[asterisk-bugs] [Asterisk 0014623]: Race condition between bridge and channel masquerading

Asterisk Bug Tracker noreply at bugs.digium.com
Sun Mar 8 20:41:29 CDT 2009


A NOTE has been added to this issue. 
====================================================================== 
http://bugs.digium.com/view.php?id=14623 
====================================================================== 
Reported By:                guillecabeza
Assigned To:                
====================================================================== 
Project:                    Asterisk
Issue ID:                   14623
Category:                   Core/Channels
Reproducibility:            sometimes
Severity:                   crash
Priority:                   normal
Status:                     new
Asterisk Version:           SVN 
Regression:                 No 
SVN Branch (only for SVN checkouts, not tarball releases):  trunk 
SVN Revision (number only!): 180032 
Request Review:              
====================================================================== 
Date Submitted:             2009-03-08 16:07 CDT
Last Modified:              2009-03-08 20:41 CDT
====================================================================== 
Summary:                    Race condition between bridge and channel
masquerading
Description: 
The bridge checks for zombieness

/* Stop if we're a zombie or need a soft hangup */
		if (ast_test_flag(c0, AST_FLAG_ZOMBIE) || ast_check_hangup_locked(c0)
||
		    ast_test_flag(c1, AST_FLAG_ZOMBIE) || ast_check_hangup_locked(c1))
{

To see if some of the channels is going through a masquerading, but non
atomically, access to channel member variables happens a few lines later

if (!ast_strlen_zero(pbx_builtin_getvar_helper(c0, "BRIDGEPEER")))
     pbx_builtin_setvar_helper(c0, "BRIDGEPEER", c1->name);

Without locking on those acceses. That causes random crashes when the
memory is touched or free'd later.

====================================================================== 

---------------------------------------------------------------------- 
 (0101350) guillecabeza (reporter) - 2009-03-08 20:41
 http://bugs.digium.com/view.php?id=14623#c101350 
---------------------------------------------------------------------- 
tilghman, I'll post a backtrace as soon as I have another one. Anyway, I
think the problem is clear from dead-listing analysis.

Will post the smallest footprint patch.

Thanks 

Issue History 
Date Modified    Username       Field                    Change               
====================================================================== 
2009-03-08 20:41 guillecabeza   Note Added: 0101350                          
======================================================================




More information about the asterisk-bugs mailing list