[asterisk-bugs] [JIRA] (ASTERISK-25645) res_rtp_asterisk: Lock inversion

Steve Davies (JIRA) noreply at issues.asterisk.org
Mon Jan 4 09:55:32 CST 2016


     [ https://issues.asterisk.org/jira/browse/ASTERISK-25645?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Steve Davies updated ASTERISK-25645:
------------------------------------

    Attachment: unlock_ice_before_callback

I may be talking rubbish here, but pj_timer_heap_schedule_w_grp_lock() only increases the lock ref-count, so in itself should be harmless (?am I understanding that right?). I think it is the hard-locks grabbed inside on_timer() in ice_session.c that are the problem.

The current workaround that I am testing today is to patch pjproject with a really dirty patch, as attached in 'unlock_ice_before_callback'. This seems to work so far with asterisk 11 branch and pjproject 2.4.5.

The fact that the lock ref-count is increased using pj_timer_heap_schedule_w_grp_lock() will in fact make this patch somewhat safer, even if it is ugly.


> res_rtp_asterisk: Lock inversion
> --------------------------------
>
>                 Key: ASTERISK-25645
>                 URL: https://issues.asterisk.org/jira/browse/ASTERISK-25645
>             Project: Asterisk
>          Issue Type: Bug
>      Security Level: None
>          Components: Resources/res_rtp_asterisk
>            Reporter: Steve Davies
>         Attachments: deadlocked_threads.txt, experimental_anti_deadlock, unlock_ice_before_callback
>
>
> Reported by Steve Davies on asterisk-dev:
> commit 5e6b1476a087407a052f007d326c504cfeefebe7
> ASTERISK-25614
> 2 code paths which approximate the following will cause a lock-inversion deadlock:
> approximate call orders are:
> a)
> pj_timer_heap_poll (PJ_LOCK)
> ast_rtp_on_ice_complete
> ast_rtp_instance_set_remote_address
> remote_address_set
> ast_rtp_remote_address_set
> (DTLS_LOCK)
> ...
> b)
> ast_pbx...
> app_dial
> bridge...
> read
> rtp_read
> ...
> __rtp_recvfrom
> (DTLS_LOCK)
> dtls_srtp_check_pending
> __rtp_sendto
> pj_ice_sess_send_data
> (PJ_LOCK)



--
This message was sent by Atlassian JIRA
(v6.2#6252)



More information about the asterisk-bugs mailing list