Pekka Riikonen [Sun, 23 Nov 2008 10:58:28 +0000 (12:58 +0200)]
silcd: disconnect packet errors with random timeout
Pekka Riikonen [Sun, 23 Nov 2008 10:56:20 +0000 (12:56 +0200)]
Packet engine: moved packet sanity checks after MAC check
Pekka Riikonen [Sun, 23 Nov 2008 10:48:21 +0000 (12:48 +0200)]
Removed extra semicolons from SILC_ASSERT and SILC_VERIFY macros
Pekka Riikonen [Sat, 22 Nov 2008 16:14:35 +0000 (18:14 +0200)]
Merge branch 'master' of git://valera-ext.nynaeve.net/silc into silc.1.1.branch
Code cleanup during merge.
Reverted External IP commit
Reverted changes to silcsocketstream API. The user context can be now
set to SilcClientConnectionParams. Increased shared library revision to
avoid backwards incompatiblity.
Signed-off-by: Pekka Riikonen <priikone@silcnet.org>
Skywing [Sat, 22 Nov 2008 04:57:32 +0000 (23:57 -0500)]
Cancel silc_server_connect_to_router_retry when connecting.
There exists a crash bug such that an un-cancelled timeout callback for
silc_server_connect_to_retry fires after the connection object has
already been cleaned up. Any router_retry requests must be cancelled
when we are deleting the associated connect object. The fix that was
implemented was to cancel silc_server_connect_to_router_retry in
addition to silc_server_connect_to_router when a call to
silc_server_create_connections is made. (This routine is called when
we are to make new server connections if reconnects are enabled.)
The problem would typically occur after a long enough time with silcd
trying to connect to a router server over and over; there is a race
condition component that can delay the initial use-after-free condition
for some time.
Skywing [Sat, 22 Nov 2008 02:24:07 +0000 (21:24 -0500)]
Mark outbound initiated server to server connections as local.
This fixes an issue where if a disconnect packet is received by the
server for an outbound silc connection (i.e. a server to server link)
and there is an outstanding async operation, such as an SKE or
connection auth, the server will corrupt the heap due to not properly
calling the async abort routine.
This issue would typically happen when we have a silcd setup to connect
to a remote router server, where both ends of the connection have public
keys configured, but the initiator server's IP is wrong. In this case,
we will get past key exchange and then fail at the connection auth
packet, typically crashing the initiator silcd after heap corruption.
Skywing [Sat, 22 Nov 2008 00:38:40 +0000 (19:38 -0500)]
Merge branch 'master' of git://valera-ext.nynaeve.net/silc
Skywing [Sun, 9 Nov 2008 04:07:36 +0000 (23:07 -0500)]
Prevent continuing of an already finished FSM.
Another fix for another crash relating to misuse of FSM and callback logic in
the SKE library.
Skywing [Sun, 9 Nov 2008 02:19:03 +0000 (21:19 -0500)]
Fix crash on SKE failure.
Adds checks to prevent SKE failure notification callbacks from being called
multiple times for the same SKE instance. This would often happen, for
example, if we aborted an SKE.
Skywing [Sat, 8 Nov 2008 22:54:03 +0000 (17:54 -0500)]
Fix crash on expired keyboard prompts
Skywing [Sat, 28 Jun 2008 05:21:51 +0000 (00:21 -0500)]
Add reference counting to SilcClientEntry/SilcServerEntry for getkey response.
This is necessary in case the entry goes away before the user responds to the
keyboard input request. (Fix for getkey crash if a user logs off before one
responds to the getkey prompt.)
Skywing [Sat, 28 Jun 2008 05:12:18 +0000 (00:12 -0500)]
Fix initialization/deinitialization of various Silc*Entry objects.
A number of init/deinit cases were failing to clean up
certain resources.
Skywing [Sat, 28 Jun 2008 04:44:03 +0000 (23:44 -0500)]
Fix reference counting for SilcServerEntry objects,
analogous to the previous fixes for the broken
reference counting for SilcChannelEntry and
SilcClientEntry objects.
Skywing [Fri, 27 Jun 2008 05:18:01 +0000 (00:18 -0500)]
Add support for autosendcmd on channel entries to the
SILC client. Note that we don't support botmasks yet,
but this can be used to send a command on join of a
channel on connect/reconnect/reattach detached session.
Kp [Fri, 4 Jul 2008 18:06:00 +0000 (13:06 -0500)]
Assert that the client count is positive prior to decrementing it.
A situation has been observed where a silcd has clients connected to it,
but reports 0 local users. It is believed that when these users log
off, the server underflows and refuses new connections. Assert that no
underflow occurs, which should prove or disprove this theory.
Skywing [Fri, 27 Jun 2008 05:16:37 +0000 (00:16 -0500)]
Add ``ExternalIp'' config directive to ServerInfo tag in
silcd.conf. This allows server linking with a server
behind a NAT connecting out to a router.
Kp [Sat, 28 Jun 2008 05:28:25 +0000 (00:28 -0500)]
Fix reference counting for key exchange handling.
When a key exchange times out, the SKE can be freed before the user
responds. Switch the SKE callbacks to obtain their own reference to the
object to prevent this.
Skywing [Sun, 9 Nov 2008 04:07:36 +0000 (23:07 -0500)]
Prevent continuing of an already finished FSM.
Another fix for another crash relating to misuse of FSM and callback logic in
the SKE library.
Skywing [Sun, 9 Nov 2008 02:19:03 +0000 (21:19 -0500)]
Fix crash on SKE failure.
Adds checks to prevent SKE failure notification callbacks from being called
multiple times for the same SKE instance. This would often happen, for
example, if we aborted an SKE.
Skywing [Sun, 9 Nov 2008 02:05:06 +0000 (21:05 -0500)]
Revert "Don't delete packet stream"
This reverts commit
544d0faa279dc3a3ca8f635665bd2cb57e92342b.
Skywing [Sat, 8 Nov 2008 23:46:02 +0000 (18:46 -0500)]
Don't delete packet stream
Skywing [Sat, 8 Nov 2008 22:54:03 +0000 (17:54 -0500)]
Fix crash on expired keyboard prompts
Skywing [Sat, 28 Jun 2008 05:21:51 +0000 (00:21 -0500)]
Add reference counting to SilcClientEntry/SilcServerEntry for getkey response.
This is necessary in case the entry goes away before the user responds to the
keyboard input request. (Fix for getkey crash if a user logs off before one
responds to the getkey prompt.)
Skywing [Sat, 28 Jun 2008 05:12:18 +0000 (00:12 -0500)]
Fix initialization/deinitialization of various Silc*Entry objects.
A number of init/deinit cases were failing to clean up
certain resources.
Skywing [Sat, 28 Jun 2008 04:44:03 +0000 (23:44 -0500)]
Fix reference counting for SilcServerEntry objects,
analogous to the previous fixes for the broken
reference counting for SilcChannelEntry and
SilcClientEntry objects.
Skywing [Fri, 27 Jun 2008 05:18:01 +0000 (00:18 -0500)]
Add support for autosendcmd on channel entries to the
SILC client. Note that we don't support botmasks yet,
but this can be used to send a command on join of a
channel on connect/reconnect/reattach detached session.
kp@valhallalegends.com [Fri, 4 Jul 2008 18:06:00 +0000 (13:06 -0500)]
Assert that the client count is positive prior to decrementing it.
A situation has been observed where a silcd has clients connected to it,
but reports 0 local users. It is believed that when these users log
off, the server underflows and refuses new connections. Assert that no
underflow occurs, which should prove or disprove this theory.
Skywing [Fri, 27 Jun 2008 05:16:37 +0000 (00:16 -0500)]
Add ``ExternalIp'' config directive to ServerInfo tag in
silcd.conf. This allows server linking with a server
behind a NAT connecting out to a router.
kp@valhallalegends.com [Sat, 28 Jun 2008 05:28:25 +0000 (00:28 -0500)]
Fix reference counting for key exchange handling.
When a key exchange times out, the SKE can be freed before the user
responds. Switch the SKE callbacks to obtain their own reference to the
object to prevent this.
Pekka Riikonen [Sat, 25 Oct 2008 13:58:50 +0000 (16:58 +0300)]
Fixed channel MAC key setting in JOIN notify and command reply
In JOIN notify when MAC algo changes wrong key was set to the new MAC.
In JOIN command reply in backup router the channel key may not be set
in command reply because backup reiceives also CHANNEL_KEY packet from
router and hence clients receive it too, but new MAC context was still
allocated in the command reply, hence using empty MAC without key with
channel messages.
Pekka Riikonen [Wed, 22 Oct 2008 19:22:00 +0000 (22:22 +0300)]
silcd: fixed memory leaks
Pekka Riikonen [Wed, 24 Sep 2008 15:18:30 +0000 (18:18 +0300)]
Merge branch 'topic/mm-fixes' of git://208.110.73.182/silc into silc.1.1.branch
Signed-off-by: Pekka Riikonen <priikone@silcnet.org>
Pekka Riikonen [Wed, 24 Sep 2008 14:56:56 +0000 (17:56 +0300)]
Disconnect problem: Mark incoming connections immediately local
This fixes the problem of SKE remaining running in the background
even though the conncection is closed because it was never aborted
because the connection wasn't marked local. After SKE timeout a
crash may occur.
Pekka Riikonen [Wed, 24 Sep 2008 13:53:38 +0000 (16:53 +0300)]
Fixed more backup router reconnecting problems
Fixed also possible buffer overflows.
Pekka Riikonen [Wed, 24 Sep 2008 05:46:28 +0000 (08:46 +0300)]
Fixed server/backup router reconnecting
Pekka Riikonen [Sat, 13 Sep 2008 17:54:45 +0000 (20:54 +0300)]
Documented public_ip configuration option
Pekka Riikonen [Sat, 13 Sep 2008 12:49:23 +0000 (15:49 +0300)]
Fixed backup router shutdown crash
Pekka Riikonen [Sat, 13 Sep 2008 12:45:53 +0000 (15:45 +0300)]
SKE: Verify initiator's public key always
We used to verify initiator's public key only if we were doing mutual
authentication. We now verify it always because calling application
may need the public key initiator sent.
Pekka Riikonen [Thu, 11 Sep 2008 15:47:55 +0000 (18:47 +0300)]
Merge branch 'topic/code-cleanup' of git://208.110.73.182/silc into silc.1.1.branch
Pekka Riikonen [Thu, 11 Sep 2008 15:41:51 +0000 (18:41 +0300)]
Merge branch 'topic/null-fixes' of git://208.110.73.182/silc into silc.1.1.branch
Pekka Riikonen [Thu, 11 Sep 2008 15:41:38 +0000 (18:41 +0300)]
Merge branch 'topic/type-safety' of git://208.110.73.182/silc into silc.1.1.branch
Skywing [Fri, 27 Jun 2008 23:13:59 +0000 (18:13 -0500)]
Fix reference count bug leading to memory corruption on duplicate deletions.
Skywing [Fri, 20 Jun 2008 22:37:21 +0000 (17:37 -0500)]
Make packet stream reference counts 32 bits.
Kp [Sun, 1 Jun 2008 21:15:46 +0000 (16:15 -0500)]
Packet streams: make packet handling callback pointers read only.
The function pointers for the packet handling callbacks are never
modified, so make them read only.
Kp [Fri, 4 Jul 2008 18:03:11 +0000 (13:03 -0500)]
Reorder #if 0/#endif block to avoid splitting a basic block across the #if 0.
The bracing convention caused a #if 0/#endif to exclude the close of one
block and the open of another. This compiled correctly, but confused
other tools that expect to see a block fully present or fully absent.
Move the ending brace of the preceding block out of the #if 0 and the
ending brace of the excluded block into the #if 0 to fix that.
Skywing [Fri, 20 Jun 2008 21:19:32 +0000 (16:19 -0500)]
Fix double free in silcd.
Kp [Sun, 1 Jun 2008 17:59:42 +0000 (12:59 -0500)]
Packet streams: avoid double free if silc_id_id2str fails.
In silc_packet_set_ids, the old ID is freed before silc_id_id2str is
called. If silc_id_id2str fails, then silc_packet_set_ids returns
without resetting the ID pointer. The pointer is then free, but not
NULL. When the packet stream is destroyed, silc_packet_stream_destroy
will free the pointer again. Reset the ID pointer to NULL immediately
after freeing it to prevent this.
Kp [Sun, 1 Jun 2008 17:25:50 +0000 (12:25 -0500)]
Packet streams: fix memory leak on dlist allocation failure.
If silc_dlist_init fails to allocate a SilcDList for stream->process,
then silc_packet_stream_link_va leaks the newly allocated
SilcPacketProcess. Fix that by calling silc_free(p) on the error path.
Kp [Sat, 31 May 2008 04:31:07 +0000 (23:31 -0500)]
ASN1: Fix NULL pointer dereference on stack allocation failure.
If the second silc_stack_alloc fails, then asn1->stack2 is NULL. Thus,
when silc_asn1_init calls silc_stack_free(asn1->stack2), it is
equivalent to silc_stack_free(NULL). However, silc_stack_free does not
check for a NULL pointer. Fix silc_asn1_init to free asn1->stack1, as
was intended.
Kp [Fri, 25 Apr 2008 03:18:27 +0000 (22:18 -0500)]
Avoid NULL dereference when leaving a channel with a private key.
Split out a patch from Skywing <skywing@valhallalegends.com> to fix a
NULL pointer dereference when the client leaves a +k channel and the
local user had set a key for the channel.
Kp [Sat, 31 May 2008 21:37:45 +0000 (16:37 -0500)]
ASN1: Fix stack variable overwrite when encoding OID.
The call to sscanf specifies a format string of "%lu", a long unsigned
int. The pointer argument was cast to unsigned long *, but this is
wrong for 64 bit systems. On 64 bit systems, unsigned long is 64 bits,
but the oid value is a SilcUInt32 on all systems. As a result, sscanf
will overwrite a neighboring variable on the stack. Fix this by
changing the format string to "%u" and removing the cast.
Kp [Sun, 1 Jun 2008 04:57:51 +0000 (23:57 -0500)]
Types: make SilcUInt32 an unsigned int in most cases.
On typical 32-bit systems, both unsigned int and unsigned long are 32
bits wide. However, they have different format specifiers, so they
cannot be used interchangeably. On typical 64-bit systems, unsigned int
is 32 bits and unsigned long is 64 bits. To allow for a more consistent
format string, reorder the type size checks so that SilcUInt32 is an
unsigned int on both 32 bit and 64 bit systems.
Kp [Sun, 1 Jun 2008 04:41:59 +0000 (23:41 -0500)]
Type sanity: add compile time check that integers are of the expected size.
The comments in silctypes.h guarantee that certain types are of
particular sizes. Add compile time checks that will fail if these
guarantees are not met.
Kp [Sun, 13 Jul 2008 16:47:07 +0000 (11:47 -0500)]
Server: always drop privileges, even in foreground mode.
Foreground mode is often used as a debugging aid for live
configurations, so the server may be started with root privileges to let
it bind to its native port. Since the server already has the ability to
drop root privileges, use that ability to make foreground mode a little
safer.
Pekka Riikonen [Sun, 31 Aug 2008 07:58:11 +0000 (10:58 +0300)]
Handle failed memory allocations in packet sending
Pekka Riikonen [Sun, 31 Aug 2008 06:58:49 +0000 (09:58 +0300)]
silc_stack_free can now be called with NULL stack
Pekka Riikonen [Sat, 30 Aug 2008 12:08:03 +0000 (15:08 +0300)]
Handle EAGAIN and EINTR correctly in silc_get_input in case of error
Pekka Riikonen [Sat, 30 Aug 2008 11:15:49 +0000 (14:15 +0300)]
Mark client entry invalid when killed and when notified non-existing
Pekka Riikonen [Sat, 30 Aug 2008 11:14:45 +0000 (14:14 +0300)]
Fixed command calling crash
If command finishes synchronously the command context is not valid
anymore and cannot be accessed. Reported by Sami Farin.
Pekka Riikonen [Sat, 30 Aug 2008 11:12:33 +0000 (14:12 +0300)]
Changed packet_error structure const correctly
Pekka Riikonen [Sat, 30 Aug 2008 11:12:00 +0000 (14:12 +0300)]
Fixed resuming to work even when there are no joined channels
Pekka Riikonen [Sat, 30 Aug 2008 11:10:45 +0000 (14:10 +0300)]
Fixed channel private key deleting to restore original keys correctly
Pekka Riikonen [Sat, 30 Aug 2008 07:50:24 +0000 (10:50 +0300)]
Resolve channel in INVITE notify if we don't have it yet
Fixes bug that user cannot se INVITE notifications sent by other users.
Pekka Riikonen [Sun, 22 Jun 2008 14:42:40 +0000 (17:42 +0300)]
Remove client from expired client list before deleting it
Pekka Riikonen [Sun, 22 Jun 2008 13:56:36 +0000 (16:56 +0300)]
Fixed the silc_parse_userqfdn argument handling, again.
Pekka Riikonen [Sun, 22 Jun 2008 08:04:37 +0000 (11:04 +0300)]
Fixed silc_parse_userfqdn argument check
Pekka Riikonen [Sun, 22 Jun 2008 08:03:58 +0000 (11:03 +0300)]
Make sure client entry is not expired more than once
Pekka Riikonen [Mon, 9 Jun 2008 05:26:01 +0000 (08:26 +0300)]
Close socket if TCP connecting fails to avoid leaking sockets
Pekka Riikonen [Mon, 9 Jun 2008 05:18:33 +0000 (08:18 +0300)]
Add non-executing stack when compiling AES asm for GNU/ELF.
Patch by Kp <kp@valhallalegends.com>bg
Signed-off-by: Pekka Riikonen <priikone@silcnet.org>
Pekka Riikonen [Mon, 9 Jun 2008 05:11:20 +0000 (08:11 +0300)]
Fixed automatic reconnection to router and malloc failure handlings
If remote router disconnects while still being in Unkonwn state reconnect
to the router after disconnecting. This should prevent the bugs where
server doesn't reconnect to router after being disconnected at the early
connection state.
Fixed various memory allocation failure handlings.
Pekka Riikonen [Fri, 6 Jun 2008 05:26:04 +0000 (08:26 +0300)]
Free sock user data before disconnecting remote peer
Pekka Riikonen [Thu, 5 Jun 2008 18:37:14 +0000 (21:37 +0300)]
More disconnection crash fixes.
Make sure the server conncection is always freed when the connection
is freed.
Pekka Riikonen [Sun, 25 May 2008 09:25:04 +0000 (12:25 +0300)]
Handle memory allocation failures when unformatting data
Pekka Riikonen [Sun, 25 May 2008 09:24:41 +0000 (12:24 +0300)]
Add non-executing stack when compiling AES asm for GNU/ELF.
Patch by Kp <kp@valhallalegends.com>
Signed-off-by: Pekka Riikonen <priikone@silcnet.org>
Pekka Riikonen [Sun, 25 May 2008 09:23:17 +0000 (12:23 +0300)]
Fixed crash when packet stream creation fails.
Pekka Riikonen [Sun, 25 May 2008 09:22:33 +0000 (12:22 +0300)]
Fixes to connection freeing crashes
Pekka Riikonen [Sun, 20 Apr 2008 19:53:47 +0000 (22:53 +0300)]
Cancel rekey timeout when closing connection.
Pekka Riikonen [Sun, 20 Apr 2008 15:54:53 +0000 (18:54 +0300)]
Fixed KILL command related crash in silcd
Pekka Riikonen [Thu, 17 Apr 2008 16:08:42 +0000 (19:08 +0300)]
Free connection data correctly when disconnecting the remote peer.
The silc_server_free_sock_user_data must be called if the
silc_server_disconnect_remote is called.
Pekka Riikonen [Wed, 16 Apr 2008 12:53:18 +0000 (15:53 +0300)]
Fixed many 64-bit alignment issues from silcd.
Pekka Riikonen [Sat, 12 Apr 2008 10:51:42 +0000 (13:51 +0300)]
Check for valid packet stream when counting number of connections in silcd.
Pekka Riikonen [Sat, 12 Apr 2008 10:51:06 +0000 (13:51 +0300)]
SILC_IS_FD_STREAM and SILC_IS_SOCKET_STREAM now checks for NULL stream.
Pekka Riikonen [Sat, 12 Apr 2008 10:50:39 +0000 (13:50 +0300)]
Fixed silc_skr_init to not fail if threads support are not compiled in.
Pekka Riikonen [Sat, 12 Apr 2008 10:50:09 +0000 (13:50 +0300)]
Removed wrong SILC_LOG_ERROR and assert check from silc_idcache_add.
In some cases it is not fatal error to attempt to add entry that already
exists. Removed the assert and changed the error to debug message.
Pekka Riikonen [Thu, 10 Apr 2008 15:04:11 +0000 (18:04 +0300)]
Compute packet sums using sha512sum.
Pekka Riikonen [Thu, 10 Apr 2008 15:03:46 +0000 (18:03 +0300)]
Mark scheduler task unscheduled after silc_schedule_unset_listen_fd.
Affects epoll() version of schduler. If it isn't marked unscheduled
next time fd's events are changed they expect the fd to be in epoll()
which they are not. Setting unscheduled will add them again to epoll().
Pekka Riikonen [Thu, 10 Apr 2008 15:01:35 +0000 (18:01 +0300)]
Fixed QoS data limit handling in socket stream when reading data.
Pekka Riikonen [Thu, 10 Apr 2008 14:59:59 +0000 (17:59 +0300)]
Fixed packet stream destroy crashes when closing connections.
Take a reference of the packet stream and then destroy it. The final
reference is freed in the timeout callback. Any operation in the mean
time will detect the stream is destroyed and won't do anything.
Pekka Riikonen [Tue, 8 Apr 2008 05:01:19 +0000 (08:01 +0300)]
Accept 0600 and 0640 for server private key permissions.
Pekka Riikonen [Tue, 8 Apr 2008 05:00:40 +0000 (08:00 +0300)]
Fixed busy-loop in WATCH command when adding public keys.
If the public key decoding failed the command ended up
decoding and failing the same public key for ever.
Pekka Riikonen [Thu, 20 Mar 2008 06:35:48 +0000 (08:35 +0200)]
Fixed possible buffer overflow in PKCS#1 message decoding.
Vulnerability reported by Core Security Technologies. Thanks.
Pekka Riikonen [Thu, 13 Mar 2008 11:52:15 +0000 (11:52 +0000)]
Fixed NEW_CLIENT packet processing crash when the packet doesn't
include nickname.
Pekka Riikonen [Fri, 22 Feb 2008 14:29:58 +0000 (14:29 +0000)]
Fixed partial encryption in CTR mode. Does not affect interop
in SILC.
Pekka Riikonen [Tue, 8 Jan 2008 07:48:42 +0000 (07:48 +0000)]
Fixed fingerprint generation. RedHat bug 372021.
Pekka Riikonen [Sun, 30 Dec 2007 12:04:27 +0000 (12:04 +0000)]
Fixed unix signal delivery.
Pekka Riikonen [Sat, 22 Dec 2007 07:15:09 +0000 (07:15 +0000)]
updates.
Pekka Riikonen [Sun, 18 Nov 2007 15:52:45 +0000 (15:52 +0000)]
updates.
Jochen Eisinger [Sun, 18 Nov 2007 15:44:17 +0000 (15:44 +0000)]
Sun Nov 18 16:43:04 CET 2007 Jochen Eisinger <coffee@silcnet.org>
* Add -avoid-version and -rpath flags when compiling the plugin.
Affected file is apps/irssi/src/fe-common/silc/Makefile.in
Pekka Riikonen [Sun, 18 Nov 2007 12:37:06 +0000 (12:37 +0000)]
updates.
Pekka Riikonen [Sun, 18 Nov 2007 09:50:18 +0000 (09:50 +0000)]
new keys.