View Issue Details

IDProjectCategoryView StatusLast Update
0000773unrealircdpublic2003-11-20 19:43
Reporter[email protected] Assigned Toluke  
PrioritynormalSeveritymajorReproducibilitysometimes
Status closedResolutionfixed 
Summary0000773: [Stable] All IRC Server Crash at the Same Time !
DescriptionAll Servers Crash at the Same Time, and this was the Secound Time today.

%gdb src/ircd ircd.core
GNU gdb 4.18 (FreeBSD)
Copyright 1998 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and you are
welcome to change it and/or distribute copies of it under certain conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB. Type "show warranty" for details.
This GDB was configured as "i386-unknown-freebsd"...Deprecated bfd_read called at /usr/src/gnu/usr.bin/binutils/gdb/../../../../contrib/gdb/gdb/dbxread.c line 2627 in elfstab_build_psymtabs
Deprecated bfd_read called at /usr/src/gnu/usr.bin/binutils/gdb/../../../../contrib/gdb/gdb/dbxread.c line 933 in fill_symbuf

Core was generated by `ircd'.
Program terminated with signal 11, Segmentation fault.
Reading symbols from /usr/lib/libssl.so.2...done.
Reading symbols from /usr/lib/libcrypto.so.2...done.
Reading symbols from /usr/lib/libcrypt.so.2...done.
Reading symbols from /usr/lib/libc.so.4...done.
Reading symbols from /usr/libexec/ld-elf.so.1...done.
#0 ircvsprintf (str=0x811f180 "NOTICE ALL :SEGFAULT! I'm Meeeeellllting, what a world!\r\n",
    format=0xbfbfd695 "@%s) MODE %s %s %s", vl=0xbfbfda68 "") at ircsprintf.c:289
289 if ((*str = *p1))
(gdb) bt
#0 ircvsprintf (str=0x811f180 "NOTICE ALL :SEGFAULT! I'm Meeeeellllting, what a world!\r\n",
    format=0xbfbfd695 "@%s) MODE %s %s %s", vl=0xbfbfda68 "") at ircsprintf.c:289
#1 0x80855f5 in vsendto_one (to=0x81f3800,
    pattern=0xbfbfd650 ":irc1.bsl.ch.swissirc.net NOTICE AciDBurN :*** OperOverride -- %s (%s@%s) MODE %s %s %s",
    vl=0xbfbfda60 "3\214\025\b@") at send.c:206
#2 0x8086a6b in sendto_umode (umodes=131072, pattern=0x8089e80 "*** OperOverride -- %s (%s@%s) MODE %s %s %s")
    at send.c:1308
#3 0x804e59c in set_mode (chptr=0x8187f00, cptr=0x8158c00, parc=2, parv=0x8122ac4, pcount=0xbfbfdb30, pvar=0xbfbfef9c,
    bounce=0 '\000') at channel.c:2221
#4 0x8055215 in m_sjoin (cptr=0x8158c00, sptr=0x816fe00, parc=6, parv=0x8118ae0) at channel.c:5065
#5 0x806529b in parse (cptr=0x8158c00, buffer=0x8158cdc "@1 ~", bufend=0x8158cfb "", mptr=0x80a9718) at parse.c:479
#6 0x8064b57 in dopacket (cptr=0x8158c00,
    buffer=0x8119620 "@1 ~ !{IsHf #mayday +o sl33p^ :\r\n ~ !{Psbd #techno :@sl33p^ \r\n@Z ~ !{Psbd #chillout :@sl33p^ \r\n.net\r\nSi l'ho capito\r\n] \00312\002(\002\017karen\00312\002)\002:\017 ok???\r\n Ih Ih Oh uhhhhhhh ahhhhhhh MhMhMHHHmmHmMMM\r\naaaaaaaa"..., length=33) at packet.c:121
#7 0x8069293 in read_packet (cptr=0x8158c00, rfd=0xbfbffaa0) at s_bsd.c:1628
0000008 0x80699d7 in read_message (delay=1, listp=0x81243c0) at s_bsd.c:2179
#9 0x80638b0 in main (argc=1, argv=0xbfbffc04) at ircd.c:1386
(gdb)
Additional Information-
(16:31:15) -irc.genotec.ch- *** Notice -- Client connecting at irc0.pmo.it.swissirc.net: sl33p^ ([email protected])
-
(16:31:16) -irc.genotec.ch- *** Notice -- Recieved first Segfault, doing re-enter test
-
(16:31:16) -irc.genotec.ch- *** Notice -- Aieeee!!! Server terminating: Segmention fault (buf: @1 ~ !{IsHf #mayday +o sl33p^ :)
-
(16:31:16) -irc.genotec.ch- SEGFAULT! I'm Meeeeellllting, what a world!
-
(16:31:16) -irc.genotec.ch- *** Notice -- Dumped core to core - please read Unreal.nfo on what to do!
-
3rd party modules

Activities

syzop

2003-04-18 15:57

administrator   ~0002405

Luke: this same bug was present in 3.2, it's because opermode is not set to 0 after calling do_mode in m_mode/m_samode, so it will stay at 1 or 2... then in the next sjoin call which calls set_mode directly it will think it needs to send a operoverride message (which it shouldn't) and crashes because of a NULL pointer.

[email protected]

2003-05-10 15:51

reporter   ~0002743

Is ther any Solution for this right now ?

syzop

2003-05-10 16:25

administrator   ~0002744

yes, 3.2beta16 :PPP.

luke

2003-06-23 03:03

reporter   ~0003063

Resolved in 3.1.7-Jones Beta1.

Issue History

Date Modified Username Field Change
2003-04-11 20:10 codemastr Assigned To => luke
2003-04-11 20:10 codemastr Status new => assigned
2003-04-18 15:57 syzop Note Added: 0002405
2003-05-10 15:51 [email protected] Note Added: 0002743
2003-05-10 16:25 syzop Note Added: 0002744
2003-06-23 03:03 luke Status assigned => resolved
2003-06-23 03:03 luke Resolution open => fixed
2003-06-23 03:03 luke Note Added: 0003063
2003-11-20 19:43 syzop Status resolved => closed