Skip to content

[3.15] gh-158803: Fix crash in bytes.join() on a concurrently mutated list - #159030

Merged
vstinner merged 1 commit into
python:3.15from
christianaurichzm:backport-05d80cc-3.15
Oct 10, 2026
Merged

vstinner merged 1 commit into
python:3.15from
christianaurichzm:backport-05d80cc-3.15

Conversation

@christianaurichzm

@christianaurichzm christianaurichzm commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

In the free-threaded build, bytes.join() and bytearray.join() read
items from the list with borrowed references and without holding its
lock, so another thread could replace and free an item before it was
increfed.

Run the join under Py_BEGIN_CRITICAL_SECTION_SEQUENCE_FAST, as
PyUnicode_Join() already does.
(cherry picked from commit 05d80cc)

The test file and the pycore_critical_section.h include in Objects/bytesobject.c come from gh-128213 on main, which is not in 3.15, so the test file is created here with only the new test and the include is added.

…utated list (pythonGH-158910)

In the free-threaded build, bytes.join() and bytearray.join() read
items from the list with borrowed references and without holding its
lock, so another thread could replace and free an item before it was
increfed.

Run the join under Py_BEGIN_CRITICAL_SECTION_SEQUENCE_FAST, as
PyUnicode_Join() already does.
(cherry picked from commit 05d80cc)
@christianaurichzm christianaurichzm changed the title [3.15] gh-158803: Fix crash in bytes.join() on a concurrently mutated… [3.15] gh-158803: Fix crash in bytes.join() on a concurrently mutated list Oct 8, 2026
@eendebakpt

Copy link
Copy Markdown
Contributor

Thanks for making the backport. We will want until the branch is open for 3.15.1 before merging.

@vstinner
vstinner merged commit 9461bea into python:3.15 Oct 10, 2026
55 checks passed
@vstinner

Copy link
Copy Markdown
Member

Python 3.15.0 has just been released. LGTM. I merged the 3.15 backport.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants