Re: [RFC] Resouce leak/Denial of service in bb_boxc.c

Stipe Tolj <[email protected]>
Newsgroups gmane.comp.mobile.kannel.devel
Organization Wapme Systems AG
Message-ID <[email protected]>
Paul Keogh wrote:
> 
> In boxc_sender (), the code
> 
>     /* wait for smsbox identification */
>     if (bb_status != BB_DEAD && conn->alive && conn->is_wap == 0) {
>         mutex_lock(conn->boxc_id_mutex);
>         debug("bb.boxc", 0, "boxc_sender: sender unlocked");
>         mutex_unlock(conn->boxc_id_mutex);
>     }
> 
> means that this thread waits until a cmd_identity message is received.
> However, if a client simply connects and disconnects to the SMS Box
> port, then this thread never exits. This is easy to test with a simple
> script that makes a TCP connect() to the port and then closes immediately.
> 
> I think some code is needed in boxc_receive() to cater for this; ie.
> 
>         msg = read_from_box(conn);
> 
>         if (msg == NULL) {      /* garbage/connection lost */
>             conn->alive = 0;
>                 if (conn -> boxc_id == NULL)
>                 mutex_unlock(conn->boxc_id_mutex);
>             break;
>         }
> 
> so if the boxc_id is NULL, no cmd_identity message has been received and the
> corresponding boxc_sender() thread is still blocked on the
> conn->boxc_id_mutex
> mutex.

agreed. Sounds reasonable.

BTW, can someone tell me why the mutex_unlock() *after* the
mutex_lock() is necessary in the boxc_sender() block?!

When cmd_identify is received the boxc_receiver() thread unlock's the
mutex and the debug is thrown. Why does it have to unlock once again
there?

Stipe

[email protected]
-------------------------------------------------------------------
Wapme Systems AG

Vogelsanger Weg 80
40470 Düsseldorf

Tel: +49-211-74845-0
Fax: +49-211-74845-299

E-Mail: [email protected]
Internet: http://www.wapme-systems.de
-------------------------------------------------------------------
wapme.net - wherever you are
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.