getsentry / getsentry/sentry-java
Session-end timer runs on java.util.Timer
- Langage dominant
- Kotlin
- Étoiles
- 1.4k
- Forks
- 478
- Merge moyen
- 2 j 23 h
- PR mergées (30 j)
- 67
Description
Audit finding **B2 — actual bug, MEDIUM**.
`LifecycleWatcher` schedules session end with `java.util.Timer` (`new Timer(true)` / `scheduleEndSession`, `sentry-android-core/src/main/java/io/sentry/android/core/LifecycleWatcher.java:106-122`), sharing B1's mechanics:
* Device sleeps within the 30s background window → session ends only at wake; `Session.end()` stamps wake time → inflated session durations in release health. Replay `stop()` and `ContinuousProfiler.close(false)` also run hours late.
* The foreground check `lastUpdatedSession + sessionIntervalMillis <= now` is a wall-clock interval → a clock step causes spurious or missed session rotation.
Source: [JAVA-557]() §B2.
Guide de contribution
Ouvrir le guide de contribution
Évaluation
Cette issue n'a pas encore été évaluée.