python / python/cpython

Iterating over ctypes pointer causes hang or segmentation fault

未关闭
#92,347 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

topic-ctypes type-crash
主要语言
Python
星标
77.2k
派生
36k
平均合并
1 天 9 小时
30 天内合并 PR
558

描述

Trying to create iterable (list, tuple, set etc.) from PyCPointer instance leads to hang or segmentation fault.
This code causes hang and memory leak which goes until oom-killer kills python process:

import ctypes
x = ctypes.c_int32(12345)
buf4_p_t = ctypes.POINTER(ctypes.ARRAY(ctypes.c_byte, 4))
buf_p = ctypes.cast(ctypes.byref(x), buf4_p_t)
list(buf_p)

Similar code that causes segmentation fault:

import ctypes
x = ctypes.c_int32(54321)
xp = ctypes.pointer(x)
list(xp)

Iterating over pointer using for statement leads to an infinite loop:
for i in buf_p: print(i)
for i in xp: print(i)
list(for i in buf_p)

Tried on 3.10.3 and 3.11.0a6+, fails at both.

The possible reason is that PyCPointer_Type defines sq_item without defining tp_iter.
Despite I can't imagine any reason why anyone might need to use pointer as iterable/sequence, raising TypeError in such situation would be a better option.

Linked PRs
  • gh-126318
  • gh-157801

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

从两个复现中展示的 ctypes PyCPointer 行为开始,确认受影响的 Python 版本中存在挂起、内存增长和段错误。追踪指针索引与迭代之间的交互,然后验证完成后的行为能够安全地拒绝迭代,而不会挂起或崩溃;链接的 PR gh-126318 和 gh-157801 提供了可供检查的现有工作。

由索引模型根据 Issue 内容生成。

评估

技术栈
python
领域
backend
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
停滞
描述清晰度
基本清楚
新手友好度
25/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。