Data race in the `codec.errors` setter (`codecctx_errors_set`) on a shared stateful codec
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 77.2k
- Forks
- 35.9k
- PR merge metrics
- PR metrics pending
Description
Bug report
Bug description:
Bug description:
In the free-threaded build, the codecctx_errors_set decrefs the old handler(ERROR_DECREF(self->errors)) and stores the new one (self->errors = cb) without any synchronization
For any handler name other than the strict/ignore/replace sentinels (e.g. backslashreplace), self->errors holds a real refcounted PyUnicode.
The decref-then-assign is not atomic, so concurrent codec.errors = drops references incorrectly and can free a handler while it is still referenced.
Reproducer:
import codecs
import random
from threading import Thread
shared = codecs.getincrementalencoder('shift_jis')()
NAMES = ['backslashreplace', 'xmlcharrefreplace', 'namereplace']
def thread1():
for _ in range(20000):
try:
shared.errors = random.choice(NAMES)
except Exception:
pass
if __name__ == "__main__":
threads = [Thread(target=thread1) for _ in range(8)]
for t in threads: t.start()
for t in threads: t.join()
TSAN Report:
==================
WARNING: ThreadSanitizer: data race (pid=3576762)
Read of size 8 at 0x7fffb65a1cc0 by thread T2:
#0 codecctx_errors_set /cpython/./Modules/cjkcodecs/multibytecodec.c:194:5
#1 getset_set /cpython/Objects/descrobject.c:250:16
#2 _PyObject_GenericSetAttrWithDict /cpython/Objects/object.c:2049:19
#3 PyObject_GenericSetAttr /cpython/Objects/object.c:2120:12
#4 PyObject_SetAttr /cpython/Objects/object.c:1533:15
#5 _PyEval_EvalFrameDefault /cpython/Python/generated_cases.c.h:12146:27
...
Previous write of size 8 at 0x7fffb65a1cc0 by thread T1:
#0 codecctx_errors_set /cpython/./Modules/cjkcodecs/multibytecodec.c:195:18
#1 getset_set /cpython/Objects/descrobject.c:250:16
#2 _PyObject_GenericSetAttrWithDict /cpython/Objects/object.c:2049:19
#3 PyObject_GenericSetAttr /cpython/Objects/object.c:2120:12
#4 PyObject_SetAttr /cpython/Objects/object.c:1533:15
#5 _PyEval_EvalFrameDefault /cpython/Python/generated_cases.c.h:12146:27
...
SUMMARY: ThreadSanitizer: data race /cpython/./Modules/cjkcodecs/multibytecodec.c:194:5 in codecctx_errors_set
==================
CPython versions tested on:
CPython main branch
Operating systems tested on:
Linux
Linked PRs
- gh-153000
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start in Modules/cjkcodecs/multibytecodec.c at codecctx_errors_set, then run the supplied threaded reproducer under the free-threaded build with ThreadSanitizer. Compare the behavior with linked PR gh-153000; done means concurrent codec.errors assignments no longer produce the reported race or incorrect handler lifetime behavior.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- c, python
- Domain
- backend
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 30/100