Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 10 Aug 2026 02:31:25 +0000
From:      Jaeyoon Choi <jaeyoon@FreeBSD.org>
To:        src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org
Subject:   git: c71705a08304 - main - ufshci: do not free the devq twice on SIM attach failure
Message-ID:  <6a7937fd.1f865.199d4809@gitrepo.freebsd.org>

index | next in thread | raw e-mail

The branch main has been updated by jaeyoon:

URL: https://cgit.FreeBSD.org/src/commit/?id=c71705a0830497c080579896b4aa2a5ce2513f1c

commit c71705a0830497c080579896b4aa2a5ce2513f1c
Author:     Jaeyoon Choi <jaeyoon@FreeBSD.org>
AuthorDate: 2026-08-10 01:44:35 +0000
Commit:     Jaeyoon Choi <jaeyoon@FreeBSD.org>
CommitDate: 2026-08-10 02:28:51 +0000

    ufshci: do not free the devq twice on SIM attach failure
    
    cam_sim_free() with free_devq set already frees the devq, so the
    following cam_simq_free() call on the xpt_bus_register() and
    xpt_create_path() failure paths was a double free. Also clear
    ctrlr->ufshci_sim so a later ufshci_sim_detach() does not operate on
    the freed SIM.
    
    Sponsored by:           Samsung Electronics
    Reviewed by:            imp (mentor)
    Differential Revision:  https://reviews.freebsd.org/D58662
---
 sys/dev/ufshci/ufshci_sim.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/sys/dev/ufshci/ufshci_sim.c b/sys/dev/ufshci/ufshci_sim.c
index 9d80dd195ad9..4a106a6c7b8a 100644
--- a/sys/dev/ufshci/ufshci_sim.c
+++ b/sys/dev/ufshci/ufshci_sim.c
@@ -371,8 +371,9 @@ ufshci_sim_attach(struct ufshci_controller *ctrlr)
 
 	mtx_lock(&ctrlr->sc_mtx);
 	if (xpt_bus_register(ctrlr->ufshci_sim, ctrlr->dev, 0) != CAM_SUCCESS) {
+		/* cam_sim_free() with free_devq also frees the devq. */
 		cam_sim_free(ctrlr->ufshci_sim, /*free_devq*/ TRUE);
-		cam_simq_free(devq);
+		ctrlr->ufshci_sim = NULL;
 		mtx_unlock(&ctrlr->sc_mtx);
 		printf("Failed to create a bus\n");
 		return (ENOMEM);
@@ -383,7 +384,7 @@ ufshci_sim_attach(struct ufshci_controller *ctrlr)
 		CAM_LUN_WILDCARD) != CAM_REQ_CMP) {
 		xpt_bus_deregister(cam_sim_path(ctrlr->ufshci_sim));
 		cam_sim_free(ctrlr->ufshci_sim, /*free_devq*/ TRUE);
-		cam_simq_free(devq);
+		ctrlr->ufshci_sim = NULL;
 		mtx_unlock(&ctrlr->sc_mtx);
 		printf("Failed to create a path\n");
 		return (ENOMEM);


home | help

Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?6a7937fd.1f865.199d4809>