Ensure that HACL* states are not read concurrently
Open
@picnixz is already working on this.
Since Aug 15, 2026.
extension-modules
type-bug
- Dominant language
- Python
- Stars
- 77.2k
- Forks
- 35.9k
- PR merge metrics
- PR metrics pending
Description
Bug report
Bug description:
Sometimes, it's possible to read an HACL* state concurrently:
- sha3 reads the live HACL state outside the object lock at six sites
- blake2's digest_size getter reads the live HACL state outside the lock
Instead, we can (1) add this static information just after construction (2) compute it inside the lock sections. The problem is that HACL* update() functions update the entire state so reading static information is unsafe.
CPython versions tested on:
CPython main branch
Operating systems tested on:
No response
Linked PRs
- gh-155838
- gh-155839
- gh-157038
- gh-157039
- gh-157041
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.