CONCURDEP: Event-Guided Analysis of Dependency Invalidation in CPython Concurrency

📅 2026-09-23
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the dependency invalidation and memory errors that arise in CPython native code due to concurrency following the removal of the Global Interpreter Lock (GIL). To mitigate these issues, this work proposes a semantic model encompassing explicit dependencies, events, and attributes, leveraging source-level static analysis to recover runtime semantic dependencies. Furthermore, it constructs an event-aware dependency graph to track attribute revocation risks, integrating a state transition engine with a plugin mechanism to enable failure detection across API boundaries. Empirically, the proposed approach accurately classifies 180 cases and identifies 144 defects, including 95 previously unknown vulnerabilities, demonstrating its capacity to efficiently handle production-scale implementations.
📝 Abstract
Removing CPython's Global Interpreter Lock (GIL) exposes native code to concurrency absent from ordinary C types. Mutation or re-entry can revoke a borrowed object, storage pointer, traversal state, or lease between acquisition and use while its owner remains alive, causing native memory errors and runtime-state corruption. Race analyses track conflicting accesses. Python/C lifecycle analyses track individual object states. These reporting units leave implicit owner-subject-storage relations disconnected from later uses under parallel and re-entrant events. We present CONCURDEP, a source-level static analysis of dependency invalidation. Its key insight is to represent the runtime property a native use requires and ask which target-matched event can revoke it within the dependency's live region. CONCURDEP recovers runtime-semantic dependencies, connects them to events through an event-aware native concurrency dependency graph, and applies property-specific state and protection transfers through a shared engine and six mechanism plugins. CONCURDEP correctly classifies all 180 matched semantic-conformance cases and analyzes each of three production CPython releases with five-run medians of 22.13-27.66 seconds and 670-784 MiB peak resident memory. Source auditing confirms 1,094 of 4,273 unique production fingerprints (25.60% confirmation yield). Removing derived relation recovery loses 25-44 represented roots per release; removing cross-entry events loses 73-94. The study identifies 144 distinct bugs across free-threaded and conventional-GIL builds, including 95 previously unreported in public sources. These results show that explicit dependency, event, and property semantics expose consequential runtime failures across API boundaries and execution modes at release scale.
Problem

Research questions and friction points this paper is trying to address.

GIL removal
dependency invalidation
concurrency bugs
CPython
native memory errors
Innovation

Methods, ideas, or system contributions that make the work stand out.

Dependency Invalidation
Static Analysis
Concurrency Dependency Graph
Event-Guided Analysis
GIL Removal
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
B
Baihong Chen
Utah State University
H
Hadley Westover
Utah State University
Wen Li
Wen Li
Utah State University
Software EngineeringProgram AnalysisSoftware Security