Skip to content

socketmodule.c: Reference and buffer leaks via audit hook failures #146245

Description

@aisk

Bug report

Bug description:

Summary

Two leak bugs in socketmodule.c triggered when PySys_Audit raises:

  1. getaddrinfo (line 6983): idna and/or pstr refs leaked when audit hook raises. ~657 objects leaked per 1000 calls.
  2. sock_sendto (line 4810): pbuf Py_buffer not released when audit hook raises.

Reproducer (getaddrinfo leak)

import socket, sys

sys.addaudithook(lambda *a: (_ for _ in ()).throw(RuntimeError("audit")))
before = sys.gettotalrefcount()
for i in range(1000):
    try:
        socket.getaddrinfo("localhost", 80)
    except RuntimeError:
        pass
after = sys.gettotalrefcount()
print(f"Leaked {after - before} objects in 1000 calls")

CPython versions tested on:

CPython main branch

Operating systems tested on:

No response

Linked PRs

Activity

  1. added
    type-bugAn unexpected behavior, bug, or error
    on Mar 21, 2026
  2. added a commit that references this issue on Mar 21, 2026
  3. aisk commented on Mar 21, 2026

    @aisk
    MemberAuthor

    Hi @kimimgo, I already had a working PR when I created the issue. I created the issue just to get the issue number as a comment in the test.

    How did you create your PR within 10 minutes just after the issue was created? And the news entry filename in your PR is Misc/NEWS.d/next/Library/2026-03-21-00-00-00.gh-issue-146245.SockAud.rst, the time part is just zero. In current LLMs, the KV-cache is very important for performance, so most of the LLM agents will just use zero time in system prompts, so I suspect it is generated by LLM.

    If so, please read https://devguide.python.org/getting-started/generative-ai/ before contributing.

  4. kimimgo commented on Mar 21, 2026

    @kimimgo
    Contributor

    @aisk You're right — I should have checked for an existing PR first. I'll close my PR (#146247) since yours was already in progress.

    To be transparent: yes, I used an AI coding assistant (Claude Code) to help analyze and fix the issue. The speed and the 00-00-00 timestamp in the NEWS entry are artifacts of that workflow. I appreciate you pointing out the devguide AI policy — I've read it and will follow it more carefully going forward.

    That said, I do review and validate all changes before submitting — the responsibility for the code is mine. In this case though, your PR takes priority. Apologies for the duplicate, and thanks for the thorough bug report!

  5. added a commit that references this issue on Mar 22, 2026
  6. added 2 commits that reference this issue on Mar 22, 2026
  7. serhiy-storchaka commented on Mar 22, 2026

    @serhiy-storchaka
    Member

    There were no an existing PR yet, but it's good manners to ask if the author of the issue wants to provide a PR. Since they were the first to find this problem, they must have been working on it and may already have a solution ready. Correctly identifying the problem and creating a reproducer is important and hard work.

  8. serhiy-storchaka commented on Mar 22, 2026

    @serhiy-storchaka
    Member

    It is safer to take issues created months or years ago. If there are no ready PRs or patches, then the original reporter perhaps not so interesting in it or does not have enough time or qualification.

    But if there is a discussion, you should read it. Perhaps the issue is still open because no good solution was found.

  9. added 2 commits that reference this issue on Mar 22, 2026
  10. kimimgo commented on Mar 22, 2026

    @kimimgo
    Contributor

    @serhiy-storchaka Thank you for the advice — that's a good rule of thumb. I'll make sure to check for existing PRs and ask before submitting in the future, especially for freshly-filed issues.

  11. added a commit that references this issue on Apr 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    extension-modulesC modules in the Modules dirtype-bugAn unexpected behavior, bug, or error

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions