Conversation
create_local_bg_thread() holds a reference to the printer via
printer->use while it generates the IPP Everywhere PPD.
cupsdDeleteTemporaryPrinters() respected that reference, but
cupsdDeletePrinter() did not, so an explicit CUPS-Delete-Printer (as
cups-browsed issues when it replaces a discovered queue) freed the
printer mid-thread and corrupted the heap ("corrupted double-linked
list").
Defer deletion while printer->use > 0 by flagging the printer under
printer->lock; cupsdDeleteTemporaryPrinters() then reaps it once the
thread releases its reference. Extends the use-count protection from
OpenPrinting#1655 to the explicit deletion path.
Author
|
CI may need this first #1723 |
michaelrsweet
requested changes
Sep 26, 2026
michaelrsweet
left a comment
Member
There was a problem hiding this comment.
I think we can simply this to just decrement use to 0 but not immediately delete it. Will think some, and we should bring this fix to 2.4.x as well.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
create_local_bg_thread() holds a reference to the printer via printer->use while it generates the IPP Everywhere PPD. cupsdDeleteTemporaryPrinters() respected that reference, but cupsdDeletePrinter() did not, so an explicit CUPS-Delete-Printer (as cups-browsed issues when it replaces a discovered queue) freed the printer mid-thread and corrupted the heap ("corrupted double-linked list").
Defer deletion while printer->use > 0 by flagging the printer under printer->lock; cupsdDeleteTemporaryPrinters() then reaps it once the thread releases its reference. Extends the use-count protection from #1655 to the explicit deletion path.