View Issue Details

IDProjectCategoryView StatusLast Update
0000775unrealircdpublic2003-11-20 19:46
Reportermonolith Assigned Tosyzop  
PrioritynormalSeveritycrashReproducibilityhave not tried
Status closedResolutionfixed 
Product Version3.2-beta15 
Summary0000775: /who *121* crashes ircd
DescriptionHad an oper type /who *121* and the ircd crashed, corefile clearly shows this was the offending command.
Steps To ReproduceWould assume /who *121*.
Additional Information(gdb) bt
#0 match2 (mask=0x81f18e8 "*121*", name=0x0) at match.c:115
#1 0x281e145a in do_other_who (sptr=0x81f1800, mask=0x81f18e8 "*121*")
    at m_who.c:688
#2 0x281e08a3 in m_who (cptr=0x81f1800, sptr=0x81f1800, parc=2,
    parv=0x810de60) at m_who.c:200
#3 0x08064f35 in parse (cptr=0x81f1800, buffer=0x81f18e4 "who",
    bufend=0x81f18ed "") at parse.c:444
#4 0x08063dd5 in dopacket (cptr=0x81f1800, buffer=0x810e800 "who *121*\n",
    length=0) at packet.c:137
#5 0x0806a0b1 in read_packet (cptr=0x81f1800, rfd=0x31) at s_bsd.c:1455
#6 0x0806a986 in read_message (delay=1, listp=0x8137500) at s_bsd.c:1905
#7 0x080617f7 in main (argc=0, argv=0x8136460) at ircd.c:1336
0000008 0x08050245 in _start ()
(gdb)
3rd party modules

Activities

syzop

2003-03-07 15:21

administrator   ~0001795

Last edited: 2003-03-07 15:24

Mmm I don't crash here when doing /who *121*
[technical (you dont have to read this part)]
(m_who.c)
680: for (acptr = client; acptr; acptr = acptr->next)
681: {
682: int cansee;
683: char status[20];
684: char *channel;
685: int flg;
686:
687: if (!oper) {
688: if (match(mask, acptr->name))
689: continue;

acptr->name can be empty ('\0') but it can't be null (it's in the struct, not alocated seperately or something).

match will just call match2 for this, and:
(match.c)
112: while (*m == '?'); /* while we have ?'s */
113: cm = *m;
114: if (!cm) /* last char of mask is ?, so it
's true */
115: return 0;
So how can it crash there? ;).
[/technical]

Hm, what do you get when opening the corefile? IIRC you get some detailed info about where it crashed (cannot access memory at ...).

Can you (also) do:
--
p m
p *m
info reg eip
frame 1
p mask
p *acptr
p acptr->name
--
I changed the /who command between b14<->b15 so I'm interrested if it's crashing because of my change ;).
[*edit: corrected "dutch" english*]

edited on: 03-07 15:24

monolith

2003-03-07 16:06

reporter   ~0001796

> gdb ircd ircd.core
GNU gdb 5.2.1 (FreeBSD)
Copyright 2002 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and you are
welcome to change it and/or distribute copies of it under certain conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB. Type "show warranty" for details.
This GDB was configured as "i386-undermydesk-freebsd"...
Core was generated by `ircd'.
Program terminated with signal 11, Segmentation fault.
Reading symbols from /usr/lib/libcrypt.so.2...done.
Loaded symbols for /usr/lib/libcrypt.so.2
Reading symbols from /usr/lib/libz.so.2...done.
Loaded symbols for /usr/lib/libz.so.2
Reading symbols from /usr/lib/libc_r.so.5...done.
Loaded symbols for /usr/lib/libc_r.so.5
Reading symbols from /usr/lib/libc.so.5...done.
Loaded symbols for /usr/lib/libc.so.5
Reading symbols from modules/commands.so...done.
Loaded symbols for modules/commands.so
Reading symbols from modules/scan.so...done.
Loaded symbols for modules/scan.so
Reading symbols from /usr/libexec/ld-elf.so.1...done.
Loaded symbols for /usr/libexec/ld-elf.so.1
#0 match2 (mask=0x81f18e8 "*121*", name=0x0) at match.c:115
115 return 0;
(gdb)

(gdb) p m
$1 = (u_char *) 0x81f18e9 "121*"
(gdb)

(gdb) p *m
$2 = 49 '1'
(gdb)

(gdb) info reg eip
eip 0x8062b08 0x8062b08
(gdb)

(gdb) frame 1
#1 0x281e145a in do_other_who (sptr=0x81f1800, mask=0x81f18e8 "*121*")
    at m_who.c:688
688 if (match(mask, acptr->name))
(gdb)

(gdb) p mask
$3 = 0x81f18e8 "*121*"
(gdb)

(gdb) p *acptr
No symbol "acptr" in current context.
(gdb)

(gdb) p acptr->name
No symbol "acptr" in current context.
(gdb)

There you go. :)

syzop

2003-03-07 16:49

administrator   ~0001797

Thanks.. Hm, this is "pretty impossible":
--
(gdb) frame 1
#1 0x281e145a in do_other_who (sptr=0x81f1800, mask=0x81f18e8 "*121*")
at m_who.c:688
688 if (match(mask, acptr->name))
(gdb)
[..]
(gdb) p *acptr
No symbol "acptr" in current context.
(gdb)
--
So I wonder what's wrong ;).
* did you execute the commands in sequence?
* Are you sure you are loading the beta15 commands module (check date with ls -al)?
* Same for ircd binary (type /version or something ;P)
* did you extract UnrealIRCd to the same directory as the beta14 dir (overwriting files etc)? if so, did you do a 'make clean'?

Just guessing... probably all wrong, but just in case.
I've not exactly an idea what this can be since it looks like the debugging/symbol information is f*cked up :(.
If I got some more time I might take a look at your assembler output, but... ;).

monolith

2003-03-07 16:53

reporter   ~0001798

* did you execute the commands in sequence?

Yes, just as I pasted them.

* Are you sure you are loading the beta15 commands module (check date with ls -al)?

Considering the only thing installed is beta15, yes.

* Same for ircd binary (type /version or something ;P)

Uh, unless you're switching around revisions on your releases, it's beta15. To make you happy:

Unreal3.2-beta15. orblivion.tx.us.xnet.org CFhiIXOo [FreeBSD quark.orblivion.com 5.0-RELEASE FreeBSD 5.0-RELEASE #0: Thu Jan 16 22:16:53 GMT 2003 [email protected]:/usr/obj/usr/src/sys/GENERIC i386=2303]

* did you extract UnrealIRCd to the same directory as the beta14 dir (overwriting files etc)? if so, did you do a 'make clean'?

I don't have a beta14 dir, I never ran it.

* am I an idiot? apparently you think so. ;)

J/K. If you need something else, let me know. And no clue about the debugging symbols. If you want me to send the binary/core I'm happy to.

monolith

2003-03-07 16:58

reporter   ~0001799

Rene was poking through the code and dug this offending if() up, here is his suggested fix, untested.

match.c:

! else if (*n == '\0')

to match.c

! else if ((n == NULL) || (*n == '\0'))

syzop

2003-03-07 17:19

administrator   ~0001800

@Rene: match should never get a NULL pointer in either of his parameters, and this part is at the top, bla]
@"am I an idiot? apparently you think so." (+"j/k" etc).. well I've been debugging for 3 hours at someone his box untill I discovered he loaded old (beta12) modules, and that will give similar symptoms, so...

Sorry I don't have a FreeBSD box, so it won't help me to give binary+core (I would normally have asked for it if it was Linux indeed :/). But you can give me a shell (my email: [email protected] ) if you want.

Otherwise/untill then:

Can you reopen gdb etc and type:
diassemble 0x8062b08
this will (probably) give you a LOT of output, you will see something like (pasted from something else):
0x806190c <main>: push %ebp
The first thing (0x806190c) is the address.
Please paste 10 lines up and 10 lines below the address 0x8062b08, you probably need to press ENTER numerous times to get there ;).

syzop

2003-03-07 21:40

administrator   ~0001804

diassemble 0x8062b08
should be:
disassemble 0x8062b08
ofcourse ;P.

syzop

2003-03-07 23:07

administrator   ~0001806

Hm ok, can you send (.tar.gz'd for example) these files to [email protected] ?:
- ircd (the ircd binary)
- commands.so
- core file
- unrealircd.conf (and any other includes), oper&link blocks + cloak keys removed
- config.settings
I just got a FreeBSD shell ;)

monolith

2003-03-07 23:49

reporter   ~0001807

0x8062aee <match2+278>: mov (%esi),%al
0x8062af0 <match2+280>: xor %edi,%edi
0x8062af2 <match2+282>: test %al,%al
0x8062af4 <match2+284>: je 0x8062a15 <match2+61>
0x8062afa <match2+290>: cmp $0x2a,%al
0x8062afc <match2+292>: je 0x8062b7c <match2+420>
0x8062afe <match2+294>: cmp $0x5c,%al
0x8062b00 <match2+296>: mov %al,%dl
0x8062b02 <match2+298>: je 0x8062b76 <match2+414>
0x8062b04 <match2+300>: cmp $0x3f,%al
0x8062b06 <match2+302>: je 0x8062b48 <match2+368>
0x8062b08 <match2+304>: mov (%ebx),%cl
---------------------------------------------------------
0x8062b0a <match2+306>: movzbl %dl,%eax
0x8062b0d <match2+309>: mov 0x809f940(%eax),%dl
0x8062b13 <match2+315>: movzbl %cl,%eax
0x8062b16 <match2+318>: cmp %dl,0x809f940(%eax)
0x8062b1c <match2+324>: je 0x8062b34 <match2+348>
0x8062b1e <match2+326>: test %cl,%cl
0x8062b20 <match2+328>: je 0x8062a10 <match2+56>
0x8062b26 <match2+334>: inc %ebx
0x8062b27 <match2+335>: mov (%ebx),%cl
0x8062b29 <match2+337>: movzbl %cl,%eax
0x8062b2c <match2+340>: cmp %dl,0x809f940(%eax)
------------------------------------------------------------

Emailing a link to the stuff you requested, would post here but I did not bother to comment out passwords/etc.

monolith

2003-03-07 23:53

reporter   ~0001808

I just wanted to point out we had another ircd that randomly crashed (although running linux) with various commands, until we answered "NO" to threading. Could this be something along those lines? It's a shame that threading is such a pain.

syzop

2003-03-08 21:13

administrator   ~0001825

This is probably now fixed in CVS. I'll leave the ticket open for a few days in the hope you will be able to confirm or deny it :).

Issue History

Date Modified Username Field Change
2003-11-20 19:46 syzop Status resolved => closed