Skip to content

Data races in typeobject.c for type structure updates #133467

Description

@nascheme

Bug report

Bug description:

There are some additional data races (producing TSAN warnings) for typeobject.c in the free-threaded build.

The following stores are unsafe:

  • _Py_slot_tp_getattr_hook re-assigns tp_getattro
  • slot_tp_descr_get assigns to tp_descr_get
  • type_set_name assigns to tp_name
  • tp_base and tp_bases are assigned in likely unsafe ways

CPython versions tested on:

CPython main branch

Operating systems tested on:

No response

Linked PRs

Activity

  1. added 2 commits that reference this issue on May 8, 2025
  2. added a commit that references this issue on May 8, 2025
  3. added a commit that references this issue on May 8, 2025
  4. added a commit that references this issue on Jul 12, 2025
  5. added a commit that references this issue on Aug 1, 2025
  6. added a commit that references this issue on Aug 1, 2025
  7. added a commit that references this issue on Aug 4, 2025
  8. added a commit that references this issue on Aug 19, 2025
  9. added a commit that references this issue on Oct 7, 2025
  10. LindaSummer commented on Oct 14, 2025

    @LindaSummer
    Contributor

    Hi @nascheme ,

    I'm interested in the free-threading topic and want to try the 'tp_base and tp_bases are assigned in likely unsafe ways' subtask. 😊

    Best Regards,
    Edward

  11. nascheme commented on Oct 15, 2025

    @nascheme
    MemberAuthor

    I'm interested in the free-threading topic and want to try the 'tp_base and tp_bases are assigned in likely unsafe ways' subtask.

    I don't have specific instructions for that but here are some general thoughts. Inside typeobject.c, look at places where ->tp_base and ->tp_bases get assigned. If they are inside a function that has ASSERT_NEW_TYPE_OR_LOCKED then those should be safe. If not, you need to follow the logic to see how those functions get called. If those assignments happen after the type has been potentially revealed to other threads then the assignment is likely a data race. Possible fix would be to stop-the-world, do the assignment and then start the world again. Note that while the world is stopped, it is not safe to call most of the Python APIs. That's the reason for the complex logic related to apply_type_slot_updates(). I'm not sure but I suspect change base or bases could require similar levels of care.

  12. LindaSummer commented on Oct 16, 2025

    @LindaSummer
    Contributor

    I'm interested in the free-threading topic and want to try the 'tp_base and tp_bases are assigned in likely unsafe ways' subtask.

    I don't have specific instructions for that but here are some general thoughts. Inside typeobject.c, look at places where ->tp_base and ->tp_bases get assigned. If they are inside a function that has ASSERT_NEW_TYPE_OR_LOCKED then those should be safe. If not, you need to follow the logic to see how those functions get called. If those assignments happen after the type has been potentially revealed to other threads then the assignment is likely a data race. Possible fix would be to stop-the-world, do the assignment and then start the world again. Note that while the world is stopped, it is not safe to call most of the Python APIs. That's the reason for the complex logic related to apply_type_slot_updates(). I'm not sure but I suspect change base or bases could require similar levels of care.

    Hi @nascheme ,

    Thanks very much for your instructions! ❤ It helps me a lot and guides the way!
    I will try to construct the data race case and update if I have any new findings.

    Best Regards,
    Edward

  13. added a commit that references this issue on Nov 5, 2025
  14. kumaraditya303 commented on Nov 12, 2025

    @kumaraditya303
    Contributor

    Closing as all the races are fixed.

  15. added a commit that references this issue on Dec 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions