datatheorem / datatheorem/TrustKit

Crash in TrustKit initWithConfiguration:sharedContainerIdentifier:isSingleton:

Open
#313 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Objective-C
Stars
2.1k
Forks
381
PR merge metrics
No merged PRs in 30d

Description

No steps and cannot reproduce in test apps but we are seeing this in production. Seems most of the devices & most of the iOS versions.

Crashed: com.datatheorem.trustkit.reporterqueue
0 libobjc.A.dylib 0x2820 objc_msgSend + 32
1 XXX 0x3a6eb8 __72-[TrustKit initWithConfiguration:sharedContainerIdentifier:isSingleton:]_block_invoke_2 + 197 (TrustKit.m:197)
2 XXX 0x3a6524 __49-[TSKPinningValidator evaluateTrust:forHostname:]_block_invoke + 182 (TSKPinningValidator.m:182)
3 libdispatch.dylib 0x2320 _dispatch_call_block_and_release + 32
4 libdispatch.dylib 0x3eac _dispatch_client_callout + 20
5 libdispatch.dylib 0xb534 _dispatch_lane_serial_drain + 668
6 libdispatch.dylib 0xc0a4 _dispatch_lane_invoke + 384
7 libdispatch.dylib 0x16cdc _dispatch_workloop_worker_thread + 648
8 libsystem_pthread.dylib 0xddc _pthread_wqthread + 288
9 libsystem_pthread.dylib 0xb7c start_wqthread + 8

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the crash stack and inspect TrustKit.m:197, then trace how TSKPinningValidator.m:182 reaches the reporter queue. The issue provides no reproduction steps, so first determine what object or state is accessed at the crash site. Done means identifying and fixing the production crash, with evidence that the reported initialization path no longer fails.

Written by the indexing model from the issue text.

Assessment

Tech stack
ios, objective-c
Domain
mobile-dev, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.