Skip to content

fix(download): replace asyncio lock with thread lock - #87

Merged
HC-ONLINE merged 1 commit into
mainfrom
fix/cross-thread
Sep 16, 2026
Merged

HC-ONLINE merged 1 commit into
mainfrom
fix/cross-thread

Conversation

@HC-ONLINE

Copy link
Copy Markdown
Owner

Description

Fixes a thread-safety issue in the download token registry caused by using asyncio.Lock to protect synchronous shared state accessed from multiple threads and event loops.

The definitive audit confirmed that the actual failure mode is blocking/deadlock under cross-thread contention, rather than the originally suspected lost updates.

The fix uses threading.Lock for _DownloadRegistry, matching the existing synchronization pattern used by HTTPClient for shared synchronous state.

A dedicated regression test was also added using threading.Barrier to force contention between threads and detect the vulnerable asyncio.Lock behavior.

The public API and existing download service behavior remain unchanged.

Related Issue

Fixes #BUG-002

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update

Checklist

  • I have followed the style guidelines of this project (Ruff & Pyright)
  • I have performed a self-review of my code
  • I have commented my code, particularly in hard-to-understand areas
  • I have added tests that prove my fix is effective or that my feature works
  • New and existing unit tests pass locally with my changes
  • I have updated the documentation accordingly

Screenshots (if applicable)

Not applicable.

@HC-ONLINE
HC-ONLINE merged commit 489a468 into main Sep 16, 2026
6 checks passed
@HC-ONLINE
HC-ONLINE deleted the fix/cross-thread branch September 26, 2026 21:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant