python / python/cpython

Memory leak on interpreter shutdown when reference cycle exists between `structseq` type and its instance

未關閉
#157,176 3 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視

還沒有人認領這個 Issue。

3.14 3.15 3.16 type-bug
主要語言
Python
星號
77.2k
分支
35.9k
PR 合併指標
PR 指標待擷取

描述

Bug report

Bug description:
Environment
  • Commit/Branch: main (rev: 2d9fb5f2f70b18ce9e5d9f7f76fd5ef3f118d838)
  • OS: Linux
  • Build flags:
    CC=clang CXX=clang++ LDFLAGS='-fuse-ld=lld' ./configure --with-address-sanitizer --with-undefined-behavior-sanitizer --with-pydebug && make -j$(nproc)
    
Steps to reproduce

Run:

./python -c "import time; t = time.gmtime(); type(t).refcyle = t;"

Note: Explicitly breaking the cycle avoids the leak:

./python -c "import time; t = time.gmtime(); type(t).refcyle = t; del type(t).refcyle"
Expected behavior

The garbage collector or interpreter finalization breaks the reference cycle during shutdown; no memory leaks reported by LeakSanitizer.

Actual behavior

LeakSanitizer detects memory leaks (indirect leaks of the type, its dict, descriptors, and the instance):

=================================================================
==1164172==ERROR: LeakSanitizer: detected memory leaks

Indirect leak of 1472 byte(s) in 1 object(s) allocated from:
    #0 0x55571ba2f651 in malloc
    #1 0x55571c0c8db7 in _PyMem_DebugRawAlloc Objects/obmalloc.c:3103:24
    #2 0x55571c130728 in _PyObject_MallocWithType Include/internal/pycore_object_alloc.h:46:17
    #3 0x55571c130728 in _PyType_AllocNoTrack Objects/typeobject.c:2495:19
    #4 0x55571c13040d in PyType_GenericAlloc Objects/typeobject.c:2526:21
    #5 0x55571c1357f9 in type_from_slots_or_spec Objects/typeobject.c:5591:30
    #6 0x55571c1148ec in _PyStructSequence_NewType Objects/structseq.c:780:28
    #7 0x55571ca6ea5c in time_exec Modules/timemodule.c:2113:31
...
Indirect leak of 176 byte(s) in 1 object(s) allocated from:
    #0 0x55571ba2f651 in malloc
    #1 0x55571c0c8db7 in _PyMem_DebugRawAlloc Objects/obmalloc.c:3103:24
    #2 0x55571c5d4028 in _PyObject_MallocWithType Include/internal/pycore_object_alloc.h:46:17
    #3 0x55571c5d4028 in gc_alloc Python/gc.c:2013:17
    #4 0x55571c5d4440 in _PyObject_GC_NewVar Python/gc.c:2055:25
    #5 0x55571c110247 in PyStructSequence_New Objects/structseq.c:77:11
    #6 0x55571ca69e1d in tmtotuple Modules/timemodule.c:463:19
    #7 0x55571ca67616 in time_gmtime Modules/timemodule.c:541:12
...
SUMMARY: AddressSanitizer: 6946 byte(s) leaked in 50 allocation(s).

Full LeakSanitizer output - logs.txt

CPython versions tested on:

CPython main branch

Operating systems tested on:

Linux

Linked PRs
  • gh-157179

貢獻指南

開啟貢獻指南

從這裡開始

  1. 先讀完整個 Issue,再讀專案的貢獻指南。
  2. 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
  3. Fork 儲存庫,在一個分支上完成修改。
  4. 送出 Pull Request,並在描述裡引用這個 Issue 編號。

研究方向

先在 ASan/UBSan pydebug build 下使用 reproducer,然後檢查 Objects/structseq.c 以及 Objects/typeobject.c、Python/gc.c 和 Modules/timemodule.c 中的配置路徑。將行為與連結的 PR gh-157179 進行比較。當該循環在直譯器關閉期間不再產生 LeakSanitizer 洩漏時,即表示完成。

由索引模型根據 Issue 內容生成。

評估

技術堆疊
python
領域
backend
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
停滯
描述清晰度
描述清楚
新手友好度
25/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。