fix: reject out-of-range integers on write and search instead of silently truncating - #52
Merged
Merged
Conversation
A fixed-width ctypes integer setter silently wraps an out-of-range value
(e.g. 2**40 into a 4-byte slot stores 0), so write_int(addr, 2**40) used to
report success while writing 0, and search_by_value(int, value=2**40) used to
encode the target as 0 and quietly match every zeroed slot.
Add _check_int_fits() and apply it at every numeric coercion point:
- prepare_write (signed/generic write path),
- AbstractProcess._write_unsigned (unsigned helpers; replaces int.to_bytes'
cryptic OverflowError with the same clear ValueError),
- value_to_bytes (search-target encoder).
The accepted window is the union of the signed and unsigned ranges for the
requested width, so values in either representation (0xFFFFFFFF == -1 for a
4-byte field) stay valid; only values that genuinely cannot be encoded are
rejected. Also pins that a write to an unmapped address still raises OSError.
The NOT_VALUE_BETWEEN comparison had implementations on both the typed-int fast path and the bytewise fallback but no test. Add cases for both, including a signed negative endpoint, equivalent under the NumPy and pure-Python paths.
value_types (the scanner-panel parse/format layer) and CheatEntry's JSON round-trip were untested pure logic. Cover parsing/length-inference for every value type and the cheat-table serialization contract, without constructing the polling-thread widgets that make UI teardown flaky.
Point setup/test/lint/type-check at the existing make targets (single source of truth) and add a "before you push" note for `make pre-commit`. Also fix the stale claim that macOS is excluded from CI — the matrix runs it.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
A fixed-width
ctypesinteger setter silently wraps an out-of-range value(e.g.
2**40into a 4-byte slot stores0). As a result:write_int(addr, 2**40)reported success while actually writing0—silent corruption of the target's memory.
search_by_value(int, value=2**40)encoded the target as0and quietlymatched every zeroed slot in memory instead of erroring.
write_uint, …) raised, but withint.to_bytes'cryptic
OverflowError("int too big to convert") instead of a clear error.This adds a single range check (
_check_int_fits) applied at every numericcoercion point, so an out-of-range integer fails fast with an actionable
ValueErroreverywhere:prepare_writewrite_int,write_short, …)AbstractProcess._write_unsignedwrite_uint, …)value_to_bytessearch_by_value/_between)RemotePointer.valuesetterwrite_process_memoryThe accepted window is the union of the signed and unsigned ranges for the
requested width, so a value in either representation stays valid (
0xFFFFFFFFin a 4-byte field is the bit pattern of
-1); only values that genuinelycannot be encoded in that width are rejected.
Also included
to an unmapped address still raises
OSError.NOT_VALUE_BETWEENscan coverage (typed-int fast path + bytewisefallback), which previously had implementations but no test.
value_typesparse/format layer andthe
CheatEntryJSON round-trip (previously untested pure logic).and fix the stale note claiming macOS is excluded from CI.
Testing
Full suite green, including the slow self-process integration tests:
428 passed, flake8 clean,mypy PyMemoryEditorclean.