Repository navigation
Fix use-after-free from non-idempotent SmcCloseConnection on X11 - #22190
Merged
Merged
Conversation
X11PlatformLifetimeEvents.Dispose() could close the same session-management connection more than once. Claim the handle with Interlocked.Exchange and cancel the ICE pump before closing, so it runs exactly once. Fixes AvaloniaUI#22188 Co-Authored-By: Claude Opus 5
|
You can test this PR using the following package version. |
Collaborator
|
Contributor
Author
|
@cla-avalonia agree |
MrJul
enabled auto-merge
September 8, 2026 15:04
MrJul
pushed a commit
that referenced
this pull request
Sep 11, 2026
) X11PlatformLifetimeEvents.Dispose() could close the same session-management connection more than once. Claim the handle with Interlocked.Exchange and cancel the ICE pump before closing, so it runs exactly once. Fixes #22188 Co-authored-by: Claude Opus 5
MrJul
pushed a commit
to MrJul/Avalonia
that referenced
this pull request
Sep 22, 2026
…loniaUI#22190) X11PlatformLifetimeEvents.Dispose() could close the same session-management connection more than once. Claim the handle with Interlocked.Exchange and cancel the ICE pump before closing, so it runs exactly once. Fixes AvaloniaUI#22188 Co-authored-by: Claude Opus 5
1 of 6 tasks
grokys
pushed a commit
to Evan260/Avalonia
that referenced
this pull request
Oct 7, 2026
…loniaUI#22190) X11PlatformLifetimeEvents.Dispose() could close the same session-management connection more than once. Claim the handle with Interlocked.Exchange and cancel the ICE pump before closing, so it runs exactly once. Fixes AvaloniaUI#22188 Co-authored-by: Claude Opus 5
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #22188.
_currentSmcConnisreadonly, so theIntPtr.Zeroguard inDispose()never fires after a successful connect — butSmcCloseConnectionfrees both theSmcConnand itsIceConn.Dispose()is reachable from theDiecallback, fromHandleRequests()onIceProcessMessagesIoError, and from platform teardown, and it never cancelled_cancellationTokenSource, so the pump kept callingIceProcessMessageson the freedIceConnand re-enteredDispose()on every iteration. Losing the ICE connection therefore ends in a use-after-free rather than in a narrow race.Dispose()now claims the handle once withInterlocked.Exchangeand cancels the pump before closing. Core dump analysis is in #22188.Code written by Claude (Claude Code); reviewed and verified by @hartmark, who will respond to review comments. The equivalent change is currently running hot-patched into JetBrains Rider's bundled Avalonia 11.3.11 on the affected machine.
🤖 Generated with Claude Code