All of lore.kernel.org
 help / color / mirror / Atom feed
From: patchwork-bot+bluetooth@kernel.org
To: George Kiagiadakis <george.kiagiadakis@collabora.com>
Cc: linux-bluetooth@vger.kernel.org
Subject: Re: [PATCH BlueZ 0/5] player: Fix crash and related defects around the pending request
Date: Mon, 24 Aug 2026 20:40:07 +0000	[thread overview]
Message-ID: <178760400713.3109701.10398466433951422779.git-patchwork-notify@kernel.org> (raw)
In-Reply-To: <20260821193449.1336263-1-george.kiagiadakis@collabora.com>

Hello:

This series was applied to bluetooth/bluez.git (master)
by Luiz Augusto von Dentz <luiz.von.dentz@intel.com>:

On Fri, 21 Aug 2026 22:34:44 +0300 you wrote:
> A player that advertises the AVRCP NowPlaying feature bit but not the
> Browsing bit exports playable MediaItem1 objects while the player scope
> is still unset, and calling org.bluez.MediaItem1.Play() on one of them
> crashes bluetoothd with a NULL dereference at offset 0x28.
> 
> media_item_play() dereferences mp->scope, which is only ever set from
> SetBrowsedPlayer or ChangeFolder, and both are reached only when the
> player advertises Browsing (features[7] & 0x08). The /NowPlaying folder
> and its playable items are gated on a different bit (features[8] &
> 0x02), so the two can disagree. msg sits at offset 40 in struct
> media_folder on LP64, which is the reported fault address.
> 
> [...]

Here is the summary with links:
  - [BlueZ,1/5] player: Fix crash on MediaItem1.Play() without a browsing scope
    https://git.kernel.org/pub/scm/bluetooth/bluez.git/?id=a8d22214940d
  - [BlueZ,2/5] player: Answer pending request when the player is destroyed
    https://git.kernel.org/pub/scm/bluetooth/bluez.git/?id=ede23fb50e41
  - [BlueZ,3/5] player: Fix NumberOfItems never being updated on SetBrowsedPlayer
    https://git.kernel.org/pub/scm/bluetooth/bluez.git/?id=3215010456f1
  - [BlueZ,4/5] player: Report EBUSY from a busy Search()
    https://git.kernel.org/pub/scm/bluetooth/bluez.git/?id=a93047cd044f
  - [BlueZ,5/5] unit/test-media-player: Add media player tests
    (no matching commit)

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



      parent reply	other threads:[~2026-08-24 20:41 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-21 19:34 [PATCH BlueZ 0/5] player: Fix crash and related defects around the pending request George Kiagiadakis
2026-08-21 19:34 ` [PATCH BlueZ 1/5] player: Fix crash on MediaItem1.Play() without a browsing scope George Kiagiadakis
2026-08-21 20:38   ` player: Fix crash and related defects around the pending request bluez.test.bot
2026-08-21 19:34 ` [PATCH BlueZ 2/5] player: Answer pending request when the player is destroyed George Kiagiadakis
2026-08-21 19:34 ` [PATCH BlueZ 3/5] player: Fix NumberOfItems never being updated on SetBrowsedPlayer George Kiagiadakis
2026-08-21 19:34 ` [PATCH BlueZ 4/5] player: Report EBUSY from a busy Search() George Kiagiadakis
2026-08-21 19:34 ` [PATCH BlueZ 5/5] unit/test-media-player: Add media player tests George Kiagiadakis
2026-08-24 20:40 ` patchwork-bot+bluetooth [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=178760400713.3109701.10398466433951422779.git-patchwork-notify@kernel.org \
    --to=patchwork-bot+bluetooth@kernel.org \
    --cc=george.kiagiadakis@collabora.com \
    --cc=linux-bluetooth@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.