cpython/Lib/idlelib
Gregory P. Smith 511ca94520
gh-95778: CVE-2020-10735: Prevent DoS by very large int() (#96499)
Integer to and from text conversions via CPython's bignum `int` type is not safe against denial of service attacks due to malicious input. Very large input strings with hundred thousands of digits can consume several CPU seconds.

This PR comes fresh from a pile of work done in our private PSRT security response team repo.

Signed-off-by: Christian Heimes [Red Hat] <christian@python.org>
Tons-of-polishing-up-by: Gregory P. Smith [Google] <greg@krypto.org>
Reviews via the private PSRT repo via many others (see the NEWS entry in the PR).

<!-- gh-issue-number: gh-95778 -->
* Issue: gh-95778
<!-- /gh-issue-number -->

I wrote up [a one pager for the release managers](https://docs.google.com/document/d/1KjuF_aXlzPUxTK4BMgezGJ2Pn7uevfX7g0_mvgHlL7Y/edit#). Much of that text wound up in the Issue. Backports PRs already exist. See the issue for links.
2022-09-02 09:35:08 -07:00
..
Icons Optimize images by IMGbot (GH-21348) 2022-02-04 15:49:43 +09:00
idle_test gh-95778: CVE-2020-10735: Prevent DoS by very large int() (#96499) 2022-09-02 09:35:08 -07:00
__init__.py
__main__.py
autocomplete_w.py bpo-45193: Restore IDLE completion boxes on Ubuntu (GH-28343) 2021-09-15 03:13:23 -04:00
autocomplete.py bpo-45495: Add 'case' and 'match' to IDLE completions list. (GH-29000) 2021-10-16 18:44:00 -04:00
autoexpand.py bpo-33855: Still more edits and minimal tests for IDLE (GH-7784) 2018-06-19 19:12:52 -04:00
browser.py gh-95411: IDLE - Enable using the module browser with .pyw files (#95397) 2022-07-30 00:42:13 -04:00
calltip_w.py bpo-36176: Fix IDLE autocomplete & calltip popup colors. (#12262) 2019-03-10 20:18:40 -04:00
calltip.py bpo-42416: Use inspect.getdoc for IDLE calltips (GH-23416) 2020-11-20 01:59:11 -05:00
ChangeLog Fix typos in the Lib directory (GH-28775) 2021-10-06 16:13:48 -07:00
codecontext.py bpo-23544: Disable IDLE Stack Viewer when running user code (GH-17163) 2021-01-28 18:13:22 -05:00
colorizer.py bpo-44010: IDLE: colorize pattern-matching soft keywords (GH-25851) 2021-05-19 12:18:10 +03:00
config_key.py bpo-43655: Tkinter and IDLE dialog windows are now recognized as dialogs by window managers on macOS and X Window (#25187) 2021-04-25 13:07:58 +03:00
config-extensions.def
config-highlight.def bpo-17535: IDLE editor line numbers (GH-14030) 2019-07-23 15:22:11 +03:00
config-keys.def bpo-5680: IDLE: Customize running a module (GH-13763) 2019-06-17 22:24:10 -04:00
config-main.def bpo-4630: Add cursor no-blink option for IDLE (GH-16960) 2019-11-13 02:13:33 -05:00
config.py gh-95597: Fix typo in Lib directory files (#95599) 2022-08-03 17:16:15 -04:00
configdialog.py gh-78143: IDLE - fix settings dialog page label. (#96009) 2022-08-15 19:03:56 -04:00
CREDITS.txt gh-83270: Update IDLE's credits (#95528) 2022-08-02 00:23:42 -04:00
debugger_r.py bpo-33065: Fix problem debugging user classes with __repr__ method (GH-24183) 2021-01-10 01:59:47 -05:00
debugger.py bpo-33987: IDLE - use ttk Frame for ttk widgets (GH-11395) 2019-01-02 22:04:06 -05:00
debugobj_r.py
debugobj.py
delegator.py IDLE: Fix typos in docs and comments (GH-13749) 2019-06-03 00:21:15 -04:00
dynoption.py
editor.py gh-95841: IDLE - Revise Windows local doc url (#95845) 2022-08-11 16:54:03 -04:00
extend.txt bpo-32631: IDLE: Enable zzdummy example extension module (GH-14491) 2021-01-05 02:26:43 -05:00
filelist.py bpo-43013: Fix old tkinter module names in idlelib (GH-24326) 2021-01-25 06:33:18 -05:00
format.py bpo-38862: IDLE Strip Trailing Whitespace fixes end newlines (GH-17366) 2019-11-24 16:29:29 -05:00
grep.py bpo-23205: IDLE: Add tests and refactor grep's findfiles (GH-12203) 2019-03-23 07:33:42 -04:00
help_about.py IDLE: Fix docs URL in the About window (#28417) 2022-07-31 16:47:28 -04:00
help.html gh-75500: Add idlelib section to IDLE doc (#95832) 2022-08-09 14:34:42 -04:00
help.py gh-82006: IDLE doc improvements (#94349) 2022-06-27 18:59:26 -04:00
history.py idlelib: replace 'while 1' with 'while True' (#94827) 2022-07-13 21:09:07 -04:00
HISTORY.txt
hyperparser.py idlelib: replace 'while 1' with 'while True' (#94827) 2022-07-13 21:09:07 -04:00
idle.bat Unmark files as executable that can't actually be executed. (GH-15353) 2019-08-20 21:53:59 -07:00
idle.py
idle.pyw
iomenu.py gh-95191: IDLE: Include prompts when saving Shell #95554 2022-08-02 00:10:39 -04:00
macosx.py bpo-46996: IDLE: Drop workarounds for old Tk versions (GH-31962) 2022-03-19 17:14:21 +02:00
mainmenu.py gh-84910: Change 'IDLE Help' to 'IDLE Doc' (#95873) 2022-08-11 16:50:49 -04:00
multicall.py bpo-33855: More edits and new minimal tests for IDLE (GH-7761) 2018-06-18 04:47:59 -04:00
NEWS2x.txt
NEWS.txt gh-65802: IDLE - explain SaveAs and extensions (#95690) 2022-08-04 21:51:14 -04:00
outwin.py bpo-41152: IDLE: always use UTF-8 for standard IO streams (GH-21214) 2020-06-29 20:18:22 -04:00
parenmatch.py bpo-33855: More edits and new minimal tests for IDLE (GH-7761) 2018-06-18 04:47:59 -04:00
pathbrowser.py
percolator.py bpo-37903: IDLE: Shell sidebar with prompts (GH-22682) 2021-04-28 18:27:55 -04:00
pyparse.py bpo-45975: IDLE - Remove extraneous parens (GH-31107) 2022-02-03 14:44:35 -05:00
pyshell.py gh-95191: IDLE: Include prompts when saving Shell #95554 2022-08-02 00:10:39 -04:00
query.py bpo-46630: Fix initial focus of IDLE query dialogs (GH-31112) 2022-02-03 17:06:17 -05:00
README.txt gh-95491: Mention IDLE Issue project in Readme (#95750) 2022-08-08 09:37:43 -04:00
redirector.py bpo-33855: More edits and new minimal tests for IDLE (GH-7761) 2018-06-18 04:47:59 -04:00
replace.py bpo-45975: IDLE - Remove extraneous parens (GH-31107) 2022-02-03 14:44:35 -05:00
rpc.py idlelib: replace 'while 1' with 'while True' (#94827) 2022-07-13 21:09:07 -04:00
run.py idlelib: replace 'while 1' with 'while True' (#94827) 2022-07-13 21:09:07 -04:00
runscript.py bpo-43013: Fix old tkinter module names in idlelib (GH-24326) 2021-01-25 06:33:18 -05:00
scrolledlist.py bpo-33987: IDLE - use ttk Frame for ttk widgets (GH-11395) 2019-01-02 22:04:06 -05:00
search.py IDLE: Fix typos in docs and comments (GH-13749) 2019-06-03 00:21:15 -04:00
searchbase.py bpo-43655: Tkinter and IDLE dialog windows are now recognized as dialogs by window managers on macOS and X Window (#25187) 2021-04-25 13:07:58 +03:00
searchengine.py idlelib: replace 'while 1' with 'while True' (#94827) 2022-07-13 21:09:07 -04:00
sidebar.py bpo-45975: Use walrus operator for some idlelib while loops (GH-31083) 2022-02-02 20:59:24 -05:00
squeezer.py bpo-37903: IDLE: Shell sidebar with prompts (GH-22682) 2021-04-28 18:27:55 -04:00
stackviewer.py bpo-33905: Add test for idlelib.stackview.StackBrowser. (GH-7852) 2018-06-21 22:19:56 -04:00
statusbar.py bpo-33987: Use ttk Label on IDLE statusbar (GH-22941) 2020-10-24 19:32:34 -04:00
textview.py bpo-40443: Remove unused imports in idlelib (GH-19801) 2020-04-29 21:28:51 -04:00
TODO.txt
tooltip.py bpo-43013: Update idlelib code to 3.x (GH-24315) 2021-01-24 14:08:50 -05:00
tree.py bpo-41043: Escape literal part of the path for glob(). (GH-20994) 2020-06-20 11:10:31 +03:00
undo.py IDLE: Fix typos in docs and comments (GH-13749) 2019-06-03 00:21:15 -04:00
util.py gh-84623: Remove unused imports in stdlib (#93773) 2022-06-13 16:28:41 +02:00
window.py bpo-35660: Fix imports in idlelib.window (#11434) 2019-01-06 15:55:52 -05:00
zoomheight.py bpo-37039: Make IDLE's Zoom Height adjust to users' screens (GH-13678) 2019-06-17 15:41:00 -04:00
zzdummy.py bpo-32631: IDLE: Enable zzdummy example extension module (GH-14491) 2021-01-05 02:26:43 -05:00

README.txt: an index to idlelib files and the IDLE menu.

IDLE is Python's Integrated Development and Learning
Environment.  The user documentation is part of the Library Reference and
is available in IDLE by selecting Help => IDLE Help.  This README documents
idlelib for IDLE developers and curious users.

IDLELIB FILES lists files alphabetically by category,
with a short description of each.

IDLE MENU show the menu tree, annotated with the module
or module object that implements the corresponding function.

This file is descriptive, not prescriptive, and may have errors
and omissions and lag behind changes in idlelib.


IDLELIB FILES
=============

Implementation files not in IDLE MENU are marked (nim).

Startup
-------
__init__.py  # import, does nothing
__main__.py  # -m, starts IDLE
idle.bat
idle.py
idle.pyw

Implementation
--------------
autocomplete.py   # Complete attribute names or filenames.
autocomplete_w.py # Display completions.
autoexpand.py     # Expand word with previous word in file.
browser.py        # Create module browser window.
calltip.py        # Create calltip text.
calltip_w.py      # Display calltip.
codecontext.py    # Show compound statement headers otherwise not visible.
colorizer.py      # Colorize text (nim).
config.py         # Load, fetch, and save configuration (nim).
configdialog.py   # Display user configuration dialogs.
config_key.py     # Change keybindings.
debugger.py       # Debug code run from shell or editor; show window.
debugger_r.py     # Debug code run in remote process.
debugobj.py       # Define class used in stackviewer.
debugobj_r.py     # Communicate objects between processes with rpc (nim).
delegator.py      # Define base class for delegators (nim).
dynoption.py      # Define mutable OptionMenu widget (nim)
editor.py         # Define most of editor and utility functions.
filelist.py       # Open files and manage list of open windows (nim).
format.py         # Define format menu options.
grep.py           # Find all occurrences of pattern in multiple files.
help.py           # Display IDLE's html doc.
help_about.py     # Display About IDLE dialog.
history.py        # Get previous or next user input in shell (nim)
hyperparser.py    # Parse code around a given index.
iomenu.py         # Open, read, and write files
macosx.py         # Help IDLE run on Macs (nim).
mainmenu.py       # Define most of IDLE menu.
multicall.py      # Wrap tk widget to allow multiple calls per event (nim).
outwin.py         # Create window for grep output.
parenmatch.py     # Match fenceposts: (), [], and {}.
pathbrowser.py    # Create path browser window.
percolator.py     # Manage delegator stack (nim).
pyparse.py        # Give information on code indentation
pyshell.py        # Start IDLE, manage shell, complete editor window
query.py          # Query user for information
redirector.py     # Intercept widget subcommands (for percolator) (nim).
replace.py        # Search and replace pattern in text.
rpc.py            # Communicate between idle and user processes (nim).
run.py            # Manage user code execution subprocess.
runscript.py      # Check and run user code.
scrolledlist.py   # Define scrolledlist widget for IDLE (nim).
search.py         # Search for pattern in text.
searchbase.py     # Define base for search, replace, and grep dialogs.
searchengine.py   # Define engine for all 3 search dialogs.
sidebar.py        # Define line number and shell prompt sidebars.
squeezer.py       # Squeeze long shell output (nim).
stackviewer.py    # View stack after exception.
statusbar.py      # Define status bar for windows (nim).
tabbedpages.py    # Define tabbed pages widget (nim).
textview.py       # Define read-only text widget (nim).
tooltip.py        # Define popups for calltips, squeezer (nim).
tree.py           # Define tree widget, used in browsers (nim).
undo.py           # Manage undo stack.
util.py           # Define common objects imported elsewhere (nim).
windows.py        # Manage window list and define listed top level.
zoomheight.py     # Zoom window to full height of screen.
zzdummy.py        # Example extension.

Configuration
-------------
config-extensions.def # Defaults for extensions
config-highlight.def  # Defaults for colorizing
config-keys.def       # Defaults for key bindings
config-main.def       # Defaults for font and general tabs

Text
----
CREDITS.txt  # not maintained, displayed by About IDLE
HISTORY.txt  # NEWS up to July 2001
NEWS.txt     # commits, displayed by About IDLE
NEWS2.txt    # commits to Python2
README.txt   # this file, displayed by About IDLE
TODO.txt     # needs review
extend.txt   # about writing extensions
help.html    # copy of idle.html in docs, displayed by IDLE Help

Subdirectories
--------------
Icons        # small image files
idle_test    # files for human test and automated unit tests


IDLE MENUS
==========

Top level items and most submenu items are defined in mainmenu.
Extensions add submenu items when active.  The names given are
found, quoted, in one of these modules, paired with a '<<pseudoevent>>'.
Each pseudoevent is bound to an event handler.  Some event handlers
call another function that does the actual work.  The annotations below
are intended to at least give the module where the actual work is done.
'eEW' = editor.EditorWindow

File
  New File         # eEW.new_callback
  Open...          # iomenu.open
  Open Module      # eEw.open_module
  Recent Files
  Class Browser    # eEW.open_class_browser, browser.ClassBrowser
  Path Browser     # eEW.open_path_browser, pathbrowser
  ---
  Save             # iomenu.save
  Save As...       # iomenu.save_as
  Save Copy As...  # iomenu.save_a_copy
  ---
  Print Window     # iomenu.print_window
  ---
  Close            # eEW.close_event
  Exit             # flist.close_all_callback (bound in eEW)

Edit
  Undo             # undodelegator
  Redo             # undodelegator
  ---              # eEW.right_menu_event
  Cut              # eEW.cut
  Copy             # eEW.copy
  Paste            # eEW.past
  Select All       # eEW.select_all (+ see eEW.remove_selection)
  ---              # Next 5 items use searchengine; dialogs use searchbase
  Find             # eEW.find_event, search.SearchDialog.find
  Find Again       # eEW.find_again_event, sSD.find_again
  Find Selection   # eEW.find_selection_event, sSD.find_selection
  Find in Files... # eEW.find_in_files_event, grep
  Replace...       # eEW.replace_event, replace.ReplaceDialog.replace
  Go to Line       # eEW.goto_line_event
  Show Completions # autocomplete extension and autocompleteWidow (&HP)
  Expand Word      # autoexpand extension
  Show call tip    # Calltips extension and CalltipWindow (& Hyperparser)
  Show surrounding parens  # parenmatch (& Hyperparser)

Format (Editor only) [fFR = format.FormatRegion]
  Format Paragraph # format.FormatParagraph.format_paragraph_event
  Indent Region    # fFR.indent_region_event
  Dedent Region    # fFR.dedent_region_event
  Comment Out Reg. # fFR.comment_region_event
  Uncomment Region # fFR.uncomment_region_event
  Tabify Region    # fFR.tabify_region_event
  Untabify Region  # fFR.untabify_region_event
  Toggle Tabs      # format.Indents.toggle_tabs_event
  New Indent Width # format.Indents.change_indentwidth_event
  Strip tailing whitespace  # format.rstrip
  Zin              # zzdummy
  Zout             # zzdummy

Run (Editor only)
  Run Module         # runscript.ScriptBinding.run_module_event
  Run... Customized  # runscript.ScriptBinding.run_custom_event
  Check Module       # runscript.ScriptBinding.check_module_event
  Python Shell       # pyshell.Pyshell, pyshell.ModifiedInterpreter

Shell  # pyshell
  View Last Restart    # pyshell.PyShell.view_restart_mark
  Restart Shell        # pyshell.PyShell.restart_shell
  Previous History     # history.History.history_prev
  Next History         # history.History.history_next
  Interrupt Execution  # pyshell.PyShell.cancel_callback

Debug (Shell only)
  Go to File/Line  # outwin.OutputWindow.goto_file_line
  debugger         # debugger, debugger_r, PyShell.toggle_debugger
  Stack Viewer     # stackviewer, PyShell.open_stack_viewer
  Auto-open Stack Viewer  # stackviewer

Options
  Configure IDLE   # eEW.config_dialog, config, configdialog (cd)
    (Parts of the dialog)
    Buttons        # cd.ConfigDialog
    Font tab       # cd.FontPage, config-main.def
    Highlight tab  # cd.HighPage, query, config-highlight.def
    Keys tab       # cd.KeysPage, query, config_key, config_keys.def
    Windows tab    # cd.WinPage, config_main.def
    Shell/Ed tab   # cd.ShedPage, config-main.def
    Extensions tab # config-extensions.def, corresponding .py files
  ---
  ... Code Context # codecontext
  ... Line Numbers # sidebar
  Zoomheight       # zoomheight

Window
  <open windows>   # windows

Help
  About IDLE       # eEW.about_dialog, help_about.AboutDialog
  ---
  IDLE Help        # eEW.help_dialog, help.show_idlehelp
  Python Docs      # eEW.python_docs
  Turtle Demo      # eEW.open_turtle_demo
  ---
  <other help sources>

<Context Menu> (right click)
  Defined in editor, PyShell.pyshell
    Cut
    Copy
    Paste
    ---
    Go to file/line (shell and output only)
    Set Breakpoint (editor only)
    Clear Breakpoint (editor only)
  Defined in debugger
    Go to source line
    Show stack frame

<No menu>
Center Insert      # eEW.center_insert_event


OTHER TOPICS
============

Generally use PEP 8.

import statements
-----------------
Put imports at the top, unless there is a good reason otherwise.
PEP 8 says to group stdlib, 3rd-party dependencies, and package imports.
For idlelib, the groups are general stdlib, tkinter, and idlelib.
Sort modules within each group, except that tkinter.ttk follows tkinter.
Sort 'from idlelib import mod1' and 'from idlelib.mod2 import object'
together by module, ignoring within module objects.
Put 'import __main__' after other idlelib imports.

Imports only needed for testing are put not at the top but in an
htest function def or "if __name__ == '__main__'" clause.

Within module imports like "from idlelib.mod import class" may cause
circular imports to deadlock.  Even without this, circular imports may
require at least one of the imports to be delayed until a function call.

What's New entries
------------------

Repository directory Doc/whatsnew/ has a file 3.n.rst for each 3.n
Python version.  For the first entry in each file, add subsection
'IDLE and idlelib', in alphabetical position, to the 'Improved Modules'
section.  For the rest of cpython, entries to 3.(n+1).rst begin with
the release of 3.n.0b1.  For IDLE, entries for features backported from
'main' to '3.n' during its beta period do not got in 3.(n+1).rst.  The
latter usually gets its first entry during the 3.n.0 candidate period
or after the 3.n.0 release.

When, as per PEP 434, feature changes are backported, entries are placed
in the 3.n.rst file *in the main branch* for each Python version n that
gets the backport. (Note: the format of entries have varied between
versions.)  Add a line "New in 3.n maintenance releases." before the
first back-ported feature after 3.n.0 is released. Since each older
version file gets a different number of backports, it is easiest to
make a separate PR for each file and label it with the backports
needed.

Github repository and issues
----------------------------

The CPython repository is https://github.com/python/cpython.  The
IDLE Issues listing is https://github.com/orgs/python/projects/31.
The main classification is by Topic, based on the IDLE menu.  View the
topics list by clicking the [<]] button in the upper right.