Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1200404 > unrolled thread
| Started by | Axel Beckert <abe@debian.org> |
|---|---|
| First post | 2024-06-10 14:40 +0200 |
| Last post | 2024-06-25 12:40 +0200 |
| Articles | 7 — 2 participants |
Back to article view | Back to linux.debian.bugs.dist
Bug#1072922: nullmailer: "sendmail -bs" crashes: "traps: nullmailer-smtp[15059] general protection fault ip:7f0368d73dd9 sp:7fff5e3d7088 error:0 in libc.so.6[7f0368c41000+157000]" Axel Beckert <abe@debian.org> - 2024-06-10 14:40 +0200
Bug#1072922: nullmailer: "sendmail -bs" crashes: "traps: nullmailer-smtp[15059] general protection fault ip:7f0368d73dd9 sp:7fff5e3d7088 error:0 in libc.so.6[7f0368c41000+157000]" David Bremner <david@tethera.net> - 2024-06-11 02:10 +0200
Bug#1072922: nullmailer: "sendmail -bs" crashes: "traps: nullmailer-smtp[15059] general protection fault ip:7f0368d73dd9 sp:7fff5e3d7088 error:0 in libc.so.6[7f0368c41000+157000]" Axel Beckert <abe@debian.org> - 2024-06-11 02:40 +0200
Bug#1072922: nullmailer: "sendmail -bs" crashes: "traps: nullmailer-smtp[15059] general protection fault ip:7f0368d73dd9 sp:7fff5e3d7088 error:0 in libc.so.6[7f0368c41000+157000]" David Bremner <david@tethera.net> - 2024-06-11 12:50 +0200
Bug#1072922: nullmailer: "sendmail -bs" crashes: "traps: nullmailer-smtp[15059] general protection fault ip:7f0368d73dd9 sp:7fff5e3d7088 error:0 in libc.so.6[7f0368c41000+157000]" David Bremner <david@tethera.net> - 2024-06-12 12:30 +0200
Bug#1072922: nullmailer: "sendmail -bs" crashes: "traps: nullmailer-smtp[15059] general protection fault ip:7f0368d73dd9 sp:7fff5e3d7088 error:0 in libc.so.6[7f0368c41000+157000]" David Bremner <david@tethera.net> - 2024-06-21 21:00 +0200
Bug#1072922: nullmailer: "sendmail -bs" crashes: "traps: nullmailer-smtp[15059] general protection fault ip:7f0368d73dd9 sp:7fff5e3d7088 error:0 in libc.so.6[7f0368c41000+157000]" David Bremner <david@tethera.net> - 2024-06-25 12:40 +0200
| From | Axel Beckert <abe@debian.org> |
|---|---|
| Date | 2024-06-10 14:40 +0200 |
| Subject | Bug#1072922: nullmailer: "sendmail -bs" crashes: "traps: nullmailer-smtp[15059] general protection fault ip:7f0368d73dd9 sp:7fff5e3d7088 error:0 in libc.so.6[7f0368c41000+157000]" |
| Message-ID | <INMtz-1Vkh-1@gated-at.bofh.it> |
Package: nullmailer Version: 1:2.2+10~g7ed88a0-5 Severity: important Control: found -1 1:2.2-3 Dear David, I managed to reproducibly crash nullmailer-smtpd with a "general protection fault" by calling the following command: swaks -t abe@debian.org --pipe 'sendmail -bs' This call produces the following output first: === Trying pipe to sendmail -bs... === Connected to sendmail -bs. <- 220 nullmailer-smtpd ready -> EHLO kote1.lugs.ch <- 250 2.3.0 OK -> MAIL FROM:<root@kote1.lugs.ch> <- 250 2.1.0 Sender accepted -> RCPT TO:<abe@debian.org> <- 250 2.1.5 Recipient accepted -> DATA <- 354 End your message with a period on a line by itself -> Date: Mon, 10 Jun 2024 13:21:49 +0200 -> To: abe@debian.org -> From: root@kote1.lugs.ch -> Subject: test Mon, 10 Jun 2024 13:21:49 +0200 -> Message-Id: <20240610132149.015058@kote1.lugs.ch> -> X-Mailer: swaks v20240103.0 jetmore.org/john/code/swaks/ -> -> This is a test mailing -> -> -> . *** Child process closed connection unexpectedly. In /var/log/syslog I then find these log entries: 2024-06-10T13:21:49.468475+02:00 kote1 nullmailer: Trigger pulled. 2024-06-10T13:21:49.468687+02:00 kote1 nullmailer: Rescanning queue. 2024-06-10T13:21:49.468781+02:00 kote1 nullmailer: Starting delivery, 1 message(s) in queue. 2024-06-10T13:21:49.468793+02:00 kote1 nullmailer: Starting delivery: host: … protocol: smtp file: 1718018509.15060 2024-06-10T13:21:49.468802+02:00 kote1 nullmailer: From: <root@kote1.lugs.ch> to: <abe@debian.org> 2024-06-10T13:21:49.468808+02:00 kote1 nullmailer: Message-Id: <20240610132149.015058@kote1.lugs.ch> 2024-06-10T13:21:49.471688+02:00 kote1 kernel: traps: nullmailer-smtp[15059] general protection fault ip:7f0368d73dd9 sp:7fff5e3d7088 error:0 in libc.so.6[7f0368c41000+157000] 2024-06-10T13:21:49.600127+02:00 kote1 nullmailer: smtp: Succeeded: 250 2.6.0 <20240610132149.015058@kote1.lugs.ch> [InternalId=172490181574991, Hostname=…] 1171 bytes in 0.106, 10.754 KB/sec Queued mail for delivery 2024-06-10T13:21:49.601067+02:00 kote1 nullmailer: Sent file. 2024-06-10T13:21:49.601118+02:00 kote1 nullmailer: Delivery complete, 0 message(s) remain. The mail though seemed to end up in the queue. But since swaks exits with non-zero due to "sendmail -bs" exits with non-zero, our Ansible playbook fails, too. I initially ran into this on a production host running Debian 11 Bullseye with different settings (hence marking as found in the version in Bullseye), but I can still reproduce it on a test VM with Debian Unstable where I installed nullmailer temporarily as well. (Bug report resembles state on the latter.) -- System Information: Debian Release: trixie/sid APT prefers unstable APT policy: (990, 'unstable'), (600, 'testing'), (500, 'unstable-debug'), (500, 'buildd-unstable'), (110, 'experimental'), (1, 'experimental-debug'), (1, 'buildd-experimental') Architecture: amd64 (x86_64) Foreign Architectures: i386 Kernel: Linux 6.8.12-amd64 (SMP w/4 CPU threads; PREEMPT) Locale: LANG=C.UTF-8, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE not set Shell: /bin/sh linked to /usr/bin/dash Init: sysvinit (via /sbin/init) LSM: AppArmor: enabled Versions of packages nullmailer depends on: ii debconf [debconf-2.0] 1.5.86 ii libc6 2.38-12.1 ii libgnutls30t64 3.8.5-4 ii libstdc++6 14.1.0-1 nullmailer recommends no packages. nullmailer suggests no packages. -- debconf information: * shared/mailname: kote1.lugs.ch * nullmailer/relayhost: * nullmailer/adminaddr: abe@deuxchevaux.org nullmailer/defaultdomain: lugs.ch
[toc] | [next] | [standalone]
| From | David Bremner <david@tethera.net> |
|---|---|
| Date | 2024-06-11 02:10 +0200 |
| Message-ID | <INXfj-224p-1@gated-at.bofh.it> |
| In reply to | #1200404 |
Control: tag -1 confirmed
Axel Beckert <abe@debian.org> writes:
> Package: nullmailer
> Version: 1:2.2+10~g7ed88a0-5
> Severity: important
> Control: found -1 1:2.2-3
>
> Dear David,
>
> I managed to reproducibly crash nullmailer-smtpd with a "general
> protection fault" by calling the following command:
>
> swaks -t abe@debian.org --pipe 'sendmail -bs'
>
> This call produces the following output first:
I can duplicate this. I made a few (unsuccessful) attempts at localize
the error.
Attempt #1
If I run /usr/lib/sendmail -bs directly (or nullmailer-smtpd, which
amounts to the same thing, I think), and give exactly the same input, it
exits cleanly when I type QUIT. I also tried your swaks command on a
host where sendmail is postfix, and I see end of the transaction
-> .
<- 250 2.0.0 Ok: queued as 5EC225FB72
-> QUIT
<- 221 2.0.0 Bye
=== Connection closed with child process.
Attempt #2
swaks -t bremner@debian.org --pipe 'gdb -batch -ex run -ex bt --args /usr/lib/sendmail -bs'
This actually runs without segfaulting, which made me think it might be
a memory error.
Attempt #3
swaks -t bremner@debian.org --pipe 'valgrind /usr/lib/sendmail -bs'
This also runs without errors, so I'm out of ideas for the moment.
[toc] | [prev] | [next] | [standalone]
| From | Axel Beckert <abe@debian.org> |
|---|---|
| Date | 2024-06-11 02:40 +0200 |
| Message-ID | <INXIl-22do-3@gated-at.bofh.it> |
| In reply to | #1200481 |
Hi David, David Bremner wrote: > swaks -t bremner@debian.org --pipe 'gdb -batch -ex run -ex bt --args /usr/lib/sendmail -bs' > > This actually runs without segfaulting, which made me think it might be > a memory error. There's one memory fix commit upstream in the master branch: https://github.com/bruceg/nullmailer/commit/834e2eb6b7eac2648fc371c432a46e98d5966bb4 Could it be this one? At least "fdbuf.c" sounds as if it might be involved in file descriptor thingies. > Attempt #3 > > swaks -t bremner@debian.org --pipe 'valgrind /usr/lib/sendmail -bs' > > This also runs without errors, Clearly a Heisenbug. ;-) > so I'm out of ideas for the moment. Maybe upstream has an idea if it's not that already made commit? Regards, Axel -- ,''`. | Axel Beckert <abe@debian.org>, https://people.debian.org/~abe/ : :' : | Debian Developer, ftp.ch.debian.org Admin `. `' | 4096R: 2517 B724 C5F6 CA99 5329 6E61 2FF9 CD59 6126 16B5 `- | 1024D: F067 EA27 26B9 C3FC 1486 202E C09E 1D89 9593 0EDE
[toc] | [prev] | [next] | [standalone]
| From | David Bremner <david@tethera.net> |
|---|---|
| Date | 2024-06-11 12:50 +0200 |
| Message-ID | <IO7eF-28ic-5@gated-at.bofh.it> |
| In reply to | #1200483 |
Axel Beckert <abe@debian.org> writes: > Hi David, > > David Bremner wrote: >> swaks -t bremner@debian.org --pipe 'gdb -batch -ex run -ex bt --args /usr/lib/sendmail -bs' >> >> This actually runs without segfaulting, which made me think it might be >> a memory error. > > There's one memory fix commit upstream in the master branch: > https://github.com/bruceg/nullmailer/commit/834e2eb6b7eac2648fc371c432a46e98d5966bb4 > > Could it be this one? At least "fdbuf.c" sounds as if it might be > involved in file descriptor thingies. > We're actually running a snapshot of master, so that commit is in testing and unstable. d
[toc] | [prev] | [next] | [standalone]
| From | David Bremner <david@tethera.net> |
|---|---|
| Date | 2024-06-12 12:30 +0200 |
| Message-ID | <IOtoS-2mzK-3@gated-at.bofh.it> |
| In reply to | #1200481 |
David Bremner <david@tethera.net> writes:
>
> Attempt #3
>
> swaks -t bremner@debian.org --pipe 'valgrind /usr/lib/sendmail -bs'
>
> This also runs without errors, so I'm out of ideas for the moment.
Attempt #4:
Rebuild with asan
make clean
make CXXFLAGS="-g -O1 -fsanitize=address"
make check
I don't know if this is coincidence, or actually meaningful, but the
test "Testing protocol success with smtp (stdin)" finds one memory leak.
220 OK
smtp: Succeeded: 220 OK
=================================================================
==3035435==ERROR: LeakSanitizer: detected memory leaks
Direct leak of 13 byte(s) in 1 object(s) allocated from:
#0 0x7f64762edd10 in strdup ../../../../src/libsanitizer/asan/asan_interceptors.cpp:578
#1 0x563a16835173 in parse_option /home/bremner/software/debian/nullmailer/protocols/protocol.cc:116
#2 0x563a16835173 in parse_options /home/bremner/software/debian/nullmailer/protocols/protocol.cc:130
#3 0x563a16835173 in cli_main(int, char**) /home/bremner/software/debian/nullmailer/protocols/protocol.cc:138
SUMMARY: AddressSanitizer: 13 byte(s) leaked in 1 allocation(s).
Looking at the code there is indeed a leak, but it's hard to see how it
would lead to a crash.
[toc] | [prev] | [next] | [standalone]
| From | David Bremner <david@tethera.net> |
|---|---|
| Date | 2024-06-21 21:00 +0200 |
| Message-ID | <IRREl-4zbN-7@gated-at.bofh.it> |
| In reply to | #1200404 |
Bernhard Übelacker <bernhardu@mailbox.org> writes: > Am 21.06.24 um 01:57 schrieb Bernhard Übelacker: > >> Especially the third point is puzzling, I could not yet see why this >> pointer-content-mixup happens. > > > Hello David, hello Axel, > I did some further tests and found following location where cli_program > is delared here: > > ./lib/cli++/cli++.h:35:extern const char* cli_program; > > But the defintion looks a bit different: > > ./src/smtpd.cc:55:extern const char cli_program[] = "nullmailer-smtpd"; > > > A package built with following change does no longer show this crash. > > Kind regards, > Bernhard Hi Bernhard; Thanks for the patch. This does seem to be progress, but I don't think it completely fixes Axel's bug. At least for me I still see -> . nullmailer-smtpd: Error catching the return value from nullmailer-queue: No child processes nullmailer-smtpd: Error catching the return value from nullmailer-queue: No child processes <** 451 4.3.0 Error returned from nullmailer-queue and I get a non-zero exit code. I think the problem you found was probably a crash during the reporting of the error message.
[toc] | [prev] | [next] | [standalone]
| From | David Bremner <david@tethera.net> |
|---|---|
| Date | 2024-06-25 12:40 +0200 |
| Message-ID | <ITbKF-5s5j-1@gated-at.bofh.it> |
| In reply to | #1200404 |
Bernhard Übelacker <bernhardu@mailbox.org> writes: > Hello David, hello Axel, > > >> I had hoped the expected behaviour might have been the error message 😉 > > Maybe it is the expected behaviour? > > Following is the output of the last not crashing version 1.13 > and the current version in testing 2.2+10~g7ed88a0 with the cli_program fix. > > Both look quite similar except the previously crashing error message, > so this is maybe expected by upstream? Or it's just an old bug? It still looks like pretty strange behaviour to me. Does (nullmailer's version of) sendmail -bs always return a non-zero exit code, or just in some circumstances?
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.bugs.dist
csiph-web