# Videoroom: crash in janus\_videoroom\_reqpli() function on Janus v1.3.2

**URL:** <https://janus.discourse.group/t/videoroom-crash-in-janus-videoroom-reqpli-function-on-janus-v1-3-2/1718>\
**Category:** General\
**Created:** [September 16, 2025, 5:16am UTC](https://janus.discourse.group/t/videoroom-crash-in-janus-videoroom-reqpli-function-on-janus-v1-3-2/1718 "2025-09-16T05:16:38Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jaejong](https://avatars.discourse-cdn.com/v4/letter/j/e47774/32.png) [@Jaejong](https://janus.discourse.group/u/Jaejong)\
**Post date:** [September 16, 2025, 5:16am UTC](https://janus.discourse.group/t/videoroom-crash-in-janus-videoroom-reqpli-function-on-janus-v1-3-2/1718/1 "2025-09-16T05:16:38Z")

</div>

(My english is not that good.)

When receiving an “unpublish” request in the publishing state, we occasionally encounter a crash at ① line 2996.

Upon investigation, I found that during the handling of ②③ the “unpublish” request, ps-\>publisher = NULL; is executed.

I would like your advice on how to resolve this issue.

 ![pli crash](https://global.discourse-cdn.com/free1/uploads/janus/original/1X/df608b0db25c5cf253f1c49d56fe8d5c95fc158d.png)

---

<div class="post-metadata">

**Author:** ![lorenzo](https://yyz2.discourse-cdn.com/free1/user_avatar/janus.discourse.group/lorenzo/32/425_2.png) [@lorenzo](https://janus.discourse.group/u/lorenzo)\
**Post date:** [September 16, 2025, 9:05am UTC](https://janus.discourse.group/t/videoroom-crash-in-janus-videoroom-reqpli-function-on-janus-v1-3-2/1718/2 "2025-09-16T09:05:03Z")

</div>

This may be a good catch, I just pushed a commit that adds a NULL check for that. Please let me know if that still causes issues.

---

<div class="post-metadata">

**Author:** ![Jaejong](https://avatars.discourse-cdn.com/v4/letter/j/e47774/32.png) [@Jaejong](https://janus.discourse.group/u/Jaejong)\
**Post date:** [September 16, 2025, 4:16pm UTC](https://janus.discourse.group/t/videoroom-crash-in-janus-videoroom-reqpli-function-on-janus-v1-3-2/1718/3 "2025-09-16T16:16:45Z")

</div>

Lorenzo, Thanks for replying.  
I understand and I have one opinion.

I think the core of this issue is that ps-\>publisher becomes NULL before the (publisher stream) ps is freed.  
In the commit below, the janus\_videoroom\_publisher\_stream\_destroy() function was added, and when removing participant-\>streams\_byid, ps-\>publisher is set to NULL. I assume there must be a reason for this.

```auto
git commit - 2022-02-11 Support for multistream PeerConnections (replaces #1459) (#2211)

	publisher->streams_byid = g_hash_table_new_full(NULL, NULL,
		NULL, (GDestroyNotify)janus_videoroom_publisher_stream_destroy);
	publisher->streams_bymid = g_hash_table_new_full(g_str_hash, g_str_equal,
		(GDestroyNotify)g_free, (GDestroyNotify)janus_videoroom_publisher_stream_unref);

```

```auto
static void janus_videoroom_hangup_media_internal(gpointer session_data) {
	...
	g_hash_table_remove_all(participant->streams_byid);
	g_hash_table_remove_all(participant->streams_bymid);
	...
}

static void janus_videoroom_publisher_stream_destroy(janus_videoroom_publisher_stream *ps) {
	if(ps && g_atomic_int_compare_and_exchange(&ps->destroyed, 0, 1)) {
		if(ps->publisher)
			janus_refcount_decrease(&ps->publisher->ref);
		ps->publisher = NULL;
		janus_refcount_decrease(&ps->ref);
	}
	/* TODO Should unref the publisher instance? */
}

```

  

**I’m wondering if it can be handled using either method ① or ②.**

**① Add a janus\_refcount\_decrease(&ps-\>publisher-\>ref) call inside janus\_videoroom\_publisher\_stream\_free.**  
 → It is possible to access ps-\>publisher until the (publisher stream) ps is freed.

**② When removing publisher-\>streams\_byid, only perform janus\_refcount\_decrease.**  
 → In janus\_videoroom\_publisher\_free, janus\_videoroom\_publisher\_stream\_destroy is executed via  
g\_list\_free\_full(p-\>streams, (GDestroyNotify)(janus\_videoroom\_publisher\_stream\_destroy));

---

<div class="post-metadata">

**Author:** ![Jaejong](https://avatars.discourse-cdn.com/v4/letter/j/e47774/32.png) [@Jaejong](https://janus.discourse.group/u/Jaejong)\
**Post date:** [September 18, 2025, 6:28am UTC](https://janus.discourse.group/t/videoroom-crash-in-janus-videoroom-reqpli-function-on-janus-v1-3-2/1718/4 "2025-09-18T06:28:29Z")

</div>

I’ve added the NULL check and am testing it now. I’ll share any issues if they come up.

---

<div class="post-metadata">

**Author:** ![lorenzo](https://yyz2.discourse-cdn.com/free1/user_avatar/janus.discourse.group/lorenzo/32/425_2.png) [@lorenzo](https://janus.discourse.group/u/lorenzo)\
**Post date:** [September 18, 2025, 8:18am UTC](https://janus.discourse.group/t/videoroom-crash-in-janus-videoroom-reqpli-function-on-janus-v1-3-2/1718/5 "2025-09-18T08:18:20Z")

</div>

> [@Jaejong](#):
>
> **① Add a janus\_refcount\_decrease(&ps-\>publisher-\>ref) call inside janus\_videoroom\_publisher\_stream\_free.**  
> → It is possible to access ps-\>publisher until the (publisher stream) ps is freed.

No, free must only free stuff. Crossed references are already dealt in different ways.

> [@Jaejong](#):
>
> **② When removing publisher-\>streams\_byid, only perform janus\_refcount\_decrease.**  
> → In janus\_videoroom\_publisher\_free, janus\_videoroom\_publisher\_stream\_destroy is executed

The destroy callback function already only uses the refcount decrease. I don’t know what version you’re looking at, but I don’t see any `g_list_free_full` in `janus_videoroom_publisher_stream_destroy`. Stuff is only freed if a refcount decrease brings the reference count to 0.

---

<div class="post-metadata">

**Author:** ![Jaejong](https://avatars.discourse-cdn.com/v4/letter/j/e47774/32.png) [@Jaejong](https://janus.discourse.group/u/Jaejong)\
**Post date:** [September 18, 2025, 8:59am UTC](https://janus.discourse.group/t/videoroom-crash-in-janus-videoroom-reqpli-function-on-janus-v1-3-2/1718/7 "2025-09-18T08:59:44Z")

</div>

Thanks for replying.

`g_list_free_full` in janus\_videoroom\_publisher\_free() function.

When a publisher is freed, all its streams are deleted through the `janus_videoroom_publisher_stream_destroy()` function."

```auto
janus_videoroom_publisher_free() {
	....
	/* Get rid of all the streams */
	g_list_free_full(p->streams, (GDestroyNotify)(janus_videoroom_publisher_stream_destroy));
	...
}

```
