Repository navigation
Assertion failures from calling create_builtin with invalid object #142029
Description
Activity
- addedinterpreter-core(Objects, Python, Grammar, and Parser dirs)(Objects, Python, Grammar, and Parser dirs)type-crashA hard crash of the interpreter, possibly with a core dumpA hard crash of the interpreter, possibly with a core dump
on Nov 28, 2025 Can reproduce with main branch on Linux. Note that the new
Sclass is unnecessary - it will crash with normal strings too.Doesn't seem to occur in 3.14 but I've only checked with the prebuilt binary and not the latest development version.
With regards to the second part:
Seems that the call checks thatnameis a string, but nothing more:
Lines 4410 to 4423 in 5ec03cf
PyObject *name = PyObject_GetAttrString(spec, "name"); if (name == NULL) { return NULL; } if (!PyUnicode_Check(name)) { PyErr_Format(PyExc_TypeError, "name must be string, not %.200s", Py_TYPE(name)->tp_name); Py_DECREF(name); return NULL; } PyObject *mod = create_builtin(tstate, name, spec, NULL); But in the underlying implementation, the length of the string is also checked:
Lines 158 to 159 in 5ec03cf
assert(PyUnicode_Check(name)); assert(PyUnicode_GetLength(name) > 0); The first issue seems to be a regression in 1e4e59b
It used to be that if a module was not found within the init table (i.e. it was not a built-in module),
create_builtin()would returnNone. However, when this codeblock was rewritten, the case wherenameis not found automatically assumes that it is an internal module (sysorbuiltins).
Lines 2433 to 2442 in 5ec03cf
PyModInitFunction p0 = initfunc; if (p0 == NULL) { p0 = lookup_inittab_initfunc(&info); if (p0 == NULL) { /* Cannot re-init internal module ("sys" or "builtins") */ assert(is_core_module(tstate->interp, info.name, info.path)); mod = import_add_module(tstate, info.name); goto finally; } } Adding a check for being a core module seems to fix the first issue:
- Reverting to the previous behaviour of returning
None(instead of crashing) if not found - Still performing the current behaviour under any circumstance that wouldn't currently crash.
@@ -2435,9 +2435,14 @@ create_builtin( p0 = lookup_inittab_initfunc(&info); if (p0 == NULL) { /* Cannot re-init internal module ("sys" or "builtins") */ - assert(is_core_module(tstate->interp, info.name, info.path)); - mod = import_add_module(tstate, info.name); - goto finally; + if (is_core_module(tstate->interp, info.name, info.path)) { + mod = import_add_module(tstate, info.name); + goto finally; + } + else { + mod = Py_NewRef(Py_None); + goto finally; + } } }
Happy to open a PR if that's warranted.
- Reverting to the previous behaviour of returning
sorry about the regression from gh-139196! I missed that there was different handling for the case of "no matching inittab entry" vs "found inittab entry but the initfunc is NULL". it wasn't an intentional omission.
I wrote itamaro@2b839b9 to restore the intended behavior. @dr-carlos since you already have a PR going, it might be best if you integrate my changes into your PR.
Reacted by dr-carlossorry about the regression from gh-139196! I missed that there was different handling for the case of "no matching inittab entry" vs "found inittab entry but the initfunc is NULL". it wasn't an intentional omission.
No problem! Thanks for the clarification.
I wrote itamaro@2b839b9 to restore the intended behavior. @dr-carlos since you already have a PR going, it might be best if you integrate my changes into your PR.
And thanks for a far more robust fix than my patch. I've now integrated it into #142054!
Reacted by Itamar Oren- added a commit that references this issue
on Dec 10, 2025 - added a commit that references this issue
on Dec 15, 2025 Thanks for your bug report, both issues have been fixed.
Crash report
What happened?
It's possible to abort the interpreter by running the code below:
It's also possible to get a different abort by running this code:
Backtrace for the first abort:
Backtrace for the second abort:
CPython versions tested on:
CPython main branch
Operating systems tested on:
Linux
Output from running 'python -VV' on the command line:
Python 3.15.0a2+ (heads/main-dirty:bc9e63dd9d2, Nov 26 2025, 19:23:56) [Clang 21.1.2 (2ubuntu6)]
Linked PRs
ValueErrorinstead of crashing on empty name given tocreate_builtin()#142033ModuleNotFoundErrorinstead of crashing on nonexsistent module name given tocreate_builtin()#142054