MEDIUM SEVERITYCONFIRMED
set_chord_size(0) stored silently — chord body fires immediately with no results
Package
celery
Version
5.6.2
Verified
2026-03-28
Description
celery's `RedisBackend.set_chord_size` and all other backends perform no validation that `chord_size > 0`. When an empty chord header results in `chord_size=0`, `on_chord_part_return` evaluates `readycount == total` as `0 == 0` immediately upon the first task return, firing the chord body callback before any tasks have completed. No exception is raised at the write point — the failure is silent and delayed.
Reproduction
# celery/backends/redis.py:484 — no guard:
# def set_chord_size(self, group_id, chord_size):
# self.set(self.get_key_for_group(group_id, '.s'), chord_size)
# When chord_size=0:
# on_chord_part_return: total = 0 + 0 = 0; readycount == total (0 == 0) -> True immediately
# Chord body callback fires with empty/incomplete result set