Page MenuHomeFreeBSD

ufshci: tolerate partially constructed queues in SDB teardown
ClosedPublic

Authored by jaeyoon on Aug 5 2026, 8:03 AM.
Tags
None
Referenced Files
Unknown Object (File)
Sat, Oct 3, 2:18 AM
Unknown Object (File)
Sat, Oct 3, 2:09 AM
Unknown Object (File)
Fri, Oct 2, 4:09 PM
Unknown Object (File)
Tue, Sep 29, 11:38 PM
Unknown Object (File)
Tue, Sep 29, 12:37 PM
Unknown Object (File)
Tue, Sep 29, 4:55 AM
Unknown Object (File)
Mon, Sep 28, 6:20 PM
Unknown Object (File)
Sat, Sep 26, 8:17 PM
Subscribers
None

Details

Summary

When attach fails, ufshci_req_sdb_destroy() runs on a partially
constructed queue, and it runs twice: once from the construct error
path and once from the controller destructor.

Make that safe: NULL-check each resource before freeing it and clear
the pointer afterwards, so a second call finds nothing to do. The
construct error label no longer frees the command descriptors itself,
which fixes a double free of ucd_bus_addr. Also destroy the payload
DMA tag, which was previously leaked. Drop the mtx_initialized()
checks: the locks are always set up before any failure path can reach
the destroy.

Attach can also fail before the queues were constructed at all. The
destructor would then call a NULL qops.destroy pointer, so skip the
destroy when the queue was never set up.

Sponsored by: Samsung Electronics

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable