Crash in genericaliasobject.c when tuple_extend() fails under allocation failure
Dieses Issue hat noch niemand übernommen.
- Vorherrschende Sprache
- Python
- Sterne
- 77.2k
- Forks
- 35.9k
- PR-Merge-Kennzahlen
- PR-Kennzahlen ausstehend
Beschreibung
Crash report
What happened?
While investigating allocation-failure paths in Objects/genericaliasobject.c, I found a NULL dereference in subs_tvars().
When tuple_extend() fails, it returns -1 after _PyTuple_Resize() fails. _PyTuple_Resize() clears its out-parameter (*pv = NULL) on failure, so subargs is guaranteed to be NULL.
However, subs_tvars() unconditionally calls:
if (j < 0) {
Py_DECREF(subparams);
Py_DECREF(subargs);
return NULL;
}
As a result, Py_DECREF(subargs) dereferences a NULL pointer and crashes the interpreter instead of propagating the MemoryError.
Reproducer
A debug build with _testcapi is required.
import _testcapi
from typing import TypeVarTuple
Ts = TypeVarTuple("Ts")
alias = dict[str, tuple[*Ts]]
key = (int, str)
_testcapi.set_nomemory(24, 25)
try:
alias[key]
finally:
_testcapi.remove_mem_hooks()
The exact allocation index may vary between builds, so sweeping a range of indices is recommended.
Observed result
ASan reports:
AddressSanitizer: SEGV on unknown address 0x000000000000
#0 _Py_IsImmortal
#1 Py_DECREF
#2 subs_tvars (Objects/genericaliasobject.c)
#3 _Py_subs_parameters
#4 ga_getitem
Root cause
tuple_extend() immediately returns -1 when _PyTuple_Resize() fails. _PyTuple_Resize() sets its out-parameter to NULL on failure, so subargs is guaranteed to be NULL when control reaches the error path. Calling Py_DECREF(subargs) therefore dereferences a NULL pointer.
The issue appears related to gh-148222, which removed the same Py_DECREF() pattern from _Py_make_parameters() after _PyTuple_Resize() failure, but this analogous path in subs_tvars() remained unchanged.
Removing Py_DECREF(subargs); causes the reproducer to raise MemoryError instead of crashing.
CPython versions tested on:
CPython main branch
Operating systems tested on:
Linux
Output from running 'python -VV' on the command line:
Python 3.16.0a0 (heads/investigate-genericalias-oom-null-decref-dirty:7ce7f0bd851, Aug 1 2026) [GCC 13.3.0]
Linked PRs
- gh-155055
Beitragsleitfaden
Erste Schritte
- Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
- Forke das Repository und arbeite in einem Branch.
- Öffne einen Pull Request, der die Issue-Nummer nennt.
Rechercherichtung
Beginne in Objects/genericaliasobject.c bei subs_tvars() und tuple_extend(), und führe dann den bereitgestellten _testcapi-Reproducer für den Allokationsfehler in einem Debug-Build aus. Bestätige, dass der Fehlerpfad nicht mehr abstürzt und MemoryError weitergibt; vergleiche die analoge Behandlung in _Py_make_parameters() und prüfe die verknüpfte Arbeit gh-155055.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- c, python
- Bereich
- backend
- Issue-Typ
- Bug
- Schwierigkeit
- 2/5
- Geschätzter Aufwand
- 1-3 Stunden
- Aktivitätsstatus
- Veraltet
- Klarheit
- Klar beschrieben
- Anfängerfreundlichkeit
- 25/100