Skip to content

Commit

Permalink
http: fix parser double-free in _http_client.js
Browse files Browse the repository at this point in the history
HTTP Parser instance was freed twice, leading to the reusal of it
in several different requests simultaneously.

The flow:

`socketCloseListener` is firing, which calls `socket.read()` to flush
any queued data, `socket.buffer` has data which emits and fires
`socketOnData` in sync, this triggers a parser error which frees the
parser, `socketCloseListener` resumes execution only to have the wrong
parser associated with the socket.

The fix is to only cache the parser after the flushing from the socket,
and to assert in `socketOnData` that `socket === parser.socket`

fix #6451
  • Loading branch information
indutny authored and tjfontaine committed Nov 27, 2013
1 parent c749a84 commit 5ce4eed
Show file tree
Hide file tree
Showing 2 changed files with 65 additions and 2 deletions.
6 changes: 4 additions & 2 deletions lib/_http_client.js
Original file line number Diff line number Diff line change
Expand Up @@ -184,7 +184,6 @@ function createHangUpError() {

function socketCloseListener() {
var socket = this;
var parser = socket.parser;
var req = socket._httpMessage;
debug('HTTP socket close');

Expand All @@ -193,6 +192,9 @@ function socketCloseListener() {
// is a no-op if no final chunk remains.
socket.read();

// NOTE: Its important to get parser here, because it could be freed by
// the `socketOnData`.
var parser = socket.parser;
req.emit('close');
if (req.res && req.res.readable) {
// Socket closed before we emitted 'end' below.
Expand Down Expand Up @@ -267,7 +269,7 @@ function socketOnData(d) {
var req = this._httpMessage;
var parser = this.parser;

assert(parser);
assert(parser && parser.socket === socket);

var ret = parser.execute(d);
if (ret instanceof Error) {
Expand Down
61 changes: 61 additions & 0 deletions test/simple/test-http-client-parser-double-free.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
// Copyright Joyent, Inc. and other Node contributors.
//
// Permission is hereby granted, free of charge, to any person obtaining a
// copy of this software and associated documentation files (the
// "Software"), to deal in the Software without restriction, including
// without limitation the rights to use, copy, modify, merge, publish,
// distribute, sublicense, and/or sell copies of the Software, and to permit
// persons to whom the Software is furnished to do so, subject to the
// following conditions:
//
// The above copyright notice and this permission notice shall be included
// in all copies or substantial portions of the Software.
//
// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS
// OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
// MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN
// NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM,
// DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR
// OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE
// USE OR OTHER DEALINGS IN THE SOFTWARE.

var common = require('../common');
var assert = require('assert');
var http = require('http');
var http_common = require('_http_common');

var receivedError = 0;
var receivedClose = 0;

var buf = new Buffer(64 * 1024);
buf.fill('A');

var server = http.createServer(function(req, res) {
res.write(buf, function() {
res.socket.write(buf);
res.end(function() {
req.socket.destroy();
server.close();
});
});
}).listen(common.PORT, function() {
var req = http.request({ port: common.PORT, agent: false }, function(res) {
res.once('readable', function() {
/* read only one buffer */
res.read(1);
});
});
req.end();
req.on('close', function() {
receivedClose++;
});
req.on('error', function() {
receivedError++;
});
});

process.on('exit', function() {
assert.equal(receivedError, 1);
assert.equal(receivedClose, 1);
assert.equal(http_common.parsers.list.length, 2);
});

0 comments on commit 5ce4eed

Please sign in to comment.