Crash due to low Strict Transport Security Maximum Age
Maintainers usually reply within 1 day
@claucambra is already working on this.
Since Sep 28, 2026.
Assessment
This issue has not been assessed yet.
Description
This Nextcloud forum thread brought up a crash and helped to narrow down on the root cause which the client can handle better. The same kind of problem was already described in form of #8951.
Problem
The client turns on Qt's HSTS support with a saved on-disk store (OCC::AccessManager, since 3.17). Whenever the server sends a Strict-Transport-Security header, Qt caches a policy for that host that expires after max-age seconds. Before each request, Qt's QHstsCache::isKnownHost looks the host up. If the policy has expired, it removes the entry from its cache and then passes the entry it just removed to the store, reading memory that has already been freed. On macOS 13 and later, freed memory is zeroed, so this always crashes at address 0x8; on other systems the outcome depends on what is left in memory. The reporter's hoster sends max-age=5, so the cached policy expires five seconds after every response, and the client crashes on the first request after any five-second pause. That happens within the first minute of every launch. The bug has been in Qt since 2017 and is not fixed in any release, including dev.
Solution
The cleanest fix is a one-line change in Qt: move the addToObserved call in isKnownHost before the erase, so the store gets a copy while the entry is still valid. We'd ship it as a qtbase patch in our craft blueprints and also submit it upstream to Qt, which covers every place Qt calls that lookup. We shouldn't rely on the patch alone, because Linux distro builds use the system Qt. So the client should also clean up expired policies itself. In AccessManager::createRequest, just before handing the request to Qt, it collects the expired entries from strictTransportSecurityHosts() and passes them back through addStrictTransportSecurityHosts(). Qt removes them through a different code path without the bug, so the lookup that follows never meets an expired entry. That guard uses only public Qt API and worked in the standalone repro, but it doesn't cover the lookups Qt does internally (on redirects, for example), so it complements the Qt patch rather than replacing it. Both changes need a regression test: add a policy that expires almost immediately, wait, send a request, and check that the client doesn't crash and the entry is gone from both the cache and the store.
- Dominant language
- C++
- Stars
- 3.9k
- Forks
- 1k
- Avg merge
- 1d 5h
- Merged PRs (30d)
- 152
Getting set up
- No Dockerfile or Docker Compose file
- Has a pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from nextcloud/desktop
-
0. Needs triage bug
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day
-
Nextcloud Desktop 34.0.4 fails TestLocalDiscovery::testFileOpenedAsDirectoryCompletesDiscoveryJob()Open0. Needs triage bug
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
os: :penguin: Linux
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
nextcloud/desktop#10610 · 2 comments · 1 reaction ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
Maintainers usually reply within 1 day
-
Account flyout for unavailable servers adds duplicate buttons for each view until client restart.Open0. Needs triage bug
Difficulty 3/5 1-2 days Newbie friendliness 48/100
Maintainers usually reply within 1 day
All issues in nextcloud/desktop
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 92/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
cp-algorithms/cp-algorithms#1715 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Icinga/icinga2#11058 · 1 comment ·
Maintainers usually reply within 1 day
-
status:needs-triage
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
PX4/PX4-Autopilot#28924 ·
Maintainers usually reply within 1 day
-
component: split-view platform: windows
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
zen-browser/desktop#15616 · 1 reaction ·
Maintainers usually reply within 1 day