python / python/cpython

22 free-threading race conditions

オープン
#149,816 コメント 18 件 リアクション 9 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

interpreter-core topic-free-threading type-bug
主要言語
Python
スター
77.2k
フォーク
35.9k
PR マージ指標
PR 指標を取得中

説明

Bug report

Changes

2026-05-13: Filed issue.
2026-06-08: Added new findings (16) and (86).

Bug description

I found 22 free-threading race conditions during a partial Xint Code scan of cpython. These only apply to the free-threaded build, and were all found and tested on commit 0534774a472424f6b9be2dc4ce9784384bc02401 built with ./configure --disable-gil --enable-asan on an M3 Mac.

I'm attaching a zip file with detailed writeups of each, as well as reproduction cases for 15 of the 22 issues. I don't have scripts reproducing the findings numbered 21, 36, 82, 94, 106, 115, or 124. Race conditions can be difficult to trigger, and even the scripts I provided are trying to win tight races and may not always work.

I know this is a lot. @colesbury suggested I create a combined issue to make the triage discussion easier.

Let me know if you have any questions or concerns. The issues were found and written up by an automated system, but I have put additional work into the validation and reporting. I do want to be respectful of everyone's time while helping to make Python better.

Writeups

2026-05-13: Initial writeups and test scripts: cpython-ft.zip
2026-06-08: New writeups and test scripts for (16) and (86): cpython-ft-2026-06-08.zip

Many of the scripts are expected to crash, however some of them only produce exceptions or corrupted output. You should be able to run any of the scripts with PYTHON_GIL=1 set in your environment if you want to see a baseline without the race condition.

Finding List
  • (16) Cross-interpreter syslog race
  • (17) Unlocked __init__ races with PRNG state access in Modules/_randommodule.c
  • (21) Racy EVP_MD cache overwrite leaks references in Modules/_hashopenssl.c
  • (36) Borrowed type lookup races to use-after-free in Objects/typeobject.c
  • (49) SNI callback callable race use-after-free in Modules/_ssl.c
  • (61) Racy weakref head load before incref in Objects/typeobject.c
  • (62) Concurrent kwargs growth causes heap overwrite in Objects/call.c
  • (69) Unsynchronized extra pointer dereference in len in Modules/_elementtree.c
  • (82) Non-atomic list slot memmove in shared list delete in Objects/listobject.c
  • (84) Iterator path bypasses buffered object lock in Modules/_io/bufferedio.c
  • (86) Cross-interpreter XID registry race
  • (87) Unsynchronized Element.text borrowed-pointer race in Modules/_elementtree.c
  • (89) Unsynchronized dict iteration causes borrowed-ref UAF in Modules/_pickle.c
  • (91) Racy list item borrow causes UAF in Modules/_pickle.c
  • (94) Async-exception setter races thread-state free in Python/pystate.c
  • (96) Racy GC callback list iteration in Python/gc_free_threading.c
  • (106) Immediate decref races lock-free reader in Modules/_ctypes/_ctypes.c
  • (108) Borrowed dict used after lock release in Objects/dictobject.c
  • (115) Split clear frees keys without QSBR in Objects/dictobject.c
  • (124) Stale keys race in attribute hint fastpath in Python/bytecodes.c
  • (125 wontfix) Struct reinit races with pack/unpack in Modules/_struct.c
  • (128) Borrowed list item raced before incref in Objects/bytesobject.c
  • (129) Reentrant __index__ causes released-buffer dereference in Objects/memoryobject.c
  • (132) Non-atomic exports race in memoryview.hex in Objects/memoryobject.c
CPython versions tested on:

3.14

Operating systems tested on:

macOS

Linked PRs
  • gh-149824
  • gh-149858
  • gh-149875
  • gh-149876
  • gh-149877
  • gh-149909
  • gh-149911
  • gh-149912
  • gh-149914
  • gh-149918
  • gh-149936
  • gh-149997
  • gh-149998
  • gh-150000
  • gh-150003
  • gh-150004
  • gh-150024
  • gh-150029
  • gh-150018
  • gh-150099
  • gh-150100
  • gh-150168
  • gh-150247
  • gh-150295
  • gh-150305
  • gh-150306
  • gh-152296
  • gh-153019
  • gh-153712
  • gh-153718
  • gh-153719
  • gh-156119
  • gh-156314

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

調査の方向性

添付された cpython-ft-2026-06-08.zip から始め、一覧から未チェックの finding を1つ選び、その後、名前が示されている CPython のソースファイルと再現スクリプトを調べます。free-threaded ビルド上で、また比較のために PYTHON_GIL=1 を設定してスクリプトを実行します。多くの finding にはすでにリンクされた PR があるため、race を検証し、対象を絞った修正または follow-up を調整して初めて完了となります。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
c, python
領域
backend, testing-qa
issue の種類
バグ
難易度
5/5
見積もり時間
1週間以上
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
18/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。