HTTP: a code route can mutate the live route table and static root from a worker thread — unsynchronized writes racing every other worker's lookups
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 48/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Đặc tả rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- c
- Lĩnh vực
- backend-api-design, networking, testing-qa
Hướng nghiên cứu
Start at http_conn_thread and the g_server/eigs_http_active handling, then inspect builtin_http_route, builtin_http_route_authed, builtin_http_static, and the existing serving guard used by http_response_header. Run tests/http_readiness.py and add the live mutation case described in the issue; done means mutation fails loudly, /injected remains 404, and the concurrent probe is race-free under the planned tsan-http lane.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Observed (executed on main a18deac, make http)
A code route runs in a per-connection worker thread. The worker gets its own EigsState, but http_conn_thread then re-points the thread-local server accessor at the SPAWNING server so that handle_request reads the real route table:
/* register_http_builtins allocated a scratch Server on the worker state (so
* http_route/http_serve called inside a code route don't crash) ... Re-point
* at the spawning Server so handle_request reads the main route table. */
eigs_http_active = main_server;
The comment's intent (a scratch server absorbs config calls from a code route) is defeated two lines later: g_server is (*eigs_http_active), so http_route, http_route_authed and http_static invoked from a code route WRITE the main server's config while every other worker reads it lock-free.
Probe:
r is http_route of ["GET", "/", "page"]
c is http_route of ["GET", "/mutate", "code",
"http_route of [\"GET\", \"/injected\", \"INJECTED\"]\nhttp_static of [\"/static\", \"/tmp\"]\n\"mutated\""]
http_serve of 24911
before: GET /injected -> 404
GET /mutate -> mutated
after: GET /injected -> 200 INJECTED
One request permanently changed the routing table for the whole process.
Why it is a concurrency defect, not just a design oddity
builtin_http_routefillsroutes[route_count]'s four string fields, then doesg_server.route_count++— a plain non-atomic int with no release fence. A concurrent worker iteratingfor (i < route_count)can observe the incremented count before the slot's fields are visible and callstrcmpon NULL/garbage.builtin_http_staticswapsstatic_prefix/static_dirunder no lock while workers dereference them (the old strings are leaked rather than freed, so no UAF today — by accident).- The
route_count >= MAX_ROUTEScheck is check-then-act across threads. - Exploitation needs a trusted code route that calls these builtins, so this is a correctness/robustness issue, not a remote hole — but it is a genuine data race in the runtime's most concurrent code, and it lives in the same file that #1137 just cleaned up.
Suggested fix
Freeze configuration at http_serve, the way http_response_header already does: builtin_http_route, builtin_http_route_authed and builtin_http_static check g_server.serving (under response_mu, or make it atomic) and raise a loud error once serving. Every lock-free read of routes/static config is then reading immutable data, which is the property the current code silently assumes.
Gate
tests/http_readiness.py: a live case with a code route that callshttp_route/http_static— the request must fail loudly (500 with the error text) and/injectedmust remain 404 afterwards; plant: revert the freeze → red.- Once #1139 lands a
tsan-httplane, a probe hammering/mutateand/concurrently should report the race on today's tree and be silent after the fix.
Found during the concurrency review that followed PR #1138 (2026-09-14). The rest of the file's threading — init responder, response builder, shared store, per-IP table, config caches — reviewed sound.
- Ngôn ngữ chính
- C
- Star
- 3
- Fork
- 7
- Merge trung bình
- 5 giờ 38 phút
- Pull request đã merge (30 ngày)
- 188
Chuẩn bị môi trường
Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.
- Có Dockerfile hoặc tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của InauguralSystems/EigenScript
-
area:docs kind:docs-drift
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 92/100
InauguralSystems/EigenScript#1428 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area:docs good first issue kind:docs-drift
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 90/100
InauguralSystems/EigenScript#1396 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
docs/BUILTINS.md: task_spawn row says task_yield/task_join 'land in a later increment'; both existĐang mởarea:docs good first issue kind:docs-drift
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
InauguralSystems/EigenScript#1392 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Error carets pad multi-byte UTF-8 byte-for-byte, so the ^ lands right of the token on a terminalĐang mởarea:lint-tooling kind:silent-wrong
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
InauguralSystems/EigenScript#1373 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area:docs good first issue kind:docs-drift
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
InauguralSystems/EigenScript#1277 · 4 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của InauguralSystems/EigenScript
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 88/100
BasedHardware/omi#20271 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
area/ysql kind/bug priority/medium
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
yugabyte/yugabyte-db#34552 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
flux-framework/flux-coral2#509 ·
-
documentation
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 92/100
github/copilot-sdk#2804 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Update dbus dependency to ^0.8.0Đang mở
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 82/100
MixinNetwork/flutter-plugins#507 ·