[vlc-commits] [Git][videolan/vlc][master] 18 commits: preparser: external: fix UAF on request completion
Steve Lhomme (@robUx4)
gitlab at videolan.org
Mon Sep 14 08:09:44 UTC 2026
Steve Lhomme pushed to branch master at VideoLAN / VLC
Commits:
7857d4cc by Ayush Dey at 2026-09-14T07:38:27+00:00
preparser: external: fix UAF on request completion
preparser_task_Delete freed the task unconditionally. If the caller still
held its request handle, the task was freed while that reference was
alive, so a later vlc_preparser_req_Release call by the user would cause
an UAF and double free.
- - - - -
391a5f80 by Ayush Dey at 2026-09-14T07:38:27+00:00
preparser: external: accumulate cancel count across pools
- - - - -
1fa38811 by Ayush Dey at 2026-09-14T07:38:27+00:00
preparser: split request creation from submission
The previous functions allocated a request and queued it in one step.
This prevented callers from holding a request before it starts running.
In case of early task completion, caller would receive an already freed
vlc_preparser_req handle (if they released the task from on_ended callback).
The public API will be modified in the next commit.
- - - - -
ace6c89d by Ayush Dey at 2026-09-14T07:38:27+00:00
preparser: expose request creation and submission APIs
Add the public APIs of the internal split done in the previous
commit. This lets a caller hold a cancellable handle before the
request starts.
- - - - -
ab89097e by Ayush Dey at 2026-09-14T07:38:27+00:00
playlist: adapt vlc_preparser split
Transfer ownership of vlc_preparser_req to vlc_playlist_item_t.
- - - - -
f8d76610 by Ayush Dey at 2026-09-14T07:38:27+00:00
media_source: adapt vlc_preparser split
Transfer the preparser request ownership to the caller.
- - - - -
0761ae41 by Ayush Dey at 2026-09-14T07:38:27+00:00
preparser: adapt vlc_preparser split in the callers
- - - - -
43a8937b by Ayush Dey at 2026-09-14T07:38:27+00:00
lib: parser: split request creation from submission
Replace libvlc_parser_queue and libvlc_parser_queue_thumbnailing
with libvlc_parser_task_new_parse, libvlc_parser_task_new_thumbnail
and libvlc_parser_submit.
The previous APIs allocated a task and queued it in one step.
This prevented users from holding a task handle before it starts running.
In case of early task completion, caller would receive an already freed
libvlc_parser_task handle (if they released the task from on_parsed/on_ended
callback).
- - - - -
77017f77 by Ayush Dey at 2026-09-14T07:38:27+00:00
preparser: remove the fused submit entry points
- - - - -
27aa24e4 by Ayush Dey at 2026-09-14T07:38:27+00:00
preparser: external: drop the now unused task destructor
- - - - -
fe534e88 by Ayush Dey at 2026-09-14T07:38:27+00:00
qt: network: cancel the preparse request outside media tree lock
- - - - -
9e18731a by Ayush Dey at 2026-09-14T07:38:27+00:00
vlc_preparser: document about vlc_preparser_Cancel potential deadlock
- - - - -
7a2f811a by Ayush Dey at 2026-09-14T07:38:27+00:00
preparser: fix the thumbnailer on_ended documentation
- - - - -
47d49a0a by Ayush Dey at 2026-09-14T07:38:27+00:00
preparser: internal: join input thread before reading thumbnail result
ThumbnailerRun() read req_owner->preparse_status and req_owner->pic while
the input thread was still running. on_thumbnailer_input_event() could
still fire and overwrite both fields causing a race.
- - - - -
7709c731 by Ayush Dey at 2026-09-14T07:38:27+00:00
preparser: internal: submit tasks under the preparser lock
Publishing the request in submitted_tasks and handing its runnable to an
executor were two separate steps, so a request was visible to
preparser_Cancel() before it had been submitted.
- - - - -
db45195f by Ayush Dey at 2026-09-14T07:38:27+00:00
preparser: internal: cancel the executor the request was submitted to
preparser_Cancel() guessed the executor holding a runnable from the
request options. For a thumbnail-to-files request the runnable starts on
the thumbnailer executor and then moves to thumbnailer_to_files executor,
so the cancel tried the thumbnailer first.
vlc_executor_Cancel() inspects and unlinks runnable->node while holding
the lock of the executor it was passed. Suppose
`vlc_executor_Cancel(preparser->thumbnailer, &req_itr->runnable);` was
called, once the runnable had moved from thumbnailer to thumbnailer_to_files
executor; that call therefore touched a node owned by the thumbnailer_to_files
queue under the thumbnailer lock; a data race with the thread running that
queue, an unlink corrupting it, and an unfinished counter decremented
on the wrong executor.
- - - - -
1dc41d7a by Ayush Dey at 2026-09-14T07:38:27+00:00
preparser: internal: transfer request to thumbnailer_to_files executor under the lock
- - - - -
c6666342 by Ayush Dey at 2026-09-14T07:38:27+00:00
preparser: internal: release the thumbnail picture on the cancel path
Cancelling a THUMBNAIL_TO_FILES request while its runnable was still
queued, dequeues that runnable, so neither release ever runs and the
picture is leaked.
Make PreparserRequestDelete() the catch-all owner, in case the picture
couldn't be released by a worker thread due to interruption.
- - - - -
37 changed files:
- bin/preparser/main.c
- doc/libvlc/CHANGES-v3-to-v4.md
- doc/libvlc/parser.c
- doc/libvlc/thumbnailer.c
- doc/standalone/mrl.dox
- include/vlc/libvlc_media.h
- include/vlc/libvlc_media_player.h
- include/vlc/libvlc_parser.h
- include/vlc_media_source.h
- include/vlc_preparser.h
- include/vlc_preparser_ipc.h
- lib/downloader.c
- lib/libvlc.sym
- lib/parser.c
- modules/gui/macosx/library/VLCLibraryImageCache.m
- modules/gui/macosx/library/media-source/VLCMediaSource.m
- modules/gui/qt/network/networkmediamodel.cpp
- modules/gui/qt/player/player_controller.cpp
- modules/misc/medialibrary/MetadataExtractor.cpp
- modules/misc/medialibrary/Thumbnailer.cpp
- modules/misc/medialibrary/fs/directory.cpp
- src/libvlccore.sym
- src/media_source/media_tree.c
- src/playlist/content.c
- src/playlist/item.c
- src/playlist/preparse.c
- src/playlist/preparse.h
- src/preparser/external.c
- src/preparser/internal.c
- src/preparser/preparser.c
- src/preparser/preparser.h
- test/libvlc/media.c
- test/libvlc/media_utils.h
- test/libvlc/thumbnailer.c
- test/src/preparser/cmp_internal_external.c
- test/src/preparser/thumbnail.c
- test/src/preparser/thumbnail_to_files.c
The diff was not included because it is too large.
View it on GitLab: https://code.videolan.org/videolan/vlc/-/compare/57f36117ede8fd57abd1e82c276a367b172b0356...c666634229ca28354fd4fc1bdf8c43a8a232644b
--
View it on GitLab: https://code.videolan.org/videolan/vlc/-/compare/57f36117ede8fd57abd1e82c276a367b172b0356...c666634229ca28354fd4fc1bdf8c43a8a232644b
You're receiving this email because of your account on code.videolan.org. Manage all notifications: https://code.videolan.org/-/profile/notifications | Help: https://code.videolan.org/help
More information about the vlc-commits
mailing list