Added versionchanged directive for Python 3.15 noting that trailing null bytes are now preserved in both strings and bytes. Updated doctest example to show correct behavior and clarified workaround is only needed for 3.14 and earlier.
7dbbe95 to
eb4ce8a
Compare
|
I was working on a consolidation PR (#145488) for the same two bugs and arrived at the same fix approach independently. Closed it in favor of this one. The title should also reference gh-106939, since the null-stripping bug is the older and more-tracked issue. Tests The fix changes observable behavior but the PR doesn't add test coverage for either bug. Here are two test methods covering both, including cross-process verification via def test_shared_memory_ShareableList_trailing_nulls(self):
# gh-106939: ShareableList should preserve trailing null bytes
# in bytes and str values.
sl = shared_memory.ShareableList([
b'\x03\x02\x01\x00\x00\x00',
'?\x00',
b'\x00\x00\x00',
b'',
b'no nulls',
])
self.addCleanup(sl.shm.unlink)
self.addCleanup(sl.shm.close)
self.assertEqual(sl[0], b'\x03\x02\x01\x00\x00\x00')
self.assertEqual(sl[1], '?\x00')
self.assertEqual(sl[2], b'\x00\x00\x00')
self.assertEqual(sl[3], b'')
self.assertEqual(sl[4], b'no nulls')
sl2 = shared_memory.ShareableList(name=sl.shm.name)
self.addCleanup(sl2.shm.close)
self.assertEqual(sl2[0], b'\x03\x02\x01\x00\x00\x00')
self.assertEqual(sl2[1], '?\x00')
self.assertEqual(sl2[2], b'\x00\x00\x00')
self.assertEqual(sl2[3], b'')
self.assertEqual(sl2[4], b'no nulls')
def test_shared_memory_ShareableList_multibyte_utf8(self):
# gh-145261: ShareableList should correctly handle multi-byte
# UTF-8 strings without corruption or spillage.
sl = shared_memory.ShareableList([
'ascii', # 1-byte per char (5 bytes)
'café', # 2-byte char: é (5 bytes)
'中文测试', # 3-byte per char (12 bytes)
'𐀀𐀁', # 4-byte per char (8 bytes)
])
self.addCleanup(sl.shm.unlink)
self.addCleanup(sl.shm.close)
self.assertEqual(sl[0], 'ascii')
self.assertEqual(sl[1], 'café')
self.assertEqual(sl[2], '中文测试')
self.assertEqual(sl[3], '𐀀𐀁')
# Verify cross-process access via name-based attachment.
sl2 = shared_memory.ShareableList(name=sl.shm.name)
self.addCleanup(sl2.shm.close)
self.assertEqual(sl2[0], 'ascii')
self.assertEqual(sl2[1], 'café')
self.assertEqual(sl2[2], '中文测试')
self.assertEqual(sl2[3], '𐀀𐀁')These go in Cross-version compatibility The shared memory layout (offsets, block sizes) is unchanged by this fix. Old writer → new reader returns padded data (same as current release, no regression). New writer → old reader gets exact data, then the old |
Issue
ShareableListhas two issues:len(item)(character count) for string slot allocation instead oflen(item.encode('utf-8'))(byte count), causingUnicodeDecodeErrorwith multi-byte UTF-8 characters.rstrip(b'\x00')to recover bytes values, which strips legitimate trailing null bytes.Reproducer
Fix
Use
len(item.encode('utf-8'))for string slot allocation. For bytes, store the actual byte length in the format metadata so retrieval reads exactly the right number of bytes without needingrstrip(b'\x00').This fix attempts to resolve both the new UTF-8 corruption issue and the long-standing trailing null bytes issue reported in #106939.
Test updates
Two assertions in
test_shared_memory_ShareableList_basicsneeded adjustments since they were based on the previous behavior:bytesvalues.