Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Possible reference leak of the argument tuple in `FunctionCall()`

Đang mở Phù hợp với người mới
#534 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
2/5
Thời gian dự kiến
1-3 giờ
Mức phù hợp với người mới
76/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
cpp, pandas, python
Lĩnh vực
api

Hướng nghiên cứu

Bắt đầu trong src/map.cpp tại FunctionCall và xem xét các quy tắc ownership của CPython đối với PyTuple_Pack và PyObject_CallObject. Xác minh rằng tuple đối số được giải phóng sau cả các lần gọi thành công và thất bại, trong khi df_obj vẫn giữ nguyên cách xử lý ownership hiện có. Được xem là hoàn tất khi các lần gọi DuckDBPyRelation.map() lặp lại không còn làm rò rỉ tuple hoặc giữ lại DataFrame đầu vào.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

needs triage
What happens?

FunctionCall() passes a newly created tuple directly to PyObject_CallObject():

File: src/map.cpp

Function: FunctionCall

auto *df_obj = PyObject_CallObject(function, PyTuple_Pack(1, in_df.ptr()));

PyTuple_Pack() returns a new reference, while PyObject_CallObject() does
not steal its args reference. Because the tuple is not stored in a local
variable, it is never passed to Py_DECREF().

As a result, every invocation leaks one tuple. The tuple also owns a reference
to in_df, so the input pandas DataFrame remains alive after FunctionCall()
returns. This occurs on both successful and failed calls.

The function is used during bind-time schema inference and query execution, so
the leak is reachable through ordinary DuckDBPyRelation.map() operations.

The handling of df_obj is unrelated and correct:

auto df = py::reinterpret_steal<py::object>(df_obj);

PyObject_CallObject() returns a new reference on success, which
reinterpret_steal() adopts.

To Reproduce

This issue can be confirmed directly from the reference ownership in
src/map.cpp.

In FunctionCall(), the argument tuple is created inline:

auto *df_obj = PyObject_CallObject(function, PyTuple_Pack(1, in_df.ptr()));

According to the CPython C API reference ownership rules:

  1. PyTuple_Pack() returns a new reference.
  2. PyObject_CallObject() does not steal the reference passed as args.
  3. The tuple pointer is not stored, so there is no subsequent
    Py_DECREF() for that new reference.
  4. The tuple therefore leaks on every call and retains its reference to
    in_df.

This issue is specific to the Python API and is not reproducible through plain
SQL in the DuckDB CLI.

OS:

x86_64

DuckDB Package Version:

latest version

Python Version:

3.12

Full Name:

Ksx

Affiliation:

SMU

What is the latest build you tested with? If possible, we recommend testing with the latest nightly build.

I have not tested with any build

Did you include all relevant data sets for reproducing the issue?

No - Other reason (please specify in the issue body)

Did you include all code required to reproduce the issue?
  • Yes, I have
Did you include all relevant configuration to reproduce the issue?
  • Yes, I have
Ngôn ngữ chính
Python
Star
186
Fork
113
Merge trung bình
22 giờ 45 phút
Pull request đã merge (30 ngày)
14

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của duckdb/duckdb-python

Tất cả issue của duckdb/duckdb-python

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.