python / python/cpython

Data race in test_ssl.test_sni_callback_race

Abierto
#150,191 5 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

tests topic-free-threading type-bug
Lenguaje dominante
Python
Estrellas
77.2k
Forks
35.9k
Métricas de merge de PR
Métricas de PR pendientes

Descripción

Bug report

There is a sporadic thread sanitizer reported data race in a newly added test

  • GH-150018

For example:

Here is a summary from Claude with my edits:


On the free-threaded TSAN build, test.test_ssl.ContextTests.test_sni_callback_race sporadically reports a data race inside OpenSSL: one thread reads an ASN.1 string via ASN1_STRING_cmp (no lock held) while another writes the same heap block via ASN1_STRING_set (holding an internal CRYPTO_THREAD_lock rwlock). The test itself does not crash.

Reproducer
CC=clang-20 ./configure -C --disable-gil --with-pydebug --with-thread-sanitizer
make -j

for i in $(seq 1 30); do
  TSAN_OPTIONS="halt_on_error=1" \
    ./python -m test test_ssl -v -m test_sni_callback_race > /tmp/run_$i.log 2>&1
  [ $? -ne 0 ] && echo "FAILED on run $i" && break
done

Reproduces within ~15 runs on a 22-core machine.

TSAN report (abridged)
WARNING: ThreadSanitizer: data race

  Read of size 8 by thread T11:
    #0 memcmp
    #1 ASN1_STRING_cmp           (libcrypto.so.3)
    ...
    #22 thread_run               Modules/_threadmodule.c:388

  Previous write of size 8 by thread T12 (mutexes: write M0):
    #0 memcpy
    #1 ASN1_STRING_set           (libcrypto.so.3)
    ...
    #22 thread_run               Modules/_threadmodule.c:388

  Location is heap block of size 21 allocated by ASN1_STRING_set
  Mutex M0 created by CRYPTO_THREAD_lock_new (libcrypto.so.3)

SUMMARY: ThreadSanitizer: data race in memcmp

The writer holds an OpenSSL-owned rwlock; the reader does not take the same lock. Both call sites enter from two Python worker threads doing concurrent SSL handshakes on the same SSLContext.

Environment

  • CPython main @ c35b0f2b624 (3.16.0a0, free-threading debug TSAN)
  • Clang 20.1.8
  • OpenSSL 3.0.13 (30 Jan 2024)
  • Linux 6.8.0-101 x86_64

cc @kiri11 @encukou

Linked PRs
  • gh-150193
  • gh-153269
  • gh-153270
  • gh-153320
  • gh-153349
  • gh-153350

Guía de contribución

Abrir la guía de contribución

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Línea de trabajo

Comienza con test_ssl.test_sni_callback_race y reprodúcelo usando el comando de compilación free-threaded TSAN y las ejecuciones repetidas de las pruebas descritos en el issue. Revisa los handshakes SSL concurrentes en el SSLContext compartido y el informe TSAN abreviado. Se considera terminado cuando la prueba ya no informe de la condición de carrera de datos de OpenSSL con el reproductor indicado.

Escrito por el modelo de indexación a partir del texto del issue.

Evaluación

Stack tecnológico
python
Área
security, testing-qa
Tipo de issue
Error
Dificultad
4/5
Tiempo estimado
3-5 días
Estado de actividad
Estancado
Claridad
Bastante claro
Aptitud para principiantes
35/100

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.