fix(code-runtime-python): bind str for dispatch's rejection message conversion

The review's remaining non-blocking suggestion: dispatch's call_failure(str(exc))
resolved the builtin str at call time, so a program rebinding __main__.str could
run a hostile callable when the binding-rejection message is formatted. Bind
_str into _run locals and use it in dispatch.
This commit is contained in:
Chinesezjc 2026-08-25 13:01:39 +08:00 • committed by Tianyi Cui
parent 937ada4837
commit ac64039843
2 changed files with 6 additions and 2 deletions

View file

@ -753,6 +753,10 @@ async def _run(channel: ProtocolChannel) -> None:
# assignment RHS resolves the module global, not an unbound local.
_RuntimeError_cls = RuntimeError
_BindingRejection_cls = _BindingRejection
# `str` for dispatch's rejection conversion is likewise bound: a program
# rebinding `__main__.str` would otherwise run a hostile callable when the
# binding-rejection message is formatted.
_str = str
# 1. Boot handshake.
boot = channel.read_frame()
if boot is None or boot.get("type") != "boot":
@ -917,7 +921,7 @@ async def _run(channel: ProtocolChannel) -> None:
try:
return await fut
except _BindingRejection_cls as exc:
raise call_failure(str(exc)) from None
raise call_failure(_str(exc)) from None
namespaces: dict[str, Any] = {}
for entry in boot["namespaces"]:

View file

@ -690,7 +690,7 @@ describe('PythonCodeRuntime — programs and bindings', () => {
'try:',
' await tools.fail({})',
'except RuntimeError as e:',
' caught = str(e)',
' caught = e.args[0] if e.args else ""',
'except Exception as e:',
' caught = "WRONG TYPE: " + type(e).__name__',
'return caught',