Skip to content

fix(transports): double-checked locking for _discover_transports() TOCTOU - #24692

Closed
wesleysimplicio wants to merge 1 commit into
NousResearch:mainfrom
wesleysimplicio:fix/cx13-issue-24687-transports-discover-toctou
Closed

wesleysimplicio wants to merge 1 commit into
NousResearch:mainfrom
wesleysimplicio:fix/cx13-issue-24687-transports-discover-toctou

Conversation

@wesleysimplicio

@wesleysimplicio wesleysimplicio commented May 13, 2026 •

Copy link
Copy Markdown

What does this PR do?

Fixes a TOCTOU race in agent/transports/__init__.py::_discover_transports().

Root cause

The detailed rationale from the original PR body is preserved below. This template update keeps the review structure consistent with #29640.

Fix

  • fix the root cause in the touched subsystem instead of layering a broad workaround around the symptom
  • keep surrounding behavior stable and avoid unrelated refactors while the area is under review
  • prove the change with focused checks on the exact path that regressed

Why this shape

This shape mirrors #29640 so reviewers can quickly compare scope, root cause, fix, tests, and related context without having to decode a custom PR description.

Tests

  • Veja a descrição original preservada abaixo para detalhes de validação, testes e notas de verificação.
Original body

Related PRs / issues

Closes #24687

Original body

Summary

Fixes a TOCTOU race in agent/transports/__init__.py::_discover_transports().

What Changed

  • Standardized this PR body to the current Hermes Turbo template.
  • Preserved the original detailed description below for reference.

Fluxo

A mudança continua seguindo o fluxo original descrito na seção preservada abaixo, sem ampliar o escopo funcional deste PR.

Visão

A padronização melhora a revisão, reduz ruído e evita deriva de formatação entre PRs abertos.

Test Plan

  • Veja a descrição original preservada abaixo para detalhes de validação, testes e notas de verificação.
Original body

What does this PR do?

Summary

Fixes a TOCTOU race in agent/transports/__init__.py::_discover_transports().

Bug: _discovered = True was set at the very top of the function, before any of the four import agent.transports.* calls completed. A concurrent thread seeing the flag on the fast path would skip discovery, get None from _REGISTRY, and fall to the miss-retry path — which worked but incurred an extra _discover_transports() call on every concurrent lookup during the init window. Under non-GIL Python (3.13+ free-threaded) the window is wider and the retry overhead accumulates.

Fix: Added _discover_lock = threading.Lock() and applied double-checked locking — fast lock-free path when already discovered, slow path acquires lock, re-checks, runs all four imports, then sets _discovered = True last (value-before-flag ordering).

Test plan

  • TestDiscoverTransportsToctouRace::test_discovered_flag_set_after_imports — verifies _discovered is False when entering discovery (imports not yet done)
  • TestDiscoverTransportsToctouRace::test_concurrent_discover_calls_consistent — 50 threads race on first call, all see _discovered=True after
  • Full tests/agent/transports/ suite: 184 passed, 0 failed

Closes #24687

🤖 Generated with Claude Code

Solution Sketch

  • fix the root cause in the touched subsystem instead of layering a broad workaround around the symptom
  • keep surrounding behavior stable and avoid unrelated refactors while the area is under review
  • prove the change with focused checks on the exact path that regressed

Related Issue

Closes #24687

Type of Change

  • 🐛 Bug fix (non-breaking change that fixes an issue)
  • ✨ New feature (non-breaking change that adds functionality)
  • 🔒 Security fix
  • 📝 Documentation update
  • ✅ Tests (adding or improving test coverage)
  • ♻️ Refactor (no behavior change)
  • 🎯 New skill (bundled or hub)

Changes Made

  • preserved the existing technical rationale and validation notes inside the template body
  • scoped this PR description to the implementation already present on the branch
  • aligned the delivery format with .github/PULL_REQUEST_TEMPLATE.md

How to Test

  1. Review the existing validation notes preserved in this PR body.
  2. Run the focused checks for the touched area.
  3. Confirm the scoped change still behaves as described above.

Checklist

Code

  • I've read the Contributing Guide
  • My commit messages follow Conventional Commits (fix(scope):, feat(scope):, etc.)
  • I searched for existing PRs to make sure this isn't a duplicate
  • My PR contains only changes related to this fix/feature (no unrelated commits)
  • I've run pytest tests/ -q and all tests pass
  • I've added tests for my changes (required for bug fixes, strongly encouraged for features)
  • I've tested on my platform:

Documentation & Housekeeping

  • I've updated relevant documentation (README, docs/, docstrings) — or N/A
  • I've updated cli-config.yaml.example if I added/changed config keys — or N/A
  • I've updated CONTRIBUTING.md or AGENTS.md if I changed architecture or workflows — or N/A
  • I've considered cross-platform impact (Windows, macOS) per the compatibility guide — or N/A
  • I've updated tool descriptions/schemas if I changed tool behavior — or N/A

Screenshots / Logs

  • N/A.

Generated by Hermes Turbo


Generated by Hermes Turbo

…transports()

_discovered was set True at the top of _discover_transports() before any
of the four transport imports ran. A concurrent thread seeing the flag
could skip discovery and get a None registry hit, relying on the miss-retry
path to recover. Under non-GIL Python (3.13+ free-threaded) the window is
wider and the retry overhead accumulates.

Fix: add _discover_lock (threading.Lock()) and apply double-checked locking
— fast lock-free path after discovery, slow path acquires lock, re-checks,
runs all imports, then sets _discovered=True last (value-before-flag).

Closes NousResearch#24687

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings May 13, 2026 01:03

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot encountered an error and was unable to review this pull request. You can try again by re-requesting a review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp/agent Core agent runtime: loop, agent_init, prompt builder, context-compression, responses endpoint P2 Medium — degraded but workaround exists type/bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

concurrency: agent/transports _discovered flag set before imports complete (TOCTOU)

3 participants