Data race: ctypes `PyCData_NewGetBuffer` reads `b_ptr` without the critical section `_ctypes_resize` holds
Dieses Issue hat noch niemand übernommen.
- Vorherrschende Sprache
- Python
- Sterne
- 77.2k
- Forks
- 35.9k
- PR-Merge-Kennzahlen
- PR-Kennzahlen ausstehend
Beschreibung
Bug report
Bug description:
#131336 / #128182 made ctypes.resize and addressof/byref thread-safe by taking a critical section in _ctypes_resize, which reallocates obj->b_ptr:
But the buffer-protocol getbuffer, PyCData_NewGetBuffer (reached via memoryview(cdata)), reads self->b_ptr without that critical section:
So memoryview(obj) racing ctypes.resize(obj) reads a b_ptr that resize concurrently reallocates.
Reproducer:
import ctypes
from threading import Thread
buf = (ctypes.c_char * 64)()
def viewer():
for _ in range(20000):
try:
memoryview(buf)
except Exception:
pass
def resizer():
for i in range(20000):
try:
ctypes.resize(buf, 128 if (i & 1) else 256)
except Exception:
pass
threads = [Thread(target=viewer) for _ in range(6)]
threads += [Thread(target=resizer) for _ in range(2)]
for t in threads: t.start()
for t in threads: t.join()
TSAN Report:
==================
WARNING: ThreadSanitizer: data race (pid=1524546)
Read of size 8 at 0x7fffb6b50208 by thread T1:
#0 PyCData_NewGetBuffer /cpython/./Modules/_ctypes/_ctypes.c:3129:23
#1 PyObject_GetBuffer /cpython/Objects/abstract.c:455:15
#2 _PyManagedBuffer_FromObject /cpython/Objects/memoryobject.c:97:9
#3 PyMemoryView_FromObjectAndFlags /cpython/Objects/memoryobject.c:813:42
#4 PyMemoryView_FromObject /cpython/Objects/memoryobject.c:856:12
#5 memoryview_impl /cpython/Objects/memoryobject.c:1017:12
#6 memoryview /cpython/Objects/clinic/memoryobject.c.h:63:20
#7 type_call /cpython/Objects/typeobject.c:2472:11
#8 _PyObject_MakeTpCall /cpython/Objects/call.c:242:18
#9 _PyObject_VectorcallTstate /cpython/./Include/internal/pycore_call.h:142:16)
#10 PyObject_Vectorcall /cpython/Objects/call.c:327:12
#11 _Py_VectorCall_StackRefSteal /cpython/Python/ceval.c:726:11
#12 _PyEval_EvalFrameDefault /cpython/Python/generated_cases.c.h:4559:35
Previous write of size 8 at 0x7fffb6b50208 by thread T7:
#0 _ctypes_resize_impl /cpython/./Modules/_ctypes/callproc.c
#1 _ctypes_resize /cpython/./Modules/_ctypes/clinic/callproc.c.h:139:20
#2 _Py_BuiltinCallFast_StackRef /cpython/Python/ceval.c:817:11
#3 _PyEval_EvalFrameDefault /cpython/Python/generated_cases.c.h:2510:35
#4 _PyEval_EvalFrame /cpython/./Include/internal/pycore_ceval.h:122:16
SUMMARY: ThreadSanitizer: data race /cpython/./Modules/_ctypes/_ctypes.c:3129:23 in PyCData_NewGetBuffer
==================
CPython versions tested on:
CPython main branch
Operating systems tested on:
Linux
Linked PRs
- gh-157759
Beitragsleitfaden
Erste Schritte
- Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
- Forke das Repository und arbeite in einem Branch.
- Öffne einen Pull Request, der die Issue-Nummer nennt.
Rechercherichtung
Beginne mit Modules/_ctypes/_ctypes.c bei PyCData_NewGetBuffer und vergleiche dessen b_ptr-Zugriff mit dem kritischen Abschnitt in Modules/_ctypes/callproc.c bei _ctypes_resize_impl. Führe den mitgelieferten Multithread-Reproducer unter ThreadSanitizer aus. Die Aufgabe ist erledigt, wenn die Race Condition zwischen memoryview und ctypes.resize nicht mehr gemeldet wird, während das bestehende Verhalten intakt bleibt.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- c, python
- Bereich
- backend
- Issue-Typ
- Bug
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Aktivitätsstatus
- Veraltet
- Klarheit
- Klar beschrieben
- Anfängerfreundlichkeit
- 30/100