Skip to content

Segfault in bytes.join for mutating list #158803

Description

@eendebakpt

Crash report

In the FT build bytes.join can crash on a mutating list.

import threading

lst = [bytes(10) for _ in range(100)]

def mutate():
    while True:
        for i in range(100):
            lst[i] = bytes(10)      # new object; the old one is freed here

threading.Thread(target=mutate, daemon=True).start()
while True:
    b''.join(lst)

The issue seems to be on line

item = PySequence_Fast_GET_ITEM(seq, i);
where a borrowed ref is used.

A solution could be to add a Py_BEGIN_CRITICAL_SECTION_SEQUENCE_FAST like in #119315

#119315

CPython versions tested on:

CPython main branch

Operating systems tested on:

Windows

Output from running 'python -VV' on the command line:

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    interpreter-core(Objects, Python, Grammar, and Parser dirs)type-crashA hard crash of the interpreter, possibly with a core dump

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions