Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

HTTP: a code route can mutate the live route table and static root from a worker thread — unsynchronized writes racing every other worker's lookups

Aperta
#1,140 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
48/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Attiva
Stack tecnologico
c

Direzione di ricerca

Start at http_conn_thread and the g_server/eigs_http_active handling, then inspect builtin_http_route, builtin_http_route_authed, builtin_http_static, and the existing serving guard used by http_response_header. Run tests/http_readiness.py and add the live mutation case described in the issue; done means mutation fails loudly, /injected remains 404, and the concurrent probe is race-free under the planned tsan-http lane.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

area:concurrency area:http bug

Observed (executed on main a18deac, make http)

A code route runs in a per-connection worker thread. The worker gets its own EigsState, but http_conn_thread then re-points the thread-local server accessor at the SPAWNING server so that handle_request reads the real route table:

/* register_http_builtins allocated a scratch Server on the worker state (so
 * http_route/http_serve called inside a code route don't crash) ... Re-point
 * at the spawning Server so handle_request reads the main route table. */
eigs_http_active = main_server;

The comment's intent (a scratch server absorbs config calls from a code route) is defeated two lines later: g_server is (*eigs_http_active), so http_route, http_route_authed and http_static invoked from a code route WRITE the main server's config while every other worker reads it lock-free.

Probe:

r is http_route of ["GET", "/", "page"]
c is http_route of ["GET", "/mutate", "code",
    "http_route of [\"GET\", \"/injected\", \"INJECTED\"]\nhttp_static of [\"/static\", \"/tmp\"]\n\"mutated\""]
http_serve of 24911
before: GET /injected -> 404
        GET /mutate   -> mutated
after:  GET /injected -> 200 INJECTED

One request permanently changed the routing table for the whole process.

Why it is a concurrency defect, not just a design oddity

  • builtin_http_route fills routes[route_count]'s four string fields, then does g_server.route_count++ — a plain non-atomic int with no release fence. A concurrent worker iterating for (i < route_count) can observe the incremented count before the slot's fields are visible and call strcmp on NULL/garbage.
  • builtin_http_static swaps static_prefix/static_dir under no lock while workers dereference them (the old strings are leaked rather than freed, so no UAF today — by accident).
  • The route_count >= MAX_ROUTES check is check-then-act across threads.
  • Exploitation needs a trusted code route that calls these builtins, so this is a correctness/robustness issue, not a remote hole — but it is a genuine data race in the runtime's most concurrent code, and it lives in the same file that #1137 just cleaned up.

Suggested fix

Freeze configuration at http_serve, the way http_response_header already does: builtin_http_route, builtin_http_route_authed and builtin_http_static check g_server.serving (under response_mu, or make it atomic) and raise a loud error once serving. Every lock-free read of routes/static config is then reading immutable data, which is the property the current code silently assumes.

Gate

  • tests/http_readiness.py: a live case with a code route that calls http_route/http_static — the request must fail loudly (500 with the error text) and /injected must remain 404 afterwards; plant: revert the freeze → red.
  • Once #1139 lands a tsan-http lane, a probe hammering /mutate and / concurrently should report the race on today's tree and be silent after the fix.

Found during the concurrency review that followed PR #1138 (2026-09-14). The rest of the file's threading — init responder, response builder, shared store, per-IP table, config caches — reviewed sound.

Lingua principale
C
Stelle
3
Fork
7
Merge medio
4h 7m
PR unite (30g)
112

Preparare l'ambiente

Apri in Codespaces

Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di InauguralSystems/EigenScript

Tutte le issue di InauguralSystems/EigenScript

Issue simili

Altre issue su C

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.