Skip to content

Fix name lookup in PerformanceEntryReporter (use-after-free)#43646

Closed
tnovak wants to merge 1 commit into
facebook:mainfrom
tnovak:export-D55273403
Closed

Fix name lookup in PerformanceEntryReporter (use-after-free)#43646
tnovak wants to merge 1 commit into
facebook:mainfrom
tnovak:export-D55273403

Conversation

@tnovak

@tnovak tnovak commented Mar 25, 2024

Copy link
Copy Markdown
Contributor

Summary:
PerformanceEntryReporter maintains a buffer of RawPerformanceEntry objects,
as well as a set of pointers to elements within that buffer, used to find
entries by name.

However, those pointers aren't stable: BoundedConsumableBuffer internally uses
a vector, and there are a few cases where existing references get invalidated:

  • When the vector's capacity changes (as new entries get inserted) [1]
  • After calling clear-with-predicate, which copies elements into a new vector

This causes nameLookup to contain dangling pointers, and subsequent operations
on it can result in use-after-free.

Fix this by having BoundedConsumableBuffer reserve space for maxSize entries
up front (which ensures that existing pointers remain valid after adding new
elements) and by rebuilding nameLookup after clearing entries by name.

Note that reserve() causes the buffer's memory use to be higher than before in
case where the number of elements is small relative to the max size. Given the
(only) existing usage in PerformanceEntryReporter, as well as the property that
consumed elements remain in the buffer, that cost should be minor.

Changelog: [Internal]

[1] https://en.cppreference.com/w/cpp/container/vector/push_back

Reviewed By: rshest

Differential Revision: D55273403

Summary:
PerformanceEntryReporter maintains a buffer of RawPerformanceEntry objects,
as well as a set of _pointers_ to elements within that buffer, used to find
entries by name.

However, those pointers aren't stable: BoundedConsumableBuffer internally uses
a vector, and there are a few cases where existing references get invalidated:

- When the vector's capacity changes (as new entries get inserted) [1]
- After calling clear-with-predicate, which copies elements into a new vector

This causes nameLookup to contain dangling pointers, and subsequent operations
on it can result in use-after-free.

Fix this by having BoundedConsumableBuffer reserve space for maxSize entries
up front (which ensures that existing pointers remain valid after adding new
elements) and by rebuilding nameLookup after clearing entries by name.

Note that reserve() causes the buffer's memory use to be higher than before in
case where the number of elements is small relative to the max size. Given the
(only) existing usage in PerformanceEntryReporter, as well as the property that
consumed elements remain in the buffer, that cost should be minor.

Changelog: [Internal]

[1] https://en.cppreference.com/w/cpp/container/vector/push_back

Reviewed By: rshest

Differential Revision: D55273403
@facebook-github-bot facebook-github-bot added the CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. label Mar 25, 2024
@facebook-github-bot

Copy link
Copy Markdown
Contributor

This pull request was exported from Phabricator. Differential Revision: D55273403

@analysis-bot

Copy link
Copy Markdown
Platform Engine Arch Size (bytes) Diff
android hermes arm64-v8a 18,450,651 -15
android hermes armeabi-v7a n/a --
android hermes x86 n/a --
android hermes x86_64 n/a --
android jsc arm64-v8a 21,815,632 -16
android jsc armeabi-v7a n/a --
android jsc x86 n/a --
android jsc x86_64 n/a --

Base commit: ac714b1
Branch: main

@facebook-github-bot facebook-github-bot added the Merged This PR has been merged. label Mar 26, 2024
@facebook-github-bot

Copy link
Copy Markdown
Contributor

This pull request has been merged in 5ea9471.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA Signed This label is managed by the Facebook bot. Authors need to sign the CLA before a PR can be reviewed. fb-exported Merged This PR has been merged. p: Facebook Partner: Facebook Partner

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants