Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

UrlLib: Apple backend use-after-free when a UrlRequest is destroyed in flight

未关闭
#214 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
52/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
冷清
技术栈
cpp

调研方向

从 UrlRequest_Apple.mm 中的 Impl::SendAsync() 开始,然后跟踪 ImplBase::~ImplBase() 和 Abort(),以了解现有的取消路径。运行针对已放弃的进行中请求的受影响 UrlLib CI 覆盖测试。完成的标准是:销毁请求不能让 Apple 任务访问已释放的状态,取消操作得到遵守,并且相关后端行为得到覆盖。

由索引模型根据 Issue 内容生成。

描述

Split out from review feedback on BabylonJS/UrlLib#37 (filed here because BabylonJS/UrlLib has Issues disabled).

Problem

On the Apple (NSURLSession) backend, an in-flight UrlRequest that is destroyed before it settles leads to a use-after-free.

UrlRequest_Apple.mm's SendAsync() builds a completion handler that writes m_statusCode, m_headers, m_responseString / m_responseBuffer and calls SetError(...) — so it implicitly captures a raw this. Nothing keeps the Impl alive for the duration of the task:

  • UrlRequest::Impl there has no destructor.
  • It never reads m_cancellationSource.
  • It never calls [task cancel].

ImplBase::~ImplBase() calls Abort(), but Abort() only does m_cancellationSource.cancel(), which this backend ignores. So destroying a UrlRequest neither stops the resumed NSURLSessionDataTask nor extends the impl's lifetime — the task keeps running and its handler later writes into freed memory.

Impact

Any caller that drops a UrlRequest before it completes (e.g. abandoning a request on teardown) can corrupt whatever the freed allocation is reused for. This is not theoretical: it was observed in UrlLib CI, where an abandoned request's late failure handler wrote its error into a subsequent test's Impl, making an unrelated, previously-passing test report NSURLErrorCancelled (-999) with a non-empty ErrorString/ErrorSymbol.

Notes

  • Pre-existing; not introduced by #37. That PR's new test was simply the first code to exercise it, and now works around it by waiting for the request to settle before leaving scope.
  • Worth auditing the other backends for the same pattern.

Possible fixes

  • Have Impl inherit std::enable_shared_from_this and capture a strong reference in the completion handler, so the impl outlives the task.
  • And/or make Abort() actually cancel the NSURLSessionDataTask on this backend, honoring m_cancellationSource.
主要语言
C++
星标
22
派生
23
平均合并
4 天 8 小时
30 天内合并 PR
3

环境准备

  • 没有 Dockerfile 或 Docker Compose 文件
  • 没有 Pull Request 模板
  • 阅读贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

BabylonJS/JsRuntimeHost 的其他 Issue

查看 BabylonJS/JsRuntimeHost 的全部 Issue

相似的 Issue

更多 C++ Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。