Skip to content

Bug: Fix Logx Concurrent Map Mutation in Context Field Propagation - #2066

Merged
adelowo merged 2 commits into
mainfrom
feat-vulns
Feb 25, 2026
Merged

Bug: Fix Logx Concurrent Map Mutation in Context Field Propagation#2066
adelowo merged 2 commits into
mainfrom
feat-vulns

Conversation

@matoszz

@matoszz matoszz commented Feb 25, 2026

Copy link
Copy Markdown
Member

Addresses a production panic (fatal error: concurrent map iteration and map write) surfaced by Trust Center event listener activity.

Root cause: logx.WithField and logx.WithFields mutated the LogFields map in-place rather than allocating a new copy. Every context derived from the same request shared the same underlying map.

The race: after a transaction commits, emit() closures fire per mutation and submit work to the in-memory gala pool. The committing goroutine calls DurableContextCodec.Capture → json.Marshal on a snapshot holding a direct reference to the shared LogFields map (iterating it). Concurrently, pool workers processing previously dispatched envelopes call DurableContextCodec.Restore → logx.WithFields → writing to that same map.

Fix: WithField and WithFields now allocate a new map on each call. DurableContextCodec.Capture additionally clones the fields map before marshaling as a defensive measure.

@matoszz
matoszz requested a review from a team as a code owner February 25, 2026 15:59
@github-actions github-actions Bot added the enhancement New feature or request label Feb 25, 2026
@adelowo
adelowo enabled auto-merge (squash) February 25, 2026 16:09
@sonarqubecloud

Copy link
Copy Markdown

@adelowo
adelowo merged commit 0426de5 into main Feb 25, 2026
17 checks passed
@adelowo
adelowo deleted the feat-vulns branch February 25, 2026 16:21
Achiket123 pushed a commit to Achiket123/core that referenced this pull request Feb 28, 2026
golanglemonade added a commit that referenced this pull request Mar 17, 2026
* Specs for exporting

* fix(deps): update all patch dependencies (#2037)

* fix(deps): update all patch dependencies

* fix entity status

Signed-off-by: Sarah Funkhouser <147884153+golanglemonade@users.noreply.github.com>

---------

Signed-off-by: Sarah Funkhouser <147884153+golanglemonade@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Sarah Funkhouser <147884153+golanglemonade@users.noreply.github.com>

* Directory + Integration + Identity Holder Schema Relationships + Refs (#2061)

* uplift directory account schemas, fga, integration refs

* generate output

* Bug: Fix Logx Concurrent Map Mutation in Context Field Propagation (#2066)

* fix ts bug and logx wrapper

* add a unit test

* fix(deps): update all patch dependencies (#2064)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* fix(deps): update module github.com/alicebob/miniredis/v2 to v2.37.0 (#2065)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* debug: adding logs for cf trigger cache (#2067)

Signed-off-by: Sarah Funkhouser <147884153+golanglemonade@users.noreply.github.com>

* Fix EventQueue `ClientFromHandler` to Inject ent client | Enrich River Job submission with Listener Info (#2070)

* fix client injection / context return with ent client and add metadata and tags to river

* add listener name and some other metadata

* Notification from standards updates (#2072)

* control diffing after a standard revision is bumped

* extend tests

* task regenerate

* use ctx

* Bulk evidence export (#2074)

* task regenerate

* add mode and metadata to export job spec

* fix merge conflicts

* update task cli:generate:enum template

* use enqueue

* fix(deps): update all patch dependencies (#2068)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* chore(deps): update anchore/sbom-action action to v0.23.0 (#2071)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* Shuffle Integration Record Creation | Confirm Credentials Pre-store (#2075)

* add normalization to prevent failures (#2078)

* OSCAL Support Mapping + entx plugin (#2077)

* schema updates / additions, prep for generation

* rename to something that's going to play nice with pluralization

* with policy and annotations

* add the schema migrations and output of new plugin and annotations, fields

* remove bad mixin ref

* Update internal/ent/schema/systemdetail.go

Co-authored-by: Sarah Funkhouser <147884153+golanglemonade@users.noreply.github.com>
Signed-off-by: Matt Anderson <42154938+matoszz@users.noreply.github.com>

---------

Signed-off-by: Matt Anderson <42154938+matoszz@users.noreply.github.com>
Co-authored-by: Sarah Funkhouser <147884153+golanglemonade@users.noreply.github.com>

* fix: allow comments to be added / removed by member users (#2079)

* fix: allow comments to be added / removed by member users

Signed-off-by: Sarah Funkhouser <147884153+golanglemonade@users.noreply.github.com>

* regen

Signed-off-by: Sarah Funkhouser <147884153+golanglemonade@users.noreply.github.com>

* fix: slate parse, test

Signed-off-by: Sarah Funkhouser <147884153+golanglemonade@users.noreply.github.com>

* fix test

Signed-off-by: Sarah Funkhouser <147884153+golanglemonade@users.noreply.github.com>

* remove logs from testing

Signed-off-by: Sarah Funkhouser <147884153+golanglemonade@users.noreply.github.com>

---------

Signed-off-by: Sarah Funkhouser <147884153+golanglemonade@users.noreply.github.com>

* add identity holder crud tests (#2082)

* export db migration (#2083)

* fix(deps): update all patch dependencies (#2076)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* fix(deps): update module github.com/cloudflare/cloudflare-go/v6 to v6.8.0 (#2081)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* fix(deps): update module github.com/aws/aws-sdk-go-v2/service/securityhub to v1.68.0 (#2073)

Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

* best swing at mapx as ill get (#2084)

* Specs for exporting

* Some More Fixes

* Remove duplicate ExportExportMode enum from schema.graphql

Removed duplicate ExportExportMode enum definition from schema.

Signed-off-by: Achiket Kumar <126181868+Achiket123@users.noreply.github.com>

* Delete duplicare ExportExportMode enum from ent.graphql

Removed duplicare ExportExportMode enum definition from schema.

Signed-off-by: Achiket Kumar <126181868+Achiket123@users.noreply.github.com>

* fix:generate errors

* Update internal/objects/validators/mime.go

Co-authored-by: Sarah Funkhouser <147884153+golanglemonade@users.noreply.github.com>
Signed-off-by: Achiket Kumar <126181868+Achiket123@users.noreply.github.com>

* Update exportFiles MIME types to include application/zip

Signed-off-by: Achiket Kumar <126181868+Achiket123@users.noreply.github.com>

* Add PDF and Markdown types to exportFiles

Signed-off-by: Achiket Kumar <126181868+Achiket123@users.noreply.github.com>

* Refactor validMimeTypes for formatting

Signed-off-by: Achiket Kumar <126181868+Achiket123@users.noreply.github.com>

* Add 'application/zip' to exportFiles MIME types

Signed-off-by: Achiket Kumar <126181868+Achiket123@users.noreply.github.com>

---------

Signed-off-by: Sarah Funkhouser <147884153+golanglemonade@users.noreply.github.com>
Signed-off-by: Matt Anderson <42154938+matoszz@users.noreply.github.com>
Signed-off-by: Achiket Kumar <126181868+Achiket123@users.noreply.github.com>
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Sarah Funkhouser <147884153+golanglemonade@users.noreply.github.com>
Co-authored-by: Matt Anderson <42154938+matoszz@users.noreply.github.com>
Co-authored-by: Lanre Adelowo <yo@lanre.wtf>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants