Skip to content

Not all types have "trashcan" protection and tp_dealloc can overflow stack #124715

Description

@nascheme

We occasionally fix these kinds of bugs, like GH-102356. However, the fix by adding the "trashcan" macros to the tp_dealloc method only fixes that specific type. It would be better to have a more generic fix. A crash due to the C stack overflow leaves the user mystified as to what the problem is and these kinds of bugs could be hard to reproduce (requiring long chains of objects calling tp_dealloc recursively).

Linked PRs

Activity

  1. added
    type-crashA hard crash of the interpreter, possibly with a core dump
    on Sep 27, 2024
  2. added a commit that references this issue on Apr 30, 2025
  3. added a commit that references this issue on May 1, 2025
  4. nascheme commented on May 1, 2025

    @nascheme
    MemberAuthor

    Regarding untracking, when I was working on my "integrate trashcan PR", I started wondering if _PyObject_GC_UNTRACK() should just be changed to check if the object is already untracked and not crash. I originally made it not safe to call twice because I wanted the tiny performance benefit (avoid the branch, I wanted GC support to have as little extra overhead as possible). However, in retrospect, I think it was a mistake. Knowing when it is safe to call _PyObject_GC_UNTRACK() in theory is possible but in practice it gets really painful. If you look at typeobject.c, it has to take great care to avoid _PyObject_GC_UNTRACK() from crashing.

    Maybe we should profile this and see if it has any performance impact at all? There has been many bugs related to this over the years.

  5. added 2 commits that reference this issue on May 5, 2025
  6. added a commit that references this issue on Jul 12, 2025
  7. nascheme commented on Jul 14, 2025

    @nascheme
    MemberAuthor

    I believe this issue has been fixed with GH-132280.

  8. added a commit that references this issue on Jan 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    interpreter-core(Objects, Python, Grammar, and Parser dirs)type-crashA hard crash of the interpreter, possibly with a core dump

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions