Skip to content

Fix crash after ping of an attachment deleted via mon$attachments - #9196

Merged
dyemanov merged 1 commit into
FirebirdSQL:v5.0-releasefrom
MochalovAlexey:ping_nullptr_dereference
Oct 7, 2026
Merged

dyemanov merged 1 commit into
FirebirdSQL:v5.0-releasefrom
MochalovAlexey:ping_nullptr_dereference

Conversation

@MochalovAlexey

Copy link
Copy Markdown
Contributor

This PR fixes a crash that a customer encountered after deleting an attachment from mon$attachments.

A later ping correctly reports that the connection has been shut down. The crash happens during cleanup, when YEntry tries to release an interface that has already been destroyed.

The next field in YAttachment and the nextRef field in YEntry hold references to the same interface. The manual release call drops one reference, and setting next to nullptr drops another, destroying the object. YEntry still holds the old pointer and tries to release it when its destructor runs.

The fix removes the extra manual release so that each RefPtr releases its own reference once.

Remove the extra manual release in YAttachment::ping.
@dyemanov

dyemanov commented Oct 6, 2026

Copy link
Copy Markdown
Member

The original code used detach() here, but IIRC that time detach() wasn't decrementing the reference counter. When its behaviour was changed, this piece of code wasn't adjusted properly. It also preserved the extra decrement when later changed from detach() to release().

@dyemanov
dyemanov merged commit ba850a3 into FirebirdSQL:v5.0-release Oct 7, 2026
21 of 22 checks passed
dyemanov pushed a commit that referenced this pull request Oct 7, 2026
Remove the extra manual release in YAttachment::ping.

Co-authored-by: aleksey.mochalov <aleksey.mochalov@red-soft.ru>
dyemanov pushed a commit that referenced this pull request Oct 7, 2026
Remove the extra manual release in YAttachment::ping.

Co-authored-by: aleksey.mochalov <aleksey.mochalov@red-soft.ru>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants