diff options
| author | 2026-08-22 14:58:07 +0200 | |
|---|---|---|
| committer | 2026-08-22 22:38:19 +0200 | |
| commit | 538a608a3e77495459ea4e60068a8bb6a480f0a6 (patch) | |
| tree | a4b0b207ce7e405874872fd8305c6032c975878b | |
| parent | 1c495c5aa1ba7fd82cd22f054092fde7979d8532 (diff) | |
| download | libirecovery-538a608a3e77495459ea4e60068a8bb6a480f0a6.tar.gz libirecovery-538a608a3e77495459ea4e60068a8bb6a480f0a6.tar.bz2 | |
fix: IOKit service lifetime during KIS retries
KIS discovery reused one retained reference across multiple open attempts.
A retry could therefore release an invalid Mach port and cause macOS
to terminate the process with EXC_GUARD.
Retain the service separately for each open attempt while preserving
the callback's iterator-owned reference.
| -rw-r--r-- | src/libirecovery.c | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/src/libirecovery.c b/src/libirecovery.c index ca96181..681b641 100644 --- a/src/libirecovery.c +++ b/src/libirecovery.c @@ -2705,9 +2705,9 @@ static void* _irecv_handle_device_add(void *userdata) } if (product_id == KIS_PRODUCT_ID) { - IOObjectRetain(device); int i = 0; for (i = 0; i < 10; i++) { + IOObjectRetain(device); error = iokit_usb_open_service(&client, device); if (error == IRECV_E_SUCCESS) { break; |
