python / python/cpython

SEGV in `_PyObject_ClearFreeLists` after exception in subinterpreter

Open
#148,929 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

interpreter-core topic-subinterpreters type-crash
Dominant language
Python
Stars
77.2k
Forks
35.9k
PR merge metrics
PR metrics pending

Description

What happened?

Executing the following two file python script with python3.14 -m src crashes the (sub?)interpreter with a SIGSEGV.

# src/executor.py
import importlib
import sys
import traceback

def execute_module():
    importlib.invalidate_caches()
    sys.modules = "xxx"
    importlib.import_module("zip")
# src/__main__,py
from concurrent import interpreters

sub_interpreter = interpreters.create()
queue = interpreters.create_queue()

def run_module(queue):
    import importlib
    execute_module_fn = importlib.import_module("src.executor").execute_module
    execute_module_fn()
    queue.put(True)

sub_interpreter.call(run_module, queue)
queue.get()
sub_interpreter.close()
Starting program: /nix/store/6p5sldsqcgn0x0al9h2hvqpd4xqi1wpm-user-environment/bin/python3.14 -m src
[Thread debugging using libthread_db enabled]
Using host libthread_db library "/nix/store/km4g87jxsqxvcq344ncyb8h1i6f3cqxh-glibc-2.40-218/lib/libthread_db.so.1".
Traceback (most recent call last):
  File "<frozen runpy>", line 198, in _run_module_as_main
  File "<frozen runpy>", line 88, in _run_code
  File "/home/uli/DEV/python-segv/src/__main__.py", line 14, in <module>
    sub_interpreter.call(run_module, queue)
    ~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^
  File "/nix/store/w9f9jj6mbrk4146wm69qlyssjghildlf-python3-3.14.3/lib/python3.14/concurrent/interpreters/__init__.py", line 238, in call
    return self._call(callable, args, kwargs)
           ~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^
  File "/nix/store/w9f9jj6mbrk4146wm69qlyssjghildlf-python3-3.14.3/lib/python3.14/concurrent/interpreters/__init__.py", line 222, in _call
    raise ExecutionFailed(excinfo)
concurrent.interpreters.ExecutionFailed: AttributeError: 'str' object has no attribute 'get'
<sys>:0: RuntimeWarning: remaining subinterpreters; close them with Interpreter.close()

Program received signal SIGSEGV, Segmentation fault.
0x00007ffff7989bb9 in _PyObject_ClearFreeLists ()
   from /nix/store/w9f9jj6mbrk4146wm69qlyssjghildlf-python3-3.14.3/lib/libpython3.14.so.1.0
(gdb) bt
#0  0x00007ffff7989bb9 in _PyObject_ClearFreeLists ()
   from /nix/store/w9f9jj6mbrk4146wm69qlyssjghildlf-python3-3.14.3/lib/libpython3.14.so.1.0
#1  0x00007ffff7adce4f in _PyGC_Collect ()
   from /nix/store/w9f9jj6mbrk4146wm69qlyssjghildlf-python3-3.14.3/lib/libpython3.14.so.1.0
#2  0x00007ffff7b1ace4 in finalize_modules.lto_priv ()
   from /nix/store/w9f9jj6mbrk4146wm69qlyssjghildlf-python3-3.14.3/lib/libpython3.14.so.1.0
#3  0x00007ffff7b24b57 in Py_EndInterpreter ()
   from /nix/store/w9f9jj6mbrk4146wm69qlyssjghildlf-python3-3.14.3/lib/libpython3.14.so.1.0
#4  0x00007ffff7c35451 in _Py_Finalize.part.0.constprop.0 ()
--Type <RET> for more, q to quit, c to continue without paging--
   from /nix/store/w9f9jj6mbrk4146wm69qlyssjghildlf-python3-3.14.3/lib/libpython3.14.so.1.0
#5  0x00007ffff7b5f8d8 in Py_RunMain ()
   from /nix/store/w9f9jj6mbrk4146wm69qlyssjghildlf-python3-3.14.3/lib/libpython3.14.so.1.0
#6  0x00007ffff7b60b81 in Py_BytesMain ()
   from /nix/store/w9f9jj6mbrk4146wm69qlyssjghildlf-python3-3.14.3/lib/libpython3.14.so.1.0
#7  0x00007ffff742a4d8 in __libc_start_call_main ()
   from /nix/store/km4g87jxsqxvcq344ncyb8h1i6f3cqxh-glibc-2.40-218/lib/libc.so.6
#8  0x00007ffff742a59b in __libc_start_main_impl ()
   from /nix/store/km4g87jxsqxvcq344ncyb8h1i6f3cqxh-glibc-2.40-218/lib/libc.so.6
#9  0x0000555555555085 in _start ()

The following reduction shows the same crashing behavior, I wasn't able to reproduce it while running in gdb however.

from concurrent import interpreters

sub_interpreter = interpreters.create()

def run_module():
    import importlib
    import sys
    import traceback

    importlib.invalidate_caches()
    sys.modules = "xxx"
    importlib.import_module("zip")

sub_interpreter.call(run_module)
sub_interpreter.close()
CPython versions tested on:

3.14

Operating systems tested on:

Linux

Output from running 'python -VV' on the command line:

Python 3.14.3 (main, Feb 3 2026, 15:32:20) [GCC 14.3.0] on linux

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the reduced script using concurrent.interpreters, sys.modules = "xxx", and importlib.import_module("zip") on Python 3.14 Linux, then inspect the traceback through _PyObject_ClearFreeLists, _PyGC_Collect, finalize_modules, and Py_EndInterpreter. Done means the reproducer no longer causes a SIGSEGV during subinterpreter closure, with regression coverage for the reported exception path.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
backend
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Clearly specified
Newbie friendliness
46/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.