⚠ Archived content — this site is no longer maintained.   Current WebKit documentation is at docs.webkit.org.

Changeset 294361 in webkit


Ignore:
Timestamp:
May 17, 2022, 4:23:29 PM (4 years ago)
Author:
Patrick Angle
Message:

[Cocoa] Web Driver: RemoteAutomationTargets marked for termination and targets that have never been paired may briefly be indistinguishable in application target listing
​https://bugs.webkit.org/show_bug.cgi?id=240524
<rdar://93430106>

Reviewed by BJ Burg and Devin Rousso.

A RemoteAutomationTarget has multiple possible entries it may provide in an application listing to webinspectord,
which are then interpreted by webinspectord to determine the current state of that target. The key pieces for this bug
are that a WIRConnectionIdentifierKey which when present is taken to mean that the target is no longer pristine and
WIRAutomationTargetIsPairedKey which when true indicates that the target is paired. When a connection identifier is
present and we are no longer paired, the connection is considered terminated.

There exists a race condition where webinspectord preemptively set the targets state to "Terminated" upon sending a
close request in order to make sure that the target is no longer used. Upon receiving the close message for the target
the connection identifier is removed from the map of known connection identifiers before scheduling the actual target to
be torn down asyncronously. In most cases this works fine, but sometimes an application listing is created and sent
between removing the identifier from the map of known connections and actually tearing down the target, and that is
where this issue occurs. We will in that case send a listing for the automation target with no connection identifier
(since we removed it from the map already), which is then interpreted as a listing for a pristine automation target. At
that point, it is possible that automation sessions that are being rapidly created and destroyed will attempt to pair
with the seemingly pristine existing session, even though that session is about to be torn down.

  • Source/JavaScriptCore/inspector/remote/RemoteAutomationTarget.h:
  • Source/JavaScriptCore/inspector/remote/cocoa/RemoteConnectionToTargetCocoa.mm:

(Inspector::RemoteConnectionToTarget::close):

  • Source/JavaScriptCore/inspector/remote/cocoa/RemoteInspectorCocoa.mm:

(Inspector::RemoteInspector::listingForAutomationTarget const):

Canonical link: ​https://commits.webkit.org/250664@main

Location:
trunk/Source/JavaScriptCore/inspector/remote
Files:
3 edited

Legend:

Unmodified
Added
Removed
  • trunk/Source/JavaScriptCore/inspector/remote/RemoteAutomationTarget.h

    r250996 r294361  
    4242    void setIsPaired(bool);
    4343
     44    bool isPendingTermination() const { return m_pendingTermination; }
     45    void setIsPendingTermination() { m_pendingTermination = true; }
     46
    4447    virtual String name() const = 0;
    4548    RemoteControllableTarget::Type type() const override { return RemoteControllableTarget::Type::Automation; }
    … …  
    4851private:
    4952    bool m_paired { false };
     53    bool m_pendingTermination { false };
    5054};
    5155
  • trunk/Source/JavaScriptCore/inspector/remote/cocoa/RemoteConnectionToTargetCocoa.mm

    r282755 r294361  
    199199{
    200200    auto targetIdentifier = m_target ? m_target->targetIdentifier() : 0;
     201
     202    if (auto* automationTarget = dynamicDowncast<RemoteAutomationTarget>(m_target))
     203        automationTarget->setIsPendingTermination();
    201204   
    202205    dispatchAsyncOnTarget([this, targetIdentifier, strongThis = Ref { *this }]() {
  • trunk/Source/JavaScriptCore/inspector/remote/cocoa/RemoteInspectorCocoa.mm

    r290510 r294361  
    467467    ASSERT(isMainThread());
    468468
     469    if (target.isPendingTermination())
     470        return nullptr;
     471
    469472    RetainPtr<NSMutableDictionary> listing = adoptNS([[NSMutableDictionary alloc] init]);
    470473    [listing setObject:@(target.targetIdentifier()) forKey:WIRTargetIdentifierKey];
Note: See TracChangeset for help on using the changeset viewer.