python / python/cpython

python coredump with libffi 3.4.2

未关闭
#118,171 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

type-crash
主要语言
Python
星标
77.2k
派生
36k
PR 合并指标
PR 指标待抓取

描述

Bug report

Bug description:

I encountered a core dump and the backtrace shows that it relates to ctypes:

#0  0x00007f2b0071bf71 in closure_fcn (cif=0x7f2adcd88de8, resp=0x7ffeeb800a10, args=0x7ffeeb800890, userdata=0x3b) at /usr1/python/python/target/checkout/Python-3.9.11/Modules/_ctypes/callbacks.c:311
#1  0x00007f2b0072ba09 in ffi_closure_unix64_inner () from /path/to/python/lib/python3.9/lib-dynload/_ctypes.cpython-39-x86_64-linux-gnu.so
#2  0x00007f2b0072c1e8 in ffi_closure_unix64 () from /path/to/python/lib/python3.9/lib-dynload/_ctypes.cpython-39-x86_64-linux-gnu.so
#3  0x00007f2add597c13 in LLVMPYObjectCache::notifyObjectCompiled (this=0x3382350, M=0x324a370, MBR=...) at executionengine.cpp:195
#4  0x00007f2adea3e18b in llvm::MCJIT::emitObject(llvm::Module*) [clone .localalias] () from /path/to/python/lib/python3.9/site-packages/llvmlite/binding/libllvmlite.so
#5  0x00007f2adea3ea39 in llvm::MCJIT::generateCodeForModule(llvm::Module*) [clone .localalias] () from /path/to/python/lib/python3.9/site-packages/llvmlite/binding/libllvmlite.so
#6  0x00007f2adea39f30 in llvm::MCJIT::finalizeObject() [clone .localalias] () from /path/to/python/lib/python3.9/site-packages/llvmlite/binding/libllvmlite.so
#7  0x00007f2add5975f5 in LLVMPY_FinalizeObject (EE=0x3335f80) at executionengine.cpp:63
#8  0x00007f2b0072c052 in ffi_call_unix64 () from /path/to/python/lib/python3.9/lib-dynload/_ctypes.cpython-39-x86_64-linux-gnu.so
#9  0x00007f2b0072b428 in ffi_call_int () from /path/to/python/lib/python3.9/lib-dynload/_ctypes.cpython-39-x86_64-linux-gnu.so
#10 0x00007f2b0072b491 in ffi_call () from /path/to/python/lib/python3.9/lib-dynload/_ctypes.cpython-39-x86_64-linux-gnu.so

I changed nothing but the version of libffi from 3.3 to 3.4.2, while it runs ok with version 3,3.
I compile libffi and recompiling python with it:

# compile libffi
./configure --prefix=/path/to/libffi/ CFLAGS="-fPIC" --disable-shared --disable-docs
make && make install

# compile python with libffi
sed -i '/Linux\*|GNU\*) LINKFORSHARED=/ s/="/&-pie /' configure
./configure CFLAGS="-fstack-protector-strong -fPIC -D_FORTIFY_SOURCE=2 -O2" LDFLAGS="-L/path/to/libffi/lib64 -Bstatic -Wl,--build-id=none,-z,noexecstack,-z,relro,-z,now" LIBS="-lffi"
make && make install

I also run unittest of ctypes as ctypes unittest crashes with libffi 3.4.2,

test_callbacks (ctypes.test.test_as_parameter.AsParamPropertyWrapperTestCase) ... Aborted (core dumped)

it cored as follows:



#0  0x00007fa96efcc77b in raise () from /usr/lib64/libc.so.6
#1  0x00007fa96efcdaa1 in abort () from /usr/lib64/libc.so.6
#2  0x00007fa961fa4d5a in dlfree () from /path/to/python/lib/python3.9/lib-dynload/_ctypes.cpython-39-x86_64-linux-gnu.so
#3  0x00007fa961fa5b0e in ffi_closure_free () from /path/to/python/lib/python3.9/lib-dynload/_ctypes.cpython-39-x86_64-linux-gnu.so
#4  0x00007fa961f97f24 in CThunkObject_dealloc (myself=0x7fa9616f19e0) at /usr1/python/python/target/checkout/Python-3.9.11/Modules/_ctypes/callbacks.c:23
#5  0x00000000004cb315 in _Py_DECREF (op=<optimized out>) at ./Include/object.h:430
#6  _Py_XDECREF (op=<optimized out>) at ./Include/object.h:497
#7  free_keys_object (keys=0x7fa9616f1870) at Objects/dictobject.c:598
#8  0x00000000004cbbc0 in dictkeys_decref (dk=0x7fa9616f1870) at Objects/dictobject.c:333
#9  dict_dealloc (mp=0x7fa961bdc680) at Objects/dictobject.c:2026

Do you have any ideas?

Tested with:

  • python 3.9.11
  • libffi 3.4.2
  • OS: x86_64 GNU/Linux
CPython versions tested on:

3.9

Operating systems tested on:

Linux

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

首先使用 Python 3.9.11 和 libffi 3.4.2 重现崩溃,然后将其与 libffi 3.3 进行比较。检查 Modules/_ctypes/callbacks.c 中 closure_fcn 和 CThunkObject_dealloc 附近的代码,并运行名为 test_callbacks 的 ctypes 测试,特别是 test_as_parameter.AsParamPropertyWrapperTestCase 中的失败。完成的标准是解释清楚崩溃原因,并且相关的 ctypes 测试通过。

由索引模型根据 Issue 内容生成。

评估

技术栈
python
领域
backend
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
停滞
描述清晰度
需要澄清
新手友好度
30/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。