Agniva De Sarker c5d7ac0876 MM-46604: Fix racy access to session props (#20996)
The core mistake was that the webconn doesn't really go out of scope
once the connection disconnects. It is kept in the webhub connIndex
to be reconnected if the user connects again. This was the new
behavior as part of reliable websockets.

Therefore, it was a mistake to return the session to the pool
once the connection drops. Because the connection would still
recieve events from the web_hub.

And once you release the session, another login might acquire the
session and set some props, while the web_hub might still try
to send events to it, which will cause a read of the map prop.

The following test case illustrates such a race. It is very
hard to trigger it organically, hence I artificially wrote
the code.

The right fix is to release the session only when the connection
is stale and gets deleted from the conn index. The PR has been
load tested in `-race` mode just for extra sanity check.

```go
func TestHubSessionRace(t *testing.T) {
  th := Setup(t).InitBasic()
  defer th.TearDown()

  s := httptest.NewServer(dummyWebsocketHandler(t))
  defer s.Close()

  th.Server.HubStart()
  wc1 := registerDummyWebConn(t, th.App, s.Listener.Addr(), th.BasicUser.Id)
  defer wc1.Close()

  var wg sync.WaitGroup
  wg.Add(2)
  go func() {
    defer wg.Done()
    token := wc1.GetSessionToken()
    // Return to pool after *WebConn.Pump finishes
    wc1.App.Srv().userService.ReturnSessionToPool(wc1.GetSession())
    // A new HTTP requests acquires a session which gets it from the pool
    sess, _ := wc1.App.GetSession(token)
    // Login happens which sets some session properties
    sess.AddProp(model.SessionPropPlatform, "chrome")
  }()
  go func() {
    defer wg.Done()
    // Called from *WebConn.shouldSendEvent
    t.Log("session: ", wc1.GetSession().Props[model.SessionPropIsGuest] == "true")
  }()
  wg.Wait()
}
```

https://mattermost.atlassian.net/browse/MM-46604

```release-note
NONE
```
2022-09-14 14:27:24 +05:30
2020-01-23 12:34:29 +01:00
2022-09-02 13:52:48 +03:00
2022-09-13 13:47:01 +02:00
2022-09-06 13:55:06 +05:30
2022-08-18 11:01:37 +02:00
2020-03-13 18:35:31 +01:00
2018-05-30 10:23:25 -04:00
2022-09-09 00:41:04 +05:30
2022-09-09 00:41:04 +05:30
2022-02-17 12:34:39 -05:00
2022-09-13 10:33:32 -04:00
2022-06-24 13:18:39 +03:00

Mattermost

Mattermost is an open source platform for secure collaboration across the entire software development lifecycle. This repo is the primary source for core development on the Mattermost platform; it's written in Go and React and runs as a single Linux binary with MySQL or PostgreSQL. A new compiled version is released under an MIT license every month on the 16th.

Use it for free in Mattermost Cloud or deploy on-premises.

mattermost-hero

Learn more about the following use cases with Mattermost:

Other useful resources:

Table of contents

Install Mattermost

Other install guides:

Native mobile and desktop apps

In addition to the web interface, you can also download Mattermost clients for Android, iOS, Windows PC, macOS, and Linux.

Google Play App Store Windows PC Mac OSX Linux

Get security bulletins

Receive notifications of critical security updates. The sophistication of online attackers is perpetually increasing. If you're deploying Mattermost it's highly recommended you subscribe to the Mattermost Security Bulletin mailing list for updates on critical security releases.

Subscribe here

Get involved

Learn more

License

See the LICENSE file for license rights and limitations.

Get the latest news

Contributing

Please see CONTRIBUTING.md. Join the Mattermost Contributors server to join community discussions about contributions, development, and more.

Описание
No description provided
Readme 636 MiB
Languages
TypeScript 47%
Go 40.2%
JavaScript 8.6%
SCSS 2.8%
HTML 1.1%
Разное 0.2%