Skip to content

Data race creating Tcl interpreters concurrently via _tkinter.create under free-threading #154923

Description

@Naserume

Bug report

Bug description:

_tkinter declares Py_MOD_GIL_NOT_USED, so under --disable-gil the GIL no longer serializes calls into it. _tkinter.create() creates a new Tcl interpreter with Tcl_CreateInterp():

cpython/Modules/_tkinter.c

Lines 631 to 643 in 22a6c51

Tkapp_New(const char *screenName, const char *className,
int interactive, int wantobjects, int wantTk, int sync,
const char *use)
{
TkappObject *v;
char *argv0;
PyTypeObject *tp = (PyTypeObject *)Tkapp_Type;
v = (TkappObject *)tp->tp_alloc(tp, 0);
if (v == NULL)
return NULL;
v->interp = Tcl_CreateInterp();

reached from _tkinter_create_impl:

cpython/Modules/_tkinter.c

Lines 3456 to 3483 in 22a6c51

_tkinter_create_impl(PyObject *module, const char *screenName,
const char *baseName, const char *className,
int interactive, int wantobjects, int wantTk, int sync,
const char *use)
/*[clinic end generated code: output=e3315607648e6bb4 input=7e382ba431bed537]*/
{
/* XXX baseName is not used anymore;
* try getting rid of it. */
CHECK_STRING_LENGTH(screenName);
CHECK_STRING_LENGTH(baseName);
CHECK_STRING_LENGTH(className);
CHECK_STRING_LENGTH(use);
#if TCL_MAJOR_VERSION < 9
/* className is title-cased during Tk initialization. Tcl 8.x does not
* support non-BMP characters (encoded as 4-byte UTF-8 sequences) there
* and crashes in Tcl_UtfToTitle (see gh-126219). Reject them up front. */
for (const unsigned char *p = (const unsigned char *)className; *p; p++) {
if (*p >= 0xF0) {
PyErr_SetString(PyExc_ValueError,
"className must not contain non-BMP characters "
"with this version of Tcl/Tk");
return NULL;
}
}
#endif
return (PyObject *) Tkapp_New(screenName, className,

_tkinter does not serialize interpreter creation, so two threads calling _tkinter.create() run Tcl_CreateInterp() concurrently. That triggers Tcl's first-time global initialization, where Tcl_MutexLock lazily initializes a static mutex. That init is not concurrency-safe, so one thread's pthread_mutex_init (write) races with another thread's pthread_mutex_lock (atomic read) on the same Tcl global.

Reproducer:

import _tkinter
from threading import Thread

def worker():
    for _ in range(20000):
        try:
            _tkinter.create(None, '', 'Tk', False, 1, False, False, None)
        except Exception:
            pass

ts = [Thread(target=worker) for _ in range(12)]
for t in ts: t.start()
for t in ts: t.join()

TSAN Report (Tested on Linux, Tcl 8.6.14, with useTk=False):

==================
WARNING: ThreadSanitizer: data race (pid=650542)
  Atomic read of size 1 at 0x72a0000145d0 by thread T2:
    #0 pthread_mutex_lock <null> 
    #1 TclCreateExecEnv /usr/src/tcl8.6-8.6.14+dfsg-1build1/generic/tclExecute.c:936:5 
    #2 cfunction_vectorcall_FASTCALL /cpython/Objects/methodobject.c:449:24 
    #3 _PyObject_VectorcallTstate /cpython/./Include/internal/pycore_call.h:144:11 
    #4 PyObject_Vectorcall /cpython/Objects/call.c:327:12 
    #5 _Py_VectorCallInstrumentation_StackRefSteal /cpython/Python/ceval.c:768:11 
    #6 _PyEval_EvalFrameDefault /cpython/Python/generated_cases.c.h:1906:35  

  Previous write of size 1 at 0x72a0000145d0 by thread T1 (mutexes: write M0):
    #0 pthread_mutex_init <null> 
    #1 Tcl_MutexLock /usr/src/tcl8.6-8.6.14+dfsg-1build1/unix/tclUnixThrd.c:430:6 
    #2 cfunction_vectorcall_FASTCALL /cpython/Objects/methodobject.c:449:24 
    #3 _PyObject_VectorcallTstate /cpython/./Include/internal/pycore_call.h:144:11 
    #4 PyObject_Vectorcall /cpython/Objects/call.c:327:12 
    #5 _Py_VectorCallInstrumentation_StackRefSteal /cpython/Python/ceval.c:768:11 
    #6 _PyEval_EvalFrameDefault /cpython/Python/generated_cases.c.h:1906:35  

  Location is heap block of size 16384 at 0x72a000014000 allocated by thread T1:
    #0 malloc <null> 
    #1 GetBlocks /usr/src/tcl8.6-8.6.14+dfsg-1build1/generic/tclThreadAlloc.c:1044:17 
    #2 cfunction_vectorcall_FASTCALL /cpython/Objects/methodobject.c:449:24 
    #3 _PyObject_VectorcallTstate /cpython/./Include/internal/pycore_call.h:144:11 
    #4 PyObject_Vectorcall /cpython/Objects/call.c:327:12 
    #5 _Py_VectorCallInstrumentation_StackRefSteal /cpython/Python/ceval.c:768:11 
    #6 _PyEval_EvalFrameDefault /cpython/Python/generated_cases.c.h:1906:35 

  Mutex M0 (0x7fffb1dff7a0) created at:
    #0 pthread_mutex_lock <null>
    #1 Tcl_MutexLock /usr/src/tcl8.6-8.6.14+dfsg-1build1/unix/tclUnixThrd.c:423:2 
    #2 _PyImport_RunModInitFunc /cpython/./Python/importdl.c:436:19 
    #3 import_run_extension /cpython/Python/import.c:2167:14
    #4 _imp_create_dynamic_impl /cpython/Python/import.c:5565:11 
    #5 _imp_create_dynamic /cpython/Python/clinic/import.c.h:489:20 
    #6 cfunction_vectorcall_FASTCALL /cpython/Objects/methodobject.c:449:24 
    #7 _PyVectorcall_Call /cpython/Objects/call.c:273:16 
    #8 _PyObject_Call /cpython/Objects/call.c:348:16
    #9 PyObject_Call /cpython/Objects/call.c:373:12
    #10 _PyEval_EvalFrameDefault /cpython/Python/generated_cases.c.h:2831:38 

SUMMARY: ThreadSanitizer: data race (/cpython/cpython-tsan/bin/python3.16t+0xfad6e)  in pthread_mutex_lock
==================

On macOS with Tcl/Tk 9.0 the same reproducer surfaces the _tkinter module-global data races (PyOS_InputHook, tcl_lock). With useTk=True it crashes inside Tk's own display initialization.

CPython versions tested on:

CPython main branch

Operating systems tested on:

Linux

Metadata

Metadata

Assignees

No one assigned

    Labels

    type-bugAn unexpected behavior, bug, or error

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions