Skip to content

Probable fix to tracing regions - #113

Open
TobiasWrigstad wants to merge 1 commit into
tregions-main-testingfrom
probable-fix-to-tracing-regions
Open

TobiasWrigstad wants to merge 1 commit into
tregions-main-testingfrom
probable-fix-to-tracing-regions

Conversation

@TobiasWrigstad

@TobiasWrigstad TobiasWrigstad commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Reject closes that count an object more often than its RC allows

The close only checked that the LRC summed over all traced objects was
zero. An object counted through more internal references than its
recorded RC has a negative balance, which can cancel references from
outside on other objects. A thread holding a and b in a region can
move items from a to b between the two traversals without any
refcount operation (e.g. a pop followed by a stealing store): each item
is counted twice (-1), cancelling the +1 of each held list, and the
region closes while the thread still holds both. Neither the trace flag
nor the RC re-read sees this, since no refcount changes.

With no object allowed below zero, a zero total means every object
balances. The error is raised after the restart check, since code run
by freezing during a trace may move references that a fresh trace
counts correctly.

Adds a debug-only trace hook, called after each traversed object, and
_testinternalcapi.region_set_trace_move() to reproduce the move. The
test fails without the check on both GIL and free-threaded builds.


📚 Documentation preview 📚: https://cpython-previews--113.org.readthedocs.build/

The close only checked that the LRC summed over all traced objects was
zero. An object counted through more internal references than its
recorded RC has a negative balance, which can cancel references from
outside on other objects. A thread holding `a` and `b` in a region can
move items from `a` to `b` between the two traversals without any
refcount operation (e.g. a pop followed by a stealing store): each item
is counted twice (-1), cancelling the +1 of each held list, and the
region closes while the thread still holds both. Neither the trace flag
nor the RC re-read sees this, since no refcount changes.

With no object allowed below zero, a zero total means every object
balances. The error is raised after the restart check, since code run
by freezing during a trace may move references that a fresh trace
counts correctly.

Adds a debug-only trace hook, called after each traversed object, and
_testinternalcapi.region_set_trace_move() to reproduce the move. The
test fails without the check on both GIL and free-threaded builds.
@TobiasWrigstad
TobiasWrigstad changed the base branch from main to tregions-main-testing October 9, 2026 22:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant