python / python/cpython

posix_spawn crashes when python is run with gprofng

未关闭
#149,509 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

extension-modules type-bug
主要语言
Python
星标
77.2k
派生
35.9k
PR 合并指标
PR 指标待抓取

描述

Bug report

Bug description:

I've been observing crashes when python code calls posix_spawn when being
run under gprofng.

As an example, I tested on a Fedora 42 x86_64 system with python3-3.13.13-1.fc42.x86_64
[Python 3.13.13 (main, Apr 8 2026, 00:00:00) [GCC 15.2.1 20260123 (Red Hat 15.2.1-7)] on linux]
and binutils-2.44-12.fc42.x86_64
[GNU gprofng binutils version 2.44]

Consider this script:

import os
os.posix_spawn("/usr/bin/echo", ["/usr/bin/echo", "world"], None)
print ("hello")

If I run this on its own, it works as expected:

$ python spawn.py
hello
world

But if I run it with gprofng, it crashes:

$ gprofng collect app python spawn.py
Creating experiment directory test.1.er (Process ID: 591620) ...
free(): invalid pointer
Aborted (core dumped)
$ world

The problem goes away if I change the third argument of the posix_spawn
command from None to os.environ. I also reproduce the crash with
cpython git main as of May 6 (65ed109b5de7bab28f1051336f0ae312205c4233).

The issue is that py_posix_spawn assumes that environ does not change
over the call to posix_spawn. However, when gprofng is used, it
interposes code wrapping the posix_spawn call that can modify the
environment (apparently to sanitize the environment from things like
LD_PRELOAD entries used by gprofng) and thus change environ.

In more detail, in py_posix_spawn, we have this before the spawn call:

    EXECV_CHAR **envlist = NULL;
    ...
    Py_ssize_t argc, envc;
    ...
    if (env == Py_None) {
#ifdef USE_DARWIN_NS_GET_ENVIRON
        environ = *_NSGetEnviron();
#endif
        envlist = environ;
    } else {
        envlist = parse_envlist(env, &envc);
        if (envlist == NULL) {
            goto exit;
        }
    }

and after the call:

    if (envlist && envlist != environ) {
        free_string_array(envlist, envc);
    }

So if the env argument is null and environ is changed by the call,
then we end up trying to free environ,
using a length taken from an uninitialized variable.

Here's one possible fix:

diff --git a/Modules/posixmodule.c b/Modules/posixmodule.c
index 5bd53c2146a..4fef8a60647 100644
--- a/Modules/posixmodule.c
+++ b/Modules/posixmodule.c
@@ -7961,6 +7961,7 @@ py_posix_spawn(int use_posix_spawnp, PyObject *module, path_t *path, PyObject *a
         environ = *_NSGetEnviron();
 #endif
         envlist = environ;
+        envc = (Py_ssize_t)-1;
     } else {
         envlist = parse_envlist(env, &envc);
         if (envlist == NULL) {
@@ -8028,7 +8029,10 @@ py_posix_spawn(int use_posix_spawnp, PyObject *module, path_t *path, PyObject *a
     if (attrp) {
         (void)posix_spawnattr_destroy(attrp);
     }
-    if (envlist && envlist != environ) {
+    /* Can't just test for envlist != environ because some tools, such as
+       gprofng, interpose code around the posix_spawn call that can change
+       environ. */
+    if (envlist && envc != (Py_ssize_t)-1) {
         free_string_array(envlist, envc);
     }
     if (argvlist) {
CPython versions tested on:

3.13, CPython main branch

Operating systems tested on:

Linux

Linked PRs
  • gh-149724

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

从 Modules/posixmodule.c 中的 py_posix_spawn 开始,使用提供的 gprofng 下的复现程序比较 posix_spawn 调用前后对 environ 的处理。当环境在调用期间发生变化时复现程序不再崩溃,同时 posix_spawn 的普通行为保持不变,即可视为完成。

由索引模型根据 Issue 内容生成。

评估

技术栈
c, python
领域
operating-systems
Issue 类型
缺陷
难度
3/5
预计耗时
1-2 天
活跃度
停滞
描述清晰度
描述清楚
新手友好度
35/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。