Author: Andy Green Date: Mon Sep 21 18:10:14 2026 +0100 sai-expect: cancel the collation sul when the tty wsi closes The 150ms collation sul lives in the serial wsi's pss. When the pass string is seen on a line boundary and the next line's first bytes arrive in the same read, the sul is re-armed after the drain has already been requested; the drain completes within a millisecond, the service loop exits and lws_context_destroy() frees the pss with the sul still on the pt list. Newer lws walks the leftover suls at destroy and cancels them, which now reads the freed pss and segfaults, so the esp32 boot test reported SEGFAULT right after 'Completed: PASS' and 'sai-expect: completed'. Cancel the sul in LWS_CALLBACK_RAW_CLOSE_FILE so it never outlives the pss. Co-Authored-By: Claude Fable 5.1 diff --git a/src/expect/e-serial.c b/src/expect/e-serial.c index aa6ffb4..e0bc8a0 100644 --- a/src/expect/e-serial.c +++ b/src/expect/e-serial.c @@ -226,6 +226,11 @@ callback_serial(struct lws *wsi, enum lws_callback_reasons reason, break; case LWS_CALLBACK_RAW_CLOSE_FILE: + /* + * The collation sul lives in the pss, which is freed with + * the wsi: at context destroy it can still be scheduled + */ + lws_sul_cancel(&pss->sul); break; case LWS_CALLBACK_RAW_WRITEABLE_FILE: