AI 中文总结
本文针对Python字节码安全开展实证研究,发现PyPI中存在大量含字节码的制品,字节码分析工具鲁棒性差,其行为与源码级行为不一致,且相关发现无法从普通源码复现。
AI 中文摘要
Python包安全在很大程度上是以源码为中心的,但Python运行时可通过.pyc文件、仅编译模块及编组代码对象直接执行字节码,形成了检查-执行差距。本文针对作为安全制品的Python字节码开展实证研究,测量PyPI发行版中的字节码暴露情况,使用版本感知工具评估其实际可分析性,评估CPython运行时在对抗性字节码下的鲁棒性,并测试字节码发现的源码级复现情况。在收集的1034843个PyPI制品中,我们识别出7388个含字节码的制品,包括228578个.pyc文件和28193个制品本地无源码的.pyc文件。针对现代CPython 3.8-3.14字节码,至少1个选定反编译器为204904个范围内文件中的204901个生成了源码,该结果衡量的是生成而非经验证的功能等价性。工具并不鲁棒:观测到的PyPI字节码会触发托管代码异常和超时,而对抗性变异字节码还会导致反编译器出现本地进程故障;这些结果共同产生了17种不同的鲁棒性特征。模糊测试产生了1009个经栈去重的运行时发现,主要由指针解引用症状构成;261组表现出潜在内存损坏特征,且至少91.7%的组达到了超出文档化不安全摄入边界的执行。普通Python源码均无法复现这些结果。因此,字节码是可见的生态系统制品、实际分析目标,也是与安全相关的解释器输入,其行为无需与源码级行为匹配。
英文摘要
Python package security is largely source-centric, yet Python runtimes can execute bytecode directly through .pyc files, compiled-only modules, and marshalled code objects, creating an inspection-execution gap. We present an empirical study of Python bytecode as a security artifact. We measure bytecode exposure in PyPI distributions, evaluate practical analyzability using version-aware tooling, assess CPython runtime robustness under adversarial bytecode, and test source-level reproduction of bytecode findings. Across 1,034,843 collected PyPI artifacts, we identify 7,388 bytecode-containing artifacts, including 228,578 .pyc files and 28,193 artifact-local source-less .pyc files. For modern CPython 3.8-3.14 bytecode, at least one selected decompiler emits source for 204,901 of 204,904 in-scope files, a result measuring emission rather than verified functional equivalence. Tools are non-robust: observed PyPI bytecode triggers managed-code exceptions and timeouts, while adversarial mutated bytecode also drives decompilers into native process failures; together these outcomes yield 17 distinct robustness signatures. Fuzzing produces 1,009 stack-deduplicated runtime findings dominated by pointer-dereference symptoms; 261 groups exhibit potential memory-corruption characteristics, and at least 91.7% of groups reach execution beyond the documented-unsafe ingestion boundary. None reproduce from ordinary Python source. Bytecode is thus a visible ecosystem artifact, a practical analysis target, and a security-relevant interpreter input whose behavior need not match source-level behavior.