Visitar URL original
Return EBADF for negative stat file descriptors by youknowdot · Pull Request #9008 · RustPython/RustPython · GitHub
Skip to content

Return EBADF for negative stat file descriptors - #9008

Draft
youknowdot wants to merge 3 commits into
RustPython:mainfrom
youknowdot:fix-negative-fstat-descriptors
Draft

youknowdot wants to merge 3 commits into
RustPython:mainfrom
youknowdot:fix-negative-fstat-descriptors

Conversation

@youknowdot

Copy link
Copy Markdown
Contributor

Summary

Extract the negative-descriptor fstat guard from #8954 for the Python 3.14 main branch.

os.stat(-5) and os.fstat(-5) can reach rustix with an invalid ordinary descriptor and panic in debug builds. Return EBADF at the shared non-Windows fstat boundary before calling rustix. Add an interpreter regression covering several negative values, including numbers used as directory-descriptor sentinels elsewhere.

This is a four-line implementation change plus one new Rust integration test. Directory-fd parsing and canonical Python tests are unchanged. It is independent of the closerange/termination fixes in #9006.

Validation

Fresh main-based validation on Linux, with source/runtime identity checked:

  • Unpatched main panics on the focused probe and the exact new integration test; the split passes both.
  • Normal commit hooks and strict workspace/C-API Clippy passed.
  • Workspace tests: 1,353 passed, 18 existing ignored. Separate C-API tests: 116 passed, 4 existing ignored.
  • Dev and production-feature release builds passed. Both return EBADF for the tested negative descriptors and preserve valid/closed-fd behavior and six existing supported directory-fd cases.
  • The explicit 22-test canonical selection passed in both builds, with eight unchanged platform/implementation skips. The release test_os fstat selection also passed through cargo run.

The initial broader FileTests run aborts in the separate test_closerange case. The same case aborts on unpatched main; #9006 addresses it. That failed result is retained, and the successful selection excludes that case without changing tests or adding skips. Full local test_os remains unrun because its asyncio setup requires the sandbox-denied AF_UNIX socketpair. Hosted tests remain enabled; cross-platform CI is pending.

The runtime is main's Python 3.14.alpha. Any CPython comparison used the available 3.15.0rc3 interpreter, not a CPython 3.14 build.

AI assistance

Codex assisted with implementation, extraction, source review, regression tests, and automated validation. The original implementation authorship and Assisted-by trailer are preserved; the regression commit also includes its disclosure.

Return EBADF for negative ordinary descriptors before calling rustix, avoiding debug-build assertions on canonical invalid-fd tests. Keep directory-fd sentinel and absolute-path handling unchanged.

Assisted-by: Codex:model-version-unavailable
Exercise ordinary negative descriptors including values accepted by rustix as directory sentinels, without changing canonical tests or directory-fd parsing.

Assisted-by: Codex:model-version-unavailable
@coderabbitai

coderabbitai Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Comment thread tests/negative_fstat.rs Outdated

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

do not add python test code in rust file

Preserve the original Unix RustPython-only coverage and every regression assertion while removing the redundant Rust interpreter wrapper. CPython uses -1 as a path sentinel, so keep this regression scoped to its original runtime.

Assisted-by: Codex:model-version-unavailable
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants