git: 95c04b25323d - main - bcm2835_audio: Comment out vchi_service_release()

Christos Margiolis <[email protected]>
Newsgroups gmane.os.freebsd.devel.cvs.src
Message-ID <6a84be2d.20f36.1abaf315__24694.4363041379$1787084350$gmane$org@gitrepo.freebsd.org>
The branch main has been updated by christos:

URL: https://cgit.FreeBSD.org/src/commit/?id=95c04b25323d59da43203a08e56db141ac37181b

commit 95c04b25323d59da43203a08e56db141ac37181b
Author:     Xuqing Yang <[email protected]>
AuthorDate: 2026-08-18 20:17:44 +0000
Commit:     Christos Margiolis <[email protected]>
CommitDate: 2026-08-18 20:18:01 +0000

    bcm2835_audio: Comment out vchi_service_release()
    
    bcm2835_audio_release() calls vchi_service_close() and then
    unconditionally calls vchi_service_release() with the same service
    handle.
    
    In the VCHI shim implementation, a successful vchi_service_close() calls
    service_free(service). The subsequent vchi_service_release() therefore
    dereferences a freed SHIM_SERVICE_T object when it reads
    service->handle, resulting in a use-after-free panic.
    
    vchi_service_release(), however, releases a reference which might block
    vchi_service_close() from completing successfuly, so comment it out
    instead of removing it altogether, until further testing is done.
    
    PR:             297187
    MFC after:      2 weeks
    Reviewed by:    markj
    Differential Revision:  https://reviews.freebsd.org/D58921
---
 sys/arm/broadcom/bcm2835/bcm2835_audio.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/sys/arm/broadcom/bcm2835/bcm2835_audio.c b/sys/arm/broadcom/bcm2835/bcm2835_audio.c
index 1406fcc3d952..29808b053b92 100644
--- a/sys/arm/broadcom/bcm2835/bcm2835_audio.c
+++ b/sys/arm/broadcom/bcm2835/bcm2835_audio.c
@@ -360,11 +360,11 @@ bcm2835_audio_release(struct bcm2835_audio_info *sc)
 	int success;
 
 	if (sc->vchi_handle != VCHIQ_SERVICE_HANDLE_INVALID) {
+		/* XXX vchi_service_release(sc->vchi_handle)? */
 		success = vchi_service_close(sc->vchi_handle);
 		if (success != 0)
 			BCM2835_LOG_ERROR(sc, "vchi_service_close failed: %d\n",
 			    success);
-		vchi_service_release(sc->vchi_handle);
 		sc->vchi_handle = VCHIQ_SERVICE_HANDLE_INVALID;
 	}
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.