Skip to content
Merged
Show file tree
Hide file tree
Changes from 1 commit
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Prev Previous commit
Next Next commit
refactor: fix TOCTOU in UpdatePortVisibility and revert signal change
- Hold ManagerMu across the entire get/check/delete sequence in
  UpdatePortVisibility to eliminate a time-of-check-time-of-use gap
- Remove IIFE pattern in favor of explicit lock/unlock
- Revert signal.NotifyContext change in cmd.go (out of scope)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
  • Loading branch information
williammartin and Copilot committed May 13, 2026
commit e33c0eee5dc75b7a17397abb43a47bffa3e21871
18 changes: 8 additions & 10 deletions internal/codespaces/portforwarder/port_forwarder.go
Original file line number Diff line number Diff line change
Expand Up @@ -270,30 +270,28 @@ func (fwd *CodespacesPortForwarder) ListPorts(ctx context.Context) (ports []*tun

// UpdatePortVisibility changes the visibility (private, org, public) of the specified port.
func (fwd *CodespacesPortForwarder) UpdatePortVisibility(ctx context.Context, remotePort int, visibility string) error {
tunnelPort, err := func() (*tunnels.TunnelPort, error) {
fwd.connection.ManagerMu.Lock()
defer fwd.connection.ManagerMu.Unlock()
return fwd.connection.TunnelManager.GetTunnelPort(ctx, fwd.connection.Tunnel, remotePort, fwd.connection.Options)
}()
fwd.connection.ManagerMu.Lock()
tunnelPort, err := fwd.connection.TunnelManager.GetTunnelPort(ctx, fwd.connection.Tunnel, remotePort, fwd.connection.Options)
if err != nil {
Comment thread
williammartin marked this conversation as resolved.
fwd.connection.ManagerMu.Unlock()
return fmt.Errorf("error getting tunnel port: %w", err)
}

// If the port visibility isn't changing, don't do anything
if AccessControlEntriesToVisibility(tunnelPort.AccessControl.Entries) == visibility {
fwd.connection.ManagerMu.Unlock()
return nil
}

// Delete the existing tunnel port to update
port, err := convertIntToUint16(remotePort)
if err != nil {
fwd.connection.ManagerMu.Unlock()
return fmt.Errorf("error converting port: %w", err)
}
if err := func() error {
fwd.connection.ManagerMu.Lock()
defer fwd.connection.ManagerMu.Unlock()
return fwd.connection.TunnelManager.DeleteTunnelPort(ctx, fwd.connection.Tunnel, port, fwd.connection.Options)
}(); err != nil {
err = fwd.connection.TunnelManager.DeleteTunnelPort(ctx, fwd.connection.Tunnel, port, fwd.connection.Options)
fwd.connection.ManagerMu.Unlock()
if err != nil {
return fmt.Errorf("error deleting tunnel port: %w", err)
}

Expand Down
9 changes: 2 additions & 7 deletions internal/ghcmd/cmd.go
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@ import (
"net"
"os"
"os/exec"
"os/signal"

"path/filepath"
"slices"
"strconv"
Expand Down Expand Up @@ -135,12 +135,7 @@ func Main() exitCode {
}
}

// Intercept SIGINT/SIGTERM so that defers (e.g. telemetry flush) run
// before the process exits. Without this, the Go runtime's default
// signal handler calls os.Exit immediately, skipping all defers.
ctx, stop := signal.NotifyContext(context.Background(), os.Interrupt)
defer stop()

ctx := context.Background()
updateCtx, updateCancel := context.WithCancel(ctx)
defer updateCancel()
updateMessageChan := make(chan *update.ReleaseInfo)
Expand Down
Loading