Data race in test_ssl.test_sni_callback_race
Nadie ha tomado este issue todavía.
- Lenguaje dominante
- Python
- Estrellas
- 77.2k
- Forks
- 35.9k
- Métricas de merge de PR
- Métricas de PR pendientes
Descripción
Bug report
There is a sporadic thread sanitizer reported data race in a newly added test
- GH-150018
For example:
Here is a summary from Claude with my edits:
On the free-threaded TSAN build, test.test_ssl.ContextTests.test_sni_callback_race sporadically reports a data race inside OpenSSL: one thread reads an ASN.1 string via ASN1_STRING_cmp (no lock held) while another writes the same heap block via ASN1_STRING_set (holding an internal CRYPTO_THREAD_lock rwlock). The test itself does not crash.
Reproducer
CC=clang-20 ./configure -C --disable-gil --with-pydebug --with-thread-sanitizer
make -j
for i in $(seq 1 30); do
TSAN_OPTIONS="halt_on_error=1" \
./python -m test test_ssl -v -m test_sni_callback_race > /tmp/run_$i.log 2>&1
[ $? -ne 0 ] && echo "FAILED on run $i" && break
done
Reproduces within ~15 runs on a 22-core machine.
TSAN report (abridged)
WARNING: ThreadSanitizer: data race
Read of size 8 by thread T11:
#0 memcmp
#1 ASN1_STRING_cmp (libcrypto.so.3)
...
#22 thread_run Modules/_threadmodule.c:388
Previous write of size 8 by thread T12 (mutexes: write M0):
#0 memcpy
#1 ASN1_STRING_set (libcrypto.so.3)
...
#22 thread_run Modules/_threadmodule.c:388
Location is heap block of size 21 allocated by ASN1_STRING_set
Mutex M0 created by CRYPTO_THREAD_lock_new (libcrypto.so.3)
SUMMARY: ThreadSanitizer: data race in memcmp
The writer holds an OpenSSL-owned rwlock; the reader does not take the same lock. Both call sites enter from two Python worker threads doing concurrent SSL handshakes on the same SSLContext.
Environment
- CPython
main@ c35b0f2b624 (3.16.0a0, free-threading debug TSAN) - Clang 20.1.8
- OpenSSL 3.0.13 (30 Jan 2024)
- Linux 6.8.0-101 x86_64
cc @kiri11 @encukou
Linked PRs
- gh-150193
- gh-153269
- gh-153270
- gh-153320
- gh-153349
- gh-153350
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Línea de trabajo
Comienza con test_ssl.test_sni_callback_race y reprodúcelo usando el comando de compilación free-threaded TSAN y las ejecuciones repetidas de las pruebas descritos en el issue. Revisa los handshakes SSL concurrentes en el SSLContext compartido y el informe TSAN abreviado. Se considera terminado cuando la prueba ya no informe de la condición de carrera de datos de OpenSSL con el reproductor indicado.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Stack tecnológico
- python
- Área
- security, testing-qa
- Tipo de issue
- Error
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Estado de actividad
- Estancado
- Claridad
- Bastante claro
- Aptitud para principiantes
- 35/100