python / python/cpython

Data race on instr->op.code in _Py_Specialize_Resume() with tlbc disabled (TSan CI failure in test_thread_local_bytecode)

未关闭
#157,194 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

interpreter-core topic-free-threading type-bug
主要语言
Python
星标
77.2k
派生
35.9k
PR 合并指标
PR 指标待抓取

描述

Bug report

Bug description:

The "Sanitizers / TSan (free-threading)" job of 90eb9f4bcd failed in test_thread_local_bytecode: https://github.com/python/cpython/actions/runs/34236688928/job/102096192233

FAIL: test_no_copies_if_tlbc_disabled (test.test_thread_local_bytecode.TLBCTests.test_no_copies_if_tlbc_disabled)
    assert_python_ok("-X", "tlbc=0", "-c", code)
AssertionError: Process return code is 66
stdout:
---
---
stderr:
---
---

The empty output and the return code are TSan: the job sets TSAN_OPTIONS=log_path=.../san_log, so the report goes to a file rather than stderr, and 66 is TSan's default exit code. The report is in the run's TSan-logs-free-threading artifact, as san_log.test_thread_local_bytecode.17102:

WARNING: ThreadSanitizer: data race (pid=17102)
  Read of size 1 at 0x7fe6eaa078f8 by thread T2:
    #0 _Py_Specialize_Resume Python/specialize.c:2957:43
    #1 _PyEval_EvalFrameDefault Python/generated_cases.c.h:11357:17
    ...
    #24 thread_run ./Modules/_threadmodule.c:388:21

  Previous atomic write of size 1 at 0x7fe6eaa078f8 by main thread:
    #0 _Py_atomic_compare_exchange_uint8 ./Include/cpython/pyatomic_gcc.h:105:10
    #1 set_opcode Python/specialize.c:334:10
    #2 unspecialize Python/specialize.c:383:10
    #3 _Py_Specialize_Resume Python/specialize.c:2971:5
    ...

Both stacks are _Py_Specialize_Resume() on the same instruction, one from a worker thread and one from the main thread. The write side is atomic; the read side is not:

https://github.com/python/cpython/blob/main/Python/specialize.c#L2957

    if (tstate->tracing == 0 && instr->op.code == RESUME) {

Everything else in specialize.c treats instr->op.code as an atomic location in the free-threaded build. set_opcode() writes it with _Py_atomic_compare_exchange_uint8(), and unspecialize() reads it with FT_ATOMIC_LOAD_UINT8_RELAXED(). That convention arrived with the helpers introduced in gh-115999 (9ce4fa0719d, "Introduce helpers for (un)specializing instructions").

The plain read above post-dates it: it was added in 2026 by 3d0824aef26 (gh-127958, "Trace from RESUME in the JIT"). There is a second one of the same shape in _Py_Specialize_BinaryOp(), added in 2025 by 3893a92d956 (gh-100239):

https://github.com/python/cpython/blob/main/Python/specialize.c#L2351

    if (instr->op.code == BINARY_OP_EXTEND) {

The race needs two threads specializing the same instruction. In a free-threaded build each thread normally gets its own copy of the bytecode, so this does not happen; with -X tlbc=0 the copies are disabled and the bytecode is shared, which is exactly what test_no_copies_if_tlbc_disabled runs. That is why this test is the one that trips it.

CPython versions tested on:

CPython main branch

Operating systems tested on:

Linux (CI)

Linked PRs
  • gh-157195

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

从 Python/specialize.c 中第 2957 行附近的 _Py_Specialize_Resume() 和第 2351 行附近的 _Py_Specialize_BinaryOp() 开始,对比附近的原子访问和 TSan 报告。使用 TSan 运行 test_thread_local_bytecode.TLBCTests.test_no_copies_if_tlbc_disabled;当共享指令路径不再报告竞争时即表示完成。

由索引模型根据 Issue 内容生成。

评估

技术栈
python
领域
backend, testing-qa
Issue 类型
缺陷
难度
3/5
预计耗时
1-2 天
活跃度
停滞
描述清晰度
描述清楚
新手友好度
25/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。