python / python/cpython

Py_CLEAR/Py_SETREF() regression on the main branch with C++: SEGV with simple `numpy` program

Đang mở
#157,649 21 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

interpreter-core type-bug
Ngôn ngữ chính
Python
Star
77.2k
Fork
35.9k
Chỉ số merge pull request
Chỉ số pull request đang chờ

Mô tả

Bug report

Bug description:

The program that triggers the crash:

import numpy

for _ in range(200):
    numpy.prod(2, dtype=numpy.intp)

Reproducer at https://github.com/lucascolley/cpython-np-prod-repro. This produces the SEGV on CPython main branch, but passes on the 3.15 branch.

❯ export BUILD_EDITABLE_PYTHON=false

❯ pixi run repro
✨ Pixi task (repro): python repro.py
Python: 3.16.0a0 (heads/master-dirty:d8a1072491, Sep 16 2026, 22:19:03) [Clang 21.1.8 ]
AddressSanitizer:DEADLYSIGNAL
=================================================================
==54023==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x00010639c214 bp 0x00016afdf230 sp 0x00016afdf1d0 T0)
==54023==The signal is caused by a WRITE memory access.
==54023==HINT: address points to the zero page.
    #0 0x00010639c214 in _PyGCHead_SET_NEXT pycore_gc.h:151
    #1 0x00010639c214 in _PyObject_GC_UNTRACK pycore_gc.h:264
    #2 0x00010639c214 in type_dealloc typeobject.c:6898
    #3 0x000106338e40 in _Py_Dealloc object.c:3333
    #4 0x00010e880a34 in PyUFunc_GenericReduction+0x119c (_multiarray_umath.cpython-316-darwin.so:arm64+0x704a34)
    #5 0x000106237858 in _PyVectorcall_Call call.c:273
    #6 0x00010652b77c in _PyEval_EvalFrameDefault generated_cases.c.h:2831
    #7 0x0001065153bc in _PyEval_EvalFrame pycore_ceval.h:122
    #8 0x0001065153bc in _PyEval_Vector ceval.c:2176
    #9 0x000106237a78 in _PyObject_VectorcallTstate pycore_call.h:144
    #10 0x000106237a78 in PyObject_Vectorcall call.c:327
    #11 0x00010e54bd1c in dispatcher_vectorcall+0xc70 (_multiarray_umath.cpython-316-darwin.so:arm64+0x3cfd1c)
    #12 0x000106237a78 in _PyObject_VectorcallTstate pycore_call.h:144
    #13 0x000106237a78 in PyObject_Vectorcall call.c:327
    #14 0x000106515938 in _Py_VectorCall_StackRefSteal ceval.c:728
    #15 0x000106529170 in _PyEval_EvalFrameDefault generated_cases.c.h:3686
    #16 0x000106514db0 in _PyEval_EvalFrame pycore_ceval.h:122
    #17 0x000106514db0 in _PyEval_Vector ceval.c:2176
    #18 0x000106514db0 in PyEval_EvalCode ceval.c:681
    #19 0x00010665ba10 in run_mod pythonrun.c:1509
    #20 0x00010665633c in _PyRun_File pythonrun.c:1332
    #21 0x00010665633c in _PyRun_SimpleFile pythonrun.c:544
    #22 0x000106655998 in _PyRun_AnyFile pythonrun.c:92
    #23 0x0001066bd0b0 in pymain_run_file_obj main.c:478
    #24 0x0001066bd0b0 in pymain_run_file main.c:494
    #25 0x0001066bbe68 in pymain_run_python main.c:804
    #26 0x0001066bbe68 in Py_RunMain main.c:891
    #27 0x0001066bc830 in pymain_main main.c:921
    #28 0x0001066bc9e0 in Py_BytesMain main.c:945
    #29 0x000189febdfc in start+0x1b4c (dyld:arm64e+0x1fdfc)

==54023==Register values:
 x[0] = 0x00006190000dde88   x[1] = 0x000000010639c054   x[2] = 0x000000016afde9d0   x[3] = 0x000061600009a870
 x[4] = 0x0000000000000218   x[5] = 0x0000000000000218   x[6] = 0x0000000169fe4000   x[7] = 0x0000000000000001
 x[8] = 0x00006190000dde80   x[9] = 0x0000000000000000  x[10] = 0x0000000000000000  x[11] = 0x00000fffffffffff
x[12] = 0x0000000000000000  x[13] = 0xffffffffffffffff  x[14] = 0x0000000000000000  x[15] = 0x00007fffffffffff
x[16] = 0x0000000000000028  x[17] = 0x0000604000000410  x[18] = 0x0000000000000000  x[19] = 0x00006190000dde90
x[20] = 0x0000604000000438  x[21] = 0x0000000080805980  x[22] = 0x0000008000020000  x[23] = 0x0000000106c42940
x[24] = 0x0000008000020000  x[25] = 0x0000000000000000  x[26] = 0x000000016afdfb20  x[27] = 0x0000000000000000
x[28] = 0x00006110001f42e4     fp = 0x000000016afdf230     lr = 0x000000010639c1d8     sp = 0x000000016afdf1d0
AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV pycore_gc.h:151 in _PyGCHead_SET_NEXT
==54023==ABORTING

@ngoldbaum perhaps you can reproduce?

[workspace]
channels = ["https://prefix.dev/conda-forge"]
platforms = ["osx-arm64"]
preview = ["pixi-build"]
requires-pixi = ">=0.74.0"

[tasks]
repro = "python repro.py"

[dependencies]
numpy = {
  git = "https://github.com/numpy/numpy",
  package = {
    host-dependencies = {
      python = {
        flags = ["asan"],
        # passing with 3.15 branch
        # branch = "3.15",
        # failing with main
        branch = "main",
        git = "https://github.com/python/cpython",
        subdirectory = "Tools/pixi-packages",
      },
      meson-python = "*",
      cython = "*",
    },
    build = {
      backend.name = "pixi-build-python",
      config.compilers = ["c", "cxx"],
    },
  },
}
CPython versions tested on:

CPython main branch

Operating systems tested on:

macOS

Linked PRs
  • gh-157718

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Hướng nghiên cứu

Bắt đầu với reproducer của NumPy và các stack frame của CPython trong pycore_gc.h và typeobject.c, so sánh main với nhánh 3.15. Xem lại PR được liên kết gh-157718 để biết công việc hiện tại; được xem là hoàn tất khi vòng lặp numpy.prod được cung cấp không còn tạo ra AddressSanitizer SEGV trên CPython main.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
c, cpp, numpy, python
Lĩnh vực
backend
Loại issue
Lỗi
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Đình trệ
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
30/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.