Data race on instr->op.code in _Py_Specialize_Resume() with tlbc disabled (TSan CI failure in test_thread_local_bytecode)
Nadie ha tomado este issue todavía.
- Lenguaje dominante
- Python
- Estrellas
- 77.2k
- Forks
- 35.9k
- Métricas de merge de PR
- Métricas de PR pendientes
Descripción
Bug report
Bug description:
The "Sanitizers / TSan (free-threading)" job of 90eb9f4bcd failed in test_thread_local_bytecode: https://github.com/python/cpython/actions/runs/34236688928/job/102096192233
FAIL: test_no_copies_if_tlbc_disabled (test.test_thread_local_bytecode.TLBCTests.test_no_copies_if_tlbc_disabled)
assert_python_ok("-X", "tlbc=0", "-c", code)
AssertionError: Process return code is 66
stdout:
---
---
stderr:
---
---
The empty output and the return code are TSan: the job sets TSAN_OPTIONS=log_path=.../san_log, so the report goes to a file rather than stderr, and 66 is TSan's default exit code. The report is in the run's TSan-logs-free-threading artifact, as san_log.test_thread_local_bytecode.17102:
WARNING: ThreadSanitizer: data race (pid=17102)
Read of size 1 at 0x7fe6eaa078f8 by thread T2:
#0 _Py_Specialize_Resume Python/specialize.c:2957:43
#1 _PyEval_EvalFrameDefault Python/generated_cases.c.h:11357:17
...
#24 thread_run ./Modules/_threadmodule.c:388:21
Previous atomic write of size 1 at 0x7fe6eaa078f8 by main thread:
#0 _Py_atomic_compare_exchange_uint8 ./Include/cpython/pyatomic_gcc.h:105:10
#1 set_opcode Python/specialize.c:334:10
#2 unspecialize Python/specialize.c:383:10
#3 _Py_Specialize_Resume Python/specialize.c:2971:5
...
Both stacks are _Py_Specialize_Resume() on the same instruction, one from a worker thread and one from the main thread. The write side is atomic; the read side is not:
https://github.com/python/cpython/blob/main/Python/specialize.c#L2957
if (tstate->tracing == 0 && instr->op.code == RESUME) {
Everything else in specialize.c treats instr->op.code as an atomic location in the free-threaded build. set_opcode() writes it with _Py_atomic_compare_exchange_uint8(), and unspecialize() reads it with FT_ATOMIC_LOAD_UINT8_RELAXED(). That convention arrived with the helpers introduced in gh-115999 (9ce4fa0719d, "Introduce helpers for (un)specializing instructions").
The plain read above post-dates it: it was added in 2026 by 3d0824aef26 (gh-127958, "Trace from RESUME in the JIT"). There is a second one of the same shape in _Py_Specialize_BinaryOp(), added in 2025 by 3893a92d956 (gh-100239):
https://github.com/python/cpython/blob/main/Python/specialize.c#L2351
if (instr->op.code == BINARY_OP_EXTEND) {
The race needs two threads specializing the same instruction. In a free-threaded build each thread normally gets its own copy of the bytecode, so this does not happen; with -X tlbc=0 the copies are disabled and the bytecode is shared, which is exactly what test_no_copies_if_tlbc_disabled runs. That is why this test is the one that trips it.
CPython versions tested on:
CPython main branch
Operating systems tested on:
Linux (CI)
Linked PRs
- gh-157195
Guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Línea de trabajo
Empieza en Python/specialize.c, en _Py_Specialize_Resume() alrededor de la línea 2957 y _Py_Specialize_BinaryOp() alrededor de la línea 2351, comparando los accesos atómicos cercanos y el informe de TSan. Ejecuta test_thread_local_bytecode.TLBCTests.test_no_copies_if_tlbc_disabled con TSan; se considera terminado cuando las rutas de instrucciones compartidas ya no informen de una condición de carrera.
Escrito por el modelo de indexación a partir del texto del issue.
Evaluación
- Stack tecnológico
- python
- Área
- backend, testing-qa
- Tipo de issue
- Error
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Estado de actividad
- Estancado
- Claridad
- Bien especificado
- Aptitud para principiantes
- 25/100