Repository navigation
context variables can leak out of asyncio.Task #140947
Copy link
Copy link
Closed
Labels
3.15bugs and security fixesbugs and security fixestopic-asynciotype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
Description
Activity
- addedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on Nov 3, 2025 - added3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes3.15bugs and security fixesbugs and security fixes
on Nov 3, 2025 Output on Windows:
❯ ./python.bat main.py Running Debug|x64 interpreter... Python: 3.15.0a2+ (heads/main:af7cca3c39d, Dec 14 2025, 16:45:59) [MSC v.1944 64 bit (AMD64)] -------------------------------------------------------------------------------- connection_made: task=None, context={} -------------------------------------------------------------------------------- data_received: task=None, context={} -------------------------------------------------------------------------------- asgi start: task='Task-5', context={} -------------------------------------------------------------------------------- asgi end: task='Task-5', context={'cvar3': True, 'cvar1': True, 'cvar2': True} -------------------------------------------------------------------------------- connection_lost: task=None, context={} ---------------------------------------
The context of
connection_lostis empty which suggests that this bug is not present in windows implementation, still I'll double check it once I add tests on the PR.Both the bug report as well as the regression tests in uvicorn also suggest that Windows is not affected.
The fix is merged in main branch, I'll prefer to wait for some time before backporting this to older branch just to makes sure that if any bug pops up it only affects main branch.
Which older branch?
3.14 and 3.13 branches
Makes sense. Thanks for the PR. :)
- added a commit that references this issue
on Apr 21, 2026 - removed3.13only security fixesonly security fixes3.14bugs and security fixesbugs and security fixes
on Jul 23, 2026 After much thought I think backporting this is too risky as it a large behavior change of old code. Keeping this for 3.15+.
Reacted by Marcelo Trylesinski- added 2 commits that reference this issue
on Sep 29, 2026
Metadata
Metadata
Assignees
Labels
3.15bugs and security fixesbugs and security fixestopic-asynciotype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
Projects
- StatusShow more project fieldsDone
Bug report
Bug description:
This is a minimal reproducer for Kludex/uvicorn#2167. TL;DR when using
asyncioas event loop, users ofuvicornwere seeing polluted contexts after sending in large payloads. For thoseuvicornpaused reading on the main thread and resumed it in a task.The
asgitask sets three context variables:cvar1is set at the beginning of the function, which may or may not be before the reading is paused.cvar2is set after the reading is paused.cvar3is set after the reading is resumed.The context variables that have been set in the task before the reading is resumed (
cvar1andcvar2) leak out of the task into the main thread.CPython versions tested on:
3.14
Operating systems tested on:
Linux
Linked PRs