http: fix parser double-free in _http_client.js
HTTP Parser instance was freed twice, leading to the reusal of it in several different requests simultaneously. The flow: `socketCloseListener` is firing, which calls `socket.read()` to flush any queued data, `socket.buffer` has data which emits and fires `socketOnData` in sync, this triggers a parser error which frees the parser, `socketCloseListener` resumes execution only to have the wrong parser associated with the socket. The fix is to only cache the parser after the flushing from the socket, and to assert in `socketOnData` that `socket === parser.socket` fix #6451
This commit is contained in:
parent
c749a841cd
commit
5ce4eed54d
@ -184,7 +184,6 @@ function createHangUpError() {
|
|||||||
|
|
||||||
function socketCloseListener() {
|
function socketCloseListener() {
|
||||||
var socket = this;
|
var socket = this;
|
||||||
var parser = socket.parser;
|
|
||||||
var req = socket._httpMessage;
|
var req = socket._httpMessage;
|
||||||
debug('HTTP socket close');
|
debug('HTTP socket close');
|
||||||
|
|
||||||
@ -193,6 +192,9 @@ function socketCloseListener() {
|
|||||||
// is a no-op if no final chunk remains.
|
// is a no-op if no final chunk remains.
|
||||||
socket.read();
|
socket.read();
|
||||||
|
|
||||||
|
// NOTE: Its important to get parser here, because it could be freed by
|
||||||
|
// the `socketOnData`.
|
||||||
|
var parser = socket.parser;
|
||||||
req.emit('close');
|
req.emit('close');
|
||||||
if (req.res && req.res.readable) {
|
if (req.res && req.res.readable) {
|
||||||
// Socket closed before we emitted 'end' below.
|
// Socket closed before we emitted 'end' below.
|
||||||
@ -267,7 +269,7 @@ function socketOnData(d) {
|
|||||||
var req = this._httpMessage;
|
var req = this._httpMessage;
|
||||||
var parser = this.parser;
|
var parser = this.parser;
|
||||||
|
|
||||||
assert(parser);
|
assert(parser && parser.socket === socket);
|
||||||
|
|
||||||
var ret = parser.execute(d);
|
var ret = parser.execute(d);
|
||||||
if (ret instanceof Error) {
|
if (ret instanceof Error) {
|
||||||
|
61
test/simple/test-http-client-parser-double-free.js
Normal file
61
test/simple/test-http-client-parser-double-free.js
Normal file
@ -0,0 +1,61 @@
|
|||||||
|
// Copyright Joyent, Inc. and other Node contributors.
|
||||||
|
//
|
||||||
|
// Permission is hereby granted, free of charge, to any person obtaining a
|
||||||
|
// copy of this software and associated documentation files (the
|
||||||
|
// "Software"), to deal in the Software without restriction, including
|
||||||
|
// without limitation the rights to use, copy, modify, merge, publish,
|
||||||
|
// distribute, sublicense, and/or sell copies of the Software, and to permit
|
||||||
|
// persons to whom the Software is furnished to do so, subject to the
|
||||||
|
// following conditions:
|
||||||
|
//
|
||||||
|
// The above copyright notice and this permission notice shall be included
|
||||||
|
// in all copies or substantial portions of the Software.
|
||||||
|
//
|
||||||
|
// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
|
||||||
|
// OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
|
||||||
|
// MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN
|
||||||
|
// NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM,
|
||||||
|
// DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR
|
||||||
|
// OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE
|
||||||
|
// USE OR OTHER DEALINGS IN THE SOFTWARE.
|
||||||
|
|
||||||
|
var common = require('../common');
|
||||||
|
var assert = require('assert');
|
||||||
|
var http = require('http');
|
||||||
|
var http_common = require('_http_common');
|
||||||
|
|
||||||
|
var receivedError = 0;
|
||||||
|
var receivedClose = 0;
|
||||||
|
|
||||||
|
var buf = new Buffer(64 * 1024);
|
||||||
|
buf.fill('A');
|
||||||
|
|
||||||
|
var server = http.createServer(function(req, res) {
|
||||||
|
res.write(buf, function() {
|
||||||
|
res.socket.write(buf);
|
||||||
|
res.end(function() {
|
||||||
|
req.socket.destroy();
|
||||||
|
server.close();
|
||||||
|
});
|
||||||
|
});
|
||||||
|
}).listen(common.PORT, function() {
|
||||||
|
var req = http.request({ port: common.PORT, agent: false }, function(res) {
|
||||||
|
res.once('readable', function() {
|
||||||
|
/* read only one buffer */
|
||||||
|
res.read(1);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
req.end();
|
||||||
|
req.on('close', function() {
|
||||||
|
receivedClose++;
|
||||||
|
});
|
||||||
|
req.on('error', function() {
|
||||||
|
receivedError++;
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
process.on('exit', function() {
|
||||||
|
assert.equal(receivedError, 1);
|
||||||
|
assert.equal(receivedClose, 1);
|
||||||
|
assert.equal(http_common.parsers.list.length, 2);
|
||||||
|
});
|
Loading…
x
Reference in New Issue
Block a user