State/liveness keyed on PID alone is vulnerable to PID reuse
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 55/100
Direzione di ricerca
Inizia leggendo DevProxy/State/StateManager.cs, in particolare IsProcessRunning, LoadStateFromFileAsync e GetOrphanedSystemProxyStatesAsync, poi esamina DevProxy/State/ProxyInstanceState.cs per comprendere i dati del file di stato. Traccia il modo in cui i comandi delle istanze scollegate utilizzano la disponibilità del PID. Il lavoro è completato quando lo stato obsoleto viene rifiutato se un PID è stato riutilizzato, mentre le istanze legittime continuano a essere riconosciute.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Description
Dev Proxy tracks detached instances by PID alone (state-<pid>.json), and StateManager determines whether an instance is "alive" purely by checking whether a process with that PID currently exists (StateManager.IsProcessRunning(int pid) → Process.GetProcessById).
Operating systems recycle PIDs. After an instance exits (cleanly or via crash), its PID number can be reassigned to a completely unrelated process. When that happens:
IsProcessRunning(pid)returnstruefor the stale state record, so Dev Proxy believes its old instance is still alive.- Commands that key on liveness (
stop,status,LoadAllStatesAsync,FindSystemProxyInstanceAsync, and the crash-recovery / orphaned-system-proxy reconciliation added in thestop --forcefix) can act on — or refuse to act on — the wrong process.
This is a pre-existing, low-probability correctness issue in the whole detached-instance design; it is independent of any single command.
Suggested fix
Store additional identity beyond the PID in the state file and verify it before treating a PID as "our" live instance. Options:
- Persist the process start time (
Process.StartTime) alongside the PID, and inIsProcessRunningcompare the running process's start time to the recorded value — a mismatch means the PID was reused and the record is stale. - Optionally also persist the process name / a Dev Proxy marker as a secondary check.
Process.StartTime is available cross-platform in .NET and is the standard, low-cost way to disambiguate PID reuse.
Notes
- Found while implementing the fix for #1731 (
devproxy stop --forcecannot restore the system proxy after a crashed instance). That fix relies onasSystemProxystate records to reconcile orphaned system-proxy registrations; PID-reuse hardening would make that reconciliation (and all liveness checks) more robust but is intentionally out of scope for that change. - Affected code:
DevProxy/State/StateManager.cs(IsProcessRunning,LoadStateFromFileAsync,GetOrphanedSystemProxyStatesAsync),DevProxy/State/ProxyInstanceState.cs.
- Lingua principale
- C#
- Stelle
- 833
- Fork
- 90
- Merge medio
- 16h 44m
- PR unite (30g)
- 40
Preparare l'ambiente
- Include un Dockerfile o un file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di dotnet/dev-proxy
-
LanguageModelRateLimitingPlugin returns a billing error (insufficient_quota) instead of a rate limit errorForse già presa @waldekmastykarz l’ha presa 1 giorno fa. Apertawork in progress
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
dotnet/dev-proxy#1911 · 1 assegnatario ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
I maintainer di solito rispondono entro 1 giorno
-
config get doesn't print the start command for presets with a .devproxy folderForse già presa @waldekmastykarz l’ha presa 1 giorno fa. Apertawork in progress
Difficoltà 2/5 1-3 ore Idoneità per principianti 25/100
dotnet/dev-proxy#1906 · 1 assegnatario ·
I maintainer di solito rispondono entro 1 giorno
-
GenericRandomErrorPlugin sends literal @dynamic in Retry-After for non-429 responsesForse già presa @waldekmastykarz l’ha presa 1 giorno fa. Apertawork in progress
Difficoltà 3/5 1-2 giorni Idoneità per principianti 35/100
dotnet/dev-proxy#1905 · 1 assegnatario ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di dotnet/dev-proxy
Issue simili
-
[C#]:主页联网更新的提示投稿横幅指向错误Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
PCL-Community/PCL-CE#3652 ·
I maintainer di solito rispondono entro 1 giorno
-
area:frontend bug FE P3
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
klasolsson81/jobbliggaren#2010 ·
I maintainer di solito rispondono entro 1 giorno
-
[aw] Upgrade availableApertaagentic-workflows untriaged
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 65/100
I maintainer di solito rispondono entro 1 giorno
-
area: homeblaze type: bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
RicoSuter/Namotion.Interceptor#630 ·
I maintainer di solito rispondono entro 1 giorno
-
Akka.Hosting enhancement
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100