open-telemetry / open-telemetry/opentelemetry-lambda

Python layer 0.21.0 + Python 3.14: SystemError importing google._upb._message via google.cloud.pubsub_v1 (Serverless zipped deps)

Open
#2,570 0 comments 2 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
Go
Stars
432
Forks
246
Avg merge
3d 10h
Merged PRs (30d)
47

Description

Describe the bug

After upgrading the OpenTelemetry Python Lambda layer to 0.21.0, our function fails at cold start while otel_wrapper.py imports the handler.

The crash happens when the handler imports google.cloud.pubsub_v1. That import chain loads proto-plus, which then imports the protobuf C extension google._upb._message and raises:

  SystemError: <built-in function __import__> returned a result with an exception set

This started only after the layer bump to 0.21.0 (same function code and same Serverless packaging). Pinning the function dependency protobuf==7.35.1 restores a successful import (newer protobuf 7.36.x pulled by google-cloud-pubsub failed on this runtime).

This looks like a protobuf / google._upb native-extension conflict on Python 3.14: two copies of protobuf on sys.path (layer under /opt/python vs. Serverless zipped deps under /tmp/sls-py-req), and/or an ABI issue of protobuf 7.36.x with CPython 3.14 on Linux aarch64 when the layer wrapper is in the import path.

Steps to reproduce

  1. AWS Lambda, Python 3.14, architecture arm64.
  2. Attach ADOT / OTel Python layer opentelemetry-python-0_21_0 (ARN pattern arn:aws:lambda:<region>:184161586896:layer:opentelemetry-python-0_21_0:1). Handler is wrapped by /opt/python/otel_wrapper.py.
  3. Package application dependencies with Serverless Framework v4 using serverless-python-requirements:
    • pythonRequirements.zip: true (deps extracted at runtime to /tmp/sls-py-req)
    • dockerizePip: non-linux
    • useUv: true
  4. Function depends on google-cloud-pubsub (we use 2.39.2) and imports from google.cloud import pubsub_v1 at module load (not inside the handler).
  5. Do not pin protobuf (let Pub/Sub pull the latest, currently 7.36.x).
  6. Invoke the function (cold start).

What did you expect to see?

The wrapper should import the handler and Pub/Sub (google.cloud.pubsub_v1 / proto / protobuf) without crashing, as with the previous Python layer (pre-0.21.0).

What did you see instead?

Cold-start failure before the handler runs. CloudWatch:

  {
    "errorMessage": "<built-in function __import__> returned a result with an exception set",
    "errorType": "SystemError",
    "stackTrace": [
      "  File \"/var/lang/lib/python3.14/importlib/__init__.py\", line 88, in import_module\n    return _bootstrap._gcd_import(name[level:], package, level)\n",
      "  File \"/opt/python/otel_wrapper.py\", line 61, in <module>\n    handler_module = import_module(modified_mod_name)\n",
      "  File \"/var/task/src/functions/send_data_gcp_function.py\", line 5, in <module>\n    from src.domain.use_cases.send_data_gcp.send_data_gcp_use_case import SendDataGCPUseCase\n",
      "  File \"/var/task/src/domain/use_cases/send_data_gcp/send_data_gcp_use_case.py\", line 12, in <module>\n    from src.services.message.pubsub.producer import GCPProducer\n",
      "  File \"/var/task/src/services/message/pubsub/producer.py\", line 3, in <module>\n    from google.cloud import pubsub_v1\n",
      "  File \"/tmp/sls-py-req/google/cloud/pubsub_v1/__init__.py\", line 17, in <module>\n    from google.cloud.pubsub_v1 import publisher, subscriber, types\n",
      "  File \"/tmp/sls-py-req/google/cloud/pubsub_v1/publisher/client.py\", line 30, in <module>\n    from google.cloud.pubsub_v1 import types\n",
      "  File \"/tmp/sls-py-req/google/cloud/pubsub_v1/types.py\", line 24, in <module>\n    import proto\n",
      "  File \"/tmp/sls-py-req/proto/marshal/compat.py\", line 27, in <module>\n    from google._upb import _message as _message_upb\n"
    ]
  }

What version of collector/language SDK version did you use?

  • Python layer: layer-python/0.21.0 (opentelemetry-python-0_21_0:1)
  • Language SDK bundled in that layer: OpenTelemetry Python 1.44.0 / 0.65b0 (layer-python/0.21.0)
  • Collector layer: not required to reproduce (failure is in the Python wrapper import path). We can attach collector version if useful.

What language layer did you use?

  • Python (opentelemetry-python-0_21_0), AWS Lambda python3.14, arm64.

Additional context
Add any other context about the problem here.

Tip: React with 👍 to help prioritize this issue. Please use comments to provide useful context, avoiding +1 or me too, to help us triage it. Learn more here.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with /opt/python/otel_wrapper.py and follow the reported import chain through producer.py, google.cloud.pubsub_v1, proto, and google._upb._message. Reproduce the Python 3.14 arm64 Lambda cold start with the layer and zipped dependencies, then verify that the compatible dependency and import-path behavior prevents the SystemError without pinning protobuf manually.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, google-cloud, python
Domain
backend, cloud, devops
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.