Skip to content

fix(scopes): apply withScope data to events in globalHubMode - #6004

Open
markushi wants to merge 2 commits into
mainfrom
fix/with-scope-global-hub-mode
Open

fix(scopes): apply withScope data to events in globalHubMode#6004
markushi wants to merge 2 commits into
mainfrom
fix/with-scope-global-hub-mode

Conversation

@markushi

Copy link
Copy Markdown
Member

📜 Description

Sentry.withScope forks the current scope and makes it current, but Sentry.getCurrentScopes short-circuited to rootScopes when globalHubMode was enabled, so the fork was never read back. Everything set inside the callback was silently dropped.

Honour scopes that were explicitly made current, as long as they descend from the current rootScopes. Implicit forking stays suppressed. pushScope and popScope remain no-ops, since they are unbalanced.

💡 Motivation and Context

globalHubMode is on by default on Android, so this affected all Android users since 8.0.0.

💚 How did you test it?

Unit tests in SentryTest.kt, run for globalHubMode both true and false. Verified they fail without the fix.

📝 Checklist

  • I added GH Issue ID & Linear ID
  • I added tests to verify the changes.
  • No new PII added or SDK only sends newly added PII if sendDefaultPII is enabled.
  • I updated the docs if needed.
  • I updated the wizard if needed.
  • Review from the native team if needed.
  • No breaking change or entry added to the changelog.
  • No breaking change for hybrid SDKs or communicated to hybrid SDKs.
  • Public API changes reviewed by another Mobile SDK team member or implemented according to the develop docs spec.

🔮 Next steps

Hybrid SDKs relying on withScope being a no-op under globalHubMode should be made aware.

🤖 Generated with Claude Code

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@linear-code

linear-code Bot commented Aug 26, 2026

Copy link
Copy Markdown

JAVA-489

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@sentry

sentry Bot commented Aug 26, 2026

Copy link
Copy Markdown

📲 Install Builds

Android

🔗 App Name App ID Version Configuration
SDK Size io.sentry.tests.size 8.53.0 (1) release

⚙️ sentry-android Build Distribution Settings

@markushi
markushi marked this pull request as ready for review August 26, 2026 10:05
Comment on lines +122 to 125
if (scopes != null && !scopes.isNoOp() && rootScopes.isAncestorOf(scopes)) {
return scopes;
}
return rootScopes;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: A TOCTOU race condition in getCurrentScopes() can cause it to return a stale Scopes object if Sentry.init() is called concurrently.
Severity: LOW

Suggested Fix

To prevent the race condition, read the volatile variable rootScopes into a local variable at the start of the method. Use this local variable for both the isAncestorOf check and the subsequent return statement to ensure the same object is used for both operations.

Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.

Location: sentry/src/main/java/io/sentry/Sentry.java#L122-L125

Potential issue: In `Sentry.getCurrentScopes()`, when `globalHubMode` is enabled, a
time-of-check to time-of-use (TOCTOU) race condition exists. The method reads the
`volatile` field `rootScopes` to perform a check with `isAncestorOf`, and then reads it
again for the return statement. If another thread calls `Sentry.init()` between these
two reads, `rootScopes` can be reassigned. This can cause `getCurrentScopes()` to return
a stale `Scopes` object from a previous SDK initialization, which is inconsistent with
the newly initialized SDK state. While the practical impact is low due to the narrow
race window and rare re-initialization, it is a concurrency flaw.

Did we get this right? 👍 / 👎 to inform future reviews.

@markushi markushi added the deep-dive PR needs a thorough review of design, behavior, and edge cases label Aug 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

deep-dive PR needs a thorough review of design, behavior, and edge cases

Projects

None yet

Development

Successfully merging this pull request may close these issues.

HTTP request payload and response body not captured in error events

1 participant