python / python/cpython

PyErr_GivenExceptionMatches crashes with SIGSEGV on deeply nested tuple targets

Aberta
#156,204 1 comentário 0 reações 0 responsáveis Ver no GitHub

Ninguém assumiu esta issue ainda.

interpreter-core type-crash
Linguagem predominante
Python
Estrelas
77.2k
Forks
36k
Métricas de merge de PRs
Métricas de PR pendentes

Descrição

Crash report

What happened?
Problem Description

PyErr_GivenExceptionMatches(err, exc) in Python/errors.c recursively iterates through nested tuple exception targets without guarding recursion depth via Py_EnterRecursiveCall() / Py_LeaveRecursiveCall().

When evaluating deeply nested tuple structures passed through C API extensions or dynamic tuple composition, unbounded native C call stack growth leads to stack exhaustion and an immediate SIGSEGV crash.

Steps to Reproduce
import ctypes

lib = ctypes.pythonapi
lib.PyErr_GivenExceptionMatches.argtypes = [ctypes.py_object, ctypes.py_object]
lib.PyErr_GivenExceptionMatches.restype = ctypes.c_int

# Construct deeply nested tuple target
tup = (1, ValueError)
for _ in range(1_000_000):
    tup = (1, tup)

# Trigger exception matching traversal
res = lib.PyErr_GivenExceptionMatches(TypeError(), tup)
Actual Result

Segmentation fault (core dumped)

Program received signal SIGSEGV, Segmentation fault.
PyTuple_Size (op=op@entry=0x7ffff2beda30) at Objects/tupleobject.c:100
100             return Py_SIZE(op);
#0  PyTuple_Size (op=op@entry=0x7ffff2beda30) at Objects/tupleobject.c:100
#1  0x0000555555824f63 in PyErr_GivenExceptionMatches (err=err@entry=0x7ffff78ea900, exc=0x7ffff2beda30) at Python/errors.c:339
#2  0x0000555555824fb0 in PyErr_GivenExceptionMatches (err=err@entry=0x7ffff78ea900, exc=0x7ffff2beda90) at Python/errors.c:342
#3  0x0000555555824fb0 in PyErr_GivenExceptionMatches (err=err@entry=0x7ffff78ea900, exc=0x7ffff2bedaf0) at Python/errors.c:342
#4  0x0000555555824fb0 in PyErr_GivenExceptionMatches (err=err@entry=0x7ffff78ea900, exc=0x7ffff2bedb50) at Python/errors.c:342
...
rsp             0x7fffff7ff000      0x7fffff7ff000
Expected Result

PyErr_GivenExceptionMatches should guard recursion with Py_EnterRecursiveCall() / Py_LeaveRecursiveCall(), setting a RecursionError and returning 0 safely when recursion depth is exceeded instead of crashing the interpreter.

CPython versions tested on:

CPython main branch

Operating systems tested on:

Linux

Output from running 'python -VV' on the command line:

Python 3.16.0a0 (heads/fix-err-given-exception-matches-recursion:999a046b24c, Aug 21 2026, 18:34:) [GCC 13.3.0]

Linked PRs
  • gh-156205

Guia de contribuição

Abrir o guia de contribuição

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Direção de pesquisa

Comece em Python/errors.c, em PyErr_GivenExceptionMatches, e reproduza o caso de tupla profundamente aninhada da issue. Verifique as convenções existentes de proteção contra recursão e, em seguida, confirme que um aninhamento excessivo gera RecursionError e retorna com segurança em vez de causar um crash; o PR vinculado gh-156205 indica que o trabalho já está em andamento.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
c, python
Domínio
backend
Tipo de issue
Bug
Dificuldade
3/5
Tempo estimado
1-2 dias
Status de atividade
Estagnada
Clareza
Claramente especificada
Facilidade para iniciantes
35/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.