FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Crash when detaching dict from inline values and no memory is available · Issue #124547 · python/cpython · GitHub

Repository navigation

Crash when detaching dict from inline values and no memory is available #124547

Description

Bug report

Bug description:

Add to test_class.py in TestInlineValues:

    def test_detach_materialized_dict_no_memory(self):
        a = WithAttrs()
        d = a.__dict__
        _testcapi.set_nomemory(0)
        del a
        print(d["a"])

This will crash because the dictionary will no longer points to valid memory:

#0  Py_XINCREF (op=<unknown at remote 0xdddddddddddddddd>) at ./Include/refcount.h:456
#1  _Py_XNewRef (obj=<unknown at remote 0xdddddddddddddddd>) at ./Include/refcount.h:488
#2  _Py_dict_lookup_threadsafe (mp=mp@entry=0x7ffff778ff50, key=key@entry='a', hash=<optimized out>, value_addr=value_addr@entry=0x7fffffffb078) at Objects/dictobject.c:1544
#3  0x0000000000518457 in dict_subscript (self={'b': <unknown at remote 0xdddddddddddddddd>, 'd': <unknown at remote 0xdddddddddddddddd>, 'a': <unknown at remote 0xdddddddddddddddd>, 'c': <unknown at remote 0xdddddddddddddddd>}, key='a')
    at Objects/dictobject.c:3325
#4  0x000000000049d8c6 in PyObject_GetItem (o=o@entry={'b': <unknown at remote 0xdddddddddddddddd>, 'd': <unknown at remote 0xdddddddddddddddd>, 'a': <unknown at remote 0xdddddddddddddddd>, 'c': <unknown at remote 0xdddddddddddddddd>},
    key=key@entry='a') at Objects/abstract.c:158

CPython versions tested on:

CPython main branch

Operating systems tested on:

Linux

Linked PRs

Activity

  1. added
    type-bugAn unexpected behavior, bug, or error
    on Sep 25, 2024
  2. DinoV commented on Sep 25, 2024

    ContributorAuthor

    In 3.13 this could be fixed by having the dict keep the object alive, and then decref it when the dict goes away (recovering the object from the inline values). In 3.14 it's no longer possible to recover the inline values because we support inline values on objects of various sizes.

  3. rruuaanng commented on Sep 26, 2024

    Contributor

    It seems the issue originates from _testcapi.set_nomemory(0).

    When I run this code

    from test.test_class import WithAttrs
    import _testcapi
    
    
    a = WithAttrs()
    d = a.__dict__
    # _testcapi.set_nomemory(0)
    del a
    print(d, d["a"])

    It's output is as follows

    Running Release|x64 interpreter...
    object address  : 000001C8DC77D1E0
    object refcount : 3
    object type     : 00007FFFC0F03F80
    object type name: MemoryError
    object repr     :
    lost sys.stderr
    object address  : 000001C8DC77D120
    object refcount : 3
    object type     : 00007FFFC0F03F80
    object type name: MemoryError
    object repr     :
    lost sys.stderr
    object address  : 000001C8DC77D1E0
    object refcount : 3
    object type     : 00007FFFC0F03F80
    object type name: MemoryError
    object repr     :
    lost sys.stderr
    

    It seems that nomemory(0) is used to simulate normal conditions and insert debugging hooks, but I don’t understand why commenting it out appears to resolve the issue.

  4. added a commit that references this issue on Sep 27, 2024
  5. added a commit that references this issue on Sep 27, 2024
  6. added a commit that references this issue on Sep 27, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

type-bugAn unexpected behavior, bug, or error

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions


    Back | FazBrowse Home | New Git URL