Skip to content

JIT dict access guards check the wrong stack operand #158380

Description

@cocolato

Bug report

Bug description:

When the Tier 2 optimizer uses a dict's recorded type as its probable type, it replaces the subscript guard with _GUARD_TYPE. This guard checks the top of the stack, which holds the key. The dict is one slot below it.

For a plain dict and a string key, as in the example below, the guard fails and execution exits the current Tier 2 trace.

import sys


def f(mapping):
    for _ in range(10_000):
        before = sys._jit.is_active()
        mapping["key"]
        after = sys._jit.is_active()
    return before, after


print(f({"key": 1}))

Run it with Tier 2 enabled:

PYTHON_JIT=1 ./build/python.exe repro.py

Actual output:

(True, False)

Dict writes mapping["key"] = 1 have the same problem.

CPython versions tested on:

CPython main branch

Operating systems tested on:

macOS

Linked PRs

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    interpreter-core(Objects, Python, Grammar, and Parser dirs)topic-JITtype-bugAn unexpected behavior, bug, or error

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions