Skip to content

fix: scope Cancel request matching to the current session (#4023) - #4267

Merged
marcschier merged 1 commit into
master378from
romanett-backport-70c74e7
Aug 18, 2026
Merged

marcschier merged 1 commit into
master378from
romanett-backport-70c74e7

Conversation

@romanett

Copy link
Copy Markdown
Contributor

Backport of 70c74e7 from master to master378.

Summary

Scopes Cancel request matching to the caller's session and adds a regression test verifying a request handle can no longer cancel work belonging to another session.

Problem

Per OPC UA Part 4, Cancel applies to a request handle from the same session that issued the original request. Previously StandardServer.CancelAsync validated the caller's session but forwarded only the raw requestHandle to RequestManager.CancelRequests, which iterated the global outstanding-request table and canceled every request whose ClientHandle matched — regardless of owning session. Since request handles are only session-scoped and different sessions can reuse the same value, one session could cancel another session's in-flight request.

Changes

  • Pass the validated caller session id from StandardServer.CancelAsync into RequestManager.CancelRequests.
  • Restrict RequestManager.CancelRequests to requests whose SessionId and ClientHandle both match.
  • Update the existing request-manager test call and add CancelRequestsDoesNotCancelMatchingHandleFromDifferentSession regression test.

Notes on the backport

The master378 branch predates the RequestLifetime cancellation model and the SessionPublishQueueTests present on master, so those parts of the original commit do not apply. The core fix and the regression test were adapted to this branch's SetStatusCode/OperationStatus model. Opc.Ua.Server.Tests builds clean and both RequestManagerTests pass.

Co-authored-by: Copilot App 223556219+Copilot@users.noreply.github.com

@codecov

codecov Bot commented Aug 16, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 33.33333% with 4 lines in your changes missing coverage. Please review.
✅ Project coverage is 60.23%. Comparing base (db256c6) to head (d079262).

Files with missing lines Patch % Lines
Libraries/Opc.Ua.Server/Server/StandardServer.cs 0.00% 4 Missing ⚠️

❌ Your patch check has failed because the patch coverage (33.33%) is below the target coverage (80.00%). You can increase the patch coverage or adjust the target coverage.

Additional details and impacted files

Impacted file tree graph

@@              Coverage Diff              @@
##           master378    #4267      +/-   ##
=============================================
+ Coverage      60.19%   60.23%   +0.03%     
=============================================
  Files            378      378              
  Lines          79067    79071       +4     
  Branches       13838    13838              
=============================================
+ Hits           47598    47625      +27     
+ Misses         27047    27023      -24     
- Partials        4422     4423       +1     
Files with missing lines Coverage Δ
Libraries/Opc.Ua.Server/Server/RequestManager.cs 62.35% <100.00%> (+0.44%) ⬆️
Libraries/Opc.Ua.Server/Server/StandardServer.cs 70.86% <0.00%> (-0.13%) ⬇️

... and 11 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

Backport of 70c74e7 from master. Restrict RequestManager.CancelRequests to requests whose SessionId and ClientHandle both match the Cancel request, and pass the validated caller session id from StandardServer.CancelAsync. Adds a regression test proving matching request handles in different sessions no longer interfere.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@romanett romanett added the 1.5.378 Only affects 1.5.378 (pre 2.0) label Aug 16, 2026
@marcschier
marcschier merged commit a278219 into master378 Aug 18, 2026
111 of 112 checks passed
@marcschier
marcschier deleted the romanett-backport-70c74e7 branch August 18, 2026 15:15
GoetzGoerisch pushed a commit to umati/connect that referenced this pull request Sep 23, 2026
…5.378.176 (#45)

This PR contains the following updates:

| Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) |
|---|---|---|---|
| [OPCFoundation.NetStandard.Opc.Ua](https://github.com/OPCFoundation/UA-.NETStandard) | `1.5.378.156` → `1.5.378.176` | ![age](https://developer.mend.io/api/mc/badges/age/nuget/OPCFoundation.NetStandard.Opc.Ua/1.5.378.176?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/nuget/OPCFoundation.NetStandard.Opc.Ua/1.5.378.156/1.5.378.176?slim=true) |

---

### Release Notes

<details>
<summary>OPCFoundation/UA-.NETStandard (OPCFoundation.NetStandard.Opc.Ua)</summary>

### [`v1.5.378.176`](https://github.com/OPCFoundation/UA-.NETStandard/releases/tag/1.5.378.176): OPC UA 1.05 Maintenance Update

[Compare Source](OPCFoundation/UA-.NETStandard@1.5.378.156...1.5.378.176)

Maintenance Release for fixing bugs found on the main378 development branch.

#### Released packages

[OPCFoundation.NetStandard.Opc.Ua](https://www.nuget.org/packages/OPCFoundation.NetStandard.Opc.Ua/1.5.378.176)
[OPCFoundation.NetStandard.Opc.Ua.Core](https://www.nuget.org/packages/OPCFoundation.NetStandard.Opc.Ua.Core/1.5.378.176)
[OPCFoundation.NetStandard.Opc.Ua.Security.Certificates](https://www.nuget.org/packages/OPCFoundation.NetStandard.Opc.Ua.Security.Certificates/1.5.378.176)
[OPCFoundation.NetStandard.Opc.Ua.Configuration](https://www.nuget.org/packages/OPCFoundation.NetStandard.Opc.Ua.Configuration/1.5.378.176)
[OPCFoundation.NetStandard.Opc.Ua.Server](https://www.nuget.org/packages/OPCFoundation.NetStandard.Opc.Ua.Server/1.5.378.176)
[OPCFoundation.NetStandard.Opc.Ua.Client](https://www.nuget.org/packages/OPCFoundation.NetStandard.Opc.Ua.Client/1.5.378.176)
[OPCFoundation.NetStandard.Opc.Ua.Client.ComplexTypes](https://www.nuget.org/packages/OPCFoundation.NetStandard.Opc.Ua.Client.ComplexTypes/1.5.378.176)
[OPCFoundation.NetStandard.Opc.Ua.Bindings.Https](https://www.nuget.org/packages/OPCFoundation.NetStandard.Opc.Ua.Bindings.Https/1.5.378.176)
[OPCFoundation.NetStandard.Opc.Ua.PubSub](https://www.nuget.org/packages/OPCFoundation.NetStandard.Opc.Ua.PubSub/1.5.378.176)

#### What's Changed

- Fix publish queue lost wake-up by [@&#8203;marcschier](https://github.com/marcschier) in [#&#8203;4017](OPCFoundation/UA-.NETStandard#4017)
- Obsolete legacy TraceConfiguration in favor of ITelemetryContext by [@&#8203;marcschier](https://github.com/marcschier) with [@&#8203;Copilot](https://github.com/Copilot) in [#&#8203;4090](OPCFoundation/UA-.NETStandard#4090)
- Preserve publish queue timestamp ordering by [@&#8203;marcschier](https://github.com/marcschier) with [@&#8203;Copilot](https://github.com/Copilot) in [#&#8203;4084](OPCFoundation/UA-.NETStandard#4084)
- Fix BadContinuationPointInvalid caused by empty continuation point in Browser.BrowseAsync by [@&#8203;marcschier](https://github.com/marcschier) in [#&#8203;4168](OPCFoundation/UA-.NETStandard#4168)
- Add documentation for custom NodeSet2 authoring workflow by [@&#8203;romanett](https://github.com/romanett) with [@&#8203;Copilot](https://github.com/Copilot) in [#&#8203;4170](OPCFoundation/UA-.NETStandard#4170)
- Fixed timer leaks in ChannelAsyncOperation.EndAsync ([#&#8203;3669](OPCFoundation/UA-.NETStandard#3669)) by [@&#8203;KarenKrill](https://github.com/KarenKrill) in [#&#8203;4166](OPCFoundation/UA-.NETStandard#4166)
- Treat zero MaxNotificationsPerPublish as unlimited (OPC 10000-4) by [@&#8203;romanett](https://github.com/romanett) in [#&#8203;4263](OPCFoundation/UA-.NETStandard#4263)
- fix(server): enforce browse continuation point limit at capacity ([#&#8203;4036](OPCFoundation/UA-.NETStandard#4036)) by [@&#8203;romanett](https://github.com/romanett) in [#&#8203;4270](OPCFoundation/UA-.NETStandard#4270)
- Fix unordered server endpoint validation ([#&#8203;4029](OPCFoundation/UA-.NETStandard#4029)) \[backport to master378] by [@&#8203;romanett](https://github.com/romanett) in [#&#8203;4269](OPCFoundation/UA-.NETStandard#4269)
- fix: don't return continuation points on BadNoContinuationPoints ([#&#8203;4022](OPCFoundation/UA-.NETStandard#4022)) \[backport to master378] by [@&#8203;romanett](https://github.com/romanett) in [#&#8203;4268](OPCFoundation/UA-.NETStandard#4268)
- fix: scope Cancel request matching to the current session ([#&#8203;4023](OPCFoundation/UA-.NETStandard#4023)) by [@&#8203;romanett](https://github.com/romanett) in [#&#8203;4267](OPCFoundation/UA-.NETStandard#4267)
- Set ContinuationPoint to null when browse is finished (port of [#&#8203;4057](OPCFoundation/UA-.NETStandard#4057)) by [@&#8203;romanett](https://github.com/romanett) in [#&#8203;4266](OPCFoundation/UA-.NETStandard#4266)
- Default TransportQuotas in ApplicationConfiguration.ValidateAsync to prevent server-start NullReferenceException (backport to master378) by [@&#8203;romanett](https://github.com/romanett) in [#&#8203;4264](OPCFoundation/UA-.NETStandard#4264)
- Fix ServerTimestamp update on read of stored/static nodes ([#&#8203;4257](OPCFoundation/UA-.NETStandard#4257)) by [@&#8203;romanett](https://github.com/romanett) in [#&#8203;4260](OPCFoundation/UA-.NETStandard#4260)
- Fix reverse connect hold time when several Servers share one listener by [@&#8203;romanett](https://github.com/romanett) in [#&#8203;4341](OPCFoundation/UA-.NETStandard#4341)
- \[master378] Fix Publish with maximum TimeoutHint by [@&#8203;mrsuciu](https://github.com/mrsuciu) in [#&#8203;4373](OPCFoundation/UA-.NETStandard#4373)
- \[master378] Send the filtered retain trailing event with a client specific Retain = false by [@&#8203;romanett](https://github.com/romanett) in [#&#8203;4454](OPCFoundation/UA-.NETStandard#4454)
- Master378 backport ctt changes by [@&#8203;mrsuciu](https://github.com/mrsuciu) in [#&#8203;4326](OPCFoundation/UA-.NETStandard#4326)
- Update Microsoft.SourceLink.GitHub and  Microsoft.SourceLink.AzureRepos.Git from 10.0.102 to 10.0.111 by [@&#8203;mrsuciu](https://github.com/mrsuciu) in [#&#8203;4465](OPCFoundation/UA-.NETStandard#4465)

**Full Changelog**: <OPCFoundation/UA-.NETStandard@1.5.378.156...1.5.378.176>

</details>

---

### Configuration

📅 **Schedule**: (UTC)

- Branch creation
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC43Ny4wIiwidXBkYXRlZEluVmVyIjoiNDQuNzcuMCIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->

Reviewed-on: https://codeberg.org/umati/connect/pulls/45
Signed-off-by: umati-bot <git-bot@umati.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

1.5.378 Only affects 1.5.378 (pre 2.0)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants