From owner-freebsd-i386@FreeBSD.ORG Sun Dec 16 02:30:01 2007 Return-Path: Delivered-To: freebsd-i386@hub.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 7D21116A421 for ; Sun, 16 Dec 2007 02:30:01 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [IPv6:2001:4f8:fff6::28]) by mx1.freebsd.org (Postfix) with ESMTP id 667DD13C458 for ; Sun, 16 Dec 2007 02:30:01 +0000 (UTC) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.14.2/8.14.2) with ESMTP id lBG2U1DV099135 for ; Sun, 16 Dec 2007 02:30:01 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.14.2/8.14.1/Submit) id lBG2U1MP099134; Sun, 16 Dec 2007 02:30:01 GMT (envelope-from gnats) Resent-Date: Sun, 16 Dec 2007 02:30:01 GMT Resent-Message-Id: <200712160230.lBG2U1MP099134@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-i386@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, Dan Lukes Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 7C4ED16A41A for ; Sun, 16 Dec 2007 02:28:04 +0000 (UTC) (envelope-from dan@kulesh.obluda.cz) Received: from smtp1.kolej.mff.cuni.cz (smtp1.kolej.mff.cuni.cz [78.128.192.4]) by mx1.freebsd.org (Postfix) with ESMTP id 1F1BF13C461 for ; Sun, 16 Dec 2007 02:28:03 +0000 (UTC) (envelope-from dan@kulesh.obluda.cz) Received: from kulesh.obluda.cz (openvpn.ms.mff.cuni.cz [195.113.20.87]) by smtp1.kolej.mff.cuni.cz (8.13.8/8.13.8) with ESMTP id lBG2Rkd7067756 for ; Sun, 16 Dec 2007 03:27:50 +0100 (CET) (envelope-from dan@kulesh.obluda.cz) Received: from kulesh.obluda.cz (localhost. [127.0.0.1]) by kulesh.obluda.cz (8.14.2/8.14.2) with ESMTP id lBG2RhfV001202 for ; Sun, 16 Dec 2007 03:27:43 +0100 (CET) (envelope-from dan@kulesh.obluda.cz) Received: (from root@localhost) by kulesh.obluda.cz (8.14.2/8.14.1/Submit) id lBG2RhFn001201; Sun, 16 Dec 2007 03:27:43 +0100 (CET) (envelope-from dan) Message-Id: <200712160227.lBG2RhFn001201@kulesh.obluda.cz> Date: Sun, 16 Dec 2007 03:27:43 +0100 (CET) From: Dan Lukes To: FreeBSD-gnats-submit@FreeBSD.org X-Send-Pr-Version: 3.113 Cc: Subject: i386/118737: [ PATCH ] Panic due double free within detach of cpufreq/est X-BeenThere: freebsd-i386@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list Reply-To: Dan Lukes List-Id: I386-specific issues for FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 16 Dec 2007 02:30:01 -0000 >Number: 118737 >Category: i386 >Synopsis: [ PATCH ] Panic due double free within detach of cpufreq/est >Confidential: no >Severity: serious >Priority: low >Responsible: freebsd-i386 >State: open >Quarter: >Keywords: >Date-Required: >Class: sw-bug >Submitter-Id: current-users >Arrival-Date: Sun Dec 16 02:30:00 UTC 2007 >Closed-Date: >Last-Modified: >Originator: Dan Lukes >Release: FreeBSD 6.3-PRERELEASE i386 >Organization: Obludarium >Environment: System: FreeBSD 6.3-PRERELEASE #18: Sun Dec 16 03:05:00 CET 2007 i386 src/sys/i386/cpufreq/est.c,v 1.7.2.1 2006/05/29 22:40:03 njl As far as I know the problem apply to CURRENT as well >Description: on est_detach the sc->freq_list freed but driver cease to detach (ENXIO) on second try to unload driver the memory is freed second time causing the panic() >How-To-Repeat: On hardware supported by est driver unload cpufreq module - it fail with ENXIO unload it second time - it will panic >Fix: Unregister the driver properly then return NOERROR to upper layer. --- sys/i386/cpufreq/est.c.ORIG 2007-12-16 02:13:42.000000000 +0100 +++ sys/i386/cpufreq/est.c 2007-12-16 02:26:46.000000000 +0100 @@ -1032,11 +1032,14 @@ est_detach(device_t dev) { struct est_softc *sc; + int error; sc = device_get_softc(dev); - if (sc->acpi_settings) + + error = cpufreq_unregister(dev); + if (!error && sc->acpi_settings) free(sc->freq_list, M_DEVBUF); - return (ENXIO); + return (error); } /* >Release-Note: >Audit-Trail: >Unformatted: