Page MenuHomeFreeBSD

firewire: NULL check on malloc in fw_busreset()
ClosedPublic

Authored by seuros on Jun 21 2026, 8:21 PM.
Referenced Files
Unknown Object (File)
Sat, Sep 19, 11:44 AM
Unknown Object (File)
Fri, Sep 18, 2:39 PM
Unknown Object (File)
Thu, Sep 17, 4:49 PM
Unknown Object (File)
Sat, Sep 12, 6:36 PM
Unknown Object (File)
Fri, Sep 11, 1:03 PM
Unknown Object (File)
Fri, Sep 11, 4:30 AM
Unknown Object (File)
Tue, Sep 8, 2:31 PM
Unknown Object (File)
Tue, Sep 8, 7:25 AM
Subscribers

Details

Summary

fw_busreset() allocates newrom with M_NOWAIT from interrupt context.
If the allocation fails, crom_load() dereferences a NULL pointer.

Skip the config ROM comparison on allocation failure so the next bus
reset will retry.

Test Plan

Hard to reproduce reliably. Triggered by wiggling the cable on a
battery-powered FireWire camera, the intermittent connection causes
rapid bus resets that race with allocation, eventually hitting the
NULL path. Panic no longer occurs with the fix.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable