Skip to content

Commit 024b474

Browse files
generatedunixname1608173377072046meta-codesync[bot]
authored andcommitted
Fix use-after-free race in RCTInstance callFunctionOnJSModule (#58816)
Summary: Pull Request resolved: #58816 ## Changelog: [Internal] Reviewed By: zeyap Differential Revision: D122831570 fbshipit-source-id: 924ffa228cadc454069b268a0fd1c1126953ba33
1 parent 51e9a97 commit 024b474

1 file changed

Lines changed: 7 additions & 3 deletions

File tree

  • packages/react-native/ReactCommon/react/runtime/platform/ios/ReactCommon

‎packages/react-native/ReactCommon/react/runtime/platform/ios/ReactCommon/RCTInstance.mm‎

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -171,10 +171,14 @@ - (void)dealloc
171171

172172
- (void)callFunctionOnJSModule:(NSString *)moduleName method:(NSString *)method args:(NSArray *)args
173173
{
174-
if (_valid) {
175-
_reactInstance->callFunctionOnModule(
176-
[moduleName UTF8String], [method UTF8String], convertIdToFollyDynamic(args ? args : @[]));
174+
// This is called from arbitrary threads, while -invalidate destroys _reactInstance on
175+
// the JS thread, so checking _valid and dereferencing have to happen as one step.
176+
std::lock_guard<std::mutex> lock(_invalidationMutex);
177+
if (!_valid || !_reactInstance) {
178+
return;
177179
}
180+
_reactInstance->callFunctionOnModule(
181+
[moduleName UTF8String] ?: "", [method UTF8String] ?: "", convertIdToFollyDynamic(args ? args : @[]));
178182
}
179183

180184
- (void)invalidate

0 commit comments

Comments
 (0)