Skip to content

Commit 0326314

Browse files
Autopilot Botfacebook-github-bot
authored andcommitted
Fix use-after-free race in RCTInstance callFunctionOnJSModule (#58816)
Summary: ## Changelog: [Internal] Differential Revision: D122831570
1 parent 7c007b3 commit 0326314

1 file changed

Lines changed: 12 additions & 3 deletions

File tree

  • packages/react-native/ReactCommon/react/runtime/platform/ios/ReactCommon

‎packages/react-native/ReactCommon/react/runtime/platform/ios/ReactCommon/RCTInstance.mm‎

Lines changed: 12 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -171,10 +171,19 @@ - (void)dealloc
171171

172172
- (void)callFunctionOnJSModule:(NSString *)moduleName method:(NSString *)method args:(NSArray *)args
173173
{
174-
if (_valid) {
175-
_reactInstance->callFunctionOnModule(
176-
[moduleName UTF8String], [method UTF8String], convertIdToFollyDynamic(args ? args : @[]));
174+
// Convert outside the lock: the payload can be large, and -invalidate blocks on
175+
// _invalidationMutex.
176+
auto dynamicArgs = convertIdToFollyDynamic(args ? args : @[]);
177+
std::string moduleNameString = [moduleName UTF8String] ?: "";
178+
std::string methodString = [method UTF8String] ?: "";
179+
180+
// This is called from arbitrary threads, while -invalidate destroys _reactInstance on
181+
// the JS thread, so checking _valid and dereferencing have to happen as one step.
182+
std::lock_guard<std::mutex> lock(_invalidationMutex);
183+
if (!_valid || !_reactInstance) {
184+
return;
177185
}
186+
_reactInstance->callFunctionOnModule(moduleNameString, methodString, std::move(dynamicArgs));
178187
}
179188

180189
- (void)invalidate

0 commit comments

Comments
 (0)