Checklist
Description
L2pingService::run() reads an L2ping object's status_ while that
object's worker thread can update it. The read and writes are not
synchronized, so the service can encounter a C++ data race.
The service's main thread calls buildDeviceList(), which starts an
L2ping worker thread for each newly found device. After the function
returns, the main thread calls object->getStatus() without waiting for
the worker to finish.
Relevant locations:
system/autoware_bluetooth_monitor/service/l2ping_service.cpp:139-145:
the main thread takes a status snapshot.
system/autoware_bluetooth_monitor/service/l2ping_service.cpp:249-252:
buildDeviceList() starts the worker thread.
system/autoware_bluetooth_monitor/service/l2ping.cpp:69-73:
L2ping::run() creates the std::thread.
system/autoware_bluetooth_monitor/service/l2ping.cpp:60-62,136:
the worker writes device information and round-trip time.
system/autoware_bluetooth_monitor/service/l2ping.cpp:170-188:
the worker writes status fields; getStatus() copies the same object.
Expected behavior
The service should return a consistent snapshot of each device's status
while the ping worker continues running.
Actual behavior
From source inspection, getStatus() copies status_ without a lock.
The worker updates fields of the same non-atomic object, including
std::string fields, without a lock. These accesses can be concurrent,
which is undefined behavior in C++. No runtime failure has been
observed or reproduced for this report.
Steps to reproduce
- Pair a Bluetooth device and include its address in the monitor's
addresses parameter. Ensure bluetoothctl paired-devices lists it.
- Start
l2ping_service and launch autoware_bluetooth_monitor as
described in the package README. The service starts an L2ping
worker for the matching device.
- Allow the monitor to request status repeatedly while the worker
continues to ping the device. Each successful request reaches
L2pingService::run() and calls object->getStatus().
- To detect the race dynamically, run the service under ThreadSanitizer
and inspect concurrent accesses to L2ping::status_. The exact
scheduling, and whether a visible failure occurs, may vary.
Versions
- Autoware Universe commit:
2e7f15416f75031ee13532417b9ab452eba94990
Possible causes
No response
Additional context
No response
Checklist
Description
L2pingService::run()reads anL2pingobject'sstatus_while thatobject's worker thread can update it. The read and writes are not
synchronized, so the service can encounter a C++ data race.
The service's main thread calls
buildDeviceList(), which starts anL2pingworker thread for each newly found device. After the functionreturns, the main thread calls
object->getStatus()without waiting forthe worker to finish.
Relevant locations:
system/autoware_bluetooth_monitor/service/l2ping_service.cpp:139-145:the main thread takes a status snapshot.
system/autoware_bluetooth_monitor/service/l2ping_service.cpp:249-252:buildDeviceList()starts the worker thread.system/autoware_bluetooth_monitor/service/l2ping.cpp:69-73:L2ping::run()creates thestd::thread.system/autoware_bluetooth_monitor/service/l2ping.cpp:60-62,136:the worker writes device information and round-trip time.
system/autoware_bluetooth_monitor/service/l2ping.cpp:170-188:the worker writes status fields;
getStatus()copies the same object.Expected behavior
The service should return a consistent snapshot of each device's status
while the ping worker continues running.
Actual behavior
From source inspection,
getStatus()copiesstatus_without a lock.The worker updates fields of the same non-atomic object, including
std::stringfields, without a lock. These accesses can be concurrent,which is undefined behavior in C++. No runtime failure has been
observed or reproduced for this report.
Steps to reproduce
addressesparameter. Ensurebluetoothctl paired-deviceslists it.l2ping_serviceand launchautoware_bluetooth_monitorasdescribed in the package README. The service starts an
L2pingworker for the matching device.
continues to ping the device. Each successful request reaches
L2pingService::run()and callsobject->getStatus().and inspect concurrent accesses to
L2ping::status_. The exactscheduling, and whether a visible failure occurs, may vary.
Versions
2e7f15416f75031ee13532417b9ab452eba94990Possible causes
No response
Additional context
No response