@@ -502,13 +502,29 @@ test_byteswriter_ptr(PyObject *Py_UNUSED(module), PyObject *Py_UNUSED(args))
502502}
503503
504504
505+ static PyObject *
506+ bytearray_overflow (PyObject * Py_UNUSED (module ), PyObject * arg )
507+ {
508+ PyObject * bytearray = PyObject_CallOneArg ((PyObject * )& PyByteArray_Type , arg );
509+ if (bytearray == NULL ) {
510+ return NULL ;
511+ }
512+
513+ char * data = PyByteArray_AS_STRING (bytearray );
514+ Py_ssize_t size = PyByteArray_GET_SIZE (bytearray );
515+ data [size ] = '#' ; // Buffer overflow!
516+ return bytearray ;
517+ }
518+
519+
505520static PyMethodDef test_methods [] = {
506521 {"bytes_resize" , bytes_resize , METH_VARARGS },
507522 {"bytes_join" , bytes_join , METH_VARARGS },
508523 {"byteswriter_abc" , byteswriter_abc , METH_NOARGS },
509524 {"byteswriter_resize" , byteswriter_resize , METH_NOARGS },
510525 {"byteswriter_highlevel" , byteswriter_highlevel , METH_NOARGS },
511526 {"test_byteswriter_ptr" , test_byteswriter_ptr , METH_NOARGS },
527+ {"bytearray_overflow" , bytearray_overflow , METH_O },
512528 {NULL },
513529};
514530
0 commit comments