Skip to content

path_subscript hardcodes slice length to 4 instead of self->count #9680

Description

@Fuyugithub

Bug Description

In src/path.c, the path_subscript function hardcodes len = 4 when computing slice indices, instead of using self->count (the actual path length).

Location

src/path.c:595

Code

static PyObject *
path_subscript(PyPathObject *self, PyObject *item) {
    ...
    if (PySlice_Check(item)) {
        int len = 4;  // BUG: should be self->count
        Py_ssize_t start, stop, step, slicelength;
        if (PySlice_GetIndicesEx(item, len, &start, &stop, &step, &slicelength) < 0) {

Impact

For paths with more than 4 points:

  • Negative indices resolve incorrectly: path[-1:] on a 100-point path returns the 4th element, not the last
  • Slices beyond index 4 are silently empty or wrong

For paths with fewer than 4 points:

  • path[3:] on a 2-point path allows out-of-bounds access

PoC

from PIL import ImagePath
p = ImagePath.Path([(0,0), (1,1), (2,2), (3,3), (4,4), (5,5)])
print(p[-1:])   # Expected: [(5,5)], Actual: [(3,3)]
print(p[4:])    # Expected: [(4,4), (5,5)], Actual: []

Suggested Fix

Py_ssize_t len = self->count;  // use actual path length

Environment

  • Pillow version: current main
  • Affected: ImagePath.Path.__getitem__ with slice arguments

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions