Skip to content

Session-end timer runs on java.util.Timer #5576

Description

@runningcode

Audit finding B2 — actual bug, MEDIUM.

LifecycleWatcher schedules session end with java.util.Timer (new Timer(true) / scheduleEndSession, sentry-android-core/src/main/java/io/sentry/android/core/LifecycleWatcher.java:106-122), sharing B1's mechanics:

  • Device sleeps within the 30s background window → session ends only at wake; Session.end() stamps wake time → inflated session durations in release health. Replay stop() and ContinuousProfiler.close(false) also run hours late.
  • The foreground check lastUpdatedSession + sessionIntervalMillis <= now is a wall-clock interval → a clock step causes spurious or missed session rotation.

Source: JAVA-557 §B2.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions