HTTP: a code route can mutate the live route table and static root from a worker thread — unsynchronized writes racing every other worker's lookups
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 48/100
- Tipo di issue
- Bug
- Chiarezza
- Specificata chiaramente
- Stato di attività
- Attiva
- Stack tecnologico
- c
- Ambito
- backend-api-design, networking, testing-qa
Direzione di ricerca
Start at http_conn_thread and the g_server/eigs_http_active handling, then inspect builtin_http_route, builtin_http_route_authed, builtin_http_static, and the existing serving guard used by http_response_header. Run tests/http_readiness.py and add the live mutation case described in the issue; done means mutation fails loudly, /injected remains 404, and the concurrent probe is race-free under the planned tsan-http lane.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Observed (executed on main a18deac, make http)
A code route runs in a per-connection worker thread. The worker gets its own EigsState, but http_conn_thread then re-points the thread-local server accessor at the SPAWNING server so that handle_request reads the real route table:
/* register_http_builtins allocated a scratch Server on the worker state (so
* http_route/http_serve called inside a code route don't crash) ... Re-point
* at the spawning Server so handle_request reads the main route table. */
eigs_http_active = main_server;
The comment's intent (a scratch server absorbs config calls from a code route) is defeated two lines later: g_server is (*eigs_http_active), so http_route, http_route_authed and http_static invoked from a code route WRITE the main server's config while every other worker reads it lock-free.
Probe:
r is http_route of ["GET", "/", "page"]
c is http_route of ["GET", "/mutate", "code",
"http_route of [\"GET\", \"/injected\", \"INJECTED\"]\nhttp_static of [\"/static\", \"/tmp\"]\n\"mutated\""]
http_serve of 24911
before: GET /injected -> 404
GET /mutate -> mutated
after: GET /injected -> 200 INJECTED
One request permanently changed the routing table for the whole process.
Why it is a concurrency defect, not just a design oddity
builtin_http_routefillsroutes[route_count]'s four string fields, then doesg_server.route_count++— a plain non-atomic int with no release fence. A concurrent worker iteratingfor (i < route_count)can observe the incremented count before the slot's fields are visible and callstrcmpon NULL/garbage.builtin_http_staticswapsstatic_prefix/static_dirunder no lock while workers dereference them (the old strings are leaked rather than freed, so no UAF today — by accident).- The
route_count >= MAX_ROUTEScheck is check-then-act across threads. - Exploitation needs a trusted code route that calls these builtins, so this is a correctness/robustness issue, not a remote hole — but it is a genuine data race in the runtime's most concurrent code, and it lives in the same file that #1137 just cleaned up.
Suggested fix
Freeze configuration at http_serve, the way http_response_header already does: builtin_http_route, builtin_http_route_authed and builtin_http_static check g_server.serving (under response_mu, or make it atomic) and raise a loud error once serving. Every lock-free read of routes/static config is then reading immutable data, which is the property the current code silently assumes.
Gate
tests/http_readiness.py: a live case with a code route that callshttp_route/http_static— the request must fail loudly (500 with the error text) and/injectedmust remain 404 afterwards; plant: revert the freeze → red.- Once #1139 lands a
tsan-httplane, a probe hammering/mutateand/concurrently should report the race on today's tree and be silent after the fix.
Found during the concurrency review that followed PR #1138 (2026-09-14). The rest of the file's threading — init responder, response builder, shared store, per-IP table, config caches — reviewed sound.
- Lingua principale
- C
- Stelle
- 3
- Fork
- 7
- Merge medio
- 4h 7m
- PR unite (30g)
- 112
Preparare l'ambiente
Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.
- Include un Dockerfile o un file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di InauguralSystems/EigenScript
-
area:embed kind:silent-wrong
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
InauguralSystems/EigenScript#1387 ·
I maintainer di solito rispondono entro 1 giorno
-
area:stdlib kind:silent-wrong
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
InauguralSystems/EigenScript#1378 ·
I maintainer di solito rispondono entro 1 giorno
-
area:gates kind:gate-defect
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
InauguralSystems/EigenScript#1374 ·
I maintainer di solito rispondono entro 1 giorno
-
Error carets pad multi-byte UTF-8 byte-for-byte, so the ^ lands right of the token on a terminalApertaarea:lint-tooling kind:silent-wrong
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
InauguralSystems/EigenScript#1373 ·
I maintainer di solito rispondono entro 1 giorno
-
area:gates kind:docs-drift
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
InauguralSystems/EigenScript#1372 ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di InauguralSystems/EigenScript
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
-
[Issue]: Headers - vx_ext_amd.h does not compile as C (enum types used without the enum keyword)Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 84/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
Qiskit/qiskit#17079 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno