Skip to content

fix(engine/windows): keep tooltip position rect alive - fix use after free#188476

Merged
mattkae merged 5 commits into
flutter:masterfrom
richyo-codes:fix-windows-tooltip-position-uaf
Jul 6, 2026
Merged

fix(engine/windows): keep tooltip position rect alive - fix use after free#188476
mattkae merged 5 commits into
flutter:masterfrom
richyo-codes:fix-windows-tooltip-position-uaf

Conversation

@richyo-codes

Copy link
Copy Markdown
Contributor

Pointer to Tooltip Position Rectangle was being free'd, then used after free.

Now using a scoped deleter until after the constrained-size check has read it.

Pre-launch Checklist

If you need help, consider asking for advice on the #hackers-new channel on Discord.

If this change needs to override an active code freeze, provide a comment explaining why. The code freeze workflow can be overridden by code reviewers. See pinned issues for any active code freezes with guidance.

Note: The Flutter team is currently trialing the use of Gemini Code Assist for GitHub. Comments from the gemini-code-assist bot should not be taken as authoritative feedback from the Flutter team. If you find its comments useful you can update your code accordingly, but if you are unsure or disagree with the feedback, please feel free to wait for a Flutter team member's review for guidance on which automated comments should be addressed.

@richyo-codes
richyo-codes requested a review from a team as a code owner June 24, 2026 03:23
@flutter-dashboard

Copy link
Copy Markdown

It looks like this pull request may not have tests. Please make sure to add tests or get an explicit test exemption before merging.

If you are not sure if you need tests, consider this rule of thumb: the purpose of a test is to make sure someone doesn't accidentally revert the fix. Ask yourself, is there anything in your PR that you feel it is important we not accidentally revert back to how it was before your fix?

Reviewers: Read the Tree Hygiene page and make sure this patch meets those guidelines before LGTMing. If you believe this PR qualifies for a test exemption, contact "@test-exemption-reviewer" in the #hackers channel in Discord (don't just cc them here, they won't see it!). The test exemption team is a small volunteer group, so all reviewers should feel empowered to ask for tests, without delegating that responsibility entirely to the test exemption group.

@github-actions github-actions Bot added engine flutter/engine related. See also e: labels. platform-windows Building on or for Windows specifically a: desktop Running on desktop team-windows Owned by the Windows platform team labels Jun 24, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates host_window_tooltip.cc to manage the lifetime of the WindowRect returned by get_position_callback_ using std::unique_ptr with a custom free deleter. Feedback indicates that if get_position_callback_ returns nullptr, dereferencing rect will cause a null pointer dereference, and suggests adding a null check to handle this case safely.

Comment thread engine/src/flutter/shell/platform/windows/host_window_tooltip.cc
richyo-codes and others added 2 commits June 24, 2026 04:39
Match the popup window positioning path by owning the callback result with a scoped deleter until after the constrained-size check has read it.
Since the function is named HostWindowPopup::UpdatePosition and we can't update the position without the position rect. I'm going to approve Gemini's suggested fix of returning early using a guard.

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
@richyo-codes
richyo-codes force-pushed the fix-windows-tooltip-position-uaf branch from a250a9f to b31d8ef Compare June 24, 2026 08:39
@mattkae mattkae added the CICD Run CI/CD label Jun 24, 2026
mattkae
mattkae previously approved these changes Jun 24, 2026

@mattkae mattkae left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yup, that seems like a reasonable improvement. Thanks for the contribution!

loic-sharma
loic-sharma previously approved these changes Jun 24, 2026

@loic-sharma loic-sharma left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for fixing this!

@richyo-codes
richyo-codes dismissed stale reviews from loic-sharma and mattkae via fe5d0c4 June 25, 2026 20:32
@github-actions github-actions Bot removed the CICD Run CI/CD label Jun 25, 2026
@richyo-codes

Copy link
Copy Markdown
Contributor Author

There was a conflict from a refactor / variable name change in adbaad4 that I resolved via webui

@loic-sharma loic-sharma added the CICD Run CI/CD label Jun 26, 2026

@loic-sharma loic-sharma left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-LGTM!

@flutter-dashboard flutter-dashboard Bot removed the CICD Run CI/CD label Jun 30, 2026
@loic-sharma loic-sharma added the CICD Run CI/CD label Jun 30, 2026
@loic-sharma

Copy link
Copy Markdown
Member

The Google tests timed out, I restarted them.

@flutter-dashboard flutter-dashboard Bot removed the CICD Run CI/CD label Jul 1, 2026
@loic-sharma loic-sharma added the CICD Run CI/CD label Jul 1, 2026
@richyo-codes

Copy link
Copy Markdown
Contributor Author

Is there anything else left to do? Can this be merged now?

@mattkae
mattkae added this pull request to the merge queue Jul 6, 2026
@mattkae

mattkae commented Jul 6, 2026

Copy link
Copy Markdown
Contributor

Is there anything else left to do? Can this be merged now?

Added to the queue! Should merge shortly :)

Merged via the queue into flutter:master with commit fc1edec Jul 6, 2026
204 checks passed
Rusino pushed a commit to Rusino/flutter that referenced this pull request Jul 7, 2026
… free (flutter#188476)

Pointer to Tooltip Position Rectangle was being free'd, then used after
free.

Now using a scoped deleter until after the constrained-size check has
read it.

## Pre-launch Checklist

- [X] I read the [Contributor Guide] and followed the process outlined
there for submitting PRs.
- [X] I read the [AI contribution guidelines] and understand my
responsibilities, or I am not using AI tools.
- [X] I read the [Tree Hygiene] wiki page, which explains my
responsibilities.
- [X] I read and followed the [Flutter Style Guide], including [Features
we expect every widget to implement].
- [X] I signed the [CLA].
- [X] I listed at least one issue that this PR fixes in the description
above.
- [X] I updated/added relevant documentation (doc comments with `///`).
- [X] I added new tests to check the change I am making, or this PR is
[test-exempt].
- [X] I followed the [breaking change policy] and added [Data Driven
Fixes] where supported.
- [X] All existing and new tests are passing.

If you need help, consider asking for advice on the #hackers-new channel
on [Discord].

If this change needs to override an active code freeze, provide a
comment explaining why. The code freeze workflow can be overridden by
code reviewers. See pinned issues for any active code freezes with
guidance.

**Note**: The Flutter team is currently trialing the use of [Gemini Code
Assist for
GitHub](https://developers.google.com/gemini-code-assist/docs/review-github-code).
Comments from the `gemini-code-assist` bot should not be taken as
authoritative feedback from the Flutter team. If you find its comments
useful you can update your code accordingly, but if you are unsure or
disagree with the feedback, please feel free to wait for a Flutter team
member's review for guidance on which automated comments should be
addressed.

<!-- Links -->
[Contributor Guide]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#overview
[AI contribution guidelines]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#ai-contribution-guidelines
[Tree Hygiene]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md
[test-exempt]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#tests
[Flutter Style Guide]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md
[Features we expect every widget to implement]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md#features-we-expect-every-widget-to-implement
[CLA]: https://cla.developers.google.com/
[flutter/tests]: https://github.com/flutter/tests
[breaking change policy]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#handling-breaking-changes
[Discord]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Chat.md
[Data Driven Fixes]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Data-driven-Fixes.md

---------

Co-authored-by: gemini-code-assist[bot] <176961590+gemini-code-assist[bot]@users.noreply.github.com>
Co-authored-by: Loïc Sharma <[email protected]>
auto-submit Bot pushed a commit to flutter/packages that referenced this pull request Jul 8, 2026
…12137)

Manual roll Flutter from 6995038d96ef to 91939cc4db78 (48 revisions)

Manual roll requested by [email protected]

flutter/flutter@6995038...91939cc

2026-07-07 [email protected] Roll Skia from 80ae1deed9ed to 075fbe4778d9 (6 revisions) (flutter/flutter#189067)
2026-07-07 [email protected] Bump customer testing version for new registrants (flutter/flutter#189070)
2026-07-07 [email protected] Roll Packages from fc00ceb to 92525f5 (2 revisions) (flutter/flutter#189069)
2026-07-07 [email protected] fix android semantics integration test hangs due to postframe callback (flutter/flutter#189043)
2026-07-07 [email protected] Bump goldctl (flutter/flutter#189030)
2026-07-07 [email protected] Roll Skia from 71db7c06c5fe to 80ae1deed9ed (2 revisions) (flutter/flutter#189060)
2026-07-07 [email protected] Collect analytics on AI agent usage (flutter/flutter#187630)
2026-07-07 [email protected] Roll Skia from 125a76cc4cf3 to 71db7c06c5fe (4 revisions) (flutter/flutter#189054)
2026-07-07 [email protected] Roll Dart SDK from 70577d6f2bba to c648e3429d76 (1 revision) (flutter/flutter#189052)
2026-07-07 [email protected] Fix RenderSliverPadding setter assertion (flutter/flutter#187353)
2026-07-07 [email protected] Roll Skia from 2dde156aec3e to 125a76cc4cf3 (3 revisions) (flutter/flutter#189037)
2026-07-07 [email protected] Explain asynchronous causes in the setState() called after dispose() error (flutter/flutter#187294)
2026-07-07 [email protected] Roll Skia from 7dccd1e79a5b to 2dde156aec3e (2 revisions) (flutter/flutter#189035)
2026-07-07 [email protected] Add `STRING_CATALOG_GENERATE_SYMBOLS = YES;` (flutter/flutter#188163)
2026-07-07 [email protected] Print warnings on Intel Macs / targeting Intel Macs (flutter/flutter#188835)
2026-07-07 [email protected] Roll Dart SDK from 4c03f64b19f6 to 70577d6f2bba (1 revision) (flutter/flutter#189031)
2026-07-07 [email protected] Roll Fuchsia Linux SDK from n1Lm2Z4DZkfC3bwj5... to 7RjQJBW3m-3Jl-7jr... (flutter/flutter#189032)
2026-07-06 [email protected] Recommend `OverlayPortal.overlayChildLayoutBuilder` over Target-Follower (flutter/flutter#188894)
2026-07-06 [email protected] Sync CHANGELOG.md from stable (flutter/flutter#189025)
2026-07-06 [email protected] Rename preferredSize to size and preferredConstraints to constraints in the windowing API (flutter/flutter#189017)
2026-07-06 [email protected] Skip locked issues in no-response check (flutter/flutter#188950)
2026-07-06 [email protected] Fix potential race condtion in android_semantics_integration_test (flutter/flutter#188830)
2026-07-06 [email protected] ci: udpate wait-for-engine-build composite action to cocoon (flutter/flutter#189020)
2026-07-06 [email protected] Roll Skia from 2b55eed5500d to 7dccd1e79a5b (3 revisions) (flutter/flutter#189021)
2026-07-06 [email protected] [AGP 9] Update Flutter Template Versions (flutter/flutter#188762)
2026-07-06 [email protected] fix(engine/windows): keep tooltip position rect alive - fix use after free (flutter/flutter#188476)
2026-07-06 [email protected] [Tool] Fix null check operator crash in currentPackageConfig (flutter/flutter#188454)
2026-07-06 [email protected] [Tool] Gracefully handle WDAC/AppLocker blocks for impellerc (flutter/flutter#188452)
2026-07-06 [email protected] [flutter_tools] Throw DaemonException if app fails to start early (flutter/flutter#188921)
2026-07-06 [email protected] Roll Dart SDK from ce7a2567eb59 to 4c03f64b19f6 (2 revisions) (flutter/flutter#189015)
2026-07-06 [email protected] [flutter_tools, engine] Add --disable-service-origin-check option to disable VM service origin checks (flutter/flutter#188745)
2026-07-06 [email protected] [flutter_tools] Fix test flakiness in widget_preview_detection_test.dart (flutter/flutter#188922)
2026-07-06 [email protected] Roll pub packages (flutter/flutter#189009)
2026-07-06 [email protected] Roll Skia from c0e2b9667d91 to 2b55eed5500d (1 revision) (flutter/flutter#189006)
2026-07-06 [email protected] Roll Packages from 2fbe873 to fc00ceb (1 revision) (flutter/flutter#189007)
2026-07-06 [email protected] Roll Skia from b68567542f81 to c0e2b9667d91 (1 revision) (flutter/flutter#189004)
2026-07-06 [email protected] Fixing multiline GetBoxesForRange (flutter/flutter#188803)
2026-07-06 [email protected] Roll Skia from e15ea7a4b927 to b68567542f81 (4 revisions) (flutter/flutter#189000)
2026-07-06 [email protected] Roll Skia from 79806692425f to e15ea7a4b927 (2 revisions) (flutter/flutter#188992)
2026-07-06 [email protected] Roll Skia from 2826ae6dc649 to 79806692425f (1 revision) (flutter/flutter#188991)
2026-07-06 [email protected] Roll Skia from 7f99eee20fd6 to 2826ae6dc649 (1 revision) (flutter/flutter#188990)
2026-07-06 [email protected] Add debugPaintFocusBoxes (flutter/flutter#188288)
2026-07-05 [email protected] Roll Fuchsia Linux SDK from bkK6BLiZDRnE7AQQj... to n1Lm2Z4DZkfC3bwj5... (flutter/flutter#188989)
2026-07-05 [email protected] Roll Skia from 75a4bf6706bd to 7f99eee20fd6 (2 revisions) (flutter/flutter#188988)
...
kalyujniy pushed a commit to brickit-app/camera that referenced this pull request Jul 8, 2026
…lutter#12137)

Manual roll Flutter from 6995038d96ef to 91939cc4db78 (48 revisions)

Manual roll requested by [email protected]

flutter/flutter@6995038...91939cc

2026-07-07 [email protected] Roll Skia from 80ae1deed9ed to 075fbe4778d9 (6 revisions) (flutter/flutter#189067)
2026-07-07 [email protected] Bump customer testing version for new registrants (flutter/flutter#189070)
2026-07-07 [email protected] Roll Packages from fc00ceb to 92525f5 (2 revisions) (flutter/flutter#189069)
2026-07-07 [email protected] fix android semantics integration test hangs due to postframe callback (flutter/flutter#189043)
2026-07-07 [email protected] Bump goldctl (flutter/flutter#189030)
2026-07-07 [email protected] Roll Skia from 71db7c06c5fe to 80ae1deed9ed (2 revisions) (flutter/flutter#189060)
2026-07-07 [email protected] Collect analytics on AI agent usage (flutter/flutter#187630)
2026-07-07 [email protected] Roll Skia from 125a76cc4cf3 to 71db7c06c5fe (4 revisions) (flutter/flutter#189054)
2026-07-07 [email protected] Roll Dart SDK from 70577d6f2bba to c648e3429d76 (1 revision) (flutter/flutter#189052)
2026-07-07 [email protected] Fix RenderSliverPadding setter assertion (flutter/flutter#187353)
2026-07-07 [email protected] Roll Skia from 2dde156aec3e to 125a76cc4cf3 (3 revisions) (flutter/flutter#189037)
2026-07-07 [email protected] Explain asynchronous causes in the setState() called after dispose() error (flutter/flutter#187294)
2026-07-07 [email protected] Roll Skia from 7dccd1e79a5b to 2dde156aec3e (2 revisions) (flutter/flutter#189035)
2026-07-07 [email protected] Add `STRING_CATALOG_GENERATE_SYMBOLS = YES;` (flutter/flutter#188163)
2026-07-07 [email protected] Print warnings on Intel Macs / targeting Intel Macs (flutter/flutter#188835)
2026-07-07 [email protected] Roll Dart SDK from 4c03f64b19f6 to 70577d6f2bba (1 revision) (flutter/flutter#189031)
2026-07-07 [email protected] Roll Fuchsia Linux SDK from n1Lm2Z4DZkfC3bwj5... to 7RjQJBW3m-3Jl-7jr... (flutter/flutter#189032)
2026-07-06 [email protected] Recommend `OverlayPortal.overlayChildLayoutBuilder` over Target-Follower (flutter/flutter#188894)
2026-07-06 [email protected] Sync CHANGELOG.md from stable (flutter/flutter#189025)
2026-07-06 [email protected] Rename preferredSize to size and preferredConstraints to constraints in the windowing API (flutter/flutter#189017)
2026-07-06 [email protected] Skip locked issues in no-response check (flutter/flutter#188950)
2026-07-06 [email protected] Fix potential race condtion in android_semantics_integration_test (flutter/flutter#188830)
2026-07-06 [email protected] ci: udpate wait-for-engine-build composite action to cocoon (flutter/flutter#189020)
2026-07-06 [email protected] Roll Skia from 2b55eed5500d to 7dccd1e79a5b (3 revisions) (flutter/flutter#189021)
2026-07-06 [email protected] [AGP 9] Update Flutter Template Versions (flutter/flutter#188762)
2026-07-06 [email protected] fix(engine/windows): keep tooltip position rect alive - fix use after free (flutter/flutter#188476)
2026-07-06 [email protected] [Tool] Fix null check operator crash in currentPackageConfig (flutter/flutter#188454)
2026-07-06 [email protected] [Tool] Gracefully handle WDAC/AppLocker blocks for impellerc (flutter/flutter#188452)
2026-07-06 [email protected] [flutter_tools] Throw DaemonException if app fails to start early (flutter/flutter#188921)
2026-07-06 [email protected] Roll Dart SDK from ce7a2567eb59 to 4c03f64b19f6 (2 revisions) (flutter/flutter#189015)
2026-07-06 [email protected] [flutter_tools, engine] Add --disable-service-origin-check option to disable VM service origin checks (flutter/flutter#188745)
2026-07-06 [email protected] [flutter_tools] Fix test flakiness in widget_preview_detection_test.dart (flutter/flutter#188922)
2026-07-06 [email protected] Roll pub packages (flutter/flutter#189009)
2026-07-06 [email protected] Roll Skia from c0e2b9667d91 to 2b55eed5500d (1 revision) (flutter/flutter#189006)
2026-07-06 [email protected] Roll Packages from 2fbe873 to fc00ceb (1 revision) (flutter/flutter#189007)
2026-07-06 [email protected] Roll Skia from b68567542f81 to c0e2b9667d91 (1 revision) (flutter/flutter#189004)
2026-07-06 [email protected] Fixing multiline GetBoxesForRange (flutter/flutter#188803)
2026-07-06 [email protected] Roll Skia from e15ea7a4b927 to b68567542f81 (4 revisions) (flutter/flutter#189000)
2026-07-06 [email protected] Roll Skia from 79806692425f to e15ea7a4b927 (2 revisions) (flutter/flutter#188992)
2026-07-06 [email protected] Roll Skia from 2826ae6dc649 to 79806692425f (1 revision) (flutter/flutter#188991)
2026-07-06 [email protected] Roll Skia from 7f99eee20fd6 to 2826ae6dc649 (1 revision) (flutter/flutter#188990)
2026-07-06 [email protected] Add debugPaintFocusBoxes (flutter/flutter#188288)
2026-07-05 [email protected] Roll Fuchsia Linux SDK from bkK6BLiZDRnE7AQQj... to n1Lm2Z4DZkfC3bwj5... (flutter/flutter#188989)
2026-07-05 [email protected] Roll Skia from 75a4bf6706bd to 7f99eee20fd6 (2 revisions) (flutter/flutter#188988)
...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

a: desktop Running on desktop CICD Run CI/CD engine flutter/engine related. See also e: labels. platform-windows Building on or for Windows specifically team-windows Owned by the Windows platform team

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants