Prevent cache writer use-after-free during cleanup - #2550
Merged
ge0rdi merged 1 commit intoOct 4, 2026
Merged
Conversation
ge0rdi
approved these changes
Oct 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Prevent the asynchronous cache writer from retaining pointers to entries that normal cache cleanup can erase, and serialize explicit cache clearing with an in-flight save.
Why
SaveCacheFileThreadfirst snapshots raw pointers tom_IconInfosandm_ItemInfosunder read locks, releases those locks, then reacquires a read lock for each pointer while serializing it.The later lock cannot make a pointer valid again if the entry was erased between the snapshot and that reacquisition.
ResetTempIcons()can erase temporary items and temporary/Metro icons during that window.ClearCache()can erase every cached item and icon while a save is in progress.The save path already skips temporary and Metro entries when it eventually serializes them. This change applies those same exclusions while the snapshot lock is still held, so pointers to entries that
ResetTempIcons()may erase are never retained.ClearCache()waits for an in-flight cache writer before deleting the persistent containers and cache file.This also ensures an already-running save cannot recreate
DataCache.dbafter an explicit cache clear.Verification
Buildcompleted successfully for exact commitc2c47b4b3b5d4ae8fd0dcb98e424a0e5877d6338in run37158312012.m_ItemInfos/m_IconInfoserase/clear paths: runtime cleanup removes only entries now excluded from snapshots; full cache clearing is explicitly synchronized; shutdown already waits for the save thread.This is a source-identified lifetime bug; it is not being attributed to a specific reported crash.