Skip to content

Fix use-after-free from non-idempotent SmcCloseConnection on X11 - #22190

Merged
MrJul merged 1 commit into
AvaloniaUI:mainfrom
hartmark:fix/x11-smc-close-use-after-free
Sep 8, 2026
Merged

MrJul merged 1 commit into
AvaloniaUI:mainfrom
hartmark:fix/x11-smc-close-use-after-free

Conversation

@hartmark

@hartmark hartmark commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Fixes #22188.

_currentSmcConn is readonly, so the IntPtr.Zero guard in Dispose() never fires after a successful connect — but SmcCloseConnection frees both the SmcConn and its IceConn. Dispose() is reachable from the Die callback, from HandleRequests() on IceProcessMessagesIoError, and from platform teardown, and it never cancelled _cancellationTokenSource, so the pump kept calling IceProcessMessages on the freed IceConn and re-entered Dispose() on every iteration. Losing the ICE connection therefore ends in a use-after-free rather than in a narrow race.

Dispose() now claims the handle once with Interlocked.Exchange and cancels the pump before closing. Core dump analysis is in #22188.


Code written by Claude (Claude Code); reviewed and verified by @hartmark, who will respond to review comments. The equivalent change is currently running hot-patched into JetBrains Rider's bundled Avalonia 11.3.11 on the affected machine.

🤖 Generated with Claude Code

X11PlatformLifetimeEvents.Dispose() could close the same session-management
connection more than once. Claim the handle with Interlocked.Exchange and
cancel the ICE pump before closing, so it runs exactly once.

Fixes AvaloniaUI#22188

Co-Authored-By: Claude Opus 5 
@MrJul MrJul added bug area-x11 backport-candidate-11.3.x Consider this PR for backporting to 11.3 branch backport-candidate-12.1.x Consider this PR for backporting to 12.1 branch labels Sep 8, 2026
@avaloniaui-bot

Copy link
Copy Markdown

You can test this PR using the following package version. 12.2.999-cibuild0069624-alpha. (feed url: https://nuget-feed-all.avaloniaui.net/v3/index.json) [PRBUILDID]

@cla-avalonia

cla-avalonia commented Sep 8, 2026 •

Copy link
Copy Markdown
Collaborator
  • All contributors have signed the CLA.

@hartmark

hartmark commented Sep 8, 2026

Copy link
Copy Markdown
Contributor Author

@cla-avalonia agree

@MrJul MrJul left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch, thank you! LGTM

@MrJul
MrJul enabled auto-merge September 8, 2026 15:04
@MrJul
MrJul added this pull request to the merge queue Sep 8, 2026
Merged via the queue into AvaloniaUI:main with commit c6a9d34 Sep 8, 2026
10 checks passed
MrJul pushed a commit that referenced this pull request Sep 11, 2026
)

X11PlatformLifetimeEvents.Dispose() could close the same session-management
connection more than once. Claim the handle with Interlocked.Exchange and
cancel the ICE pump before closing, so it runs exactly once.

Fixes #22188

Co-authored-by: Claude Opus 5 
@MrJul MrJul added backported-11.3.x and removed backport-candidate-11.3.x Consider this PR for backporting to 11.3 branch labels Sep 11, 2026
MrJul pushed a commit to MrJul/Avalonia that referenced this pull request Sep 22, 2026
…loniaUI#22190)

X11PlatformLifetimeEvents.Dispose() could close the same session-management
connection more than once. Claim the handle with Interlocked.Exchange and
cancel the ICE pump before closing, so it runs exactly once.

Fixes AvaloniaUI#22188

Co-authored-by: Claude Opus 5 
@MrJul MrJul added backported-12.1.x and removed backport-candidate-12.1.x Consider this PR for backporting to 12.1 branch labels Sep 22, 2026
@coffeemuse coffeemuse mentioned this pull request Sep 23, 2026
1 of 6 tasks
grokys pushed a commit to Evan260/Avalonia that referenced this pull request Oct 7, 2026
…loniaUI#22190)

X11PlatformLifetimeEvents.Dispose() could close the same session-management
connection more than once. Claim the handle with Interlocked.Exchange and
cancel the ICE pump before closing, so it runs exactly once.

Fixes AvaloniaUI#22188

Co-authored-by: Claude Opus 5 
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

X11: use-after-free from non-idempotent SmcCloseConnection in X11PlatformLifetimeEvents

4 participants