| Message ID | 20201215171600.25534-1-domagoj@pensa.hr |
|---|---|
| State | Accepted |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net> Delivered-To: patchwork@openvpn.net Delivered-To: patchwork@openvpn.net Received: from director12.mail.ord1d.rsapps.net ([172.30.191.6]) by backend30.mail.ord1d.rsapps.net with LMTP id IPu0NFDz2F+qLQAAIUCqbw (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Tue, 15 Dec 2020 12:33:04 -0500 Received: from proxy7.mail.ord1d.rsapps.net ([172.30.191.6]) by director12.mail.ord1d.rsapps.net with LMTP id WFVfNFDz2F/iHwAAIasKDg (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Tue, 15 Dec 2020 12:33:04 -0500 Received: from smtp23.gate.ord1d ([172.30.191.6]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) by proxy7.mail.ord1d.rsapps.net with LMTPS id yCiINlDz2F+bZAAAMe1Fpw (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Tue, 15 Dec 2020 12:33:04 -0500 X-Spam-Threshold: 95 X-Spam-Score: 0 X-Spam-Flag: NO X-Virus-Scanned: OK X-Orig-To: openvpnslackdevel@openvpn.net X-Originating-Ip: [216.105.38.7] Authentication-Results: smtp23.gate.ord1d.rsapps.net; iprev=pass policy.iprev="216.105.38.7"; spf=pass smtp.mailfrom="openvpn-devel-bounces@lists.sourceforge.net" smtp.helo="lists.sourceforge.net"; dkim=fail (signature verification failed) header.d=sourceforge.net; dkim=fail (signature verification failed) header.d=sf.net; dmarc=none (p=nil; dis=none) header.from=pensa.hr X-Suspicious-Flag: YES X-Classification-ID: 95ee4a0a-3efb-11eb-90a5-525400bfb165-1-1 Received: from [216.105.38.7] ([216.105.38.7:34014] helo=lists.sourceforge.net) by smtp23.gate.ord1d.rsapps.net (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) (ecelerity 4.2.38.62370 r(:)) with ESMTPS (cipher=DHE-RSA-AES256-GCM-SHA384) id EA/08-28983-053F8DF5; Tue, 15 Dec 2020 12:33:04 -0500 Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com) by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.90_1) (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) id 1kpEBT-000386-FL; Tue, 15 Dec 2020 17:32:23 +0000 Received: from [172.30.20.202] (helo=mx.sourceforge.net) by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.90_1) (envelope-from <domagoj@pensa.hr>) id 1kpEBS-00036d-Gh for openvpn-devel@lists.sourceforge.net; Tue, 15 Dec 2020 17:32:22 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Type:Content-Transfer-Encoding:MIME-Version :Date:Subject:Message-ID:Cc:To:From:Sender:Reply-To:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=4e5wvsMjiDaqGMsIhPDRuO97NCp51bpMrlSq+zo0Gpg=; b=AO/LH3tmshOzlmeHqOHoBr5dc2 oK7L+SrqA5CHju5JtHjSdJE0uWl8uu26+HQDqJZZPCRoxjFbVYLL3BK7Qe+627VEXDEqx1C0MjWfk SbuleX0BUyXYVM5AbbaD4CuowAKCGAgMfULnUPJ6SyCeI2EP5VLpwkRTXRB6MsRDKiho=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Type:Content-Transfer-Encoding:MIME-Version:Date:Subject: Message-ID:Cc:To:From:Sender:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: In-Reply-To:References:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=4e5wvsMjiDaqGMsIhPDRuO97NCp51bpMrlSq+zo0Gpg=; b=gkWVCDmg/DgWcmQDKCmmppn5/Z 7btTJmj9A84N7GREkOAer9XVJJERxlvAwI5dQcm1Zy2QfPErRajIYHPtCh5uTYgTuG3QD2xXqmKKg VCXbT3roA1Yrqs90Ovw1P2jcqoelAM0t37ZUl6wR4ev/RJ5bG0nvbzL253lByb54KpTw=; Received: from sender4-of-o50.zoho.com ([136.143.188.50]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.92.2) id 1kpEAq-00EYeV-EI for openvpn-devel@lists.sourceforge.net; Tue, 15 Dec 2020 17:31:48 +0000 ARC-Seal: i=1; a=rsa-sha256; t=1608052567; cv=none; d=zohomail.com; s=zohoarc; b=AqyWyxgHlhg0SU+BjeMsWlG+TMoueI38vN6/TSNZNPryrnaGiXW9HK0AqsmS2/4El2Swyenk1Q8FnfEavHiDwXWZ2Ov+F5U+uGbDOzFsNX3Nu187a0foK/zssiL5Gkq3AuQQ3e95LsEd8gKHlXSJJZZYzA0Skj5XxTGga8eQV2A= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1608052567; h=Content-Type:Content-Transfer-Encoding:Cc:Date:From:MIME-Version:Message-ID:Subject:To; bh=4e5wvsMjiDaqGMsIhPDRuO97NCp51bpMrlSq+zo0Gpg=; b=AcE+2bybeUuqTNIij54WFHmx0of4Sodv+FlXSFMpZRLoz7+NJqCZkH/cDaT2ZoqdWZVneldZk3eGgleHqYjQTQJAEbuVuMJFT7nZk1sJtaYrc8ute3CEKAewNEaoFZ0v4ZibHzuNXYsZQyG6DxVzD4Q4cLHCgJ8O/z8uDQ5Morg= ARC-Authentication-Results: i=1; mx.zohomail.com; spf=pass smtp.mailfrom=domagoj@pensa.hr; dmarc=pass header.from=<domagoj@pensa.hr> header.from=<domagoj@pensa.hr> Received: from localhost (21-233.dsl.iskon.hr [89.164.21.233]) by mx.zohomail.com with SMTPS id 1608052563090877.9381997072572; Tue, 15 Dec 2020 09:16:03 -0800 (PST) From: Domagoj Pensa <domagoj@pensa.hr> To: openvpn-devel@lists.sourceforge.net Message-ID: <20201215171600.25534-1-domagoj@pensa.hr> Date: Tue, 15 Dec 2020 18:16:00 +0100 X-Mailer: git-send-email 2.29.2 MIME-Version: 1.0 X-ZohoMailClient: External X-Spam-Report: Spam Filtering performed by mx.sourceforge.net. See http://spamassassin.org/tag/ for more details. -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at https://www.dnswl.org/, no trust [136.143.188.50 listed in list.dnswl.org] 0.0 RCVD_IN_MSPIKE_H4 RBL: Very Good reputation (+4) [136.143.188.50 listed in wl.mailspike.net] 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: pensa.hr] -0.0 SPF_PASS SPF: sender matches SPF record 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record 0.0 RCVD_IN_MSPIKE_WL Mailspike good senders X-Headers-End: 1kpEAq-00EYeV-EI Subject: [Openvpn-devel] [PATCH] Fix too early argv freeing when registering DNS X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: <openvpn-devel.lists.sourceforge.net> List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe> List-Archive: <http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel> List-Post: <mailto:openvpn-devel@lists.sourceforge.net> List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help> List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe> Cc: Domagoj Pensa <domagoj@pensa.hr> Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox |
| Series |
[Openvpn-devel] Fix too early argv freeing when registering DNS
|
|
Commit Message
Domagoj Pensa
Dec. 15, 2020, 6:16 a.m. UTC
When registering DNS on Windows, argv is freed after being used in first
ipconfig command (/flushdns).
Then same argv is used uninitialized in next ipconfig command (/registerdns)
causing heap exception and subprocess crash.
As a consequence second command is never executed and locked netcmd
semaphore is not cleanly released.
Removing argv freeing between ipconfig calls solves the problem.
This issue was introduced in commit 870e240 (argv: do fewer memory
re-allocations). After a quick glance at commit no similar problem was
spotted in rest of the argv related changes.
Signed-off-by: Domagoj Pensa <domagoj@pensa.hr>
---
src/openvpn/tun.c | 1 -
1 file changed, 1 deletion(-)
Comments
Hi, On Tue, Dec 15, 2020 at 06:16:00PM +0100, Domagoj Pensa wrote: > When registering DNS on Windows, argv is freed after being used in first > ipconfig command (/flushdns). > > Then same argv is used uninitialized in next ipconfig command (/registerdns) > causing heap exception and subprocess crash. > > As a consequence second command is never executed and locked netcmd > semaphore is not cleanly released. > > Removing argv freeing between ipconfig calls solves the problem. Oh! Yes, now with your patch, this is very obvious - there is a trac ticket (so when I merge this, I'll add the trac ticket number to the commit message) but it sort of puzzled Selva and me, because the code "looked sane". Acked-by: gert@greenie.muc.de gert
Hi On Tue, Dec 15, 2020 at 12:37 PM Gert Doering <gert@greenie.muc.de> wrote: > Hi, > > On Tue, Dec 15, 2020 at 06:16:00PM +0100, Domagoj Pensa wrote: > > When registering DNS on Windows, argv is freed after being used in first > > ipconfig command (/flushdns). > > > > Then same argv is used uninitialized in next ipconfig command > (/registerdns) > > causing heap exception and subprocess crash. > > > > As a consequence second command is never executed and locked netcmd > > semaphore is not cleanly released. > > > > Removing argv freeing between ipconfig calls solves the problem. > > Oh! Yes, now with your patch, this is very obvious - there is a trac > ticket (so when I merge this, I'll add the trac ticket number to the > commit message) but it sort of puzzled Selva and me, because the > code "looked sane". > Indeed, I went looking at wrong places. Thanks, Selva <div dir="ltr"><div>Hi</div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Dec 15, 2020 at 12:37 PM Gert Doering <<a href="mailto:gert@greenie.muc.de">gert@greenie.muc.de</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Hi,<br> <br> On Tue, Dec 15, 2020 at 06:16:00PM +0100, Domagoj Pensa wrote:<br> > When registering DNS on Windows, argv is freed after being used in first<br> > ipconfig command (/flushdns).<br> > <br> > Then same argv is used uninitialized in next ipconfig command (/registerdns)<br> > causing heap exception and subprocess crash.<br> > <br> > As a consequence second command is never executed and locked netcmd<br> > semaphore is not cleanly released.<br> > <br> > Removing argv freeing between ipconfig calls solves the problem.<br> <br> Oh! Yes, now with your patch, this is very obvious - there is a trac<br> ticket (so when I merge this, I'll add the trac ticket number to the<br> commit message) but it sort of puzzled Selva and me, because the<br> code "looked sane".<br></blockquote><div><br></div><div>Indeed, I went looking at wrong places.</div><div><br></div><div>Thanks,</div><div><br></div><div>Selva</div><div> </div></div></div>
Thanks. As already said, all of a sudden it is very obvious
why it is crashing here... somewhat annoying that this wasn't
noticed before 2.5.0 release, though.
I've stared-at-code, and tested this on Win10 (ubuntu 18 / mingw build)
with a config with --register-dns. Without the patch, crash, with the
patch, it just works.
Testing is not fully straightforward, as you can not "just run" such
a config, but you need to either run openvpn-gui as admin, or run
openvpn from a admin-cmd.exe - and it never OOMs for me, just never
proceeeds after "ipconfig.exe /flushdns".
Thanks :-)
Your patch has been applied to the master and release/2.5 branch.
commit ab4688e3bd78d010ccc96adec66ab552bd009328 (master)
commit 2f2df474158b6c24325a47334fc8b5eb77a69b85 (release/2.5)
Author: Domagoj Pensa
Date: Tue Dec 15 18:16:00 2020 +0100
Fix too early argv freeing when registering DNS
Signed-off-by: Domagoj Pensa <domagoj@pensa.hr>
Acked-by: Gert Doering <gert@greenie.muc.de>
Message-Id: <20201215171600.25534-1-domagoj@pensa.hr>
URL: https://www.mail-archive.com/search?l=mid&q=20201215171600.25534-1-domagoj@pensa.hr
Signed-off-by: Gert Doering <gert@greenie.muc.de>
--
kind regards,
Gert Doering
Hi! You're welcome. I'm glad that it helps. Even if it is just one line of code removed. :) Best regards, Domagoj On Tue, Dec 15, 2020 at 08:21:51PM +0100, Gert Doering wrote: > Thanks. As already said, all of a sudden it is very obvious > why it is crashing here... somewhat annoying that this wasn't > noticed before 2.5.0 release, though. > > I've stared-at-code, and tested this on Win10 (ubuntu 18 / mingw build) > with a config with --register-dns. Without the patch, crash, with the > patch, it just works. > > Testing is not fully straightforward, as you can not "just run" such > a config, but you need to either run openvpn-gui as admin, or run > openvpn from a admin-cmd.exe - and it never OOMs for me, just never > proceeeds after "ipconfig.exe /flushdns". > > Thanks :-) > > Your patch has been applied to the master and release/2.5 branch. > > commit ab4688e3bd78d010ccc96adec66ab552bd009328 (master) > commit 2f2df474158b6c24325a47334fc8b5eb77a69b85 (release/2.5) > Author: Domagoj Pensa > Date: Tue Dec 15 18:16:00 2020 +0100 > > Fix too early argv freeing when registering DNS > > Signed-off-by: Domagoj Pensa <domagoj@pensa.hr> > Acked-by: Gert Doering <gert@greenie.muc.de> > Message-Id: <20201215171600.25534-1-domagoj@pensa.hr> > URL: https://www.mail-archive.com/search?l=mid&q=20201215171600.25534-1-domagoj@pensa.hr > Signed-off-by: Gert Doering <gert@greenie.muc.de> > > > -- > kind regards, > > Gert Doering >
diff --git a/src/openvpn/tun.c b/src/openvpn/tun.c index 400a50ca..2b227bb6 100644 --- a/src/openvpn/tun.c +++ b/src/openvpn/tun.c @@ -5235,7 +5235,6 @@ ipconfig_register_dns(const struct env_set *es) WIN_IPCONFIG_PATH_SUFFIX); argv_msg(D_TUNTAP_INFO, &argv); openvpn_execve_check(&argv, es, 0, err); - argv_free(&argv); argv_printf(&argv, "%s%s /registerdns", get_win_sys_path(),