From 5ce4eed54dceb15c34d3508e733124edd282601b Mon Sep 17 00:00:00 2001 From: Fedor Indutny Date: Wed, 27 Nov 2013 14:54:58 +0400 Subject: [PATCH] http: fix parser double-free in _http_client.js HTTP Parser instance was freed twice, leading to the reusal of it in several different requests simultaneously. The flow: `socketCloseListener` is firing, which calls `socket.read()` to flush any queued data, `socket.buffer` has data which emits and fires `socketOnData` in sync, this triggers a parser error which frees the parser, `socketCloseListener` resumes execution only to have the wrong parser associated with the socket. The fix is to only cache the parser after the flushing from the socket, and to assert in `socketOnData` that `socket === parser.socket` fix #6451 --- lib/_http_client.js | 6 ++- test/simple/test-http-client-parser-double-free.js | 61 ++++++++++++++++++++++ 2 files changed, 65 insertions(+), 2 deletions(-) create mode 100644 test/simple/test-http-client-parser-double-free.js diff --git a/lib/_http_client.js b/lib/_http_client.js index 6669249..56aa6e0 100644 --- a/lib/_http_client.js +++ b/lib/_http_client.js @@ -184,7 +184,6 @@ function createHangUpError() { function socketCloseListener() { var socket = this; - var parser = socket.parser; var req = socket._httpMessage; debug('HTTP socket close'); @@ -193,6 +192,9 @@ function socketCloseListener() { // is a no-op if no final chunk remains. socket.read(); + // NOTE: Its important to get parser here, because it could be freed by + // the `socketOnData`. + var parser = socket.parser; req.emit('close'); if (req.res && req.res.readable) { // Socket closed before we emitted 'end' below. @@ -267,7 +269,7 @@ function socketOnData(d) { var req = this._httpMessage; var parser = this.parser; - assert(parser); + assert(parser && parser.socket === socket); var ret = parser.execute(d); if (ret instanceof Error) { diff --git a/test/simple/test-http-client-parser-double-free.js b/test/simple/test-http-client-parser-double-free.js new file mode 100644 index 0000000..5c62f95 --- /dev/null +++ b/test/simple/test-http-client-parser-double-free.js @@ -0,0 +1,61 @@ +// Copyright Joyent, Inc. and other Node contributors. +// +// Permission is hereby granted, free of charge, to any person obtaining a +// copy of this software and associated documentation files (the +// "Software"), to deal in the Software without restriction, including +// without limitation the rights to use, copy, modify, merge, publish, +// distribute, sublicense, and/or sell copies of the Software, and to permit +// persons to whom the Software is furnished to do so, subject to the +// following conditions: +// +// The above copyright notice and this permission notice shall be included +// in all copies or substantial portions of the Software. +// +// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS +// OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF +// MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN +// NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, +// DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR +// OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE +// USE OR OTHER DEALINGS IN THE SOFTWARE. + +var common = require('../common'); +var assert = require('assert'); +var http = require('http'); +var http_common = require('_http_common'); + +var receivedError = 0; +var receivedClose = 0; + +var buf = new Buffer(64 * 1024); +buf.fill('A'); + +var server = http.createServer(function(req, res) { + res.write(buf, function() { + res.socket.write(buf); + res.end(function() { + req.socket.destroy(); + server.close(); + }); + }); +}).listen(common.PORT, function() { + var req = http.request({ port: common.PORT, agent: false }, function(res) { + res.once('readable', function() { + /* read only one buffer */ + res.read(1); + }); + }); + req.end(); + req.on('close', function() { + receivedClose++; + }); + req.on('error', function() { + receivedError++; + }); +}); + +process.on('exit', function() { + assert.equal(receivedError, 1); + assert.equal(receivedClose, 1); + assert.equal(http_common.parsers.list.length, 2); +}); -- 2.7.4