fix 5.2 audit findings on Windows: F-PROC-1 injection, F-MEM-5 UAF, F-PROC-2 restart race, F-PROC-3, F5, F6

This commit is contained in:
2026-08-16 12:29:42 +07:00
parent 54b7a7a6ac
commit 761b48e41f
9 changed files with 134 additions and 69 deletions
@@ -79,6 +79,18 @@ public:
INativeInstrument* get(uint32_t channel);
// F-MEM-5 (audit 5.2): get() releases mu_ before the caller derefs, so a
// worker thread's assign()/unload() can destroy the instance mid-use.
// has() is a safe existence check; withInstrument() runs code against the
// instance while mu_ is still held. Use these from non-Ui threads.
bool has(uint32_t channel);
template <typename F>
auto withInstrument(uint32_t channel, F&& fn) -> decltype(fn((INativeInstrument*)nullptr)) {
std::lock_guard<std::mutex> lock(mu_);
auto it = channels_.find(channel);
return fn(it == channels_.end() ? nullptr : it->second.get());
}
// Real-time MIDI dispatch (audio loop thread). Each call holds mu_ for the
// WHOLE call — lookup + reloading check + instrument call under one lock —
// so a worker thread's assign()/unload() can never swap the map and destroy