WM: Fix invalid memory access in wmTimer handling code. #105380

Merged
Bastien Montagne merged 1 commits from mont29/blender:F-wmtimer-fix into blender-v3.5-release 2023-03-03 15:24:37 +01:00

Timer management code often loops over the list of timers, calling
independant callbacks that end up freeing other timers in the list. That
would result in potentail access-after-free errors, as reported in #105160.

The typical identified scenario is wmTimer calling wmJob code, which
calls some of the job's callbacks (update or end e.g.), which call
WM_report, which removes and add another timer.

To address this issue on a general level, the deletion of timers is now
deferred, with the public API WM_event_remove_timer only marking the
timer for deletion, and the private new function
wm_window_delete_removed_timers effectively removing and deleting all
marked timers.

This implements design task #105369.

Timer management code often loops over the list of timers, calling independant callbacks that end up freeing other timers in the list. That would result in potentail access-after-free errors, as reported in #105160. The typical identified scenario is wmTimer calling wmJob code, which calls some of the job's callbacks (`update` or `end` e.g.), which call `WM_report`, which removes and add another timer. To address this issue on a general level, the deletion of timers is now deferred, with the public API `WM_event_remove_timer` only marking the timer for deletion, and the private new function `wm_window_delete_removed_timers` effectively removing and deleting all marked timers. This implements design task #105369.
Bastien Montagne added the
Module
Core
label 2023-03-02 18:02:21 +01:00
Bastien Montagne added this to the Core project 2023-03-02 18:02:39 +01:00
Bastien Montagne requested review from Brecht Van Lommel 2023-03-02 18:02:53 +01:00
Bastien Montagne requested review from Campbell Barton 2023-03-02 18:02:53 +01:00
Author
Owner

@blender-bot build

@blender-bot build
Brecht Van Lommel requested changes 2023-03-02 18:29:44 +01:00
@ -1872,1 +1897,4 @@
event->type = EVENT_NONE; /* Timer users customdata, don't want `NULL == NULL`. */
}
}
}

Clearing wm->reports.reporttimer and event->customdata should still happen immediately, not deferred.

Not sure if it causes any actual issues, but no reason to take the risk.

MEM_freeN(wt->customdata) could be done immediately as well.

Clearing `wm->reports.reporttimer` and `event->customdata` should still happen immediately, not deferred. Not sure if it causes any actual issues, but no reason to take the risk. `MEM_freeN(wt->customdata)` could be done immediately as well.
Author
Owner

Fair point, done.

Would keep MEM_freeN(wt->customdata) together with the actual timer freeing though, sounds safer to me?

Fair point, done. Would keep `MEM_freeN(wt->customdata)` together with the actual timer freeing though, sounds safer to me?

I think it's better to be freed immediately so ASAN will catch any use of this memory after free. I don't think we have to hang onto memory in case there is buggy code somewhere using it.

I think it's better to be freed immediately so ASAN will catch any use of this memory after free. I don't think we have to hang onto memory in case there is buggy code somewhere using it.
Author
Owner

Ah OK I see now, done.

Ah OK I see now, done.
mont29 marked this conversation as resolved
Bastien Montagne force-pushed F-wmtimer-fix from 83edd41ca6 to 87ef63b1ec 2023-03-02 18:52:18 +01:00 Compare
Bastien Montagne force-pushed F-wmtimer-fix from 87ef63b1ec to 3b608183e1 2023-03-02 18:54:32 +01:00 Compare
Bastien Montagne force-pushed F-wmtimer-fix from 3b608183e1 to 2332bc4e54 2023-03-02 18:58:31 +01:00 Compare
Author
Owner

@blender-bot build

@blender-bot build
Brecht Van Lommel approved these changes 2023-03-02 19:01:51 +01:00
@ -1897,0 +1918,4 @@
/* Immediately free customdata if requested, so that invalid usages of that data after
* calling `WM_event_remove_timer` can be easily spotted (through ASAN errors e.g.). */
if (timer->customdata != NULL && (timer->flags & WM_TIMER_NO_FREE_CUSTOM_DATA) == 0) {
MEM_freeN(timer->customdata);

I'd set this to NULL for clarity, rather not have any dangling pointer even if it should not be accessed.

I'd set this to NULL for clarity, rather not have any dangling pointer even if it should not be accessed.
mont29 marked this conversation as resolved
Bastien Montagne force-pushed F-wmtimer-fix from 2332bc4e54 to fafa5b9fcd 2023-03-02 19:55:11 +01:00 Compare
Bastien Montagne force-pushed F-wmtimer-fix from fafa5b9fcd to fab26f7c7e 2023-03-03 15:23:13 +01:00 Compare
Bastien Montagne merged commit d66672e17a into blender-v3.5-release 2023-03-03 15:24:37 +01:00
Bastien Montagne deleted branch F-wmtimer-fix 2023-03-03 15:24:38 +01:00
Bastien Montagne removed this from the Core project 2023-07-03 12:48:13 +02:00
Sign in to join this conversation.
No Label
Interest
Alembic
Interest
Animation & Rigging
Interest
Asset Browser
Interest
Asset Browser Project Overview
Interest
Audio
Interest
Automated Testing
Interest
Blender Asset Bundle
Interest
BlendFile
Interest
Collada
Interest
Compatibility
Interest
Compositing
Interest
Core
Interest
Cycles
Interest
Dependency Graph
Interest
Development Management
Interest
EEVEE
Interest
EEVEE & Viewport
Interest
Freestyle
Interest
Geometry Nodes
Interest
Grease Pencil
Interest
ID Management
Interest
Images & Movies
Interest
Import Export
Interest
Line Art
Interest
Masking
Interest
Metal
Interest
Modeling
Interest
Modifiers
Interest
Motion Tracking
Interest
Nodes & Physics
Interest
OpenGL
Interest
Overlay
Interest
Overrides
Interest
Performance
Interest
Physics
Interest
Pipeline, Assets & IO
Interest
Platforms, Builds & Tests
Interest
Python API
Interest
Render & Cycles
Interest
Render Pipeline
Interest
Sculpt, Paint & Texture
Interest
Text Editor
Interest
Translations
Interest
Triaging
Interest
Undo
Interest
USD
Interest
User Interface
Interest
UV Editing
Interest
VFX & Video
Interest
Video Sequencer
Interest
Virtual Reality
Interest
Vulkan
Interest
Wayland
Interest
Workbench
Legacy
Blender 2.8 Project
Legacy
Milestone 1: Basic, Local Asset Browser
Legacy
OpenGL Error
Meta
Good First Issue
Meta
Papercut
Meta
Retrospective
Meta
Security
Module
Animation & Rigging
Module
Core
Module
Development Management
Module
EEVEE & Viewport
Module
Grease Pencil
Module
Modeling
Module
Nodes & Physics
Module
Pipeline, Assets & IO
Module
Platforms, Builds & Tests
Module
Python API
Module
Render & Cycles
Module
Sculpt, Paint & Texture
Module
Triaging
Module
User Interface
Module
VFX & Video
Platform
FreeBSD
Platform
Linux
Platform
macOS
Platform
Windows
Priority
High
Priority
Low
Priority
Normal
Priority
Unbreak Now!
Status
Archived
Status
Confirmed
Status
Duplicate
Status
Needs Info from Developers
Status
Needs Information from User
Status
Needs Triage
Status
Resolved
Type
Bug
Type
Design
Type
Known Issue
Type
Patch
Type
Report
Type
To Do
No Milestone
No project
No Assignees
2 Participants
Notifications
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: blender/blender#105380
No description provided.