Skip to content

winmm: Fix use-after-free race between stream destroy and buffer thread. - #854

Open
kinetiknz wants to merge 1 commit into
masterfrom
winmm-destroy-race
Open

winmm: Fix use-after-free race between stream destroy and buffer thread.#854
kinetiknz wants to merge 1 commit into
masterfrom
winmm-destroy-race

Conversation

@kinetiknz

Copy link
Copy Markdown
Collaborator

Destroy could free a stream while buffer thread work items referencing it were still queued or in flight, particularly after a data callback error. Count pending work items per stream (and in-flight driver callbacks per context) and make destroy wait for them to drain. Also fix free_buffers accounting on refill's error paths so the wait terminates.

Destroy could free a stream while buffer thread work items referencing
it were still queued or in flight, particularly after a data callback
error. Count pending work items per stream (and in-flight driver
callbacks per context) and make destroy wait for them to drain. Also
fix free_buffers accounting on refill's error paths so the wait
terminates.
@kinetiknz
kinetiknz requested a review from padenot July 29, 2026 04:29
@kinetiknz kinetiknz self-assigned this Jul 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant