Repository navigation
22 free-threading race conditions #149816
Description
Activity
- addedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on May 14, 2026 (125) Struct reinit races with pack/unpack in Modules/_struct.c
Is this is same as #143379?
(125) Struct reinit races with pack/unpack in Modules/_struct.c
Is this is same as #143379?
Looks pretty similar, just as a threading race instead of reentrancy.
Then I think it's not something worth fixing, on same ground.
Reacted by Ryan Hileman and Maurycy Pawłowski-Wieroński- added a commit that references this issue
on May 14, 2026 I don't think it is worth fixing issues of calling
__init__in multiple threads.Neither of the mentioned init bugs (struct / random) are init racing with itself, they're init racing with something else. The struct bug is far more contrived because it requires you to call init a second time while using the struct object. The random init/sample race seems fine to fix because if someone ever does manage to hit that they won't even get a crash, just incorrect numbers out of their seeded rng.
There's a separate question on the cpython philosophy of "should a script be able to intentionally crash or memory corrupt the interpreter using the stdlib and no ctypes?", which should inform whether more contrived reentrancy issues / race conditions should be fixed
- addedinterpreter-core(Objects, Python, Grammar, and Parser dirs)(Objects, Python, Grammar, and Parser dirs)
on May 15, 2026 I will have a look at all issues related to SSL and crypto myself in 10 days unless someone beats me to it.
- added 4 commits that reference this issue
on May 15, 2026 (36)does not seem correct, because_PyType_Lookupis supposed to return the borrowed reference by design.44 remaining items
I added two cross-interpreter free-threading races to the list (16) and (86), and attached another zip to the issue description with their writeups and reproduction scripts:
- (16) Cross-interpreter syslog race: syslog.syslog() borrows a global without a cross-interpreter lock.
- (86) Cross-interpreter XID registry race: the local XID registry relies on GIL acquisition for thread safety, which doesn't work in free-threaded builds.
#149918 fixes
(69) Unsynchronized extra pointer dereference in len in Modules/_elementtree.c. Would any core dev like to review it? Thanks in advance!@lunixbochs I am unable to reproduce the issue
(124) Stale keys race in attribute hint fastpath in Python/bytecodes.c. Do you have a specific reproduction script or build configuration (ASAN flags, usleep placement, specific interleaving) that reliably surfaces #124 as a sanitizer report or assertion failure? Or is the intent that the issue is demonstrated purely through code-path analysis rather than a live crash/sanitizer report?
Bug report
Changes
2026-05-13: Filed issue.
2026-06-08: Added new findings (16) and (86).
Bug description
I found 22 free-threading race conditions during a partial Xint Code scan of cpython. These only apply to the free-threaded build, and were all found and tested on commit 0534774 built with
./configure --disable-gil --enable-asanon an M3 Mac.I'm attaching a zip file with detailed writeups of each, as well as reproduction cases for 15 of the 22 issues. I don't have scripts reproducing the findings numbered 21, 36, 82, 94, 106, 115, or 124. Race conditions can be difficult to trigger, and even the scripts I provided are trying to win tight races and may not always work.
I know this is a lot. @colesbury suggested I create a combined issue to make the triage discussion easier.
Let me know if you have any questions or concerns. The issues were found and written up by an automated system, but I have put additional work into the validation and reporting. I do want to be respectful of everyone's time while helping to make Python better.
Writeups
2026-05-13: Initial writeups and test scripts: cpython-ft.zip
2026-06-08: New writeups and test scripts for (16) and (86): cpython-ft-2026-06-08.zip
Many of the scripts are expected to crash, however some of them only produce exceptions or corrupted output. You should be able to run any of the scripts with
PYTHON_GIL=1set in your environment if you want to see a baseline without the race condition.Finding List
__init__races with PRNG state access inModules/_randommodule.cModules/_hashopenssl.cObjects/typeobject.cModules/_ssl.cObjects/typeobject.cObjects/call.cModules/_elementtree.cObjects/listobject.cModules/_io/bufferedio.cModules/_elementtree.cModules/_pickle.cModules/_pickle.cPython/pystate.cPython/gc_free_threading.cModules/_ctypes/_ctypes.cObjects/dictobject.cObjects/dictobject.cPython/bytecodes.cModules/_struct.cObjects/bytesobject.c__index__causes released-buffer dereference inObjects/memoryobject.cObjects/memoryobject.cCPython versions tested on:
3.14
Operating systems tested on:
macOS
Linked PRs
_random.Random.__init__method #149824memoryviewwith free-threading #149858memoryviewwith free-threading (GH-149858) #149875memoryviewwith free-threading (GH-149858) #149876memoryviewwith free-threading (GH-149858) #149877_PyBytes_FromListwith free-threading #149909_PyBytes_FromListwith free-threading (GH-149909) #149911_PyBytes_FromListwith free-threading (GH-149909) #149912dict.clear()race on split-table dict with non-embedded values #149914Modules/_elementtree.cwith free-threaded #149918_random.Random.__init__method (GH-149824) #149997_random.Random.__init__method (GH-149824) #149998dict.clear()race on split-table dict with non-embedded values (GH-149914) #150000kwargsgrowth in_thread.start_new_thread#150168setattrandobject.__dict__update #152296