Skip to content

[3.12] gh-158446: Reject float format precision near INT_MAX (GH-158474) - #158479

Merged
Yhg1s merged 2 commits into
python:3.12from
miss-islington:backport-b7b4f3e-3.12
Sep 30, 2026
Merged

Yhg1s merged 2 commits into
python:3.12from
miss-islington:backport-b7b4f3e-3.12

Conversation

@miss-islington

@miss-islington miss-islington commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Formatting a float or complex with a precision within about 1000 of
INT_MAX could crash or produce incorrect output.
PyOS_double_to_string() now raises ValueError("precision too big") for
such precisions, as the format string parsers already do for
precisions above INT_MAX.

The limit applies regardless of presentation type or value, so a few
calls that previously succeeded (inf, nan, or 'g' with such a
precision) now raise as well.
(cherry picked from commit b7b4f3e)

Co-authored-by: Gregory P. Smith 68491+gpshead@users.noreply.github.com

…-158474)

Formatting a float or complex with a precision within about 1000 of
INT_MAX could crash or produce incorrect output.
PyOS_double_to_string() now raises ValueError("precision too big") for
such precisions, as the format string parsers already do for
precisions above INT_MAX.

The limit applies regardless of presentation type or value, so a few
calls that previously succeeded (inf, nan, or 'g' with such a
precision) now raise as well.
(cherry picked from commit b7b4f3e)

Co-authored-by: Gregory P. Smith <68491+gpshead@users.noreply.github.com>
test_format.py does not import import_module on this branch.  Import
INT_MAX from _testcapi directly, as the neighboring test does.
@Yhg1s
Yhg1s merged commit f30b0d1 into python:3.12 Sep 30, 2026
28 checks passed
@miss-islington
miss-islington deleted the backport-b7b4f3e-3.12 branch September 30, 2026 15:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

release-blocker type-bug An unexpected behavior, bug, or error type-security A security issue

Projects

Development

Successfully merging this pull request may close these issues.

3 participants