Skip to content

Commit 5243d8d

Browse files
committed
Merge remote-tracking branch 'upstream/main' into tachyon-land-158581
2 parents 2dbcf91 + 1643525 commit 5243d8d

159 files changed

Lines changed: 5277 additions & 2744 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.github/workflows/build.yml‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -547,6 +547,9 @@ jobs:
547547
- check-name: Undefined behavior
548548
sanitizer: UBSan
549549
free-threading: false
550+
- check-name: Memory
551+
sanitizer: MSan
552+
free-threading: false
550553
uses: ./.github/workflows/reusable-san.yml
551554
with:
552555
sanitizer: ${{ matrix.sanitizer }}

‎.github/workflows/reusable-san.yml‎

Lines changed: 20 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -60,7 +60,7 @@ jobs:
6060
|| ''
6161
}}
6262
- name: UBSan option setup
63-
if: inputs.sanitizer != 'TSan'
63+
if: inputs.sanitizer == 'UBSan'
6464
run: >-
6565
echo
6666
"UBSAN_OPTIONS=${SAN_LOG_OPTION}
@@ -69,6 +69,20 @@ jobs:
6969
>> "$GITHUB_ENV"
7070
env:
7171
SAN_LOG_OPTION: log_path=${{ github.workspace }}/san_log
72+
- name: MSan option setup
73+
if: inputs.sanitizer == 'MSan'
74+
run: |
75+
echo "MSAN_OPTIONS=${SAN_LOG_OPTION} allocator_may_return_null=1 handle_segv=0" >> "$GITHUB_ENV"
76+
# MSan reports false positives for memory initialized by libraries
77+
# that are not built with MSan, so disable modules that use them.
78+
# _remote_debugging links to libzstd directly, but we unpoision the memory.
79+
{
80+
echo '*disabled*'
81+
echo '_bz2 _ctypes _curses _curses_panel _dbm _decimal _gdbm _hashlib'
82+
echo '_lzma _sqlite3 _ssl _tkinter _uuid _zstd readline zlib'
83+
} > Modules/Setup.local
84+
env:
85+
SAN_LOG_OPTION: log_path=${{ github.workspace }}/san_log
7286
- name: Add ccache to PATH
7387
run: |
7488
echo "PATH=/usr/lib/ccache:$PATH" >> "$GITHUB_ENV"
@@ -93,6 +107,8 @@ jobs:
93107
# gh-157958: -O2 instead of the pydebug default -Og to avoid a clang 21
94108
# compile-time blowup on some interpreter files.
95109
# (https://github.com/llvm/llvm-project/issues/179695)
110+
# MSan uses --with-assertions instead of --with-pydebug because its
111+
# hooks on the Python memory allocators hide uninitialized reads.
96112
- name: Configure CPython
97113
run: >-
98114
./configure
@@ -101,9 +117,11 @@ jobs:
101117
${{
102118
inputs.sanitizer == 'TSan'
103119
&& '--with-thread-sanitizer'
120+
|| inputs.sanitizer == 'MSan'
121+
&& '--with-memory-sanitizer'
104122
|| '--with-undefined-behavior-sanitizer --with-strict-overflow'
105123
}}
106-
--with-pydebug
124+
${{ inputs.sanitizer == 'MSan' && '--with-assertions' || '--with-pydebug' }}
107125
${{ inputs.sanitizer == 'TSan' && '--with-openssl="$OPENSSL_DIR" --with-openssl-rpath=auto' || '' }}
108126
${{ inputs.free-threading && '--disable-gil' || '' }}
109127
- name: Build CPython

‎Doc/c-api/exceptions.rst‎

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1034,6 +1034,10 @@ because the :ref:`call protocol <call>` takes care of recursion handling.
10341034
case, a :exc:`RecursionError` is set and a nonzero value is returned.
10351035
Otherwise, zero is returned.
10361036
1037+
The check is based on the remaining C stack space of the current thread,
1038+
not on a count of calls, so it is unaffected by
1039+
:c:func:`Py_SetRecursionLimit` and :func:`sys.setrecursionlimit`.
1040+
10371041
*where* should be a UTF-8 encoded string such as ``" in instance check"`` to
10381042
be concatenated to the :exc:`RecursionError` message caused by the recursion
10391043
depth limit.
@@ -1044,6 +1048,10 @@ because the :ref:`call protocol <call>` takes care of recursion handling.
10441048
.. versionchanged:: 3.9
10451049
This function is now also available in the :ref:`limited API <limited-c-api>`.
10461050
1051+
.. versionchanged:: 3.14
1052+
The check is based on the remaining C stack space. Previously, a
1053+
separate counter of C-level calls was used.
1054+
10471055
.. c:function:: void Py_LeaveRecursiveCall(void)
10481056
10491057
Ends a :c:func:`Py_EnterRecursiveCall`. Must be called once for each

‎Doc/c-api/interp-lifecycle.rst‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -514,7 +514,7 @@ Process-wide parameters
514514
Return the version of this Python interpreter. This is a string that looks
515515
something like ::
516516
517-
"3.0a5+ (py3k:63103M, May 12 2008, 00:53:55) \n[GCC 4.2.3]"
517+
"3.15.0rc2 (3.15.0~rc2-1.fc44.x86_64, Sep 3 2026, 00:00:00) [GCC 16.2.1 20260819 (Red Hat 16.2.1-2)]"
518518
519519
.. index:: single: version (in module sys)
520520

‎Doc/c-api/sys.rst‎

Lines changed: 23 additions & 20 deletions
Original file line numberDiff line numberDiff line change
@@ -152,28 +152,29 @@ Operating System Utilities
152152
<c-preinit>` and so that the LC_CTYPE locale is properly configured: see
153153
the :c:func:`Py_PreInitialize` function.
154154
155-
Decode a byte string from the :term:`filesystem encoding and error handler`.
156-
If the error handler is :ref:`surrogateescape error handler
157-
<surrogateescape>`, undecodable bytes are decoded as characters in range
158-
U+DC80..U+DCFF; and if a byte sequence can be decoded as a surrogate
159-
character, the bytes are escaped using the surrogateescape error handler
160-
instead of decoding them.
155+
Decode a byte string from the :term:`filesystem encoding <filesystem
156+
encoding and error handler>` with the :ref:`surrogateescape error handler
157+
<surrogateescape>`.
158+
159+
Undecodable bytes are decoded as characters in range U+DC80..U+DCFF. If a
160+
byte sequence can be decoded as a surrogate character, escape the bytes
161+
using the surrogateescape error handler instead of decoding them.
161162
162163
Return a pointer to a newly allocated wide character string, use
163164
:c:func:`PyMem_RawFree` to free the memory. If size is not ``NULL``, write
164165
the number of wide characters excluding the null character into ``*size``
165166
166-
Return ``NULL`` on decoding error or memory allocation error. If *size* is
167-
not ``NULL``, ``*size`` is set to ``(size_t)-1`` on memory error or set to
168-
``(size_t)-2`` on decoding error.
167+
On memory allocation failure, set *\*size* to ``(size_t)-1`` and return
168+
``NULL``.
169+
170+
On decode error, set *\*size* to ``(size_t)-2`` and return ``NULL``.
171+
Decoding errors should never happen, unless there is a bug in the C
172+
library.
169173
170174
The :term:`filesystem encoding and error handler` are selected by
171175
:c:func:`PyConfig_Read`: see :c:member:`~PyConfig.filesystem_encoding` and
172176
:c:member:`~PyConfig.filesystem_errors` members of :c:type:`PyConfig`.
173177
174-
Decoding errors should never happen, unless there is a bug in the C
175-
library.
176-
177178
Use the :c:func:`Py_EncodeLocale` function to encode the character string
178179
back to a byte string.
179180
@@ -195,17 +196,19 @@ Operating System Utilities
195196
196197
.. c:function:: char* Py_EncodeLocale(const wchar_t *text, size_t *error_pos)
197198
198-
Encode a wide character string to the :term:`filesystem encoding and error
199-
handler`. If the error handler is :ref:`surrogateescape error handler
200-
<surrogateescape>`, surrogate characters in the range U+DC80..U+DCFF are
201-
converted to bytes 0x80..0xFF.
199+
Encode a wide character string to the :term:`filesystem encoding <filesystem
200+
encoding and error handler>` with the :ref:`surrogateescape error handler
201+
<surrogateescape>`. Surrogate characters in the range U+DC80..U+DCFF are
202+
encoded to bytes 0x80..0xFF.
202203
203204
Return a pointer to a newly allocated byte string, use :c:func:`PyMem_Free`
204-
to free the memory. Return ``NULL`` on encoding error or memory allocation
205-
error.
205+
to free the memory.
206+
207+
On memory allocation failure, set *\*error_pos* to ``(size_t)-1`` and return
208+
``NULL``.
206209
207-
If error_pos is not ``NULL``, ``*error_pos`` is set to ``(size_t)-1`` on
208-
success, or set to the index of the invalid character on encoding error.
210+
On encoding error, set *\*error_pos* to the index of the first unencodable
211+
character and return ``NULL``.
209212
210213
The :term:`filesystem encoding and error handler` are selected by
211214
:c:func:`PyConfig_Read`: see :c:member:`~PyConfig.filesystem_encoding` and

‎Doc/c-api/unicode.rst‎

Lines changed: 40 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -168,8 +168,14 @@ access to internal read-only data of Unicode objects:
168168
The function performs no checks for any of its requirements,
169169
and is intended for usage in loops.
170170
171+
While :class:`str` objects are usually immutable in Python, this special C API allows
172+
mutating a fresh :class:`str` object if the string has not been "used" yet.
173+
171174
.. versionadded:: 3.3
172175
176+
.. soft-deprecated:: next
177+
Use the :c:type:`PyUnicodeWriter` API instead.
178+
173179
174180
.. c:function:: Py_UCS4 PyUnicode_READ(int kind, void *data, Py_ssize_t index)
175181
@@ -407,9 +413,15 @@ APIs:
407413
using the :c:type:`PyUnicodeWriter` API, or one of the ``PyUnicode_From*``
408414
functions below.
409415
416+
While :class:`str` objects are usually immutable in Python, this special C API
417+
returns a :class:`str` object that can be mutated, except if *size* is zero, in which
418+
case it returns the immutable empty string constant.
410419
411420
.. versionadded:: 3.3
412421
422+
.. soft-deprecated:: next
423+
Use the :c:type:`PyUnicodeWriter` API instead.
424+
413425
414426
.. c:function:: PyObject* PyUnicode_FromKindAndData(int kind, const void *buffer, \
415427
Py_ssize_t size)
@@ -754,11 +766,16 @@ APIs:
754766
possible. Returns ``-1`` and sets an exception on error, otherwise returns
755767
the number of copied characters.
756768
757-
The string must not have been “used” yet.
769+
While :class:`str` objects are usually immutable in Python, this special C API allows
770+
mutating a fresh :class:`str` object if the string has not been "used" yet.
771+
758772
See :c:func:`PyUnicode_New` for details.
759773
760774
.. versionadded:: 3.3
761775
776+
.. soft-deprecated:: next
777+
Use the :c:type:`PyUnicodeWriter` API instead.
778+
762779
763780
.. c:function:: int PyUnicode_Resize(PyObject **unicode, Py_ssize_t length);
764781
@@ -774,6 +791,14 @@ APIs:
774791
The function doesn't check string content, the result may not be a
775792
string in canonical representation.
776793
794+
While :class:`str` objects are usually immutable in Python, this special C API
795+
can resize a :class:`str` object in-place if the string has not been "used" yet.
796+
It returns a :class:`str` object which can be mutated, except if *size* is zero, in
797+
which case it returns the immutable empty string constant.
798+
799+
.. soft-deprecated:: next
800+
Use the :c:type:`PyUnicodeWriter` API instead.
801+
777802
778803
.. c:function:: Py_ssize_t PyUnicode_Fill(PyObject *unicode, Py_ssize_t start, \
779804
Py_ssize_t length, Py_UCS4 fill_char)
@@ -784,14 +809,19 @@ APIs:
784809
Fail if *fill_char* is bigger than the string maximum character, or if the
785810
string has more than 1 reference.
786811
787-
The string must not have been “used” yet.
788-
See :c:func:`PyUnicode_New` for details.
789-
790812
Return the number of written characters, or return ``-1`` and raise an
791813
exception on error.
792814
815+
While :class:`str` objects are usually immutable in Python, this special C API allows
816+
mutating a fresh :class:`str` object if the string has not been "used" yet.
817+
818+
See :c:func:`PyUnicode_New` for details.
819+
793820
.. versionadded:: 3.3
794821
822+
.. soft-deprecated:: next
823+
Use the :c:type:`PyUnicodeWriter` API instead.
824+
795825
796826
.. c:function:: int PyUnicode_WriteChar(PyObject *unicode, Py_ssize_t index, \
797827
Py_UCS4 character)
@@ -804,11 +834,16 @@ APIs:
804834
See :c:func:`PyUnicode_WRITE` for a version that skips these checks,
805835
making them your responsibility.
806836
807-
The string must not have been “used” yet.
837+
While :class:`str` objects are usually immutable in Python, this special C API allows
838+
mutating a fresh :class:`str` object if the string has not been "used" yet.
839+
808840
See :c:func:`PyUnicode_New` for details.
809841
810842
.. versionadded:: 3.3
811843
844+
.. soft-deprecated:: next
845+
Use the :c:type:`PyUnicodeWriter` API instead.
846+
812847
813848
.. c:function:: Py_UCS4 PyUnicode_ReadChar(PyObject *unicode, Py_ssize_t index)
814849

‎Doc/howto/abi3t-migration.rst‎

Lines changed: 30 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -217,9 +217,9 @@ Module export hook
217217

218218
Unless you've done this step already, your extension module defines a
219219
:ref:`module initialization function <extension-pyinit>`
220-
named :samp:`PyInit_{<module_name>}`.
220+
named :samp:`PyInit_{<modname>}` (where ``modname`` is the name of your module).
221221
You will need to port it to a :ref:`module export hook <extension-export-hook>`,
222-
:samp:`PyModExport_{<module name>}`, a feature added in CPython 3.15 in
222+
:samp:`PyModExport_{<modname>}`, a feature added in CPython 3.15 in
223223
:pep:`793`.
224224

225225
Your existing init function should look like this (with your own names
@@ -297,6 +297,34 @@ pointer to static data.
297297
If you cannot avoid additional code, refer to the
298298
:ref:`caveats in PyModExport documentation <pymodexport-api-caveats>`.
299299

300+
.. note::
301+
302+
When building for Windows using the Setuptools_ build tool,
303+
removing the :samp:`PyInit_{<modname>}` function may result in the linker error
304+
:samp:`LINK : error LNK2001: unresolved external symbol PyInit_{<modname>}`.
305+
This is caused by Setuptools passing an ``/EXPORT`` linker flag, which
306+
is redundant since Python 3.15 (see :gh:`141671`).
307+
A workaround is to add a dummy :samp:`PyInit_{<modname>}` function
308+
to your code.
309+
Python 3.15+ will never call this function if
310+
:samp:`PyModExport_{<modname>}` is present, so it can always fail:
311+
312+
.. code-block:: c
313+
314+
// Workaround for https://github.com/pypa/distutils/issues/387
315+
PyMODINIT_FUNC
316+
PyInit_<modname>(void)
317+
{
318+
PyErr_SetString(PyExc_SystemError,
319+
"PyInit_* called for module with PyModExport_*");
320+
return NULL;
321+
}
322+
323+
(This issue is present in Setuptools 84.0.0; it might be fixed in newer
324+
versions.)
325+
326+
.. _Setuptools: https://setuptools.pypa.io/
327+
300328

301329
Existing slots
302330
--------------

‎Doc/library/codecs.rst‎

Lines changed: 21 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -1395,15 +1395,6 @@ encodings.
13951395
| | | :mod:`encodings.idna`. |
13961396
| | | Only ``errors='strict'`` |
13971397
| | | is supported. |
1398-
| | | |
1399-
| | | .. warning:: |
1400-
| | | |
1401-
| | | This codec builds on |
1402-
| | | ``punycode``, whose |
1403-
| | | algorithms scale |
1404-
| | | poorly, so limit the |
1405-
| | | length of untrusted |
1406-
| | | input. |
14071398
+--------------------+---------+---------------------------+
14081399
| mbcs | ansi, | Windows only: Encode the |
14091400
| | dbcs | operand according to the |
@@ -1655,11 +1646,6 @@ Applications) and :rfc:`3492` (Nameprep: A Stringprep Profile for
16551646
Internationalized Domain Names (IDN)). It builds upon the ``punycode`` encoding
16561647
and :mod:`stringprep`.
16571648

1658-
.. warning::
1659-
1660-
This module builds on ``punycode``, whose algorithms scale poorly, so limit
1661-
the length of untrusted input.
1662-
16631649
If you need the IDNA 2008 standard from :rfc:`5891` and :rfc:`5895`, use the
16641650
third-party :pypi:`idna` module.
16651651

@@ -1697,11 +1683,31 @@ international domain names, and to unify similar characters. The nameprep
16971683
functions can be used directly if desired.
16981684

16991685

1700-
.. function:: nameprep(label)
1686+
.. function:: nameprep(label, *, limit=None)
17011687

17021688
Return the nameprepped version of *label*. The implementation currently assumes
17031689
query strings, so ``AllowUnassigned`` is true.
17041690

1691+
Raise :exc:`UnicodeEncodeError` if the nameprep algorithm emits an error.
1692+
1693+
If the *limit* argument is given, it should be set to the maximum size
1694+
of an encoded A-label (that is, 63 for IDNA).
1695+
:func:`!nameprep` will raise :exc:`UnicodeEncodeError` if the label is
1696+
**much** larger than *limit*.
1697+
Note that this is only a rough check meant to skip expensive processing
1698+
of extremely large input; the caller should check any exact
1699+
limits separately.
1700+
1701+
.. warning::
1702+
1703+
For backwards compatibility, label size is unlimited by default.
1704+
This may cause issues when processing the result with the
1705+
``punycode`` encoding, whose algorithms scale poorly.
1706+
1707+
.. versionchanged:: next
1708+
1709+
Added the *limit* parameter.
1710+
17051711

17061712
.. function:: ToASCII(label)
17071713

‎Doc/library/ctypes.rst‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1755,8 +1755,9 @@ These prefabricated library loaders are available:
17551755
:c:expr:`int`, which is of course not always the truth, so you have to assign
17561756
the correct :attr:`!restype` attribute to use these functions.
17571757

1758-
Note that if the Python interpreter is statically linked, this will be
1759-
``None``, as ``dlopen`` is not possible in this case.
1758+
.. note::
1759+
1760+
If the Python interpreter is statically linked, this may be ``None``.
17601761

17611762
.. audit-event:: ctypes.dlopen name ctypes.LibraryLoader
17621763

‎Doc/using/configure.rst‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1026,6 +1026,10 @@ Debug options
10261026

10271027
Enable MemorySanitizer allocation error detector, ``msan`` (default is no).
10281028

1029+
MSan reports false positives for memory initialized by libraries that are
1030+
not built with MSan, so either build all dependencies with MSan or disable
1031+
the extension modules that use them in :file:`Modules/Setup.local`.
1032+
10291033
.. versionadded:: 3.6
10301034

10311035
.. option:: --with-undefined-behavior-sanitizer

0 commit comments

Comments
 (0)