Thanks!

I haven't tried it on noble (no noble machine with bluetooth here), but
I had a look at the 1.0.5 source and the bug is there too.
adapter_register_application() calls send_with_reply() with the adapter
as user_data and throws away the pending call, so there is nothing for
adapter_free() to cancel. When the error reply arrives later,
bluez_register_application_a2dp_reply() takes the legacy fallback and
bluez_register_endpoint_legacy() ends up in
dbus_message_new_method_call() with the freed adapter->path. Same
assertion as in the backtrace. So a bluetoothd restart or an adapter
reset with a RegisterApplication() in flight should kill wireplumber on
noble as well.

The two commits don't apply to 1.0.5 as is though, quite a few hunks
fail because the code moved around a lot between 1.0 and 1.6, so it
would need a hand-ported version. If you want to do the noble diff as
you offered, that would be great. I can review it once it's up.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2160089

Title:
  bluez5: WirePlumber SIGABRT (use-after-free) when BT adapter is
  removed with pending RegisterApplication calls

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/pipewire/+bug/2160089/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to