Skip to content

upipe_transfer: do not leak a reference when freeze fails - #1228

Open
JDarnley wants to merge 1 commit into
Upipe:masterfrom
JDarnley:dev4
Open

upipe_transfer: do not leak a reference when freeze fails#1228
JDarnley wants to merge 1 commit into
Upipe:masterfrom
JDarnley:dev4

Conversation

@JDarnley

Copy link
Copy Markdown
Contributor

Managers allocated without a mutex always hit this: umutex_lock(NULL) returns UBASE_ERR_INVALID, so upipe_work_freeze() bails out through UBASE_RETURN without setting upipe_work->frozen, and upipe_work_thaw() then returns early on !frozen without releasing. The refcount never reaches zero, UPIPE_XFER_DETACH is never sent, and the worker thread never leaves upump_mgr_run(), hanging shutdown.

Lock first and take the reference only once the lock is held. The failing path still returns UBASE_ERR_INVALID and leaves frozen untouched, so inner pipe access is unaffected.

Managers allocated without a mutex always hit this: umutex_lock(NULL)
returns UBASE_ERR_INVALID, so upipe_work_freeze() bails out through
UBASE_RETURN without setting upipe_work->frozen, and upipe_work_thaw()
then returns early on !frozen without releasing. The refcount never
reaches zero, UPIPE_XFER_DETACH is never sent, and the worker thread
never leaves upump_mgr_run(), hanging shutdown.

Lock first and take the reference only once the lock is held. The
failing path still returns UBASE_ERR_INVALID and leaves frozen
untouched, so inner pipe access is unaffected.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant