mdns_maintenance_query() takes a ref on the browser's varlink link but never installs itself as that link's userdata. dns_query_free() then unconditionally runs sd_varlink_set_userdata(varlink_request, NULL), so freeing any maintenance query wipes the browse query's registration on the shared sb->link slot, disabling the abort paths in vl_on_disconnect() and dns_service_browser_free(). The maintenance query also never takes a reference on the DnsServiceBrowser, so a client disconnect could free the browser while a maintenance query was still in flight, leaving the per-service schedule_event timer and the raw service->service_browser back-pointer dangling (use-after-free on the next timer tick or query completion). Take a service_browser_request reference instead, matching the browse query path. dns_query_free() already drops it. The browser now outlives its in-flight maintenance queries. Follow-up for8458b7fb91(cherry picked from commit46c15e88e0) (cherry picked from commit9e41763ec9) (cherry picked from commitb428e7bfa1)
System and Service Manager
Details
Most documentation is available on systemd's web site.
Assorted, older, general information about systemd can be found in the systemd Wiki.
Information about build requirements is provided in the README file.
Consult our NEWS file for information about what's new in the most recent systemd versions.
Please see the Code Map for information about this repository's layout and content.
Please see the Hacking guide for information on how to hack on systemd and test your modifications.
Please see our Contribution Guidelines for more information about filing GitHub Issues and posting GitHub Pull Requests.
When preparing patches for systemd, please follow our Coding Style Guidelines.
If you are looking for support, please contact our mailing list, join our IRC channel #systemd on libera.chat or Matrix channel
Stable branches with backported patches are available in the stable repo.
We have a security bug bounty program sponsored by the Sovereign Tech Fund hosted on YesWeHack
Repositories with distribution packages built from git main are available on OBS, and also repositories with packages built from the latest stable release
