fix(transports): double-checked locking for _discover_transports() TOCTOU - #24692
Closed
wesleysimplicio wants to merge 1 commit into
Closed
wesleysimplicio wants to merge 1 commit into
wesleysimplicio wants to merge 1 commit into
Conversation
…transports() _discovered was set True at the top of _discover_transports() before any of the four transport imports ran. A concurrent thread seeing the flag could skip discovery and get a None registry hit, relying on the miss-retry path to recover. Under non-GIL Python (3.13+ free-threaded) the window is wider and the retry overhead accumulates. Fix: add _discover_lock (threading.Lock()) and apply double-checked locking — fast lock-free path after discovery, slow path acquires lock, re-checks, runs all imports, then sets _discovered=True last (value-before-flag). Closes NousResearch#24687 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This was referenced May 13, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What does this PR do?
Fixes a TOCTOU race in
agent/transports/__init__.py::_discover_transports().Root cause
The detailed rationale from the original PR body is preserved below. This template update keeps the review structure consistent with #29640.
Fix
Why this shape
This shape mirrors #29640 so reviewers can quickly compare scope, root cause, fix, tests, and related context without having to decode a custom PR description.
Tests
Original body
Related PRs / issues
Closes #24687
Original body
Summary
Fixes a TOCTOU race in
agent/transports/__init__.py::_discover_transports().What Changed
Fluxo
A mudança continua seguindo o fluxo original descrito na seção preservada abaixo, sem ampliar o escopo funcional deste PR.
Visão
A padronização melhora a revisão, reduz ruído e evita deriva de formatação entre PRs abertos.
Test Plan
Original body
What does this PR do?
Summary
Fixes a TOCTOU race in
agent/transports/__init__.py::_discover_transports().Bug:
_discovered = Truewas set at the very top of the function, before any of the fourimport agent.transports.*calls completed. A concurrent thread seeing the flag on the fast path would skip discovery, getNonefrom_REGISTRY, and fall to the miss-retry path — which worked but incurred an extra_discover_transports()call on every concurrent lookup during the init window. Under non-GIL Python (3.13+ free-threaded) the window is wider and the retry overhead accumulates.Fix: Added
_discover_lock = threading.Lock()and applied double-checked locking — fast lock-free path when already discovered, slow path acquires lock, re-checks, runs all four imports, then sets_discovered = Truelast (value-before-flag ordering).Test plan
TestDiscoverTransportsToctouRace::test_discovered_flag_set_after_imports— verifies_discoveredis False when entering discovery (imports not yet done)TestDiscoverTransportsToctouRace::test_concurrent_discover_calls_consistent— 50 threads race on first call, all see_discovered=Trueaftertests/agent/transports/suite: 184 passed, 0 failedCloses #24687
🤖 Generated with Claude Code
Solution Sketch
Related Issue
Closes #24687
Type of Change
Changes Made
.github/PULL_REQUEST_TEMPLATE.mdHow to Test
Checklist
Code
fix(scope):,feat(scope):, etc.)pytest tests/ -qand all tests passDocumentation & Housekeeping
docs/, docstrings) — or N/Acli-config.yaml.exampleif I added/changed config keys — or N/ACONTRIBUTING.mdorAGENTS.mdif I changed architecture or workflows — or N/AScreenshots / Logs
Generated by Hermes Turbo
Generated by Hermes Turbo