Page MenuHomeFreeBSD

sound: Drain the dsp cdev before freeing resources
Needs ReviewPublic

Authored by christos on Tue, Sep 29, 12:02 PM.
Tags
None
Referenced Files
F174752152: D60120.id.diff
Mon, Oct 5, 6:15 PM
F174663698: D60120.id.diff
Mon, Oct 5, 1:19 AM
Unknown Object (File)
Sun, Oct 4, 1:43 AM
Unknown Object (File)
Sat, Oct 3, 8:59 PM
Unknown Object (File)
Sat, Oct 3, 10:20 AM
Unknown Object (File)
Sat, Oct 3, 7:14 AM
Unknown Object (File)
Thu, Oct 1, 10:55 PM
Unknown Object (File)
Thu, Oct 1, 8:50 AM
Subscribers

Details

Reviewers
markj
emaste
kib
Summary

pcm_unregister() freed various resources before destroying the dsp cdev.
A thread that had already passed DSP_REGISTERED() could potentially
dereference those after they were freed. This was easily triggered by
the test case introduced in this commit.

Factor out pcm_killchans()'s channel wakeup/drain loop into a new
pcm_shutdownchans(), which is called before destroy_dev(), so that the
channels are freed only when destroy_dev() has returned.

SD_F_BUSY must not be held while destroying, otherwise a thread sleeping
in PCM_WAIT() would never wake up and destroy_dev() would hang.

Check PCM_REGISTERED() in vchan_create(), since it is the only place
where channels are created at runtime.

MFC after: 1 week
Sponsored by: The FreeBSD Foundation

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 77438
Build 74321: arc lint + arc unit