atspi-common: register_tree panics (then aborts) when adapters become active out of order: push_adapter doesn't keep the list sorted for adapter_index's binary search
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 2/5
- 見積もり時間
- 1〜3時間
- 初心者へのやさしさ
- 72/100
- issue の種類
- バグ
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- linux, rust
調査の方向性
バグは adapters/atspi-common/src/context.rs にあります。push_adapter はリストを整列された状態に保たずに追加するため、adapter_index の二分探索がエントリを見逃します。まず adapter_index と push_adapter を読み、次に adapter.rs の register_tree にある unwrap を確認してください。順序 1、2、0 で追加された adapter がすべて見つかり、提案された整列挿入を使用し、remove_adapter がそのエントリを引き続き見つけられれば完了です。
索引モデルが issue の本文から書いたものです。
説明
What happens
AppContext in accesskit_atspi_common finds adapters with a binary search, but push_adapter appends to the end, so the list is only sorted if adapters are added in order of id:
// adapters/atspi-common/src/context.rs
pub(crate) fn adapter_index(&self, id: usize) -> Result<usize, usize> {
self.adapters.binary_search_by(|adapter| adapter.0.cmp(&id))
}
pub(crate) fn push_adapter(&mut self, id: usize, context: &Arc<Context>) {
self.adapters.push((id, Arc::clone(context)));
}
With accesskit_unix, an adapter is pushed when it goes from Pending to Active, which happens in the application's next update_if_active for that window after AT-SPI is enabled. With several windows, that is whatever order the application updates them in, not the order they were created, so the list can end up out of order (for example ids [1, 2, 0]). A binary search then misses an adapter that is in the list, and register_tree panics on
let adapter_index = app_context.adapter_index(self.id).unwrap();
while holding the app context's write lock. Unwinding drops the adapter, whose Drop calls write_app_context() on the now poisoned lock and panics again, so the process aborts:
panicked at accesskit_atspi_common-0.18.1/src/adapter.rs:461
panicked at accesskit_atspi_common-0.18.1/src/context.rs:85
panic in a destructor during cleanup
thread caused non-unwinding panic. aborting.
remove_adapter has the same problem in a quieter form: on an unsorted list it can fail to find the adapter and leave it in the list.
What should happen
Adapters can become active in any order without the lookup failing.
How to reproduce
We hit it in an application with several windows, each with an accesskit_winit adapter, on Ubuntu 26.04 (GNOME 50, Wayland and XWayland) with AT-SPI enabled, when the windows were updated in a different order than they were created. It depends on that order, so we don't have a small program that hits it every time; the lookup itself shows it. With the adapters pushed in the order 1, 2, 0:
let adapters: Vec<(usize, ())> = vec![(1, ()), (2, ()), (0, ())];
let found = adapters.binary_search_by(|adapter| adapter.0.cmp(&0));
println!("{found:?}"); // Err(0): adapter 0 is in the list but isn't found
Suggested fix
Keep the list sorted when adding:
pub(crate) fn push_adapter(&mut self, id: usize, context: &Arc<Context>) {
match self.adapter_index(id) {
Ok(index) => self.adapters[index] = (id, Arc::clone(context)),
Err(index) => self.adapters.insert(index, (id, Arc::clone(context))),
}
}
We're running with exactly this change (on 0.18.1, which egui 0.36 uses) and haven't seen the crash since. The code is the same on main (context.rs lines 109–115, adapter.rs line 463).
Versions: accesskit_atspi_common 0.18.1 through accesskit_unix 0.21.1 and accesskit_winit; also present in 0.21.0 and on main.
- 主要言語
- Rust
- スター
- 1.5k
- フォーク
- 122
- 平均マージ
- 10分
- マージ済み PR(30日)
- 16
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
AccessKit/accesskit のほかの issue
-
Document sub-treesオープン
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
メンテナーはふだん 1 日以内に返信
-
Unix cache signals lose their structure argument and are rejected by AT-SPI対応中かも @luccahuguet が今日担当しました。 オープン
難易度 3/5 半日 初心者へのやさしさ 18/100
AccessKit/accesskit#818 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 68/100
AccessKit/accesskit#802 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 5/5 1週間以上 初心者へのやさしさ 35/100
AccessKit/accesskit#778 · コメント 24 件 ·
メンテナーはふだん 1 日以内に返信
AccessKit/accesskit の issue をすべて見る
似ている issue
-
C-bug
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
rust-lang/rust-analyzer#23501 ·
メンテナーはふだん 1 日以内に返信
-
Streamable HTTP client: a 401 or 403 with a JSON-RPC error body and no WWW-Authenticate loses its HTTP status対応中かも このイシューにリンクされたプルリクエストがオープン中、またはマージ済みです。 オープンbug P2 ready for work T-security T-transport
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
modelcontextprotocol/rust-sdk#1339 ·
メンテナーはふだん 3 日以内に返信
-
French BIP39 wordlist starts with a UTF-8 BOM, so generated French mnemonics carry U+FEFF and derive a non-canonical seed対応中かも @Kshot3000 が今日担当しました。 オープン
難易度 1/5 1時間未満 初心者へのやさしさ 91/100
ergoplatform/sigma-rust#976 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
メンテナーはふだん 1 日以内に返信
-
[Bug]: Web chat input doesn't regain focus after a reply finishes対応中かも @GaijinSystems が今日担当しました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
zeroclaw-labs/zeroclaw#11658 ·
メンテナーはふだん 2 日以内に返信