pcm_unregister() freed various resources before destroying the dsp cdev.
A thread that had already passed DSP_REGISTERED() could potentially
dereference those after they were freed. This was easily triggered by
the test case introduced in this commit.
Factor out pcm_killchans()'s channel wakeup/drain loop into a new
pcm_shutdownchans(), which is called before destroy_dev(), so that the
channels are freed only when destroy_dev() has returned.
SD_F_BUSY must not be held while destroying, otherwise a thread sleeping
in PCM_WAIT() would never wake up and destroy_dev() would hang.
Check PCM_REGISTERED() in vchan_create(), since it is the only place
where channels are created at runtime.
MFC after: 1 week
Sponsored by: The FreeBSD Foundation