python / python/cpython

Missing Py_SetStackPointer call in LIST_APPEND

未关闭
#151,119 5 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

interpreter-core type-crash
主要语言
Python
星标
77.2k
派生
35.9k
PR 合并指标
PR 指标待抓取

描述

Bug report

Bug description:

In a debug build:

import _testcapi
_testcapi.set_nomemory(2)
result = [f'1{x}' for x in range(1)]
Assertion failed: (tstate->current_frame == NULL || tstate->current_frame->stackpointer != NULL), function _Py_Dealloc, file object.c, line 3298.
fish: Job 1, './python.exe test.py' terminated by signal SIGABRT (Abort)

LIST_APPEND op calls _PyList_AppendTakeRef without setting the stack frame, _PyList_AppendTakeRef calls _PyList_AppendTakeRefListResize with a stolen ref to newitem. If the list resize fails, then newitem is decref'd, which can cause a dealloc, which triggers the above assert on a debug build.

Unless there is a performance impact, then I'm assuming this is just a case of calling Py_SetStackPointer at the appropriate point?

Python 3.16.0a0 (heads/main-dirty:29a920e, Jun 9 2026, 00:36:55) [Clang 22.1.6 ]

CPython versions tested on:

CPython main branch

Operating systems tested on:

Linux

Linked PRs
  • gh-151538

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

该 issue 已经关联到 PR gh-151538,因此应先审查这项工作,而不是独立开始。要重现该失败,请在 debug 构建中运行所示的 _testcapi.set_nomemory(2) 列表推导示例,然后检查 LIST_APPEND、_PyList_AppendTakeRef 和 _PyList_AppendTakeRefListResize;当 resize 失败时不再出现 object.c 断言,即表示完成。

由索引模型根据 Issue 内容生成。

评估

技术栈
python
领域
backend
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
停滞
描述清晰度
基本清楚
新手友好度
20/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。