Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

HTTP: a code route can mutate the live route table and static root from a worker thread — unsynchronized writes racing every other worker's lookups

Đã đóng
#1,140 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

Chưa có ai nhận issue này.

Đánh giá

Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức phù hợp với người mới
48/100
Loại issue
Lỗi
Độ rõ ràng
Đặc tả rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
c

Hướng nghiên cứu

Start at http_conn_thread and the g_server/eigs_http_active handling, then inspect builtin_http_route, builtin_http_route_authed, builtin_http_static, and the existing serving guard used by http_response_header. Run tests/http_readiness.py and add the live mutation case described in the issue; done means mutation fails loudly, /injected remains 404, and the concurrent probe is race-free under the planned tsan-http lane.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

area:concurrency area:http bug

Observed (executed on main a18deac, make http)

A code route runs in a per-connection worker thread. The worker gets its own EigsState, but http_conn_thread then re-points the thread-local server accessor at the SPAWNING server so that handle_request reads the real route table:

/* register_http_builtins allocated a scratch Server on the worker state (so
 * http_route/http_serve called inside a code route don't crash) ... Re-point
 * at the spawning Server so handle_request reads the main route table. */
eigs_http_active = main_server;

The comment's intent (a scratch server absorbs config calls from a code route) is defeated two lines later: g_server is (*eigs_http_active), so http_route, http_route_authed and http_static invoked from a code route WRITE the main server's config while every other worker reads it lock-free.

Probe:

r is http_route of ["GET", "/", "page"]
c is http_route of ["GET", "/mutate", "code",
    "http_route of [\"GET\", \"/injected\", \"INJECTED\"]\nhttp_static of [\"/static\", \"/tmp\"]\n\"mutated\""]
http_serve of 24911
before: GET /injected -> 404
        GET /mutate   -> mutated
after:  GET /injected -> 200 INJECTED

One request permanently changed the routing table for the whole process.

Why it is a concurrency defect, not just a design oddity

  • builtin_http_route fills routes[route_count]'s four string fields, then does g_server.route_count++ — a plain non-atomic int with no release fence. A concurrent worker iterating for (i < route_count) can observe the incremented count before the slot's fields are visible and call strcmp on NULL/garbage.
  • builtin_http_static swaps static_prefix/static_dir under no lock while workers dereference them (the old strings are leaked rather than freed, so no UAF today — by accident).
  • The route_count >= MAX_ROUTES check is check-then-act across threads.
  • Exploitation needs a trusted code route that calls these builtins, so this is a correctness/robustness issue, not a remote hole — but it is a genuine data race in the runtime's most concurrent code, and it lives in the same file that #1137 just cleaned up.

Suggested fix

Freeze configuration at http_serve, the way http_response_header already does: builtin_http_route, builtin_http_route_authed and builtin_http_static check g_server.serving (under response_mu, or make it atomic) and raise a loud error once serving. Every lock-free read of routes/static config is then reading immutable data, which is the property the current code silently assumes.

Gate

  • tests/http_readiness.py: a live case with a code route that calls http_route/http_static — the request must fail loudly (500 with the error text) and /injected must remain 404 afterwards; plant: revert the freeze → red.
  • Once #1139 lands a tsan-http lane, a probe hammering /mutate and / concurrently should report the race on today's tree and be silent after the fix.

Found during the concurrency review that followed PR #1138 (2026-09-14). The rest of the file's threading — init responder, response builder, shared store, per-IP table, config caches — reviewed sound.

Ngôn ngữ chính
C
Star
3
Fork
7
Merge trung bình
5 giờ 38 phút
Pull request đã merge (30 ngày)
188

Chuẩn bị môi trường

Mở trong Codespaces

Khởi chạy dev container của dự án ngay trên trình duyệt, bằng tài khoản GitHub của bạn.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của InauguralSystems/EigenScript

Tất cả issue của InauguralSystems/EigenScript

Issue tương tự

Thêm issue về C

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.