Repository navigation
Destructing _datetime in sub-interpreters in the same time may crash the process #136423
Copy link
Copy link
Closed
Closed
Copy link
Labels
extension-modulesC modules in the Modules dirC modules in the Modules dirtopic-subinterpreterstype-crashA hard crash of the interpreter, possibly with a core dumpA hard crash of the interpreter, possibly with a core dump
Description
Activity
- addedtype-crashA hard crash of the interpreter, possibly with a core dumpA hard crash of the interpreter, possibly with a core dump
on Jul 8, 2025 - addedextension-modulesC modules in the Modules dirC modules in the Modules dir
on Jul 8, 2025 - changed the title
[-]Destructing _datetime in sub-interpreters in the same time may crash the process[/-][+]Destructing `_datetime` in sub-interpreters in the same time may crash the process[/+]on Jul 8, 2025 I encountered the same bug while using the C Python API.
It seems like
Py_TPFLAGS_READYis cleared beforemanaged_static_type_state_clear(), which conficts with_PyStaticType_InitForExtension()then crashes at_PyObject_ClearFreeLists().Lines 6606 to 6616 in db47f4d
if (final) { BEGIN_TYPE_LOCK(); type_clear_flags(type, Py_TPFLAGS_READY); set_version_unlocked(type, 0); END_TYPE_LOCK(); } _PyStaticType_ClearWeakRefs(interp, type); managed_static_type_state_clear(interp, type, isbuiltin, final); /* We leave _Py_TPFLAGS_STATIC_BUILTIN set on tp_flags. */ } managed_static_type_state_clear()invokes:Lines 254 to 258 in db47f4d
static inline void managed_static_type_index_clear(PyTypeObject *self) { self->tp_subclasses = NULL; } So, a possible workaround only for this issue would be:
int _PyStaticType_InitForExtension(PyInterpreterState *interp, PyTypeObject *self) { - return init_static_type(interp, self, 0, ((self->tp_flags & Py_TPFLAGS_READY) == 0)); + return init_static_type(interp, self, 0, self->tp_subclasses == NULL); }Fixed by #136583
Metadata
Metadata
Assignees
Labels
extension-modulesC modules in the Modules dirC modules in the Modules dirtopic-subinterpreterstype-crashA hard crash of the interpreter, possibly with a core dumpA hard crash of the interpreter, possibly with a core dump
Projects
- StatusShow more project fieldsDone
- StatusShow more project fieldsDone
Crash report
What happened?
This code may lead to a interpreter crash:
I think there is a double free here.
Please note that there is a similar issue may crash the interpreter but in the initializing phase: #136421
CPython versions tested on:
CPython main branch
Operating systems tested on:
macOS, Windows
Output from running 'python -VV' on the command line:
Python 3.15.0a0 (heads/main:ba9c1986305, Jul 8 2025, 22:13:18) [MSC v.1943 64 bit (AMD64)]