python / python/cpython

Data race on instr->op.code in _Py_Specialize_Resume() with tlbc disabled (TSan CI failure in test_thread_local_bytecode)

Ouverte
#157,194 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub

Personne n'a encore pris cette issue.

interpreter-core topic-free-threading type-bug
Langage dominant
Python
Étoiles
77.2k
Forks
35.9k
Métriques de merge des PR
Métriques de PR en attente

Description

Bug report

Bug description:

The "Sanitizers / TSan (free-threading)" job of 90eb9f4bcd failed in test_thread_local_bytecode: https://github.com/python/cpython/actions/runs/34236688928/job/102096192233

FAIL: test_no_copies_if_tlbc_disabled (test.test_thread_local_bytecode.TLBCTests.test_no_copies_if_tlbc_disabled)
    assert_python_ok("-X", "tlbc=0", "-c", code)
AssertionError: Process return code is 66
stdout:
---
---
stderr:
---
---

The empty output and the return code are TSan: the job sets TSAN_OPTIONS=log_path=.../san_log, so the report goes to a file rather than stderr, and 66 is TSan's default exit code. The report is in the run's TSan-logs-free-threading artifact, as san_log.test_thread_local_bytecode.17102:

WARNING: ThreadSanitizer: data race (pid=17102)
  Read of size 1 at 0x7fe6eaa078f8 by thread T2:
    #0 _Py_Specialize_Resume Python/specialize.c:2957:43
    #1 _PyEval_EvalFrameDefault Python/generated_cases.c.h:11357:17
    ...
    #24 thread_run ./Modules/_threadmodule.c:388:21

  Previous atomic write of size 1 at 0x7fe6eaa078f8 by main thread:
    #0 _Py_atomic_compare_exchange_uint8 ./Include/cpython/pyatomic_gcc.h:105:10
    #1 set_opcode Python/specialize.c:334:10
    #2 unspecialize Python/specialize.c:383:10
    #3 _Py_Specialize_Resume Python/specialize.c:2971:5
    ...

Both stacks are _Py_Specialize_Resume() on the same instruction, one from a worker thread and one from the main thread. The write side is atomic; the read side is not:

https://github.com/python/cpython/blob/main/Python/specialize.c#L2957

    if (tstate->tracing == 0 && instr->op.code == RESUME) {

Everything else in specialize.c treats instr->op.code as an atomic location in the free-threaded build. set_opcode() writes it with _Py_atomic_compare_exchange_uint8(), and unspecialize() reads it with FT_ATOMIC_LOAD_UINT8_RELAXED(). That convention arrived with the helpers introduced in gh-115999 (9ce4fa0719d, "Introduce helpers for (un)specializing instructions").

The plain read above post-dates it: it was added in 2026 by 3d0824aef26 (gh-127958, "Trace from RESUME in the JIT"). There is a second one of the same shape in _Py_Specialize_BinaryOp(), added in 2025 by 3893a92d956 (gh-100239):

https://github.com/python/cpython/blob/main/Python/specialize.c#L2351

    if (instr->op.code == BINARY_OP_EXTEND) {

The race needs two threads specializing the same instruction. In a free-threaded build each thread normally gets its own copy of the bytecode, so this does not happen; with -X tlbc=0 the copies are disabled and the bytecode is shared, which is exactly what test_no_copies_if_tlbc_disabled runs. That is why this test is the one that trips it.

CPython versions tested on:

CPython main branch

Operating systems tested on:

Linux (CI)

Linked PRs
  • gh-157195

Guide de contribution

Ouvrir le guide de contribution

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Piste de recherche

Commencez dans Python/specialize.c à _Py_Specialize_Resume() vers la ligne 2957 et _Py_Specialize_BinaryOp() vers la ligne 2351, en comparant les accès atomiques voisins avec le rapport de TSan. Exécutez test_thread_local_bytecode.TLBCTests.test_no_copies_if_tlbc_disabled avec TSan ; c’est terminé lorsque les chemins d’instructions partagées ne signalent plus de condition de concurrence.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Évaluation

Stack technique
python
Domaine
backend, testing-qa
Type d'issue
Bug
Difficulté
3/5
Temps estimé
1-2 jours
Activité
À l'abandon
Clarté
Clairement spécifiée
Accessibilité débutants
25/100

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.