UrlLib: Apple backend use-after-free when a UrlRequest is destroyed in flight
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 52/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Tranquilla
- Stack tecnologico
- cpp
- Ambito
- backend, networking
Direzione di ricerca
Inizia in UrlRequest_Apple.mm da Impl::SendAsync(), quindi segui ImplBase::~ImplBase() e Abort() per comprendere il percorso di annullamento esistente. Esegui la copertura CI di UrlLib interessata per le richieste in corso abbandonate. Il lavoro è completato quando la distruzione di una richiesta non può consentire a un’attività Apple di accedere a uno stato liberato, l’annullamento viene rispettato e il comportamento del backend pertinente è coperto.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Split out from review feedback on BabylonJS/UrlLib#37 (filed here because BabylonJS/UrlLib has Issues disabled).
Problem
On the Apple (NSURLSession) backend, an in-flight UrlRequest that is destroyed before it settles leads to a use-after-free.
UrlRequest_Apple.mm's SendAsync() builds a completion handler that writes m_statusCode, m_headers, m_responseString / m_responseBuffer and calls SetError(...) — so it implicitly captures a raw this. Nothing keeps the Impl alive for the duration of the task:
UrlRequest::Implthere has no destructor.- It never reads
m_cancellationSource. - It never calls
[task cancel].
ImplBase::~ImplBase() calls Abort(), but Abort() only does m_cancellationSource.cancel(), which this backend ignores. So destroying a UrlRequest neither stops the resumed NSURLSessionDataTask nor extends the impl's lifetime — the task keeps running and its handler later writes into freed memory.
Impact
Any caller that drops a UrlRequest before it completes (e.g. abandoning a request on teardown) can corrupt whatever the freed allocation is reused for. This is not theoretical: it was observed in UrlLib CI, where an abandoned request's late failure handler wrote its error into a subsequent test's Impl, making an unrelated, previously-passing test report NSURLErrorCancelled (-999) with a non-empty ErrorString/ErrorSymbol.
Notes
- Pre-existing; not introduced by #37. That PR's new test was simply the first code to exercise it, and now works around it by waiting for the request to settle before leaving scope.
- Worth auditing the other backends for the same pattern.
Possible fixes
- Have
Implinheritstd::enable_shared_from_thisand capture a strong reference in the completion handler, so the impl outlives the task. - And/or make
Abort()actually cancel theNSURLSessionDataTaskon this backend, honoringm_cancellationSource.
- Lingua principale
- C++
- Stelle
- 22
- Fork
- 23
- Merge medio
- 2h 29m
- PR unite (30g)
- 3
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di BabylonJS/JsRuntimeHost
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
BabylonJS/JsRuntimeHost#234 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
BabylonJS/JsRuntimeHost#173 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 42/100
BabylonJS/JsRuntimeHost#241 · 3 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
BabylonJS/JsRuntimeHost#228 ·
I maintainer di solito rispondono entro 1 giorno
-
napi_unwrap does not reject objects that were never wrapped (V8 port faults, QuickJS port confuses types)Forse già presa @bghgary l’ha presa 48 giorni fa. Aperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 68/100
BabylonJS/JsRuntimeHost#226 ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di BabylonJS/JsRuntimeHost
Issue simili
-
Status: Awaiting triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
espressif/arduino-esp32#12984 ·
I maintainer di solito rispondono entro 1 giorno
-
torch_ops/logprob.cu does not compile with the serving container's nvcc (13.3.73); check_torch_ops.py cannot run as shippedForse già presa Una pull request collegata a questa issue è aperta o già unita. Aperta
Difficoltà 2/5 Meno di un'ora Idoneità per principianti 72/100
ashhart/TensorFold#535 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 66/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
I maintainer di solito rispondono entro 1 giorno
-
agent:Windows bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
I maintainer di solito rispondono entro 1 giorno