View Issue Details

IDProjectCategoryView StatusLast Update
0001237unrealircdpublic2003-11-20 19:43
ReporterRocko Assigned Tosyzop  
PrioritynormalSeveritycrashReproducibilityalways
Status closedResolutionfixed 
Product Version3.2-beta17 
Summary0001237: Crash with the new channelmode +f and services, part 2
DescriptionOkay, here we go again.
Sorry, I haven't tested +f, when it gets triggered ;)

1. Crash when I do "/knock #channel Text" and services are linked.

2. Crash when the protection get triggered and services are linked. Example: You have set +f [15c#M]:60, do 15 ctcps in 60 seconds.. server sets +M and crash. (The other server where services are linked)
Additional Informationcore from the /knock crash.

Program terminated with signal 11, Segmentation fault.
Reading symbols from /usr/lib/libssl.so.0.9.6...done.
Loaded symbols for /usr/lib/libssl.so.0.9.6
Reading symbols from /usr/lib/libcrypto.so.0.9.6...done.
Loaded symbols for /usr/lib/libcrypto.so.0.9.6
Reading symbols from /lib/libcrypt.so.1...done.
Loaded symbols for /lib/libcrypt.so.1
Reading symbols from /lib/libnsl.so.1...done.
Loaded symbols for /lib/libnsl.so.1
Reading symbols from /lib/libdl.so.2...done.
Loaded symbols for /lib/libdl.so.2
Reading symbols from /lib/libc.so.6...done.
Loaded symbols for /lib/libc.so.6
Reading symbols from /lib/ld-linux.so.2...done.
Loaded symbols for /lib/ld-linux.so.2
Reading symbols from src/modules/commands.so...done.
Loaded symbols for src/modules/commands.so
#0 0x08054c9d in can_send (cptr=0x81dbc48, chptr=0x81fbee0,
    msgtext=0x81dbd67 "[Knock] by [email protected] (Huhu) ") at channel.c:800
800 lp = find_membership_link(cptr->user->channel, chptr);
(gdb) bt
#0 0x08054c9d in can_send (cptr=0x81dbc48, chptr=0x81fbee0,
    msgtext=0x81dbd67 "[Knock] by [email protected] (Huhu) ") at channel.c:800
#1 0x40274f5e in m_message (cptr=0x81dbc48, sptr=0x81dbc48, parc=3, parv=0x811b360, notice=1) at m_message.c:396
#2 0x40275655 in m_notice (cptr=0x81dbc48, sptr=0x81dbc48, parc=3, parv=0x811b360) at m_message.c:620
#3 0x08069edb in parse (cptr=0x81dbc48, buffer=0x81dbd2c ":server.TEST.net NOTICE", bufend=0x81dbda8 "") at parse.c:471
#4 0x08068ad8 in dopacket (cptr=0x81dbc48,
    buffer=0x811bd00 ":server.TEST.net NOTICE @#Test :[Knock] by [email protected] (Hu
hu) \r\nregistered. Here on blah, we provide our users with services that a"..., length=126) at packet.c:137
#5 0x0806efbf in read_packet (cptr=0x81dbc48, rfd=0xbffffa1c) at s_bsd.c:1443
#6 0x0806f81f in read_message (delay=1, listp=0x812c340) at s_bsd.c:1927
#7 0x080662e8 in main (argc=1, argv=0xbffffb74) at ircd.c:1368
3rd party modules

Activities

syzop

2003-09-07 15:37

administrator   ~0003615

Hm I think this (or at least one of the bugs) is because of my +mu fixes.
Could you type in gdb:
p *cptr
p *chptr
I think I forgot to check at multiple places if the sender is a server or user :/.

syzop

2003-09-07 15:50

administrator   ~0003616

Hm, recheckout CVS, fix was channel.c (in can_send) line 796:
    if (!MyClient(cptr))
to
    if (!MyClient(cptr) && IsClient(cptr))

Rocko

2003-09-07 15:54

reporter   ~0003617

Okay.

(gdb) p *cptr
$1 = {next = 0x81e1650, prev = 0x81e8cc0, hnext = 0x81dd118, user = 0x0, serv = 0x81dbfe8, lastnick = 1062932305, flags = 270798976,
  umodes = 0, from = 0x81dbc48, fd = 4, hopcount = 1 '\001', name = "server.TEST.net", '\0' <repeats 28 times>,
  username = "rocko\0\0\0\0\0", info = "TEST Server [SSL - Port 6670]\0\0\0\0\0\0\0\0\0", srvptr = 0x812aa40, status = 0,
  count = 0, oflag = 0, since = 1062932589, firsttime = 1062932305, lasttime = 1062932589, last = 1062932306, nexttarget = 0, nextnick = 0,
  targets = '\0' <repeats 19 times>,
  buffer = ":server.TEST.net NOTICE\0@#Test\0:[Knock] by [email protected] (blah) \0x.
net is now synced [secs: 0 recv: 3.714 sent: 1.903]\0d (SSLv3-DES-CBC3-SHA"..., lastsq = 0, sendQ = {length = 0, offset = 0, head = 0x0,
    tail = 0x0}, recvQ = {length = 0, offset = 0, head = 0x0, tail = 0x0}, nospoof = 0, proto = 2943, sendM = 106, sendK = 7, receiveM = 53,
  ssl = 0x81dc030, lastrecvM = 0, priority = 4, receiveK = 3, sendB = 651, receiveB = 66, listener = 0x812aa40, class = 0x81d07f8,
  authfd = -1, slot = 2, ip = {s_addr = 1003987161}, port = 0, hostp = 0x0, watches = 0, watch = 0x0,
  sockhost = "217.160.215.12", '\0' <repeats 49 times>, passwd = 0x0, error_str = 0x0}
(gdb) p *chptr
$2 = {nextch = 0x81e1838, prevch = 0x0, hnextch = 0x0, mode = {mode = 38960, limit = 0, key = '\0' <repeats 23 times>,
    link = '\0' <repeats 32 times>, floodprot = 0x81e9070}, creationtime = 1062932221,
  topic = 0x81e89d0 "\00311,10[\0031]\0038,1\037¯\00313,6[\0031]\0038,1¯\00311,10[\0031]\0038,1¯\00313,6[\0031]\0038,1¯\00311,10[\0031]\037\00
39,6 Welcome To \002#Test\002. This is the official \002Test\002 Network Channel \00311,10[\0031]\0038,1\037¯\00313,6[\0031]\003
8,1¯\00311,10[\0031]\0038,1¯\0031"..., topic_nick = 0x81e8ab8 "[email protected]", topic_time = 1062187754,
  users = 2, members = 0x81e6e18, invites = 0x0, banlist = 0x0, exlist = 0x0, chname = "#"}

Rocko

2003-09-07 15:56

reporter   ~0003618

Ups, you was faster.. ok, I am testing it.

Rocko

2003-09-07 16:18

reporter   ~0003619

Ok, that part is now fixed too.

Cool how fast I found it or?
I found that bug 2 days ago, but hadn't time to report it ;)

syzop

2003-09-07 16:45

administrator   ~0003620

Good.

Bug was introduced Thu Sep 4 19:04:40 2003 UTC (2 days, 21 hours ago), so I guess you found it pretty soon then.. :).

Issue History

Date Modified Username Field Change
2003-09-07 10:42 Rocko New Issue
2003-09-07 15:37 syzop Note Added: 0003615
2003-09-07 15:50 syzop Note Added: 0003616
2003-09-07 15:54 Rocko Note Added: 0003617
2003-09-07 15:56 Rocko Note Added: 0003618
2003-09-07 16:18 Rocko Note Added: 0003619
2003-09-07 16:45 syzop Status new => resolved
2003-09-07 16:45 syzop Resolution open => fixed
2003-09-07 16:45 syzop Assigned To => syzop
2003-09-07 16:45 syzop Note Added: 0003620
2003-11-20 19:43 syzop Status resolved => closed