python / python/cpython

[Free-threading] `assert(!_Py_IsImmortal(op))` failure when BRC merge queue races with `sys.intern`

未关闭
#152,276 0 条评论 1 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

interpreter-core topic-free-threading type-bug
主要语言
Python
星标
77.2k
派生
35.9k
PR 合并指标
PR 指标待抓取

描述

Bug report

Bug description:

In the free-threaded build, there is a race condition where an object can be queued for Biased Reference Counting (BRC) merging, but become immortal before the queue is processed. This causes a fatal C-level assertion failure:

assert.h assertion failed at Objects/object.c:467 in Py_ssize_t _Py_ExplicitMergeRefcount(PyObject *, Py_ssize_t): !_Py_IsImmortal(op)

*** Check failure stack trace: ***
    @     _Py_ExplicitMergeRefcount
    @     merge_queued_objects
    @     _Py_brc_merge_refcounts
    @     _Py_HandlePending
    @     _PyEval_EvalFrameDefault

Reproduction. Fails when running under ASAN/TSAN and the free-threading build:

import threading
import sys
def test_race():
    # 1 million strings will trap Thread A inside map() for milliseconds,
    # giving Thread B plenty of time to queue references to strings that 
    # Thread A hasn't interned yet.
    strings = ["race_string_massive_" + str(j) for j in range(1000000)]
    
    # Give Thread B a copy of the list.
    shared = list(strings)
    
    def thread_b_func():
        # Thread B clears its list, reducing the shared refcount to 0.
        # Since Thread B is not the owner, they are placed in Thread A's merge queue.
        shared.clear()
    tb = threading.Thread(target=thread_b_func)
    tb.start()
    # Thread A executes entirely in C for milliseconds.
    # Strings are queued by Thread B, AND THEN made immortal by sys.intern!
    list(map(sys.intern, strings))
    tb.join()
if __name__ == "__main__":
    test_race()
CPython versions tested on:

3.14

Operating systems tested on:

Linux

Linked PRs
  • gh-152277

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

从 Objects/object.c 中的 _Py_ExplicitMergeRefcount 开始,跟踪提到的 merge_queued_objects、_Py_brc_merge_refcounts 和 _Py_HandlePending 调用路径。使用 free-threaded 构建在 ASAN 或 TSAN 下复现竞态,然后比较链接的 PR gh-152277 中的行为和解决方案。

由索引模型根据 Issue 内容生成。

评估

技术栈
c, python
领域
backend
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
停滞
描述清晰度
基本清楚
新手友好度
30/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。