Repository navigation
Data races in typeobject.c for type structure updates #133467
Description
Activity
- addedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on May 5, 2025 - addedinterpreter-core(Objects, Python, Grammar, and Parser dirs)(Objects, Python, Grammar, and Parser dirs)
on May 7, 2025 - added a commit that references this issue
on Aug 1, 2025 Hi @nascheme ,
I'm interested in the free-threading topic and want to try the 'tp_base and tp_bases are assigned in likely unsafe ways' subtask. 😊
Best Regards,
EdwardI'm interested in the free-threading topic and want to try the 'tp_base and tp_bases are assigned in likely unsafe ways' subtask.
I don't have specific instructions for that but here are some general thoughts. Inside typeobject.c, look at places where
->tp_baseand->tp_basesget assigned. If they are inside a function that hasASSERT_NEW_TYPE_OR_LOCKEDthen those should be safe. If not, you need to follow the logic to see how those functions get called. If those assignments happen after the type has been potentially revealed to other threads then the assignment is likely a data race. Possible fix would be to stop-the-world, do the assignment and then start the world again. Note that while the world is stopped, it is not safe to call most of the Python APIs. That's the reason for the complex logic related toapply_type_slot_updates(). I'm not sure but I suspect change base or bases could require similar levels of care.Reacted by Edward XuI'm interested in the free-threading topic and want to try the 'tp_base and tp_bases are assigned in likely unsafe ways' subtask.
I don't have specific instructions for that but here are some general thoughts. Inside typeobject.c, look at places where
->tp_baseand->tp_basesget assigned. If they are inside a function that hasASSERT_NEW_TYPE_OR_LOCKEDthen those should be safe. If not, you need to follow the logic to see how those functions get called. If those assignments happen after the type has been potentially revealed to other threads then the assignment is likely a data race. Possible fix would be to stop-the-world, do the assignment and then start the world again. Note that while the world is stopped, it is not safe to call most of the Python APIs. That's the reason for the complex logic related toapply_type_slot_updates(). I'm not sure but I suspect change base or bases could require similar levels of care.Hi @nascheme ,
Thanks very much for your instructions! ❤ It helps me a lot and guides the way!
I will try to construct the data race case and update if I have any new findings.Best Regards,
EdwardReacted by Neil SchemenauerClosing as all the races are fixed.
Bug report
Bug description:
There are some additional data races (producing TSAN warnings) for typeobject.c in the free-threaded build.
The following stores are unsafe:
CPython versions tested on:
CPython main branch
Operating systems tested on:
No response
Linked PRs
type_set_name(GH-137302) #137303tp_baserace in free threading #140549