python / python/cpython

python coredump with libffi 3.4.2

未關閉
#118,171 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

還沒有人認領這個 Issue。

type-crash
主要語言
Python
星號
77.2k
分支
36k
PR 合併指標
PR 指標待擷取

描述

Bug report

Bug description:

I encountered a core dump and the backtrace shows that it relates to ctypes:

#0  0x00007f2b0071bf71 in closure_fcn (cif=0x7f2adcd88de8, resp=0x7ffeeb800a10, args=0x7ffeeb800890, userdata=0x3b) at /usr1/python/python/target/checkout/Python-3.9.11/Modules/_ctypes/callbacks.c:311
#1  0x00007f2b0072ba09 in ffi_closure_unix64_inner () from /path/to/python/lib/python3.9/lib-dynload/_ctypes.cpython-39-x86_64-linux-gnu.so
#2  0x00007f2b0072c1e8 in ffi_closure_unix64 () from /path/to/python/lib/python3.9/lib-dynload/_ctypes.cpython-39-x86_64-linux-gnu.so
#3  0x00007f2add597c13 in LLVMPYObjectCache::notifyObjectCompiled (this=0x3382350, M=0x324a370, MBR=...) at executionengine.cpp:195
#4  0x00007f2adea3e18b in llvm::MCJIT::emitObject(llvm::Module*) [clone .localalias] () from /path/to/python/lib/python3.9/site-packages/llvmlite/binding/libllvmlite.so
#5  0x00007f2adea3ea39 in llvm::MCJIT::generateCodeForModule(llvm::Module*) [clone .localalias] () from /path/to/python/lib/python3.9/site-packages/llvmlite/binding/libllvmlite.so
#6  0x00007f2adea39f30 in llvm::MCJIT::finalizeObject() [clone .localalias] () from /path/to/python/lib/python3.9/site-packages/llvmlite/binding/libllvmlite.so
#7  0x00007f2add5975f5 in LLVMPY_FinalizeObject (EE=0x3335f80) at executionengine.cpp:63
#8  0x00007f2b0072c052 in ffi_call_unix64 () from /path/to/python/lib/python3.9/lib-dynload/_ctypes.cpython-39-x86_64-linux-gnu.so
#9  0x00007f2b0072b428 in ffi_call_int () from /path/to/python/lib/python3.9/lib-dynload/_ctypes.cpython-39-x86_64-linux-gnu.so
#10 0x00007f2b0072b491 in ffi_call () from /path/to/python/lib/python3.9/lib-dynload/_ctypes.cpython-39-x86_64-linux-gnu.so

I changed nothing but the version of libffi from 3.3 to 3.4.2, while it runs ok with version 3,3.
I compile libffi and recompiling python with it:

# compile libffi
./configure --prefix=/path/to/libffi/ CFLAGS="-fPIC" --disable-shared --disable-docs
make && make install

# compile python with libffi
sed -i '/Linux\*|GNU\*) LINKFORSHARED=/ s/="/&-pie /' configure
./configure CFLAGS="-fstack-protector-strong -fPIC -D_FORTIFY_SOURCE=2 -O2" LDFLAGS="-L/path/to/libffi/lib64 -Bstatic -Wl,--build-id=none,-z,noexecstack,-z,relro,-z,now" LIBS="-lffi"
make && make install

I also run unittest of ctypes as ctypes unittest crashes with libffi 3.4.2,

test_callbacks (ctypes.test.test_as_parameter.AsParamPropertyWrapperTestCase) ... Aborted (core dumped)

it cored as follows:



#0  0x00007fa96efcc77b in raise () from /usr/lib64/libc.so.6
#1  0x00007fa96efcdaa1 in abort () from /usr/lib64/libc.so.6
#2  0x00007fa961fa4d5a in dlfree () from /path/to/python/lib/python3.9/lib-dynload/_ctypes.cpython-39-x86_64-linux-gnu.so
#3  0x00007fa961fa5b0e in ffi_closure_free () from /path/to/python/lib/python3.9/lib-dynload/_ctypes.cpython-39-x86_64-linux-gnu.so
#4  0x00007fa961f97f24 in CThunkObject_dealloc (myself=0x7fa9616f19e0) at /usr1/python/python/target/checkout/Python-3.9.11/Modules/_ctypes/callbacks.c:23
#5  0x00000000004cb315 in _Py_DECREF (op=<optimized out>) at ./Include/object.h:430
#6  _Py_XDECREF (op=<optimized out>) at ./Include/object.h:497
#7  free_keys_object (keys=0x7fa9616f1870) at Objects/dictobject.c:598
#8  0x00000000004cbbc0 in dictkeys_decref (dk=0x7fa9616f1870) at Objects/dictobject.c:333
#9  dict_dealloc (mp=0x7fa961bdc680) at Objects/dictobject.c:2026

Do you have any ideas?

Tested with:

  • python 3.9.11
  • libffi 3.4.2
  • OS: x86_64 GNU/Linux
CPython versions tested on:

3.9

Operating systems tested on:

Linux

貢獻指南

開啟貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

研究方向

首先使用 Python 3.9.11 和 libffi 3.4.2 重現當機,然後將其與 libffi 3.3 進行比較。檢查 Modules/_ctypes/callbacks.c 中 closure_fcn 和 CThunkObject_dealloc 附近的程式碼,並執行名為 test_callbacks 的 ctypes 測試,特別是 test_as_parameter.AsParamPropertyWrapperTestCase 中的失敗。完成的標準是解釋清楚當機原因,且相關的 ctypes 測試通過。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
python
領域
backend
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
停滯
描述清晰度
需要釐清
新手友好度
30/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。