arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

CONCURDEP:CPython 并发中依赖失效的事件引导分析

CONCURDEP: Event-Guided Analysis of Dependency Invalidation in CPython Concurrency

Baihong Chen, Hadley Westover, Wen Li

arXiv 2609.28608首次发表:更新:

发表机构

Utah State University(犹他州立大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

CONCURDEP 通过事件引导的静态分析,显式建模依赖、事件和属性语义,在发布规模下有效识别 CPython 并发中跨 API 边界的运行时失效缺陷。

AI 中文摘要

移除 CPython 的全局解释器锁(GIL)会使原生代码暴露于普通 C 类型所不具备的并发环境中。在获取与使用之间,可变操作或重入可能撤销已借用的对象、存储指针、遍历状态或租约,而对象所有者仍然存活,从而导致原生内存错误和运行时状态损坏。竞态分析追踪冲突的访问。Python/C 生命周期分析追踪单个对象的状态。这些报告单元使隐式的所有者-主体-存储关系与后续在并行和重入事件下的使用脱节。我们提出 CONCURDEP,一种基于源代码的依赖失效静态分析。其关键洞察是表示原生使用所需的运行时属性,并询问在依赖的活跃区域内哪个目标匹配的事件可以撤销该属性。CONCURDEP 恢复运行时语义依赖,通过事件感知的原生并发依赖图将它们与事件连接,并通过共享引擎和六个机制插件应用属性特定的状态和转移保护。CONCURDEP 正确分类了所有 180 个匹配的语义一致性案例,并分析了三个生产级 CPython 版本,五次运行的中位时间为 22.13-27.66 秒,峰值常驻内存为 670-784 MiB。源代码审计确认了 4,273 个唯一生产指纹中的 1,094 个(25.60% 确认率)。移除派生关系恢复每个版本丢失 25-44 个表示的根;移除跨入口事件丢失 73-94 个。该研究在自由线程和传统 GIL 构建中识别出 144 个不同的缺陷,其中 95 个在公开来源中此前未报告。这些结果表明,显式的依赖、事件和属性语义在发布规模下暴露了跨 API 边界和执行模式的有后果的运行时故障。

英文摘要

Removing CPython's Global Interpreter Lock (GIL) exposes native code to concurrency absent from ordinary C types. Mutation or re-entry can revoke a borrowed object, storage pointer, traversal state, or lease between acquisition and use while its owner remains alive, causing native memory errors and runtime-state corruption. Race analyses track conflicting accesses. Python/C lifecycle analyses track individual object states. These reporting units leave implicit owner-subject-storage relations disconnected from later uses under parallel and re-entrant events. We present CONCURDEP, a source-level static analysis of dependency invalidation. Its key insight is to represent the runtime property a native use requires and ask which target-matched event can revoke it within the dependency's live region. CONCURDEP recovers runtime-semantic dependencies, connects them to events through an event-aware native concurrency dependency graph, and applies property-specific state and protection transfers through a shared engine and six mechanism plugins. CONCURDEP correctly classifies all 180 matched semantic-conformance cases and analyzes each of three production CPython releases with five-run medians of 22.13-27.66 seconds and 670-784 MiB peak resident memory. Source auditing confirms 1,094 of 4,273 unique production fingerprints (25.60% confirmation yield). Removing derived relation recovery loses 25-44 represented roots per release; removing cross-entry events loses 73-94. The study identifies 144 distinct bugs across free-threaded and conventional-GIL builds, including 95 previously unreported in public sources. These results show that explicit dependency, event, and property semantics expose consequential runtime failures across API boundaries and execution modes at release scale.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑