Skip to content

allow cachebox 6 - #637

Open
braingram wants to merge 2 commits into
qlustered:devfrom
braingram:allow_cachebox_6
Open

braingram wants to merge 2 commits into
qlustered:devfrom
braingram:allow_cachebox_6

Conversation

@braingram

Copy link
Copy Markdown

Closes #601

I saw no usage of API mentioned in the breaking changes for cachebox 6: https://github.com/awolverp/cachebox/releases/tag/v6.0.0

Testing locally with python 3.14 the tests passed except for one:

_______________________________________________________________________________________ TestPicklingSecurity.test_restricted_unpickler_memory_exhaustion_cve ________________________________________________________________________________________

self = <tests.test_serialization.TestPicklingSecurity object at 0x10ba28690>

    @pytest.mark.skipif(sys.platform == "win32", reason="Resource module is Unix-only")
    def test_restricted_unpickler_memory_exhaustion_cve(self):
        """CVE-2026-33155: Prevent DoS via massive allocation through REDUCE opcode.

        The payload calls bytes(10_000_000_000) which is allowed by find_class
        but would allocate ~9.3GB of memory. The fix should reject this before
        the allocation happens.
        """
        import resource

        # 1. Cap memory to 500MB to prevent system freezes during the test
        soft, hard = resource.getrlimit(resource.RLIMIT_AS)
        maxsize_bytes = 500 * 1024 * 1024
>       resource.setrlimit(resource.RLIMIT_AS, (maxsize_bytes, hard))
E       ValueError: current limit exceeds maximum limit

tests/test_serialization.py:241: ValueError

which I suspect is unrelated (and due to the system used for testing).

I wasn't able to run the test suite on python 3.15 since several test/static/dev dependencies (based on the current pins) don't have python 3.15 wheels. However with the changes in this PR I'm able to install deepdiff on python 3.15.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant