Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

State/liveness keyed on PID alone is vulnerable to PID reuse

Open
#1,755 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
55/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Quiet
Tech stack
csharp
Domain
cli, devtools

Research direction

Start by reading DevProxy/State/StateManager.cs, especially IsProcessRunning, LoadStateFromFileAsync, and GetOrphanedSystemProxyStatesAsync, then inspect DevProxy/State/ProxyInstanceState.cs to understand the state-file data. Trace how detached-instance commands use PID liveness. Done means stale state is rejected when a PID has been reused, while legitimate instances continue to be recognized.

Written by the indexing model from the issue text.

Description

Description

Dev Proxy tracks detached instances by PID alone (state-<pid>.json), and StateManager determines whether an instance is "alive" purely by checking whether a process with that PID currently exists (StateManager.IsProcessRunning(int pid) → Process.GetProcessById).

Operating systems recycle PIDs. After an instance exits (cleanly or via crash), its PID number can be reassigned to a completely unrelated process. When that happens:

  • IsProcessRunning(pid) returns true for the stale state record, so Dev Proxy believes its old instance is still alive.
  • Commands that key on liveness (stop, status, LoadAllStatesAsync, FindSystemProxyInstanceAsync, and the crash-recovery / orphaned-system-proxy reconciliation added in the stop --force fix) can act on — or refuse to act on — the wrong process.

This is a pre-existing, low-probability correctness issue in the whole detached-instance design; it is independent of any single command.

Suggested fix

Store additional identity beyond the PID in the state file and verify it before treating a PID as "our" live instance. Options:

  • Persist the process start time (Process.StartTime) alongside the PID, and in IsProcessRunning compare the running process's start time to the recorded value — a mismatch means the PID was reused and the record is stale.
  • Optionally also persist the process name / a Dev Proxy marker as a secondary check.

Process.StartTime is available cross-platform in .NET and is the standard, low-cost way to disambiguate PID reuse.

Notes

  • Found while implementing the fix for #1731 (devproxy stop --force cannot restore the system proxy after a crashed instance). That fix relies on asSystemProxy state records to reconcile orphaned system-proxy registrations; PID-reuse hardening would make that reconciliation (and all liveness checks) more robust but is intentionally out of scope for that change.
  • Affected code: DevProxy/State/StateManager.cs (IsProcessRunning, LoadStateFromFileAsync, GetOrphanedSystemProxyStatesAsync), DevProxy/State/ProxyInstanceState.cs.
Dominant language
C#
Stars
833
Forks
90
Avg merge
15h 59m
Merged PRs (30d)
39

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from dotnet/dev-proxy

All issues in dotnet/dev-proxy

Similar issues

More C# issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.