#52474: fix: refactor to avoid UAF in NodeStreamLoader
Merged
Description of Change
Under specific circumstances NodeStreamLoader can hit a UAF when it deletes itself before completing NodeStreamLoader::NotifyReadable, so refactor to avoid that possibility.
Test added as a separate commit first to show the ASan failure flagging the UAF: https://github.com/electron/electron/actions/runs/30314440929/job/90138979629
Also added tests for two other edge cases which get fixed by the refactor, which would cause the streaming response to stall out: https://github.com/electron/electron/actions/runs/30321732441/job/90160483107
Checklist
- I have built and tested this change
- I have filled out the PR description
- I have reviewed and verified the changes
-
npm testpasses - tests are changed or added
- PR release notes describe the change in a way relevant to app developers, and are capitalized, punctuated, and past tense.
Release Notes
Notes: Fixed a UAF with protocol.registerStreamProtocol when an error is emitted during a read
Backports
Semver Impact
Major
Breaking changes
Minor
New features
Patch
Bug fixes
None
Docs, tests, etc.
Semantic Versioning helps users understand the impact of updates:
- Major (X.y.z): Breaking changes that may require code modifications
- Minor (x.Y.z): New features that maintain backward compatibility
- Patch (x.y.Z): Bug fixes that don't change the API
- None: Changes that don't affect using facing parts of Electron