Skip to content

Potential Use after Free in PrivacyGuard_jni.cpp #1334

Description

@chrdavis

Looks like use after free for whatever the char* is pointing to in the InitializationConfiguration

2025-03-09T03:08:06.0300303Z ../../third_party/oneds_sdk/public/lib/jni/PrivacyGuard_jni.cpp:64:40: error: object backing the pointer config.NotificationEventName will be destroyed at the end of the full-expression [-Werror,-Wdangling-assignment-gsl]
2025-03-09T03:08:06.0300589Z 64 | config.NotificationEventName = JStringToStdString(env, NotificationEventName).c_str();
2025-03-09T03:08:06.0300768Z | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
2025-03-09T03:08:06.0301025Z ../../third_party/oneds_sdk/public/lib/jni/PrivacyGuard_jni.cpp:68:55: error: object backing the pointer config.SemanticContextNotificationEventName will be destroyed at the end of the full-expression [-Werror,-Wdangling-assignment-gsl]
2025-03-09T03:08:06.0301322Z 68 | config.SemanticContextNotificationEventName = JStringToStdString(env, SemanticContextEventName).c_str();
2025-03-09T03:08:06.0301514Z | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
2025-03-09T03:08:06.0301761Z ../../third_party/oneds_sdk/public/lib/jni/PrivacyGuard_jni.cpp:72:35: error: object backing the pointer config.SummaryEventName will be destroyed at the end of the full-expression [-Werror,-Wdangling-assignment-gsl]
2025-03-09T03:08:06.0302026Z 72 | config.SummaryEventName = JStringToStdString(env, SummaryEventName).c_str();
2025-03-09T03:08:06.0302187Z | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
2025-03-09T03:08:06.0302414Z ../../third_party/oneds_sdk/public/lib/jni/PrivacyGuard_jni.cpp:117:40: error: object backing the pointer config.NotificationEventName will be destroyed at the end of the full-expression [-Werror,-Wdangling-assignment-gsl]
2025-03-09T03:08:06.0302663Z 117 | config.NotificationEventName = JStringToStdString(env, NotificationEventName).c_str();
2025-03-09T03:08:06.0302824Z | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
2025-03-09T03:08:06.0303057Z ../../third_party/oneds_sdk/public/lib/jni/PrivacyGuard_jni.cpp:121:55: error: object backing the pointer config.SemanticContextNotificationEventName will be destroyed at the end of the full-expression [-Werror,-Wdangling-assignment-gsl]
2025-03-09T03:08:06.0303328Z 121 | config.SemanticContextNotificationEventName = JStringToStdString(env, SemanticContextEventName).c_str();
2025-03-09T03:08:06.0303567Z | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
2025-03-09T03:08:06.0304070Z ../../third_party/oneds_sdk/public/lib/jni/PrivacyGuard_jni.cpp:125:35: error: object backing the pointer config.SummaryEventName will be destroyed at the end of the full-expression [-Werror,-Wdangling-assignment-gsl]
2025-03-09T03:08:06.0304558Z 125 | config.SummaryEventName = JStringToStdString(env, SummaryEventName).c_str();
2025-03-09T03:08:06.0304829Z | ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
2025-03-09T03:08:06.0304958Z 6 errors generated.

Pinned by bmehta001

Activity

  1. changed the title [-]rivacyGuard_jni.cpp:68:55: error: object backing the pointer config.SemanticContextNotificationEventName will be destroyed at the end of the full-expression [-Werror,-Wdangling-assignment-gsl][/-] [+]PrivacyGuard_jni.cpp:68:55: error: object backing the pointer config.SemanticContextNotificationEventName will be destroyed at the end of the full-expression [-Werror,-Wdangling-assignment-gsl][/+] on Mar 9, 2025
  2. changed the title [-]PrivacyGuard_jni.cpp:68:55: error: object backing the pointer config.SemanticContextNotificationEventName will be destroyed at the end of the full-expression [-Werror,-Wdangling-assignment-gsl][/-] [+]Potential Use after Free in PrivacyGuard_jni.cpp[/+] on Mar 11, 2025
  3. bmehta001 commented on Sep 24, 2026

    @bmehta001
    Contributor

    Hi Chris Davis (@chrdavis), Addressed in #1520: JNI Privacy Guard initialization now keeps backing strings alive while constructing the guard instead of assigning c_str() pointers from temporary strings. #1525 further hardens custom event-name storage and initialization lifetime. Closing as fixed; please reopen if the dangling-pointer diagnostic persists on current main.

  4. self-assigned this
    on Sep 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

bugSomething isn't workinghelp wantedExtra attention is needed

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions