python / python/cpython

PyErr_GivenExceptionMatches crashes with SIGSEGV on deeply nested tuple targets

未關閉
#156,204 1 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

還沒有人認領這個 Issue。

interpreter-core type-crash
主要語言
Python
星號
77.2k
分支
35.9k
PR 合併指標
PR 指標待擷取

描述

Crash report

What happened?
Problem Description

PyErr_GivenExceptionMatches(err, exc) in Python/errors.c recursively iterates through nested tuple exception targets without guarding recursion depth via Py_EnterRecursiveCall() / Py_LeaveRecursiveCall().

When evaluating deeply nested tuple structures passed through C API extensions or dynamic tuple composition, unbounded native C call stack growth leads to stack exhaustion and an immediate SIGSEGV crash.

Steps to Reproduce
import ctypes

lib = ctypes.pythonapi
lib.PyErr_GivenExceptionMatches.argtypes = [ctypes.py_object, ctypes.py_object]
lib.PyErr_GivenExceptionMatches.restype = ctypes.c_int

# Construct deeply nested tuple target
tup = (1, ValueError)
for _ in range(1_000_000):
    tup = (1, tup)

# Trigger exception matching traversal
res = lib.PyErr_GivenExceptionMatches(TypeError(), tup)
Actual Result

Segmentation fault (core dumped)

Program received signal SIGSEGV, Segmentation fault.
PyTuple_Size (op=op@entry=0x7ffff2beda30) at Objects/tupleobject.c:100
100             return Py_SIZE(op);
#0  PyTuple_Size (op=op@entry=0x7ffff2beda30) at Objects/tupleobject.c:100
#1  0x0000555555824f63 in PyErr_GivenExceptionMatches (err=err@entry=0x7ffff78ea900, exc=0x7ffff2beda30) at Python/errors.c:339
#2  0x0000555555824fb0 in PyErr_GivenExceptionMatches (err=err@entry=0x7ffff78ea900, exc=0x7ffff2beda90) at Python/errors.c:342
#3  0x0000555555824fb0 in PyErr_GivenExceptionMatches (err=err@entry=0x7ffff78ea900, exc=0x7ffff2bedaf0) at Python/errors.c:342
#4  0x0000555555824fb0 in PyErr_GivenExceptionMatches (err=err@entry=0x7ffff78ea900, exc=0x7ffff2bedb50) at Python/errors.c:342
...
rsp             0x7fffff7ff000      0x7fffff7ff000
Expected Result

PyErr_GivenExceptionMatches should guard recursion with Py_EnterRecursiveCall() / Py_LeaveRecursiveCall(), setting a RecursionError and returning 0 safely when recursion depth is exceeded instead of crashing the interpreter.

CPython versions tested on:

CPython main branch

Operating systems tested on:

Linux

Output from running 'python -VV' on the command line:

Python 3.16.0a0 (heads/fix-err-given-exception-matches-recursion:999a046b24c, Aug 21 2026, 18:34:) [GCC 13.3.0]

Linked PRs
  • gh-156205

貢獻指南

開啟貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

研究方向

從 Python/errors.c 中的 PyErr_GivenExceptionMatches 開始,重現 issue 中深度巢狀 tuple 的情況。檢查現有的遞迴防護慣例,然後驗證過度巢狀會引發 RecursionError 並安全返回,而不是當機;連結的 PR gh-156205 表示相關工作已在進行中。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
c, python
領域
backend
Issue 類型
缺陷
難度
3/5
預估耗時
1-2 天
活躍度
停滯
描述清晰度
描述清楚
新手友好度
35/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。