View Issue Details

IDProjectCategoryView StatusLast Update
0001598unrealircdpublic2004-03-31 18:37
Reporterliverbugg Assigned Tosyzop  
PrioritynormalSeveritycrashReproducibilityalways
Status closedResolutionfixed 
Product Version3.2-RC1 
Summary0001598: Opteron crashes when linked
DescriptionWe are runing Unreal on a AMD Opteron and it runs fine as a single server. But when we link in a IA32 machine (Athlon XP) if a client quits, then reconnects from the same IP, ircd segfaults on the Opteron. The 32 bit server stays up and will relink with the Opteron when ircd is restarted, but as long as clients keep reconnecting to the Opteron, it keeps crashing. We tested with 2 32 bit servers to make sure the config was right. They don't crash.
Steps To ReproduceLink a Opteron to a 32 bit intel server. connect to the Opteron. disconnect. reconnect.
Additional InformationBoth servers have 2 NICs, a public and a private. The servers link over the private network and clients connect to each public.
3rd party modules

Activities

syzop

2004-02-27 15:33

administrator   ~0005232

Could you do a gdb backtrace?
--
gdb src/ircd name.of.core.file
bt
--
(core file is usually called 'core' 'core.<number>' 'ircd.core' 'ircd.core.<number>' you get the idea...)
Thanks :)

syzop

2004-03-01 21:54

administrator   ~0005264

Unfortunately without a gdb backtrace we can't help.

syzop

2004-03-01 22:32

administrator   ~0005266

For what it's worth: I wasn't able to reproduce this on ia64<->ia64 (itanium 2.. so not an opteron, don't have access to such a machine), and I cannot test ia64<->ia32 due to firewall restrictions, so again.. a backtrace would be helpful.

syzop

2004-03-02 15:42

administrator   ~0005270

15 minutes after the bugreport was posted a request for more info was made, now 5 days ago still no reply... closing bug.

liverbugg

2004-03-02 19:24

reporter   ~0005274

Sorry the admin for the opteron was away for the weekend.

Heres the backtrace

# gdb src/ircd core
GNU gdb 6.0
Copyright 2003 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and you are
welcome to change it and/or distribute copies of it under certain conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB. Type "show warranty" for details.
This GDB was configured as "x86_64-pc-linux-gnu"...Using host libthread_db library "/lib/libthread_db.so.1".

Core was generated by `/root/Unreal3.2/src/ircd'.
Program terminated with signal 11, Segmentation fault.
Reading symbols from /usr/lib/libssl.so.0.9.7...done.
Loaded symbols for /usr/lib/libssl.so.0.9.7
Reading symbols from /usr/lib/libcrypto.so.0.9.7...done.
Loaded symbols for /usr/lib/libcrypto.so.0.9.7
Reading symbols from /lib/libcrypt.so.1...done.
Loaded symbols for /lib/libcrypt.so.1
Reading symbols from /lib/libnsl.so.1...done.
Loaded symbols for /lib/libnsl.so.1
Reading symbols from /lib/libz.so.1...done.
Loaded symbols for /lib/libz.so.1
Reading symbols from /lib/libdl.so.2...done.
Loaded symbols for /lib/libdl.so.2
Reading symbols from /lib/libc.so.6...done.
Loaded symbols for /lib/libc.so.6
Reading symbols from /lib64/ld-linux-x86-64.so.2...done.
Loaded symbols for /lib64/ld-linux-x86-64.so.2
Reading symbols from tmp/99174207.commands.so...done.
Loaded symbols for tmp/99174207.commands.so
#0 find_server_quick_search (name=0x6513ed "irc.lanchelms.com") at aln.c:146
146 if (!match(name, lp->value.cptr->name))
(gdb) bt
#0 find_server_quick_search (name=0x6513ed "irc.lanchelms.com") at aln.c:146
#1 0x000000000040fbf1 in find_server_quickx (
    name=0x6513ed "irc.lanchelms.com", cptr=0x0) at aln.c:167
#2 0x0000000000451d98 in sendto_serv_butone_token_opt (one=0x6cb060,
    opt=1280, prefix=0x6513ed "irc.lanchelms.com", command=0x466d76 "SJOIN",
    token=0x46c1f6 "~", pattern=0x466d69 "%B %s :%s%s ") at send.c:784
#3 0x0000000000416fb0 in join_channel (chptr=0x6cb6f0, cptr=0x6cb060,
    sptr=0x6cb060, flags=1) at channel.c:3676
#4 0x000000000041778d in do_join (cptr=0x6cb060, sptr=0x6cb060,
    parc=774778414, parv=0x61fcc0) at channel.c:3967
#5 0x0000000000416e5e in m_join (cptr=0x6cb060, sptr=0x6cb060, parc=2,
    parv=0x61fcc0) at channel.c:3631
#6 0x000000000042a614 in parse (cptr=0x6cb060, buffer=0x6cb18c "JOIN",
    bufend=0x69b1d0 "") at parse.c:453
#7 0x0000000000429206 in dopacket (cptr=0x6cb060, buffer=0x0, length=0)
    at packet.c:138
0000008 0x00000000004300ce in read_packet (cptr=0x6cb060, rfd=0xc) at s_bsd.c:1476
#9 0x0000000000430951 in read_message (delay=1, listp=0x652d60)
    at s_bsd.c:1937
#10 0x0000000000425c79 in main (argc=2, argv=0xbffff878) at ircd.c:1431

syzop

2004-03-02 19:41

administrator   ~0005275

Ok.

Could you type the following in gdb:
--
p *lp
p *lp->value.cptr
--
Also, just to be sure, could you check if you still have this problem with latest CVS? (use: http://www.vulnscan.org/UnrealIrcd/cvs/Unr3.2-20040301.tar.gz ).. A few memory corruption bugs were fixed in it but I don't know if they could have affected you.

Do you use any of the following features: SSL, ziplinks, spamfilter, remote includes?

Did you have any previous unrealircd installed before on this machine? (I presume not but...) if so, did you have any problems?

Thanks.

liverbugg

2004-03-02 19:48

reporter   ~0005276

More info:

It crashes on other client commands after they reconnect, not just /join. /oper and /whois crash. If the opteron server is started first, and then the other server started, clients can connect to the opteron once and have to disconnect and reconnect before it crashes like I said before. But if the opteron is restarted after a crash and relinks with the other server, then any client connecting and giving a command makes it crash, no disconnecting and reconnecting required.

liverbugg

2004-03-02 19:51

reporter   ~0005277

(gdb) p *lp
Cannot access memory at address 0x536b4b37006ba320
(gdb) p *lp->value.cptr
Cannot access memory at address 0x536b4b37006ba330

We use ziplinks but the crashes happen without them also.

This is the first Unreal install on here. I'll give the cvs a try.

syzop

2004-03-02 19:56

administrator   ~0005278

hmm fun.
dunnow if you can still do gdb (I hope you are installing in a different dir ;p... else nevermind and we'll wait at cvs results), could you do:
p *Servers
p *Servers->next
p *Servers->next->next

liverbugg

2004-03-02 20:06

reporter   ~0005279

(gdb) p *Servers
Cannot access memory at address 0x536b4b37006ba320
(gdb) p *Servers->next
Cannot access memory at address 0x536b4b37006ba320
(gdb) p *Servers->next->next
Cannot access memory at address 0x536b4b37006ba320

CVS crashes the same. Also, I don't see the user who joins to the opteron as being connected if I'm on the other server.

syzop

2004-03-02 20:19

administrator   ~0005280

Hm strange :|. Looks quite hard to debug too (memory corruption or something, perhaps related to make_link or add_server_to_table, but seems weird)...

Could I get access to this machine (or another opteron) to debug it? If so, mail me at [email protected] or msg 'Syzop[AWAY]'/'Syzop' at irc.unrealircd.org.

liverbugg

2004-03-02 20:23

reporter   ~0005281

I'll talk to the admin about giving you access and email with the responce.

syzop

2004-03-05 22:49

administrator   ~0005315

Got a shell (thanks!) and I can confirm this an unreal bug... it's because of mixed int/long use, and since int is 32 bits and long 64 bits on opteron this causes problems (it also seems to be a bit different in paramter passing to functions). Found at least 1 crashbug caused by sendto_nickserv_cmd (or something), but I'm still having problems (I get randomly killed), judging from the gcc warnings I get there are quite some places left too (eg: /stats s where %d is used for sizeof() output).

I'll have a look at this issue again on Sunday, so unfortunately after RC2.. it's not worth committing the bug I found right now anyway since there's more to fix too.

syzop

2004-03-11 17:29

administrator   ~0005429

Fixed several things/bugs now, let's see if that was enough :).

syzop

2004-03-15 10:18

administrator   ~0005498

[merged dup 0001651]

syzop

2004-03-15 10:21

administrator   ~0005499

I'll keep the report open for a few days to see if any opteron users still experience problems :).

liverbugg

2004-03-15 21:57

reporter   ~0005504

Haven't had a chance to test this because the server got powered off and no one has access to it until Sunday. Will test asap.

syzop

2004-03-15 23:16

administrator   ~0005505

ok, thanks :).

liverbugg

2004-03-31 18:07

reporter   ~0005698

Finaly had the chance to test. It looks like its fixed. If I run in to any other commands or actions that cause a similar crash I'll update this bug. Thanks for the fix.

syzop

2004-03-31 18:37

administrator   ~0005701

Ok, thanks for your help :).

I'll just close the bug for now, if you have any crash again mail [email protected] or re-report it here (whatever you prefer).

Issue History

Date Modified Username Field Change
2004-02-27 15:12 liverbugg New Issue
2004-02-27 15:33 syzop Note Added: 0005232
2004-03-01 21:54 syzop Note Added: 0005264
2004-03-01 22:32 syzop Note Added: 0005266
2004-03-02 15:42 syzop Status new => closed
2004-03-02 15:42 syzop Note Added: 0005270
2004-03-02 19:24 liverbugg Status closed => feedback
2004-03-02 19:24 liverbugg Resolution open => reopened
2004-03-02 19:24 liverbugg Note Added: 0005274
2004-03-02 19:41 syzop Note Added: 0005275
2004-03-02 19:48 liverbugg Note Added: 0005276
2004-03-02 19:51 liverbugg Note Added: 0005277
2004-03-02 19:56 syzop Note Added: 0005278
2004-03-02 19:58 syzop Status feedback => new
2004-03-02 19:58 syzop Resolution reopened => open
2004-03-02 20:06 liverbugg Note Added: 0005279
2004-03-02 20:19 syzop Note Added: 0005280
2004-03-02 20:23 liverbugg Note Added: 0005281
2004-03-05 22:49 syzop Note Added: 0005315
2004-03-05 22:49 syzop Assigned To => syzop
2004-03-05 22:49 syzop Status new => assigned
2004-03-05 22:49 syzop Projection none => minor fix
2004-03-05 22:49 syzop ETA none => < 1 month
2004-03-11 17:29 syzop Note Added: 0005429
2004-03-15 10:18 syzop Note Added: 0005498
2004-03-15 10:21 syzop Note Added: 0005499
2004-03-15 10:21 syzop Status assigned => feedback
2004-03-15 10:21 syzop Resolution open => fixed
2004-03-15 10:21 syzop Projection minor fix => none
2004-03-15 10:21 syzop ETA < 1 month => none
2004-03-15 21:57 liverbugg Note Added: 0005504
2004-03-15 23:16 syzop Note Added: 0005505
2004-03-31 18:07 liverbugg Note Added: 0005698
2004-03-31 18:37 syzop Status feedback => closed
2004-03-31 18:37 syzop Note Added: 0005701