fix(scopes): apply withScope data to events in globalHubMode - #6004
Open
markushi wants to merge 2 commits into
Open
fix(scopes): apply withScope data to events in globalHubMode#6004markushi wants to merge 2 commits into
markushi wants to merge 2 commits into
Conversation
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
📲 Install BuildsAndroid
|
markushi
marked this pull request as ready for review
August 26, 2026 10:05
markushi
requested review from
0xadam-brown,
adinauer,
romtsn and
runningcode
as code owners
August 26, 2026 10:05
Comment on lines
+122
to
125
| if (scopes != null && !scopes.isNoOp() && rootScopes.isAncestorOf(scopes)) { | ||
| return scopes; | ||
| } | ||
| return rootScopes; |
There was a problem hiding this comment.
Bug: A TOCTOU race condition in getCurrentScopes() can cause it to return a stale Scopes object if Sentry.init() is called concurrently.
Severity: LOW
Suggested Fix
To prevent the race condition, read the volatile variable rootScopes into a local variable at the start of the method. Use this local variable for both the isAncestorOf check and the subsequent return statement to ensure the same object is used for both operations.
Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent. Verify if this is a real issue. If it is, propose a fix; if not, explain why it's
not valid.
Location: sentry/src/main/java/io/sentry/Sentry.java#L122-L125
Potential issue: In `Sentry.getCurrentScopes()`, when `globalHubMode` is enabled, a
time-of-check to time-of-use (TOCTOU) race condition exists. The method reads the
`volatile` field `rootScopes` to perform a check with `isAncestorOf`, and then reads it
again for the return statement. If another thread calls `Sentry.init()` between these
two reads, `rootScopes` can be reassigned. This can cause `getCurrentScopes()` to return
a stale `Scopes` object from a previous SDK initialization, which is inconsistent with
the newly initialized SDK state. While the practical impact is low due to the narrow
race window and rare re-initialization, it is a concurrency flaw.
Did we get this right? 👍 / 👎 to inform future reviews.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
📜 Description
Sentry.withScopeforks the current scope and makes it current, butSentry.getCurrentScopesshort-circuited torootScopeswhenglobalHubModewas enabled, so the fork was never read back. Everything set inside the callback was silently dropped.Honour scopes that were explicitly made current, as long as they descend from the current
rootScopes. Implicit forking stays suppressed.pushScopeandpopScoperemain no-ops, since they are unbalanced.💡 Motivation and Context
globalHubModeis on by default on Android, so this affected all Android users since 8.0.0.💚 How did you test it?
Unit tests in
SentryTest.kt, run forglobalHubModebothtrueandfalse. Verified they fail without the fix.📝 Checklist
sendDefaultPIIis enabled.🔮 Next steps
Hybrid SDKs relying on
withScopebeing a no-op underglobalHubModeshould be made aware.🤖 Generated with Claude Code