Repository navigation
test_hashlib fails when run on Free Threading with TSAN #153201
Description
Activity
- addedtype-crashA hard crash of the interpreter, possibly with a core dumpA hard crash of the interpreter, possibly with a core dump
on Jul 6, 2026 I can reproduce the issue with "OpenSSL 3.5.7 9 Jun 2026" on Fedora 44 with commands:
export TSAN_OPTIONS="$PWD/log_path=san_log suppressions=$PWD/Tools/tsan/suppressions_free_threading.txt handle_segv=0" ./python -u -m test --parallel-threads=4 -v test_hashlib -m KDFTests 2>&1|tee logIt's the
test_pbkdf2_hmac_c()test which triggers the data race.See also issue gh-143750.
I tried but failed (so far) to reproduce the issue with OpenSSL built with TSAN.
I applied this patch (extracted from #143750):
diff --git a/Tools/ssl/multissltests.py b/Tools/ssl/multissltests.py index 1a213187b89..d5e38993d97 100755 --- a/Tools/ssl/multissltests.py +++ b/Tools/ssl/multissltests.py @@ -163,6 +163,12 @@ dest='keep_sources', help="Keep original sources for debugging." ) +parser.add_argument( + '--tsan', + action='store_true', + dest='tsan', + help="Build with thread sanitizer. (Disables fips in OpenSSL 3.x)." +) class AbstractBuilder(object): @@ -317,6 +323,8 @@ def _build_src(self, config_args=()): """Now build openssl""" log.info("Running build in {}".format(self.build_dir)) cwd = self.build_dir + if self.args.tsan: + config_args += ("-fsanitize=thread",) cmd = [ "./config", *config_args, "shared", "--debug",
I ran commands:
./Tools/ssl/multissltests.py --steps=library --base-directory ~/multissl --openssl 3.5.7 --system Linux --tsan export LD_LIBRARY_PATH=~/multissl/openssl/3.5.7/lib/ ./configure --with-thread-sanitizer --with-pydebug --disable-gil --with-openssl=/home/vstinner/multissl/openssl/3.5.7 make clean make ./python -u -m test --parallel-threads=4 -v test_hashlib -m KDFTests 2>&1|tee logSadly, so far I failed to reproduce the test_hashlib failure this way.
I think it might be a false-positive race because openssl was not compiled with tsan enabled.
This failure now blocks the CI for multiple PRs :(
Example: https://github.com/python/cpython/actions/runs/28853850174?pr=153253 Even 3rd re-run is failing.And since
sanjob is required, no PRs are able to get merged which touch some specific files.
Should we disablesanjob's required status for now?The race could be in
get_openssl_evp_md_by_utf8namewhich is a known failure however that I recently fixed #153019. I want to emit a nice commit message which I unfortunately didn't have time to write for now but it was also very hard to reproduce in general.- addedextension-modulesC modules in the Modules dirC modules in the Modules dir
on Jul 7, 2026 @sobolevn Why did you reopen this?
So we can merge #153201 and backports :)
Crash report
TSAN CI job: https://github.com/python/cpython/actions/runs/28747943876/job/85377269260?pr=152717
test_hashlib fails when run on Free Threading with TSAN on the main branch.
Commands:
Tests output (truncated):
TSAN logs (truncated):
Full TSAN logs: tsan_full.log.
Linked PRs