State/liveness keyed on PID alone is vulnerable to PID reuse
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 55/100
Research direction
Start by reading DevProxy/State/StateManager.cs, especially IsProcessRunning, LoadStateFromFileAsync, and GetOrphanedSystemProxyStatesAsync, then inspect DevProxy/State/ProxyInstanceState.cs to understand the state-file data. Trace how detached-instance commands use PID liveness. Done means stale state is rejected when a PID has been reused, while legitimate instances continue to be recognized.
Written by the indexing model from the issue text.
Description
Description
Dev Proxy tracks detached instances by PID alone (state-<pid>.json), and StateManager determines whether an instance is "alive" purely by checking whether a process with that PID currently exists (StateManager.IsProcessRunning(int pid) → Process.GetProcessById).
Operating systems recycle PIDs. After an instance exits (cleanly or via crash), its PID number can be reassigned to a completely unrelated process. When that happens:
IsProcessRunning(pid)returnstruefor the stale state record, so Dev Proxy believes its old instance is still alive.- Commands that key on liveness (
stop,status,LoadAllStatesAsync,FindSystemProxyInstanceAsync, and the crash-recovery / orphaned-system-proxy reconciliation added in thestop --forcefix) can act on — or refuse to act on — the wrong process.
This is a pre-existing, low-probability correctness issue in the whole detached-instance design; it is independent of any single command.
Suggested fix
Store additional identity beyond the PID in the state file and verify it before treating a PID as "our" live instance. Options:
- Persist the process start time (
Process.StartTime) alongside the PID, and inIsProcessRunningcompare the running process's start time to the recorded value — a mismatch means the PID was reused and the record is stale. - Optionally also persist the process name / a Dev Proxy marker as a secondary check.
Process.StartTime is available cross-platform in .NET and is the standard, low-cost way to disambiguate PID reuse.
Notes
- Found while implementing the fix for #1731 (
devproxy stop --forcecannot restore the system proxy after a crashed instance). That fix relies onasSystemProxystate records to reconcile orphaned system-proxy registrations; PID-reuse hardening would make that reconciliation (and all liveness checks) more robust but is intentionally out of scope for that change. - Affected code:
DevProxy/State/StateManager.cs(IsProcessRunning,LoadStateFromFileAsync,GetOrphanedSystemProxyStatesAsync),DevProxy/State/ProxyInstanceState.cs.
- Dominant language
- C#
- Stars
- 833
- Forks
- 90
- Avg merge
- 15h 59m
- Merged PRs (30d)
- 39
Getting set up
- Ships a Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from dotnet/dev-proxy
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 1 day
-
MockStdioResponsePlugin: @stdin.body.id placeholder fails to resolve when messages arrive back-to-back after an id-less messageMay be free again @garrytrinder claimed this 81 days ago, and no pull request is open. Open
dotnet/dev-proxy#1757 · 1 reaction · 2 assignees ·
Maintainers usually reply within 1 day
-
needs peer review
Difficulty 4/5 3-5 days Newbie friendliness 52/100
dotnet/dev-proxy#1667 · 1 comment ·
Maintainers usually reply within 1 day
-
needs spec question
Difficulty 5/5 Over a week Newbie friendliness 30/100
dotnet/dev-proxy#1649 · 1 comment ·
Maintainers usually reply within 1 day
All issues in dotnet/dev-proxy
Similar issues
-
needs triage
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
spectreconsole/spectre.console#2221 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
-
area/navigationview 🧭 difficulty/starter 🚀 good first issue kind/bug platform/all project/navigation-lifecycle 🧬 triage/untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
unoplatform/uno#24925 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
PhilippC/keepass2android#3315 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
DamianEdwards/ghcp-spend-tray#39 ·
Maintainers usually reply within 1 day