Repository navigation
create_builtin() in _imp module trigger segfault if taking a builtin object as input #98354
Description
Activity
- addedtype-crashA hard crash of the interpreter, possibly with a core dumpA hard crash of the interpreter, possibly with a core dump
on Oct 17, 2022 Crashes on 3.12.0a0 with the following message:
Objects/unicodeobject.c:498: _PyUnicode_CheckConsistency: Assertion failed: PyType_HasFeature((Py_TYPE(((PyObject*)((op))))), ((1UL << 28))) Enable tracemalloc to get the memory block allocation traceback object address : 0x7ffff77eb530 object refcount : 4 object type : 0x555555c2b9b0 object type name: FakeSpec object repr : <__main__.FakeSpec object at 0x7ffff77eb530> Fatal Python error: _PyObject_AssertFailed: _PyObject_AssertFailed Python runtime state: initialized Current thread 0x00007ffff7cad740 (most recent call first): File "/home/.../cpython/crash_98354.py", line 9 in <module> Program received signal SIGABRT, Aborted.Looks like
_imp_create_builtinshould checknamefor being astrinstance in general, not only to avoid it being a keyword.To be clear, code should not be using the
_impmodule directly. That said, this would be relatively easy to reproduce with a metapath finder.Regardless, I was able to reproduce this on main (3.12, c051d55) using the OP code. It is not crashing on 3.8 (but does fail with a TypeError). Likewise with 3.9.
It does start crashing in 3.10. Looks like it started in 6223071 (GH-23378). It was probably caught before by the
PyUnicode_AsUTF8()(which was removed). Checking forPyUnicodeshould restore the pre-3.10 behavior.- added a commit that references this issue
on Oct 20, 2022 - added a commit that references this issue
on Oct 20, 2022 Per #98412 (comment), this might not be completely fixed yet.
@xiaxinmeng, can you verify if the problem you had is fixed on the main branch (i.e.
3.12a1)?Additional info from @chgnrdv:
- gh-98354: Add unicode check for 'name' attribute in _imp_create_builtin #98412 (comment)
- gh-98354: Add unicode check for 'name' attribute in _imp_create_builtin #98412 (comment)
@chgnrdv, can you confirm this is fixed by gh-99642 (for gh-99578)? If so, we can close this issue.
Per #98412 (comment), this might not be completely fixed yet.
@xiaxinmeng, can you verify if the problem you had is fixed on the main branch (i.e.
3.12a1)?Sorry for being late @ericsnowcurrently . I think this problem has been fixed.
It does not crash CPython any more, the behavior on the main branch 8f18ac0 is as follows:Traceback (most recent call last): File "/home/xxm/Downloads/cpython-main(2)/test.py", line 9, in <module> imp_time = _imp.create_builtin(A) ^^^^^^^^^^^^^^^^^^^^^^ TypeError: name must be string, not FakeSpecReacted by Eric Snow@ericsnowcurrently, sorry for the slow response. Yes, I confirm that refleak issue is fixed by gh-99578, and therefore we can close this one.
Reacted by Eric Snow
Crash report
In the following test program, _imp.create_builtin takes a object A as input. The object instance the name attribute as "self" at "self.name = self". This action triggers a segfault on CPython 3.10.7 and CPython 3.10.7. Similarly, if self.name = other keywords, e.g.,int, print, the program also crashes. It may need a checker for _imp.create_builtin to avoid keywords.
Error messages
Expected behavior on CPython 3.9.0
Unexpected Behavior on CPython 3.10.8
Segmentation fault(core dumped)
Your environment
CPython versions tested on:Python 3.10.8, Python 3.10.7
Operating system and architecture: [GCC 7.5.0] on linux