已合并
fix ashmem fd container residue in unmarshal thread and enhance marshalling failure logs #31901
fix ashmem fd container residue in unmarshal thread and enhance marshalling failure logs #31901
已合并
LyBbq创建于 8月3日
LyBbq成员
8月3日

Description:

问题背景:

unmarshal 并行开启后,RSUnmarshalThread 的 FFRT worker 线程会被多个 parcel 任务复用,而 AshmemFdContainer 是 thread_local 单例(offset→fd 映射表),此前仅依赖任务尾部的 ~AshmemFdWorker() 清理。一旦某次任务提前返回未走清理路径,残留的旧 offset→fd 条目会被该线程上的下一个 parcel 命中:ReadSafeFd 按 offset 查到属于上一个 parcel 的 fd(可能已 close),导致 ashmem 数据读取错乱、CopyFromAshmem 尺寸校验失败、unmarshalling 失败甚至 unmarshal 线程崩溃。

修复方案:

  1. 清除 thread_local 残留:每个 unmarshal 任务开始时(SetIsUnmarshalThread(true) 之后、PushFdsToContainer() 之前)主动调用 AshmemFdContainer::Instance().Clear(),将 fd 表严格限定在本任务生命周期内,消除线程复用带来的脏数据;为此将 Clear() 从 private 提升为 public(rs_unmarshal_thread.cpp、rs_ashmem_helper.h)
  2. 加固 ashmem parcel 构造:CreateAshmemParcel 对 header 写入(interfaceToken / ashmem 标志 / dataSize / fd / offsetSize)逐项检查返回值,任一失败立即打日志并返回 nullptr,避免发出格式残缺的 ashmem parcel 导致对端解析失败(rs_ashmem_helper.cpp)
  3. 补充失败路径日志:rs_marshalling_helper.cpp 中约 30 处原本静默 return false 的分支新增 ROSEN_LOGE,覆盖 DrawCmdList(recordCmd / 扩展对象 / 各类 size 超限)、RSLinearGradientBlurPara、粒子参数、Surface 读写、WriteToParcel 等;另补充 CommitTransactionrenderPipelineAgent_ 为空的丢包日志、AshmemAllocator::WriteToAshmem/CopyFromAshmem 参数非法日志、ParseFromAshmemParcel token 不匹配日志,便于定位 unmarshalling 失败的具体环节

Issue number:https://gitcode.com/openharmony/graphic_graphic_2d/issues/25442

Test & Result:

  • 编译、静态检查、冒烟测试通过(CI 全绿,已合入 master)
  • 复现场景连续压测,unmarshal 线程不再出现因残留 fd 导致的解析失败/崩溃

CodeCheck:

类型 自检项 自检结果
多线程 在类的成员变量中定义了vector/map/list等容器类型,且在多个成员函数中有操作时,需要加锁保护 自检结果:
定义全局变量,在多个函数中都有操作时,需要加锁保护 自检结果:
内存操作 调用外部接口时,确认是否对返回值做了判空判断,尤其外部接口返回了nullptr的情况,避免进程崩溃 自检结果:
内存操作优先使用安全函数,并检查其返回值 自检结果:
注意每个异常退出流程,是否都已经将资源释放(推荐使用RAII) 自检结果:
隐式内存分配场景:realpath、ReadParcelable序列化、cJSON相关函数时等,需主动释放或使用智能指针 自检结果:
外部输入 所有外部输入均不可信,需判断外部输入是否直接作为内存分配的大小,数组下标、循环条件、SQL查询等 自检结果:
注意外部字符串数据有无尾0 自检结果:
外部输入的路径不可信,需使用realpath做标准化处理,并判断路径的合法性 自检结果:
敏感信息 注意日志中打印敏感信息需匿名化 自检结果:
数学运算 代码中是否混合了加减乘除等运算,需检查是否可能导致整数溢出或符号翻转 自检结果:
初始化 类成员、局部变量使用前需初始化 自检结果:
权限管理 作为系统服务对外提供了接口(或RSCmd),是否做了权限保护和校验,只允许申请了权限的应用访问 自检结果:

L0新增用例自检结果

likedislike
Pull Request已成功合入, 合并人@openharmony_ci
(感谢 LyBbq 的贡献)
LLyBbq成员
8月3日 关联了issue:[Bug]: 修复umarlling Thread多线程问题
openharmony_ciopenharmony_ci成员
8月3日 添加了label:waiting_on_author
openharmony_ci
openharmony_ci成员
8月3日 评论:

感谢提交 Pull Requests!如果您提交的PR已经开发完毕,请评论 "start build" 触发门禁,更多交互操作,请访问OpenHarmony社区支持命令清单。如果需要调整订阅PR、Issue的变更状态,请访问订阅链接


Thanks for submitting the pull request. If your Pull Request has already been developed, you can leave a "start build" comment to trigger the gated system. For more commands, please visit OpenHarmony Command List. If you need to change the subscription of a Pull Request or Issue, please visit the link.

likedislike
openharmony_ciopenharmony_ci成员
8月3日 添加了label:dco检查成功
LLyBbq成员
8月3日 审查状态已重置,审查人: white-dragon-tiger
此处折叠了72条消息 查看更多
openharmony_ciopenharmony_ci成员
20 天前 删除了label:waiting_for_review
openharmony_ciopenharmony_ci成员
20 天前 添加了label:merged
LLyBbq成员
16 天前 修改标题为 “fix ashmem fd container residue in unmarshal thread and enhance marshalling failure logs”,原标题为“fix”
LLyBbq成员
16 天前 修改了pull request 的描述
LLyBbq成员
16 天前 修改了pull request 的描述