[asterisk-bugs] [Asterisk 0014623]: Race condition between bridge and channel masquerading

Asterisk Bug Tracker noreply at bugs.digium.com
Sun Mar 8 16:07:07 CDT 2009


The following issue has been SUBMITTED. 
====================================================================== 
http://bugs.digium.com/view.php?id=14623 
====================================================================== 
Reported By:                guillecabeza
Assigned To:                
====================================================================== 
Project:                    Asterisk
Issue ID:                   14623
Category:                   Core/Channels
Reproducibility:            sometimes
Severity:                   crash
Priority:                   normal
Status:                     new
Asterisk Version:           SVN 
Regression:                 No 
SVN Branch (only for SVN checkouts, not tarball releases):  trunk 
SVN Revision (number only!): 180032 
Request Review:              
====================================================================== 
Date Submitted:             2009-03-08 16:07 CDT
Last Modified:              2009-03-08 16:07 CDT
====================================================================== 
Summary:                    Race condition between bridge and channel
masquerading
Description: 
The bridge checks for zombieness

/* Stop if we're a zombie or need a soft hangup */
		if (ast_test_flag(c0, AST_FLAG_ZOMBIE) || ast_check_hangup_locked(c0)
||
		    ast_test_flag(c1, AST_FLAG_ZOMBIE) || ast_check_hangup_locked(c1))
{

To see if some of the channels is going through a masquerading, but non
atomically, access to channel member variables happens a few lines later

if (!ast_strlen_zero(pbx_builtin_getvar_helper(c0, "BRIDGEPEER")))
     pbx_builtin_setvar_helper(c0, "BRIDGEPEER", c1->name);

Without locking on those acceses. That causes random crashes when the
memory is touched or free'd later.

====================================================================== 

Issue History 
Date Modified    Username       Field                    Change               
====================================================================== 
2009-03-08 16:07 guillecabeza   New Issue                                    
2009-03-08 16:07 guillecabeza   Asterisk Version          => SVN             
2009-03-08 16:07 guillecabeza   Regression                => No              
2009-03-08 16:07 guillecabeza   SVN Branch (only for SVN checkouts, not tarball
releases) =>  trunk          
2009-03-08 16:07 guillecabeza   SVN Revision (number only!) => 180032          
======================================================================




More information about the asterisk-bugs mailing list