PyErr_GivenExceptionMatches crashes with SIGSEGV on deeply nested tuple targets
Ninguém assumiu esta issue ainda.
- Linguagem predominante
- Python
- Estrelas
- 77.2k
- Forks
- 36k
- Métricas de merge de PRs
- Métricas de PR pendentes
Descrição
Crash report
What happened?
Problem Description
PyErr_GivenExceptionMatches(err, exc) in Python/errors.c recursively iterates through nested tuple exception targets without guarding recursion depth via Py_EnterRecursiveCall() / Py_LeaveRecursiveCall().
When evaluating deeply nested tuple structures passed through C API extensions or dynamic tuple composition, unbounded native C call stack growth leads to stack exhaustion and an immediate SIGSEGV crash.
Steps to Reproduce
import ctypes
lib = ctypes.pythonapi
lib.PyErr_GivenExceptionMatches.argtypes = [ctypes.py_object, ctypes.py_object]
lib.PyErr_GivenExceptionMatches.restype = ctypes.c_int
# Construct deeply nested tuple target
tup = (1, ValueError)
for _ in range(1_000_000):
tup = (1, tup)
# Trigger exception matching traversal
res = lib.PyErr_GivenExceptionMatches(TypeError(), tup)
Actual Result
Segmentation fault (core dumped)
Program received signal SIGSEGV, Segmentation fault.
PyTuple_Size (op=op@entry=0x7ffff2beda30) at Objects/tupleobject.c:100
100 return Py_SIZE(op);
#0 PyTuple_Size (op=op@entry=0x7ffff2beda30) at Objects/tupleobject.c:100
#1 0x0000555555824f63 in PyErr_GivenExceptionMatches (err=err@entry=0x7ffff78ea900, exc=0x7ffff2beda30) at Python/errors.c:339
#2 0x0000555555824fb0 in PyErr_GivenExceptionMatches (err=err@entry=0x7ffff78ea900, exc=0x7ffff2beda90) at Python/errors.c:342
#3 0x0000555555824fb0 in PyErr_GivenExceptionMatches (err=err@entry=0x7ffff78ea900, exc=0x7ffff2bedaf0) at Python/errors.c:342
#4 0x0000555555824fb0 in PyErr_GivenExceptionMatches (err=err@entry=0x7ffff78ea900, exc=0x7ffff2bedb50) at Python/errors.c:342
...
rsp 0x7fffff7ff000 0x7fffff7ff000
Expected Result
PyErr_GivenExceptionMatches should guard recursion with Py_EnterRecursiveCall() / Py_LeaveRecursiveCall(), setting a RecursionError and returning 0 safely when recursion depth is exceeded instead of crashing the interpreter.
CPython versions tested on:
CPython main branch
Operating systems tested on:
Linux
Output from running 'python -VV' on the command line:
Python 3.16.0a0 (heads/fix-err-given-exception-matches-recursion:999a046b24c, Aug 21 2026, 18:34:) [GCC 13.3.0]
Linked PRs
- gh-156205
Guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Direção de pesquisa
Comece em Python/errors.c, em PyErr_GivenExceptionMatches, e reproduza o caso de tupla profundamente aninhada da issue. Verifique as convenções existentes de proteção contra recursão e, em seguida, confirme que um aninhamento excessivo gera RecursionError e retorna com segurança em vez de causar um crash; o PR vinculado gh-156205 indica que o trabalho já está em andamento.
Escrita pelo modelo de indexação a partir do texto da issue.
Avaliação
- Stack de tecnologia
- c, python
- Domínio
- backend
- Tipo de issue
- Bug
- Dificuldade
- 3/5
- Tempo estimado
- 1-2 dias
- Status de atividade
- Estagnada
- Clareza
- Claramente especificada
- Facilidade para iniciantes
- 35/100