UrlLib: Apple backend use-after-free when a UrlRequest is destroyed in flight
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 52/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 冷清
- 技术栈
- cpp
- 领域
- backend, networking
调研方向
从 UrlRequest_Apple.mm 中的 Impl::SendAsync() 开始,然后跟踪 ImplBase::~ImplBase() 和 Abort(),以了解现有的取消路径。运行针对已放弃的进行中请求的受影响 UrlLib CI 覆盖测试。完成的标准是:销毁请求不能让 Apple 任务访问已释放的状态,取消操作得到遵守,并且相关后端行为得到覆盖。
由索引模型根据 Issue 内容生成。
描述
Split out from review feedback on BabylonJS/UrlLib#37 (filed here because BabylonJS/UrlLib has Issues disabled).
Problem
On the Apple (NSURLSession) backend, an in-flight UrlRequest that is destroyed before it settles leads to a use-after-free.
UrlRequest_Apple.mm's SendAsync() builds a completion handler that writes m_statusCode, m_headers, m_responseString / m_responseBuffer and calls SetError(...) — so it implicitly captures a raw this. Nothing keeps the Impl alive for the duration of the task:
UrlRequest::Implthere has no destructor.- It never reads
m_cancellationSource. - It never calls
[task cancel].
ImplBase::~ImplBase() calls Abort(), but Abort() only does m_cancellationSource.cancel(), which this backend ignores. So destroying a UrlRequest neither stops the resumed NSURLSessionDataTask nor extends the impl's lifetime — the task keeps running and its handler later writes into freed memory.
Impact
Any caller that drops a UrlRequest before it completes (e.g. abandoning a request on teardown) can corrupt whatever the freed allocation is reused for. This is not theoretical: it was observed in UrlLib CI, where an abandoned request's late failure handler wrote its error into a subsequent test's Impl, making an unrelated, previously-passing test report NSURLErrorCancelled (-999) with a non-empty ErrorString/ErrorSymbol.
Notes
- Pre-existing; not introduced by #37. That PR's new test was simply the first code to exercise it, and now works around it by waiting for the request to settle before leaving scope.
- Worth auditing the other backends for the same pattern.
Possible fixes
- Have
Implinheritstd::enable_shared_from_thisand capture a strong reference in the completion handler, so the impl outlives the task. - And/or make
Abort()actually cancel theNSURLSessionDataTaskon this backend, honoringm_cancellationSource.
- 主要语言
- C++
- 星标
- 22
- 派生
- 23
- 平均合并
- 4 天 8 小时
- 30 天内合并 PR
- 3
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
BabylonJS/JsRuntimeHost 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 84/100
BabylonJS/JsRuntimeHost#234 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 82/100
BabylonJS/JsRuntimeHost#173 ·
维护者通常 1 天内回复
-
难度 4/5 3-5 天 新手友好度 42/100
BabylonJS/JsRuntimeHost#241 · 3 条评论 ·
维护者通常 1 天内回复
-
难度 5/5 一周以上 新手友好度 35/100
BabylonJS/JsRuntimeHost#228 ·
维护者通常 1 天内回复
-
napi_unwrap does not reject objects that were never wrapped (V8 port faults, QuickJS port confuses types)可能已有人在做 关联的 PR 仍在进行中或已合并。 未关闭
难度 4/5 3-5 天 新手友好度 68/100
BabylonJS/JsRuntimeHost#226 ·
维护者通常 1 天内回复
查看 BabylonJS/JsRuntimeHost 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 68/100
维护者通常 1 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 73/100
EchoTools/nevr-runtime#116 ·
维护者通常 1 天内回复
-
code-quality libc++
难度 1/5 1 小时以内 新手友好度 82/100
llvm/llvm-project#229284 ·
维护者通常 1 天内回复
-
test-issue
难度 2/5 1-3 小时 新手友好度 82/100
llvm/offload-test-suite#1557 ·
维护者通常 1 天内回复
-
enhancement
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复