Skip to content

Fix cookie overflow - #13677

Merged
Dreamsorcerer merged 5 commits into
masterfrom
fix-cookie-overflow
Sep 9, 2026
Merged

Dreamsorcerer merged 5 commits into
masterfrom
fix-cookie-overflow

Conversation

@Dreamsorcerer

Copy link
Copy Markdown
Member

No description provided.

@Dreamsorcerer Dreamsorcerer added backport-3.14 Trigger automatic backporting to the 3.14 release branch by Patchback robot backport-3.15 Trigger automatic backporting to the 3.15 release branch by Patchback robot labels Sep 9, 2026
@psf-chronographer psf-chronographer Bot added the bot:chronographer:provided There is a change note present in this PR label Sep 9, 2026
@codecov

codecov Bot commented Sep 9, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 99.03%. Comparing base (9332972) to head (2f49592).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@           Coverage Diff           @@
##           master   #13677   +/-   ##
=======================================
  Coverage   99.02%   99.03%           
=======================================
  Files         135      135           
  Lines       50894    50940   +46     
  Branches     2674     2677    +3     
=======================================
+ Hits        50400    50446   +46     
  Misses        370      370           
  Partials      124      124           
Flag Coverage Δ
Autobahn 21.94% <10.41%> (-0.02%) ⬇️
CI-GHA 98.92% <100.00%> (+<0.01%) ⬆️
OS-Linux 98.69% <100.00%> (+<0.01%) ⬆️
OS-Windows 97.31% <100.00%> (+<0.01%) ⬆️
OS-macOS 98.18% <100.00%> (-0.01%) ⬇️
Py-3.10 98.12% <100.00%> (+<0.01%) ⬆️
Py-3.11 98.35% <100.00%> (+<0.01%) ⬆️
Py-3.12 98.44% <100.00%> (+<0.01%) ⬆️
Py-3.13 98.42% <100.00%> (-0.01%) ⬇️
Py-3.14 98.46% <100.00%> (+<0.01%) ⬆️
Py-3.14t 97.82% <100.00%> (+<0.01%) ⬆️
Py-pypy-3.11 97.40% <100.00%> (+<0.01%) ⬆️
VM-macos 98.18% <100.00%> (-0.01%) ⬇️
VM-ubuntu 98.69% <100.00%> (+<0.01%) ⬆️
VM-windows 97.31% <100.00%> (+<0.01%) ⬆️
cython-coverage 83.18% <94.44%> (+0.01%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

Comment thread tests/test_cookiejar.py Outdated
Comment thread tests/test_client_functional.py Outdated
@greptile-apps

greptile-apps Bot commented Sep 9, 2026

Copy link
Copy Markdown

Confidence Score: 5/5

Safe to merge based on focused runtime coverage of both corrected failure paths.

The executed before-and-after checks exercised oversized positive and negative cookie expiration values and a cookie-processing exception after response receipt. The updated behavior matched the intended handling, and all focused regression tests passed.

Files Needing Attention: No further files need attention; the exercised changes are in aiohttp/cookiejar.py, aiohttp/client.py, and their focused regression tests.

T-Rex T-Rex Logs

What T-Rex did

  • Ran the CookieJar and in-process client harnesses against the previous and updated implementations, then ran the focused cookiejar and client-functional pytest selections.
  • Observed that the previous implementation raised OverflowError when handling a 309-digit positive Max-Age and retained one acquired connection after the cookie-jar exception.
  • Applied the changes to clamp positive Max-Age to CookieJar.MAX_TIME, immediately expire negative Max-Age, report zero acquired connections after the exception, and allow the follow-up request to complete.
  • Executed the focused regression selections and confirmed all six tests passed, validating the corrected cookie expiration and response cleanup behavior.
  • Cross-validated the changes against the targeted code areas and reviewed the accompanying artifacts to verify the before-and-after overflow handling and cleanup behavior.

View all artifacts

T-Rex Ran code and verified through T-Rex

Reviews (1): Last reviewed commit: "Apply suggestion from @Dreamsorcerer" | Re-trigger Greptile

@codspeed

codspeed Bot commented Sep 9, 2026

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 97 untouched benchmarks
⏩ 83 skipped benchmarks1


Comparing fix-cookie-overflow (2f49592) with master (9332972)

Open in CodSpeed

Footnotes

  1. 83 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports. ↩

@Dreamsorcerer
Dreamsorcerer merged commit 9e08ba0 into master Sep 9, 2026
53 checks passed
@Dreamsorcerer
Dreamsorcerer deleted the fix-cookie-overflow branch September 9, 2026 02:08
@patchback

patchback Bot commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Backport to 3.15: 💚 backport PR created

✅ Backport PR branch: patchback/backports/3.15/9e08ba02abe573ce9e4cc541d4e3c3646adb43a7/pr-13677

Backported as #13678

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

@patchback

patchback Bot commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

Backport to 3.14: 💚 backport PR created

✅ Backport PR branch: patchback/backports/3.14/9e08ba02abe573ce9e4cc541d4e3c3646adb43a7/pr-13677

Backported as #13679

🤖 @patchback
I'm built with octomachinery and
my source is open — https://github.com/sanitizers/patchback-github-app.

Dreamsorcerer added a commit that referenced this pull request Sep 9, 2026
**This is a backport of PR #13677 as merged into master
(9e08ba0).**

---------

Co-authored-by: Sam Bull <git@sambull.org>
Dreamsorcerer added a commit that referenced this pull request Sep 9, 2026
**This is a backport of PR #13677 as merged into master
(9e08ba0).**

---------

Co-authored-by: Sam Bull <git@sambull.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport-3.14 Trigger automatic backporting to the 3.14 release branch by Patchback robot backport-3.15 Trigger automatic backporting to the 3.15 release branch by Patchback robot bot:chronographer:provided There is a change note present in this PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant