Hello Subversion Developers,

Following up on our recent investigation into svnserve (1.14.x) crashes in
high-load environments (linked to our report on SVN-4817), we have
identified a third, distinct race condition in the logging implementation
in subversion/svnserve/logger.c.

Problem Description: In log_message(), the code performs memory allocations
from the shared logger->pool before acquiring the serialization mutex
(logger->mutex).

When multiple threads encounter errors simultaneously (a frequent
occurrence during network congestion bursts), they attempt concurrent
allocations from the same APR pool, leading to internal corruption and a
SIGSEGV during the subsequent svn_pool_clear.

Proposed Fix: The attached/in-lined patch moves the apr_palloc and
svn_time_to_cstring calls inside the mutex lock.

We have verified this fix in production; it has successfully stabilized our
fleet under the same load conditions that previously triggered the crashes.

--
Eric Boehm
Broadcom

Attachment: svnserve_log_concurrency.patch
Description: Binary data

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

Reply via email to