Skip to content

Errors during array module import result in double-DECREF #153210

Description

@stestagg

Crash report

What happened?

In DEBUG build:

import collections.abc

del collections.abc.MutableSequence
import array

or:

sys.setrecursionlimit(25)
import array

generates a double DECREF on the array ArrayType object due to poisoned module state:

Python/gc.c:96: gc_decref: Assertion "gc_get_refs(g) > 0" failed: refcount is too small
object type name: type
object repr     : <class 'array.array'>
Fatal Python error: _PyObject_AssertFailed: _PyObject_AssertFailed

Analysis

So, array_modexec creates the ArrayType and assigns it to array state:

CREATE_TYPE(m, state->ArrayType, &array_spec);

It then goes on to do some other setup tasks, and if any of these fail, it DECREF's state->ArrayType but leaves the type object on the state struct:

cpython/Modules/arraymodule.c

Lines 3409 to 3421 in 836b206

PyObject *mutablesequence = PyImport_ImportModuleAttrString(
"collections.abc", "MutableSequence");
if (!mutablesequence) {
Py_DECREF((PyObject *)state->ArrayType);
return -1;
}
PyObject *res = PyObject_CallMethod(mutablesequence, "register", "O",
(PyObject *)state->ArrayType);
Py_DECREF(mutablesequence);
if (!res) {
Py_DECREF((PyObject *)state->ArrayType);
return -1;
}

Returning -1 error code.

PyModule_ExecDef passes the -1 up the chain:

return -1;

which ends up with an exception in _bootstrap.py:
except:
try:
del sys.modules[spec.name]
except KeyError:
pass
raise

At this point, the array module refcount falls and it's cleaned up, and array_clear calls:

Py_CLEAR(state->ArrayType);

because the ArrayType pointer is still in the module state, this generates the double DECREF

CPython versions tested on:

CPython main branch

Operating systems tested on:

Linux

Output from running 'python -VV' on the command line:

Python 3.16.0a0 (heads/main-dirty:1034e73, Jul 6 2026, 11:11:46) [Clang 22.1.6 ]

Linked PRs

Activity

  1. added
    type-crashA hard crash of the interpreter, possibly with a core dump
    on Jul 6, 2026
  2. self-assigned this
    on Jul 6, 2026
  3. sobolevn commented on Jul 6, 2026

    @sobolevn
    Member

    Indeed, I also found several other problems with the setup. I will send a PR, thanks for the report! 👍

  4. stestagg commented on Jul 6, 2026

    @stestagg
    ContributorAuthor

    @sobolevn Haha, we got there at the same time :), I'll withdraw mine

  5. added 2 commits that reference this issue on Jul 7, 2026
  6. nedbat commented on Jul 7, 2026

    @nedbat
    Member

    @sobolevn I'm seeing failures with from array import ArrayType: https://github.com/coveragepy/coveragepy/actions/runs/28859740335

    It also happens with newly built main:

    % /usr/local/cpython/bin/python3.16
    Python 3.16.0a0 (heads/main:2cd5b79284d, Jul  7 2026, 07:09:41) [Clang 21.0.0 (clang-2100.1.1.101)] on darwin
    Type "help", "copyright", "credits" or "license" for more information.
    >>> from array import ArrayType
    Traceback (most recent call last):
      File "<python-input-0>", line 1, in <module>
        from array import ArrayType
    ImportError: cannot import name 'ArrayType' from 'array' (/usr/local/cpython/lib/python3.16/lib-dynload/array.cpython-316-darwin.so)
    
  7. nedbat commented on Jul 7, 2026

    @nedbat
    Member

    Building from the commit before this fix:

    % /usr/local/cpython/bin/python3.16
    Python 3.16.0a0 (tags/v3.15.0b1-901-g35c6779c7b5:35c6779c7b5, Jul  7 2026, 07:35:22) [Clang 21.0.0 (clang-2100.1.1.101)] on darwin
    Type "help", "copyright", "credits" or "license" for more information.
    >>> from array import ArrayType
    >>>
    
  8. sobolevn commented on Jul 7, 2026

    @sobolevn
    Member

    @nedbat thanks for the report! on it :)

  9. added 5 commits that reference this issue on Jul 7, 2026
  10. added a commit that references this issue on Jul 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

extension-modulesC modules in the Modules dirtype-crashA hard crash of the interpreter, possibly with a core dump

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions