Bug report
On CPython 3.14 with the experimental JIT, this standard-library-only command produces UBSan misaligned-access reports in Python/jit.c, followed by an ASan SEGV. It happens both with and without the tail-call interpreter:
./python -c 'import re; re.compile(r"[\x00-\uffff]")'
No SQLAlchemy, setuptools, Cython, or third-party extension is needed to reproduce it.
The original build used:
CC=clang CXX=clang++ LDFLAGS='-fuse-ld=lld' ./configure --with-tail-call-interp --enable-experimental-jit=yes --with-pydebug --with-address-sanitizer --with-undefined-behavior-sanitizer
The crash also occurs without --with-tail-call-interp (with the JIT and sanitizers still enabled). In that build, the ASan stack points to _PyEval_EvalFrameDefault instead of _TAIL_CALL_JUMP_BACKWARD_JIT.
./python -VV for the original tail-call build:
Python 3.14.8+ (heads/3.14:6490ca6f033, Oct 7 2026, 14:42:11) [Clang 23.1.1 ]
Expected: the regular expression compiles without a sanitizer error or process abort.
The first log below is from the original SQLAlchemy editable-build failure with tail calls enabled. The same sanitizer reports and crash also occur with the command above (as shown in the minimal-reproducer comment). The second log is from that command without tail calls.
Tail-call interpreter: original editable-build log
❯ ./python -c 'import re; re.compile(r"[\x00-\uffff]")'
Python/jit.c:220:5: runtime error: store to misaligned address 0x7f6e76f08013 for type 'uint32_t' (aka 'unsigned int'), which requires 4 byte alignment
0x7f6e76f08013: note: pointer points here
49 89 d6 e8 00 00 00 00 5b 41 5c 41 5d 41 5e 41 5f c3 00 00 00 00 00 00 00 00 00 00 00 00 00 00
^
SUMMARY: UndefinedBehaviorSanitizer: undefined-behavior Python/jit.c:220:5
Python/jit.c:228:5: runtime error: store to misaligned address 0x7f6e76f09c0e for type 'uint64_t' (aka 'unsigned long'), which requires 8 byte alignment
0x7f6e76f09c0e: note: pointer points here
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
^
SUMMARY: UndefinedBehaviorSanitizer: undefined-behavior Python/jit.c:228:5
Python/jit.c:332:24: runtime error: load of misaligned address 0x7f6e76f09c0e for type 'uint64_t' (aka 'unsigned long'), which requires 8 byte alignment
0x7f6e76f09c0e: note: pointer points here
00 00 00 00 30 61 63 77 6e 7f 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
^
SUMMARY: UndefinedBehaviorSanitizer: undefined-behavior Python/jit.c:332:24
AddressSanitizer:DEADLYSIGNAL
=================================================================
==535419==ERROR: AddressSanitizer: SEGV on unknown address 0x7f6e76f07ff8 (pc 0x55a84770061a bp 0x7fff6ca14ac0 sp 0x7fff6ca14a20 T0)
==535419==The signal is caused by a READ memory access.
#0 0x55a84770061a in _TAIL_CALL_JUMP_BACKWARD_JIT /home/boss/projects/oss/cpython/3.14/Python/generated_cases.c.h:7844:25
#1 0x55a847654a8c in _PyEval_EvalFrameDefault /home/boss/projects/oss/cpython/3.14/Python/ceval.c:1253:16
#2 0x55a84765346b in _PyEval_Vector /home/boss/projects/oss/cpython/3.14/Python/ceval.c:2113:12
#3 0x55a84765346b in PyEval_EvalCode /home/boss/projects/oss/cpython/3.14/Python/ceval.c:984:21
#4 0x55a847aa5cd3 in run_eval_code_obj /home/boss/projects/oss/cpython/3.14/Python/pythonrun.c:1396:12
#5 0x55a847aa550c in run_mod /home/boss/projects/oss/cpython/3.14/Python/pythonrun.c:1490:19
#6 0x55a847aa0591 in _PyRun_String /home/boss/projects/oss/cpython/3.14/Python/pythonrun.c:1285:15
#7 0x55a847aa0436 in _PyRun_SimpleString /home/boss/projects/oss/cpython/3.14/Python/pythonrun.c:588:21
#8 0x55a847b5589d in pymain_run_command /home/boss/projects/oss/cpython/3.14/Modules/main.c:274:18
#9 0x55a847b5589d in pymain_run_python /home/boss/projects/oss/cpython/3.14/Modules/main.c:743:21
#10 0x55a847b5589d in Py_RunMain /home/boss/projects/oss/cpython/3.14/Modules/main.c:839:5
#11 0x55a847b56c81 in pymain_main /home/boss/projects/oss/cpython/3.14/Modules/main.c:869:12
#12 0x55a847b56f1c in Py_BytesMain /home/boss/projects/oss/cpython/3.14/Modules/main.c:893:12
#13 0x7f6e77627780 (/usr/lib/libc.so.6+0x27780) (BuildId: d320029ad1a23be2f4bce117fd321cbd23a2014b)
#14 0x7f6e776278b8 in __libc_start_main (/usr/lib/libc.so.6+0x278b8) (BuildId: d320029ad1a23be2f4bce117fd321cbd23a2014b)
#15 0x55a846cd6ee4 in _start (/home/boss/projects/oss/cpython/3.14/python+0xcf0ee4) (BuildId: 4e68dfa688acb6e058491ece68f3f379cbae01c7)
==535419==Register values:
rax = 0x00000ab509084759 rbx = 0x00007fff6ca14a20 rcx = 0x0000000000000000 rdx = 0x00000f6e4ebb7000
rdi = 0x00007f6e7787b3f8 rsi = 0x000055a848423858 rbp = 0x00007fff6ca14ac0 rsp = 0x00007fff6ca14a20
r8 = 0x00007f6e77786dc0 r9 = 0x00000000000000f5 r10 = 0x0000000000000000 r11 = 0x00007cee76a56ca0
r12 = 0x00007d3e76a029a8 r13 = 0x00007cee76a56ca0 r14 = 0x000055a848457b90 r15 = 0x00007f6e76f08000
AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV /home/boss/projects/oss/cpython/3.14/Python/generated_cases.c.h:7844:25 in _TAIL_CALL_JUMP_BACKWARD_JIT
==535419==ABORTING
Default interpreter (no tail calls): standard-library reproducer
❯ ./python -c 'import re; re.compile(r"[\x00-\uffff]")'
Python/jit.c:220:5: runtime error: store to misaligned address 0x7f5c3142b013 for type 'uint32_t' (aka 'unsigned int'), which requires 4 byte alignment
0x7f5c3142b013: note: pointer points here
49 89 d6 e8 00 00 00 00 5b 41 5c 41 5d 41 5e 41 5f c3 00 00 00 00 00 00 00 00 00 00 00 00 00 00
^
SUMMARY: UndefinedBehaviorSanitizer: undefined-behavior Python/jit.c:220:5
Python/jit.c:228:5: runtime error: store to misaligned address 0x7f5c3142cc0e for type 'uint64_t' (aka 'unsigned long'), which requires 8 byte alignment
0x7f5c3142cc0e: note: pointer points here
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
^
SUMMARY: UndefinedBehaviorSanitizer: undefined-behavior Python/jit.c:228:5
Python/jit.c:332:24: runtime error: load of misaligned address 0x7f5c3142cc0e for type 'uint64_t' (aka 'unsigned long'), which requires 8 byte alignment
0x7f5c3142cc0e: note: pointer points here
00 00 00 00 30 61 23 31 5c 7f 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
^
SUMMARY: UndefinedBehaviorSanitizer: undefined-behavior Python/jit.c:332:24
AddressSanitizer:DEADLYSIGNAL
=================================================================
==520015==ERROR: AddressSanitizer: SEGV on unknown address 0x7f5c3142aff8 (pc 0x5632107a0162 bp 0x7fff58639310 sp 0x7fff58638700 T0)
==520015==The signal is caused by a READ memory access.
#0 0x5632107a0162 in _PyEval_EvalFrameDefault /home/boss/projects/oss/cpython/3.14/Python/generated_cases.c.h:7844:25
#1 0x56321075e56b in _PyEval_Vector /home/boss/projects/oss/cpython/3.14/Python/ceval.c:2113:12
#2 0x56321075e56b in PyEval_EvalCode /home/boss/projects/oss/cpython/3.14/Python/ceval.c:984:21
#3 0x563210b955a3 in run_eval_code_obj /home/boss/projects/oss/cpython/3.14/Python/pythonrun.c:1396:12
#4 0x563210b94ddc in run_mod /home/boss/projects/oss/cpython/3.14/Python/pythonrun.c:1490:19
#5 0x563210b8fe61 in _PyRun_String /home/boss/projects/oss/cpython/3.14/Python/pythonrun.c:1285:15
#6 0x563210b8fd06 in _PyRun_SimpleString /home/boss/projects/oss/cpython/3.14/Python/pythonrun.c:588:21
#7 0x563210c4516d in pymain_run_command /home/boss/projects/oss/cpython/3.14/Modules/main.c:274:18
#8 0x563210c4516d in pymain_run_python /home/boss/projects/oss/cpython/3.14/Modules/main.c:743:21
#9 0x563210c4516d in Py_RunMain /home/boss/projects/oss/cpython/3.14/Modules/main.c:839:5
#10 0x563210c46551 in pymain_main /home/boss/projects/oss/cpython/3.14/Modules/main.c:869:12
#11 0x563210c467ec in Py_BytesMain /home/boss/projects/oss/cpython/3.14/Modules/main.c:893:12
#12 0x7f5c31227780 (/usr/lib/libc.so.6+0x27780) (BuildId: d320029ad1a23be2f4bce117fd321cbd23a2014b)
#13 0x7f5c312278b8 in __libc_start_main (/usr/lib/libc.so.6+0x278b8) (BuildId: d320029ad1a23be2f4bce117fd321cbd23a2014b)
#14 0x56320fde1fe4 in _start (/home/boss/projects/oss/cpython/3.14/python+0xcddfe4) (BuildId: 819ff20d4560a9d8e0284f7be7f5c21b09864423)
==520015==Register values:
rax = 0x00000ac6422a1f59 rbx = 0x00007fff58638700 rcx = 0x0000000000000000 rdx = 0x00000f6c05f37000
rdi = 0x00007f5c3155f3f8 rsi = 0x000056321150f858 rbp = 0x00007fff58639310 rsp = 0x00007fff58638700
r8 = 0x00007f5c31386dc0 r9 = 0x00000000000000f5 r10 = 0x0000000000000000 r11 = 0x00007cdc30656ca0
r12 = 0x00007dec305e5710 r13 = 0x00007f5c3142b000 r14 = 0x00007cdc30656ca0 r15 = 0x00007d2c306029a8
AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV /home/boss/projects/oss/cpython/3.14/Python/generated_cases.c.h:7844:25 in _PyEval_EvalFrameDefault
==520015==ABORTING
CPython versions tested on:
3.14
Operating systems tested on:
Linux
Bug report
On CPython 3.14 with the experimental JIT, this standard-library-only command produces UBSan misaligned-access reports in
Python/jit.c, followed by an ASan SEGV. It happens both with and without the tail-call interpreter:./python -c 'import re; re.compile(r"[\x00-\uffff]")'No SQLAlchemy, setuptools, Cython, or third-party extension is needed to reproduce it.
The original build used:
CC=clang CXX=clang++ LDFLAGS='-fuse-ld=lld' ./configure --with-tail-call-interp --enable-experimental-jit=yes --with-pydebug --with-address-sanitizer --with-undefined-behavior-sanitizerThe crash also occurs without
--with-tail-call-interp(with the JIT and sanitizers still enabled). In that build, the ASan stack points to_PyEval_EvalFrameDefaultinstead of_TAIL_CALL_JUMP_BACKWARD_JIT../python -VVfor the original tail-call build:Expected: the regular expression compiles without a sanitizer error or process abort.
The first log below is from the original SQLAlchemy editable-build failure with tail calls enabled. The same sanitizer reports and crash also occur with the command above (as shown in the minimal-reproducer comment). The second log is from that command without tail calls.
Tail-call interpreter: original editable-build log
Default interpreter (no tail calls): standard-library reproducer
CPython versions tested on:
3.14
Operating systems tested on:
Linux