Skip to content

HMAC.copy() does not correctly copy its attributes #142451

Description

@YuanchengJiang

Crash report

What happened?

import hmac
import hashlib

h = hmac.HMAC(b'key', digestmod=hashlib.sha256)
h_copy = h.copy()
print(h_copy.name)
python: ../Modules/_hashopenssl.c:610: const char *get_asn1_utf8name_by_nid(int): Assertion `ERR_peek_last_error() != 0' failed

CPython versions tested on:

CPython main branch

Operating systems tested on:

Linux

Output from running 'python -VV' on the command line:

No response

Linked PRs

Activity

  1. added
    type-crashA hard crash of the interpreter, possibly with a core dump
    on Dec 9, 2025
  2. yihong0618 commented on Dec 9, 2025

    @yihong0618
    Contributor

    macos works fine

    python3.14 works fine

    it happens in linux main

    errror

    Traceback (most recent call last):
      File "/home/yihong/cpython/ttt.py", line 6, in <module>
        print(h_copy.name)
              ^^^^^^^^^^^
      File "/home/yihong/cpython/Lib/hmac.py", line 157, in name
        return self._hmac.name
               ^^^^^^^^^^^^^^^
    ValueError: [object identifier routines] unknown nid
    

    seems with openssl problen

    yihong@ubuntu:~/cpython$ openssl version
    OpenSSL 3.3.1 4 Jun 2024 (Library: OpenSSL 3.3.1 4 Jun 2024)

  3. yihong0618 commented on Dec 9, 2025

    @yihong0618
    Contributor

    bisect this commit bring this issue

    cc @picnixz

    b9c50b4

  4. self-assigned this
    on Dec 9, 2025
  5. picnixz commented on Dec 9, 2025

    @picnixz
    Member

    OK, I know the issue. I forgot to copy the evp_md_nid in hmac.copy so it get initialized to 0, which leads to a crash. Thanks for catching this!

    Note: I'm actually surprised that the error indicator is not set in this case, because it goes against OpenSSL docs actually:

    OBJ_nid2obj(), OBJ_nid2ln() and OBJ_nid2sn() convert the NID n to an ASN1_OBJECT structure, its long name and its short name respectively, or NULL if an error occurred.

  6. picnixz commented on Dec 9, 2025

    @picnixz
    Member

    So actually we have two issues:

    • On some OpenSSL versions it seems that OBJ_nid2obj may return NULL without an error indicator set (which is a bit weird though but I guess I can also remove the assertion, it could have been a too strict guard).
    • The copy is lacking the NID because I forgot to copy the field as well...
  7. yihong0618 commented on Dec 10, 2025

    @yihong0618
    Contributor

    So actually we have two issues:

    • On some OpenSSL versions it seems that OBJ_nid2obj may return NULL without an error indicator set (which is a bit weird though but I guess I can also remove the assertion, it could have been a too strict guard).
    • The copy is lacking the NID because I forgot to copy the field as well...

    yes different OpenSSL version behavior

  8. added 2 commits that reference this issue on Dec 10, 2025
  9. picnixz commented on Dec 14, 2025

    @picnixz
    Member

    Thank you for the report!

  10. changed the title [-]Assertion failure at Modules/_hashopenssl.c:610 `const char *get_asn1_utf8name_by_nid(int): Assertion 'ERR_peek_last_error() != 0' failed.`[/-] [+]HMAC.copy() does not correctly copy its attributes[/+] on Dec 14, 2025
  11. added
    stdlibStandard Library Python modules in the Lib/ directory
    and removed
    3.15bugs and security fixes
    on Dec 14, 2025
  12. picnixz commented on Dec 14, 2025

    @picnixz
    Member

    I'm going to re-use this issue for the lack of block_size in HMAC.copy as well.

  13. added 4 commits that reference this issue on Dec 14, 2025
  14. added a commit that references this issue on Dec 16, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

extension-modulesC modules in the Modules dirstdlibStandard Library Python modules in the Lib/ directorytype-crashA hard crash of the interpreter, possibly with a core dump

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions