dis: FOR_ITER reports wrong exhausted-path jump target (END_FOR instead of POP_ITER)
まだ誰も着手していません。
- 主要言語
- Python
- スター
- 77.2k
- フォーク
- 35.9k
- PR マージ指標
- PR 指標を取得中
説明
Bug Report
Bug description:
In Python 3.15, dis reports the wrong jump target for FOR_ITER when the iterator is exhausted. The reported target lands on END_FOR, but the CPython runtime actually jumps one instruction past it to POP_ITER.
Root cause: In bytecodes.c, FOR_ITER uses JUMPBY(oparg + 1) to skip past END_FOR. However, dis computes the jump target as NIP + oparg * 2 bytes (without the +1), landing on END_FOR rather than POP_ITER.
import dis
def f():
for x in [1, 2, 3]:
pass
instrs = {i.offset: i for i in dis.get_instructions(f.__code__, show_caches=True)}
for i in dis.get_instructions(f.__code__):
if i.opname == "FOR_ITER":
for_iter = i
# dis reports this as the jump target:
reported_target = for_iter.jump_target
reported_name = instrs[reported_target].opname # "END_FOR"
# CPython runtime actually jumps here (oparg+1 instructions past NIP):
nip = for_iter.offset + 4 # 4 bytes = FOR_ITER word + CACHE word
actual_target = nip + (for_iter.arg + 1) * 2
actual_name = instrs[actual_target].opname # "POP_ITER"
print(f"dis reports: offset {reported_target} = {reported_name}") # END_FOR
print(f"runtime jumps: offset {actual_target} = {actual_name}") # POP_ITER
Output:
dis reports: offset 20 = END_FOR
runtime jumps: offset 22 = POP_ITER
The stack-effect model remains self-consistent (FOR_ITER +1, END_FOR -1, POP_ITER -2), but the reported jump target is misleading to any tool that builds a control-flow graph from dis output. The exhausted-iterator edge should point to POP_ITER, not END_FOR.
CPython versions tested on:
CPython main branch (3.15)
Operating systems tested on:
macOS
Linked PRs
- gh-149503
コントリビューションガイド
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
調査の方向性
bytecodes.c の FOR_ITER 実装と、ジャンプ先を計算する dis のエントリーポイントから始めてください。レポートに記載されたイテレーター枯渇時のターゲットとランタイムの動作を比較し、そのターゲットが END_FOR ではなく POP_ITER であることを示すリグレッションテストのカバレッジを追加してください。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- python
- 領域
- devtools
- issue の種類
- バグ
- 難易度
- 3/5
- 見積もり時間
- 1〜2日
- 活発さ
- 停滞
- 明瞭さ
- 明確に書かれている
- 初心者へのやさしさ
- 35/100