Repository navigation
Commit ae8799c
Bump engine to d8cb9b8 so the GIL-free declaration actually holds
The audit in 2e19844 was performed against engine d8cb9b8, but the submodule
pointer was left at 4172c5e from #21, nine commits behind. The two revisions
differ in exactly the way the audit depended on.
Engine 6e64401 ("Make peak-memory tracking a compile-time option
(SP_TRACK_MEMORY)", merged one day before this branch) puts the
g_allocated_bytes / g_peak_bytes counters behind an option that defaults to
OFF, precisely so the library can be called from several threads at once. At
4172c5e those counters are unconditional, and every sp_malloc / sp_free
updates them non-atomically. So the audit's "no writable data/bss symbols"
finding was true of the engine it inspected and false of the engine this
branch ships: nm on the cp313t extension built from 4172c5e lists
_g_allocated_bytes and _g_peak_bytes as its only external writable data.
That race is reachable from the usage the README blesses, since two threads
building or evaluating *distinct* problems both allocate. Bumping the pointer
removes it: nm on the rebuilt extension shows no mutable globals at all, and
the engine's own ctest suite passes at d8cb9b8.
Verified on cpython-3.13.5+freethreaded, 8 threads:
* independent problem per thread, 300 evaluations each, every result
bit-identical to a single-threaded reference: 10/10 runs clean.
* sharing one expression capsule across threads, which the README
forbids: 10/10 runs die with SIGSEGV / SIGBUS / SIGABRT / SIGTRAP.
The second number is why the README and the bindings.c comment no longer
describe that contract as "the same contract as with the GIL". expr::refcount
is a plain int updated non-atomically by expr_retain() / free_expr(), and
capsule destructors run on whichever thread drops the last Python reference,
so breaking the rule now corrupts the heap instead of interleaving calls. The
same misuse is harmless under the GIL. Making that count atomic upstream would
turn it back into ordinary unsupported usage; until then the docs say plainly
how sharp the edge is.
Both documents also note that SP_TRACK_MEMORY must stay off in a wheel build,
since turning it on silently reintroduces the global-counter race.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>1 parent 8406c34 commit ae8799c
3 files changed
Lines changed: 48 additions & 19 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
20 | | - | |
21 | | - | |
22 | | - | |
23 | | - | |
24 | | - | |
25 | | - | |
26 | | - | |
27 | | - | |
28 | | - | |
29 | | - | |
30 | | - | |
31 | | - | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
32 | 48 | | |
33 | 49 | | |
34 | 50 | | |
| |||
Submodule SparseDiffEngine updated 136 files
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
191 | 191 | | |
192 | 192 | | |
193 | 193 | | |
194 | | - | |
195 | | - | |
196 | | - | |
197 | | - | |
198 | | - | |
199 | | - | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
200 | 213 | | |
201 | 214 | | |
202 | 215 | | |
| |||
0 commit comments