python / python/cpython

Crash in genericaliasobject.c when tuple_extend() fails under allocation failure

Open
#155,053 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

interpreter-core type-crash
Dominant language
Python
Stars
77.2k
Forks
35.9k
PR merge metrics
PR metrics pending

Description

Crash report

What happened?

While investigating allocation-failure paths in Objects/genericaliasobject.c, I found a NULL dereference in subs_tvars().

When tuple_extend() fails, it returns -1 after _PyTuple_Resize() fails. _PyTuple_Resize() clears its out-parameter (*pv = NULL) on failure, so subargs is guaranteed to be NULL.

However, subs_tvars() unconditionally calls:

if (j < 0) {
    Py_DECREF(subparams);
    Py_DECREF(subargs);
    return NULL;
}

As a result, Py_DECREF(subargs) dereferences a NULL pointer and crashes the interpreter instead of propagating the MemoryError.

Reproducer

A debug build with _testcapi is required.

import _testcapi
from typing import TypeVarTuple

Ts = TypeVarTuple("Ts")
alias = dict[str, tuple[*Ts]]
key = (int, str)

_testcapi.set_nomemory(24, 25)
try:
    alias[key]
finally:
    _testcapi.remove_mem_hooks()

The exact allocation index may vary between builds, so sweeping a range of indices is recommended.

Observed result

ASan reports:

AddressSanitizer: SEGV on unknown address 0x000000000000

#0 _Py_IsImmortal
#1 Py_DECREF
#2 subs_tvars (Objects/genericaliasobject.c)
#3 _Py_subs_parameters
#4 ga_getitem
Root cause

tuple_extend() immediately returns -1 when _PyTuple_Resize() fails. _PyTuple_Resize() sets its out-parameter to NULL on failure, so subargs is guaranteed to be NULL when control reaches the error path. Calling Py_DECREF(subargs) therefore dereferences a NULL pointer.

The issue appears related to gh-148222, which removed the same Py_DECREF() pattern from _Py_make_parameters() after _PyTuple_Resize() failure, but this analogous path in subs_tvars() remained unchanged.

Removing Py_DECREF(subargs); causes the reproducer to raise MemoryError instead of crashing.

CPython versions tested on:

CPython main branch

Operating systems tested on:

Linux

Output from running 'python -VV' on the command line:

Python 3.16.0a0 (heads/investigate-genericalias-oom-null-decref-dirty:7ce7f0bd851, Aug 1 2026) [GCC 13.3.0]

Linked PRs
  • gh-155055

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start in Objects/genericaliasobject.c at subs_tvars() and tuple_extend(), then run the provided _testcapi allocation-failure reproducer on a debug build. Confirm the failure path no longer crashes and propagates MemoryError; compare the analogous handling in _Py_make_parameters() and check the linked gh-155055 work.

Written by the indexing model from the issue text.

Assessment

Tech stack
c, python
Domain
backend
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.