RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Bug 1196371 - rpc.gssd segfaults in gssproxy (proxymech.so)
Summary: rpc.gssd segfaults in gssproxy (proxymech.so)
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: gssproxy
Version: 7.2
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: rc
: ---
Assignee: Simo Sorce
QA Contact: Yongcheng Yang
URL:
Whiteboard:
: 1196794 (view as bug list)
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2015-02-25 20:13 UTC by Steve Dickson
Modified: 2015-11-19 09:30 UTC (History)
5 users (show)

Fixed In Version: gssproxy-0.4.1-2.el7
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2015-11-19 09:30:39 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)
Full Backtrace (3.34 KB, text/plain)
2015-02-25 20:13 UTC, Steve Dickson
no flags Details
wireshark trace showing the AUTH_ERROR (1.39 KB, application/octet-stream)
2015-02-26 16:48 UTC, Steve Dickson
no flags Details
valgrid log (79.21 KB, text/plain)
2015-02-26 17:01 UTC, Steve Dickson
no flags Details
Fix for the double-free bug (8.12 KB, patch)
2015-02-26 22:37 UTC, Simo Sorce
no flags Details | Diff


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHBA-2015:2298 0 normal SHIPPED_LIVE gssproxy bug fix and enhancement update 2015-11-19 09:43:20 UTC

Description Steve Dickson 2015-02-25 20:13:51 UTC
Created attachment 995330 [details]
Full Backtrace

Description of problem:
The following segfault happen in rpc.gssd when Red Hat Storage
server (aka the ganesha server)

#0 memmove_ssse3_back () at ../sysdeps/x86_64/multiarch/memcpy-ssse3-back.S:2588
#0 0x00007fb790aba8e3 in memmove (__len=103, __src=<optimized out>, __dest=<optimized out>) at /usr/include/bits/string3.h:57
#2  xdrmem_putbytes (xdrs=0x7fff5aa23880, addr=<optimized out>, len=103) at xdr_mem.c:145
#3  0x00007fb790ab9fda in gssrpc_xdr_opaque (xdrs=0x7fff5aa23880, cp=<optimized out>, cnt=<optimized out>)
    at xdr.c:414

The full back trace is attached. 

Version-Release number of selected component (if applicable):
gssproxy-0.3.0-10.el7

How reproducible:
100%

Steps to Reproduce:
1. start rpc.gssd with a valid keytab
2. mount the Red Hat storage server. 
3.

Additional info:
The problem occurs because the rhel7 client is trying to
set up a GSS context with the server. Security is not
enabled on the server so the request is failed with 
an AUTH_ERROR error.

Comment 1 Simo Sorce 2015-02-25 20:37:34 UTC
What nfs-utils and gssproxy package versions ?

Comment 2 Steve Dickson 2015-02-25 20:59:51 UTC
(In reply to Simo Sorce from comment #1)
> What nfs-utils and gssproxy package versions ?
See above... gssproxy-0.3.0-10.el7
nfs-utils-1.3.0-0.8.el7

Comment 4 Steve Dickson 2015-02-26 16:09:27 UTC
to get the attached back trace I did the following:

Restart rpc.gssd
   systemctl restart rpc-gssd 

Attached to the runnning process
   gdb -p $(pidof rpc.gssd)

Set the following gdb things
   set follow-fork-mode child # gdb will follow the forked child
   handle SIG37 nostop # gdb will ignore SIG 37
   c # continue 

In another window 
  mount ganesha-server:/export /mnt

Comment 5 Steve Dickson 2015-02-26 16:48:55 UTC
Created attachment 995695 [details]
wireshark trace showing the AUTH_ERROR

Comment 6 Steve Dickson 2015-02-26 17:01:41 UTC
Created attachment 995700 [details]
valgrid log

Comment 7 Benjamin Coddington 2015-02-26 22:30:09 UTC
*** Bug 1196794 has been marked as a duplicate of this bug. ***

Comment 8 Simo Sorce 2015-02-26 22:37:11 UTC
Created attachment 995848 [details]
Fix for the double-free bug

Steve,
the attached patch is a more complete version of the scratch build you tested today, and it is the one sent upstream.
For reference.

Comment 9 Dmitri Pal 2015-04-15 16:48:42 UTC
Upstream ticket:
https://fedorahosted.org/gss-proxy/ticket/144

Comment 10 Dmitri Pal 2015-04-16 19:27:20 UTC
Upstream ticket:
https://fedorahosted.org/gss-proxy/ticket/137

Comment 11 Roland Mainz 2015-07-10 01:03:17 UTC
Fixed in gssproxy-0.4.1-2.el7 ...

... marking bug as MODIFIED.

Comment 16 errata-xmlrpc 2015-11-19 09:30:39 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHBA-2015-2298.html


Note You need to log in before you can comment on or make changes to this bug.