python / python/cpython

Data race in `faulthandler.enable()` and `faulthandler.disable()` with free-threading

Offen
#151,363 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

extension-modules type-bug
Vorherrschende Sprache
Python
Sterne
77.2k
Forks
36k
PR-Merge-Kennzahlen
PR-Kennzahlen ausstehend

Beschreibung

Bug report

Bug description:

faulthandler.enable() and faulthandler.disable() read and write the global fatal_error state with no synchronization. enable() checks the enabled guard and then sets it,

https://github.com/python/cpython/blob/b18168cb32d545ed976b760983478cbd5dde5bdf/Modules/faulthandler.c#L536-L541

while disable() reads the same guard and tears the state back down, including Py_CLEAR(fatal_error.file),

https://github.com/python/cpython/blob/b18168cb32d545ed976b760983478cbd5dde5bdf/Modules/faulthandler.c#L641-L658

so two threads calling enable() and disable() concurrently race on the enabled flag, on the installed signal handlers, and on the fatal_error.file reference.

Reproducer:

import faulthandler, os
from threading import Thread, Event

def owner():
    f = open(os.devnull, 'w')
    for _ in range(200000):
        faulthandler.enable(file=f, all_threads=False)
        f.write('x')
        f.flush()
    f.close()

def toggler():
    for _ in range(200000):
        faulthandler.disable()

threads  = [Thread(target=owner)   for _ in range(4)]
threads += [Thread(target=toggler) for _ in range(4)]
for t in threads: t.start()
for t in threads: t.join()

With TSAN build, the owner thread's own f.write()/enable() raises ValueError: I/O operation on uninitialized object because a concurrent disable() dropped the last reference to f and finalized it.

TSAN Report:

WARNING: ThreadSanitizer: data race (pid=1671402)
  Write of size 4 at 0x555555e19478 by thread T5:
    #0 faulthandler_disable /cpython/./Modules/faulthandler.c:644:29 (python3.16t+0x57830e) 
    #1 faulthandler_disable_py_impl /cpython/./Modules/faulthandler.c:674:5  
    #2 faulthandler_disable_py /cpython/./Modules/clinic/faulthandler.c.h:299:12 
    #3 cfunction_vectorcall_NOARGS /cpython/Objects/methodobject.c:508:24  
    #4 _PyObject_VectorcallTstate /cpython/./Include/internal/pycore_call.h:144:11  
    #5 PyObject_Vectorcall /cpython/Objects/call.c:327:12 
...

  Previous read of size 4 at 0x555555e19478 by thread T4:
    #0 faulthandler_enable /cpython/./Modules/faulthandler.c:538:21  
    #1 faulthandler_py_enable_impl /cpython/./Modules/faulthandler.c:633:9 
    #2 faulthandler_py_enable /cpython/./Modules/clinic/faulthandler.c.h:278:20 
    #3 cfunction_vectorcall_FASTCALL_KEYWORDS /cpython/Objects/methodobject.c:465:24  
    #4 _PyObject_VectorcallTstate /cpython/./Include/internal/pycore_call.h:144:11  
    #5 PyObject_Vectorcall /cpython/Objects/call.c:327:12 
...

  Location is global '_PyRuntime' of size 405824 at 0x555555e16c80 

SUMMARY: ThreadSanitizer: data race /cpython/./Modules/faulthandler.c:644:29 in faulthandler_disable
==================
CPython versions tested on:

CPython main branch

Operating systems tested on:

Linux

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Beginne in Modules/faulthandler.c bei den enable()-Zeilen 536-541 und den disable()-Zeilen 641-658, und führe dann den bereitgestellten Reproducer mit einem ThreadSanitizer-Build aus. Verfolge den gemeinsam genutzten enabled-Zustand, die Signal-Handler und den Besitz von fatal_error.file; abgeschlossen ist die Arbeit, wenn nebenläufige Aufrufe von enable()/disable() nicht mehr den gemeldeten Race-Zustand verursachen oder die Datei des Aufrufers ungültig machen.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
python
Bereich
operating-systems
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
46/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.