Skip to content

memory leak bug #372

Description

@LoveUforever2018

If you'd like to put out an incentive for fixing this bug, you can do so at https://issuehunt.io/r/bk138/droidVNC-NG

Describe the bug

There is a memory leak bug in method: JNIEXPORT jboolean JNICALL Java_net_christianbeier_droidvnc_1ng_MainService_vncUpdateFramebuffer()
It will cause the client memory to fail to be released normally, When the method: void
rfbClientConnectionGone(rfbClientPtr cl) is executed in the file rfbserver.c

I recommend that such code below should not be allowed to be submitted in the future:

  /* Lock out client reads. */
    rfbClientIteratorPtr iterator;
    rfbClientPtr cl;
    iterator = rfbGetClientIterator(theScreen);
    while ((cl = rfbClientIteratorNext(iterator))) {
        LOCK(cl->sendMutex);
    }
    rfbReleaseClientIterator(iterator);

    /* Swap frame buffers. */
    char *tmp = theScreen->frameBuffer;
    theScreen->frameBuffer = backBuffer;
    backBuffer = tmp;

    iterator = rfbGetClientIterator(theScreen);
    while ((cl = rfbClientIteratorNext(iterator))) {
        UNLOCK(cl->sendMutex);
    }
    rfbReleaseClientIterator(iterator);

cl->sendMutex is not allowed to LOCK and UNLOCK in deferent iterator code loop, because when you LOCK it in the first iterator loop, if 'cl' is removed from client list. then the second iterator cant UNLOCK it. it will cause the method: void
rfbClientConnectionGone(rfbClientPtr cl) can't execute LOCK(cl->sendMutex) successfully. and the code will stop here forever.

I have been solved this bug in my branch. I want this report can help droidVNC-NG become more and more reliable, thank you for you build the project for us.
To Reproduce

Expected Behavior

The client memory should be released whenever client disconnected
Logs/Backtraces

Your environment (please complete the following information):

  • droidVNC-NG version:2.19.0
  • Android version:35
  • Client-side OS and version:android 12
  • VNC client and version:noVNC(463c39e)

Additional context

I solved this bug by add a client temp list buffer(clLockedList) to record these clients that excuted LOCK(cl->sendMutex), and then use this temp buffer to execute UNLOCK(clLockedList[i]->sendMutex) where i is 0 to recorded client number.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions