ladybird/Tests/LibIPC
sideshowbarker c551a8094a LibIPC: Don’t dispatch queued messages when sync IPC peer disconnects
Problem: When the browser is closed during startup, we crash inside
PageHost::attach_compositor_ui_client() — on what looks like a normal
null check, but which is actually reading uninitialized memory.

Cause: A sync allocate_compositor_context_id IPC call is issued by the
PageHost constructor before ConnectionFromClient::m_page_host has been
assigned. The sync call runs inside the initializer that’s still
computing m_page_host’s value. If a peer disconnects before responding
(e.g., during shutdown), wait_for_specific_endpoint_message_impl’s
failure path drains any still-queued messages via handle_messages().
One of those is the initial ConnectToCompositor, which dispatches to
m_page_host->attach_compositor_ui_client() — but m_page_host is
uninitialized garbage at that point, so the call segfaults.

Fix: On peer EOF, stop draining queued messages from the failure path.
Re-entering arbitrary handlers from any sync IPC wait is unsafe — since
that wait can be reached from a constructor whose members are still
being initialized. Instead, call shutdown() to close the transport and
invoke die(). That exits processes cleanly via _exit(0) — achieving the
same effect the queued close_server message would’ve had.

Fixes https://github.com/LadybirdBrowser/ladybird/issues/9582
2026-05-24 10:00:31 +02:00
..
CMakeLists.txt LibIPC: Don’t dispatch queued messages when sync IPC peer disconnects 2026-05-24 10:00:31 +02:00
TestConnection.cpp LibIPC: Don’t dispatch queued messages when sync IPC peer disconnects 2026-05-24 10:00:31 +02:00
TestTransportSocket.cpp LibIPC: Notify readers when thread exits 2026-03-14 02:05:34 -05:00