Skip to content

[RTDB Desktop] Fix use-after-free in WebSocketListenResponse by removing dangling View* pointer - #1890

Merged
AustinBenoit merged 4 commits into
mainfrom
fix-rtdb-view-uaf
Jul 28, 2026
Merged

[RTDB Desktop] Fix use-after-free in WebSocketListenResponse by removing dangling View* pointer#1890
AustinBenoit merged 4 commits into
mainfrom
fix-rtdb-view-uaf

Conversation

@AustinBenoit

Copy link
Copy Markdown
Contributor

Description

Provide details of the change, and generalize the change in the PR title above.

Fixes an intermittent desktop/Unity ACCESS_VIOLATION crash occurring when a Realtime Database event listener is detached while a WebSocket listen response is still pending.

Root Cause:
WebSocketListenResponse stored a raw, non-owning pointer to the query's local View object (const View* view_). When all listeners for a query are removed (e.g., during UI scene teardown or network reconnect churn),
SyncTree synchronously deallocates the View.

However, any in-flight WebSocketListenResponse in the network queue remains active. When the server response completes later, the callback dereferences the freed pointer (response->view()->query_spec()), causing an
immediate memory access violation (often misattributed in Windows crash dumps to public uS::Socket exports due to symbolication snapping).

WebSocketListenResponse already stores QuerySpec query_spec_ by value and uses it in error handling. Updated the success callback to use response->query_spec() directly. Removed the unused const View* view parameter from ListenProvider::StartListening, WebSocketListenResponse, InfoListenProvider, SyncTree::SetupListener, and related unit test mocks.


Testing

Ran integration tests.


Type of Change

Place an x the applicable box:

  • Bug fix. Add the issue # below if applicable.
  • New feature. A non-breaking change which adds functionality.
  • Other, such as a build process or documentation change.

Notes

  • Bug fixes and feature changes require an update to the Release Notes section of release_build_files/readme.md.
  • Read the contribution guidelines CONTRIBUTING.md.
  • Changes to the public API require an internal API review. If you'd like to help us make Firebase APIs better, please propose your change in a feature request so that we can discuss it together.

Bugs:
#1881
From Unity:
1391

Fix use-after-free in WebSocketListenResponse by removing dangling View*
pointer.

Fixes an intermittent desktop/Unity ACCESS_VIOLATION crash occurring when a Realtime Database event
listener is detached while a WebSocket listen response is still pending.
@AustinBenoit AustinBenoit added the tests-requested: full Trigger a FULL set of integration tests (uses expanded test matrix). label Jul 27, 2026
@AustinBenoit
AustinBenoit requested a review from a-maurice July 27, 2026 16:06
@github-actions github-actions Bot added tests: in-progress This PR's integration tests are in progress. and removed tests-requested: full Trigger a FULL set of integration tests (uses expanded test matrix). labels Jul 27, 2026
@github-actions

github-actions Bot commented Jul 27, 2026

Copy link
Copy Markdown

✅  Integration test succeeded!

Requested by @AustinBenoit on commit 1871444
Last updated: Tue Jul 28 07:57 PDT 2026
View integration test log & download artifacts

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request removes the View pointer parameter from the StartListening interface and its implementations, including InfoListenProvider and WebSocketListenProvider. In WebSocketListenResponse, the QuerySpec is now stored and accessed directly instead of through the View object. This resolves an intermittent use-after-free crash (ACCESS_VIOLATION) that occurred when detaching a listener while a WebSocket listen response was pending, as the View could be destroyed before the response was processed. I have no feedback to provide.

@github-actions github-actions Bot added the tests: failed This PR's integration tests failed. label Jul 27, 2026
@firebase-workflow-trigger firebase-workflow-trigger Bot removed the tests: in-progress This PR's integration tests are in progress. label Jul 27, 2026
@AustinBenoit AustinBenoit added tests: succeeded This PR's integration tests succeeded. and removed tests: failed This PR's integration tests failed. labels Jul 28, 2026
@AustinBenoit
AustinBenoit enabled auto-merge (squash) July 28, 2026 13:56
@@ -79,7 +75,7 @@ void WebSocketListenProvider::StartListening(const QuerySpec& query_spec,

std::vector<Event> events;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Lint warning: Add #include <vector> for vector<>

@AustinBenoit
AustinBenoit merged commit 1871444 into main Jul 28, 2026
39 checks passed
@github-actions github-actions Bot added tests: in-progress This PR's integration tests are in progress. tests: succeeded This PR's integration tests succeeded. and removed tests: succeeded This PR's integration tests succeeded. labels Jul 28, 2026
@firebase-workflow-trigger firebase-workflow-trigger Bot removed the tests: in-progress This PR's integration tests are in progress. label Jul 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

tests: succeeded This PR's integration tests succeeded.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants