Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

gh-136234: Fix _SelectorSocketTransport.writelines to be robust to connection loss#136743

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Merged
kumaraditya303 merged 2 commits intopython:mainfrombmerry:fix-gh-136234
Sep 8, 2025

Conversation

@bmerry
Copy link
Contributor

@bmerrybmerry commentedJul 17, 2025
edited by bedevere-appbot
Loading

@python-cla-bot
Copy link

python-cla-botbot commentedJul 17, 2025
edited
Loading

All commit authors signed the Contributor License Agreement.

CLA signed

@bmerry
Copy link
ContributorAuthor

I've previously signed the CLA on behalf of my organisation, but my work email address has changed since then (same employer though). Is there a process to reuse that form, or do I need to sign a new one? Alternatively, I can rewrite my commits to use that old email address (it still works, just deprecated).

@kumaraditya303
Copy link
Contributor

do I need to sign a new one?

You need to sign again with the new email.

@bmerry
Copy link
ContributorAuthor

do I need to sign a new one?

You need to sign again with the new email.

Ok, will do. Might take a few days to run it past my employer.

@kumaraditya303kumaraditya303 added needs backport to 3.13bugs and security fixes needs backport to 3.14bugs and security fixes type-bugAn unexpected behavior, bug, or error labelsJul 21, 2025
@bmerry
Copy link
ContributorAuthor

@kumaraditya303 thanks for reviewing. The CLA has had to go to our IP people (even though I've previously signed it with a different email address), so there may be a delay. I'm hoping not longer than a week or two.

@kumaraditya303
Copy link
Contributor

Okay, ping me when the CLA is done and I'll merge it, thanks!

@bmerry
Copy link
ContributorAuthor

Okay, ping me when the CLA is done and I'll merge it, thanks!

@kumaraditya303 I've filled in the form (had to use the Adobe eSign process since it's on behalf of an organisation). So it's now just waiting for the PSF to process it. I don't know if I get a notification when that's complete, but if I do I'll ping you again.

@bmerry
Copy link
ContributorAuthor

@kumaraditya303 any idea how long it's supposed to take for a CLA signed on behalf of an organisation to be processed? I submitted the form more than 2 weeks ago and haven't seen anything about it since.

@kumaraditya303
Copy link
Contributor

any idea how long it's supposed to take for a CLA signed on behalf of an organisation to be processed? I submitted the form more than 2 weeks ago and haven't seen anything about it since.

You need to sign the CLA with the new email as well independent of organization signing.

@bmerry
Copy link
ContributorAuthor

any idea how long it's supposed to take for a CLA signed on behalf of an organisation to be processed? I submitted the form more than 2 weeks ago and haven't seen anything about it since.

You need to sign the CLA with the new email as well independent of organization signing.

The form says "If you wish to sign a Contributor Agreement on behalf of an organization or to use a different Initial License, please use the manual form instead" (note theinstead). Presumably it must be possible to not do the automatic form since that only caters to one of the possible initial licenses. I'll follow up with the PSF to check what's happening.

@bmerry
Copy link
ContributorAuthor

any idea how long it's supposed to take for a CLA signed on behalf of an organisation to be processed? I submitted the form more than 2 weeks ago and haven't seen anything about it since.

You need to sign the CLA with the new email as well independent of organization signing.

The form says "If you wish to sign a Contributor Agreement on behalf of an organization or to use a different Initial License, please use the manual form instead" (note theinstead). Presumably it must be possible to not do the automatic form since that only caters to one of the possible initial licenses. I'll follow up with the PSF to check what's happening.

@kumaraditya303 I've had no reply from the PSF, so for expediency I've signed the CLA as an individual so that the CLAbot will be happy. This contribution is made on behalf of my employer, for which I've completed the manual form.

@kumaraditya303kumaraditya303 merged commit7d435cf intopython:mainSep 8, 2025
51 checks passed
@miss-islington-app
Copy link

Thanks@bmerry for the PR, and@kumaraditya303 for merging it 🌮🎉.. I'm working now to backport this PR to: 3.13, 3.14.
🐍🍒⛏🤖

miss-islington pushed a commit to miss-islington/cpython that referenced this pull requestSep 8, 2025
…t to connection loss (pythonGH-136743)(cherry picked from commit7d435cf)Co-authored-by: Bruce Merry <1963944+bmerry@users.noreply.github.com>
miss-islington pushed a commit to miss-islington/cpython that referenced this pull requestSep 8, 2025
…t to connection loss (pythonGH-136743)(cherry picked from commit7d435cf)Co-authored-by: Bruce Merry <1963944+bmerry@users.noreply.github.com>
@bedevere-app
Copy link

GH-138673 is a backport of this pull request to the3.14 branch.

@bedevere-appbedevere-appbot removed the needs backport to 3.14bugs and security fixes labelSep 8, 2025
@bedevere-app
Copy link

GH-138674 is a backport of this pull request to the3.13 branch.

@bedevere-appbedevere-appbot removed the needs backport to 3.13bugs and security fixes labelSep 8, 2025
@bmerrybmerry deleted the fix-gh-136234 branchSeptember 8, 2025 16:14
@bmerry
Copy link
ContributorAuthor

Are there any security grounds for a 3.12 backport? If an attacker can figure out how to win this race condition, they could potentially DoS a server that is not expecting an AttributeError. I guess typically that would just crash the asyncio Task that's handling the connection and the server would survive.

kumaraditya303 pushed a commit to miss-islington/cpython that referenced this pull requestSep 9, 2025
…t to connection loss (pythonGH-136743)(cherry picked from commit7d435cf)Co-authored-by: Bruce Merry <1963944+bmerry@users.noreply.github.com>
kumaraditya303 added a commit to kumaraditya303/cpython that referenced this pull requestSep 9, 2025
@bedevere-app
Copy link

GH-138702 is a backport of this pull request to the3.14 branch.

1 similar comment
@bedevere-app
Copy link

GH-138702 is a backport of this pull request to the3.14 branch.

lkollar pushed a commit to lkollar/cpython that referenced this pull requestSep 9, 2025
kumaraditya303 added a commit that referenced this pull requestOct 7, 2025
miss-islington pushed a commit to miss-islington/cpython that referenced this pull requestOct 7, 2025
…e robust to connection loss (pythonGH-136743) (pythonGH-138702)(cherry picked from commit5cd6cfe)Co-authored-by: Kumar Aditya <kumaraditya@python.org>
kumaraditya303 added a commit that referenced this pull requestOct 7, 2025
…st to connection loss (GH-136743) (GH-138702) (#139710)[3.14]gh-136234: Fix `SelectorSocketTransport.writelines` to be robust to connection loss (GH-136743) (GH-138702)(cherry picked from commit5cd6cfe)Co-authored-by: Kumar Aditya <kumaraditya@python.org>
Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

@kumaraditya303kumaraditya303kumaraditya303 approved these changes

@1st11st1Awaiting requested review from 1st11st1 is a code owner

@asvetlovasvetlovAwaiting requested review from asvetlovasvetlov is a code owner

@willingcwillingcAwaiting requested review from willingcwillingc is a code owner

Assignees

No one assigned

Labels

topic-asynciotype-bugAn unexpected behavior, bug, or error

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

_SelectorSocketTransport.writelines does not protect against connection lost

2 participants

@bmerry@kumaraditya303

[8]ページ先頭

©2009-2025 Movatter.jp