• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

aio-libs / multidict / 34813154583
87%

Build:
DEFAULT BRANCH: master
Ran 14 Sep 2026 06:22AM UTC
Jobs 1
Files 34
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

14 Sep 2026 06:21AM UTC coverage: 85.981%. Remained the same
34813154583

push

github

web-flow
Fix a data race on self->state in update()/extend()/merge() (#1452)

<!-- Thank you for your contribution! -->

## What do these changes do?

`update()`, `extend()`, and `merge()` used to read `self->state` to
parse
their arguments before acquiring `self`'s critical section, while
`__init__()` on an already-published, shared multidict
(`d.__init__(other)`)
rewrote that same field under lock via `md_clone_from_ht()`/`md_init()`
on
every reinit, racing with those unlocked reads.

Rather than routing reads around the racy field, this closes the race at
its root: `self->state` is now written exactly once, at object
construction (`multidict_tp_new`, the vectorcall constructor, and
`multidict_copy`), and `__init__()`/clone never touch it again.
`md_init()`
no longer takes a `state` parameter and instead asserts
`md->state != NULL`; `md_clone_from_ht()` no longer touches `state` at
all. `self->state` is therefore safe to read unlocked from anywhere, not
just the specific call sites that happened to need fixing.

## Are there changes in behavior for the user?

No.

## Is it a substantial burden for the maintainers to support this?

No, it narrows `md_init()`'s responsibility and moves the one-time state
assignment to the three real construction sites.

## Related issue number

N/A, found via a ThreadSanitizer run against a TSan-instrumented
free-threaded CPython build, not a filed issue.

## Checklist

- [x] I think the code is well written
- [ ] Unit tests for the changes exist
- [ ] Documentation reflects the changes
- [ ] If you provide code modification, please add yourself to
`CONTRIBUTORS.txt`
- [x] Add a new news fragment into the `CHANGES/` folder
- [x] `make doc-spelling` passes and any new technical words are added
to `docs/spelling_wordlist.txt`

<details>
<summary>Agent run details (optional, for reviewers)</summary>

No dedicated regression test: since `__init__()` no longer writes
`self->state` at all, racing it against `update()`/`extend()`/`me... (continued)

715 of 1430 branches covered (50.0%)

Branch coverage included in aggregate %.

5179 of 5425 relevant lines covered (95.47%)

1.91 hits per line

Jobs
ID Job ID Ran Files Coverage
1 MyPy - 34813154583.1 14 Sep 2026 06:22AM UTC 68
85.98
GitHub Action Run
Source Files on build 34813154583
  • Tree
  • List 34
  • Changed 2
  • Source Changed 0
  • Coverage Changed 2
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Github Actions Build #34813154583
  • 9f8087e9 on github
  • Prev Build on master (#34800370841)
  • Next Build on master (#34814557513)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc