Visitar URL original
gh-158952: Reject read-only buffers before reading in _pyio by emerardd · Pull Request #158953 · python/cpython · GitHub
Skip to content

gh-158952: Reject read-only buffers before reading in _pyio - #158953

Open
emerardd wants to merge 4 commits into
python:mainfrom
emerardd:fix/gh-158952-readinto-readonly
Open

emerardd wants to merge 4 commits into
python:mainfrom
emerardd:fix/gh-158952-readinto-readonly

Conversation

@emerardd

@emerardd emerardd commented Oct 7, 2026 •

Copy link
Copy Markdown

Passing a read-only destination to _pyio.BytesIO.readinto() or readinto1() currently consumes input before raising TypeError. The C implementation rejects the argument without moving the stream position. For example, readinto(b"xxx") on _pyio.BytesIO(b"abcdef") raises but leaves only b"def" unread.

Check the destination memoryview's readonly flag in BufferedIOBase._readinto() before calling read() or read1(). This prevents the pure Python fallback from consuming input on an invalid destination.

The shared C/Python BytesIO regression test covers both methods, bytes and read-only memoryviews, empty destinations, and initial positions at the beginning, near EOF, and beyond EOF. It checks both the position and the remaining input after the error.

Validation on a locally built Windows x64 debug CPython 3.16.0a0 at main 2639fd65ff8e0c1949c480a8e670fe9c2467a1f8:

  • Before the fix, the C test passes and the Python test fails eight subcases.
  • With the fix, both tests pass.
  • python_d.exe -m test -v test_io: 1,043 tests run, 35 skipped, success.
  • Ruff 0.15.17 and git diff --check pass.

Linux and macOS validation has not been run locally.

Fixes #158952.

Comment thread Lib/_pyio.py
Comment thread Lib/test/test_io/test_memoryio.py Outdated
Comment on lines +573 to +575
for method in ("readinto", "readinto1"):
for buffer in (b"xxx", memoryview(b"xxx"),
b"", memoryview(b"")):

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Use support.subTests() for parametrizing the method and buffer. It would be easier.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Updated the test to use support.subTests() in 3831e0c, keeping all parameter combinations. The full test_io suite passes.

Comment thread Lib/test/test_io/test_memoryio.py Outdated

@cmaloney cmaloney left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Overall looking good to me, I think the test should go a more general location for buffered I/O classes

b"xxx", memoryview(b"xxx"), b"", memoryview(b""),
))
@support.subTests("position", (0, 4, 10))
def test_readinto_readonly_buffer(self, method, buffer, position):

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this would fit better in test_bufferedio. Goal for me is to test all the Buffered I/O implementations readinto a readonly buffer doesn't advance. That the others implement it right already is nice, but a good thing to make sure we keep.

test_general IOTest would also work well as a spot but I don't like it quite as much just because it keeps adding to the big ball of general tests.

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks! Added a shared test in BufferedReaderTest in f46989f, covering both BufferedReader and BufferedRandom in the C and Python implementations. It checks readinto and readinto1, readonly bytes and memoryviews, and both prefilled and unfilled read buffers. The test verifies that the failed call preserves the logical position and subsequent readable data. I retained the BytesIO regression test to cover the original bug directly.

The shared test uses nonempty targets with data remaining: the Python buffered readers currently return 0 for empty targets or at EOF, whereas the C implementations reject them. The existing BytesIO regression still covers those edge cases.

The full test_io suite passes (1,047 tests, 35 skipped).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

_pyio.BytesIO.readinto() advances the stream when passed a read-only buffer

3 participants