Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1200404 > unrolled thread

Bug#1072922: nullmailer: "sendmail -bs" crashes: "traps: nullmailer-smtp[15059] general protection fault ip:7f0368d73dd9 sp:7fff5e3d7088 error:0 in libc.so.6[7f0368c41000+157000]"

Started byAxel Beckert <abe@debian.org>
First post2024-06-10 14:40 +0200
Last post2024-06-25 12:40 +0200
Articles 7 — 2 participants

Back to article view | Back to linux.debian.bugs.dist


Contents

  Bug#1072922: nullmailer: "sendmail -bs" crashes: "traps: nullmailer-smtp[15059] general protection fault ip:7f0368d73dd9 sp:7fff5e3d7088 error:0 in libc.so.6[7f0368c41000+157000]" Axel Beckert <abe@debian.org> - 2024-06-10 14:40 +0200
    Bug#1072922: nullmailer: "sendmail -bs" crashes: "traps: nullmailer-smtp[15059] general protection fault ip:7f0368d73dd9 sp:7fff5e3d7088 error:0 in libc.so.6[7f0368c41000+157000]" David Bremner <david@tethera.net> - 2024-06-11 02:10 +0200
      Bug#1072922: nullmailer: "sendmail -bs" crashes: "traps: nullmailer-smtp[15059] general protection fault ip:7f0368d73dd9 sp:7fff5e3d7088 error:0 in libc.so.6[7f0368c41000+157000]" Axel Beckert <abe@debian.org> - 2024-06-11 02:40 +0200
        Bug#1072922: nullmailer: "sendmail -bs" crashes: "traps: nullmailer-smtp[15059] general protection fault ip:7f0368d73dd9 sp:7fff5e3d7088 error:0 in libc.so.6[7f0368c41000+157000]" David Bremner <david@tethera.net> - 2024-06-11 12:50 +0200
      Bug#1072922: nullmailer: "sendmail -bs" crashes: "traps: nullmailer-smtp[15059] general protection fault ip:7f0368d73dd9 sp:7fff5e3d7088 error:0 in libc.so.6[7f0368c41000+157000]" David Bremner <david@tethera.net> - 2024-06-12 12:30 +0200
    Bug#1072922: nullmailer: "sendmail -bs" crashes: "traps: nullmailer-smtp[15059] general protection fault ip:7f0368d73dd9 sp:7fff5e3d7088 error:0 in libc.so.6[7f0368c41000+157000]" David Bremner <david@tethera.net> - 2024-06-21 21:00 +0200
    Bug#1072922: nullmailer: "sendmail -bs" crashes: "traps: nullmailer-smtp[15059] general protection fault ip:7f0368d73dd9 sp:7fff5e3d7088 error:0 in libc.so.6[7f0368c41000+157000]" David Bremner <david@tethera.net> - 2024-06-25 12:40 +0200

#1200404 — Bug#1072922: nullmailer: "sendmail -bs" crashes: "traps: nullmailer-smtp[15059] general protection fault ip:7f0368d73dd9 sp:7fff5e3d7088 error:0 in libc.so.6[7f0368c41000+157000]"

FromAxel Beckert <abe@debian.org>
Date2024-06-10 14:40 +0200
SubjectBug#1072922: nullmailer: "sendmail -bs" crashes: "traps: nullmailer-smtp[15059] general protection fault ip:7f0368d73dd9 sp:7fff5e3d7088 error:0 in libc.so.6[7f0368c41000+157000]"
Message-ID<INMtz-1Vkh-1@gated-at.bofh.it>
Package: nullmailer
Version: 1:2.2+10~g7ed88a0-5
Severity: important
Control: found -1 1:2.2-3

Dear David,

I managed to reproducibly crash nullmailer-smtpd with a "general
protection fault" by calling the following command:

  swaks -t abe@debian.org --pipe 'sendmail -bs'

This call produces the following output first:

  === Trying pipe to sendmail -bs...
  === Connected to sendmail -bs.
  <-  220 nullmailer-smtpd ready
   -> EHLO kote1.lugs.ch
  <-  250 2.3.0 OK
   -> MAIL FROM:<root@kote1.lugs.ch>
  <-  250 2.1.0 Sender accepted
   -> RCPT TO:<abe@debian.org>
  <-  250 2.1.5 Recipient accepted
   -> DATA
  <-  354 End your message with a period on a line by itself
   -> Date: Mon, 10 Jun 2024 13:21:49 +0200
   -> To: abe@debian.org
   -> From: root@kote1.lugs.ch
   -> Subject: test Mon, 10 Jun 2024 13:21:49 +0200
   -> Message-Id: <20240610132149.015058@kote1.lugs.ch>
   -> X-Mailer: swaks v20240103.0 jetmore.org/john/code/swaks/
   ->
   -> This is a test mailing
   ->
   ->
   -> .
  *** Child process closed connection unexpectedly.

In /var/log/syslog I then find these log entries:

  2024-06-10T13:21:49.468475+02:00 kote1 nullmailer: Trigger pulled.
  2024-06-10T13:21:49.468687+02:00 kote1 nullmailer: Rescanning queue.
  2024-06-10T13:21:49.468781+02:00 kote1 nullmailer: Starting delivery, 1 message(s) in queue.
  2024-06-10T13:21:49.468793+02:00 kote1 nullmailer: Starting delivery: host: … protocol: smtp file: 1718018509.15060
  2024-06-10T13:21:49.468802+02:00 kote1 nullmailer: From: <root@kote1.lugs.ch> to: <abe@debian.org>
  2024-06-10T13:21:49.468808+02:00 kote1 nullmailer: Message-Id: <20240610132149.015058@kote1.lugs.ch>
  2024-06-10T13:21:49.471688+02:00 kote1 kernel: traps: nullmailer-smtp[15059] general protection fault ip:7f0368d73dd9 sp:7fff5e3d7088 error:0 in libc.so.6[7f0368c41000+157000]
  2024-06-10T13:21:49.600127+02:00 kote1 nullmailer: smtp: Succeeded: 250 2.6.0 <20240610132149.015058@kote1.lugs.ch> [InternalId=172490181574991, Hostname=…] 1171 bytes in 0.106, 10.754 KB/sec Queued mail for delivery
  2024-06-10T13:21:49.601067+02:00 kote1 nullmailer: Sent file.
  2024-06-10T13:21:49.601118+02:00 kote1 nullmailer: Delivery complete, 0 message(s) remain.

The mail though seemed to end up in the queue. But since swaks exits
with non-zero due to "sendmail -bs" exits with non-zero, our Ansible
playbook fails, too.

I initially ran into this on a production host running Debian 11
Bullseye with different settings (hence marking as found in the version
in Bullseye), but I can still reproduce it on a test VM with Debian
Unstable where I installed nullmailer temporarily as well. (Bug report
resembles state on the latter.)

-- System Information:
Debian Release: trixie/sid
  APT prefers unstable
  APT policy: (990, 'unstable'), (600, 'testing'), (500, 'unstable-debug'), (500, 'buildd-unstable'), (110, 'experimental'), (1, 'experimental-debug'), (1, 'buildd-experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 6.8.12-amd64 (SMP w/4 CPU threads; PREEMPT)
Locale: LANG=C.UTF-8, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: sysvinit (via /sbin/init)
LSM: AppArmor: enabled

Versions of packages nullmailer depends on:
ii  debconf [debconf-2.0]  1.5.86
ii  libc6                  2.38-12.1
ii  libgnutls30t64         3.8.5-4
ii  libstdc++6             14.1.0-1

nullmailer recommends no packages.

nullmailer suggests no packages.

-- debconf information:
* shared/mailname: kote1.lugs.ch
* nullmailer/relayhost:
* nullmailer/adminaddr: abe@deuxchevaux.org
  nullmailer/defaultdomain: lugs.ch

[toc] | [next] | [standalone]


#1200481

FromDavid Bremner <david@tethera.net>
Date2024-06-11 02:10 +0200
Message-ID<INXfj-224p-1@gated-at.bofh.it>
In reply to#1200404
Control: tag -1 confirmed

Axel Beckert <abe@debian.org> writes:

> Package: nullmailer
> Version: 1:2.2+10~g7ed88a0-5
> Severity: important
> Control: found -1 1:2.2-3
>
> Dear David,
>
> I managed to reproducibly crash nullmailer-smtpd with a "general
> protection fault" by calling the following command:
>
>   swaks -t abe@debian.org --pipe 'sendmail -bs'
>
> This call produces the following output first:

I can duplicate this. I made a few (unsuccessful) attempts at localize
the error.

Attempt #1

If I run /usr/lib/sendmail -bs directly (or nullmailer-smtpd, which
amounts to the same thing, I think), and give exactly the same input, it
exits cleanly when I type QUIT.  I also tried your swaks command on a
host where sendmail is postfix, and I see end of the transaction

    -> .
    <-  250 2.0.0 Ok: queued as 5EC225FB72
     -> QUIT
    <-  221 2.0.0 Bye
    === Connection closed with child process.

Attempt #2

swaks -t bremner@debian.org --pipe 'gdb -batch -ex run -ex bt --args /usr/lib/sendmail -bs'

This actually runs without segfaulting, which made me think it might be
a memory error.

Attempt #3

swaks -t bremner@debian.org --pipe 'valgrind /usr/lib/sendmail -bs'

This also runs without errors, so I'm out of ideas for the moment.

[toc] | [prev] | [next] | [standalone]


#1200483

FromAxel Beckert <abe@debian.org>
Date2024-06-11 02:40 +0200
Message-ID<INXIl-22do-3@gated-at.bofh.it>
In reply to#1200481
Hi David,

David Bremner wrote:
> swaks -t bremner@debian.org --pipe 'gdb -batch -ex run -ex bt --args /usr/lib/sendmail -bs'
> 
> This actually runs without segfaulting, which made me think it might be
> a memory error.

There's one memory fix commit upstream in the master branch:
https://github.com/bruceg/nullmailer/commit/834e2eb6b7eac2648fc371c432a46e98d5966bb4

Could it be this one? At least "fdbuf.c" sounds as if it might be
involved in file descriptor thingies.

> Attempt #3
> 
> swaks -t bremner@debian.org --pipe 'valgrind /usr/lib/sendmail -bs'
> 
> This also runs without errors,

Clearly a Heisenbug. ;-)

> so I'm out of ideas for the moment.

Maybe upstream has an idea if it's not that already made commit?

		Regards, Axel
-- 
 ,''`.  |  Axel Beckert <abe@debian.org>, https://people.debian.org/~abe/
: :' :  |  Debian Developer, ftp.ch.debian.org Admin
`. `'   |  4096R: 2517 B724 C5F6 CA99 5329  6E61 2FF9 CD59 6126 16B5
  `-    |  1024D: F067 EA27 26B9 C3FC 1486  202E C09E 1D89 9593 0EDE

[toc] | [prev] | [next] | [standalone]


#1200528

FromDavid Bremner <david@tethera.net>
Date2024-06-11 12:50 +0200
Message-ID<IO7eF-28ic-5@gated-at.bofh.it>
In reply to#1200483
Axel Beckert <abe@debian.org> writes:

> Hi David,
>
> David Bremner wrote:
>> swaks -t bremner@debian.org --pipe 'gdb -batch -ex run -ex bt --args /usr/lib/sendmail -bs'
>> 
>> This actually runs without segfaulting, which made me think it might be
>> a memory error.
>
> There's one memory fix commit upstream in the master branch:
> https://github.com/bruceg/nullmailer/commit/834e2eb6b7eac2648fc371c432a46e98d5966bb4
>
> Could it be this one? At least "fdbuf.c" sounds as if it might be
> involved in file descriptor thingies.
>

We're actually running a snapshot of master, so that commit is in
testing and unstable.

d

[toc] | [prev] | [next] | [standalone]


#1200636

FromDavid Bremner <david@tethera.net>
Date2024-06-12 12:30 +0200
Message-ID<IOtoS-2mzK-3@gated-at.bofh.it>
In reply to#1200481
David Bremner <david@tethera.net> writes:

>
> Attempt #3
>
> swaks -t bremner@debian.org --pipe 'valgrind /usr/lib/sendmail -bs'
>
> This also runs without errors, so I'm out of ideas for the moment.

Attempt #4:

Rebuild with asan

make clean
make CXXFLAGS="-g -O1 -fsanitize=address"
make check

I don't know if this is coincidence, or actually meaningful, but the
test "Testing protocol success with smtp (stdin)" finds one memory leak.

    220 OK
    smtp: Succeeded: 220 OK

    =================================================================
    ==3035435==ERROR: LeakSanitizer: detected memory leaks

    Direct leak of 13 byte(s) in 1 object(s) allocated from:
        #0 0x7f64762edd10 in strdup ../../../../src/libsanitizer/asan/asan_interceptors.cpp:578
        #1 0x563a16835173 in parse_option /home/bremner/software/debian/nullmailer/protocols/protocol.cc:116
        #2 0x563a16835173 in parse_options /home/bremner/software/debian/nullmailer/protocols/protocol.cc:130
        #3 0x563a16835173 in cli_main(int, char**) /home/bremner/software/debian/nullmailer/protocols/protocol.cc:138

    SUMMARY: AddressSanitizer: 13 byte(s) leaked in 1 allocation(s).

Looking at the code there is indeed a leak, but it's hard to see how it
would lead to a crash.

[toc] | [prev] | [next] | [standalone]


#1201857

FromDavid Bremner <david@tethera.net>
Date2024-06-21 21:00 +0200
Message-ID<IRREl-4zbN-7@gated-at.bofh.it>
In reply to#1200404
Bernhard Übelacker <bernhardu@mailbox.org> writes:

> Am 21.06.24 um 01:57 schrieb Bernhard Übelacker:
>
>> Especially the third point is puzzling, I could not yet see why this 
>> pointer-content-mixup happens.
>
>
> Hello David, hello Axel,
> I did some further tests and found following location where cli_program
> is delared here:
>
>    ./lib/cli++/cli++.h:35:extern const char* cli_program;
>
> But the defintion looks a bit different:
>
>    ./src/smtpd.cc:55:extern const char cli_program[] = "nullmailer-smtpd";
>
>
> A package built with following change does no longer show this crash.
>
> Kind regards,
> Bernhard

Hi Bernhard;

Thanks for the patch. This does seem to be progress, but I don't think
it completely fixes Axel's bug. At least for me I still see

 -> .
nullmailer-smtpd: Error catching the return value from nullmailer-queue: No child processes
nullmailer-smtpd: Error catching the return value from nullmailer-queue: No child processes
<** 451 4.3.0 Error returned from nullmailer-queue

and I get a non-zero exit code. I think the problem you found was
probably a crash during the reporting of the error message.

[toc] | [prev] | [next] | [standalone]


#1202234

FromDavid Bremner <david@tethera.net>
Date2024-06-25 12:40 +0200
Message-ID<ITbKF-5s5j-1@gated-at.bofh.it>
In reply to#1200404
Bernhard Übelacker <bernhardu@mailbox.org> writes:

> Hello David, hello Axel,
>
>
>> I had hoped the expected behaviour might have been the error message 😉
>
> Maybe it is the expected behaviour?
>
> Following is the output of the last not crashing version 1.13
> and the current version in testing 2.2+10~g7ed88a0 with the cli_program fix.
>
> Both look quite similar except the previously crashing error message,
> so this is maybe expected by upstream?

Or it's just an old bug?

It still looks like pretty strange behaviour to me. Does (nullmailer's
version of) sendmail -bs always return a non-zero exit code, or just in
some circumstances?

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.bugs.dist


csiph-web