View Issue Details

IDProjectCategoryView StatusLast Update
0000732unrealircdpublic2003-11-20 19:46
ReporterAngryWolf Assigned Tosyzop  
PrioritynormalSeveritycrashReproducibilityN/A
Status closedResolutionfixed 
Product Version3.2-beta14 
Summary0000732: Crash when linking servers with probably a bad configuration
DescriptionI just wanted to do some testing with the latest cvs. I have three servers installed, one with debug mode. All the servers are compiled with ssl and ziplinks support, and compiled as Hubs. I used the OS provided threads library. (Version numbers mentioned in Additional information.).

A map (which i wanted to make real):

angrywolf.test1.com
|- angrywolf.test2.com
'- debug.test3.com

Link configurations for angrywolf.test1.com:

link angrywolf.test2.com
{
        username *;
        hostname 127.0.0.1;
        bind-ip *;
        port 7665;
        hub *;
        password-connect "something";
        password-receive "something";
        class servers;
        compression-level 9;
        options {
            zip;
            ssl;
        };
};

link debug.test3.com
{
        username *;
        hostname 127.0.0.1;
        bind-ip *;
        port 8665;
        hub *;
        password-connect "something";
        password-receive "something";
        class servers;
        compression-level 9;
        options {
            zip;
            ssl;
        };
};

The others has the following configuration:

link angrywolf.test1.com
{
        username *;
        hostname 127.0.0.1;
        bind-ip *;
        port 6665;
        leaf *;
        password-connect "something";
        password-receive "something";
        class servers;
        compression-level 9;
        options {
            autoconnect;
            zip;
            ssl;
        };
};

Steps which I have done:

1. (on angrywolf.test1.com) /connect angrywolf.test2.com

*** Notice -- (link) Secure ZIPlink angrywolf.test1.com -> angrywolf.test2.com[@127.0.0.1.0] established
+(SSLv3-DES-CBC3-SHA-168bits)
*** (link) Secure ZIPlink angrywolf.test2.com -> angrywolf.test1.com[@127.0.0.1.33462] established
+(SSLv3-DES-CBC3-SHA-168bits)

2. (on debug.test3.com) /connect angrywolf.test1.com

*** (link) Secure ZIPlink angrywolf.test1.com -> debug.test3.com[@127.0.0.1.33561] established
+(SSLv3-DES-CBC3-SHA-168bits)
*** LocOps -- Link angrywolf.test1.com cancelled, is Non-Hub but introduced Leaf debug.test3.com

And a segmentation fault.

I did the same steps with first connecting debug.test3.com and connecting angrywolf.test2.com after.

The results say that I can reproduce the bug with the same
configuration.

By the way, after 5 minutes, I couldn't reproduce the bug.
Steps To ReproduceWrong place, but:

[Sun Feb 16 17:06:03 2003] - Connect - [email protected] [VHOST 3DE8A95.275F8276.4122A6C7.IP]
[Sun Feb 16 17:06:06 2003] - OPER (AngryWolf) by ([email protected])
[Sun Feb 16 17:06:10 2003] - 18
[Sun Feb 16 17:06:10 2003] - 18
[Sun Feb 16 17:11:57 2003] - 18
[Sun Feb 16 17:11:57 2003] - 18
[Sun Feb 16 18:19:11 2003] - Connect - [email protected] [VHOST 3DE8A95.275F8276.4122A6C7.IP]
[Sun Feb 16 18:24:52 2003] - OPER (AngryWolf) by ([email protected])
[Sun Feb 16 19:01:56 2003] - Connect - [email protected] [VHOST 3DE8A95.275F8276.4122A6C7.IP]
[Sun Feb 16 19:02:09 2003] - 18
[Sun Feb 16 19:02:09 2003] - 18
[Sun Feb 16 19:04:30 2003] - Disconnect - (0:2:38) [email protected] [VHOST 3DE8A95.275F8276.4122A6C7.IP
]
[Sun Feb 16 19:04:35 2003] - Connect - [email protected] [VHOST 3DE8A95.275F8276.4122A6C7.IP]
[Sun Feb 16 19:04:45 2003] - Disconnect - (0:0:12) [email protected] [VHOST 3DE8A95.275F8276.4122A6C7.IP
]
[Sun Feb 16 19:04:46 2003] - Connect - [email protected] [VHOST 3DE8A95.275F8276.4122A6C7.IP]
[Sun Feb 16 19:05:37 2003] - 18
[Sun Feb 16 19:05:37 2003] - 18
[Sun Feb 16 19:06:02 2003] - 18
[Sun Feb 16 19:06:02 2003] - 18
[Sun Feb 16 19:07:55 2003] - Connect - [email protected] [VHOST 3DE8A95.275F8276.4122A6C7.IP]
[Sun Feb 16 19:08:34 2003] - Disconnect - (0:0:44) [email protected] [VHOST 3DE8A95.275F8276.4122A6C7.IP]

What are these "18" strings in ircd.log? [All of my servers doing this] :)
Additional Information(gdb) wolf@wolf:~/tmp/ircdd> gdb ircd core
GNU gdb 5.1.1
Copyright 2002 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and you are
welcome to change it and/or distribute copies of it under certain conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB. Type "show warranty" for details.
This GDB was configured as "i386-suse-linux"...
Core was generated by `./ircd -x 10'.
Program terminated with signal 11, Segmentation fault.
Reading symbols from /usr/lib/libssl.so.0.9.6...done.
Loaded symbols for /usr/lib/libssl.so.0.9.6
Reading symbols from /usr/lib/libcrypto.so.0.9.6...done.
Loaded symbols for /usr/lib/libcrypto.so.0.9.6
Reading symbols from /lib/libcrypt.so.1...done.
Loaded symbols for /lib/libcrypt.so.1
Reading symbols from /lib/libnsl.so.1...done.
Loaded symbols for /lib/libnsl.so.1
Reading symbols from /lib/libz.so.1...done.
Loaded symbols for /lib/libz.so.1
Reading symbols from /lib/libdl.so.2...done.
Loaded symbols for /lib/libdl.so.2
Reading symbols from /lib/libpthread.so.0...done.

warning: Unable to set global thread event mask: generic error
[New Thread 1024 (LWP 29809)]
Error while reading shared library symbols:
Cannot enable thread event reporting for Thread 1024 (LWP 29809): generic error
Reading symbols from /lib/libc.so.6...done.
Loaded symbols for /lib/libc.so.6
Reading symbols from /lib/ld-linux.so.2...done.
Loaded symbols for /lib/ld-linux.so.2
Reading symbols from modules/commands.so...done.
Loaded symbols for modules/commands.so
Reading symbols from modules/m_getinfo.so...done.
Loaded symbols for modules/m_getinfo.so
#0 sendto_serv_butone_token (one=0x819b898, prefix=0x819b8c1 "angrywolf.test1.com",
    command=0x402e2eab "SWHOIS", token=0x402e2ea8 "BA", pattern=0x402e2eec "%s :%s") at send.c:566
566 if (acptr->serv->numeric)
(gdb) bt
#0 sendto_serv_butone_token (one=0x819b898, prefix=0x819b8c1 "angrywolf.test1.com",
    command=0x402e2eab "SWHOIS", token=0x402e2ea8 "BA", pattern=0x402e2eec "%s :%s") at send.c:566
#1 0x402d783b in m_swhois (cptr=0x819b898, sptr=0x819b898, parc=3, parv=0x811b680) at m_swhois.c:123
#2 0x08069b5d in parse (cptr=0x819b898, buffer=0x819b97c "BA", bufend=0x819b991 "") at parse.c:450
#3 0x08068653 in dopacket (cptr=0x819b898,
    buffer=0x811c040 "xÚl\217[KÃ@\024\204¡\217\201ü\207#\005Û*\t{IZÉ\203$\215iǬ\025¶PPD6Í\232\006Ó¬$é\rÁßî&E\215Eæmfç;³\016Ïâ|¿\225é«Y\212¢ÄæB®\200ÝMA\202ÓmÂ¥IöÖê\001\023\213u.àñú¡2à¿\212q\t\221\b×qmÑÊzr1\031\230H\t\233\224Ú6y\006\025ñ0M\212Â¥\210 ËØí\206\032W\0013ü¡O\r6ñ\fÜ¿\b\223²èé\232\213¡st\207Ôw\210\222ãUÁ\\\005\235\002f*R\003ó\215Èuí\024~¢\027Àpòq³\237\017 B", length=300) at packet.c:137
#4 0x0806f9c5 in read_packet (cptr=0x819b898, rfd=0xbffff34c) at s_bsd.c:1426
#5 0x0807020e in read_message (delay=0, listp=0x8146340) at s_bsd.c:1896
#6 0x08065ab9 in main (argc=3, argv=0xbffff494) at ircd.c:1335
#7 0x401c39ed in __libc_start_main () from /lib/libc.so.6
(gdb) x/x acptr
0x0: Error accessing memory address 0x0: No such process.
(gdb) x/x acptr->serv
Error accessing memory address 0x10: No such process.
(gdb) x/x acptr->serv->numeric
Error accessing memory address 0x10: No such process.
(gdb) p *acptr->serv
Error accessing memory address 0x10: No such process.
(gdb) p *acptr->serv->numeric
Error accessing memory address 0x10: No such process.


============================

SuSE 8.0
gcc version 2.95.3 20010315 (SuSE)
v3.2-beta14
using OpenSSL 0.9.6g [engine] 9 Aug 2002
using zlib 1.1.3
3rd party modules

Activities

AngryWolf

2003-02-16 18:30

reporter   ~0001599

Oops, what is this looooong table width? :) Bug in mantis, lol :)

AngryWolf

2003-02-16 18:35

reporter   ~0001600

Still trying to reproduce, now I get these:

*** Notice -- Connection to angrywolf.test1.com[127.0.0.1] activated.
*** Notice -- (link) Secure ZIPlink angrywolf.test2.com -> angrywolf.test1.com[@127.0.0.1.0] established
+(SSLv3-DES-CBC3-SHA-168bits)
*** (link) Secure ZIPlink angrywolf.test1.com -> angrywolf.test2.com[@127.0.0.1.33663] established
+(SSLv3-DES-CBC3-SHA-168bits)
*** LocOps -- Link angrywolf.test1.com cancelled, is Non-Hub but introduced Leaf debug.test3.com
*** Notice -- Cannot find server 1 (& AngryWolf_ 1 !{JzIN wolf 10.0.0.1 1 0 +owghaAxNWtG netadmin.test1.com
+:AngryWolf)
*** Notice -- Cannot find server 3 (& AngryWolf 2 !{JzIj wolf 10.0.0.1 3 0 +owghaAxNWtG netadmin.test3.com
+:AngryWolf)
*** Notice -- Missing user AngryWolf in SJOIN for #opers from angrywolf.test1.com (~ !{JzIN #opers
+:AngryWolf @AngryWolf_ )
*** Notice -- Missing user AngryWolf_ in SJOIN for #opers from angrywolf.test1.com (~ !{JzIN #opers
+:AngryWolf @AngryWolf_ )
*** Notice -- Missing user AngryWolf in SJOIN for #tarsalgo from angrywolf.test1.com (~ !{JzIN #tarsalgo
+:AngryWolf @AngryWolf_ )
*** Notice -- Missing user AngryWolf_ in SJOIN for #tarsalgo from angrywolf.test1.com (~ !{JzIN #tarsalgo
+:AngryWolf @AngryWolf_ )
*** Notice -- Link angrywolf.test1.com -> angrywolf.test2.com is now synced [secs: 0 recv: 0.597 sent: 0.
+408]

syzop

2003-02-16 19:08

administrator   ~0001601

Can you disable ssl / zip just to be sure?
Also I have no idea what this "Error accessing memory address 0x0: No such process" is and it sucks.

AngryWolf

2003-02-16 19:25

reporter   ~0001602

Yes, but with ssl/zip enabled still can't reproduce the bug... dunno what am I doing wrong.

AngryWolf

2003-02-16 19:31

reporter   ~0001603

Still can't... I'm doing the same.

*** Notice -- Link angrywolf.test1.com -> angrywolf.test2.com is now synced [secs: 0 recv: 0.620 sent: 0.
+613]
*** (sync) Link angrywolf.test2.com -> angrywolf.test1.com is now synced [secs: 0 recv: 0.613 sent: 0.156]
*** (link) Link angrywolf.test1.com -> debug.test3.com[@127.0.0.1.0] established
*** LocOps -- Link angrywolf.test1.com cancelled, is Non-Hub but introduced Leaf debug.test3.com
*** Signoff: AngryWolf__ (angrywolf.test2.com angrywolf.test1.com)
*** Notice -- Cannot find server 3 (& AngryWolf 2 !{J{Gq wolf 10.0.0.1 3 0 +owghaAxNWtG netadmin.test3.com
+:AngryWolf)

syzop

2003-02-16 19:42

administrator   ~0001604

So this
*** LocOps -- Link angrywolf.test1.com cancelled, is Non-Hub but introduced Leaf debug.test3.com
thing causes those problems I guess? (thats why you said maybe its config?)

*working at some other stuff atm* ;)

AngryWolf

2003-02-16 20:41

reporter   ~0001605

I could reproduce the bug. I started the debug server with parameter -x 10.

#0 sendto_serv_butone_token (one=0x818db70, prefix=0x818db99 "angrywolf.test1.com",
    command=0x402e2eab "SWHOIS", token=0x402e2ea8 "BA", pattern=0x402e2eec "%s :%s") at send.c:566
566 if (acptr->serv->numeric)
(gdb) bt
#0 sendto_serv_butone_token (one=0x818db70, prefix=0x818db99 "angrywolf.test1.com",
    command=0x402e2eab "SWHOIS", token=0x402e2ea8 "BA", pattern=0x402e2eec "%s :%s") at send.c:566
#1 0x402d783b in m_swhois (cptr=0x818db70, sptr=0x818db70, parc=3, parv=0x811b680) at m_swhois.c:123
#2 0x08069b5d in parse (cptr=0x818db70, buffer=0x818dc54 "BA", bufend=0x818dc69 "") at parse.c:450
#3 0x08068653 in dopacket (cptr=0x818db70,
    buffer=0x811c040 ":angrywolf.test1.com NOTICE AUTH :*** Looking up your hostname...\r\n:angrywolf.test1.com NOTICE AUTH :*** Found your hostname (cached)\r\nPROTOCTL NOQUIT TOKEN NICKv2 SJOIN SJOIN2 UMODE2 VL SJ3 NS SJB64\r"..., length=932) at packet.c:137
#4 0x0806f9c5 in read_packet (cptr=0x818db70, rfd=0xbffff34c) at s_bsd.c:1426
#5 0x0807020e in read_message (delay=9, listp=0x814a580) at s_bsd.c:1896
#6 0x08065b71 in main (argc=3, argv=0xbffff494) at ircd.c:1355
#7 0x401c39ed in __libc_start_main () from /lib/libc.so.6
(gdb) print acptr
$1 = (aClient *) 0x0

AngryWolf

2003-02-16 20:42

reporter   ~0001606

Yes, this bug appears when I try /connect angrywolf.test1.com

syzop

2003-02-16 20:55

administrator   ~0001607

I guess the server was not properly dropped / squit / marked dead.

AngryWolf

2003-02-17 18:31

reporter   ~0001618

Last edited: 2003-02-17 18:31

By the way I found something for displaying the following numbers in my ircd.log:

[Sun Feb 16 19:05:37 2003] - 18
[Sun Feb 16 19:05:37 2003] - 18
[Sun Feb 16 19:06:02 2003] - 18

in ssl.c:
------------------
static int ssl_verify_callback(int preverify_ok, X509_STORE_CTX *ctx)
{
        int verify_err = 0;

        verify_err = X509_STORE_CTX_get_error(ctx);
        ircd_log(LOG_ERROR, "%i", verify_err);
------------------

edited on: 02-17 18:31

syzop

2003-02-17 19:04

administrator   ~0001619

k, I've fixed the "18" problem in CVS, thanks for tracing (also removed 2 zip_free debugging things) ;)

AngryWolf

2003-02-18 05:56

reporter   ~0001622

Reproduced the bug in latest cvs..
(1.1.1.1.2.1.2.1.2.1644 2003/02/17 21:11:47)

#0 sendto_serv_butone_token (one=0x818d548, prefix=0x818d571 "angrywolf.test1.com",
    command=0x402e2f8b "SWHOIS", token=0x402e2f88 "BA", pattern=0x402e2fcc "%s :%s") at send.c:566
566 if (acptr->serv->numeric)
(gdb) bt
#0 sendto_serv_butone_token (one=0x818d548, prefix=0x818d571 "angrywolf.test1.com",
    command=0x402e2f8b "SWHOIS", token=0x402e2f88 "BA", pattern=0x402e2fcc "%s :%s") at send.c:566
#1 0x402d78ab in m_swhois (cptr=0x818d548, sptr=0x818d548, parc=3, parv=0x811b4c0) at m_swhois.c:123
#2 0x08069b6d in parse (cptr=0x818d548, buffer=0x818d62c "BA", bufend=0x818d641 "") at parse.c:450
#3 0x08068663 in dopacket (cptr=0x818d548,
    buffer=0x811be80 ":angrywolf.test1.com SMO o :(\002link\002) Link angrywolf.test1.com -> debug.test3.com[@127.0.0.1.0] established\r\n@1 ' angrywolf.test2.com 2 2 :AngryWolf's Test Server\r\n& AngryWolf 1 !{KSRH wolf 10.0.0.1 1 "..., length=631) at packet.c:137
#4 0x0806f9d5 in read_packet (cptr=0x818d548, rfd=0xbffff34c) at s_bsd.c:1426
#5 0x0807021e in read_message (delay=4, listp=0x814a3c0) at s_bsd.c:1896
#6 0x08065b71 in main (argc=3, argv=0xbffff494) at ircd.c:1355
#7 0x401c39ed in __libc_start_main () from /lib/libc.so.6
(gdb) print acptr
$1 = (aClient *) 0x0

debug.log contains:

Sending [:debug.test3.com NOTICE AngryWolf :(^Blink^B) Link angrywolf.test1.com -> debug.test3.com[@127.0.0.1.
0] established] to AngryWolf
Parsing: @1 ' angrywolf.test2.com 2 2 :AngryWolf's Test Server (from angrywolf.test1.com)
FindCommand '
Sending [:debug.test3.com NOTICE AngryWolf :*** LocOps -- Link angrywolf.test1.com cancelled, is Non-Hub but i
ntroduced Leaf angrywolf.test2.com] to AngryWolf
Sending [ERROR :Closing Link: angrywolf.test1.com[127.0.0.1] (Non-Hub Link)] to angrywolf.test1.com
Parsing: & AngryWolf 1 !{KSRH wolf 10.0.0.1 1 0 +owghaAxNWtG netadmin.test1.com :AngryWolf (from angrywolf.tes
t1.com)
FindCommand &
Sending [:debug.test3.com NOTICE AngryWolf :*** Notice -- Cannot find server 1 (& AngryWolf 1 !{KSRH wolf 10.0
.0.1 1 0 +owghaAxNWtG netadmin.test1.com :AngryWolf)] to AngryWolf
Parsing: BA AngryWolf :a coder (from angrywolf.test1.com)
FindCommand BA

{AngryWolf}

2003-02-18 13:49

reporter   ~0001625

Last edited: 2003-02-18 13:50

Just to comment that "Parsing: BA AngryWolf :a coder ": it's just the swhois text adopted from my friend's server, he call me this, because i make him some simple modifications..., so don't think i'm a stuck-up or consequental..

Syzop, I'ld like to "write up" somewhere what you have found in s_serv.c (sendto_serv_butone_token):

---
acptr = (aClient *) find_server_quick(prefix);
if (acptr->serv->numeric)
---

As you said, no NULL check, and if you compare these lines with what is in sendto_serv_butone_token_opt(), you can see NULL pointers handled correctly.

By the way, I don't think that it makes the bug totally fixed. Because after sending a message to the other server about "Closing link", that one still tries to send clients information. I might be wrong, just my ideas.

edited on: 02-18 13:50

syzop

2003-02-18 17:35

administrator   ~0001626

I've told you the CAUSE (the origin, where the problem all starts, look it up in a dictionary.. whatever) is something ELSE..
So this particular pointercheck / whatever is not where you should start fixing it, or well.. you could.. but then you have to fix >50 other "bugs" too since server input is (generally) trusted. See http://www.packetstormsecurity.org/0206-exploits/unreal-dos.txt for a nice example of an idiot (and you will [hopefully] understand why you shouldnt act the same ;P).

*back on topic*
AFAIK right after the "Link angrywolf.test1.com cancelled" the link should be closed, and no further data should have been received, this however does not happen, somehow we still get data from the server while the server is dead/stuff has been freed/etc.
I wasn't able to trace it quickly, however real "live" debugging will help, but like I said: it's not a high priority.
Why not? Because if you set your config right, it's fixed!
I've told you already:
I do NOT say it shouldn't be fixed, I AGREE it shouldn't crash and it SHOULD be fixed, it's however not exactly one of my major concerns right now.
EOF.

AngryWolf

2003-02-18 17:58

reporter   ~0001627

Last edited: 2003-02-18 18:04

Right. If I try to fix the bug above, I will see there is another one:

#0 0x0807f454 in exit_client (cptr=0x818a018, sptr=0x818a018, from=0x8145ba0,
    comment=0x402ba980 "Transport endpoint is not connected") at s_misc.c:400
400 sptr->serv->conf->refcount--;
(gdb) bt
#0 0x0807f454 in exit_client (cptr=0x818a018, sptr=0x818a018, from=0x8145ba0,
    comment=0x402ba980 "Transport endpoint is not connected") at s_misc.c:400
#1 0x08070446 in read_message (delay=1, listp=0x8147220) at s_bsd.c:1965
#2 0x08065ac8 in main (argc=1, argv=0xbffff4a4) at ircd.c:1336
#3 0x401c39ed in __libc_start_main () from /lib/libc.so.6
(gdb) print sptr
$1 = (aClient *) 0x818a018
(gdb) print sptr->serv
$3 = (aServer *) 0x0

However, I don't wholly agree about just letting a configuration make ircd crash, and the problems described in unreal-dos.txt are far away from this type of bug.

"look it up in a dictionary" ==> what should I look up? By the way, I always use a dictionary if I don't know a word, heh..

And you're not the only Unreal coder, are you? If you are working on another task, no problem, I'll wait. If it's low priority, then I can only say no wonder if you get a lot of bugreports about "ircd crashes randomly, can't reproduce", and so on.

But I don't want to be rude. End for now.

edited on: 02-18 18:04

syzop

2003-02-18 18:05

administrator   ~0001628

You don't understand, could be me.. could be you.. nevermind. Final comment:
>And you're not the only Unreal coder, are you?
Exactly, thats what I ment, someone else can do that, for me it's not high priority.

AngryWolf

2003-02-18 18:23

reporter   ~0001629

Oops, sorry, I lost all hopes when you told me it's not a high priority...

AngryWolf

2003-03-13 06:03

reporter   ~0001915

Now I tried the same linking without enabling debugging, so server1.test.com and server2.test.com were linked, i wanted to bring up server3.test.com on the network, but server2 closed the conenction and server3 segfaulted.

#0 0x0807dfeb in m_netinfo (cptr=0x817dac0, sptr=0x817dac0, parc=9, parv=0x8113920) at s_serv.c:1504
1504 if ((MyConnect(cptr)) && (IsZipped(cptr)) && cptr->zip->in->total_out && cptr->zip->out->total_in) {
(gdb) bt
#0 0x0807dfeb in m_netinfo (cptr=0x817dac0, sptr=0x817dac0, parc=9, parv=0x8113920) at s_serv.c:1504
#1 0x0806755b in parse (cptr=0x817dac0, buffer=0x817dba4 "AO", bufend=0x817dbcd "") at parse.c:449
#2 0x08066173 in dopacket (cptr=0x817dac0,
    buffer=0x81142c0 ":server1.test.com NOTICE AUTH :*** Looking up your hostname...\r\n:server1.test.com NOTICE AUTH :*** Checking ident...\r\n:server1.test.com NOTICE AUTH :*** Received identd response\r\n:server1.test.com NOT"..., length=678) at packet.c:137
#3 0x0806c5f5 in read_packet (cptr=0x817dac0, rfd=0xbffff958) at s_bsd.c:1430
#4 0x0806ce0f in read_message (delay=1, listp=0x813f160) at s_bsd.c:1905
#5 0x08063bc8 in main (argc=1, argv=0xbffffabc) at ircd.c:1336
#6 0x401891c4 in __libc_start_main () from /lib/libc.so.6
(gdb) print *cptr
$1 = {next = 0x402921d8, prev = 0x402921d8, hnext = 0x0, user = 0x0, serv = 0x817de60,
  lastnick = 1047535310, flags = 17043616, umodes = 0, from = 0x0, fd = -2, hopcount = 1 '\001',
  name = "server1.test.com", '\0' <repeats 47 times>, username = "wolf\0\0\0\0\0\0",
  info = "Test1 IRC Server", '\0' <repeats 34 times>, srvptr = 0x813dae0, status = 0, count = 0, oflag = 0,
  since = 1047535318, firsttime = 1047535310, lasttime = 1047535311, last = 0, nexttarget = 0, nextnick = 0,
  targets = '\0' <repeats 19 times>,
  buffer = "AO\01\01047535310\02303\045CFE2A0\00\00\00\0:TEST\0wghaAxNWtG\0netadmin.test.com\0:I'm using X-chat, heh\04714] established", '\0' <repeats 400 times>, lastsq = 0, sendQ = {length = 0, offset = 0,
    head = 0x0, tail = 0x0}, recvQ = {length = 0, offset = 0, head = 0x0, tail = 0x0}, proto = 3071,
  sendM = 6, sendK = 0, receiveM = 14, zip = 0x0, ssl = 0x0, lastrecvM = 0, priority = 0, receiveK = 0,
  sendB = 145, receiveB = 678, listener = 0x813dae0, class = 0x816f748, authfd = -1, slot = -1, ip = {
    s_addr = 16777343}, port = 0, hostp = 0x0, watches = 0, watch = 0x0,
  sockhost = "127.0.0.1", '\0' <repeats 54 times>, passwd = 0x0, error_str = 0x0}
(gdb) print *cptr->zip
Cannot access memory at address 0x0

AngryWolf

2003-03-13 06:06

reporter   ~0001916

No, server2 segfaulted too

#0 0x08066234 in dopacket (cptr=0x817dac0, buffer=0x81142c0 " \234\226\223\020\223ÆøbÒ\004-&\035\f\025Ô¡)",
    length=44) at packet.c:189
189 if ((IsZipped(cptr)) && cptr->zip->incount)
(gdb) bt
#0 0x08066234 in dopacket (cptr=0x817dac0, buffer=0x81142c0 " \234\226\223\020\223ÆøbÒ\004-&\035\f\025Ô¡)",
    length=44) at packet.c:189
#1 0x0806c5f5 in read_packet (cptr=0x817dac0, rfd=0xbffff968) at s_bsd.c:1430
#2 0x0806ce0f in read_message (delay=9, listp=0x8142300) at s_bsd.c:1905
#3 0x08063c71 in main (argc=1, argv=0xbffffabc) at ircd.c:1355
#4 0x401891c4 in __libc_start_main () from /lib/libc.so.6
(gdb) print *cptr
$3 = {next = 0x402921d8, prev = 0x402921d8, hnext = 0x0, user = 0x0, serv = 0x817de60,
  lastnick = 1047535274, flags = 19140768, umodes = 0, from = 0x0, fd = -2, hopcount = 1 '\001',
  name = "server1.test.com", '\0' <repeats 47 times>, username = "wolf\0\0\0\0\0\0",
  info = "Test1 IRC Server", '\0' <repeats 34 times>, srvptr = 0x813dae0, status = 0, count = 0, oflag = 0,
  since = 1047535304, firsttime = 1047535274, lasttime = 1047535304, last = 1047535275, nexttarget = 0,
  nextnick = 0, targets = '\0' <repeats 19 times>,
  buffer = "\n1 '\0server3.test.com\02\03\0:Test3 IRC Server\0rver1.test.com -> server3.test.com[[email protected]] established\0ent: 0.658]", '\0' <repeats 388 times>, lastsq = 0, sendQ = {length = 0, offset = 0,
    head = 0x0, tail = 0x0}, recvQ = {length = 0, offset = 0, head = 0x0, tail = 0x0}, proto = 3071,
  sendM = 7, sendK = 0, receiveM = 16, zip = 0x0, ssl = 0x0, lastrecvM = 0, priority = 0, receiveK = 0,
  sendB = 331, receiveB = 772, listener = 0x813dae0, class = 0x816f748, authfd = -1, slot = -1, ip = {
    s_addr = 16777343}, port = 0, hostp = 0x0, watches = 0, watch = 0x0,
  sockhost = "127.0.0.1", '\0' <repeats 54 times>, passwd = 0x0, error_str = 0x0}
(gdb) print cptr->zip
$2 = (struct Zdata *) 0x0

AngryWolf

2003-03-13 06:11

reporter   ~0001917

Well, the problem was that I specified hub *; for a leaf server and vice versa, so it's working with the right config...

syzop

2003-04-16 16:33

administrator   ~0002357

Last edited: 2003-04-16 16:35

Hm, traced. [oh and btw, I said that about your config a few months ago, but I guess the above comment is just "for the record" :P]

edited on: 04-16-03 16:35

syzop

2003-04-16 17:08

administrator   ~0002358

Fixed in .1739.

Issue History

Date Modified Username Field Change
2003-04-16 16:33 syzop Note Added: 0002357
2003-04-16 16:35 syzop Note Edited: 0002357
2003-04-16 17:08 syzop Status new => resolved
2003-04-16 17:08 syzop Resolution open => fixed
2003-04-16 17:08 syzop Assigned To => syzop
2003-04-16 17:08 syzop Note Added: 0002358
2003-11-20 19:46 syzop Status resolved => closed