Pull Request已成功合入, 合并人@ascend-robot
(感谢 21xiu 的贡献)变更摘要
此 PR 修复了 NPU 后端 THNPEvent 和 THNPStream 的 tp_dealloc 覆盖函数中缺失的 weakref 清理逻辑。PyTorch 基础类 THPStream / THPEvent 已增加 weakref 支持,但 NPU 后端的自定义释放函数未同步调用 PyObject_ClearWeakRefs,导致 weakref 中的 wr_object 在对象释放后仍指向已释放内存(悬空指针),引发 use-after-free。同时 THNPStream_dealloc 还缺少 Py_CLEAR(self->context) 导致 lazy stream context 泄漏。改动在两处 tp_dealloc 中添加了必要的清理调用,并补充了回归测试。
主要改动
-
在
THNPStream_dealloc中添加 weakref 清理和 context 释放:在torch_npu/csrc/npu/Stream.cpp的THNPStream_dealloc函数中,析构NPUStream之后、调用tp_free之前,新增PyObject_ClearWeakRefs((PyObject*)self)清除弱引用,以及Py_CLEAR(self->context)释放 lazy stream context,防止内存泄漏和悬空指针。 -
在
THNPEvent_dealloc中添加 weakref 清理:在torch_npu/csrc/npu/Event.cpp的THNPEvent_dealloc函数中,析构NPUEvent之后、调用tp_free之前,新增PyObject_ClearWeakRefs((PyObject*)self)清除弱引用。 -
新增 weakref 回调与悬空指针回归测试:在
test/dynamo/test_stream.py中添加_assert_weakref_callback_fires辅助方法以及两个测试用例test_npu_stream_event_weakref_callback和test_dynamo_registry_no_dangling_weakref,分别验证 weakref 回调正确触发以及 dynamo 外部对象注册表中不会保留指向已释放 Stream 的悬空 weakref。


代码审查
审查总结
已审查文件:
test/dynamo/test_stream.py— 无问题(测试代码逻辑正确)torch_npu/csrc/npu/Event.cpp— 1 个 P3 问题(注释错误)torch_npu/csrc/npu/Stream.cpp— 无问题
按优先级统计:
- P0: 0
- P1: 0
- P2: 0
- P3: 1
整体风险评估: 低风险。本次变更的核心修复(在 tp_dealloc 中调用 PyObject_ClearWeakRefs 解决 UAF、在 Stream 中添加 Py_CLEAR(self->context) 解决泄漏)均正确,操作顺序合理,测试覆盖充分。唯一的问题是 Event.cpp 中 tp_weaklistoffset 的注释因复制粘贴错误引用了错误的基类名称,但不影响运行时行为。
⚠️ 已识别出整体风险,但无法提取行内评论,请参考整体评估。


Thanks for your pull-request.
The full list of commands accepted by me can be found at here。
You can get sig-info at here
PR Approval Progress
✅ Congratulations! All modules have met the lgtm and approve requirements.
Module Approval Details
| module | lgtm status | approve status |
|---|---|---|
| repo-Ascend/pytorch | ✅ htchu, liangsongwei, ffmh (3/2) | ✅ htchu, liangsongwei (2/1) |
| test | ✅ htchu, liangsongwei, ffmh (3/2) | ✅ htchu, liangsongwei (2/1) |
💡 Tip:
- Committer can comment
/approveor/lgtm- Commenting
/approveimplies both code review (lgtm) and intent to merge (approve)
CLA Signature Pass
xiu_21, thanks for your pull request. All authors of the commits have signed the CLA. 👍


Linking Issue Notice
@xiu_21 , the pull request must be linked to at least one issue.
If an issue has already been linked, but the needs-issue label remains, you can remove the label by commenting /check-issue .


当前仓库存在以下 保护分支 :
| Protected Branch | Version | Release |
|---|---|---|
| master | ||
| v2.7.1 | ||
| v2.9.0 | ||
| v2.10.0 | ||
| v2.11.0 | ||
| v2.12.0 | ||
| v2.9.0-26.1.0 | ||
| v2.7.1-26.1.0 | ||
| v2.10.0-26.1.0 | ||
| v2.11.0-26.1.0 | ||
| v2.12.0-26.1.0 | ||
| ci-test |
评论 /sync <branch1> <branch2> ... 可将当前 PR 修改同步到其它分支(创建同步 PR):
a) 如果当前 PR 是 Open 状态,同步操作将延迟到 PR 被合并时执行
b) 如果当前 PR 已经 Merged,将立即执行同步操作
注意:
- /sync 命令可以指定同步到多个分支,仅最后一个 /sync 命令生效
- 如果创建的同步 PR 不正确,可通过向同步 PR 的源分支提交轻量级 PR 完善,或使用 /close 命令关闭


ascend docs pipeline is running...


✅ 跳过 docs ci 检查,没有需要检查的文档文件


| 阶段 | 任务名 | 状态 | 详情 |
|---|---|---|---|
| 编译构建 | Build_X86 | ✅ | >>> |
| Build_ARM | ✅ | >>> | |
| Build_LibTorch_x86 | ✅ | >>> | |
| Build_LibTorch_ARM | ✅ | >>> | |
| Build_X86_torchair | 🛑 | >>> | |
| Build_ARM_torchair | 🛑 | >>> | |
| patch_test | 🛑 | >>> | |
| 恶意代码检查 | Antipoison | ✅ | >>> |
| 编码安全与规范检查 | CodeCheck | ✅ | >>> |
| check_error | ✅ | >>> | |
| CodeCheck_lintrunner | ✅ | >>> | |
| 开源片段检查 | SCA | ✅ | >>> |
| 开发者测试 | UT_X86_Part_01 | 🛑 | >>> |
| UT_X86_Part_02 | 🛑 | >>> | |
| UT_ARM_A3_Part_01 | 🛑 | >>> | |
| UT_ARM_A3_Part_02 | 🛑 | >>> | |
| UT_ARM_A2_Part_01 | ✅ | >>> | |
| UT_ARM_A2_Part_02 | ✅ | >>> | |
| UT_ARM_A2_Part_03 | ✅ | >>> | |
| UT_inductor_Part_01 | 🛑 | >>> | |
| UT_inductor_Part_02 | 🛑 | >>> | |
| UT_inductor_Part_03 | 🛑 | >>> | |
| UT_inductor_Part_04 | 🛑 | >>> | |
| UT_DIST_ARM_Part_01 | 🛑 | >>> | |
| UT_DIST_ARM_Part_02 | 🛑 | >>> | |
| UT_DIST_ARM_Part_03 | 🛑 | >>> | |
| UT_DIST_ARM_Part_04 | 🛑 | >>> | |
| UT_ARM_A2_Select_Part_01 | ✅ | >>> | |
| UT_ARM_A2_Select_Part_02 | ✅ | >>> | |
| 流水线 | PR-pipeline_pytorch | ✅ | >>> |
- compile、compile_inductor、compile_torchair : 运行流水线
- retry : 重试流水线所有失败子任务
- retry <任务名> : 仅重试指定失败子任务
- stop : 停止流水线


/approve


/check-pr


/check-pr


The following label is not ready.
lgtm: Please wait for reviewers to review the code.


/lgtm




【合入来源】
【修改方案】
PyTorch 基础类 THPStream / THPEvent 中增加了 weakref 支持(添加了 weakreflist 字段),但 NPU 后端的 tp_dealloc 覆盖函数未同步更新。
CPython 对静态 PyType 不会自动链式调用父类 tp_dealloc,因此 THNPEvent_dealloc 和 THNPStream_dealloc 一直缺少:
【资料变更】
不涉及
【接口变更】
不涉及
【功能验证】
pytest test/dynamo/test_stream.py -k test_npu_stream_event_weakref_callback


修改前:
修改后:
【CheckList】