Repository navigation
Segmentation fault with Python 3.14.1, 3.13.10: insertdict: Assertion `!_PyDict_HasSplitTable(mp)' failed. #142218
Description
Activity
- addedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on Dec 3, 2025 CC @ZeroIntensity (mentorship):
type-crash,3.14,3.13, removetype-bugI'll try to reproduce
Reacted by Peter BiermaTriggers an assertion error in debug mode for 3.14, I assume the same for 3.13:
❯ ./python seg_fault_debug.py python: Objects/dictobject.c:1866: insertdict: Assertion `!_PyDict_HasSplitTable(mp)' failed. Aborted (core dumped)I'll see if we can shrink the reproducer.
- addedtype-crashA hard crash of the interpreter, possibly with a core dumpA hard crash of the interpreter, possibly with a core dump3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes3.15bugs and security fixesbugs and security fixesand removedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on Dec 3, 2025 I simplified the reproducer a little bit by removing the dataclasses, but it's still messy
This is related to the slow attribute resolution path -- can't reproduce with fast slot access, which is perhaps why the assertion error regards a dictionary insertion (
__dict__).Smaller, without dataclasses or asyncio:
from enum import Enum class O: def __init__(self): self.attr = "whatever" class E(str, Enum): a = "attr" setattr(O(), E.a, "new-whatever")
(
"whatever"and"new-whatever"could be any other objects, e.g.Noneand an empty tuple)Reproduced on 3.15, thanks @ZeroIntensity. This must have been a flawed bugfix backported everywhere.
- addedinterpreter-core(Objects, Python, Grammar, and Parser dirs)(Objects, Python, Grammar, and Parser dirs)
on Dec 3, 2025 from enum import Enum class O: def __init__(self): self.attr = "whatever" class E(str, Enum): a = "attr" O().__dict__.__setitem__(E.a, "something else") # `E.a` as the string seems to cause segfault
The class is required in this repro -- I guess it's something related to how
__dict__is governed by the owner.For example, this will not fail:
-O().__dict__.__setitem__(E.a, "something else") # `E.a` as the string seems to cause segfault +import copy +copy.deepcopy(O().__dict__).__setitem__(E.a, "something else")
So this likely isn't a problem with dictionaries.
7 remaining items
- changed the title
[-]Segmentation fault with Python 3.14.1, 3.13.10[/-][+]Segmentation fault with Python 3.14.1, 3.13.10: insertdict: Assertion `!_PyDict_HasSplitTable(mp)' failed.[/+]on Dec 3, 2025 Thanks all for the quick report, repro minimising, bisecting, fixing, reviewing and backporting!
Reacted by Bartosz SławeckiReacted by Mikhail Efimov- moved this from Todo to Done in Release and Deferred blockers 🚫
on Dec 4, 2025
Metadata
Metadata
Assignees
Labels
Projects
- StatusShow more project fieldsDone
Bug report
Bug description:
There's a segmentation fault in Python 3.14.1 and 3.13.10 which doesn't happen in the previous point releases.
I'm sorry about the messy reproducer, the issue was noticed in a much larger program and this is what I ended up with after removing all the cruft.
seg_fault_issue_import.py:seg_fault_debug.py:Running
seg_fault_debug.pycauses a segmentation fault with Python 3.13.10 and 3.14.1:Original reproducer
seg_fault_issue_import.py:seg_fault_debug.py:CPython versions tested on:
3.14
Operating systems tested on:
Linux
Linked PRs