Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

State/liveness keyed on PID alone is vulnerable to PID reuse

Aperta
#1,755 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
55/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Tranquilla
Stack tecnologico
csharp
Ambito
cli, devtools

Direzione di ricerca

Inizia leggendo DevProxy/State/StateManager.cs, in particolare IsProcessRunning, LoadStateFromFileAsync e GetOrphanedSystemProxyStatesAsync, poi esamina DevProxy/State/ProxyInstanceState.cs per comprendere i dati del file di stato. Traccia il modo in cui i comandi delle istanze scollegate utilizzano la disponibilità del PID. Il lavoro è completato quando lo stato obsoleto viene rifiutato se un PID è stato riutilizzato, mentre le istanze legittime continuano a essere riconosciute.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Description

Dev Proxy tracks detached instances by PID alone (state-<pid>.json), and StateManager determines whether an instance is "alive" purely by checking whether a process with that PID currently exists (StateManager.IsProcessRunning(int pid) → Process.GetProcessById).

Operating systems recycle PIDs. After an instance exits (cleanly or via crash), its PID number can be reassigned to a completely unrelated process. When that happens:

  • IsProcessRunning(pid) returns true for the stale state record, so Dev Proxy believes its old instance is still alive.
  • Commands that key on liveness (stop, status, LoadAllStatesAsync, FindSystemProxyInstanceAsync, and the crash-recovery / orphaned-system-proxy reconciliation added in the stop --force fix) can act on — or refuse to act on — the wrong process.

This is a pre-existing, low-probability correctness issue in the whole detached-instance design; it is independent of any single command.

Suggested fix

Store additional identity beyond the PID in the state file and verify it before treating a PID as "our" live instance. Options:

  • Persist the process start time (Process.StartTime) alongside the PID, and in IsProcessRunning compare the running process's start time to the recorded value — a mismatch means the PID was reused and the record is stale.
  • Optionally also persist the process name / a Dev Proxy marker as a secondary check.

Process.StartTime is available cross-platform in .NET and is the standard, low-cost way to disambiguate PID reuse.

Notes

  • Found while implementing the fix for #1731 (devproxy stop --force cannot restore the system proxy after a crashed instance). That fix relies on asSystemProxy state records to reconcile orphaned system-proxy registrations; PID-reuse hardening would make that reconciliation (and all liveness checks) more robust but is intentionally out of scope for that change.
  • Affected code: DevProxy/State/StateManager.cs (IsProcessRunning, LoadStateFromFileAsync, GetOrphanedSystemProxyStatesAsync), DevProxy/State/ProxyInstanceState.cs.
Lingua principale
C#
Stelle
833
Fork
90
Merge medio
16h 44m
PR unite (30g)
40

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di dotnet/dev-proxy

Tutte le issue di dotnet/dev-proxy

Issue simili

Altre issue su C#

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.