Commit 4a099e8
Core - OnSelectClientCertificate own the copied certificate vector (#5281)
* Fix deferred client certificate selection reading freed memory
CefCertificateCallbackWrapper held the offered certificate list as
`const X509CertificateList&`, bound to a stack local built in
ClientAdapter::OnSelectClientCertificate. Once that handler returned the
list was destroyed, so calling Select() at any later point walked freed
memory and threw inside the thumbprint-matching loop, taking the host
process down with it.
CEF explicitly permits answering later. cef_request_handler.h says to
return true and call Select "either in this method or at a later time",
so a wrapper that outlives the handler has to own the list it selects
from. It now holds a heap-allocated copy, freed in the finalizer. A ref
class cannot contain a std::vector by value, hence the pointer. Copying
the vector copies the reference-counted CefX509Certificate pointers, and
those references are what keep the certificates alive.
This is the remaining half of #2948. The comment above the caller reads
"Create a copy of the vector in an attempt to fix #2948", and the copy is
indeed made - but it is then bound by reference, so it dies at the same
instant the original would have.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
* Remove the redundant certificate vector copy in ClientAdapter
The wrapper takes its own copy in its constructor, so the local copy added
by a51cdd3 in ClientAdapter::OnSelectClientCertificate is now pure
redundancy - two copies where one is needed. Pass `certificates` straight
through instead.
Also refreshes the comment on _certificateList, which described the caller's
stack local that this removes.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
---------
Co-authored-by: John Hodnik <jhodnik@activu.com>
Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>1 parent d24556a commit 4a099e8
2 files changed
Lines changed: 18 additions & 9 deletions
Lines changed: 15 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
22 | | - | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
23 | 31 | | |
24 | 32 | | |
25 | 33 | | |
26 | | - | |
| 34 | + | |
27 | 35 | | |
28 | 36 | | |
29 | 37 | | |
30 | 38 | | |
31 | 39 | | |
32 | 40 | | |
33 | 41 | | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
34 | 45 | | |
35 | 46 | | |
36 | 47 | | |
| |||
53 | 64 | | |
54 | 65 | | |
55 | 66 | | |
56 | | - | |
57 | | - | |
| 67 | + | |
| 68 | + | |
58 | 69 | | |
59 | 70 | | |
60 | 71 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
764 | 764 | | |
765 | 765 | | |
766 | 766 | | |
767 | | - | |
768 | | - | |
769 | 767 | | |
770 | 768 | | |
771 | 769 | | |
| |||
780 | 778 | | |
781 | 779 | | |
782 | 780 | | |
783 | | - | |
784 | | - | |
785 | 781 | | |
786 | 782 | | |
787 | | - | |
| 783 | + | |
| 784 | + | |
| 785 | + | |
788 | 786 | | |
789 | 787 | | |
790 | 788 | | |
| |||
0 commit comments