| Author | |
| Committer | |
| Tree | 65cba5fe9aa9430fad2ea900c8f5da6ef1c05596 |
builder: destroy the deletion stub before lws_context_destroy() Left to lws_context_destroy(), the deletion stub manager is destroyed from its vhost and builder.mgr_deletion is left pointing at freed memory, while the stdwsi close it triggers still runs our handler, which looks the lsp up through that very pointer. With lws tolerating the NULL lsp it now gets there, that is survivable, but take the stub down ourselves at shutdown, after the service loop, so the pointer is cleared the way it is everywhere else we destroy it. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> | |
diff --git a/src/builder/b-sai.c b/src/builder/b-sai.c index 1ad5b3e..73505a6 100644 --- a/src/builder/b-sai.c +++ b/src/builder/b-sai.c @@ -948,6 +948,16 @@ saib_app_run(int argc, const char **argv) suspender_destroy(); +#if defined(LWS_WITH_STUB) + /* + * Take the deletion stub down ourselves, before lws_context_destroy() + * does it from the vhost: that way builder.mgr_deletion is cleared + * rather than left pointing at a manager lws has freed. + */ + if (builder.mgr_deletion) + lws_stub_destroy(&builder.mgr_deletion); +#endif + /* destroy the unique servers */